AI cold calling is the use of a conversational voice AI agent to place outbound sales calls — the agent dials, speaks, listens, answers questions and either books a meeting or hands off to a person. Across the EU it is governed by two separate bodies of law that do different jobs: the AI Act, which since 2 August 2026 has required that people be told they are dealing with an AI system, and the ePrivacy Directive as transposed into each member state, which decides whether you were allowed to make the call in the first place. The first is uniform across the bloc. The second is not, and the differences between the Netherlands, Germany and Finland are large enough to change a campaign plan.
This guide covers what the AI Act now requires of a voice agent, how the calling rules differ across Sono’s markets, and the one question about conversational AI that no European regulator has yet answered. We are not lawyers and this is not legal advice — but every claim below traces to legislation, a regulator or the European Commission, and where the position is genuinely unresolved we say so rather than guessing.
What changed on 2 August 2026?
Article 50 of the EU AI Act came into application. It requires that AI systems intended to interact directly with people be designed so that those people are informed they are interacting with an AI system — unless that is obvious “from the point of view of a natural person who is reasonably well-informed, observant and circumspect” (Article 50(1), European Commission AI Act Service Desk). A separate obligation in Article 50(2) requires providers of systems generating synthetic audio to mark the output in a machine-readable format so it is detectable as artificially generated.
Two details decide who carries the obligation, and most write-ups get them wrong.
Article 50(1) and 50(2) are provider obligations. Article 50(3) and 50(4) are deployer obligations. The Commission’s own guidance is explicit: “Providers must comply with the relevant transparency obligations in Article 50(1) and (2) AI Act… Deployers fall within the scope of the transparency obligations in Article 50(3) and (4)” (Commission guidelines on Article 50 transparency, 20 July 2026). So a business that buys an off-the-shelf voice agent and runs it is a deployer, and has no direct 50(1) duty.
But white-labelling can move you across the line. The same guidance states that where a company takes an existing generative AI system and modifies it — new training data, for instance — then puts it into service under its own name, “that company becomes a provider of the new system”. If you brand a voice agent as your own, assume you have inherited the provider obligations.
Does the AI Act actually cover phone calls?
Yes, explicitly, and this is the part worth knowing. The Commission’s July 2026 guidelines list “AI-enabled voice assistants, chatbots/conversational agents” as in scope, and give a worked example of what compliance sounds like:
“Auditory disclosure: In voice-based or telephony contexts, explicit spoken statements at the beginning of the interaction (e.g. ‘This is an AI-powered assistant’)”
The guidelines also say notification must come “at the latest at the time of the first interaction”, and that for longer interactions “periodic reminders and context-aware disclosures are likely to be necessary”.
On the “unless it is obvious” carve-out, the Commission reads it narrowly and says why: it is “becoming increasingly hard for natural persons to know whether an interaction with an AI system or an actual human being is taking place”, so the obviousness exception “should be limited”. In practice, on a cold call to someone who did not initiate contact, the carve-out is not available. Disclose in the first sentence.
Penalties under Article 50 run to €15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99(4)).
One clarification, since there has been confusion: the Digital Omnibus on AI — Regulation (EU) 2026/1744 of 8 July 2026 — did not defer Article 50. It deferred certain high-risk obligations to 2027 and 2028, and it shortened the transitional period for the Article 50(2) marking duty to 2 December 2026. Transparency is live and enforceable now.
Were you allowed to make the call at all?
Different question, different law. The EU-level rule is Article 13 of the ePrivacy Directive, and it splits calls in two.
Article 13(1) requires prior consent for “the use of automated calling and communication systems without human intervention (automatic calling machines)”. Article 13(3) covers everything else — live human calls — and leaves the choice between opt-in and opt-out “to be determined by national legislation”.
Then Article 13(5) creates the divergence that matters commercially: paragraphs 1 and 3 “shall apply to subscribers who are natural persons”, with member states required only to ensure that the legitimate interests of non-natural-person subscribers are “sufficiently protected”. Every country answered that differently. There is no single European rule for calling a business.
Separately, GDPR applies to the data behind the call. B2B outbound normally runs on legitimate interests under Article 6(1)(f), but Article 21(2) gives an unconditional right to object to direct marketing and Article 21(3) makes that objection absolute: once someone objects, “the personal data shall no longer be processed for such purposes” (GDPR, consolidated). And legitimate interests will not rescue an unlawful call — Germany’s Federal Administrative Court held in January 2025 that Article 6(1)(f) cannot justify the underlying processing where the call itself breaches national marketing law.
How do the rules differ across Europe?
Six markets, six answers. This is a summary, not a compliance sign-off — check locally before you dial.
| Market | Live call to a business | Notes |
|---|---|---|
| Netherlands | Consent for zzp’ers, vof and other businesses without legal personality. Companies with legal personality (BV, NV) still callable. | Changed 1 July 2026: the existing-customer exception was abolished. ACM enforces. |
| Germany | Presumed consent (mutmaßliche Einwilligung) — a lower bar than consumers’ express consent, but narrow. | The Federal Administrative Court tightened it in 2025: a published business number does not create presumed consent. |
| Sweden | Opt-out, and the statute only protects natural persons — calls to a legal person’s number fall outside it. | NIX-Telefon is self-regulatory, not statutory, and only natural persons can register. |
| Finland | Opt-out for a human call. But automated calls need consent. | See the next section — this is where AI agents get complicated. |
| Ireland | Landlines opt-out via the National Directory Database; mobiles require prior opt-in consent. | Business numbers are in the NDD and can carry a preference. DPC enforces. |
| Poland | Governed by the 2024 Prawo komunikacji elektronicznej, which replaced the old Art. 172 regime. | The predecessor required consent and was not limited to natural persons. Verify the current standard locally — we have not confirmed it against the statute. |
Two of these are worth dwelling on.
The Netherlands moved recently and in your direction of travel. Since 1 July 2026, ACM’s position is that businesses need prior express consent to call consumers, and that “consumers and small entrepreneurs (zzp’ers and vof’s) get more protection against unwanted telemarketing” (ACM, 25 June 2026). If your Dutch target list is full of sole traders, it is now a consent list.
Germany is the most permissive of the six for B2B, and the most easily misread. Businesses need only presumed consent, not express consent. But the Bundesverwaltungsgericht held in January 2025 that presumed consent requires an objectively justified interest on the recipient’s side, and that a number published in a professional directory does not supply one — dentists publish their numbers “exclusively to ensure they can be reached by patients”. Fines run to €300,000 under the UWG, and Germany also imposes a five-year consent-documentation duty.
Is a conversational AI agent an “automated calling machine”?
This is the unresolved question, and it is the one that decides whether AI outbound is a screening exercise or a consent-only exercise.
The statutory hinge is ePrivacy Article 13(1): “automated calling and communication systems without human intervention”. A pre-recorded message played by a dialler is plainly caught. A human with a headset plainly is not. A generative agent holding a real two-way conversation, with no human on the line, sits between the two — and the answer determines whether you can call any business not on an opt-out register, or only businesses that have opted in.
No European regulator has answered it. We checked the EDPB and the data protection authorities of the Netherlands, Germany, Finland, Sweden, Poland and Ireland. None has published guidance, an opinion or an enforcement action on conversational AI voice agents making outbound calls. The EDPB’s nearest instrument is its 2021 guidelines on virtual voice assistants, which addresses device-based assistants rather than outbound telephony. ACM’s April 2026 telemarketing supervision materials do not mention AI at all.
The closest signal comes from Finland, and it is not encouraging for a permissive reading. The Data Protection Ombudsman draws the line by machine versus person: “If direct marketing takes the form of an automated (robotic) call, i.e. if the marketing is carried out by a machine instead of a person, prior consent from the person receiving the call is required” — whereas for traditional telephone marketing “prior consent from the recipient is not required” (Tietosuojavaltuutetun toimisto). On its face, an AI voice agent is a machine instead of a person.
So the honest position: build for consent. An AI calling programme aimed at people who have opted in — inbound enquiries, existing customers, event registrants, renewals — carries a fraction of the regulatory risk of pure cold outbound, and does not depend on how a question gets answered later. Anyone telling you confidently that AI calls are simply “live calls” is asserting something no regulator has confirmed.
How do you run it without getting fined?
Seven things, in order of how much trouble they save you.
- Say it is an AI in the first sentence. Required under Article 50 for systems interacting with people in the EU, and the Commission has published the example wording. It also removes the deception element regulators react to most sharply.
- Aim at consented audiences first. Given the unresolved Article 13(1) question, this is the single biggest risk reduction available, and it costs you nothing legally.
- Screen against every national opt-out register that applies — Ireland’s NDD, Sweden’s NIX where the subscriber is a natural person, and the national equivalents in each market you dial. Screen fresh, not from a list someone checked last quarter.
- Know the legal form of who you are calling. In the Netherlands this now decides whether you need consent. A list that does not distinguish BV from zzp is not a usable list.
- Honour objections instantly and permanently, across every list and channel. GDPR Article 21(3) is absolute, and most enforcement starts with someone who asked to be left alone and was called again.
- Log everything — number, time, consent basis, screening date, disclosure given, outcome. If a regulator asks, the log is your defence; without one you have an assertion.
- Keep a human escalation path. An agent that cannot hand over to a person when someone gets annoyed is manufacturing complaints, and complaints are how investigations start.
For the wider data-protection picture — recording, retention, DPIAs, the AI Act in more detail — see our guide to GDPR and EU AI Act compliance for voice AI. For where cold outbound sits alongside inbound enquiry handling, start with lead qualification.
Most companies that get into trouble here were not confused about the law. They bought a list, did not check it, and dialled. If you are going to put an AI on the phone, the compliance work is the cheap part to get right and the expensive part to skip. Sono handles disclosure, screening and logging as part of how outbound calls are set up, in each market’s own language, so the audit trail exists whether or not anyone asks for it — talk to us if you want to see it against your own list.
Useful links and sources
- AI Act Article 50 — transparency obligations — European Commission AI Act Service Desk
- Guidelines on Article 50 transparency obligations — European Commission, 20 July 2026
- Regulation (EU) 2026/1744 — Digital Omnibus on AI — EUR-Lex, 8 July 2026
- ePrivacy Directive 2002/58/EC, consolidated — EUR-Lex
- GDPR, consolidated text — EUR-Lex
- Strengere regels voor telemarketing vanaf 1 juli — ACM, 25 June 2026
- BVerwG 6 C 3.23 — Bundesverwaltungsgericht, 29 January 2025
- Direct marketing FAQ — Tietosuojavaltuutetun toimisto
- National Directory Database FAQ — Data Protection Commission