AI governance for telecom operators

    Telecom operators come to the AI Act with a heavy compliance framework already in place, spanning AGCOM oversight, NIS2 obligations and traffic data protection. The surprise, for many, is discovering that some commercial processes fall under Annex III for a reason that has nothing to do with networks.

    The regulatory framework

    • AI Act: most network use cases remain minimal risk, while customer creditworthiness assessment falls under Annex III
    • NIS2, which classifies telecom operators as essential entities
    • Cyber Resilience Act, for products with digital elements placed on the market
    • AGCOM oversight of electronic communications services
    • GDPR and ePrivacy, for traffic data, location data and profiling

    Use cases and their risk level

    Use caseClassificationNote
    Credit assessment for device instalment plansHigh risk, Annex IIIIt is credit scoring in every respect, even when introduced as a commercial process
    Churn and propensity modelsLimited or minimal riskConsider profiling requirements under the GDPR
    Customer service conversational assistantsLimited riskArticle 50 transparency obligations, already in force
    Predictive maintenance and network optimisationMinimal riskNIS2 resilience obligations still apply
    Traffic fraud detectionAssess case by caseDepends on the effect on the individual customer

    Where to start

    1. 1Check whether credit assessment processes exist, including those presented as commercial offers with deferred payment, because they change the risk classification
    2. 2Coordinate the documentation required by the AI Act with documentation already produced for NIS2, avoiding two separate frameworks for the same systems
    3. 3Define the contractual role for models supplied by network vendors, which are rarely developed internally

    What we do for the sector

    The path is always the same and the content changes: it starts from the use case map, assesses impact before investing, validates with a prototype, and only then reaches production. Rapid prototyping runs through protot.ai, our validation unit.

    1

    Use case definition

    We separate network use cases, where risk stays minimal, from commercial processes that may fall under Annex III without anyone noticing. The resulting portfolio distinguishes by purpose and flags the processes that change class, starting with customer credit assessment.

    2

    Impact assessment

    We measure expected economic impact and coordinate the assessment with what already exists for NIS2, because two separate frameworks on the same systems cost twice and hold up less. Where traffic data is involved the assessment also reaches the ePrivacy perimeter.

    3

    Prototyping and validation

    With protot.ai we take the hypothesis to a working prototype on real data, useful above all where volume makes it hard to estimate results in the abstract. In customer service, that means measuring on real conversations how much the system genuinely resolves without escalation.

    4

    Production and oversight

    In production the work covers integration with network and billing systems, defining the contractual role for vendor-supplied models, and ongoing oversight. Most models are not developed in house, and that changes who answers for what.

    Assess your organisation's starting point