AI governance for telecom operators
Telecom operators come to the AI Act with a heavy compliance framework already in place, spanning AGCOM oversight, NIS2 obligations and traffic data protection. The surprise, for many, is discovering that some commercial processes fall under Annex III for a reason that has nothing to do with networks.
The regulatory framework
- AI Act: most network use cases remain minimal risk, while customer creditworthiness assessment falls under Annex III
- NIS2, which classifies telecom operators as essential entities
- Cyber Resilience Act, for products with digital elements placed on the market
- AGCOM oversight of electronic communications services
- GDPR and ePrivacy, for traffic data, location data and profiling
Use cases and their risk level
| Use case | Classification | Note |
|---|---|---|
| Credit assessment for device instalment plans | High risk, Annex III | It is credit scoring in every respect, even when introduced as a commercial process |
| Churn and propensity models | Limited or minimal risk | Consider profiling requirements under the GDPR |
| Customer service conversational assistants | Limited risk | Article 50 transparency obligations, already in force |
| Predictive maintenance and network optimisation | Minimal risk | NIS2 resilience obligations still apply |
| Traffic fraud detection | Assess case by case | Depends on the effect on the individual customer |
Where to start
- 1Check whether credit assessment processes exist, including those presented as commercial offers with deferred payment, because they change the risk classification
- 2Coordinate the documentation required by the AI Act with documentation already produced for NIS2, avoiding two separate frameworks for the same systems
- 3Define the contractual role for models supplied by network vendors, which are rarely developed internally
What we do for the sector
The path is always the same and the content changes: it starts from the use case map, assesses impact before investing, validates with a prototype, and only then reaches production. Rapid prototyping runs through protot.ai, our validation unit.
Use case definition
We separate network use cases, where risk stays minimal, from commercial processes that may fall under Annex III without anyone noticing. The resulting portfolio distinguishes by purpose and flags the processes that change class, starting with customer credit assessment.
Impact assessment
We measure expected economic impact and coordinate the assessment with what already exists for NIS2, because two separate frameworks on the same systems cost twice and hold up less. Where traffic data is involved the assessment also reaches the ePrivacy perimeter.
Prototyping and validation
With protot.ai we take the hypothesis to a working prototype on real data, useful above all where volume makes it hard to estimate results in the abstract. In customer service, that means measuring on real conversations how much the system genuinely resolves without escalation.
Production and oversight
In production the work covers integration with network and billing systems, defining the contractual role for vendor-supplied models, and ongoing oversight. Most models are not developed in house, and that changes who answers for what.