AI & AutomationGuide

EU AI Act and CRM AI: What Companies Using Bitrix24 Need to Do in 2026-2027

The EU AI Act (Regulation (EU) 2024/1689) is already in force, and its transparency obligations under Article 50 apply from 2 August 2026 - meaning companies using CoPilot in their CRM right now need a concrete compliance plan. This article maps each obligation to a specific date and to the Bitrix24 settings or internal policies that address it. This is not legal advice; consult qualified legal counsel for your specific situation.

Bitrix24 WhatsAppTelegramERPEmailTelephony

Every channel ends up in one portal

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Regulatory interpretation may vary; always consult a qualified legal professional for advice on your specific situation.

EU AI Act Timeline: Key Dates for CRM Users

The EU AI Act entered into force on 1 August 2024 and rolls out in phases; the dates most relevant to CRM users are 2 August 2026 (Article 50 transparency), 2 December 2026 (transition for marking AI-generated content), 2 December 2027 (Annex III high-risk systems including employee monitoring), and 2 August 2028 (Annex I high-risk systems).

The regulation was subsequently amended by Regulation (EU) 2026/1744 "Digital Omnibus on AI", published in the Official Journal on 24 July 2026, which shifted some high-risk deadlines to give deployers more time while keeping the transparency obligations firmly in place.

Date Obligation Who it affects
2 Feb 2025 Prohibited AI practices banned; AI literacy obligation active All providers and deployers in the EU
2 Aug 2025 General-purpose AI model rules apply Providers of foundation models
2 Aug 2026 Article 50: disclose chatbot / AI interaction; mark AI-generated content Providers of AI systems that interact with people or generate content; deployers that publish deep fakes or AI text to inform the public (Art. 50(4))
2 Dec 2026 Transition deadline: generative systems placed on market before 2 Aug 2026 must meet Article 50(2) marking Providers of generative AI systems placed on the market before 2 Aug 2026 (e.g. the system behind CoPilot image generation)
2 Dec 2027 Annex III high-risk obligations (including Annex III point 4(b): AI monitoring/evaluating employee performance) Deployers of employee monitoring and call-scoring AI
2 Aug 2028 Annex I high-risk obligations Deployers of AI in safety-critical sectors

Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744.


Which Bitrix24 AI Features Trigger EU AI Act Obligations?

Bitrix24 CoPilot is active by default for all users from account creation, covers call transcription, CRM field auto-fill, chat analysis, script scoring, and content generation - each of these touches at least one EU AI Act obligation, and some may qualify as high-risk under Annex III point 4(b).

CoPilot uses third-party AI providers - currently gpt-4o-2024-11-20 for text generation and CRM field updates, AudioAssistant AI for call transcription, and Dall-E-3 for image generation (Bitrix24 helpdesk). Requests to OpenAI are transmitted to the USA for processing (Bitrix24 AI Tools Terms of Use, 7 Aug 2026).

Here is how the main features map to regulatory risk:

CoPilot Feature EU AI Act Touch Point Risk Level
CoPilot chat in Feed / Tasks Article 50: users may not know they interact with AI Low - transparency obligation
Call transcription (CRM) Article 50 disclosure; potential Annex III point 4(b) if used to score employees Medium - legal assessment needed
Script / call scoring ("Rate call") Annex III point 4(b): monitoring and evaluating employee performance Potentially high-risk
CRM field auto-fill from calls or emails Human review recommended; Bitrix24 Terms 1.4 apply if outputs feed decisions about people Low-medium
AI-generated images (Dall-E-3) Article 50(2): AI-generated content must be marked Low - marking obligation
CoPilot Follow-Up for video calls Disclosure that meeting notes are AI-generated Low - transparency obligation

For more detail on what CoPilot does with call data, see AI Call Analysis in Bitrix24: Transcription, Quality Scoring, and Sales Coaching.


Article 50 Transparency: What You Must Disclose and When

From 2 August 2026, Article 50 of the EU AI Act requires providers to ensure people know they interact with an AI system and that AI-generated content is marked, and deployers to disclose deep fakes and AI-generated public-interest text; marking for systems already on the market before that date is due by 2 December 2026.

Article 50 of Regulation (EU) 2024/1689 sets out several transparency obligations; the key ones for CRM users are:

50(1) - Chatbot disclosure: When a natural person interacts with an AI system that generates text, speech or other output and could reasonably assume they are dealing with a human, the provider must design the system so that the person is informed they are interacting with AI. This matters for AI chat agents that talk to customers, such as a Vibecode app or a third-party Market app connected to Open Channels (Bitrix24 has no built-in AI auto-reply bot there); if your company builds such an agent itself, ask counsel whether it acts as the provider.

50(2) - Marking AI-generated content: Providers of generative AI systems must ensure that outputs are marked in a machine-readable format and detectable as AI-generated; for CoPilot features such as image generation (Dall-E-3), this duty sits with the provider of the system, not with the company using it. Systems placed on the market before 2 August 2026 must comply by 2 December 2026. Separately, under Article 50(4) deployers must disclose deep fakes and AI-generated text published to inform the public on matters of public interest, unless the text has undergone human review or editorial control.

Practical actions in Bitrix24:

  • Add a visible disclosure when CoPilot-generated text is sent to customers (e.g. a footer note in emails drafted with CoPilot).
  • Mark AI-generated images before publishing them through Bitrix24 Sites or any customer-facing channel.
  • Review your email templates: if CoPilot drafts emails that are sent to customers, consider telling recipients; the Article 50(4) duty covers AI text published to inform the public. CoPilot currently fills CRM fields from emails (helpdesk) and generates text - ensure customer-facing output is clearly identified.
  • Document that disclosure notices are in place.

High-Risk AI in the Workplace: Call Scoring and Employee Monitoring

Annex III point 4(b) of the EU AI Act lists AI used to monitor and evaluate the performance and behaviour of persons in work relationships as high-risk; Bitrix24's call-scoring feature ("Rate call - CoPilot checks the conversation against the script") may fall into this category and requires a legal assessment before the 2 December 2027 deadline.

The "Rate call" feature, documented in the Bitrix24 helpdesk, analyzes agents' calls, compares them to sales scripts, and produces evaluation results visible in the CRM timeline. This is precisely the type of automated performance evaluation that Annex III point 4(b) targets.

If this feature qualifies as high-risk, the high-risk rules apply from 2 December 2027 (Regulation (EU) 2026/1744); which duties fall on your company as a deployer of Annex III point 4(b) systems should be confirmed by counsel. Typical preparation steps:

  • Implement human oversight procedures (a person must be able to override or disregard AI scores).
  • Ensure the employees being monitored are informed that AI is used to evaluate their performance.
  • Keep logs and records of how AI scores are reviewed.

Bitrix24 AI Tools Terms of Use (clause 1.4) already prohibit using AI Tools "for making decisions which produce legal effects concerning individuals, or similarly significant effects, without meaningful human involvement." This aligns with the AI Act's human oversight requirement, but it places the burden of implementing that oversight on the deployer - your organisation.

Action now: commission a legal assessment of whether your use of call scoring constitutes a high-risk AI system under Annex III. Do not wait for the 2 December 2027 deadline to begin this work.

For broader context on data sovereignty decisions that affect compliance choices, see GDPR-Compliant CRM: Why Self-Hosted Bitrix24 Wins for EU Companies.


AI Literacy: Training Your Team Before the Deadline

The AI literacy obligation under the EU AI Act has applied since 2 February 2025; Regulation (EU) 2026/1744 softened it, and it does not require providers or deployers to guarantee any specific level of AI literacy of any individual - practical training for staff who operate or oversee AI systems remains the sensible response.

Legal basis: Article 4 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This is not a one-time checkbox. Practically, it means:

  • Staff using CoPilot for call analysis, CRM field auto-fill, or content generation should understand what the tool does, what data it sends to third-party providers, and where outputs may be inaccurate.
  • Managers who use AI-generated call scores to make decisions about employees must understand that those scores are probabilistic outputs - not objective facts.
  • Your organisation should maintain records of which staff received training, on what topics, and when.

A starting point for internal training: Bitrix24 administrators can review which CoPilot tools are enabled and allow or restrict CoPilot chat via Settings -> CoPilot preferences (helpdesk). Training should cover why those restrictions are in place.


GDPR and the AI Act: How Data Processing Rules Interact

The EU AI Act does not replace GDPR - both apply simultaneously; for Bitrix24 CoPilot, this means your GDPR obligations as a data controller (lawful basis, data subject rights, cross-border transfer safeguards) layer on top of AI Act obligations, and Portugal-based accounts are served from a US-region data centre by default.

Key GDPR touchpoints when using Bitrix24 CoPilot in the EU:

Data controller responsibilities (GDPR Art. 28): Your company is the controller; the vendor's entity in Cyprus (for Portugal customers) is the processor. The Bitrix24 Data Processing Agreement (29 Nov 2024) governs this relationship. Review it to confirm sub-processor authorisation is adequate for AI providers.

Cross-border transfers: CoPilot requests go to OpenAI in the USA (Bitrix24 AI Tools Terms, clause 8.1). The Bitrix24 DPA references the EU-U.S. Data Privacy Framework for infrastructure transfers. Confirm that the transfer mechanism for AI processing is documented in your records of processing activities.

Portuguese and Spanish accounts on US servers: According to the Bitrix24 sub-processor list (last updated 30 Jul 2025), customers in Portugal are served from the US region (AWS, N. Virginia) by default. EU-zone hosting (.eu accounts in Frankfurt) is available but requires a migration request via helpdesk. If data residency inside the EU is a requirement for your GDPR or AI Act risk posture, raise this with your Bitrix24 partner or contact the helpdesk.

Data subject rights and automated decisions: GDPR Article 22 restricts solely automated decisions with significant effects. The Bitrix24 AI Tools Terms (1.4) mirror this by prohibiting decisions with legal or similarly significant effects without human involvement. Document your human review steps.

AI provider data use: Bitrix24 AI Tools Terms (clause 6.1) state that AI providers may use your content to improve their AI technologies under their own terms. Bitrix24 stores data for up to 14 days for technical purposes then deletes it (CoPilot FAQ). Review whether this is disclosed in your privacy notices to employees and customers.

For a detailed look at data residency options and how self-hosted Bitrix24 changes the picture, see Where Bitrix24 AI Processes Your Data and How to Stay Compliant.


Obligation-to-Action Checklist for Bitrix24 Administrators

The checklist below maps each EU AI Act obligation to a concrete action in Bitrix24 or in your organisation's policies; it is structured by deadline so you can prioritise work.

A compliance plan built around these steps will address the core obligations for a typical CRM-using company in the EU. This is a starting point - your legal counsel should validate it against your specific use cases.

By 2 August 2026 (Article 50 - already active)

  • Audit active CoPilot features: go to Settings -> CoPilot preferences and document which tools are enabled (text generation, image generation, CRM, call transcription).
  • Add chatbot disclosures: where AI agents or auto-replies (for example Vibecode apps or third-party Market apps) interact with customers or job applicants, add a clear statement that they are interacting with an AI system.
  • Update privacy notices: include a description of AI-assisted processing (transcription, field auto-fill, scoring) in your employee and customer privacy notices.
  • Check provider used: employees can verify their AI provider in the CoPilot chat (Messenger -> CoPilot chat -> chat name -> Provider). Document this centrally.
  • Review the Bitrix24 DPA and sub-processor list (sub-processor list) to confirm transfer mechanisms cover AI provider processing.

By 2 December 2026 (Article 50(2) - AI-generated content marking)

  • Ask the vendor about marking: machine-readable marking of CoPilot outputs, including Dall-E-3 images, is the provider's Article 50(2) duty - confirm how Bitrix24 implements it.
  • Disclose AI-generated public text: if CoPilot drafts web copy published to inform the public on matters of public interest and nobody reviews it editorially, disclose that it is AI-generated (Article 50(4), applies from 2 August 2026).
  • Document the marking process and keep evidence of compliance.

By 2 February 2025 (already past) - verify completion

  • AI literacy: confirm that staff using CoPilot have received training on its capabilities, limitations, and the data flows involved.
  • Prohibited practices audit: confirm none of the prohibited AI practices (subliminal manipulation, social scoring, biometric categorisation for prohibited purposes) are in use.

By 2 December 2027 (Annex III high-risk - if applicable)

  • Legal assessment: commission a written legal opinion on whether your use of call scoring / "Rate call" qualifies as an Annex III point 4(b) high-risk AI system.
  • Human oversight procedure: if high-risk, document the human review process for AI-generated call scores before they influence employment decisions.
  • Employee notification: inform employees in writing that AI is used to evaluate call performance.
  • Records: keep the vendor's documentation and your own records of how AI call scores are reviewed and used.
  • Impact assessments: ask counsel which assessments, for example under GDPR, apply to your use of call scoring.

Ongoing

  • Monitor sub-processor changes: Bitrix24 announces new sub-processors at least 10 days in advance (where GDPR applies). Subscribe to these notifications and update your records.
  • Restrict CoPilot tools where employees should not use them: choose which tools use CoPilot and allow or restrict CoPilot chat (Settings -> CoPilot preferences, administrator-only).
  • Consider EU data zone hosting if data residency inside the EU is a hard requirement - request migration to the Frankfurt region via helpdesk.

For guidance on configuring Bitrix24 for compliance from the start, the Bitrix24 Onboarding Questionnaire: 50+ Questions to Ask First covers the governance questions worth addressing before go-live.

Questions we get asked

FAQ: EU AI Act & CRM AI

Does the EU AI Act apply to my company if we just use Bitrix24 CoPilot for internal tasks?

Yes. The EU AI Act applies to 'deployers' - organisations that use AI systems in a professional context within the EU, regardless of whether the use is internal or customer-facing. Using CoPilot for call transcription, employee task summaries, or script scoring all constitutes deploying an AI system. Article 50 transparency obligations apply from 2 August 2026 and the AI literacy obligation has applied since 2 February 2025.

Does Bitrix24 CoPilot count as a high-risk AI system under Annex III?

General CoPilot use (text generation, CRM field auto-fill) is unlikely to qualify as high-risk on its own. However, the call-scoring feature ('Rate call') that evaluates employee performance against sales scripts may fall under Annex III point 4(b), which covers AI used to monitor and evaluate persons in work relationships. A legal assessment is necessary before the 2 December 2027 deadline. See Regulation (EU) 2024/1689, Annex III.

Where does Bitrix24 CoPilot process data, and does that affect EU AI Act compliance?

CoPilot uses third-party AI providers, primarily OpenAI; requests are transmitted to the USA for processing, as stated in the Bitrix24 AI Tools Terms of Use. Portugal-based accounts are served from the US AWS region by default. This cross-border transfer must be covered by an appropriate mechanism (e.g. Standard Contractual Clauses or the EU-U.S. Data Privacy Framework) under GDPR, which layers on top of AI Act obligations.

What does the AI literacy obligation require from our company?

The AI literacy obligation (Article 4 of Regulation (EU) 2024/1689) has applied since 2 February 2025. Regulation (EU) 2026/1744 softened it: it does not require providers or deployers to guarantee any specific level of AI literacy of any individual. Practically, this means documented training for anyone using CoPilot features, especially managers who use AI-generated call scores in performance decisions.

Can Bitrix24 CoPilot make decisions about employees or customers automatically?

The Bitrix24 AI Tools Terms of Use (clause 1.4) expressly prohibit using CoPilot 'for making decisions which produce legal effects concerning individuals, or similarly significant effects, without meaningful human involvement.' This aligns with the EU AI Act's human oversight requirements and GDPR Article 22. Your internal processes must ensure a human reviews and approves any consequential output before it is acted upon.

Is there a way to move Bitrix24 account data to EU servers to improve our compliance posture?

Yes. Bitrix24 hosts accounts in Frankfurt, Germany (AWS) for .eu zone accounts. Customers in Portugal on the default US region can request a transfer to EU data centres via the Bitrix24 helpdesk. Note that even on EU-hosted accounts, CoPilot prompts are still transmitted to OpenAI in the USA for processing, so the transfer mechanism for AI processing must still be addressed separately.

Who wrote this

ACP Group implementation team

Bitrix24 Gold Partner

Written by the consultants who run Bitrix24 implementations, migrations and integrations for clients in the UAE, Brazil and Portugal.

Bitrix24 Gold Partner1,200+ projects since 2018

What we hear in the first ten minutes

Send one message and skip the discovery call

Write to +971 55 780 1481 on WhatsApp. Describe your setup and the headcount, and you get a written scope and price back in one working day.

Chat on WhatsApp Use the form instead

Same number for calls. UAE business hours.