Skip to content

The AI Act probably does not regulate your lead scoring

Annex III lists eight areas of high-risk AI use, and sales prospecting is in none of them. The obligation that does land on a go-to-market stack is smaller, more specific, and mostly about the chat widget — while the law that actually governs scoring people is seven years old.

Antiqore6 min read

Every vendor in this category now has an AI Act paragraph. Most of them imply that a scoring model is regulated machinery requiring conformity assessment. It is worth reading the annex, because the answer is narrower than the marketing, and the thing that does apply is being ignored while everyone looks at the wrong clause.

What Annex III actually lists

High-risk classification is not a judgement call about how consequential your model feels. It is a list. Annex III names eight areas:

#Area
1Biometrics
2Critical infrastructure
3Education and vocational training
4Employment, workers management and access to self-employment
5Access to essential private and public services and benefits
6Law enforcement
7Migration, asylum and border control
8Administration of justice and democratic processes

Sales prospecting is not there. The closest thing is inside area five, which covers systems used “to evaluate the creditworthiness of natural persons or establish their credit score” — an assessment that decides whether a person gets a loan, not whether a rep makes a call.

The difference is the consequence borne by the person scored. Being declined credit is a closed door. Being ranked 34th on a prospect list is a phone call that may not come. The annex draws the line there, and a B2B lead score sits on the safe side of it.

The obligation that does land

Systems that interact with people carry a transparency duty: the person has to be aware they are dealing with AI, and synthetic content has to be identifiable as generated. That is a real requirement, it is not burdensome, and in a go-to-market stack it points at exactly one component — the chat widget.

It is worth noticing how low that bar is, and how many widgets still clear it only by accident: a human first name, a typing indicator and no disclosure anywhere is a design that was chosen, and the transparency duty is the law catching up with why it was chosen.

The regulated surface is the one that talks to people, not the one that ranks them.

The law that has applied since 2018

While the AI Act was being drafted, GDPR Article 22 already governed decisions taken solely by automated means that produce legal effects or similarly significantly affect someone. Alongside it, Articles 13 to 15 require you to tell people that such decision-making exists and give meaningful information about the logic involved.

For scoring companies, this mostly does not bite: a company is not a natural person. The boundary is crossed the moment the record carries people — and every serious GTM record does:

  • The named buying committee is a list of identifiable individuals.
  • An email-confidence score is an assessment attached to a person.
  • Behavioural history from your own site is a record of what one person did.
  • Any inference about seniority, authority or intent is an inference about a human being.

None of that is prohibited. It does mean the honest answer to “what do you do with my data” has to be available, which is the same requirement we wrote about in what legitimate interest actually covers — and, again, it is answerable only if you recorded the source at the time you collected it.

What we do about it

Two things, both of which predate the Act and neither of which is generous.

The chat refuses questions its corpus does not cover and cites the page it answered from, which we wrote about in the best thing a chat widget can say. A widget that cites its source is transparent about being a machine by construction, not by disclaimer.

And the score is kept as three separate numbers — fit, intent and confidence — rather than one composite. A single number is unexplainable by design; three tell you which part is weak, which is what “meaningful information about the logic” means when a person asks. That is set out in the evidence standard.

Frequently asked questions

Is B2B lead scoring high-risk under the EU AI Act?
Almost certainly not. Annex III lists eight areas of high-risk use, and sales prospecting is in none of them. The nearest neighbour is scoring the creditworthiness of natural persons, which is a different activity with a different consequence for the person being scored.
Then what does apply to a go-to-market AI system?
The transparency duty. A system that interacts with a person has to make clear the person is dealing with AI, and synthetic content has to be identifiable as such. For most GTM stacks that means the chat widget, not the scoring model.
When do the obligations start?
They phase in from entry into force: prohibitions at six months, general-purpose AI at twelve, Annex III high-risk at twenty-four, and Annex I high-risk at thirty-six. The high-risk dates only matter if you are actually in one of those categories.
Which law should a revenue team actually worry about?
GDPR Article 22, on decisions taken solely by automated means that produce legal or similarly significant effects, and Articles 13 to 15 on what you must tell people about the logic involved. That is the regime that has applied since 2018 and already covers scoring people.
Does scoring companies count as personal data?
The company record generally does not. The named individuals attached to it do — a buying committee is a list of identifiable people, and an email-confidence score is an assessment attached to a person. The company/person boundary is where most GTM systems quietly cross into personal data.