Telecom 2 min read

Steps for telecom operators to prepare for EU AI Act

An overview of key AI Act requirements for telecom operators, focusing on data preparation, cybersecurity, and call authentication standards.

Regulating AI communications in telecom: Challenges of 2026

In 2026–2027, telecom operators will face the necessity of adapting to the European AI Act. The regulation establishes strict requirements for artificial intelligence systems that process personal data, impact network security, or interact with customers (voicebots, anti-fraud systems). Operators must ensure decision transparency, the quality and representativeness of training data, the cybersecurity of AI models, and the possibility of human intervention in high-risk scenarios.

Market implications

The introduction of the EU AI Act forces telecom operators to overhaul their data management and security frameworks. Non-compliance risks substantial financial penalties and the potential suspension of critical AI-driven services, such as automated customer support and fraud detection. However, successful adaptation will significantly enhance network security, mitigate AI-driven fraud, and build greater consumer trust.

Data preparation and implementing Data Governance

Successful AI implementation does not start with choosing language models, but with organizing data. Telecom companies often face information fragmentation across disparate systems (OSS/BSS, CRM, SIEM), a lack of unified reference data, and low data quality. To comply with the AI Act, operators need to implement Data Governance policies that include data collection standardization and regular quality audits.

Cybersecurity and call authentication

According to the CFCA Global Fraud Loss Survey 2025, global losses from telecom fraud reached $41.82 billion. The ENISA Threat Landscape 2025 report highlights the risks of using AI to automate phishing and create deepfakes. To protect networks, operators require multi-layered security systems: AI-driven anomaly monitoring, enhanced authentication, and anti-spoofing protection.

A key tool in combating caller ID spoofing is the STIR/SHAKEN framework. It allows operators to cryptographically sign and verify Caller IDs. In accordance with RFC 8224, this is achieved using the Identity header in SIP, which contains a PASSporT token confirming the call's attestation level. Compatibility with this standard must be supported by all network elements, including routing and billing platforms.

A practical checklist

To ensure compliance with the EU AI Act and protect infrastructure, operators should take the following practical steps:

  • Conducting an audit and inventory of existing AI systems.
  • Developing unified Data Governance standards.
  • Strengthening AI infrastructure protection against manipulation and attacks.
  • Implementing STIR/SHAKEN call authentication at all routing stages.
  • Training staff on regulatory requirements and cybersecurity.

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. Розробка ПЗ з використанням ШІ та AI-консалтинг — softengi.com
  2. DooxSwitch — dooxswitch.com
  3. Xplorum AI Platform — softengi.com
  4. Ionbond AI Visual Inspection — softengi.com
  5. WhTech-WMS — softengi.com
  6. Agora CSP — softengi.com