🤖 The CRM is now full of AI agents
Over the past year the big vendors have pushed AI agents inside the CRM. Not a side panel that suggests things: processes that act on their own against your data — qualifying a lead, replying to a client, updating an opportunity, opening a support case.
Zoho calls it Zia and describes it plainly on its own site: AI agents "capable of executing business tasks autonomously", alongside predictive lead scoring, revenue forecasting, sentiment analysis on emails and calls, data enrichment and anomaly detection. Salesforce and HubSpot have gone the same way under their own brands.
The promise is good and often real. The problem is that almost nobody has read the small print: in Europe the date is 2 August 2026.
📅 What exactly happens on 2 August 2026
The EU Artificial Intelligence Act entered into force in August 2024, but it applies in phases. The first ones are already behind us: prohibited practices and AI literacy from 2 February 2025, and general-purpose AI model obligations from 2 August 2025.
The big phase is next. According to the European Commission itself, the regulation "will be fully applicable 2 years later on 2 August 2026, with some exceptions". In practice, that day the remainder of the Act starts to apply, with one specific carve-out — Article 6(1), which waits until 2027.
For a CRM with agents, that boils down to three things:
- Transparency. The Commission puts it like this: "when using AI systems such as chatbots, humans should be made aware that they are interacting with a machine". If your CRM answers client emails, chats or messages with an agent, you have to say so.
- Generated content. Synthetic text, images and audio have to be marked as such.
- High risk. Annex III systems come in on that date. Most commercial CRM uses are not high risk, but some HR uses are — CV screening, promotion decisions — and they often live inside the same CRM.
🧭 Checklist: what to review in your CRM before August
Short and honest:
- Inventory. List which AI features are switched on and which of them act without anyone approving the outcome.
- Client disclosure. Any channel where an agent talks to a person (email, web chat, WhatsApp) must make clear it is AI.
- Traceability. Keep a record of what the agent did, with what data and when. If you cannot reconstruct it, you cannot defend it.
- Human in the loop. Decide which actions never run unattended: discounts, cancellations, any decision about people.
- Data. What leaves for the model provider, and on what legal basis. GDPR and the AI Act overlap here.
- Contracts. Check what your CRM vendor signs about using your data to train its models.
🛠️ Why this is easier with a custom CRM
All of the above is far easier to satisfy when the CRM is yours. In the CRMs I build, traceability is not a late add-on: every automatic action lands in an activity log with its trigger, its conditions and its outcome, and automations are defined with explicit rules — what fires them, which conditions hold, which action runs — instead of an opaque model deciding on its own.
That is my practical read: AI in the CRM is fine where it saves repetitive work, but the business process has to stay explicit and auditable. An agent drafting an email is help. An agent closing an opportunity without a trace is a problem with an expiry date.
✅ In short
- Off-the-shelf CRMs already ship AI agents that act autonomously.
- On 2 August 2026 the EU AI Act becomes fully applicable.
- You must disclose when a machine is talking, mark generated content and be able to prove what the system did.
- If your CRM will not let you reconstruct that, the problem is not the law: it is the CRM.
Want to go through your CRM — the one you have, or the one you need — before August? Tell me about your case.
Sources: AI regulatory framework — European Commission · AI Act implementation timeline · Zia — Zoho CRM