KrambergAI AI Consulting for SMEs

Whitepaper · 2026 Edition

AI Telephony
for SMEs

A practical guide: how small and medium-sized enterprises answer calls reliably, ease the load on their teams and handle customer requests in a structured way

Audience

Managing directors, IT leads, service managers and departments in small and medium-sized enterprises

Scope

Use cases, architecture, data protection, EU AI Act, business case, rollout, checklists

Published by

KrambergAI GmbH
krambergai.com

KrambergAIAI Telephony for SMEs

Overview

Contents

Executive summary3
01The starting point: why the phone endures4
02Terms: phone menu, voicebot, AI voice assistant5
03What AI telephony can do6
04Why the answering machine no longer suffices7
05Suitable inbound use cases8
06Outbound calling and its legal limits10
07Where automation has to stop11
08The business process decides success12
09Technical architecture13
10Integration with existing systems15
11Conversation design and the human handover16
12Data protection under the GDPR17
13Recording, transcripts and confidentiality19
14EU AI Act: transparency duty from 2 August 202620
15Co-determination and employee data protection22
16Information security and permissions23
17Measuring quality: metrics and error classes24
18Building a realistic business case26
19Choosing the right provider28
20Rolling out in eight controlled steps30
21Practical examples from SMEs32
22Common mistakes and how to avoid them34
Checklists for management, data protection and security35
Frequently asked questions37
Glossary39
About KrambergAI40

About this whitepaper. The guide is written for decision-makers who are evaluating AI telephony, planning it or looking to run an existing solution more professionally. It is not a product comparison but a walk through the operational, technical, legal and financial questions that should be settled before a decision is made.

The content does not replace legal or data-protection advice. Legal requirements must always be assessed for the specific use case. Editorial status: July 2026.

KrambergAI GmbH · krambergai.com2
KrambergAIExecutive Summary

Executive Summary

What matters

AI telephony is not a question of the voice; it is a question of the process. Those who know beforehand what should happen after a call end up with a dependable tool. Those who do not end up with an expensive answering machine that pronounces things nicely.

The problem is rarely the technology

Recognizing, understanding and generating speech works reliably enough today for everyday operation. The projects that fail, fail on unclear responsibilities, missing required information and a handover to staff that no one defined.

The value lies at the interface

A call whose result is later copied into the CRM by hand saves little. The financial effect appears when the call turns into a ticket, an appointment or a complete callback record without an intermediate step.

Transparency becomes mandatory in August 2026

Under Article 50 of the AI Act, from 2 August 2026 it must be clear that an AI system is speaking on the other end. This deadline was not postponed by the Digital Omnibus. Anyone planning today is planning under the law as it stands.

Starting small is not timidity

The most robust entry point is a tightly scoped, low-risk use case: calls outside business hours, structured callback requests, routing by request. There is always time to expand later.

The ten core statements

  1. An AI voice assistant does not replace staff. It ensures that staff enter a conversation with complete information.
  2. What should be automated are repeatable processes with nameable required information, not judgment calls.
  3. Every use case needs a defined conversation goal, fixed required fields, permitted statements and clear escalation rules.
  4. The caller must learn at the outset that they are speaking with an AI system, and must be able to reach a human at any time.
  5. The voice is not proof of identity. Disclosing personal data requires an additional check.
  6. Permanent call recording is not a default but a decision that must be justified.
  7. Write actions in connected systems require validation, confirmation and an audit-proof log.
  8. The works council must, as a rule, be involved in the rollout. That belongs in the schedule, not the retrospective.
  9. A business case built on the per-minute price is not a business case. What counts is additional answered calls, reduced follow-up work and avoided misroutes.
  10. Quality is measurable. Without metrics, judging a solution comes down to taste.

The one question before you start

Take a typical call and describe it through to the end: who handles the request, with which information, in which system, within which deadline? If that question cannot be answered in a few sentences within the company, AI telephony will not solve the problem – it will only make it visible faster.

KrambergAI GmbH · krambergai.com3
KrambergAI01 · Starting point
Chapter 01

The starting point: why the phone endures

Despite portals, forms and messaging apps, the phone remains the first channel for many SMEs when things get urgent. And that is exactly where it meets teams that are already stretched.

Customers report faults, ask about appointments, need information or want to discuss a job. They pick up the receiver because the request rarely fits into a form field, because they want a firm answer, or simply because they know the call works. This is especially true in the skilled trades, in technical service and in project business – wherever customers have a problem rather than an order to place.

On the other end there is rarely a dedicated call center. Reception, the back office, dispatch and customer service handle the phone on the side. Someone in the middle of costing a job, writing an invoice or briefing a field technician either does not pick up at all or picks up under pressure. Both have consequences.

What the missed call actually costs

The lost call is the obvious damage, but not the most expensive. More costly are the knock-on effects that hardly anyone in the business traces back to a single cause:

Where AI telephony comes in

An AI voice assistant answers calls, understands the request, asks for the missing details and transfers the information into a defined business process. Depending on the use case, it prepares callbacks, coordinates appointments, creates service tickets or hands the call to a member of staff in a targeted way – complete with a summary of what has already been discussed.

The decisive difference from older voice systems is not audio quality. It is that such an assistant can classify freely phrased requests, ask targeted follow-up questions and pass the result on in a structured form. A call becomes a record that a member of staff can work with straight away.

The honest starting point

Before any technology comes into play, look at the phone system: how many calls come in each day? How many go unanswered, and at what times? How long is an average call? How many calls concern the same five requests? These four figures decide the value of a solution more than any vendor promise.

AI Telephony for SMEs · A Practical Guide4
KrambergAI02 · Terms
Chapter 02

Terms: phone menu, voicebot, AI voice assistant

Three technologies are sold in the market under the same buzzword. They differ fundamentally in what they can do, what they cost and what preparation they demand.

FeaturePhone menu (IVR)Rule-based voicebotAI voice assistant
InputKey press, fixed keywordsPredefined answer optionsFreely phrased speech
DialogueRigid treePredefined pathsTargeted follow-ups, topic changes possible
UnderstandingNoneIntent recognition with trained categoriesClassification even with unfamiliar phrasing
ResultTransferTransfer, simple data captureStructured record, system action, handover with context
EffortLowMedium, high maintenance per categoryMedium to high, focused on process and integration
RiskCaller hangs upBot fails to grasp deviationsFree phrasing can lead to false statements unless constrained

Why the distinction matters in practice

A phone menu is not inherently bad. For a company with three clearly separated departments and low call volume, it can be the most economical solution. The mistake arises where it is meant to take on tasks it was never built for: capturing requests, asking follow-up questions, judging urgency.

The rule-based voicebot partly solves this, but every phrasing variant must be anticipated in advance. That produces a maintenance burden which grows with each use case and eventually finds no one willing to carry it.

The AI voice assistant built on large language models reverses this: it also understands what no one wrote down beforehand. That strength is also its risk – a model allowed to phrase freely will phrase freely even when it does not know the answer. Hence the principle running through this whitepaper:

Free in tone, bound on substance

The AI may phrase things clearly and naturally. What it may say and do on substance must come from verified data sources and defined rules, not from the language model itself. Binding statements on prices, appointments, deadlines or contract terms come from the system, not the model’s memory.

A fourth term: the voice agent

The term voice agent is increasingly common. It refers to an AI voice assistant that carries out several steps on its own: look up, check, book, notify. Technically it is the same category, and the most demanding one. The more a system may decide for itself, the more precise its permissions, checks and logs must be. A voice agent with write access across several systems is the wrong place to start.

AI Telephony for SMEs · A Practical Guide5
KrambergAI03 · Capabilities
Chapter 03

What AI telephony can do

A good AI telephony solution is more than a digital answering machine. It does not merely record messages; it guides conversations in a structured way and prepares a concrete next step.

Availability

  • Answer calls outside business hours
  • Absorb call peaks without anyone waiting
  • Handle several calls at once
  • Pre-qualify calls in the on-call context

Capture

  • Record callback requests in full
  • Categorize requests automatically
  • Ask for customer data and case numbers
  • Take fault reports in a structured way

Action

  • Request, check or book appointments
  • Create service tickets or CRM tasks
  • Send confirmations by email or SMS
  • Escalate by rule

Handover

  • Route to the right department
  • Provide a conversation summary
  • Give standard information on services and processes
  • Offer alternative contact routes

The value is not in the voice

It is tempting to judge an AI telephony solution by how natural its speech output sounds. In a vendor demo that is the most striking difference. In operation it is the least important one.

The decisive value comes from the combination of four things: telephony, conversation logic, company knowledge and existing business systems. If one of these is missing, the rest is ineffective. A perfect voice that cannot get an appointment into the calendar has not improved the process. It has extended it by one step.

A test for every demonstration. Do not ask, “How does this sound?” Ask, “Show me the record that ends up in my system after this call.” If there is no answer to that, the solution is not ready yet – no matter how good it sounds.

What is realistic today

A well-configured assistant holds a natural conversation with pauses, follow-up questions and the option to interrupt it. It copes with background noise, mobile-network quality and regional accents. It usually understands names and addresses, but confuses similar-sounding letters and therefore has to confirm them back. It keeps a latency that does not make the dialogue unpleasant.

What it cannot do: reliably read irony, infer a fact from a tone of voice, or capture a request for which it lacks the underlying data. Those who account for these limits in the conversation design get a dependable system. Those who ignore them produce calls that annoy the caller.

AI Telephony for SMEs · A Practical Guide6
KrambergAI04 · Structured capture
Chapter 04

Why the answering machine no longer suffices

An answering machine leaves it to the caller to state all the important information. That works for people who are practiced at it. For everyone else, gaps appear that someone has to close afterwards.

In practice, customer numbers, locations, callback times, equipment names or details of urgency are therefore regularly missing. The message then reads: “This is Mr. Schuster, please call me back.” Whether it concerns maintenance, a complaint or an emergency stays open until someone calls back.

The difference is the follow-up question

An AI voice assistant can ask targeted questions, in the order the process needs:

Who and how to reach them

  • What is your name?
  • On which number can we reach you?
  • When would a callback suit you?
  • Is there already a case number?

What and how urgent

  • Which location does this concern?
  • Which piece of equipment is affected?
  • Since when has the fault existed?
  • Is there an outage or a restriction?

This produces structured records instead of incomplete voicemails. Staff can respond faster and have to chase fewer details afterwards. The callback no longer begins with “What was it about again?” but with an answer.

Two side effects that are often overlooked

Prioritization becomes possible. Once urgency, location and equipment type are captured, the callback list can be sorted. Twelve equivalent slips become an order of work. On an on-call evening, that is the difference between a calm shift and a hectic one.

Data quality rises measurably. An assistant that repeats and confirms the callback number produces fewer undeliverable callbacks than a voicemail in which the number was mumbled once. It is unspectacular and, in day-to-day work, one of the most noticeable effects.

The test for required information

Define per use case which details are strictly necessary so that a member of staff can carry on without a follow-up call. Anything beyond that is optional. An assistant that asks for ten required fields lengthens the call and raises the drop-off rate. Four to six well-chosen fields carry the process in most cases.

AI Telephony for SMEs · A Practical Guide7
KrambergAI05 · Use cases
Chapter 05

Suitable inbound use cases

The best entry point is not to automate every call at once. It makes more sense to take one clearly bounded use case with low risk and measurable value.

Structured call answering

The assistant captures name, phone number, request, customer number and preferred callback time, then creates a task or a call note. It makes no decision and gives no information. That makes this the lowest-risk entry point of all: even if the assistant misunderstands something, a human checks the result before anyone acts.

Low riskValue measurable quicklyNo write access needed

Appointment requests

The system determines the type of appointment, the location and availability. Depending on the permissions granted, it can propose, reserve or directly book a slot. The three levels differ considerably in risk: a proposal is harmless, a reservation blocks capacity, and a booking creates an expectation for the customer and in the schedule. Start with the proposal and work your way up.

Medium riskCalendar integration required

Fault reports

The AI asks for the equipment, location, symptom, time and impact. Critical cases are escalated by defined rules. Here the escalation logic is the actual core: what counts as critical? Who is informed, and when? What happens if no one answers? These questions must be answered before the first call, not after the first incident.

Medium to high riskEscalation chain mandatory

Smart routing

Callers are directed by their request to the responsible department, location or on-call service. The advantage over a phone menu is that the caller can state their request in their own words instead of working through seven options. The prerequisite is a clean responsibility matrix – and the willingness to keep it up to date.

Low riskImmediately noticeable to callers

Status enquiries

After a suitable identity check, the assistant can provide released information on orders, deliveries, appointments or service cases. The critical point sits in the first half-sentence: without a reliable identity check, no personal information may be disclosed. Chapters 12 and 16 cover this in detail.

High risk without identity checkRead access to the specialist system

AI Telephony for SMEs · A Practical Guide8
KrambergAI05 · Use cases

Suitability check: does the use case fit?

The matrix below helps to classify a candidate before any effort is spent. The more answers fall in the left-hand column, the more suitable the case is as a starting point.

CriterionWell suitedUnsuitable or later
FrequencySeveral times a day, recurringOne-offs, seasonal outliers
ProcessRepeatable and describableEvery conversation runs differently
Required informationClearly nameable, four to six fieldsOnly emerges during the call
DecisionRule-based or deferredRequires judgment and experience
Data sourceAvailable, maintained, reachable via interfaceScattered, outdated, only accessible by hand
ResponsibilityClearly settledNegotiated case by case
Consequence of errorCorrectable, a human checksImmediate external effect
Emotional stateFactual, information-drivenComplaint, conflict, emergency
MeasurabilityBefore/after comparison possibleNo baseline available

The typical fallacy

Many companies choose as their first use case the one that costs the most time. That is understandable and usually wrong. The most time-consuming call is, as a rule, also the most complex, the most emotional and the one with the most exceptions. It is the worst candidate for a start – not because it could not be automated, but because with it everything can go wrong at once and no one can say what caused it.

Choose instead the case that is frequent, dull and easy to describe. It brings less spectacular figures, but it delivers something more valuable: a working path from the phone system into the target system, on which everything else can be built.

A proven starting point

Calls outside business hours with structured callback capture. The benchmark is the answering machine or the dial tone – both a low bar. There is no risk that a customer receives information they should not. And the effect is immediately visible the next morning: complete cases instead of guesswork.

On the demands placed on your data. An assistant can only be as capable of giving information as the systems behind it. If the order status in the ERP is only correct after the evening batch run, the assistant must not give any binding information on it during the day. Such limitations belong in the documentation before a customer discovers them.

AI Telephony for SMEs · A Practical Guide9
KrambergAI06 · Outbound
Chapter 06

Outbound calling and its legal limits

On paper, outbound calls look like the logical extension. Legally they are a different matter – and the area in which companies get into trouble fastest with AI telephony.

The decisive difference from inbound

With an incoming call, the caller chose to make contact. With an outgoing call, the company decides, and the person called has to put up with the contact. German competition law draws clear consequences from this.

Advertising calls: Section 7 UWG

Telephone advertising to consumers is prohibited without their prior express consent. Toward other market participants, presumed consent is sufficient, but it may not simply be assumed; it must follow from the context. Consent must be documented and retained. Breaches can be subject to warning letters from competitors and associations and to fines from the Federal Network Agency. Using an AI system changes nothing about this legal position – it merely lowers the threshold to call many numbers.

What is unproblematic in outbound

Not every outgoing call is advertising. Permissible and practically useful are, in particular, calls that concern an existing case and that the customer expects:

The line is crossed where the confirmation of an appointment becomes a pointer to a further offer. That one sentence turns a service call into an advertising call.

Further points to settle for outbound

Recommendation. Do not start with outbound. In SMEs the benefit is usually smaller than for inbound, the required legal scrutiny considerably higher, and the reputational damage from a mistake immediate. If outbound at all, then first for appointment reminders on existing jobs – a case that serves customers and reduces no-shows on visits.

AI Telephony for SMEs · A Practical Guide10
KrambergAI07 · Limits
Chapter 07

Where automation has to stop

Not every conversation should be completed by an AI. A responsibly designed assistant recognizes its limits and actively steps aside.

With complaints, contract questions, binding price commitments, payment details, safety-critical situations or complex professional decisions, a member of staff must be involved – not because the technology could not, but because the consequences of a mistake outweigh the time saved.

The reasons to hand over

An assistant offers the handover when one of the following applies. This list belongs in the configuration as rules, not in the presentation as an intention:

The emergency is not a use case

An AI voice assistant is not an emergency system and must never behave like one. When a request reveals immediate danger to persons, the answer must open with a pointer to the emergency number and an immediate handover – not with the next required question. This rule takes precedence over all others and must be explicitly tested.

What happens when no one is there

The handover assumes a human is reachable. At 10 pm that is often not the case. For that there must be a defined, honest fallback path:

The principle

AI telephony should not hide staff; it should ensure they enter the conversation with the right information. A system that blocks the way to a human may improve the statistics short term while damaging the customer relationship exactly where it should be dependable.

A test for every acceptance. Call in and say in the first sentence: “I would like to speak to a human.” What happens next says more than any feature list. If the assistant argues, deflects or first wants the customer number, the configuration is wrong.

AI Telephony for SMEs · A Practical Guide11
KrambergAI08 · Business process
Chapter 08

The business process decides success

A natural dialogue alone is not enough. The company has to define what happens after a call. This chapter describes the minimum that must be set down in writing for that.

The ten definitions per use case

1. Goal of the conversation
What is achieved at the end? One sentence. Example: “A complete callback task sits in the CRM, assigned to a department.”
2. Required information
Which fields must be filled so a member of staff can work without a follow-up call? What happens if one stays empty?
3. Permitted statements
What may the assistant say on substance? Prices, deadlines, commitments and legally relevant statements usually are not among them.
4. Data sources used
Where does each piece of information come from? How current is it? What applies if it is unreachable?
5. Permitted system actions
Read, write, change, delete – separated by system and use case. When in doubt, less.
6. Responsible department
Who handles the result? Who deputizes during absences?
7. Escalation rules
Which features trigger an escalation, to whom, by when, with what fallback level?
8. Human control points
At which point does a human check – before or after the action, a sample or in full?
9. Documentation requirements
What is logged, kept for how long, viewable by whom?
10. Quality metrics
How is it measured whether the case works? Which value triggers a correction?

Free to phrase, bound to decide

The AI may phrase things flexibly and clearly. Binding decisions, however, should be made against clear rules. Whether a case counts as critical is not decided by the language model but by a rule that someone wrote down, checked and approved. This separation is the single most important design principle of a dependable solution.

Why this work must come first

The ten definitions look like bureaucracy and are the opposite of it. They are the part of the project someone has to do anyway – at the table beforehand or later, under pressure, in live operation. Clearing it up in advance costs two workshops; clearing it up afterwards costs conversation quality every day.

In practice, this preparatory work is the real value of an AI telephony project. Companies often find that responsibilities are unclear, that three departments answer the same question differently, or that a process has only worked because one person keeps it in their head. These findings are uncomfortable and valuable, whether or not an assistant is introduced in the end.

AI Telephony for SMEs · A Practical Guide12
KrambergAI09 · Architecture
Chapter 09

Technical architecture

An AI telephony solution consists of several building blocks that can be procured individually. Those who understand how they interact can compare offers and assess failure scenarios.

The chain from ring to answer

Building blockTaskWhat to watch for
Telephony connectionAnswers the call, usually via a SIP trunk or a link to the phone systemNumber portability, encryption, behavior under load, fallback to the old diversion
Speech recognitionConverts spoken words into textAccents, background noise, mobile quality; recognition of numbers, names and addresses
Dialogue controlGuides the conversation, holds the state, decides the next stepSeparation of phrasing and decision, traceability, testability
Language modelUnderstands the request, phrases answersPlace of processing, use for training, version changes, behavior when knowledge is missing
Specialist data accessProvides verified information from CRM, ERP, calendar, knowledge basePermissions on the least-privilege principle, response times, behavior when unreachable
Speech outputProduces the audible answerIntelligibility over naturalness, correct pronunciation of technical terms and proper names
LoggingDocuments the course, decisions and system actionsWhat exactly is stored, for how long, viewable by whom

Latency: the underrated factor

Every building block costs time: recognition, understanding, data retrieval, phrasing and output add up. Above roughly one second the conversation feels sluggish; beyond about two seconds, callers talk into the pause or ask whether anyone is still there.

The most common driver of latency in SME projects is not the language model but data retrieval from a legacy system. If the ERP customer lookup takes three seconds, the caller notices. Two remedies work: an intermediate data store for read access, or a conversation designed to fill the wait, for instance by confirming the details already captured.

Barge-in

An assistant you cannot interrupt feels rude. The ability to react to a caller speaking over it and to cut off its own output makes a big difference in daily use and is rarely shown in demos. Ask about it explicitly and try it.

A word on voice quality. Cloning a real voice – the managing director’s, say – is technically possible but not advisable. The benefit is small, the irritation considerable, and its lawfulness depends on the consent of the person concerned. A neutral, clearly intelligible voice that is recognizably synthetic serves better.

AI Telephony for SMEs · A Practical Guide13
KrambergAI09 · Architecture

Resilience: what happens when something fails

A phone line is part of a company’s reachability. It must not depend on every component being available at all times. For each failure there must be a defined response.

FailureExpected behavior
Language model unreachableFall back to simple capture behavior or a direct transfer; no invented answers
CRM or ERP unreachableContinue the conversation, buffer the details, post them afterwards; no answers from memory
Calendar unreachableDo not book the appointment; capture it as a request and promise a callback
Entire platform downAutomatic call diversion to the previous target number or an announcement with an alternative contact route
Call volume over capacityA defined ceiling with a waiting announcement instead of uncontrolled degradation
Model version changesRegression test before activation; a return to the previous version must be possible

The fallback path is not a detail

Agree contractually that, in the event of a failure, the phone number is diverted within a defined deadline to a target number you specify – and test this path at least once under real conditions before going live. A fallback path that has never been tried is an assumption.

Operating models compared

ModelAdvantageDisadvantageSuits
All-in-one platformQuick to launch, one contact, predictable costsDependence on the vendor, limited adaptability, data flows through a third partyStandard cases, a first pilot, a small IT team
Platform with your own logicProcesses freely designed, data sovereignty over the specialist dataRequires your own development and maintenanceBespoke processes, existing IT capability
Self-hostingFull control over data and processingHigh effort for operation, availability and updatesSpecial protection needs, existing operations

For most SMEs the middle path is the right one: a platform for telephony and speech processing, connected to process logic and data access that the company controls itself. This keeps a change of platform vendor possible without rebuilding the entire specialist logic.

A question of lock-in. Before signing, clarify: who owns the conversation data, the dialogue configuration and the analytics? In what format do you receive them if you terminate? How long does number porting take? A vendor who will not answer these questions in writing will not answer them later at all.

AI Telephony for SMEs · A Practical Guide14
KrambergAI10 · Integration
Chapter 10

Integration with existing systems

The financial value rises when the captured information does not have to be transferred by hand. This is precisely where it is decided whether a project saves time or merely shifts it.

Typical integrations

Customer and case

  • CRM systems
  • ERP systems
  • Order management
  • Document management

Service and dispatch

  • Ticket systems
  • Field-service systems
  • On-call scheduling
  • Calendar

Notification

  • Email
  • SMS services
  • Team messaging
  • Phone system

Integration usually takes place through defined programming interfaces. With them the voice assistant can search for customer data, check appointments, create tickets or store conversation results.

Reading is not writing

The most important distinction in the whole integration topic is between read and write access. A read error produces a wrong piece of information that is noticed and can be corrected. A write error changes the data and keeps having an effect, often unnoticed.

Write actions such as appointment bookings or ticket changes therefore need additional checks, confirmations and logs:

Least privilege for permissions

The assistant should only be able to access data and functions that are necessary for its specific purpose. In practice this principle is often violated because an existing technical account with broad rights is the quickest route. That is convenient and creates a risk that no one wants to roll back later.

Instead, set up a dedicated technical account for each use case with exactly the rights needed. The callback assistant needs no access to prices. The appointment assistant needs no access to open items.

The data-quality problem is exposed, not created

When the assistant cannot find a customer, it is rarely the assistant’s fault. It is three records for the same company, phone numbers in five spellings, and locations that are named differently in the ERP than by the customer. AI telephony exposes this legacy debt. Plan time for it – and treat it as a gain, not a project delay.

AI Telephony for SMEs · A Practical Guide15
KrambergAI11 · Conversation design
Chapter 11

Conversation design and the human handover

Conversation design decides whether a caller experiences the call as helpful or as an obstacle. It is craft, not gut feeling.

The structure of a dependable conversation

  1. Greeting with transparencyCompany, a note that this is an AI system, and the purpose – one sentence. Example: “This is the digital assistant of Müller Ltd. I take down your request and pass it on.”
  2. Open opening question“What can I help you with?” rather than a list of options. The caller answers in their own words.
  3. Classification and targeted follow-upAsk only for the details the process needs. Every extra question lengthens the call and raises drop-off.
  4. Confirmation of critical valuesRepeat and confirm phone numbers, customer numbers, appointments and addresses – the values that break the process if wrong.
  5. Announcement of the action“I’ll create a ticket, and the technical team will get in touch by noon tomorrow.” The caller knows what happens, and by when.
  6. Close with a way outWhat to do if the callback does not come? A concrete pointer, not a platitude

Principles of phrasing

Proven

  • Short sentences, one thought per sentence
  • One question at a time
  • Concrete times instead of “shortly”
  • Admitting when something is not known
  • Polite, factual, professional

Avoid

  • Forced casualness and small talk
  • Several questions in one sentence
  • Claims without a data basis
  • Loops of apology for misunderstandings
  • Faked humanity

The handover: the moment everything is decided

A handover succeeds when the caller need not repeat their request. The member of staff needs three things on screen before accepting: who is calling, what it is about, and what the assistant has captured or promised. In a warm handover the caller stays on the line while the summary arrives; in a cold handover the call is passed on and the summary follows. The warm variant is more pleasant and more demanding technically. Where it is not possible, the summary should at least reach the member of staff before the phone rings.

The summary is a working document

A good summary is short, structured and free of interpretation. It states the request, the required information, the next step promised and – most important – the points on which the assistant was unsure. A note like “customer number uncertain” helps more than three paragraphs of prose.

Design for accessibility

Not every caller speaks clearly, quickly or in the local language. An assistant that aborts at the first uncertainty shuts people out. What helps: a second attempt with simpler phrasing, a longer answer window, a clear route to a human and, where warranted, a second language.

AI Telephony for SMEs · A Practical Guide16
KrambergAI12 · Data protection
Chapter 12

Data protection under the GDPR

Phone calls regularly contain personal data: name, phone number, voice, customer number, location or details of a specific request. Data protection is therefore not an appendix but part of the design.

The questions that must be answered before deployment

Determining the legal basis

Every processing operation needs a legal basis under Article 6 GDPR. For AI telephony, three come into practical consideration, and they are not freely interchangeable:

BasisTypical caseLimit
Contract
Art. 6(1)(b)
The call concerns an existing job or its initiationDoes not cover analytics beyond performing the contract
Legitimate interest
Art. 6(1)(f)
Efficient handling of incoming calls, routing, reachabilityRequires a documented balancing test; does not cover permanent recording
Consent
Art. 6(1)(a)
Call recording, quality review based on recordingsMust be freely given, informed and revocable; a “no” must have no consequences

Practical note. Consent given on the phone by continuing to listen (“by continuing, you agree”) is not valid consent if there is no equivalent alternative. Anyone who declines the recording must still be able to bring their request forward – by the same route, not with substantial extra effort.

Data processing and place of processing

Platform providers, speech-service providers and model operators are, as a rule, processors under Article 28 GDPR. What is required is a data processing agreement, an overview of sub-processors and a provision for how you are informed when they change.

The place of processing is one of the few questions that demands a clear answer. Does the processing take place exclusively within the EU? If data reaches third countries: on what basis, with what additional measures? A vendor who answers this question with a general assurance of security has not answered it.

AI Telephony for SMEs · A Practical Guide17
KrambergAI12 · Data protection

Data protection impact assessment

A data protection impact assessment under Article 35 GDPR is required where a processing operation is likely to result in a high risk to the rights of data subjects. With AI telephony there are good reasons to consider this seriously – particularly where voice recordings are processed, transcripts stored or conversation content systematically analyzed.

Even where there is no obligation, a documented threshold assessment is worthwhile. It costs little and later answers the supervisory authority’s question of why you reached your conclusion. The list of processing activities for which an impact assessment is mandatory is published by the German supervisory authorities; a look at the list of the authority responsible for your federal state belongs in the preparation.

Implementing data-subject rights in practice

Access, rectification and erasure must also work for conversation data. That sounds self-evident and, in practice, fails on a simple question: where exactly is what?

RightWhat this means in concrete terms
Access
Art. 15
You must be able to say what conversation data on a person exists – including data held by the platform provider. That assumes conversations can be assigned to a person without you having to listen through every recording.
Rectification
Art. 16
A misheard name in the CRM must be correctable. This concerns the record, not the transcript – a transcript reflects what was said.
Erasure
Art. 17
Erasure must cover all storage locations: platform, logs, backups, target systems. Clarify in advance how the vendor implements this and how long backups are kept.
Objection
Art. 21
Anyone who objects to processing by the AI system must have an equivalent route to a human.

Setting retention periods

Set a period for each type of data and justify it. A proven pattern, to be checked in each case:

The voice is not an ID

A caller’s voice is not reliable proof of identity. It can be imitated and today reproduced technically with little effort. Sensitive information and changes therefore need additional checks – such as a question about features of the case, a callback to the number on file, or confirmation via a second channel. Where this check is not possible, the information does not belong in the automated part.

On model training. Clarify in writing whether conversation data is used to improve the vendor’s models. A phrase such as “to improve our services” is too vague. What is needed is an unambiguous statement with an opt-out – and confirmation that it also applies to sub-processors.

AI Telephony for SMEs · A Practical Guide18
KrambergAI13 · Recording
Chapter 13

Recording, transcripts and confidentiality

Whether conversations are recorded is often decided in passing during projects – usually in favor of recording, because it is delivered as a technical feature. That is the wrong way round.

Recording is the exception, not the default

Permanent call recording should not be enabled automatically. It requires a defined purpose, a legal basis and, as a rule, valid consent from both sides. In Germany, secretly recording the non-public spoken word is a criminal offense (Section 201 of the Criminal Code) – aimed at individuals, not companies, but a sign of the weight the spoken word carries.

Often it is enough to process speech only during the call and store structured results – sufficient for the process, simpler for data protection and far less intrusive for the caller.

Three storage levels compared

LevelWhat is storedBenefitEffort and risk
ResultStructured record: request, required information, actionCarries the business processLow; like a regular call note
Result + transcriptPlus the conversation textError analysis, dialogue improvement, evidence in disputesMedium; holds everything the caller mentioned in passing
Result + audioPlus the voice recordingAnalysis of recognition errors and voice qualityHigh; x

For most SME use cases the first level suffices in regular operation. The second is useful in the pilot phase and should then be time-limited or switched off. The third requires explicit justification.

The overlooked side effect of transcripts

A transcript contains everything that was said, including what no one meant to capture – an illness mentioned, a remark about a colleague, a private aside. This data then sits in your system, is subject to access requests and must be protected. Anyone storing transcripts should be able to justify it, not merely point to the platform.

What to clarify in any case

Recommendation. Start without audio recording. If you need transcripts for error analysis in the pilot phase, limit them to the pilot duration and define beforehand who may view them. The decision can be broadened later, but is harder to reverse once operations are used to it.

AI Telephony for SMEs · A Practical Guide19
KrambergAI14 · EU AI Act
Chapter 14

EU AI Act: transparency duty from 2 August 2026

For AI telephony, the EU AI Act is not a future topic. The duty to inform callers about the use of AI becomes applicable on 2 August 2026 – and it was not postponed by the political debate around the Digital Omnibus.

What Article 50 requires

Article 50 of the AI Act (Regulation (EU) 2024/1689) sets out transparency duties that apply regardless of a system’s risk class. An AI voice assistant is, as a rule, not a high-risk system – and is nonetheless covered by Article 50. For telephony, paragraph 1 is chiefly relevant: AI systems intended for direct interaction with people must be designed so that the person concerned recognizes that they are interacting with an AI system. An exception applies only where this is obvious from the circumstances anyway – which is not something to rely on with a naturally sounding phone assistant.

The timeline, in brief

  • Since 2 February 2025: Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among their own staff and contractors.
  • From 2 August 2026: the transparency duties under Article 50(1), (3) and (4) become applicable. From that date, penalties are also possible.
  • Postponed: the Digital Omnibus moves the obligations for high-risk systems under Annex III to 2 December 2027 and under Annex I to 2 August 2028. The marking duty for synthetic content under Article 50(2) receives a transitional period until 2 December 2026 for systems already on the market.
  • Not postponed: the disclosure duty under Article 50(1) – that is, precisely the duty that counts for phone assistants.

On the procedural status. The Digital Omnibus amendments rest on a provisional agreement between Council and Parliament of 7 May 2026; Parliament gave its approval on 16 June 2026. Formal adoption by the Council and publication in the Official Journal were still outstanding at editorial close. Until then, the 2024 version applies. The deadline for Article 50(1) is unaffected by all of this.

Provider or deployer – or both

The duties are distributed differently. Whoever buys a phone assistant as a finished product and uses it is a deployer. Whoever offers the solution under their own name, substantially modifies it or changes its purpose can become a provider – with far more extensive duties. For SMEs the standard case is the deployer role. The classification should nonetheless be documented, because it determines the set of duties.

Penalties

Breaches of Article 50 fall under Article 99 of the Regulation. The range is up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. Small and medium-sized enterprises receive special consideration in setting the amount. In Germany, the Federal Network Agency is to become the responsible market surveillance authority.

AI Telephony for SMEs · A Practical Guide20
KrambergAI14 · EU AI Act

What this means for the announcement

The caller should learn at the start of the conversation, clearly and understandably, that they are speaking with an AI system. The notice must not be hidden inside a long greeting. It should also explain what task the assistant performs and how, if needed, a human contact or an alternative route can be reached.

Sound

“Hello, this is the digital assistant of Müller Ltd. I am an AI system and I take down your request. If you would rather speak with a member of staff, just say so.”

Clear, early, names the function and the way out.

Not sound

“Hello and a warm welcome to Müller Ltd, your partner for building technology since 1987. So that we can advise you as well as possible, we use modern technologies. How can I help you?”

“Modern technologies” is not disclosure. The notice is effectively missing.

For many companies the notice feels like a disadvantage. Experience suggests otherwise: callers who know from the start whom they are dealing with phrase things more clearly and briefly and are more forgiving of a misunderstanding. Deceived callers are not – and they almost always notice.

AI literacy under Article 4

Since 2 February 2025, providers and deployers must, to the best of their ability, ensure that their staff and contractors have sufficient AI literacy – measured against their role, their prior knowledge and the context of use. For AI telephony this means, concretely: anyone taking over conversations that an assistant has prepared must understand what the system can do, where it makes mistakes and how to spot a wrong result. A two-hour session with the affected teams and a short record usually meet this requirement better than an online course with no bearing on your own process.

Implementation in five steps

  1. InventoryWhich AI systems are in use or planned? The phone assistant is rarely the only one.
  2. Role clarificationAre you a deployer, a provider or both? Document the classification with reasons.
  3. Technical implementationAdd the disclosure to the greeting, anchor it in the conversation design, test it.
  4. Contracts and governanceReview vendor contracts: who fulfills which duty? Name the responsible person in the company.
  5. Documentation and trainingMake what you have done demonstrable. In case of doubt, what is written down counts.

For context. For an SME with one phone assistant in the callback process, the effort is manageable: a correct announcement, a documented role classification, a short training of the affected teams. The effort grows with what the assistant is allowed to decide itself. This can only be assessed as legally binding in the specific case – this section does not replace legal advice.

AI Telephony for SMEs · A Practical Guide21
KrambergAI15 · Co-determination
Chapter 15

Co-determination and employee data protection

This chapter is regularly overlooked in projects – and it is the most common reason why a finished system is not allowed to go live.

Why the works council must be involved

Where a works council exists, it has a co-determination right under Section 87(1) no. 6 of the Works Constitution Act on the introduction and use of technical devices designed to monitor the conduct or performance of employees. Case law reads this broadly: it is enough that the device is objectively suitable for monitoring. No intention need be present.

An AI voice assistant is regularly suitable for this. It records when a handover occurs, who accepts it, how long the follow-up conversation lasts and whether a callback was made within the promised deadline. Whether you want to analyze this data is irrelevant. What matters is that you could.

The practical advice

Bring the works council into the concept phase, not the acceptance stage. A body consulted before the selection asks different questions than one presented with a finished system. The time saved is considerable, and the questions are often professionally justified.

What belongs in a works agreement

Handling concern within the team

The question “Does this replace me?” is in the room whether asked or not. It is answered not by a presentation but by what the system does. Where an assistant makes the callback list complete and the on-call evening calmer, that speaks for itself. Where it arrives while jobs are being discussed, no communication measure helps.

It has proven effective to involve the staff who answer the calls today in the conversation design. They know which follow-up questions clarify a request, which phrasings customers use and where the exceptions lurk. That knowledge is the best basis for the configuration, and their involvement takes much of the sting out of the rollout.

Relevant even without a works council. Where no works council exists, co-determination does not apply, but employee data protection does. Data about the work of employees is subject to the GDPR and Section 26 of the Federal Data Protection Act. A documented purpose limitation makes sense in that case too – and it protects the company as much as the employees.

AI Telephony for SMEs · A Practical Guide22
KrambergAI16 · Security
Chapter 16

Information security and permissions

A phone assistant with access to specialist systems is an entry point into the company. It deserves the same attention as any other entry point – and it has one peculiarity the others do not: anyone can call it.

The particular attack surface

A language model processes what the caller says, which makes the caller an untrusted input source. This creates risks that classic systems do not have:

The countermeasures

MeasureImplementation
Rights per use caseA dedicated account per case, only the required fields and functions, read separated from write
Allow list, not block listThe assistant may perform defined actions; everything else is excluded by the absence of permission, not by instruction
Identity check before disclosureA callback to the number on file, a second channel, or a question about non-public features. No information on say-so alone
Rate limitsA cap on actions per conversation and per number, and on concurrent conversations
Detecting anomaliesAn alert on unusual patterns: the same number repeatedly, atypical times, clustered information requests
Logging and reviewEvery action traceably tied to its conversation, reviewed regularly
Kill switchA named person can shut it down at any time; the diversion takes effect automatically

The design principle

Never rely on a language model to keep to an instruction. System-prompt instructions are behavior steering, not a security boundary. Security exists where an action is technically impossible: missing rights, an upstream check, a hard limit in the target system. What the assistant must never do, it must not be able to do.

Fit into existing structures. Include the assistant in your record of processing activities, your incident response plan and, if you have one, your information security management. It is a productive system with external contact, not a marginal tool.

AI Telephony for SMEs · A Practical Guide23
KrambergAI17 · Quality
Chapter 17

Measuring quality: metrics and error classes

Without metrics, judging a phone assistant comes down to taste. And matters of taste, in a company, are decided by the person who is loudest in their dissatisfaction.

The metrics that carry

MetricWhat it measuresWhat to watch for
Answer rateShare of calls that are answered at allThe only figure directly comparable before and after the rollout
Completion rateShare of conversations that reach the defined goalMust be measured per use case, not overall
Handover rateShare of conversations passed to a humanA low rate is not the goal. A high rate at the caller’s request is correct
CompletenessShare of cases with all required informationThe best single indicator of downstream value
Rework rateShare of cases where a member of staff has to follow upShows whether the time saving is real or merely shifted
Drop-off rateShare of callers who hang upAnalyze by conversation phase. Drop-offs during the greeting have different causes than during data capture
Misroute rateShare of transfers into the wrong departmentOnly measurable if staff can report misroutes – with one click, not a form
On-time callback rateShare of promised callbacks that were keptMeasures the process, not the assistant – and is important for exactly that reason
Response timeDelay between the caller’s and the system’s turnDo not view it as an average; look at the slowest five percent

The metric that misleads

The most common figure in the market is the share of conversations that end without a member of staff. It is easy to increase: make it harder for the caller to reach a human. The figure rises, customer satisfaction falls, and both look like success in the report. Measure instead whether the request was handled – not whether the assistant was left on its own.

The baseline decides

Every metric needs a comparison value from before the rollout. These values cannot be determined after the launch. Take two weeks for a measurement of the current state: call volume by hour, answer rate, average call duration, share of incomplete callback notes. Without this baseline you will not be able to prove the value – neither to management nor to yourself.

AI Telephony for SMEs · A Practical Guide24
KrambergAI17 · Quality

Error classes: not every error is equal

A shared language for errors is the prerequisite for making improvement plannable. Without it, the feedback from operations reads “the thing doesn’t work” and no one knows where to start.

ClassDescriptionExampleWhere to act
A – CriticalA wrong binding statement or a wrong system action with external effectAn appointment confirmed that does not exist; information given to an unauthorized personSwitch off immediately, clarify the cause, reactivate only afterwards
B – Process errorA case ends up wrong or incomplete in the systemA ticket in the wrong department; a required field emptyRevise the rules and required fields
C – Understanding errorThe request is misclassified, a detail misheard“Maintenance” captured as “fault”; a digit in the number transposedAdd confirmation, sharpen phrasing
D – Dialogue errorThe conversation goes in circles, feels unnatural, the caller hangs upThe same follow-up three times; no reaction to an interruptionAdjust the conversation design and abort rules
E – TechnicalOutage, delay, dropped connectionAn interface does not answer; latency over four secondsOperations, fallback paths, capacity

A Class A error is not a learning opportunity

For Class A errors there is no tolerance threshold and no quota. They lead to the immediate shutdown of the affected use case until the cause is understood and fixed. This rule belongs in writing before going live – with a named person allowed to apply it without consultation. Anyone who first discusses it in an emergency discusses it for too long.

How the review works in practice

  1. Weekly in the pilot phaseOne hour, fixed participants: department, IT, process owner. Go through ten conversations from the sample, classify errors, derive three actions.
  2. Monthly in regular operationLook at the metrics, check outliers, bundle adjustments. Do not tinker with the dialogue every week – that produces instability.
  3. On every changeA regression test with a fixed set of test conversations. A set of twenty calls covering all use cases and the critical edge cases is enough for an SME.
  4. Feedback from operationsA way for staff to flag a poor conversation – without a form, without having to justify it. These reports are the most valuable input you will get.

On expectations. An assistant is worse in the first few weeks than the demonstration suggested. That is normal: the demonstration ran with good audio, clear speech and no edge cases. Live operation delivers mobile networks, construction-site noise and requests no one anticipated. Plan for four to eight weeks of tuning and judge only afterwards.

AI Telephony for SMEs · A Practical Guide25
KrambergAI18 · Business case
Chapter 18

Building a realistic business case

The economics of AI telephony do not hinge on the per-minute price, but on what an unanswered call costs in your business and how much rework you do today.

The benefit side

ItemCalculationReliability
Additional answered callsPreviously unanswered calls × share the assistant takes onHigh – readable from the phone system
Reduced reworkCases × minutes saved per case × internal hourly rateHigh – measurable via completeness rate
Fewer misroutesMisroutes × people involved × minutes × hourly rateMedium – requires tracking
More complete data captureAvoided follow-up calls × minutes × hourly rateMedium
Avoided on-call visitsVisits made unnecessary by pre-qualification × visit costMedium to high, considerable in some sectors
Won appointments and jobsAdditional calls × share with job potential × win rate × contribution marginLow – the most speculative item. Show it separately
Fewer interruptionsNot seriously quantifiableState qualitatively, do not calculate

The cost side

A per-minute figure alone says little. Costs are typically made up of:

One-off

  • Analysis and design
  • Conversation design per use case
  • Setup and telephony connection
  • Integration with CRM, ERP, calendar
  • Data-protection review, works agreement
  • Testing and pilot support

Ongoing

  • Platform fee
  • Phone numbers and connections
  • Call minutes
  • Speech processing and model usage
  • Support and incident handling
  • Internal maintenance and quality assurance

The item most often missing

Internal maintenance. A phone assistant is not a device you install. Someone has to review the metrics, work through feedback, add new responsibilities and re-test after a model change. Reckon on a few hours a month, and name a person. A system without a caretaker decays slowly and unnoticed.

On the data basis. The calculation should use your real call data. Vendor figures from idealized demonstrations are not enough. A vendor who states savings in percent without knowing your figures is quoting a number from a different company.

AI Telephony for SMEs · A Practical Guide26
KrambergAI18 · Business case

Model calculation

Important note. The calculation below is a structural example with freely chosen assumptions for a fictitious company. It is not a statement about achievable results and not an industry average. Replace every line with your own figures – the structure carries, the values do not.

Assumed company: technical service provider, 35 employees, 60 incoming calls per working day, 20 working days per month, current answer rate 82 percent, internal hourly rate €55.

Benefit per monthAssumptionAmount
Reduced rework300 cases × 4 min. saved€1,100
Fewer misroutes25 cases × 8 min. across two people€185
Avoided follow-up calls80 cases × 5 min.€365
Avoided on-call visits1 visit through pre-qualification€380
Subtotal, reliable benefit€2,030
Additional jobs speculative220 additional answered calls, 6% with potential, 30% win rate, margin €400€1,580
Cost per monthAssumptionAmount
Rollout, amortized€14,000 over 24 months€585
Platform and phone numbersFlat fee€350
Call minutes and model usage1,200 calls × 2 min. × €0.15€360
Internal maintenance and QA5 hrs × €55€275
Total cost€1,570

How to read this calculation

The reliable benefit of €2,030 covers the cost of €1,570 – without assuming a single additional job. That is exactly how a business case should be built: the investment has to carry itself on the items you can measure. Everything that comes from additional jobs is the upside – it belongs in the picture, but not in the justification. If a calculation only works with the speculative items, it does not work.

The three most common calculation errors

AI Telephony for SMEs · A Practical Guide27
KrambergAI19 · Choosing a provider
Chapter 19

Choosing the right provider

The market is crowded and growing fast. Providers differ less in what they show than in what they commit to in writing.

Evaluation matrix

Weight the criteria to your situation and rate each provider. What matters is less the total score than the discussion that emerges while filling it in.

CriterionQuestion to askExclude if
Place of processingProcessing exclusively within the EU? Which sub-processors, based where?No written statement
Model trainingIs conversation data used to train models? Can it be switched off, including for sub-processors?Only general phrasing
StorageWhat is stored, for how long, where? How is erasure done, including backups?Recording not switchable off
Data processingProcessing agreement under Art. 28 GDPR? Notice when sub-processors change?No processing agreement
Transparency noticeIs the Art. 50 disclosure implementable and freely phrasable?Not implementable
IntegrationWhich interfaces exist? Cost of a bespoke connection? Who operates it?Only standard connectors, no extension
HandoverWarm or cold? Does the summary arrive before the phone rings?No context handover
Barge-inDoes it react to interruption? Have it shown liveNot available
Fallback pathBehavior on failure? How fast the diversion? Contractually committed?No commitment
AnalyticsWhich metrics does the platform deliver? Are they exportable?Only a satisfaction gauge
Version changesNotice of model changes? Test phase? Rollback possible?Unannounced changes
ExitFormat of data and configuration on exit? Porting time?No provision
ReferencesComparable size and sector, in live operation? A reference call possible?Only logos, no contact
Speech qualityAccents and background noise – tested with your own callersTest not possible
Pricing modelFull monthly cost at your volume, incl. model usage and supportPer-minute price only

The most revealing question in a selection meeting

“Show me a conversation that went wrong – and what you made of it.” A provider who knows, names and has fixed mistakes is more mature than one who only replays successful recordings. Dodging the question means either no live experience or no willingness to be open. Either is grounds for exclusion.

AI Telephony for SMEs · A Practical Guide28
KrambergAI19 · Choosing a provider

Warning signs

In the sales pitch

  • Savings in percent without knowing your figures
  • “Live in two weeks” – without asking about your systems
  • Demonstration only with scripted conversations
  • Evasion on the question of the place of processing
  • Data protection presented as “handled”, without documents
  • Pricing quoted per minute only

Good signs

  • Asks about your call volume before offering anything
  • Advises against certain use cases
  • Offers a time-limited pilot with an exit option
  • Presents the processing agreement and sub-processor list unprompted
  • Talks about limits and failure cases of its own accord
  • Names reference customers who are reachable by phone

The test that really counts

Do not just have something demonstrated to you. Arrange a limited test under your conditions, and define beforehand what success means. A sound test scenario includes:

On contract terms. Agree a time-limited pilot phase with an express exit option and no follow-on costs. A provider confident in its solution can accept that. A 36-month contract before the first live call is, regardless of price, a poor decision.

Consultant, platform or both

Three constellations are common in the market. The pure platform provider delivers technology you configure yourself – cheap if you have the capability, otherwise expensive by the detour. The systems integrator delivers a solution on a third-party platform – higher cost, but one contact for the result. The full-service provider delivers both from one source – convenient, with the risk that a later switch affects both parts.

For most SMEs the second variant is the right fit: the platform is replaceable, while the process logic and the specialist data stay under your own control. With the integrator, make sure the process work is taken seriously and not merely configured.

AI Telephony for SMEs · A Practical Guide29
KrambergAI20 · Rollout
Chapter 20

Rolling out in eight controlled steps

A good pilot starts outside business hours or with the structured capture of callback requests. Only after quality is proven are further functions added.

  1. Analyze actual call volume Measure for two weeks: calls by hour and weekday, answer rate, call duration, share of recurring requests. These values become your baseline later. Without them you cannot prove any value. 2 weeks
  2. Select a suitable pilot process Frequent, repeatable, low-risk, measurable. Not the most demanding case, but the dullest one with volume. The suitability matrix from Chapter 5 helps with the decision. 1 week
  3. Define the target process and responsibilities The ten definitions from Chapter 8, in writing, with the people who answer the calls today. This step is the most demanding and the most valuable. Anyone who cuts it short pays twice later. 2 to 4 weeks
  4. Review data protection and risks Legal basis, record of processing activities, threshold assessment for an impact assessment, processing agreement, retention periods. In parallel: involve the works council and settle the transparency announcement. Runs alongside step 3, not after it. in parallel
  5. Develop conversation logic and interfaces Build the dialogue, implement the required fields, establish the connection to the target system, set up permissions, configure fallback paths. 3 to 6 weeks
  6. Run realistic tests With your own staff, your own terminology, your own edge cases. From the mobile, from the vehicle, with background noise. Including the cases meant to go wrong: an interface dropping, a request for a human, a hazard. 2 weeks
  7. Start limited live operation One time window, one number, one use case. The fallback path active and tested. A named person with the authority to switch off. Daily review in the first week. 4 to 8 weeks
  8. Measure quality and expand under control Set the metrics against the baseline, classify errors, tune. Only once the first case runs stably does the second one come. Not in parallel. ongoing

On the schedule

For a first use case in an SME, three to four months from analysis to stable operation is realistic. Anyone wanting to be faster usually cuts corners at step 3 – and finds the omitted work again in operation. The pure configuration time is often only a few days. That is precisely why vendors can promise “live in two weeks” and projects still take half a year.

AI Telephony for SMEs · A Practical Guide30
KrambergAI20 · Rollout

Who is needed in the project

RoleTaskEffort
SponsorDecides on scope and budget, approves the go-live, names the switch-off authorityA few meetings
Process ownerDrives the ten definitions, resolves conflicts between departments – the key roleConsiderable, across the whole run
DepartmentProvides conversation knowledge, tests, reports errors, signs offIntermittent, high in steps 3 and 6
ITTelephony connection, interfaces, permissions, operationsConcentrated in step 5
Data protectionLegal basis, record, impact assessment, processing agreementsIntermittent, involve early
Works councilCo-determination, works agreementIntermittent, involve from step 2

The critical role. Without the process owner, the project fails – regardless of the technology. This person must be allowed to decide which department is responsible, what the assistant may say and when to escalate. A project in which these questions are meant to be settled by consensus does not settle them.

Communicating internally and externally

Internally: inform the affected teams before the first handover rings. Explain what the assistant does, where it makes mistakes and how to report a poor experience. Involve the staff in the conversation design – they know more about the calls than any consultant.

Externally: an announcement to customers is possible but rarely necessary. More important than the announcement is the notice in the conversation itself. What you should not do: conceal the use and hope no one notices. Someone notices, and then the question is no longer the technology but trust.

The transition to regular operation

A pilot does not end by continuing to run. It ends with a decision. Define beforehand what you base it on:

If these points are met, the case moves into regular operation and the next one can begin. If they are not met, it is improved or discontinued. A pilot without an exit option is not a pilot but a rollout with a grace period.

AI Telephony for SMEs · A Practical Guide31
KrambergAI21 · Practical examples
Chapter 21

Practical examples from SMEs

The following examples are typified scenarios, not customer accounts. They show how a use case is tailored and where the critical point lies in each.

Plumbing and heating company: callback capture outside business hours

Starting point: 24 employees, calls from 5 to 9 pm go to an answering machine. In the morning there are twelve messages, half of them incomplete. The back-office assistant spends the morning making callbacks to clarify.

Design: the assistant answers from 5 pm, capturing name, phone number, property address, request and urgency. On a smell of gas or escaping water: an immediate pointer to the emergency service and a transfer to the on-call team. Everything else is created as a case in the order system, sorted by urgency.

Critical point: distinguishing an emergency from a maintenance request. This was not left to the model but governed by an allow list of keywords that, in any case of doubt, leads to the on-call team. Better one transfer too many.

Effect: the morning starts with a prioritized list of complete cases instead of clarifying callbacks.

Technical service provider: fault intake with pre-qualification

Starting point: nationwide service for equipment at commercial customers. The on-call team is regularly dispatched because the phone call did not establish whether the fault has to be fixed on site or can be resolved remotely.

Design: the assistant asks for equipment type, location, error code, time and impact, and matches the details against a catalog of known fault patterns. For known cases with a documented remote fix, it gives the pointer to the known remediation step and records the result. If the fault persists, the on-call team is alerted with the full history.

Critical point: the fault catalog. It comes from the ticket system, is maintained and is extended with each new fault pattern. The assistant only gives pointers from this catalog – never its own judgments.

Effect: the on-call team is dispatched less often to cases that could have been resolved by phone. Where it is dispatched, it knows the situation.

Traffic-safety company: call intake in shift operation

Starting point: reports on barriers, damage and diversions come in around the clock, from clients, authorities and passers-by. Dispatch is staffed but not continuously at the desk.

Design: the assistant answers, distinguishes between a client report, a damage report and a general enquiry, and captures location, project number and the facts. Safety-relevant reports – a toppled barrier, exposed roadway – lead directly to alerting the shift.

Critical point: location details. Street names and site designations are often misheard. Solved by matching against active projects and consistent confirmation: “You mean the project on Bahnhofstrasse in Filderstadt, is that correct?”

Effect: reports reach the shift with location and urgency instead of as a request to call back.

AI Telephony for SMEs · A Practical Guide32
KrambergAI21 · Practical examples

Electrical contractor: appointment coordination in project business

Starting point: site-survey and handover appointments are arranged by phone. The coordination drags across several calls because both sides are rarely reachable at the same time.

Design: the assistant takes appointment requests, checks availability in the dispatch calendar and proposes two concrete windows. It reserves but does not book: confirmation follows the next day from dispatch, which accounts for the travel route.

Critical point: the deliberate decision against direct booking. Route optimization is in no calendar. An assistant that booked would have created appointments that dispatch has to move again – turning relief into an extra task.

Effect: three calls become one plus a confirmation.

Marina: seasonal enquiries and berth management

Starting point: in spring, call peaks on berth availability, crane appointments and winter storage. Always the same eight questions. The harbor office is two people and often out on the grounds.

Design: the assistant answers general questions on opening hours, prices per the posted list and procedures from a maintained knowledge base. Availability enquiries and bookings it takes as a request and forwards to the harbor office – without a commitment.

Critical point: the knowledge base. It contains only information that is also on the posted notice, with a clear owner and a date of last update. Anything not in it leads to a transfer.

Effect: the harbor office is relieved of recurring standard questions and stays reachable for the cases that need a decision.

What these examples have in common

On transferability. The examples are typified and serve to illustrate. They do not describe specific customer projects and contain no figures on results achieved. Whether a design fits your company is decided by your call data, your systems and your responsibilities.

AI Telephony for SMEs · A Practical Guide33
KrambergAI22 · Common mistakes
Chapter 22

Common mistakes and how to avoid them

The patterns repeat. Those who know them spare themselves the experience.

MistakeWhat follows from itWhat helps
Starting with the hardest caseEverything goes wrong at once and no one knows what caused itChoose the most frequent, dullest case
Settling the process after the technologyThe assistant holds conversations whose result no one handlesThe ten definitions from Chapter 8 before configuration
Checking data protection at the endThe finished system is not allowed to go liveInvolve data protection and the works council from step 2
Making the way to a human hardThe metric rises, the customer relationship suffersGrant the request for a human on the first ask
Letting the model decideUnpredictable statements on prices, deadlines, responsibilitiesDecisions by rule, phrasing by the model
Enabling recording “just in case”Consent problem, erasure effort, more data than necessaryStart without audio, time-limit transcripts
Disclosure without an identity checkPersonal data to strangersA second factor or no disclosure
No baseline before launchThe value cannot be provenTwo weeks of current-state measurement before the rollout
No fallback pathOn a failure, the company is unreachableCommit the diversion contractually and test it before launch
No owner after launchQuality decays unnoticed over monthsName a person with a time budget, monthly review
Too many required fieldsConversations grow long, callers hang upFour to six fields, the rest optional
Informing the team only at acceptanceResistance, missed expertise in the designInvolve the people who answer the calls today

The costliest mistake

The assistant is introduced, it works, and no one takes care of it. After four months a responsibility has changed, a model update has shifted the behavior, and three staff have given up reporting misroutes. The system keeps running and quietly produces worse results. The effort to prevent this is a few hours a month. The effort to repair it later is a new project.

AI Telephony for SMEs · A Practical Guide34
KrambergAIChecklists

Working material

Checklist for management

Twelve questions that should be answered before a project is approved. If you cannot answer more than three of them, the project is not yet ready for a decision.


Data protection checklist

AI Telephony for SMEs · A Practical Guide35
KrambergAIChecklists

Information security checklist


Acceptance checklist

These tests belong before going live. All are to be carried out with real phones, not in the vendor’s web interface.

Document the result. An acceptance record with the date, the tester and the result per test is the basis for re-checking the same cases after a model change. Without this record, every check starts again from scratch.

AI Telephony for SMEs · A Practical Guide36
KrambergAIFAQ

Frequently asked questions

Questions and answers

What is AI telephony?

AI telephony is the use of artificial intelligence to answer and handle phone calls. Unlike a classic phone menu, an AI voice assistant understands freely phrased speech, asks targeted follow-up questions and passes the result on in a structured way – as a task, an appointment or a ticket in the connected system.

Which companies is AI telephony suitable for?

For companies with recurring, describable phone requests and a certain call volume. Especially suitable are the skilled trades, technical service, dispatch and project business. Less suitable are businesses whose calls run differently every time and rely on judgment and experience.

Does an AI voice assistant replace human staff?

No. A responsibly designed assistant does not replace staff; it ensures that they enter a conversation with complete information. It takes on repeatable tasks such as capture and routing, and hands over anything that requires a decision, empathy or professional judgment.

Which calls can sensibly be automated?

Repeatable processes with nameable required information: callback capture, appointment requests, fault reports, routing by request and status enquiries after an identity check. Unsuitable are complaints, contract questions, binding price commitments and safety-critical situations.

How is AI telephony integrated with CRM or ERP?

Integration usually takes place via defined programming interfaces. The assistant can search for customer data, check appointments, create tickets or store conversation results. The key distinction is between read and write access: write actions require additional validation, confirmation and logging.

Which data-protection requirements apply to AI telephony?

Phone calls contain personal data, so the GDPR applies in full. Required are a legal basis per processing purpose, a data processing agreement with the providers, defined retention periods and a process for data-subject rights. Where voice recordings are processed, a data protection impact assessment should be considered.

Must a caller be informed about the use of AI?

Yes. Under Article 50 of the EU AI Act, the transparency duty becomes applicable on 2 August 2026: the person concerned must recognize that they are interacting with an AI system. The notice should come at the start of the conversation, clearly and understandably, together with a way through to a human.

May conversations with an AI voice assistant be recorded?

Only under the conditions of the GDPR and, as a rule, with valid consent from both sides. Recording should be the exception, not the default. For many use cases it is enough to process speech during the call and store only the structured result – without an audio recording.

AI Telephony for SMEs · A Practical Guide37
KrambergAIFAQ

What does an AI telephony solution cost?

Costs are made up of one-off items (analysis, conversation design, setup, integration) and ongoing items (platform fee, phone numbers, call minutes, model usage, support and internal maintenance). A per-minute price alone says little. What is decisive is the full monthly cost at your volume, set against the measurable benefit.

How should a company begin with AI telephony?

Best with a bounded, low-risk use case: calls outside business hours or the structured capture of callback requests. The benchmark is the answering machine – a low bar. Only once quality is proven are further functions added.

How long does the rollout take?

For a first use case in an SME, three to four months from analysis to stable operation is realistic. The pure configuration time is often only a few days. The bulk of the time goes into defining the process, integration, data protection and testing.

Do callers notice they are speaking with an AI?

They should – and from 2 August 2026 they must be informed. Experience shows that callers who know from the start whom they are dealing with phrase things more clearly and are more forgiving of a misunderstanding. Concealment damages trust as soon as it is noticed.

What happens if the assistant misunderstands something?

A well-designed assistant confirms critical values such as phone numbers and appointments and, after the second unsuccessful attempt, hands over to a human. Understanding errors are captured through an error classification and reduced through targeted confirmations and clearer phrasing.

Does the works council have to have agreed?

Where a works council exists, it has, as a rule, a co-determination right under Section 87(1) no. 6 of the Works Constitution Act, because the system is objectively suitable for monitoring conduct or performance. The council should be involved in the concept phase, not at acceptance. Without a works council, employee data protection still applies.

May we use the assistant to call customers?

With caution. Advertising calls to consumers require prior express consent under Section 7 UWG. Unproblematic are service calls the customer expects: appointment confirmations, requested callbacks, notice of delays. The recommendation is not to start with outbound.

What happens if the system fails?

For that there must be a defined, tested fallback path: an automatic diversion of the phone number to a target number you specify, or an announcement with an alternative contact route. The fallback should be committed contractually and tried at least once under real conditions before going live.

Can we use the voice of our managing director?

It is technically possible but not advisable. The benefit is small, the irritation for the caller considerable, and its lawfulness depends on the consent of the person concerned. A neutral, clearly intelligible voice that is recognizably synthetic serves the purpose better.

AI Telephony for SMEs · A Practical Guide38
KrambergAIGlossary

Reference

Glossary

Barge-in
The ability to interrupt the assistant by speaking. It stops its output and listens. A key feature for a natural conversation.
Completion rate
The share of conversations that reach the defined goal. Measured per use case, not overall.
Data protection impact assessment
An assessment under Article 35 GDPR of processing operations likely to result in a high risk. Should be considered for AI telephony, particularly where recordings are involved.
Deployer
Whoever uses an AI system under their own responsibility. The standard role for SMEs, with fewer duties than a provider.
Fallback path
The defined behavior on a failure, for example an automatic diversion of the phone number to a target number specified in advance.
Handover
The transfer of a conversation to a member of staff, ideally with a summary that reaches the person before acceptance.
Idempotence
The property whereby a repeated action produces no additional effect. Prevents duplicate tickets on an abort and retry.
Intent recognition
The classification of a request into a defined category, the basis for further conversation control.
IVR
Interactive Voice Response, the classic phone menu with key presses or fixed keywords. Not to be confused with an AI voice assistant.
Latency
The delay between the caller’s and the system’s turn. Above roughly one second, the conversation feels sluggish.
Least privilege
The principle of granting only the minimum rights necessary. Central to the security of a phone assistant.
Provider
Whoever develops an AI system or places it on the market under their own name. Bears more extensive duties than a deployer.
Regression test
A re-check with a fixed set of test conversations, especially after a model or version change.
SIP trunk
A technical connection for internet telephony over which the assistant answers calls.
Transcript
The written record of a conversation. Contains everything that was said and is therefore subject to data protection.
Voicebot
A rule-based voice system with predefined paths. A middle stage between a phone menu and an AI voice assistant.
AI Telephony for SMEs · A Practical Guide39
KrambergAI AI Consulting for SMEs

About KrambergAI

We help small and medium-sized enterprises use artificial intelligence in a way that is practical, lawful and controlled – not as an end in itself, but where it demonstrably eases the daily workload.

Our conviction runs through this whitepaper: AI should make work calmer, not louder. It should give teams relief, provide managers with control, meet security requirements and preserve a company’s sovereignty over its own data and processes. Technology is the means. The measure is whether the result holds up in day-to-day operation.

This is why we place value on data protection under EU law and on development in Germany – not as a label, but as a practical prerequisite for solutions that decision-makers can answer for.

Consulting

Assessment, selection and controlled introduction of AI solutions for SMEs.

Approach

Process before technology, measurable value, honesty about limits.

Focus

The mid-market in the DACH region, data protection under EU law, development in Germany.


Contact

KrambergAI GmbH
Website: krambergai.com

On this whitepaper

Editorial status: July 2026. This guide provides general information and does not replace legal or data-protection advice for the specific case. Statements on the legal position reflect the status at editorial close; the amendments to the AI Act through the Digital Omnibus had not been formally adopted at that point. The model calculation in Chapter 18 is a fictitious example with freely chosen assumptions. The practical examples in Chapter 21 are typified and do not describe specific customer projects.