Skip to content
Confir.
Tools & Comparisons

ServiceNow AI (Now Assist) and the EU AI Act: Why ITSM Automation Is Usually Low-Risk — and the Three Edges That Aren't

AI Tool Compliance5 August 2026· 11 min read

ServiceNow AI (Now Assist) for ITSM is usually minimal risk under the EU AI Act. See the three edges — HR use (Annex III pt 4), custom skills (Art 25), data.

Probably not high-risk. A 4,000-person insurer running Now Assist to summarise incidents and route tickets sits at minimal or limited risk — no Chapter III obligations attach. The verdict only flips when the platform is pointed at an employment decision, when you build a custom skill, or when you ignore the data flowing through it.

The EU AI Act (Regulation (EU) 2024/1689) does not classify tools by name. Risk tier follows the use case and how your organisation configures and applies the system (Article 6, Annex III). Treat ServiceNow not as one global verdict but as an inventory of skills and use cases to classify individually — this guide separates the default ITSM baseline from the three edges that change your duties.


What Now Assist actually does — and why that matters for classification

Now Assist automates IT service management: incident summarisation, ticket triage and routing, knowledge-article generation, case handling, and virtual-agent chat across IT, HR, and customer workflows. It is operational plumbing, not a decision engine about individuals — and that distinction is the whole game under the Act. Ordinary ITSM automation — summarising an incident, routing a ticket, drafting a knowledge article, running business analytics over operational data — is not an Annex III use case; like defensive cybersecurity tooling, it falls to minimal or limited risk.

The trap is assuming the platform carries a single label. It does not: the same Now Assist licence can host a minimal-risk ticket router and a high-risk HR screener at once. Classify each, not the platform.


Default risk tier: ordinary ITSM use is minimal or limited risk

Most deployers running stock Now Assist for IT operations live here — obligations are light, but not zero.

Minimal-risk uses carry no mandatory Chapter III high-risk obligations. Only the baseline duties apply: data governance hygiene and Article 4 AI literacy (covered below).

Limited-risk transparency bites where a person interacts with an AI system. Under Article 50, a Now Assist virtual agent or chatbot must disclose to the user that they are interacting with AI, unless that is obvious from the context. A short notice in the chat interface satisfies this — a disclosure duty, not a documentation stack.

Article 50's generative-output marking and the broader content-marking duties apply from 2 December 2026 under the Digital Omnibus, adopted by the European Parliament (16 June 2026) and the Council (29 June 2026), pending only Official Journal publication.


Edge 1 — Using Now Assist for HR decisions can touch Annex III point 4

ServiceNow runs HR Service Delivery. Pointing Now Assist at recruitment screening, promotion, task allocation, or performance-linked monitoring moves the use towards Annex III point 4 — point 4(a) for recruitment and selection, point 4(b) for decisions in an existing employment relationship.

The trigger is influence on outcomes, not the mere existence of an HR module: screening or employment-tied access provisioning that materially shapes a hiring or promotion decision is what crosses the line.

If the use is genuinely high-risk, the deployer inherits Article 26 duties — human oversight, monitoring, logging — plus an Article 27 Fundamental Rights Impact Assessment before deployment.

There is a hard line above that tier. Article 5(1)(f) prohibits emotion-recognition systems in the workplace outright — never configure Now Assist to infer an employee's emotional state — and Article 5(1)(g) prohibits biometric categorisation that infers sensitive attributes. These are prohibitions, not high-risk obligations: no compliance route makes them permissible. Scope HR use cases out of high-risk where you can; where you cannot, classify and treat them as high-risk deployments. Full stop.


Edge 2 — Building a custom skill can make you the provider (Article 25)

Out of the box, your organisation is a deployer under Article 26, while ServiceNow and its upstream GPAI model providers carry their provider and Chapter V duties.

That allocation flips under Article 25. You become a provider when you build a custom Now Assist skill, agent, or workflow for a defined purpose, put your own name or trademark on the system, substantially modify it, or change its intended purpose to a high-risk one.

If the system you now provide is high-risk, you carry the full Article 16 stack: risk management (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping and logging (Article 12), transparency (Article 13), human oversight (Article 14), accuracy and robustness (Article 15), plus conformity assessment (Article 43) before placing it on the market.

The nuance many deployers miss: most custom skills automating routine ITSM will still not be high-risk. Article 25 changes who holds duties; the tier still depends on the use case. Log every custom skill in the AI inventory with its intended purpose and a role determination before it ships.


Edge 3 — Data governance over ticket and PII data, and Article 4 literacy

Tickets, HR cases, and customer records flowing through Now Assist routinely contain personal data. Your deployer data-governance hygiene and GDPR obligations run in parallel with the AI Act baseline — the floor, not the high-risk ceiling.

Article 4 AI literacy has applied since 2 February 2025: staff who operate or rely on Now Assist outputs must have sufficient understanding to use it responsibly, even at minimal risk.

Scope what data Now Assist can read, retain, and surface, constraining prompts and grounding sources so it cannot expose records beyond a user's existing permissions. Keep a clear record of model and data residency and the contractual layer with ServiceNow, and document the literacy briefings. None of this needs a high-risk trigger — it is the baseline every professional deployer maintains.


Decision table: classifying a ServiceNow AI use case

Classify per skill and use case, not once for the whole platform. This table maps representative Now Assist uses to tier, role, and trigger.

Use caseLikely tierYour roleTrigger / obligationFirst action
Incident summarisation, ticket routingMinimal riskDeployerNone beyond baselineLog in inventory; Article 4 literacy
Virtual-agent chatLimited riskDeployerArticle 50 disclosureAdd "you are chatting with AI" notice
HR recruitment or promotion supportPotentially high-riskDeployer (or provider if customised)Annex III pt 4 + Article 27 FRIAClassify; descope or treat as high-risk
Custom skill for a defined purposeDepends on useRole shifts to providerArticle 25 (+ Article 16 if high-risk)Role determination before ship
Emotion inference on employeesProhibitedn/aArticle 5(1)(f)Do not build it

The high-risk Annex III deadline is 2 December 2027 under Article 6(2), deferred by the Digital Omnibus, which was adopted by the European Parliament and Council in June 2026 and is pending only Official Journal publication.


Worked example: Meridian Mutual rolls out Now Assist

Meridian Mutual, a roughly 4,000-staff EU insurer, enables Now Assist across IT and HR service delivery. The IT operations use — incident summarisation, ticket routing, agent assist — lands at minimal or limited risk. The IT virtual agent gets an Article 50 "you are chatting with an AI" disclosure, staff complete Article 4 literacy briefings, and the obligations are cleanly met.

Then the HR team asks for a custom skill to pre-screen internal promotion applications. This hits two edges at once. Building the skill triggers Article 25 provider status, and the use touches Annex III point 4(b) — decisions in an existing employment relationship. Together that is a high-risk provider scenario: the full Article 16 stack on Meridian's side, plus an Article 27 FRIA on the deploying side.

Meridian's risk lead descopes the feature: promotion ranking becomes a non-decisional summarisation aid with a mandatory human decision, keeping it out of the high-risk tier while retaining logging and oversight.

The outcome: one platform, three distinct classifications. The high-risk burden came entirely from the HR-decision configuration, not from Now Assist itself.


How Confir helps

Confir inventories each Now Assist skill and use case as a separate entry, runs a deterministic, rule-based classification against Article 6 and Annex III — no model inference, no hallucination — and records the deployer or provider role determination (Articles 25 and 26).

Where an edge is triggered, it generates the Article 4 literacy, Article 50 disclosure, and Article 27 FRIA artefacts with citations, and keeps the platform mapped as obligations move — keeping obligation dates current as the Digital Omnibus, now adopted, takes effect. It also surfaces the Article 99 penalty context — up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices (Article 99(3)), €15 million or 3% for most other breaches (Article 99(4)), and €7.5 million or 1% for supplying incorrect information (Article 99(5)) — so role and tier mistakes are caught before they ship.


Frequently asked questions

Is ServiceNow Now Assist high-risk under the EU AI Act?

Not by default. The Act classifies use cases, not tools, so it never labels Now Assist high-risk by name (Article 6, Annex III). Ordinary ITSM automation — incident summarisation, ticket routing, knowledge articles, agent assist — is minimal or limited risk with no Chapter III high-risk obligations. It only becomes high-risk if you use it to make or materially influence an Annex III decision, most commonly an HR employment decision under Annex III point 4. Classify each use case and custom skill separately, not the platform as a whole.

When does ServiceNow AI use become an Annex III high-risk case?

When the use falls inside an Annex III category. For ITSM, the realistic trigger is HR Service Delivery: pointing Now Assist at recruitment screening, promotion, or other decisions in an employment relationship engages Annex III point 4 (4(a) recruitment, 4(b) in-employment decisions). At that point the deployer picks up Article 26 duties — human oversight, logging, monitoring — plus an Article 27 Fundamental Rights Impact Assessment. A descoped, non-decisional assistant with a mandatory human decision can often stay out of the high-risk tier entirely.

Does building a custom Now Assist skill make me a provider?

It can. Out of the box you are a deployer under Article 26. Building a custom Now Assist skill or agent for a defined purpose, putting your own name or trademark on the system, substantially modifying it, or changing its intended purpose to a high-risk one flips you to provider under Article 25. As a provider of a high-risk system you carry the full Article 16 stack, including conformity assessment (Article 43). Note that Article 25 changes who holds duties; the risk tier still depends on the use case.

Do I need an Article 50 disclosure for a Now Assist virtual agent?

Yes, where end users chat with the virtual agent. Article 50 requires that people interacting with an AI system are informed they are interacting with AI unless it is obvious from the context. A simple notice in the chat interface satisfies this. Generative-output marking and the broader content-marking duties apply from 2 December 2026 under the Digital Omnibus, now adopted by the European Parliament and Council.

What baseline duties apply even if our ServiceNow AI use is minimal risk?

Two. First, Article 4 AI literacy — in force since 2 February 2025 — requires staff who operate or rely on Now Assist outputs to have sufficient understanding to use it responsibly; this applies regardless of risk tier. Second, data governance over the ticket, HR-case, and customer personal data flowing through the assistant, running alongside your GDPR obligations. Scope what Now Assist can read, retain, and surface so it cannot expose records beyond a user's existing permissions.

Can Now Assist be used to monitor employee emotions or sentiment?

No. Article 5(1)(f) prohibits emotion-recognition systems in the workplace outright, and Article 5(1)(g) prohibits biometric categorisation that infers sensitive attributes. These are prohibitions, not high-risk obligations, so there is no compliance route that makes them permissible. Never configure Now Assist or a custom skill to infer employee emotional state, mood, or sensitive characteristics from text, voice, or behavioural data. Ordinary operational analytics over IT tickets does not engage these prohibitions.

What are the penalties for getting ServiceNow AI classification wrong?

Penalties scale with the breach. Prohibited-practice violations (Article 99(3)) reach €35 million or 7% of total worldwide annual turnover, whichever is higher; most other obligation breaches (Article 99(4)) reach €15 million or 3%; supplying incorrect information (Article 99(5)) reaches €7.5 million or 1%. The practical risk is misclassifying an HR use as low-risk or overlooking that a custom skill made you a provider — both expand your obligations well beyond baseline ITSM duties.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →

Keep reading