By Rafael Luque Ocaña

AI in B2B and food distribution: your operations aren't high-risk; your HR might be

Demand forecasting, routes, pricing, CRM: the technological core of a distributor is minimal risk under the AI Act. High risk enters through another door — human resources — and knowing how to tell them apart avoids both panic and neglect.

A mid-sized wholesale distributor uses more AI today than it realises: demand forecasting, route optimisation, dynamic pricing, a CRM that scores opportunities, an order-taking chatbot. When the AI Act enters the conversation, the first reaction is usually alarm — "we use AI in everything, this is going to land on us." The reality, once properly classified, is calmer and more interesting: the core operations of distribution are minimal risk. High risk, when it appears, enters through a door almost nobody is watching.

The core: minimal risk, light obligations

Let's run through the typical stack with the classification it actually carries:

Demand forecasting (RELEX, Blue Yonder, SAP IBP and similar tools): prediction by SKU and point of sale, procurement planning. With no bearing on specific individuals, this is a minimal-risk system. No impact assessment, no high-risk obligations; it does still count for the inventory and for the training of the staff who use it.

Route optimisation and delivery: assigning orders to vehicles, sizing the fleet. In its pure logistics use, minimal risk. The fine print appears if the system moves from optimising routes to monitoring and evaluating the driver — one of the two doors, covered next.

B2B dynamic pricing: price adjustment between businesses based on demand, margins and segment. In pure B2B, minimal risk from an AI governance standpoint. The caveat: extending it to end consumers with differentiation by personal characteristics changes the analysis entirely and calls for re-assessment before taking that step.

AI-powered CRM (Salesforce Einstein, HubSpot AI, Dynamics): lead scoring, churn prediction, assisted drafting. Minimal risk; remember that B2B contacts are personal data — the GDPR applies in full — and that systematic, large-scale profiling brings a data protection impact assessment into play.

Customer service chatbot: as in any sector, this triggers transparency towards the customer — the notice that the customer is talking to an AI, whose out-of-the-box compliance is worth verifying and documenting.

The pattern is clear: the distributor's technological core calls for order — inventory, training, transparency, supplier verification — but it doesn't carry high-risk obligations. Anyone selling you otherwise is inflating your risk to sell you the fix.

The door high risk actually walks through: people

Annex III of the AI Act doesn't classify sectors; it classifies uses. And there's one cross-cutting use that turns any company, in any sector, into a high-risk case: employment. In a distributor, that shows up as two very common systems:

The AI-powered ATS — screening and scoring applications for warehouse, delivery and office roles. As we covered in detail before, pre-selecting candidates with AI is high risk by definition under Annex III, and it also triggers GDPR obligations that are already in force today: a data protection impact assessment is mandatory whenever there's systematic profiling with significant effects, and fully automated decisions about candidates require the safeguards of Article 22.

AI-assisted performance evaluation — HR modules that analyse KPIs, flag "high performers" or recommend promotions. Same door, same regime, with two added layers that matter in distribution: collective agreements often set out evaluation procedures that the AI cannot bypass, and worker representatives have their own information rights over algorithms that affect working conditions.

The asymmetry is the sector's key commercial and risk insight: most of your stack calls for order; the HR slice calls for rigour. Mixing up the two levels in either direction gets expensive — through excess (paralysis and spend where none is needed) or through neglect (an ATS with no data protection impact assessment has a GDPR obligation outstanding that is already enforceable today).

What to do, in order

  1. Take stock of everything, including the AI that arrived bundled inside the ERP and the CRM without a formal purchase decision.
  2. Classify by splitting the two doors: operations (minimal risk, order) and people (high risk, rigour). What decides is each system's actual purpose, not its product name.
  3. Close today what's due today: the ATS's impact assessment, Article 22 safeguards, chatbot transparency, staff training with a record.
  4. Schedule what's due tomorrow: the full high-risk obligations of Annex III arrive on the timeline set by the Digital Omnibus — room to build the file properly, not an excuse to leave it unstarted.

A distributor that keeps those two waters separate turns the AI Act into what it should be: an exercise in order with one specific point of rigour. No more, no less.

Product mentions are descriptive of the market and do not imply any business relationship. This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.