alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533
Become a Member
alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533

What does AI transparency require?

What does AI transparency require?

AI transparency includes disclosing that AI is involved and, in some contexts, duties to explain decisions. Explainability, meaning saying how a system reaches its output, is good practice more broadly, but specific information and explanation duties can already arise under the GDPR.

What the AI Act requires on disclosure

Legal requirement (EU AI Act, Art. 50). These duties apply from 2 August 2026; the full timeline is in what the EU AI Act requires. They depend on whether the company is the provider or the deployer of the system (AI Act, Art. 50). A company developing AI for its own use can also be a provider; check whether you are a provider or a deployer.

Provider obligations:

  • AI that interacts with people. Such systems must be designed so that people know they are dealing with AI, unless this is obvious from the context.
  • Generated content. Providers of systems that generate audio, images, video or text must mark the output in a machine-readable format, detectable as AI-generated. For systems placed on the market before 2 August 2026, this is due by 2 December 2026 (Regulation (EU) 2026/1744). The duty does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data provided by the deployer or its meaning (Art. 50(2)).

Deployer obligations:

  • Deepfakes. A deepfake is AI-generated or manipulated image, audio or video content that resembles real people, objects, places or events and could falsely appear authentic. The deployer must disclose this.
  • Text on matters of public interest. A deployer that publishes AI-generated text to inform the public on matters of public interest must disclose this, unless a person has reviewed the text and someone holds editorial responsibility for it.
  • Emotion recognition and biometric categorisation. The deployer must inform the people exposed. Emotion recognition means identifying or inferring emotions or intentions on the basis of biometric data (Art. 3(39)). A notice does not make every use lawful: such systems are prohibited at work and in education, except for medical or safety reasons (Art. 5(1)(f); Commission guidelines on prohibited practices). Inferring emotions from text content is not automatically covered, but GDPR and employment law can still apply.

A high-risk system can carry these duties in addition to the high-risk requirements (Art. 50(6)).

Explaining decisions

Legal requirement (GDPR). This already applies. For automated decisions within Art. 22, the person concerned is entitled to meaningful information about the logic involved (GDPR, Art. 13(2)(f), 14(2)(g) and 15(1)(h)). The Court of Justice of the EU clarified that this means explaining, concisely and intelligibly, the procedure and principles actually applied; it is not a right to the source code or a full technical explanation of the model (C-203/22, 27 February 2025).

Legal requirement (EU AI Act, Art. 86). A person affected by a decision the deployer bases on the output of a high-risk system listed in Annex III (except point 2, critical infrastructure), where the decision produces legal effects or similarly significant adverse effects for them, can ask the deployer for an explanation of the role the AI played and the main elements of the decision (AI Act, Art. 86). Art. 86 is not expressly postponed by the Omnibus, but it concerns only high-risk systems, so its timing depends on classification and the Art. 111 transitional rules and needs a legal assessment. Handling challenges is covered in how human oversight of AI works.

Recommendation. Tell people in plain language what the AI does and does not do, its known limits and how to reach a person. Where AI supports decisions about people, record the main factors behind each outcome so you can explain it.

Sample AI transparency notices

  1. Customer chatbot, first message: “You are chatting with an AI assistant. It can help with orders and deliveries but may make mistakes. Type ‘agent’ at any time to reach a member of our team.”
  2. Deepfake in a campaign video: “This video was created with AI. The person and events shown are not real.”
  3. Automated news summary that nobody reviews: “This summary was generated by AI and has not been reviewed by our editors.”

Recommendation. A notice does not make a chatbot safe. Approve it separately as a narrowly scoped automated service with testing, monitoring, escalation to a person and agreed stop criteria. This does not override legal safeguards for decisions about people.

With a vendor’s generative tool, marking is the provider’s job; confirm it through your questions for an AI vendor. Notices alone do not make a system compliant with the rest of the AI Act.

Next step: check that every AI-run chat or voice channel on your website and apps says from the start that the customer is talking to AI.

Sources and further reading

This article is for general information and is not legal advice.

Event

AI Horizon Conference

The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.

November 11, 2026
Lisbon, Portugal
Register Now
AI Horizon
alt alt

Join Us in Shaping the Future of Ethical AI!

Join us as a member and play a vital role in shaping a future where AI is created responsibly, with integrity, transparency, and fairness at its core.

Apply Now