When users have to know that AI is involved
The transparency duties of the AI Act reach almost every deployment, well beyond the high-risk cases. They bite wherever someone cannot readily tell that they are dealing with a system or its output.
Most duties under the AI Act hang on the risk class. The transparency duties do not. They turn on whether a person can tell what they are dealing with, and so they also catch the customer service chatbot and the generated image in an advertisement.
Four cases that require disclosure
- Interaction with a systemAnyone talking to a chatbot or a voice application has to be told, unless it is obvious to a reasonably observant person.
- Generated or altered contentText, images, audio and video from an AI system need machine-readable marking so that their origin remains traceable.
- DeepfakesWhere a depiction looks real but is not, the artificial origin has to be apparent. Art and satire enjoy reliefs in form, not in principle.
- Emotion recognition and biometricsSystems recognising emotions or categorising biometrically require the people concerned to be informed, whatever the risk class.
What to do
- Take stock: where do customers or staff meet a system or its output?
- Decide case by case whether disclosure is required and in what form
- Place notices where the interaction happens, not in the terms of use
- Have the provider confirm that outputs are marked machine-readably
- Set an editorial rule for generated images and text in marketing
- Keep a record of when each notice was introduced
How we help
We go through the touchpoints with you, assess each one, and word the notices so that they do their job without getting in the way of the application. Where you use third-party tools, we check whether the provider’s commitments carry your own duty.
Chatbot in support, generated images in marketing?
We will tell you what has to be disclosed and by when, and draft the notices.
Get in touchFrequently asked questions
Does this affect us even though our system is not high-risk?
Yes. The transparency duties in Article 50 AI Act apply regardless of the risk classification. A different question decides: is there a risk that a person will not readily recognise that they are interacting with an AI system or looking at AI-generated output? That covers customer service chatbots as much as generated images in advertising.
When does the labelling duty start?
For most duties on 2 August 2026, and the Digital Omnibus changed nothing there. Only machine-readable marking of generated content moved. Systems already offered before 2 August 2026 have until 2 December 2026 for it. For a new introduction the earlier date stands.
Is a note in the small print enough?
No. The notice has to reach the person concerned, which means where the interaction happens and in good time, so before or at first use. For generated content a machine-readable marking is added. A visible note alone is not enough in those cases.
What applies to images and video that look real?
Deepfakes carry their own disclosure duty: it must be apparent that the content was artificially generated or altered. There are reliefs for artistic, satirical and fictional works, but they concern the form of the disclosure rather than removing it.
Who labels, the provider or us as deployer?
Both, in different places. The provider owes the technical marking in the output, the deployer owes the disclosure to the people dealing with it. Where a third-party tool is used, the marking should be assured contractually. Without it, your own duty cannot be met.