EU AI Act transparency guidance lands: what providers and deployers need to do now
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
The European Commission has published its final guidelines on the EU AI Act’s transparency obligations, giving businesses a clearer view of what Article 50 will require when it starts to apply from 2 August 2026. For clients using customer-facing AI, generative AI content tools, deepfake functionality, emotion recognition or biometric categorisation, this is an important compliance milestone rather than a purely theoretical policy update.
The Commission says the guidelines are intended to help providers, deployers and competent authorities apply Article 50 consistently, effectively, proportionately and uniformly. In practical terms, the update is designed to reduce deception and manipulation by helping people recognise when they are interacting with AI or are being shown AI-generated or AI-manipulated content.
The guidance is especially useful because it does not just repeat the legislation. It clarifies who is in and out of scope, how the provider and deployer roles should be understood across the value chain, what key concepts mean, what exceptions may apply, and how compliance may be demonstrated in practice.
Providers of AI systems that directly interact with natural persons must design and develop those systems so that people are informed they are interacting with AI, unless that is obvious. The Commission’s FAQ says this notification must be given from the start of the first interaction, in a clear and distinguishable manner, and in line with accessibility requirements.
The Commission also narrows this obligation by setting out four cumulative criteria: the tool must qualify as an AI system, it must be designed for a genuine two way exchange, the interaction must be direct, and it must be with natural persons. Systems operating only in the background, machine to machine systems, and tools without direct contact with people fall outside this specific obligation.
That matters commercially because many businesses will need to revisit where AI disclosures appear in user journeys, customer support tools, internal assistant interfaces and avatar based services. The question is not whether AI is being used somewhere in the workflow, but whether the system is directly interacting with a person in a way that triggers Article 50.
Providers of generative AI systems must ensure that synthetic audio, image, video and text outputs are marked in a machine-readable format and are detectable as AI generated or AI manipulated. The Commission emphasises that the marking should be effective, reliable, robust and interoperable.
There are, however, some important boundaries and exceptions. The FAQ says the obligation does not cover certain outputs, including short sequences of numbers, symbols or letters, source code, outputs intended exclusively for machine-to-machine processing without human exposure, or outputs used only in closed loop industrial and product development environments unless they are the final output. The marking obligation also does not apply where the AI system performs an assistive function for standard editing, and the Commission materials indicate there is also a narrow proportionality-based exemption for some business to business or industrial contexts, subject to conditions set out in the guidelines.
For product, engineering and cybersecurity teams, that is a significant point. Compliance will depend on technical design choices around marking, provenance, detection and interoperability, not just on adding legal wording to terms of use.
Deployers have their own duties, and they are not merely passive recipients of whatever the provider has built. Under Article 50, deployers must inform people when they are exposed to emotion recognition or biometric categorisation systems, and the Commission says this obligation applies whether the systems operate in real time or ex-post. The FAQ expressly links that obligation to the protection of privacy.
Deployers must also clearly label deepfakes. The Commission says disclosure should be made on first exposure at the latest, in a clear and distinguishable way, and must be understandable and perceivable without technical tools or extra user steps. In other words, a hidden machine-readable mark embedded by the provider is not enough on its own for the deployer’s separate disclosure obligation.
There is also a specific rule for AI generated or AI manipulated text published for the purpose of informing the public on matters of public interest where there has been no human review or editorial control. The Commission gives a broad sense of “matters of public interest”, including politics, public administration, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety and wider economic, financial, political, scientific or cultural developments that may be relevant to public debate.
That part of the guidance is particularly relevant for communications, media, public affairs and corporate affairs functions. The exemption for human review or editorial control is not satisfied by superficial checks such as spelling or grammar correction, and the Commission expects substantive review by relevant human decision makers or a responsible editorial entity with authority to approve, alter or reject the text on substantive grounds.
From a privacy perspective, the update is a reminder that transparency under the AI Act overlaps directly with the use of emotion recognition and biometric categorisation tools. Businesses using those tools will need notices that are operationally workable and appropriately timed, not just high-level policy statements.
From a cybersecurity and engineering perspective, the Commission’s repeated focus on machine readable marking, detectability, robustness, reliability and interoperability means transparency needs to be built into technical architecture and content workflows. This is likely to require coordination across product, security, engineering and legal teams, particularly where AI generated content moves between internal systems, customers, platforms and public channels.
From a governance and compliance perspective, the main challenge will be allocation of responsibility. The Commission materials are explicit that different obligations apply to different actors along the value chain, and that businesses need to understand whether they are acting as provider, deployer or both in a particular use case. They will also need a credible way to demonstrate compliance, whether through the approved voluntary Code of Practice for marking and labelling obligations or through alternative equally adequate means.
For UK headquartered organisations, this is still highly relevant if they place AI systems on the EU market, put them into service there, or deploy in scope systems in EU facing operations. The fact that a business sits outside the EU does not make Article 50 a non-issue where its products, services or publishing workflows fall within the AI Act’s scope.
The update should therefore be read as a practical compliance signal for cross-border organisations. UK and EU groups alike will need to map which tools are directly interactive, which generate synthetic content, where deepfake or public interest text labelling could be triggered, and where biometric or emotion recognition functionality is being used.
The headline date is 2 August 2026, when Article 50 starts to apply. There is a limited grace period only for the marking and detection obligation for AI generated content under Article 50(2), and only for AI systems placed on the market before 2 August 2026. For those systems, compliance with that obligation is deferred until 2 December 2026.
The Commission also says content generated before 2 August 2026 does not need to be labelled retroactively, although it encourages relevant deployers to do so where possible.
Enforcement will mainly sit with national market surveillance authorities. The AI Office has a more limited enforcement role for certain systems built on general purpose AI models and for certain very large online search engine or platform contexts, while the European Data Protection Supervisor will enforce the rules for EU institutions, bodies and agencies. The Commission’s materials also flag potentially significant penalties, with fines of up to €15 million or 3% of total worldwide annual turnover for companies, subject to proportionality for SMEs and small mid cap companies.
Businesses should start with a focused scoping exercise. In practice, that means identifying which systems fall into the Commission’s four core categories: direct interaction with natural persons, synthetic content generation or manipulation, deepfakes or public interest text publication, and emotion recognition or biometric categorisation.
They should then test existing controls against the Commission’s operational expectations. For interactive systems, that means checking whether users are informed from the first interaction in a clear and accessible way. For generative systems, it means assessing whether outputs are machine readable, detectable and supported by sufficiently robust technical measures. For deepfakes and public interest text, it means making sure labels are visible or audible where required, and that any claimed human review or editorial control is genuinely substantive rather than cosmetic.
Businesses should also decide whether to rely on the voluntary Code of Practice for the marking and labelling obligations covered by Articles 50(2) and 50(4). The Commission says signatories may benefit from a more streamlined and predictable way to demonstrate compliance, while non signatories will need to evidence alternative equally adequate means.
Finally, teams should document ownership and escalation routes now. The practical burden of Article 50 will cut across legal, privacy, security, product, engineering, marketing and corporate communications functions, and it will be easier to operationalise the new rules if those accountabilities are agreed before the August 2026 go live date.
The Commission has added useful detail, but the guidance still leaves businesses with several fact-sensitive judgement calls. Those include whether an interaction is sufficiently direct and genuinely two way, when it is “obvious” to an average person that they are dealing with AI, what counts as standard editing rather than synthetic content generation, when a business to business or industrial use case may benefit from the narrow exemption discussed in the FAQ, and whether a publication has undergone enough human review or editorial control to avoid labelling.
There will also be practical questions about how businesses evidence that their marking and detection measures are effective, reliable, robust and interoperable, especially as technical standards and state of the art practices evolve. That means governance documentation, technical validation and auditability are likely to become as important as the label itself.
The Commission’s update is therefore best read as both clarification and warning. The rules are now close enough to implementation that businesses should move from AI policy discussion to concrete workflow design, technical controls and accountability mapping.
If you would like to discuss how current or future regulations impact what you do with AI, please contact Tom Whittaker, Brian Wong, Lucy Pegler, Martin Cook or any other member in our Technology team.
Written by Olivia Ward
Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.
Update your preferred sourcesBe sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.
Follow us