5 min read

AI Act transparency: who owns what your AI says?

Disclosure is one part of AI transparency. The operating challenge is knowing which systems speak for the business, which obligations apply, and who can demonstrate that the right controls were in place.


A company can add an “AI assistant” label to its chatbot and still have little control over what the system says. It may make unsupported promises, publish material nobody has substantively reviewed or lose important disclosure information as content moves between tools.

The label helps the audience understand an interaction. It does not settle the authority of the system or the company’s responsibility for using it.

The EU AI Act’s transparency rules turn this into a practical management question: can you identify where AI reaches people, establish which rules apply and show who owns the response?

The Obligation

Start with the obligation and the applicable date

The European Commission states that Article 50’s transparency obligations apply from 2 August 2026. They cover several different situations, including direct AI interactions and certain synthetic content. They do not create a universal requirement to label every sentence that AI helped produce.

There is an important transition to distinguish from that general date. Article 111(4) of the current consolidated regulation gives providers of relevant systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2), the machine-readable marking obligation. That provision does not postpone all of Article 50.

A compliance plan built around a single date can therefore misclassify the work. Record the particular obligation, the organization’s role and the applicable transition for each system.

The Role

Establish which role your business occupies

The Act distinguishes the provider of a system from the organization using it under its authority, the deployer. A business that develops or commissions a system and places it on the market or puts it into service under its own name may have provider responsibilities. Buying access and using the system may instead put it in the deployer role.

The Commission’s questions and answers also explain that a legal entity can remain the deployer when contractors operate a system on its behalf and under its control.

For management, the implication is that outsourcing the work does not eliminate the need to understand your own role. A supplier should describe its responsibilities, while your team establishes the obligations attached to your use.

Ask legal and technical specialists to assess the actual arrangement. Branding, integration and changes to a system deserve examination; a product’s marketing category cannot decide the legal classification.

The Interaction

Separate direct interaction from the work behind it

For systems intended to interact directly with people, Article 50(1) requires providers to design for informing them that they are interacting with AI, unless that is obvious in context. Article 50(5) requires the relevant information to be clear, distinguishable and accessible by the first interaction or exposure.

This makes the point of contact important. A customer-facing conversational agent and a tool that prepares notes for a human employee do not present the same interaction.

Beyond that disclosure requirement, I would examine the operational authority. What can the system promise? When must it refer the matter to a person? Who can suspend it? These are management controls, not a claim that Article 50 alone prescribes every element of customer-service design.

Walk through the actual experience. A disclosure written in a specification can be absent or obscured in the deployed interface. A system update can alter the experience without changing the company’s policy document.

The Disclosure

Keep machine-readable marking and public disclosure distinct

The Commission separates provider-side marking of generated content from deployer obligations to inform people about particular uses. These include deepfakes and certain public-interest text, as well as emotion recognition and biometric categorization.

For a business, the practical task is to understand what happens to content as it moves from generation to publication. Technical marking in a file and a disclosure that a person can perceive serve different purposes.

Identify who generates the asset, who edits it, where it is published and what evidence accompanies the final version. Do not assume that a mark present in the original survives every export or publishing step.

THE THROUGH-LINE

Equally, do not treat a visible label as proof that the underlying content is accurate or that the use itself is permitted. Transparency obligations sit alongside other applicable rules.

Editorial Control

Editorial responsibility requires substantive review

For AI-generated or manipulated text published to inform the public on matters of public interest, Article 50(4) includes an exception where human review or editorial control has taken place and a person or legal entity holds editorial responsibility.

The Commission explains that this involves examination of substance and the authority to approve, change or reject it. Spelling and grammar checks alone do not qualify.

That distinction matters well beyond the label. A named editor needs access to the sources and enough expertise to challenge the claims. If nobody can investigate a figure, question the interpretation or stop publication, the workflow has allocated a name without providing the means to exercise responsibility.

I would keep a proportionate record of the source material, substantive review and final approval. The useful evidence is that someone examined the argument and could change the outcome.

The Call

Make transparency an owned part of operations

Begin with an inventory of AI interactions and published outputs across customer service, marketing, employee communication and other relevant functions. Include systems introduced by individual teams or external agencies.

For each use, record the role assessment, applicable disclosure or marking requirement, implementation owner, review procedure and evidence of the current version. Agree which changes require reassessment. A new output format or a shift from human-mediated assistance to direct customer interaction can change the question.

Ask suppliers how relevant capabilities are maintained through updates and what evidence they can provide. Then test the points your own organization controls.

Article 50 does not resolve every AI, privacy or sector-specific obligation. Have the precise scope and exceptions checked for your circumstances. The management work can still start immediately: identify the systems speaking in the company’s name and require an accountable owner to explain how each is governed.