This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
The Lens

Digital developments in focus

| 4 minute read

EU Clarifies AI Transparency Duties as Deadline Looms

The AI Act’s transparency rules (or most of them at least) apply from 2 August 2026, with the goal of increasing transparency of AI-generated or manipulated content. Having published the Code of Practice in June (see our blog), the Commission has now released guidelines which are intended to complement the Code and help both providers and deployers comply with their Article 50 AI Act (‘AIA’) transparency obligations. 

What are the transparency rules?

The AIA’s transparency rules require:

  • Providers of AI systems to: (i) design their AI systems in a way that ensures people know when they are directly interacting with an AI system, unless this is obvious (Art 50(1)); and (ii) add machine-readable marks which allow AI-generated or manipulated content to be identified, subject to exceptions (the so-called watermarking rules) (Art 50(2)); and
     
  • Deployers (i.e. users) of AI systems to: (i) inform individuals when they are exposed to emotion recognition and biometric categorisation tools (Art 50(3)); and (ii) where the AI system can create deepfakes, disclose that any deepfake content is AI-generated or manipulated (Art 50(4)).

What do the guidelines cover?

The (non-binding) guidelines provide additional detail on some key concepts and definitions from the AIA, and practical examples to explain how to comply. 

This includes additional detail on general concepts from the AIA, for example:

  • Deployers: to qualify as a deployer, an organisation must be using an AI system under its own authority (i.e. by assuming responsibility over the decision to deploy the system and over the manner of the actual use of the system (including its outputs)).  This means, for example, that a company that commissions an ad agency to produce an advert without taking decisions or exercising control over whether and how the ad agency uses AI in its production, would not be a deployer (and would not therefore need to comply with the deployer transparency obligations). This raises interesting questions about how involved an organisation may want to be where it partners with suppliers using AI.  
     
  • Extra-territoriality: The AIA applies to non-EU providers and deployers if the output of their AI system is used in the EU. While the scope of this remains somewhat unclear, the guidelines helpfully confirm that incidental, unforeseeable or unauthorised downstream use alone should not trigger the AIA’s application.  We might expect this to influence providers’ licensing and usage terms (some providers may try to restrict users outside the EU from using outputs in the EU, to avoid the risk of breach). 
     
  • Cumulative obligations: A single AI System (or its output) could trigger multiple AIA obligations for different actors (providers or deployers). For example, an AI system that interacts directly with an individual and generates content could trigger both provider transparency rules (Art 50(1) and 50(2)). If that same system was then used to generate deepfakes, that could also trigger some deployer transparency rules, and if it was instead used for a high-risk purpose (such as recruitment) it could trigger the high-risk rules.  

The guidelines also include guidance on concepts specific to the transparency rules, for example:

  • The transparency rules apply to agents: The commission has previously confirmed in its general FAQs that the AIA applies to agents and the guidelines reiterate this in relation to the transparency rules. The output of an agent must be managed in line with the transparency rules and agents must be designed and developed so that they disclose both the fact they are ‘artificial’, and the person they are acting for ( - this second requirement is new in the guidelines, and is not an express requirement of the AIA). The guidelines go on to discuss how: (i) it may be difficult to know in advance when an agent will interact with an individual, but the agent should be designed to disclose itself wherever this is likely; and (ii) agents should disclose themselves to the person instructing them at key steps in the process and at every new interaction. 
     
  • Repeated disclosures: The need for repeated disclosures is discussed in several places. For example, the guidelines confirm that provider disclosures under Art 50(1) may not need to be continuous, and in many cases a single, prominent notification before the first interaction with an AI system is sufficient. This will, however, not always be the case – for example where children, vulnerable adults or agents (see above) are involved. The guidelines also give details on how to manage disclosures in practice - for example, information must be provided in a clear and distinguishable manner and a general disclosure like ‘services on this website use AI’ is not sufficient.
     
  • Marking and detection both needed: While providers must ensure that relevant AI outputs are marked as artificially generated, for every marking solution deployed they should also ensure there is a corresponding means for detection which provides human readable results. The guidelines also state that providers may use a single marking technique or combination of techniques to satisfy this requirement. 
     
  • Exemptions: The guidelines provide further details on various exemptions and exceptions to the transparency rules. It confirms, for example, that while it is not necessary for providers to disclose interactions with an AI System where this is obvious to the ‘reasonably well-informed, observant and circumspect natural person’ (a standard taken from consumer law), this will be narrowly construed.  It also confirms that certain outputs, including source code, fall outside of the provider watermarking rules, as do AI systems that perform an ‘assistive function for standard editing’ or minor alterations. Spell checking, minor colour adjustments and AI translations all benefit from this exception. 

Next steps

Both providers and deployers now have more guidance on how to comply with the transparency rules, from the Code of Conduct and guidelines to the FAQs and fact sheets that accompany them. 

However, this new guidance has come extremely close to the rules coming into force. While the AI omnibus extended the compliance deadline for the provider watermarking rules for AI systems already on the market to December, the rest of the transparency rules start to apply in only a few weeks – and for providers who have not signed up to the Transparency Code of Practice, the guidelines suggest they carry out a gap analysis of their plans against the code (and now informed by the guidelines). 

It seems inevitable that provider compliance will be a mixed picture in the early days, and that the user experience in the EU will be inconsistent (and in some cases jarring) as providers and deployers adapt to the rules.  

Sign up to receive the latest insights. Click here to subscribe to The Lens Blog.

Tags

ai, digital regulation