Back to Blog

EU AI Act Transparency Rules: A Website and Content Checklist

·17 min read·Rendframe·EU AI Act, AI Governance, Compliance, AI Content

A company uses an AI assistant on its website, generates a campaign image, and asks a model to draft a policy article. Does it need three “made by AI” labels, one, or none? Since 2 August 2026, the EU AI Act has made that a live operational question—but the answer depends on the system, the company’s role, the audience, the content, and the review process.

Editorial flow diagram in which an AI interaction and synthetic content pass through role, review, and disclosure checks before publication
Do not label everything blindly. Map the role, exposure, content type, and review path first.

The useful reading of Article 50 is narrower than “every use of ChatGPT needs a badge” and more demanding than “our vendor handles compliance.”

This guide turns current European Commission guidance into a working audit for websites, customer assistants, marketing, and publishing. It is not legal advice; have qualified counsel confirm borderline cases, sector rules, and territorial scope.

The short answer: classify before you disclose

Article 50 transparency duties apply from 2 August 2026. The Commission’s current guidance identifies four practical surfaces:

  • Direct AI interaction: providers must design systems so people know from the start that they are interacting with AI, unless that fact is genuinely obvious.
  • Machine-readable provenance: providers of systems that generate synthetic text, image, audio, or video must support marking and detection, subject to defined exceptions and technical proportionality.
  • Emotion recognition and biometric categorisation: deployers must inform exposed people that the system is operating.
  • Deepfakes and certain public-interest text: deployers must give people a clear, perceivable disclosure. For public-interest text, substantive human review or editorial control with real responsibility can provide an exception.

A machine-readable mark hidden in a file does not replace a disclosure that a person can see or hear. A caption added by a marketing user does not fulfil a system provider’s technical marking duty.

Decision orderRole before label
01

Who are you?

Provider, deployer, or both for this exact system?

02

Who is exposed?

An EU user, employee, customer, or only another machine?

03

What happens?

Direct interaction, synthetic content, biometrics, or background processing?

04

What control exists?

Clear notice, provenance, qualified review, responsibility, and evidence?

First decide whether the business and system are in scope

A provider develops an AI system, has one developed, or places it on the EU market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority for professional purposes. A company can be a deployer for a purchased writing tool and a provider for a customer assistant it packages under its own brand.

Classify every system, not the company once. Rebranding, substantial changes, custom orchestration, or service under your name can change the analysis. Record the vendor, model, interface, data, tools, and business owner.

Non-EU incorporation is not an automatic escape. The Commission explains that the framework can reach actors outside the Union when a system is placed on the EU market, used in the EU, or its output is used there. For a Ukrainian SaaS company selling to customers in Poland or Germany, the relevant question is therefore not “are we in the EU?” but “where is this system offered, used, and producing effects?”

Six common business cases

ScenarioLikely Article 50 questionPractical action
Website support assistantIs this a genuine direct two-way AI interaction, and who provides the system?Show the AI identity at the first interaction; confirm the provider/deployer split and test the production interface.
Scripted FAQ or formDoes it qualify as an AI system and genuine interaction at all?Do not call a decision tree “AI” for theatre. Document why it is in or out of scope.
Virtual spokesperson resembling a real personCould the image, voice, or video falsely appear authentic?Treat it as a potential deepfake; make the disclosure visible or audible on first exposure.
Generative product backgroundDoes it resemble a real place, object, event, or circumstance in a misleading way?Assess the actual depiction and consumer context; also apply ad-platform and consumer-protection rules.
AI-drafted public-interest articleWas it substantively reviewed, controlled, and accepted by an accountable editor?Label it if no qualifying review exists. If relying on the exception, retain the review trail.
Internal invoice summaryIs anyone externally exposed to a covered interaction or publication?Article 50 labelling may not be the issue; privacy, security, accuracy, access, and AI literacy still are.

For chatbots, put the truth in the first screen

The Commission says the interaction duty concerns systems designed for a genuine two-way exchange in which the AI itself communicates directly with a natural person. A background fraud score, a machine-to-machine job, or a form that merely collects data is different. The notice is expected at the start of the first interaction, clearly and accessibly.

The “obvious” exception should not become a design strategy. A sparkle icon, human name, animated portrait, or generic “assistant” label can make the system less obvious, not more. If the interface can be mistaken for a person, state the system’s nature in plain language before the first answer.

Do not assume a vendor contract closes the question. Check the production widget, mobile layout, voice mode, messaging channels, accessibility tree, and human handoff. Material changes or branding may create provider duties of your own.

For content, separate provenance from audience disclosure

Providers of generative systems have the technical marking and detection task. Most businesses using an off-the-shelf generator are deployers, but should still preserve available provenance through export, resizing, transcoding, and CMS ingestion.

Deployers have visible disclosure duties for deepfakes. The legal definition focuses on AI-generated or manipulated image, audio, or video that resembles an existing person, object, place, entity, or event and could falsely appear authentic or truthful. Not every generative illustration is a deepfake. Context, resemblance, audience expectation, and likelihood of deception matter.

Public-interest text has a different test. The Commission lists areas such as politics, public services, justice, rights, security, public health, environmental protection, consumer safety, and economic, financial, scientific, or cultural developments relevant to public debate. AI-generated or manipulated text published to inform the public in those areas must be labelled when it lacks qualifying human review or editorial control.

That does not create a blanket labelling rule for every product description, email, or edited draft. It also does not make ordinary marketing risk-free. Consumer law, sector regulation, intellectual-property rules, privacy, contracts, and platform policies may require accuracy or disclosure even when Article 50 does not.

“A human looked at it” is not an editorial process

The Commission’s current Q&A draws a useful line. Qualifying human review is a deliberate examination of substance by someone with relevant knowledge and professional judgement. Editorial control means the responsible editor can approve, alter, or reject the substance, fact-check it, and assess the reliability of sources. Spell-checking, formatting, or pressing approve is not enough.

Build the workflow around evidence:

  1. name the reviewer and the subject competence required;
  2. store the draft, cited sources, material corrections, and approved version;
  3. give the reviewer authority to reject publication, not merely suggest changes;
  4. name the natural or legal person holding editorial responsibility;
  5. repeat review when facts, models, prompts, or automation change materially.

A ten-day transparency audit

Days 1–2InventorySystems, vendors, models, channels, owners, countries, and audiences
Days 3–4ClassifyProvider/deployer role, interaction, output type, public-interest and deepfake tests
Days 5–7ImplementNotices, labels, preserved provenance, editorial gates, accessibility, and handoff
Days 8–10ProveProduction tests, screenshots, review records, vendor evidence, and approval

Start with exposure, not procurement history. Check site chat, messaging, voice, automated support email, campaign assets, avatars, help-centre publishing, social scheduling, and agency tools. Their work belongs in the inventory.

For each item, record: system and version; business owner; provider; deployer; purpose; markets; audience; input and output types; direct interaction; synthetic-content types; public-interest relevance; deepfake risk; review owner; editorial responsibility; notice or label; machine-readable provenance; accessibility check; retention location; and last review date.

Prioritise live customer interaction, realistic synthetic people or events, automatically published public-interest text, and any emotion-recognition or biometric categorisation. Then review lower-exposure internal uses.

Write a disclosure a person can actually understand

A useful chatbot notice can be short: “You are chatting with an AI assistant. It can make mistakes. Ask for a person before changing an account or relying on an important answer.” Adapt the last sentence to the product; Article 50 requires transparency, while your risk controls determine handoff and restricted actions.

For content, name the intervention precisely: “Voice generated with AI”, “AI-generated image of a fictional scene”, or “This public-information summary was generated by AI and was not reviewed by an editor.” The Commission provides optional EU icons, but says the icon alone does not establish compliance. Its user testing found better recognition when an icon was paired with text.

Place the disclosure at first exposure, not behind a legal link. Keep it visible in downloads and reshares where the chosen method allows. Add meaningful alt text or an accessible name, maintain contrast, and make timed labels stay long enough to be understood.

Keep a small evidence pack

A compliance claim without a production check is fragile. Keep the classification memo, supplier documentation, screenshots or recordings of first interaction, test date and locale, content-provenance result, reviewer identity, substantive review record, accessibility result, exceptions relied on, approval, and next review date.

Re-run the check after a model swap, new channel, new geography, voice or avatar launch, automated publishing, removal of human review, or material vendor change. Assign one owner who can stop publication or deployment when the evidence is incomplete.

What changed in August—and what did not

Article 50 applies from 2 August 2026. The narrow grace period until 2 December 2026 concerns the provider-side machine-readable marking and detection duty for systems placed on the market before 2 August. It is not a general postponement for chatbot notices, deepfake disclosure, or unreviewed public-interest text. Content generated before 2 August does not need retroactive labelling under this rule, although voluntary disclosure is encouraged.

The AI Omnibus that entered into force on 27 July 2026 changed parts of the wider timetable, including high-risk-system dates. Do not let headlines about those extensions obscure the transparency rules already applying now.

Article 4 AI-literacy measures are separate. Providers and deployers must support relevant staff and others operating AI on their behalf with context-appropriate literacy; the Commission states that no specific individual proficiency level is mandated. Privacy, security, consumer protection, accessibility, employment, sector, and contract duties also continue to apply.

Frequently asked questions

Does every AI-generated text need a label in the EU?

No. Article 50’s deployer disclosure covers AI-generated or manipulated text published to inform the public on matters of public interest when qualifying human review or editorial control is absent. Other laws or platform rules can still require disclosure.

Must a website chatbot say it is AI?

Providers of directly interactive AI systems must design them so people are informed from the start, unless the AI nature is obvious. A business deploying the system should verify the live notice and clarify whether its customisation makes it a provider too.

Is light human editing enough to avoid an AI-text label?

No. The Commission says spell-checking, grammar fixes, or procedural approval are not substantive review. The reviewer needs relevant judgement and authority, and a person or organisation must hold editorial responsibility.

Can the EU AI Act affect a company outside the EU?

Yes. The framework can apply where a system is placed on or used in the EU market, or its output is used in the EU. Confirm the facts and territorial analysis with qualified counsel.

What is the Article 50 deadline?

The transparency duties apply from 2 August 2026. A narrow transition until 2 December 2026 applies only to provider-side marking and detection for certain systems placed on the market before 2 August.

Build transparency into the system, not the footer

The fastest safe route is a small, testable control system: inventory the AI surfaces, assign the legal and technical role, show the right notice at the right moment, preserve provenance, require real review where needed, and retain evidence. That work improves trust and operational quality even when a lawyer ultimately concludes that a particular label is not mandatory.

Rendframe can audit the technical and product side of a customer-facing AI system—interface disclosure, accessibility, content provenance, editorial gates, human handoff, logging, and release tests—while your counsel owns the legal conclusion. Explore our AI systems engineering and AI training, or send us the system and markets you need reviewed.

Continue reading: use the AI assistant brief to document roles and controls, then build an AI-literacy programme that changes the work.

Sources and review date

Reviewed 18 August 2026 against the European Commission’s Article 50 questions and answers, transparency guidelines, quick facts, AI-content labelling guidance and icons, AI-literacy Q&A, and the official Regulation (EU) 2026/1744 amending the AI Act. Guidance and national enforcement practice can change; re-check current sources and obtain legal advice for a live system.