AI Information Duties
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the AI Act imposes specific duties on providers to inform relevant parties (users, authorities, affected persons) about corrective actions, incidents, and system modifications, which represents a distinct compliance obligation that warrants separate topical coverage.
Overview
15 sources · Sep 25, 2026Legal Framework
The AI Act establishes a layered set of information duties that bind different actors across the AI value chain. The primary provisions governing transparency and information to deployers are found in Article 13 of the AI Act, which requires that high-risk AI systems be designed and developed with sufficient transparency for deployers to interpret outputs and use them appropriately. Providers must accompany their systems with instructions for use in a suitable digital or other format containing concise, complete, accurate, and clear information that is relevant, accessible, and understandable to deployers.
Those instructions must cover, at minimum, the provider's identity and contact details, the system's characteristics, capabilities, and performance limitations, predetermined modifications, human oversight measures, and computational requirements. The article specifies:
"AI-systemen met een hoog risico gaan vergezeld van gebruiksinstructies in een passend digitaal of ander formaat dat beknopte, volledige, juiste en duidelijke informatie bevat die relevant, toegankelijk en begrijpelijk is voor gebruiksverantwoordelijken."
— AI Act Art. 13(2)
A separate information regime applies to notified bodies under Article 45 of the AI Act, which requires them to inform notifying authorities of certification decisions, refusals, suspensions, and withdrawals, and to share information with other notified bodies about negative conformity assessment results. Recital 120 adds a further dimension: providers and deployers must enable detection and disclosure of artificially generated or manipulated outputs, linking AI Act transparency duties to the DSA's systemic risk framework for very large online platforms.
Key Developments
Enforcement remains in its early stages, but data protection authorities are already applying GDPR information principles to AI systems. The EDPB's Opinion 28/2024 emphasizes that given the complexity of AI technologies, information about processing of personal data within AI models must be delivered in an accessible and user-friendly manner:
"Considering the complexity of the technologies involved, information on the processing of personal data within AI models should therefore be provided in an accessible, understandable and user-friendly way"
— EDPB Opinion 28/2024 §52
The Italian Garante has begun sanctioning AI operators for inadequate transparency: a €158,000 fine against Character.AI and a €55,000 fine against the Agency for Digital Italy signal that DPAs will scrutinize whether information provided to users meets both GDPR Article 13 standards and emerging AI Act expectations. The EDPB ChatGPT Taskforce report further underscores that transparency obligations are a focal point for cross-border enforcement coordination.
Status of the Debate
This topic is regulator-defined. The AI Act's information duties are newly codified, with no case law yet testing their boundaries. The provisions are detailed but leave interpretive gaps—particularly around what constitutes "sufficient transparency" for deployers under Article 13(1) and how AI Act duties interact with GDPR transparency requirements. The EDPB and national DPAs are filling this space through guidance and early enforcement, but no court has ruled on the scope or adequacy of AI-specific information duties. Resolution will likely come through the first wave of AI Act enforcement actions and any subsequent CJEU preliminary references on the interplay between AI Act and GDPR information obligations.
Practical Guidance
- Map your information duties by actor role. Providers of high-risk AI systems must prepare deployer-facing instructions under Article 13; deployers in turn face separate transparency duties toward affected persons. Identify which role you occupy and audit accordingly.
- Ensure instructions for use cover all mandatory elements. Article 13(3) lists minimum content—identity and contact details, system capabilities and limitations, predetermined modifications, human oversight measures, and hardware requirements. Gaps here are a direct compliance failure.
- Align AI Act and GDPR information practices. Where personal data is processed, information must satisfy both regimes. The EDPB stresses accessibility and understandability; boilerplate privacy notices will not suffice for AI-driven processing.
- Prepare for artificial content disclosure obligations. Recital 120 links AI Act duties to DSA systemic risk mitigation—providers and deployers of systems generating manipulated content must enable detection and disclosure, particularly where very large online platforms are involved.
- Establish incident and modification reporting channels. Notified bodies under Article 45 must inform authorities of certification changes; providers should build internal workflows to ensure timely information flows to regulators and other notified bodies.
Nothing of this type on this topic.