Skip to content
Topic Developing

AI Transparency

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal โ€” legal information, not advice.

This new topic is needed to specifically capture the transparency obligations framework for AI systems providers and deployers, which is a distinct and comprehensive requirement under the AI Act that encompasses disclosure of system characteristics, performance metrics, limitations, and intended use to end-users and relevant stakeholders.

5 linked items 3 Laws2 News

Overview

Legal Framework

Article 50 of the AI Act establishes the core transparency obligations for providers and deployers of certain AI systems. It mandates that providers of AI systems intended to interact with natural persons, emotion recognition systems, biometric categorization systems, and AI systems that generate or manipulate image, audio, or video content ("deepfakes") must ensure transparency to end-users. The required disclosures, detailed in Article 50(1) and (2), include informing individuals that they are interacting with an AI system, the system's intended purpose, and its capabilities and limitations. For generated content, the provider must ensure the output is marked as artificially generated or manipulated. Deployers of these systems, as per Article 50(3), must notify a natural person when they are exposed to an emotion recognition or biometric categorization system. Furthermore, Article 50(5) requires deployers of AI systems that generate deepfake content to disclose the artificial nature of that content, unless use is authorized for law enforcement or the content is part of an obvious artistic or creative work.

Practical Application

The provision creates a distinct, purpose-built transparency regime for specific AI applications where a lack of clarity could deceive or manipulate individuals, undermining their autonomy. While the authoritative Tekst & Commentaar on the GDPR clarifies transparency as a fundamental principle for data processing, the AI Act's framework is tailored to the unique risks of AI interaction and content generation, operating alongside but separately from GDPR obligations. The practical burden differs: providers must design systems with transparency in mind (e.g., building in disclosure mechanisms), while deployers have operational duties to activate these disclosures or provide their own notifications. Enforcement will focus on whether the required information is communicated in a clear, timely, and meaningful way to the affected individual.

Key Considerations

  • Mapping Obligations by Role: Organizations must first determine if they act as a "provider" or "deployer" under the AI Act for their AI systems and then apply the specific transparency duties attached to that role and system type (e.g., interaction, emotion recognition, deepfake generation).
  • Integrating with GDPR: For AI systems that also involve personal data processing, the transparency requirements under Article 13 GDPR (providing information to data subjects) continue to apply and must be coordinated with, not replaced by, the AI Act's Article 50 disclosures.
  • Technical Implementation for Providers: Providers of in-scope systems must design technical solutions to embed disclosures (e.g., real-time notifications for AI interaction) or output markings (e.g., watermarking for generated content) directly into the system or its outputs to enable compliance by deployers.
Everything on this topic, by type links go to the exact provision / paragraph / section