Action: The European Union (EU) has begun applying its AI Act’s transparency requirements for certain AI systems and AI-generated or manipulated content.
Trusted Insights for What’s Ahead®
- Under the Act, firms must disclose when people interact with AI in certain circumstances and must make synthetic text, audio, images, and video detectable in a machine-readable format.1 Firms must also disclose AI systems that generate or manipulate text published with the purpose of informing the public on “matters of public interest.”
- The Act’s labeling and disclosure requirements apply both to AI-generated images and video and to AI-generated text and audio content. It also requires disclosure of the use of emotion recognition or biometric categorization systems. Personal data processed by these systems must be handled according to the EU’s General Data Protection Regulation (GDPR) and other laws.
- The European Commission also approved a voluntary Code of Practice (and EU icons) intended to help industry compliance, reduce administrative burdens, and provide legal certainty across the EU.2 This covers three broad areas: safety and security, transparency, and copyright.3
- The Act includes exceptions, such as when it would be obvious to a reasonable person that a person is interacting with an AI system or when permitted for law enforcement purposes. The Act also excludes certain “standard editing” functions or when the AI does not affect the “meaning, style, or intent” of the content. Public-interest text that has undergone “human review or editorial control” is also exempt, though the guidelines specify that superficial human grammar and spelling checks are not sufficient to claim this exemption.
- The US does not currently have a comparable national AI transparency regime; legislation that would establish certain labeling requirements has been introduced in both the House and Senate.
- US policymaking has been active at the state level. For example, California’s AI Transparency Act requires that companies operating AI systems with more than 1 million monthly users offer a free AI detection tool and embed disclosures in AI-generated images, video, and audio. Beginning January 1, 2027, large online platforms (e.g., social media networks) must also display the embedded AI-generated content disclosures. Thirty-one states also have enacted laws regulating political deepfakes.
- What this means for CEOs:
- The requirements have global reach, applying to all systems used in the EU regardless of corporate headquarters. Firms should understand their compliance obligations.
- Features of the guidelines that remain open to interpretation, combined with the rapidly evolving capabilities of AI systems, could create friction between regulators and covered firms and may ultimately lead to litigation. Firms should document how they classify systems and content, the basis for applying any exceptions, and the technical and governance measures used to comply.
- As a growing number of jurisdictions weigh AI labeling requirements, firms will need to navigate a fragmented regulatory landscape and consider how to avoid confusion introduced by overlapping or inconsistent labels.
- Firms that intend to rely on the voluntary compliance regime in the Code of Practice, or one of the provided exceptions, should understand how AI is being used within their organization and provide clear guidelines to employees. Firms should also evaluate vendor contracts to ensure clear allocation of compliance responsibilities.
- As regulators gain experience implementing the rules and AI capabilities continue to advance, policymakers may refine or amend the framework. Firms should monitor regulatory guidance, enforcement activity, and legislative developments and be prepared to adjust their compliance practices accordingly.
- https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
- https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content