FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Governance · 5 minute read

EU AI Act Transparency Obligations: Who Must Tell Whom

EU AI Act transparency obligations require telling people when they are interacting with an AI system, marking synthetic content in a machine-readable way, informing people subject to emotion recognition or biometric categorisation, and disclosing deepfakes. They apply regardless of risk classification.

By FISTA Solutions· AI-Native Engineering Team·
EU AI Act Transparency Obligations: Who Must Tell Whom article cover

Transparency obligations under the EU AI Act are the ones most likely to affect an ordinary product, because they apply based on what a system does rather than on risk classification. A customer service assistant can carry disclosure duties while sitting well outside the high-risk categories. This guide covers who must tell whom, drawing on FISTA Solutions' AI agents work. This article is general guidance, not legal advice.

What do the obligations cover?

SituationObligationWho carries it
AI system interacting with peopleInform them it is AIProvider, by design
Synthetic audio, image, video, textMachine-readable markingProvider
Emotion recognition or biometric categorisationInform those exposedDeployer
Deepfake contentDisclose it is artificially generatedDeployer
AI-generated text published on matters of public interestDisclose, with conditionsDeployer

What does interaction disclosure require?

That people are informed they are interacting with an AI system, unless that is obvious from the circumstances to a reasonably observant and circumspect person.

The practical test is whether a typical user would know — not whether the information exists in a terms page nobody reads. A chat interface that presents as a person, uses a human name, and never says otherwise does not meet the spirit of this even if a disclosure sits three clicks away.

How should synthetic content be marked?

In a machine-readable format allowing detection that the content was artificially generated or manipulated. That means embedded provenance signals rather than only a visible label.

Visible disclosure and machine-readable marking serve different purposes: one informs the person looking at it, the other allows platforms and tools to detect it downstream. Both matter. See what is content provenance.

What about emotion recognition?

Deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them.

Separately, certain uses of emotion recognition in workplaces and educational settings fall within the Act's prohibitions rather than merely its transparency rules. Establish which side of that line a proposed use sits on before building anything.

Are there exceptions for creative work?

There are carve-outs where content is evidently artistic, creative, satirical, or fictional, with disclosure adapted so it does not spoil the presentation of the work.

Those exceptions are narrow. The default is disclosure, and a commercial product is unlikely to sit inside them.

Who carries each obligation?

Some sit with providers and are met by design — interaction disclosure and machine-readable marking are built into the system. Others sit with deployers and are met by operation, including informing people exposed to emotion recognition and disclosing deepfake content.

Organisations that build and deploy their own systems carry both, which is the common case.

How should disclosure be designed?

Into the product rather than added as a footnote. Disclosure that is visible at the point of interaction, in plain language, and that does not require the user to go looking.

Products that treat this as a legal checkbox produce a line of small text nobody reads, which satisfies nobody including the regulator. Treating it as a design problem generally produces a better product, because users behave differently when they know what they are talking to.

How do these interact with other obligations?

They stack. A high-risk system that interacts with people carries both the high-risk requirements and the transparency ones, and a system outside the high-risk categories can still carry transparency duties.

Classification is not a single verdict; it is several questions with separate answers. See EU AI Act high-risk obligations.

When do these apply?

The Act applies in phases. Confirm the current dates for the specific obligations you carry rather than relying on a general summary, and account for transitional arrangements.

What does compliance cost?

Little, if designed in. Disclosure is a product decision, marking is a pipeline decision, and both are cheap at design time.

Retrofitting provenance marking into a content pipeline already in production is considerably more expensive, because the pipeline was not built to carry the metadata.

What are the common mistakes?

Hiding disclosure in terms of service. Adding a visible label without machine-readable marking. Assuming a low-risk classification removes all obligations. And treating creative carve-outs as broader than they are.

Who owns this internally?

Product, with legal support. These are product design decisions with legal consequences rather than legal documents with product consequences, and treating them the other way round produces worse outcomes on both counts.

What should you do first?

List every place your products generate content or interact with people, and check what each one currently discloses. Most organisations find at least one interface where the answer is nothing.

What evidence should you keep?

A record of what each interface discloses, when the disclosure was introduced, and what marking the content pipeline applies. Screenshots age badly; a written record tied to a release is better.

For content pipelines, keep evidence that marking is actually applied rather than merely configured. Pipelines change, and a marking step that was removed during a refactor is the kind of failure nobody notices until someone asks.

How FISTA Solutions helps

FISTA Solutions builds disclosure and provenance into products by design: interaction disclosure presented at the point of use in plain language, machine-readable marking built into content pipelines rather than added afterwards, and obligations assessed per interface rather than assumed from a single classification. Delivery runs through AI agents, AI enablement, and web and mobile. The record is 150+ projects for 50+ companies across 12+ countries.

To review disclosure across your products, message FISTA on WhatsApp, or read what is AI watermarking.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Do transparency obligations apply to low-risk systems?

Yes. They apply based on what the system does rather than on risk classification, so an ordinary customer-facing assistant can carry disclosure duties while sitting outside the high-risk categories entirely. This is general guidance, not legal advice.

02What does interaction disclosure require?

That people are informed they are interacting with an AI system, unless it is obvious from the circumstances to a reasonably observant person. The practical test is whether a typical user would know, not whether the information exists somewhere.

03How should synthetic content be marked?

In a machine-readable format that allows detection of artificial generation or manipulation, which means embedded provenance signals rather than only a visible label. Visible disclosure and machine-readable marking serve different purposes.

04What about emotion recognition?

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Some uses of emotion recognition in workplaces and education are prohibited outright rather than merely regulated.

05Are there exceptions for deepfakes?

There are carve-outs where content is evidently artistic, creative, satirical or fictional, with the disclosure adapted so it does not spoil the work. Those are narrow, and the default is disclosure.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project