Skip to main content
EU AI Act Transparency Obligations: Your 2026 Readiness ChecklistEU AI Act & GPAI
5 min readFor Legal & Compliance Officers

EU AI Act Transparency Obligations: Your 2026 Readiness Checklist

The EU AI Act's transparency obligations take effect on 2 August 2026. If you're deploying AI systems that interact with users or generate content, you have thirteen months to get your compliance infrastructure in place.

This isn't about checking a box. The European Commission published detailed guidelines in July 2025 clarifying what "transparent by design" means in practice. Your team needs to implement technical controls, update disclosure protocols, and document compliance evidence before the enforcement window opens.

This checklist walks through the specific obligations that apply to providers and deployers of AI systems under Articles 50(2), (4), and (5). Each item includes the requirement reference, what compliance looks like, and the evidence you'll need when enforcement begins.

Prerequisites

Before you start this checklist, confirm:

  • You've classified your AI systems under the EU AI Act's risk tiers. Transparency obligations vary by use case, not just by model architecture.
  • You know whether you're a provider or deployer as defined by the AI Act. Providers design systems; deployers use them under their own authority. Your obligations differ.
  • You have access to your technical documentation (Annex IV if you're a high-risk provider). Transparency compliance builds on existing documentation requirements.
  • You understand the August 2026 timeline. Systems placed on the market before 2 August 2026 must comply with content-marking obligations by 2 December 2026. New systems must comply immediately.

Transparency Compliance Checklist

For Providers of AI Systems

1. Design systems to inform users of direct AI interaction (Article 50(1))

Your AI system must notify users when they're interacting with it, not a human. This applies to chatbots, virtual assistants, and any conversational interface.

Compliance looks like: A clear, persistent indicator in the user interface stating "You are chatting with an AI assistant." The disclosure appears before the user submits their first input, not buried in terms of service.

Evidence: UI mockups, user flow documentation, and test screenshots showing the disclosure at first interaction.

2. Implement machine-readable watermarking for AI-generated content (Article 50(2))

If your system generates or manipulates images, audio, or video, it must embed detectable metadata or watermarks enabling automated detection.

Compliance looks like: Content includes C2PA or IPTC metadata fields populated with provenance information. The watermark survives common transformations (compression, cropping) and can be verified by third-party detection tools.

Evidence: Technical specification of your watermarking implementation, sample outputs with embedded metadata, and test results from detection tools.

3. Document exemptions if you claim them (Article 50(3))

The Commission's guidelines list specific exemptions: AI for accessibility, certain security applications, and systems where disclosure would defeat the purpose. If you're claiming an exemption, document why it applies.

Compliance looks like: A written legal analysis explaining which exemption applies, the specific use case, and why alternative transparency measures aren't feasible. Reviewed by legal counsel.

Evidence: Exemption justification memo, use case description, and approval from your legal team.

4. Prepare to demonstrate compliance through the Code of Practice (Article 50(4))

The Commission concluded that the Code of Practice on Transparency of AI-generated content adequately covers Article 50 obligations. Signing the code doesn't guarantee compliance, but it shows you're following EU-wide guidance.

Compliance looks like: Your organization has reviewed the code's commitments, mapped them to your systems, and signed as a participant. You've documented which measures you've implemented.

Evidence: Signed participation agreement, internal mapping of code measures to your systems, and implementation status tracker.

For Deployers of AI Systems

5. Disclose deep fakes to the subjects depicted (Article 50(4))

If you deploy a system that generates or manipulates images, audio, or video resembling real people, you must inform those individuals that the content is artificially generated.

Compliance looks like: A documented notification process that triggers when your system creates content depicting identifiable individuals. The notice explains what was generated and provides contact information for questions.

Evidence: Notification template, process flowchart, and logs showing when notifications were sent.

6. Label AI-generated content on matters of public interest (Article 50(4))

When you publish AI-generated or AI-manipulated content addressing public interest topics (politics, health, safety), you must disclose the AI's role. This applies even if a human reviewed the output.

Compliance looks like: A visible disclaimer on each piece of content: "This article was generated with AI assistance" or "This image was created using AI." The label appears with the content, not just in a general site disclaimer.

Evidence: Content labeling policy, sample labeled outputs, and editorial workflow documentation showing where the label gets applied.

7. Inform users of emotion recognition systems (Article 50(5))

If you deploy an AI system that infers emotions from biometric data (facial expressions, voice tone), you must tell the people being analyzed.

Compliance looks like: Signage in physical locations ("This area uses AI-based emotion detection") or on-screen notices in digital contexts before data collection begins. The notice explains what's being detected and why.

Evidence: Notice templates, placement documentation (photos of signage or screenshots), and legal review confirming adequacy.

8. Disclose biometric categorization systems (Article 50(5))

Systems that categorize people based on biometric data (age estimation, demographic inference) require explicit disclosure before use.

Compliance looks like: A consent flow or mandatory notice explaining that the system will categorize individuals based on biometric characteristics. Users understand what's happening before they proceed.

Evidence: User flow documentation, consent records, and technical controls preventing use without disclosure.

Common Mistakes

Treating transparency as a one-time implementation. The Commission will facilitate formal code updates at least every two years. Your compliance program needs ongoing review cycles.

Assuming watermarking is optional for internal systems. Article 50(2) applies to providers regardless of whether content leaves your organization. If you generate manipulated media, you need detectable marks.

Burying disclosures in privacy policies. The guidelines emphasize that users must recognize AI interaction in context. A link to a 40-page policy doesn't meet the standard.

Confusing provider and deployer obligations. If you fine-tune a foundation model and deploy it in your own application, you may be both. Map obligations to each role separately.

Ignoring the December 2026 deadline for legacy systems. You get four extra months for content marking if your system was already on the market, but that's not much runway for technical implementation.

Next Steps

By September 2025: Complete your provider/deployer classification and map which transparency obligations apply to each system.

By December 2025: Implement technical controls (watermarking, user notifications) in development and staging environments. Begin testing detection and disclosure mechanisms.

By March 2026: Conduct internal compliance audits. Document your implementation, collect evidence, and identify gaps.

By June 2026: Finalize all implementations, train relevant staff on disclosure protocols, and prepare your enforcement response plan.

The AI Office has 145 staff, with fewer than a quarter working directly on regulation and compliance. That doesn't mean enforcement will be lenient. When enforcement powers activate on 2 August 2026, fines can reach 3% of annual revenue. Your compliance posture needs to be defensible under scrutiny, not just documented for show.

Start with the technical requirements. Watermarking and user notifications require engineering work, not just policy updates. Everything else flows from those foundations.

You Might Also Like