The EU AI act makes AI disclosure a business requirement
August 2 is the key date. From then, the EU AI Act’s transparency rules require providers and deployers of covered AI systems to tell people when they are interacting with AI. The requirement also covers specific uses and outputs, including deepfakes, emotion-recognition systems, biometric categorization, and certain AI-generated or manipulated content on matters of public interest.
This is not limited to companies headquartered in Europe. The relevant question is where the AI system is placed on the market, put into service, or where its output is used. A non-EU company can therefore fall within the rules when its AI products or outputs reach the European market.
For executives, the first task is classification. An enterprise needs to know which systems interact directly with people and which role it plays for each system. Covered examples include AI chatbots, conversational agents, AI companions, and coding agents. The organization must then connect each applicable system to the correct disclosure control.
The scope is important because the rules do not apply uniformly to every use of AI. Recommendation systems, spam filters, authentication tools, search and retrieval, transcription, text and code autocomplete, and predictive maintenance are among the tools the article identifies as outside this specific direct-interaction requirement. A broad policy that treats every AI feature in the same way can therefore create unnecessary work without improving compliance.
Timing requires similar precision. Most of the transparency requirements start to apply on August 2. Systems placed on the market before that date receive additional time for certain obligations, with a December 2 compliance date cited in the article. Companies should not build their plans around that extension. It applies to a narrower group of systems, not the enterprise AI estate as a whole.
Henna Virkkunen, European Commission Executive Vice-President for Tech Sovereignty, Security and Democracy, said the Commission’s guidelines are intended to support the “smooth and effective application of the AI Act” and make systems such as chatbots and AI agents “more transparent and trustworthy.”
Sanchit Vir Gogia, Chief Analyst at Greyhound Research, makes the territorial point explicit: “Systems placed on the European market, put into service there, or producing outputs used there are inside the field, wherever the developer sits.” His recommendation is also practical. Enterprises should plan around August 2 and treat any later relief as additional margin, not as the compliance strategy.
For the C-suite, the immediate deliverable is clear: establish an accurate inventory of affected systems, determine the company’s provider or deployer role, identify the required disclosure, and assign an accountable owner. The hard part is not publishing a notice. It is knowing where a notice is legally required and ensuring that it remains operational across products, suppliers, and markets.
AI labels must work at both the human and machine level
The transparency requirement goes beyond showing users a message. Covered AI-generated text, images, audio, and video also need machine-readable marking. This means information identifying the content as AI-generated or modified must be detectable by software, not only visible to a person.
The Commission provides three labels: “AI,” “Fully AI-generated,” and “Partially AI-modified.” The choice communicates how AI contributed to the output. A news summary, piece of music, artwork, or video created by AI without human oversight beyond prompting can be labeled “Fully AI-generated.” A genuine photograph in which AI has replaced a person’s face is an example of “Partially AI-modified.” The corresponding icons are available free in PNG and SVG formats.
The objective is straightforward. Generative AI makes realistic synthetic content cheap to create at scale. Verification has not become equally cheap. Sanchit Vir Gogia, Chief Analyst at Greyhound Research, describes the imbalance directly: “Generative systems have collapsed the cost of producing convincing content while the cost of judging it stands where it always stood.” He calls the marking requirement “an attempt to restore friction to that imbalance.”
Executives should separate two controls that are easy to confuse. The first is user disclosure. A person needs a clear and accessible signal that AI is involved. The second is technical provenance, meaning information that allows systems to identify where content came from or how it was modified. A mature compliance process needs to manage both where the Act requires them.
Implementation cannot end when a watermark or metadata field is added at generation. Content moves. Images are cropped and compressed. Text is edited or translated. Audio can be transcribed. Files move between internal systems, suppliers, social platforms, and publishing tools. Each transformation can weaken or remove provenance information.
That creates a measurable technical requirement for management: test whether the mark survives the actual content lifecycle. The source article cites a published test in which Meta’s preview detector failed to detect 55% of cropped images despite its invisible watermark being designed to survive cropping. The example shows why laboratory performance alone is insufficient evidence of operational compliance.
The executive priority should therefore be durability, not merely deployment. Product, legal, security, marketing, and procurement teams need evidence that required labels are present when users receive the content and that machine-readable signals survive normal processing. Where they do not, the company needs a documented failure path and a corrective control.
The practical standard is simple. A disclosure must be visible where the user encounters the AI or its content. A provenance marker must remain detectable through expected transformations. And the enterprise must retain evidence that both controls work. That turns transparency from a label-design exercise into a testable operating requirement.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Not every AI system or AI-assisted output needs a disclosure
The EU AI Act’s transparency requirements are specific. They do not mean that every use of AI must carry the same notice. Enterprises need to classify systems by function, audience, content type, and level of human oversight before deciding whether disclosure is required.
For systems that interact with people, the article identifies chatbots, conversational agents, AI companions, and coding agents as covered examples. By contrast, AI-enabled recommendation systems, spam filters, authentication, search and retrieval, transcription, text and code autocomplete, and predictive maintenance fall outside the direct-interaction requirement described in the Commission’s guidelines.
Content rules also depend on context. Shashi Bellamkonda, Principal Research Director at Info-Tech Research Group, points to three relevant characteristics for the content requirements discussed in the article: whether the material has been published, whether it informs the public, and whether it concerns matters of public interest. As a result, some B2B material or corporate blog content may not require AI disclosure when it does not meet the applicable criteria.
Human oversight can also change the result. According to the article, published AI-generated text on public-interest matters does not require the same labeling when it has undergone human review or is subject to editorial control. Editorial control has a specific meaning here: a person must hold ultimate legal responsibility for publication. Adding a nominal approval step should not be treated as sufficient evidence of meaningful oversight.
Deepfakes require another distinction. The Act generally requires disclosure for AI-generated or manipulated image, audio, or video content that constitutes a deepfake. However, the article notes more limited requirements or exemptions for artistic, creative, satirical, and fictional works. That distinction matters for media, advertising, entertainment, and communications businesses.
For executives, the main risk is poor classification. Applying a disclosure to every AI-assisted process can create unnecessary complexity and weaken the value of notices by making them ubiquitous. Applying exemptions too broadly creates regulatory exposure. The better approach is to maintain documented rules that connect each AI use case to its function, audience, output, human review process, and resulting transparency obligation.
Bellamkonda also recommends a broader practice beyond minimum legal compliance. Companies should disclose AI-generated content and indicate whether a person reviewed it where appropriate. This can provide useful context to customers even when a particular disclosure is not legally mandatory.
The executive decision is therefore not simply whether the company “uses AI.” Almost every large enterprise will. The relevant questions are what the system does, who encounters its output, whether the output falls within a regulated category, and whether meaningful human review changes the applicable requirement.
AI transparency failures can carry penalties measured in millions of euros or a percentage of global revenue
The financial consequences make AI transparency an enterprise risk issue rather than a narrow product requirement. The article states that non-compliance can result in penalties ranging from €750,000, approximately $856,000, to €15 million, approximately $17 million. Depending on the infringement, penalties can reach up to 3% of total worldwide annual revenue.
Percentage-based penalties materially change the exposure for large multinational companies. Executives should therefore assess AI transparency alongside other regulatory risks that can affect group-level financial performance. The cost of compliance needs to be considered against the potential penalty, but financial exposure is only one part of the decision. Regulatory investigations can also require evidence about how a company classified systems, implemented controls, and managed suppliers.
Timing is critical. Most of the transparency rules covered in the article start to apply on August 2. Certain AI systems placed on the market before that date have additional time, with December 2 identified as the subsequent compliance date. That extension should not be interpreted as a four-month delay for the entire organization.
Sanchit Vir Gogia, Chief Analyst at Greyhound Research, makes that distinction explicit. A four-month allowance on a limited obligation and population of systems, he said, “is not a strategy.” His recommendation is to prepare for August 2 and “treat any relief that arrives as margin.”
That approach is operationally sound because enterprises need time to discover where covered AI already exists. AI functions can be embedded in customer platforms, employee software, marketing systems, development tools, and third-party services. Legal teams cannot determine disclosure duties accurately without an inventory that connects these systems to owners, users, suppliers, and outputs.
Executives should therefore define a minimum compliance position for August 2. The company needs to identify covered systems, establish its provider or deployer role, implement required disclosures in priority use cases, and name the person accountable for each control. Evidence of those decisions should be retained.
The objective should not be to eliminate every theoretical compliance risk before the deadline. It should be to establish a defensible operating process that finds covered systems, applies the correct controls, tests them, records evidence, and corrects failures. That capability will remain necessary after August 2 because AI products, suppliers, and regulatory interpretations will continue to change.
The EU’s voluntary code of practice offers a clearer compliance path, but signing it does not replace the law
The European Commission has introduced a voluntary code of practice alongside its AI transparency guidelines. The code gives providers and deployers a structured way to demonstrate how they meet the AI Act’s transparency obligations. According to the Commission, signing can provide greater “legal certainty” and a “simple and practical” route for showing compliance.
Participation also gives companies access to the Signatory Taskforce. This group allows signatories to share implementation practices and work on technologies for AI marking and labeling. That can be useful while technical methods for provenance, watermarking, and content identification continue to develop.
The key word is voluntary. A company does not have to sign the code to comply with the AI Act. Non-signatories can use other technical and organizational methods. However, they must be able to show surveillance authorities that their chosen methods are adequate.
Sanchit Vir Gogia, Chief Analyst at Greyhound Research, summarizes the trade-off clearly: non-signatories “keep their flexibility, and will face more case-by-case scrutiny for it.” That distinction should drive the executive decision. A company that chooses its own compliance framework gains freedom but assumes a greater burden of proving that its controls work.
Signing should therefore be a governance decision, not a communications exercise. Management should compare the code with existing AI governance, product controls, risk processes, and technical infrastructure. If internal methods already provide stronger evidence and reliable transparency controls, retaining flexibility may be justified. If practices vary widely across business units, a common framework could reduce implementation differences and simplify regulatory discussions.
Executives should also avoid treating participation as automatic proof that every product complies. The underlying legal obligations remain. Systems still need to be identified correctly, disclosures implemented in the appropriate place, machine-readable markers maintained where required, and supporting evidence retained.
The practical question is which route gives the enterprise the strongest evidence at acceptable operational cost. Regulators will ultimately care about whether the required transparency exists and whether the organization can demonstrate it. A documented, testable process matters more than a policy statement.
Major technology companies already support AI labeling, but enterprises remain responsible for their own compliance
Google, Adobe, LinkedIn, and Meta already have mechanisms for identifying or labeling AI-generated content. Their work shows that AI provenance and disclosure capabilities are moving into widely used technology platforms. It does not mean that enterprises can delegate their regulatory responsibility to those platforms.
Shashi Bellamkonda, Principal Research Director at Info-Tech Research Group, points to Google, Adobe, and LinkedIn as companies that have established ways to identify images marked as AI-generated. He also notes that Meta has made AI labeling a requirement in relevant cases, although the creator may have responsibility for adding the AI-generated label.
That difference matters. A platform can provide a labeling feature without ensuring that an enterprise uses it correctly. A creator can fail to declare AI use. Metadata can disappear during processing. Content can also move between platforms with different technical standards and disclosure policies. Compliance therefore depends on the complete publishing process, not just the capabilities of one vendor.
Bellamkonda described the transparency requirements as “a good move for guardrails around public information,” adding that companies with strong compliance and ethical oversight may have less cause for concern. He recommends that companies generally disclose AI-generated content and state whether it has undergone human review.
For the C-suite, the main constraint is control across systems. Large enterprises rarely create and distribute content through a single platform. Marketing teams may generate material with one service, edit it with another, store it internally, and publish it through several external channels. Each step can affect labels, metadata, and other provenance information.
Executives should therefore distinguish between vendor capability and enterprise control. Procurement teams need to know what labeling mechanisms a vendor provides, when they are applied, what transformations they survive, and what evidence the vendor makes available. Product and compliance teams then need to verify those claims in the company’s actual workflows.
Existing industry capabilities can reduce implementation work, but they should not define the compliance standard. The EU requirement is the relevant baseline. An enterprise must determine whether the final user receives the required disclosure and whether applicable machine-readable markings remain present.
This also creates an opportunity to standardize internal practice. Companies can define a common policy for AI-generated content, human review, labeling, and evidence retention across approved technology providers. Clear rules make adoption easier for employees while giving management a more consistent view of regulatory exposure.
AI labels can fail after normal content editing, so enterprises must test them in real workflows
Adding a watermark, metadata field, or other machine-readable marker at the point of generation does not prove that the control will work when users receive the content. The core technical problem is durability. AI content is routinely cropped, compressed, translated, transcribed, resized, reformatted, and edited. Any of these operations can weaken or remove provenance signals.
The source article gives a concrete example. Meta said its invisible watermark was designed to survive cropping. Yet a published test cited in the article found that Meta’s preview detector missed 55% of cropped images. This is an important result for executives. A control can work as designed in one environment and still fail after ordinary content processing.
Sanchit Vir Gogia, Chief Analyst at Greyhound Research, identifies durability as the hardest part of implementation because marking can perform well under controlled conditions but “badly in ordinary life.” His advice to technology leaders is direct: “CIOs should ask which platform can actually provide evidence before believing its dashboard.”
That changes how enterprises should evaluate AI transparency products. Vendor documentation and dashboard indicators are useful, but they are not sufficient evidence. A company should take representative outputs and test them through the same tools, platforms, transformations, and publishing processes used in production. The final result should then be checked for both visible disclosure and machine-readable provenance where required.
This testing should cover predictable changes. Images should be cropped and compressed. Text should be translated and edited. Audio and video should pass through normal production and distribution processes. Transcription should also be tested where relevant. The purpose is to establish which transformations preserve a marker, which degrade it, and which remove it entirely.
Gogia recommends auditing real outputs from generation through editing and publication. At each stage, the organization should identify who is responsible, whether the required mark survives, and what evidence supports the result or any claimed exception. When a label disappears, teams should record the root cause and determine whether the problem can recur.
For executives, this makes provenance reliability a measurable service requirement. Procurement contracts should specify supported marking methods, known failure modes, evidence access, and notice when technical behavior changes. Internal teams should define acceptable detection rates and escalation processes based on the applicable legal requirement rather than assuming that a vendor feature is sufficient.
The goal is durable transparency at the point where content reaches the user. Testing the generation system alone cannot establish that result. Enterprises need evidence from the full production workflow.
AI transparency requires clear ownership, durable evidence, and stronger supplier contracts
The biggest organizational problem is fragmented responsibility. One piece of AI-generated content can pass through an AI provider, an enterprise application, an editing system, an agency, and a publishing platform. No participant necessarily controls every stage. Enterprises therefore need to define who owns each transparency obligation and what evidence each party must preserve.
Sanchit Vir Gogia, Chief Analyst at Greyhound Research, groups the main concerns around “responsibility, durability and evidence.” He identifies contracts as the “pressure point” because many existing technology agreements were designed to deliver software and say “almost nothing” about provenance persistence, verification access, or evidence retention.
That gap matters for C-suite leaders. A company can carry regulatory responsibility without having contractual access to the information needed to prove compliance. If a supplier controls the watermarking technology or detection system, the enterprise may depend on that supplier for technical records, failure information, system changes, and audit evidence.
Procurement terms should address these dependencies explicitly. Contracts should define what marking technology is used, where disclosure is applied, how provenance information is retained, which transformations are known to damage it, and what evidence the customer can obtain. Suppliers should also provide notice when these mechanisms or known limitations change.
Internal accountability is equally important. Gogia recommends a central record covering AI systems, applicable duties, responsible parties, and supporting evidence. Enterprises should inventory systems that communicate with people, generate content, or evaluate sentiment. They should also classify whether the organization acts as the AI provider, deployer, or both.
User-facing disclosure needs a named owner as well. Gogia says notices must be “clear, distinguishable and accessible.” A disclosure hidden inside lengthy terms or available only after repeated navigation is unlikely to meet that standard. For conversational AI, disclosure should appear at the first relevant interaction rather than depend on the user finding separate documentation.
Human review also requires an operational definition. It is not enough to add “human reviewed” to a workflow description. Enterprises should document what reviewers evaluate, what authority they have to change or reject an output, and who accepts legal responsibility where editorial control is relevant. That evidence can become critical when a disclosure exemption depends on meaningful human oversight.
Enforcement may differ across EU member states. Gogia therefore recommends maintaining one common transparency baseline and adding local requirements for language, sector rules, and market practice. This approach gives multinational companies consistent core controls without ignoring jurisdiction-specific obligations.
For executives, the priority is accountability that can be demonstrated. Every covered system should have an owner. Every required disclosure should have a control. Every control should generate evidence. Every critical supplier dependency should have contractual support. That structure makes AI transparency manageable as systems, vendors, and regulatory requirements change.
AI transparency must become a permanent operational and procurement control
August 2 is a starting date, not the end of the compliance program. AI systems change through software updates, new models, supplier changes, and new business uses. A disclosure that works today may become incomplete after any of those changes. Enterprises therefore need continuous controls rather than a one-time compliance review.
Before August 2, the priority is visibility. Sanchit Vir Gogia, Chief Analyst at Greyhound Research, recommends that enterprises inventory every system that communicates with people, generates content, or gauges sentiment. Each system should then be classified according to the company’s role as provider or deployer and mapped to its applicable transparency duties.
Companies should prioritize the highest-risk use cases rather than waiting for a perfect inventory. Required disclosures should be live at the point of interaction, and each control should have a named owner. Enterprises also need to define what qualifies as substantive human review and retain evidence showing when that review occurred.
The next 30 days should focus on stabilization and testing. Gogia recommends checking transparency controls where users actually encounter them, not only where developers implemented them. Teams should test whether visible labels and machine-readable provenance signals survive cropping, compression, translation, transcription, and other normal transformations.
Failures should generate corrective work. When a disclosure or provenance marker disappears, the company should record the cause, identify the responsible system or supplier, determine whether other content is affected, and test the corrective action. This creates evidence that controls are actively monitored rather than simply documented.
Within the first 90 days, procurement should make transparency requirements a standard supplier condition. Gogia recommends securing commitments on marking methods, known failure modes, and access to evidence. Contracts should also require suppliers to notify customers when any of these elements change. This is important because an enterprise cannot maintain reliable controls when critical technical behavior changes without notice.
Procurement is a central constraint because much of the AI stack sits outside the enterprise. A business may depend on external model providers, content-generation services, editing tools, SaaS applications, and publishing platforms. If those suppliers cannot preserve provenance information or provide verification evidence, internal policy alone cannot solve the problem.
Gogia describes sustained compliance as a “living control.” He recommends maintaining a central record of systems, duties, and evidence, testing controls at the user-facing point, and continuously checking supplier assurance. This gives executives a current view of what systems are covered, who owns them, and whether the controls continue to work.
Multinational enterprises must also account for differences in enforcement. Gogia recommends “a common transparency baseline carrying traceability, responsibility, and evidence, with jurisdictional overlays for language, sector rules, and local practice.” This allows the core control model to remain consistent while accommodating national or sector-specific requirements.
The executive objective is a repeatable operating model. Before August 2, identify systems, launch priority disclosures, and assign ownership. During the first 30 days, test and stabilize those controls. During the first 90 days, embed the requirements into procurement. After that, continue monitoring systems, suppliers, evidence, and regulatory changes.
This approach also supports future AI adoption. Teams can introduce new AI systems through an established process for classification, disclosure, testing, ownership, and evidence retention. Compliance then becomes part of normal technology governance rather than an additional project every time the enterprise deploys a new AI capability.
Concluding thoughts
August 2 turns AI transparency into an operating requirement. The immediate task is not to label every use of AI. It is to know which systems fall within scope, what disclosure each requires, who owns the control, and what evidence proves that it works.
The harder problem comes after implementation. Labels can disappear as content is edited. Supplier systems can change. AI features can enter the business without central oversight. A compliance policy cannot manage these risks on its own. Enterprises need controls that are tested in real workflows and supported by clear contracts, evidence retention, and named accountability.
Executives should use the deadline to establish a durable baseline. Inventory covered systems. Prioritize user-facing disclosures. Test provenance signals after normal content transformations. Require suppliers to disclose failure modes and provide evidence. Then make these checks part of procurement and ongoing AI governance.
Companies that do this well gain more than deadline compliance. They create a repeatable process for adopting AI while maintaining traceability, responsibility, and user trust as both the technology and its regulation evolve.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


