Transparency: when you must tell customers they are talking to AI
The disclosure obligations when people interact with AI or receive generated content, and how to phrase them without making the experience worse.
The short answer
The AI Act sets transparency obligations for specific situations rather than a general labelling duty. Where an AI system is intended to interact directly with people, providers must design and develop it so that the people concerned are informed that they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable way where feasible. Deployers of systems producing deep fakes, content appreciably resembling real people, objects, places or events that would falsely appear authentic, must disclose that it is artificially generated or manipulated, with narrower requirements for artistic and satirical works. Systems performing emotion recognition or biometric categorisation require informing the people exposed. For an ordinary business the practical obligations reduce to two: say plainly when a customer is dealing with an automated assistant, and be careful with generated imagery that could be mistaken for a real depiction. One provision can turn a deployer into a provider, and it applies only to high-risk systems. Article 25(1) states that a deployer “shall be considered to be a provider of a high-risk AI system … and shall be subject to the obligations of the provider under Article 16” in three circumstances: putting your own name or trademark on a high-risk system already on the market; making a substantial modification to one; and the third, which is the one most likely to catch a small business, where they “modify the intended purpose of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system concerned becomes a high-risk AI system in accordance with Article 6”. Annex III, point 4(a) covers AI systems intended to be used for the recruitment or selection of people, including to analyse and filter job applications. Whether deploying a general-purpose system for that purpose makes it such a system, and so modifies its intended purpose, requires interpretation and is not settled; if it does, the full set of provider obligations follows, which is a different order of magnitude from a disclosure line. This is general information rather than legal advice. Beyond the law, disclosure protects trust; customers forgive an assistant that says what it is and resent one that pretended to be a colleague.
Where disclosure is needed
| Situation | Disclosure | How |
|---|---|---|
| Chat assistant on your site | Yes, unless obvious | First message, plain words, with the route to a person |
| Voice assistant on a phone line | Yes | At the start of the call, with how to reach a person |
| AI-drafted email sent under a person’s name and reviewed by them | Not required | Accountability matters more than labelling |
| Automated replies sent without human review | Yes, in practice | Say it is an automated response and how to reach a person |
| Synthetic voice or video of a real person | Yes, as a deep fake | Clear disclosure |
| Realistic generated imagery implying a real scene | Treat as requiring disclosure | Caption or avoid |
| Obviously illustrative generated graphics | Not generally | Judgement; disclose if any doubt |
| Emotion recognition or biometric categorisation | Yes, inform those exposed | Strict limits apply; take advice |
| AI used internally with no customer interaction | Not required | Data protection transparency still applies |
Doing it well
- Disclose at the start of any automated interaction, before the customer invests effort.
- Use plain wording and avoid presenting the assistant as a named colleague with a photograph.
- Pair disclosure with the exit: how to reach a person, in the same breath.
- Mark generated media where it could be taken as a real depiction, and prefer real photographs of your business.
- Keep a human accountable for anything sent under a person’s name.
- Cover it in the privacy statement and any AI notice you publish.
- Check the tools you use: some platforms provide marking and disclosure features; enable them.
- Review as the rules and guidance develop, since implementation is ongoing.
The commercial case
Customers set their expectations from the disclosure. Told they are talking to an automated assistant, they ask it simple things and reach for a person when the matter is complex, which is exactly the division that makes the deployment work. Told nothing, they ask complex things, get poor answers, and conclude the business is incompetent rather than that the assistant was the wrong tool. Disclosure improves the metrics as well as the compliance position, which makes this an unusually easy obligation to meet.
What this means for you
Tell people plainly when they are interacting with an AI system, at the start and with the route to a person; mark or disclose generated content that could be mistaken for a real depiction; inform people exposed to emotion recognition or biometric categorisation; and keep a human accountable for anything sent under a person’s name. Do not rely on the obvious exception while designing an assistant to seem human. This is general information rather than legal advice.
Frequently asked questions
How should the disclosure be worded?
Plainly, at the start of the interaction, with the route to a person in the same sentence. Something like: you are chatting with our automated assistant, type agent at any time to reach a person. That satisfies the obligation, sets the right expectation and reduces frustration, which is why the wording matters commercially as well as legally. Avoid names and avatars that suggest a human colleague.
Do we have to label AI-assisted marketing copy?
The content-marking obligations focus on synthetic audio, image, video and text published to inform the public on matters of public interest, and on deep fakes, rather than on every piece of assisted business writing. Ordinary marketing copy that a person has edited and stands behind is not the target. That said, where readers would reasonably want to know, disclosure is good practice, and search guidance encourages it. Authorship and accountability matter more than a label.
What about AI-generated images on our website?
Where an image is a realistic depiction that could mislead, treat disclosure as necessary; the deep fake provisions concern content that appreciably resembles real people, objects, places or events and would falsely appear authentic. An obviously illustrative or abstract generated image is a different case. The safest approach for a business is to avoid generated imagery that implies a real depiction of your premises, team or work, and to disclose where there is any doubt.
Sources
- European Commission: AI Act (accessed 2026-09-12)
- EUR-Lex: Regulation (EU) 2024/1689, Article 50 (accessed 2026-09-14)