When Seeing Is No Longer Believing
That example was harmless. The same technology is not always so benign.
In early 2024, an employee at the Hong Kong office of Arup, a UK-based global engineering and design consultancy, received what looked like an email from Arup’s Chief Financial Officer which said that they needed to initiate a “secret transaction.” The employee was then invited to a video conference call where many known and familiar faces in the company’s hierarchy were present, but where every individual was a generated deepfake, as was the email initiating the fraud. This gave the employee the confidence that the request was legitimate and led to them sending the money. The faces were familiar. The voices were familiar. The instructions were clear.
By the end of the call, approximately US$25 million had been transferred.
This incident was not simply another cybercrime. It marked something more fundamental. For centuries, businesses have operated on a simple assumption: if you could see it, hear it or read it, there was a reasonable chance it was genuine. Artificial intelligence has fundamentally challenged that assumption. Today, AI can generate photographs of people who do not exist, produce convincing videos of events that never happened, clone a person’s voice from a few seconds of audio and draft documents that are virtually indistinguishable from those written by a human expert.
The result is not merely a technological revolution. It is a crisis of trust.
Increasingly, businesses, governments and consumers are asking the same question: How do we know what is real?
That question lies at the heart of the European Union’s latest transparency measures under the EU Artificial Intelligence Act (“AI Act”).
Rather than attempting to prohibit the use of generative AI, the EU has adopted a different philosophy. It accepts that artificial intelligence will become an integral part of everyday business and consumer life. The challenge, therefore, is not to prevent AI from being used, but to ensure that people know when it is being used.
In other words, the objective is not to regulate intelligence. It is to restore trust.
Transparency Rather Than Prohibition
Most commentary on the AI Act has focused on its regulation of high-risk AI systems. While those provisions are undoubtedly important, they will affect a relatively small proportion of organisations.
For the vast majority of businesses, the first practical obligations are likely to arise from a much simpler concept: transparency.
Article 50 of the AI Act introduces a series of obligations requiring organisations to disclose when individuals are interacting with AI and, in certain circumstances, when content has been generated or materially manipulated using AI. To support these obligations, the European Commission has published Guidelines on Article 50 and, on 10 June 2026, the final Code of Practice on the marking and labelling of AI-generated content. These transparency requirements become applicable from 2 August 2026. However, under the Digital Omnibus agreement reached in May 2026, generative AI systems already on the market before that date have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2).
For many organisations, this will represent the first tangible AI compliance requirement they encounter. Unlike some aspects of the AI Act, however, compliance does not necessarily require sophisticated technical solutions or extensive legal documentation. It requires organisations to understand where AI is already being used within their business and to adopt practical governance measures that ensure its use is transparent, consistent and capable of inspiring confidence.
The philosophy underpinning these requirements can be summarised in a single sentence: People can only make informed decisions if they know when artificial intelligence is involved.
That simple principle is rapidly becoming one of the defining themes of AI regulation, not only in Europe but increasingly around the world.
What Does Article 50 Require?
Article 50 establishes a number of transparency obligations that apply across a broad range of AI systems and use cases. Although the legislation is detailed, the obligations can be understood by grouping them into four practical categories.
1. Informing Users When They Are Interacting with AI
If an AI system interacts directly with individuals, users must be informed that they are dealing with AI unless that fact is obvious. Examples include:
- AI chatbots
- AI customer support assistants
- AI voice agents
- AI virtual receptionists
- AI sales assistants
In practice, compliance may be as simple as:
“You are currently interacting with an AI assistant.”
Many organisations already provide such disclosures, but they may now become a formal compliance requirement.
In plain terms: if a customer is talking to a bot rather than a person, tell them so.
2. Marking AI-Generated Content
Providers of generative AI systems must ensure that AI-generated outputs can be identified as AI-generated or AI-manipulated. The emphasis here is on machine-readable marking. This means embedding information within content that allows downstream systems and tools to identify its AI origin.
In plain terms: the AI tool stamps its own output with an invisible, machine-readable tag, so that other software can later recognise the content as AI-made.
It helps to keep two ideas apart:
- Marking is an invisible watermark baked into the file by the AI provider — the company that builds the AI.
- Labelling, which we come to next, is the visible “AI-generated” notice shown to a human, and typically falls on the deployer — the company that uses the AI.
The two roles carry different duties under the Act.
3. Labelling Deepfakes
One of the most publicised requirements concerns deepfakes. Where AI-generated or AI-manipulated audio, video or images create content that appears authentic but is actually not, clear disclosure may be required. Examples might include:
- Synthetic videos of public figures
- AI-generated speeches
- Manipulated product demonstrations
- Synthetic testimonials
The purpose is to prevent individuals from being misled into believing that fabricated content is genuine.
In plain terms: if AI is used to make a fake video, image or audio clip that looks real, the business using it must tell people that it is not genuine.
Two qualifications matter:
- Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the disclosure need only be made in a manner that does not hamper the display or enjoyment of the work; and
- the obligation does not apply where the use is authorised by law to detect, prevent, investigate or prosecute a criminal offence.
4. Disclosure of AI-Generated Public Interest Content
Additional transparency obligations apply where AI-generated text is published to inform the public on matters of public interest. This may affect:
- News publishers
- Media organisations
- Political content creators
- Public information services
The objective is to maintain trust in information ecosystems.
In plain terms: if you publish AI-written text on matters of public interest, you generally have to say so.
There is an important exception. No disclosure is required where the AI-generated text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication. A token human “glance” is not enough; genuine editorial oversight is what the exemption requires — a point of real significance for news publishers.
What Is New About the Code of Practice?
The recent development is not the creation of Article 50 itself. The AI Act already contains the transparency obligations. What is new is the Commission’s effort to create a practical framework explaining how organisations can implement these obligations.
The Code of Practice focuses on:
- Marking AI-generated content
- Detectability of AI-generated outputs
- Human-readable labelling
- Machine-readable identification
- Practical implementation measures
- Governance processes
Now that it has been finalised, the Code is a voluntary tool that organisations can use to demonstrate adherence to their obligations under Article 50(2) and (4). It does not impose obligations beyond the AI Act itself.
Why This May Matter to Your Business
Many organisations assume that AI regulation only affects technology companies. That assumption is capable of much mischief, as it is not just the technology companies that are using AI. Today, AI is embedded in:
- Marketing platforms
- CRM systems
- Customer support tools
- Recruitment software
- Content creation tools
- Social media management platforms
- Productivity applications
As a result, many businesses are already generating AI content without having established any governance framework around it. The transparency requirements may therefore affect organisations that do not consider themselves “AI companies”. Such as:
- A marketing department using AI-generated imagery may be affected.
- A customer service team deploying an AI chatbot may be affected.
- A communications team publishing AI-assisted content may be affected.
On several occasions, my clients have argued that the AI compliance obligations do not apply to them as they themselves have not developed any AI technology and merely licence it from others. This is not an accurate position, as compliance obligations arise even where the AI is being licensed from another provider. Licensing rather than building AI does not exempt an organisation from the obligations that fall on deployers of AI. Given how ubiquitous this technology has become, most companies use AI technology in their day-to-day working — be that Copilot embedded in Microsoft 365 or a subscription with OpenAI or Anthropic.
Transparency by Design — Practical Implementation Framework
The most effective approach is not to treat transparency as a documentation exercise. Instead, organisations should adopt what I like to call: Transparency by Design. It is the discipline of designing technology, products and business processes so that the use of artificial intelligence is apparent, understandable and capable of being trusted. It moves transparency out of privacy notices and legal policies and into the user experience itself, ensuring that people know when they are interacting with AI, when content has been generated or materially altered by AI, and when AI is influencing decisions.
The process can usually be broken into five practical steps that a business could easily implement to minimise its compliance, legal, and commercial risks.
Without an inventory, compliance is largely impossible. Transparency by Design turns Article 50 into a five-step operating habit — not a one-off document.
Step 1 — Create an AI Inventory
Most organisations do not know how many AI tools they are already using. Many clients are surprised with their own usage and consequent compliance requirements. Start by identifying:
- Chatbots
- Copilots
- Content generation tools
- Image generation tools
- Video generation tools
- AI-enabled CRM platforms
- AI-enabled HR systems
Without an inventory, compliance is largely impossible and such an inventory demonstrates controllership over the usage of this potent technology.
Step 2 — Map Transparency Triggers
For each AI system the business needs to ask: Does it:
- Interact directly with people?
- Generate content?
- Manipulate images?
- Generate audio?
- Produce video?
- Create public-facing information?
If the answer is yes, Article 50 may be relevant and if so, Step 3, 4, and 5 (as set out below) are important and applicable.
Step 3 — Define Disclosure Rules
Once you have identified where AI is being used, the next step is to decide how and when your organisation will tell people that AI is involved. Rather than leaving these decisions to individual employees or teams, develop a simple set of internal standards that everyone follows consistently.
For example:
- Customer Service: Where customers interact with an AI chatbot or virtual assistant, display a clear message such as: “You are currently interacting with an AI assistant.”
- Marketing: If marketing materials include AI-generated images, videos or audio that could reasonably be mistaken for authentic content, establish a policy on when and how they should be identified as AI-generated.
- Content Creation: Where articles, reports or other publications are substantially generated by AI, require authors or editors to record how AI was used and ensure that any necessary disclosures are made before publication.
These are only illustrative examples. Each organisation should develop disclosure standards that reflect the way it uses AI and the expectations of its customers, employees and regulators. The objective is not to disclose every use of AI indiscriminately, but to ensure that similar situations are treated in a consistent, transparent and well-governed manner across the organisation.
Step 4 — Good Governance Is About Accountability, Not Bureaucracy
Many businesses assume that governance means creating committees, drafting policies and introducing additional layers of administration. In reality, good governance is much simpler. It begins by ensuring that someone is accountable.
AI initiatives often span multiple functions. Procurement may purchase the technology, IT may implement it, Marketing may use it, HR may rely on it, while Legal or Compliance may only become involved after concerns arise. Without clear accountability, responsibility becomes fragmented and decisions fall through the gaps.
This is especially true in smaller organisations where resources are limited and formal compliance teams may not exist. AI governance can easily become an organisational “hot potato”, passed from one department to another without anyone taking ownership.
Every organisation, regardless of its size, should identify who is responsible for overseeing:
- The procurement and approval of AI tools
- The deployment of AI systems
- Transparency and disclosure obligations
- Incident management and escalation
- Monitoring changes in the regulatory landscape
Governance is not about creating bureaucracy. It is about ensuring that the right people know what they are responsible for. In practice, a simple governance framework with clear lines of accountability is usually far more effective than an extensive policy manual sitting unread on a shared drive.
usually far more effective than an extensive policy manual sitting unread on a shared drive.
Transparency by Design is not achieved by writing better policies. It is achieved by ensuring that someone is responsible for embedding transparency into the way AI is selected, deployed and used across the organisation.
Step 5 — Maintain Evidence
Increasingly, regulators ask not: “Do you have a policy?” But: “Show us how the decision was made.”
The problem arises when there is a churn of stakeholders, and after a few months the IT department wipes clean the records. Businesses use Slack and other tools where very often the messages and channels get deleted. Organisations should therefore maintain evidence of:
- AI inventories
- Risk assessments
- Transparency decisions
- Approval workflows
- Technical controls
Good records frequently become the strongest compliance defence and are worth their weight in gold in regulatory investigation and corporate due diligence exercises.
Without an inventory, compliance is largely impossible. Transparency by Design turns Article 50 into a five-step operating habit — not a one-off document.
Four Mistakes I See Organisations Repeatedly Make
Mistake 1 — Assuming the AI Vendor Will Take Care of Compliance
When organisations procure AI solutions, most of the discussion revolves around functionality, performance, security and price. By the time the licence agreement arrives, there is often little scope to negotiate the legal terms. Many of the major AI providers operate on standard contractual terms and have limited appetite for customer-specific amendments.
This often creates the misconception that regulatory compliance is the vendor’s responsibility.
It is not.
While AI providers have their own obligations under laws such as the EU AI Act, organisations deploying those systems have obligations of their own. Simply purchasing a compliant product does not guarantee that the way it is configured, deployed and used within your business will itself be compliant. Ultimately, your organisation remains accountable for how AI is used in its own products, services and business processes.
Mistake 2 — Assuming “We’re Not a High-Risk AI Business”
One of the most common misconceptions is that the EU AI Act only affects organisations developing sophisticated or “high-risk” AI systems.
In reality, many businesses will never develop a high-risk AI system, yet they may still be subject to important obligations under the Act. A company using AI to generate marketing content, operate a customer service chatbot or create synthetic media may still need to comply with transparency requirements, even though its AI systems fall well outside the high-risk category.
The question should not be,
“Are we developing high-risk AI?”
Instead, organisations should ask,
“Where are we using AI, and what obligations arise from those uses?”
Mistake 3 — Thinking Transparency Is Something Lawyers Put in Documents
Many organisations instinctively respond to new regulations by updating their legal documentation. They revise their privacy policy, add a disclaimer to their website or insert a clause into their terms and conditions.
While documentation remains important, transparency under the EU AI Act is increasingly about what users experience in practice rather than what lawyers write in policy documents.
If a customer is interacting with an AI assistant, they should be told at the point of interaction. If AI-generated content is published, appropriate disclosure should accompany the content itself where required. If synthetic media is used, the organisation should have internal processes governing how and when it is identified.
Transparency is therefore something that needs to be built into products, services and customer journeys — not simply recorded in legal documents.
Mistake 4 — Leaving Marketing Outside the AI Governance Conversation
Historically, AI governance discussions have tended to focus on IT, Legal and Compliance, with Marketing playing only a peripheral role. That approach is becoming increasingly risky. As marketing teams and their external agencies become some of the largest users of generative AI, excluding them from governance discussions may leave organisations exposed to unnecessary legal, regulatory and reputational risk.
If a significant proportion of an organisation’s public-facing content is being created or enhanced using AI, Marketing should have a seat at the governance table. This is particularly important where external agencies are creating AI-generated content on the organisation’s behalf. Businesses should ensure that agency agreements clearly address the use of AI, require compliance with applicable transparency obligations and establish appropriate review and approval processes before AI-generated content is published.
AI governance should not be confined to the technology function. It should extend to every part of the organisation that creates, deploys or communicates AI-generated content. If organisations continue to exclude the teams responsible for creating and publishing AI-generated content, they do so at their own peril.
Transparency Is Becoming the New Currency of Trust
The transparency provisions of the EU AI Act represent far more than another regulatory requirement or labelling exercise. They reflect a fundamental shift in the way governments around the world are approaching the regulation of artificial intelligence.
For many years, compliance was largely document-driven. Organisations demonstrated compliance by producing privacy policies, terms of use and internal procedures. Increasingly, however, regulators are asking a different question: what does the user actually experience?
- Can a customer tell when they are interacting with an AI system?
- Can they recognise when content has been generated or materially manipulated by AI?
- Can an organisation demonstrate that it has appropriate governance, oversight and accountability for the way AI is deployed?
These are no longer theoretical questions. They are becoming practical compliance obligations.
For many organisations, Article 50 of the EU AI Act will be the first real test of their AI governance framework. Businesses that begin preparing now are likely to discover that compliance is relatively straightforward. Those that delay may find that AI has quietly permeated their organisation without clear ownership, consistent standards or effective oversight.
The challenge facing businesses today is not simply how to adopt artificial intelligence. It is how to preserve trust while doing so. Artificial intelligence is becoming embedded in almost every aspect of modern business — from customer service and marketing to recruitment, product development and decision-making. Its adoption is inevitable. The loss of trust is not.
The organisations that thrive in this new environment will not be those that use the most AI. They will be those that use it most transparently.
That is the essence of Transparency by Design.
It means designing products, services and business processes so that the use of artificial intelligence is visible, understandable and capable of being trusted. It moves transparency out of legal documents and into the user experience itself.
The EU AI Act is unlikely to be the last piece of legislation requiring greater transparency around AI. It is more likely to be the beginning of a global movement. Just as GDPR reshaped the way organisations around the world think about privacy, AI transparency is poised to reshape the way organisations think about trust.
In the age of AI trust will no longer be assumed.
It will need to be earned by implementing principles of transparency (and preferably transparency by design).