AI Transparency & Disclosure Kit
This is a ready-to-adapt kit that includes a scoping register allowing you to inventory every AI touchpoint in your organisation, disclosure wording split in nine modules covering the different types of AI use that you might need to disclose, and and evidence pack that can be used as a record of decisions to show an auditor or regulator. It is all built around Article 50 of the EU AI Act, which has applied since 2 August 2026.
- Pages
- 27
- Format
- DOCX
- Licence
- MIT
- Updated
- 1 September 2026
Table of contents.
- 1. What this kit accomplishes
- 2. The obligation in one page
- 3. Step 1 — Inventory the touchpoints
- 4. Step 2 — Decide your role, system by system
- 5. Step 3 — Test each system against the four triggers
- 6. Step 4 — Map triggers to the disclosure modules
- 7. Placement, timing and accessibility
- 8. Machine-readable marking
- 9. Governance, review and evidence
- 10. Limits, and how current this is
- Annex A · Trigger decision table
- Annex B · Questions for your AI vendors
- Annex C · Obligation map
01What this kit accomplishes
This is a working kit, not a policy. You do not sign this document and file it, but instead you work through it, and it produces three assets you can use:
- A scoping register: every AI touchpoint in your organisation, the role you play for it, and which transparency obligations it triggers. Including the ones that trigger nothing, with the reasons written down (this is important as it becomes your audit trail).
- The disclosure wording itself: nine drafting modules covering chatbots, synthetic content, deep fakes, emotion recognition, automated decisions and privacy notices, with placement and timing rules for each.
- An evidence pack: the record that shows a supervisor/regulator, on request, that you assessed this deliberately rather than by accident.
Who needs to provide input
Whoever owns the customer-facing channel, plus legal, the data protection officer, and someone from brand or content. In our experience the scoping takes half a day with the right five people, and considerably longer with the wrong twelve.
What this kit does NOT do
- It is not a DPIA and not a fundamental rights impact assessment. Transparency is one obligation. If your system is high-risk, or your data processing is high-risk under GDPR, you need those separately.
- It does not make a high-risk system compliant. Article 50 and the high-risk regime in Chapter III are different obligations on different timelines. A system can be caught by one, both, or neither.
- It is not legal advice. It is a structured way to reach the right questions quickly and to record your answers. The judgement calls, and especially the exemptions, are yours, and several of them are genuinely arguable. When in doubt, consult with counsel.
- It does not cover employment-law consultation duties that may attach to workplace AI in some Member States. Check locally and with your counsel.
How to fill it in
Read and work through the sections in order, they provide context and insight. Sections 3 to 6 are where you do the work. They guide you through four steps, and each one ends with a table for you to fill in. You will see example tables filled in for a fictitious company (AlphaInsure) for your reference.
Throughout the document, [ORANGE SQUARE BRACKETS] are for you to replace. You will find them on the cover, and in the model wording in Section 6. Grey boxes are model wording you can lift directly.
Did we use AI to create this?
Yes, we did. We took several sample documents we produced for clients, anonymised the company details and use cases, and used an AI model (Claude Opus) to generalise these so you can use it leaving placeholder text where needed. The final output has been verified and edited by a human before publishing.
02The obligation in one page
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) requires certain AI systems to announce themselves. It is a narrow obligation with a wide reach: it does not care whether your system is high-risk, only whether a person is interacting with it, being assessed by it, or looking at something it produced.
The four triggers
| What it catches | Who owes it | Where | |
|---|---|---|---|
| T1 | AI systems intended to interact directly with natural persons. Chatbots, voice assistants, anything conversational. Customers and employees both count. | Provider (by design); the deployer presents it in practice | Art. 50(1) |
| T2 | Systems generating synthetic audio, image, video or text. Outputs must be marked in a machine-readable format and detectable as artificially generated. | Provider | Art. 50(2) |
| T3 | Emotion recognition and biometric categorisation systems. Persons exposed must be informed. | Deployer | Art. 50(3) |
| T4 | Deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest. | Deployer | Art. 50(4) |
Across all four, Article 50(5) sets the manner: the information must reach the person in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements.
What it costs to get wrong
Article 50 breaches sit in the Article 99(4) band: fines up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is the middle band with a further €35m / 7% band reserved for the prohibited practices in Article 5. Under Article 99(6), small and medium enterprises get the lower of the two figures; the Digital Omnibus added a related provision for small mid-caps. If either might apply to you, check the current consolidated text rather than relying on this line.
Official guidance you should familiarise yourself with
- Guidelines on transparency obligations for providers and deployers of AI systems: European Commission, 20 July 2026, issued under Article 96(1)(d). It is non-binding, but this is what a market surveillance authority reads. It sets out the definitions, exemptions and examples.
- Code of Practice on Transparency of AI-generated Content: European Commission, 10 June 2026. It is voluntary, and addressed at Article 50(2), (4) and (5). The Commission and the AI Board have confirmed it as an adequate voluntary tool for demonstrating compliance, but it is not the only route, and non-signatories must show adequate means of their own.
- EU icons for labelling AI-generated content: free, optional, and covered in Section 7. Using them does not by itself establish compliance.
03Step 1 — Inventory the touchpoints
List every place an AI system meets a person, or produces something a person will see. Be generous at this stage: it is much cheaper to record a system and rule it out than to discover it later in a complaint or audit. Three categories are missed almost every time so you should pay close attention to them:
- Internal tools. Article 50(1) says “natural persons”; it does not say “customers”. A staff copilot is in scope even if a customer will never see it.
- Vendor features you did not ask for. Suppliers add generative features to existing products. Your call-centre platform may have acquired a summarisation feature since you last looked, and they might have enabled it by default for you.
- Marketing and brand assets. Generated imagery usually sits with a contracted third-party agency, outside whatever inventory your technology department keeps.
Example inventory table
| Ref | System | What it does | Supplier |
|---|---|---|---|
| AIS-014 | “Alex” customer service assistant | Generative chat assistant on the website and mobile app. Answers policy questions, explains cover, takes first notice of loss. | Northwind Conversational Cloud (vendor SaaS, used unmodified) |
| AIS-021 | Claims intake voice assistant | Inbound telephone assistant on the claims line. Synthesised voice, natural-language intake, routes to a handler. | VoxLine Voice AI (vendor SaaS, used unmodified) |
| AIS-007 | Marketing content generation | Generative image and copy tooling used by the brand team for campaign assets, including one campaign using a synthetic presenter. | Two vendor tools (used unmodified) |
| AIS-030 | Claims file summarisation | Summarises loss adjuster reports and correspondence into a working brief for the claims handler. Internal only; output never sent to customers. | Vendor model via private endpoint |
| AIS-041 | Life and health underwriting risk model | Risk assessment and pricing for life and health applications. Built in-house by fine-tuning a vendor foundation model on AlphaInsure claims history. | Fine-tuned in-house from a vendor base model |
| AIS-052 | Claims fraud triage | Scores incoming claims for referral to the special investigations unit. A handler decides whether to refer. | In-house model |
| AIS-063 | Recruitment CV screening | Ranks applications against role criteria for the recruitment team. | Vendor SaaS (used unmodified) |
| AIS-070 | Internal staff assistant | General-purpose generative assistant available to all employees for drafting, summarising and research. | Vendor SaaS (used unmodified) |
Inventory table
| Ref | System | What it does | Supplier |
|---|---|---|---|
| 12 blank rows to complete in the document | |||
04Step 2 — Decide your role, system by system
The obligations are split by role, so this must be settled before anything else. And importantly, these are decided per system, not per organisation; the same company is routinely a deployer of one system and the provider of another.
The default stance
If you bought it and use it as supplied, you are a deployer. If you built it, or you put it on the market under your own name, you are a provider.
What you should be aware of
Article 25(1) converts a deployer into a provider in three situations: you put your own name or trademark on a high-risk system already on the market; you make a substantial modification to a high-risk system; or you modify the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk under Article 6. Fine-tuning a foundation model into an insurance underwriting tool is the textbook case of the third. When this happens, the original supplier stops being the provider for that instance and the whole provider obligation shifts to you.
Example role determination table
| Ref | Role | Basis |
|---|---|---|
| AIS-014 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
| AIS-021 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
| AIS-007 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
| AIS-030 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
| AIS-041 | Provider (Art. 25(1)(c)) | Fine-tuned in-house from a vendor base model to a purpose within Annex III(5)(c). Art. 25(1)(c) applies: AlphaInsure is the provider.AIS-041 was procured as a vendor model and treated for eighteen months as bought-in. Fine-tuning it to life and health risk assessment made AlphaInsure its provider under Art. 25(1)(c) — moving conformity assessment, technical documentation and post-market monitoring onto us for 2 December 2027. |
| AIS-052 | Provider | Built in-house. Provider by default. |
| AIS-063 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
| AIS-070 | Deployer | Vendor product used as supplied, without modification and within its stated intended purpose. |
Role determination table
| Ref | Role (provider / deployer / both) | Basis for the determination |
|---|---|---|
| 12 blank rows to complete in the document | ||
05Step 3 — Test each system against the four triggers
Work through each trigger for each system and record the answer even when it is “no”. An absence you can explain is an actual finding, one that you cannot explain is a gap in your process.
T1 · Does it interact directly with a natural person?
Article 50(1). The provider must design the system so the person is informed they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.
On the “obvious” exemption
The Commission’s guidelines frame this using the “average consumer” idea from EU consumer law (identify the actual audience, then ask how well-informed a member of it would be) and direct that the exemption be read narrowly. Our advice: unless the case is overwhelming, disclose anyway. The exemption saves you very little – often a few words.
- Weak grounds: the assistant has a robot name; there is a small icon; it says so in the terms of service; everyone knows these are bots now.
- Stronger grounds: the interaction happens inside a product whose whole and only stated purpose is an AI tool, entered deliberately by a user who has already been told.
Note the law enforcement carve-out in Art. 50(1) is narrow and will not apply to commercial deployments.
T2 · Does it generate synthetic audio, image, video or text?
Article 50(2). Providers must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. This is a provider duty. If you buy the tool, the marking obligation sits with your supplier, but you should be checking they discharge it, because their failure becomes your reputational problem and, if you modify the system, potentially your legal one.
The standard editing exemption
The obligation does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics. The line, as the Commission’s guidelines draw it:
| Generally exempt | Generally caught |
|---|---|
| Spellchecking and grammar correctionMinor stylistic polishing that leaves substance, meaning and messaging intactTranscriptionTranslation (for the provider marking duty; see the warning below) | SummarisationParaphrasing or rewriting that changes style, structure or meaning beyond minor correctionGenerating new text, images, audio or video from a promptMaterially altering an existing image, recording or video |
T3 · Is it emotion recognition or biometric categorisation?
Article 50(3). Deployers must inform the persons exposed, and must process any personal data in line with the GDPR and the Law Enforcement Directive as applicable. Two things to hold in mind before you reach the disclosure question:
- Some uses are prohibited outright. Article 5 bans emotion inference in the workplace and in education, except for medical or safety reasons. Disclosure does not allow a prohibited practice.
- Biometric data is special category data. GDPR Article 9 applies and the lawful basis question is usually harder than the transparency question.
T4 · Deep fakes, and AI text published on matters of public interest
Article 50(4). Two distinct duties, both levied on the deployer:
Deep fakes
Image, audio or video content generated or manipulated so that it resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (Art. 3(60)). Disclose that the content has been artificially generated or manipulated. Where the work is evidently artistic, creative, satirical or fictional, the duty softens to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work; credits or an information panel rather than a burned-in overlay. Commercial advertising is a poor fit for this carve-out!
Public-interest text
AI-generated or manipulated text published to inform the public on matters of public interest must be disclosed, unless the content underwent human review or editorial control and a natural or legal person holds editorial responsibility for the publication. This is the exemption most organisations can actually engineer around: a documented review step with a named accountable editor.
Example trigger determination table
| Ref | T1 | T2 | T3 | T4 | Outcome |
|---|---|---|---|---|---|
| AIS-014 | Yes | — | — | — | Highest-volume customer touchpoint. Disclosure carried at the top of the chat window and repeated in the assistant’s first message. |
| AIS-021 | Yes | Yes | — | — | Synthetic speech. Spoken disclosure is the first thing the caller hears, before any menu. |
| AIS-007 | — | Yes | — | Yes | The synthetic-presenter campaign is a deep fake within the meaning of Art. 3(60) and is labelled accordingly. |
| AIS-030 | — | — | — | — | Generates synthetic text, but the marking duty in Art. 50(2) sits with the provider and no natural person outside the firm is exposed. Recorded as out of scope with reasons. |
| AIS-041 | — | — | — | — | High-risk under Annex III(5)(c). Fine-tuning makes AlphaInsure the provider. No Art. 50 trigger but GDPR Art. 22 applies and high-risk obligations apply from 02/12/2027. |
| AIS-052 | — | — | — | — | Not solely automated: referral requires a handler’s decision on a reasoned basis, so Art. 22(1) is not engaged. Assessment recorded and revisited annually. |
| AIS-063 | — | — | — | — | High-risk under Annex III(4)(a). No Art. 50 trigger, but candidates receive an ADM notice and the recruiter’s decision is documented. |
| AIS-070 | Yes | — | — | — | Employees are natural persons. Art. 50(1) is not limited to customers — this was the trigger most often missed in our first pass. |
Trigger determination table
| Ref | T1 | T2 | T3 | T4 | Outcome and reasoning |
|---|---|---|---|---|---|
| 12 blank rows to complete in the document | |||||
Download the full document.
The full document continues from here. Step 4 and everything after it (the nine disclosure modules with the model wording, placement and timing rules, machine-readable marking, governance, and three annexes) are in the full Word document.
It is 27 pages, MIT licensed, and yours to adapt: put your own name on it, change what does not fit, and use the result commercially. No attribution needed on what you produce from it.
