Skip to content

AI Transparency & Disclosure Kit

This is a ready-to-adapt kit that includes a scoping register allowing you to inventory every AI touchpoint in your organisation, disclosure wording split in nine modules covering the different types of AI use that you might need to disclose, and and evidence pack that can be used as a record of decisions to show an auditor or regulator. It is all built around Article 50 of the EU AI Act, which has applied since 2 August 2026.

Pages
27
Format
DOCX
Licence
MIT
Updated
1 September 2026
01What is in the full document

Table of contents.

  1. 1. What this kit accomplishes
  2. 2. The obligation in one page
  3. 3. Step 1 — Inventory the touchpoints
  4. 4. Step 2 — Decide your role, system by system
  5. 5. Step 3 — Test each system against the four triggers
  6. 6. Step 4 — Map triggers to the disclosure modules
  7. 7. Placement, timing and accessibility
  8. 8. Machine-readable marking
  9. 9. Governance, review and evidence
  10. 10. Limits, and how current this is
  11. Annex A · Trigger decision table
  12. Annex B · Questions for your AI vendors
  13. Annex C · Obligation map
02Read an excerpt

01What this kit accomplishes

This is a working kit, not a policy. You do not sign this document and file it, but instead you work through it, and it produces three assets you can use:

  • A scoping register: every AI touchpoint in your organisation, the role you play for it, and which transparency obligations it triggers. Including the ones that trigger nothing, with the reasons written down (this is important as it becomes your audit trail).
  • The disclosure wording itself: nine drafting modules covering chatbots, synthetic content, deep fakes, emotion recognition, automated decisions and privacy notices, with placement and timing rules for each.
  • An evidence pack: the record that shows a supervisor/regulator, on request, that you assessed this deliberately rather than by accident.

Who needs to provide input

Whoever owns the customer-facing channel, plus legal, the data protection officer, and someone from brand or content. In our experience the scoping takes half a day with the right five people, and considerably longer with the wrong twelve.

What this kit does NOT do

  • It is not a DPIA and not a fundamental rights impact assessment. Transparency is one obligation. If your system is high-risk, or your data processing is high-risk under GDPR, you need those separately.
  • It does not make a high-risk system compliant. Article 50 and the high-risk regime in Chapter III are different obligations on different timelines. A system can be caught by one, both, or neither.
  • It is not legal advice. It is a structured way to reach the right questions quickly and to record your answers. The judgement calls, and especially the exemptions, are yours, and several of them are genuinely arguable. When in doubt, consult with counsel.
  • It does not cover employment-law consultation duties that may attach to workplace AI in some Member States. Check locally and with your counsel.

How to fill it in

Read and work through the sections in order, they provide context and insight. Sections 3 to 6 are where you do the work. They guide you through four steps, and each one ends with a table for you to fill in. You will see example tables filled in for a fictitious company (AlphaInsure) for your reference.

Throughout the document, [ORANGE SQUARE BRACKETS] are for you to replace. You will find them on the cover, and in the model wording in Section 6. Grey boxes are model wording you can lift directly.

Did we use AI to create this?

Yes, we did. We took several sample documents we produced for clients, anonymised the company details and use cases, and used an AI model (Claude Opus) to generalise these so you can use it leaving placeholder text where needed. The final output has been verified and edited by a human before publishing.

02The obligation in one page

Article 50 of the EU AI Act (Regulation (EU) 2024/1689) requires certain AI systems to announce themselves. It is a narrow obligation with a wide reach: it does not care whether your system is high-risk, only whether a person is interacting with it, being assessed by it, or looking at something it produced.

The four triggers

What it catchesWho owes itWhere
T1AI systems intended to interact directly with natural persons. Chatbots, voice assistants, anything conversational. Customers and employees both count.Provider (by design); the deployer presents it in practiceArt. 50(1)
T2Systems generating synthetic audio, image, video or text. Outputs must be marked in a machine-readable format and detectable as artificially generated.ProviderArt. 50(2)
T3Emotion recognition and biometric categorisation systems. Persons exposed must be informed.DeployerArt. 50(3)
T4Deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest.DeployerArt. 50(4)

Across all four, Article 50(5) sets the manner: the information must reach the person in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements.

What it costs to get wrong

Article 50 breaches sit in the Article 99(4) band: fines up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is the middle band with a further €35m / 7% band reserved for the prohibited practices in Article 5. Under Article 99(6), small and medium enterprises get the lower of the two figures; the Digital Omnibus added a related provision for small mid-caps. If either might apply to you, check the current consolidated text rather than relying on this line.

Official guidance you should familiarise yourself with

  • Guidelines on transparency obligations for providers and deployers of AI systems: European Commission, 20 July 2026, issued under Article 96(1)(d). It is non-binding, but this is what a market surveillance authority reads. It sets out the definitions, exemptions and examples.
  • Code of Practice on Transparency of AI-generated Content: European Commission, 10 June 2026. It is voluntary, and addressed at Article 50(2), (4) and (5). The Commission and the AI Board have confirmed it as an adequate voluntary tool for demonstrating compliance, but it is not the only route, and non-signatories must show adequate means of their own.
  • EU icons for labelling AI-generated content: free, optional, and covered in Section 7. Using them does not by itself establish compliance.

03Step 1 — Inventory the touchpoints

List every place an AI system meets a person, or produces something a person will see. Be generous at this stage: it is much cheaper to record a system and rule it out than to discover it later in a complaint or audit. Three categories are missed almost every time so you should pay close attention to them:

  • Internal tools. Article 50(1) says “natural persons”; it does not say “customers”. A staff copilot is in scope even if a customer will never see it.
  • Vendor features you did not ask for. Suppliers add generative features to existing products. Your call-centre platform may have acquired a summarisation feature since you last looked, and they might have enabled it by default for you.
  • Marketing and brand assets. Generated imagery usually sits with a contracted third-party agency, outside whatever inventory your technology department keeps.

Example inventory table

RefSystemWhat it doesSupplier
AIS-014“Alex” customer service assistantGenerative chat assistant on the website and mobile app. Answers policy questions, explains cover, takes first notice of loss.Northwind Conversational Cloud (vendor SaaS, used unmodified)
AIS-021Claims intake voice assistantInbound telephone assistant on the claims line. Synthesised voice, natural-language intake, routes to a handler.VoxLine Voice AI (vendor SaaS, used unmodified)
AIS-007Marketing content generationGenerative image and copy tooling used by the brand team for campaign assets, including one campaign using a synthetic presenter.Two vendor tools (used unmodified)
AIS-030Claims file summarisationSummarises loss adjuster reports and correspondence into a working brief for the claims handler. Internal only; output never sent to customers.Vendor model via private endpoint
AIS-041Life and health underwriting risk modelRisk assessment and pricing for life and health applications. Built in-house by fine-tuning a vendor foundation model on AlphaInsure claims history.Fine-tuned in-house from a vendor base model
AIS-052Claims fraud triageScores incoming claims for referral to the special investigations unit. A handler decides whether to refer.In-house model
AIS-063Recruitment CV screeningRanks applications against role criteria for the recruitment team.Vendor SaaS (used unmodified)
AIS-070Internal staff assistantGeneral-purpose generative assistant available to all employees for drafting, summarising and research.Vendor SaaS (used unmodified)

Inventory table

RefSystemWhat it doesSupplier
12 blank rows to complete in the document

04Step 2 — Decide your role, system by system

The obligations are split by role, so this must be settled before anything else. And importantly, these are decided per system, not per organisation; the same company is routinely a deployer of one system and the provider of another.

The default stance

If you bought it and use it as supplied, you are a deployer. If you built it, or you put it on the market under your own name, you are a provider.

What you should be aware of

Article 25(1) converts a deployer into a provider in three situations: you put your own name or trademark on a high-risk system already on the market; you make a substantial modification to a high-risk system; or you modify the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk under Article 6. Fine-tuning a foundation model into an insurance underwriting tool is the textbook case of the third. When this happens, the original supplier stops being the provider for that instance and the whole provider obligation shifts to you.

Example role determination table

RefRoleBasis
AIS-014DeployerVendor product used as supplied, without modification and within its stated intended purpose.
AIS-021DeployerVendor product used as supplied, without modification and within its stated intended purpose.
AIS-007DeployerVendor product used as supplied, without modification and within its stated intended purpose.
AIS-030DeployerVendor product used as supplied, without modification and within its stated intended purpose.
AIS-041Provider (Art. 25(1)(c))Fine-tuned in-house from a vendor base model to a purpose within Annex III(5)(c). Art. 25(1)(c) applies: AlphaInsure is the provider.AIS-041 was procured as a vendor model and treated for eighteen months as bought-in. Fine-tuning it to life and health risk assessment made AlphaInsure its provider under Art. 25(1)(c) — moving conformity assessment, technical documentation and post-market monitoring onto us for 2 December 2027.
AIS-052ProviderBuilt in-house. Provider by default.
AIS-063DeployerVendor product used as supplied, without modification and within its stated intended purpose.
AIS-070DeployerVendor product used as supplied, without modification and within its stated intended purpose.

Role determination table

RefRole (provider / deployer / both)Basis for the determination
12 blank rows to complete in the document

05Step 3 — Test each system against the four triggers

Work through each trigger for each system and record the answer even when it is “no”. An absence you can explain is an actual finding, one that you cannot explain is a gap in your process.

T1 · Does it interact directly with a natural person?

Article 50(1). The provider must design the system so the person is informed they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.

On the “obvious” exemption

The Commission’s guidelines frame this using the “average consumer” idea from EU consumer law (identify the actual audience, then ask how well-informed a member of it would be) and direct that the exemption be read narrowly. Our advice: unless the case is overwhelming, disclose anyway. The exemption saves you very little – often a few words.

  • Weak grounds: the assistant has a robot name; there is a small icon; it says so in the terms of service; everyone knows these are bots now.
  • Stronger grounds: the interaction happens inside a product whose whole and only stated purpose is an AI tool, entered deliberately by a user who has already been told.

Note the law enforcement carve-out in Art. 50(1) is narrow and will not apply to commercial deployments.

T2 · Does it generate synthetic audio, image, video or text?

Article 50(2). Providers must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. This is a provider duty. If you buy the tool, the marking obligation sits with your supplier, but you should be checking they discharge it, because their failure becomes your reputational problem and, if you modify the system, potentially your legal one.

The standard editing exemption

The obligation does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics. The line, as the Commission’s guidelines draw it:

Generally exemptGenerally caught
Spellchecking and grammar correctionMinor stylistic polishing that leaves substance, meaning and messaging intactTranscriptionTranslation (for the provider marking duty; see the warning below)SummarisationParaphrasing or rewriting that changes style, structure or meaning beyond minor correctionGenerating new text, images, audio or video from a promptMaterially altering an existing image, recording or video

T3 · Is it emotion recognition or biometric categorisation?

Article 50(3). Deployers must inform the persons exposed, and must process any personal data in line with the GDPR and the Law Enforcement Directive as applicable. Two things to hold in mind before you reach the disclosure question:

  • Some uses are prohibited outright. Article 5 bans emotion inference in the workplace and in education, except for medical or safety reasons. Disclosure does not allow a prohibited practice.
  • Biometric data is special category data. GDPR Article 9 applies and the lawful basis question is usually harder than the transparency question.

T4 · Deep fakes, and AI text published on matters of public interest

Article 50(4). Two distinct duties, both levied on the deployer:

Deep fakes

Image, audio or video content generated or manipulated so that it resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful (Art. 3(60)). Disclose that the content has been artificially generated or manipulated. Where the work is evidently artistic, creative, satirical or fictional, the duty softens to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work; credits or an information panel rather than a burned-in overlay. Commercial advertising is a poor fit for this carve-out!

Public-interest text

AI-generated or manipulated text published to inform the public on matters of public interest must be disclosed, unless the content underwent human review or editorial control and a natural or legal person holds editorial responsibility for the publication. This is the exemption most organisations can actually engineer around: a documented review step with a named accountable editor.

Example trigger determination table

RefT1T2T3T4Outcome
AIS-014YesHighest-volume customer touchpoint. Disclosure carried at the top of the chat window and repeated in the assistant’s first message.
AIS-021YesYesSynthetic speech. Spoken disclosure is the first thing the caller hears, before any menu.
AIS-007YesYesThe synthetic-presenter campaign is a deep fake within the meaning of Art. 3(60) and is labelled accordingly.
AIS-030Generates synthetic text, but the marking duty in Art. 50(2) sits with the provider and no natural person outside the firm is exposed. Recorded as out of scope with reasons.
AIS-041High-risk under Annex III(5)(c). Fine-tuning makes AlphaInsure the provider. No Art. 50 trigger but GDPR Art. 22 applies and high-risk obligations apply from 02/12/2027.
AIS-052Not solely automated: referral requires a handler’s decision on a reasoned basis, so Art. 22(1) is not engaged. Assessment recorded and revisited annually.
AIS-063High-risk under Annex III(4)(a). No Art. 50 trigger, but candidates receive an ADM notice and the recruiter’s decision is documented.
AIS-070YesEmployees are natural persons. Art. 50(1) is not limited to customers — this was the trigger most often missed in our first pass.

Trigger determination table

RefT1T2T3T4Outcome and reasoning
12 blank rows to complete in the document

Download the full document.

The full document continues from here. Step 4 and everything after it (the nine disclosure modules with the model wording, placement and timing rules, machine-readable marking, governance, and three annexes) are in the full Word document.

It is 27 pages, MIT licensed, and yours to adapt: put your own name on it, change what does not fit, and use the result commercially. No attribution needed on what you produce from it.

Download the file

In a couple of days we’ll reach out to make sure everything is clear. If you need any help implementing this, we’re here to assist.

We store these details so we can follow up, and we remember you on this browser for 90 days so you are not asked twice. Full detail in our privacy policy.