AI

AI Transparency Is Now a Release Requirement in Europe

Blackrock Research
August 3, 2026
5 min read

AI Transparency Is Now a Release Requirement in Europe

The European Union’s AI transparency obligations now apply. For consumer businesses, the difficult part is not writing a disclosure. It is keeping enough information attached to an AI interaction or generated asset to know which disclosure is required, place it in the right channel, and prove later that the control worked.

That makes transparency a release-management problem shared by product, marketing, publishing, procurement, and legal teams. It cannot be solved by a policy document that sits outside the systems shipping the work.

What the evidence shows

Article 50 of the EU AI Act began applying on August 2, 2026. The European Commission’s implementation guidance, published on July 20, separates duties for providers from duties for deployers.

Providers must design certain systems so people are informed when they are interacting directly with AI, unless that fact is obvious in context. Providers of systems that generate or manipulate content must also support detection through machine-readable marking, subject to the regulation’s scope and exceptions.

Deployers have a different set of responsibilities. They may need to disclose exposure to emotion-recognition or biometric-categorization systems, label deepfakes, and label AI-generated or manipulated text published to inform the public on matters of public interest when it has not undergone human review or editorial control. The regulation itself sets the legal requirements; the Commission guidance explains how it expects providers and deployers to apply them.

The distinction matters because consumer businesses often deploy systems they did not build. A retailer can buy an assistant from a model provider, configure its behavior, place it inside a shopping journey, and connect it to order data. The vendor can control parts of the underlying system, but it cannot see every interface, escalation, or publishing decision made by the retailer. Buying a compliant model does not automatically make the deployed experience compliant.

There is a limited transition through December 2, 2026, for the machine-readable marking obligation for certain systems placed on the market before August 2. The Commission’s Article 50 facts page is explicit that this is not a general delay. Other applicable duties began on August 2.

The operating consequence

Most companies do not have one clean AI pipeline. A marketing asset can begin in an agency tool, move through an internal assistant, receive edits in design software, pass through a content management system, and be resized by a social platform. If those handoffs remove provenance or machine-readable marks, the final publisher may not know how the asset was made or which label belongs with it.

Customer service has the same continuity problem. A shopper may enter through a rules-based menu, move into a generative assistant, and then transfer to a person. The conversation may resume later through a mobile app or messaging service. A notice shown once on the website is not much of a control if the same interaction can begin elsewhere without it.

This is why counting disclosures is a weak compliance measure. The better questions are whether the disclosure appears before or at the relevant interaction, survives a change in channel, stays associated with the correct asset, and can be reconstructed after release.

The human-review exception for certain public-interest text also raises an evidentiary issue. “A person looked at it” is not a durable operating standard. Teams need to define what review means, who has authority to approve publication, and what record shows that meaningful editorial control occurred.

What operators should do now

Start with customer journeys, not a list of AI vendors. Identify every point where AI communicates directly with a person, generates or materially alters content, or performs sensitive classification. For each use case, name the provider, deployer, channel owner, content owner, and accountable reviewer.

Carry provenance with the asset. A durable record should identify the generating system, creation time, material transformations, review status, disclosure decision, and publishing destinations. Where machine-readable marking applies, test the final output after resizing, transcoding, screenshots, syndication, and CMS processing. Testing only the source file misses the place where marks are often lost.

Treat the AI notice as a tested interface state. Cover web, app, voice, embedded widgets, resumed conversations, and transfers between automated and human support. Instrument the state so teams can verify that the notice appeared rather than relying on a screenshot from a happy-path test.

Update vendor requirements around evidence, not just warranties. Contracts should state who applies notices and marks, how provenance survives transformations, what documentation the supplier provides, and how product changes are communicated. A broad promise of compliance is of limited use when the release team cannot obtain the data needed to implement its side of the control.

Finally, separate legal interpretation from operating proof. Counsel should determine how Article 50 applies to a particular system. Product and operations should be able to show what was deployed: versions, logs, approvals, tests, and the customer-facing result.

The decision

Europe’s transparency rules expose a basic weakness in many AI programs: the model, asset, interface, and publishing record are managed as separate objects. Article 50 requires operators to reconnect them.

The businesses most likely to stumble are not necessarily those using the most AI. They are the ones that lose the history of an interaction or asset between generation and release. Transparency begins with a label, but compliance depends on continuity.