On August 2, 2026, two of the world's largest markets in the US and Europe began demanding a new level of AI transparency. Both want the person on the receiving end of an AI system to be aware that a machine was involved, and the disclosure should be verified by software rather than taken on faith.
The European instrument is Article 50 of the AI Act. The American counterpart is the California AI Transparency Act, enacted as SB 942 and amended last year by AB 853, which moved the operative date from January 1, 2026 to August to align with the European schedule. State legislatures have started setting their clocks to Central European Time.
California’s law impacts any provider of a publicly accessible generative system with more than a million monthly users in the state. Those providers (1) run a free public AI detection tool, (2) offer users a visible disclosure option on a generated image, video and audio, (3) embed a latent provenance disclosure in that content, and (4) push transparency terms down to licensees. Penalties run $5,000 per violation, with each day of a continuing violation counted separately. AB 853 phases in duties for large online platforms and generative AI hosting platforms on January 1, 2027, and for capture device manufacturers a year after that.
Utah and Washington followed suit in March 2026. HB 276 and HB 1170 build provenance regimes modeled closely on California, using the same threshold of a million monthly users, with Utah’s provider and platform duties commencing on January 1, 2027. Three aligned state statutes start to feel like a national standard.
A second and much broader patchwork of state laws covers chatbot disclosure, starting with Utah in May 2024. New York’s AI companion statute took effect in November 2025 and California’s SB 243 in January 2026. Oregon and Washington arrive in January 2027. Beyond the states, the FTC's authority over deceptive practices extends to every AI chatbot in the country, and the FCC ruled in February 2024 that an AI-generated voice qualifies as an artificial voice under the TCPA, bringing AI voice calls under the existing robocall consent rules.
Your location does not exempt you from these requirements. The EU AI Act applies to anyone whose AI outputs are used within the Union, regardless of legal presence. Even companies without European operations must comply with evolving US laws that increasingly align with European technical standards.
The European version arrived in July.
On July 24, 2026, Regulation (EU) 2026/1744 appeared in the Official Journal and entered into force three days later. It was the change that European AI programs had been waiting for 18 months. Obligations for standalone high-risk systems under Annex III were moved from August 2026 to December 2027, and obligations for AI embedded in regulated products were moved to August 2028. Teams that had been building toward an August deadline slowed down.
In contrast, Article 50 was left almost entirely intact by the amendment and went into effect in August. It binds systems that were already in the market on that date, and breaching it carries administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The original shared go-live date for the high-risk regime was set accidentally rather than intentionally. When the anchor moved, a large number of organizations moved their entire program, only to find that one piece had been left behind.
Many companies approach disclosure as a one-time legal notice drafted by counsel and inserted into the interface. This method is ineffective: users gain no meaningful information, and the business incurs a measurable trust penalty, as recent research demonstrates.
Disclosure is a product decision that includes determining its placement, level of detail, responsible parties, and persistence throughout the content lifecycle. Product owners should collaborate with risk owners to make these decisions.
What applies now
Because Article 50 ignores the risk tier entirely, it is the widest-reaching part of the AI Act. A system is covered if it does one of these four things.
Interact directly with a person
Providers of AI systems designed to interact with people must ensure those people know they are interacting with a machine. This includes chatbots, voice assistants, complaint-handling bots, AI hotlines, coding agents and social media bots that generate rather than template their replies. The exception is narrow. Disclosure can be skipped where the AI nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person as judged against the audience the system will reach.
Generate or manipulate synthetic content
Providers of systems that produce synthetic audio, image, video or text must mark the outputs in a machine-readable format and make them detectable as artificially generated. Capability alone triggers the requirement.
Recognize emotions or categorize people biometrically
Deployers must tell the people exposed to those systems that they are running.
Publish AI-generated materials on matters of public interest.
Deployers must disclose that the content was artificially generated or manipulated. The public-interest text duty falls away where a human has reviewed the content and a named person or entity carries editorial responsibility for it.
The Commission adopted formal guidelines on all four components in July 2026, and while the guidelines are not legally binding, national authorities will treat them as the reference text.
Two structural features can cause confusion.
The first is the split between providers and deployers. The interaction and marking duties sit with providers, meaning whoever develops a system and puts it on the market under their own name or trademark. The emotion-recognition and deepfake duties sit with deployers, meaning whoever uses a system under their own authority.
Almost every large organization is both. A bank running a third-party chatbot on its service portal is a deployer, while the same bank fine-tuning its own content model and shipping it under its own brand is a provider. The Commission has confirmed that both sets of duties can fall on a single company at the same time.
The second is agency work. Where a marketing or creative agency operates a system under your responsibility and control, you remain the deployer. Where the agency decides for itself whether and how to use AI in the assignment, it becomes the deployer and assumes the disclosure duty. Most creative services contracts written before 2025 are silent on which arrangement applies.
Providers of generative systems already on the market have until December 2026 to bring machine-readable marking into conformity, and that transition covers marking alone. Everything else applies from day one with no runway. Content both generated and published before August needs no retroactive labeling, while content generated before that date and published after it does.
The evidence nobody wants
Telling people you used AI costs you trust, and this is now one of the better-replicated findings in the applied behavioral literature. Schilke and Reimann ran thirteen experiments across professional settings, from a professor grading work to an investment fund reporting to clients, and published the findings in Organizational Behavior and Human Decision Processes. Holding actual AI use constant, people who disclosed using AI were trusted less than people who stayed quiet. The mechanism they identify is legitimacy, since disclosure signals a departure from what the evaluator expected as proper conduct, and trust follows legitimacy down. Regardless of whether the disclosure was voluntary or mandatory, the finding held.
Altay and Gilardi found something sharper in the news context. Labeling a headline as AI-generated reduced how accurately readers judged it and their willingness to share it, regardless of whether the headline was true or whether a machine had written it. Probed for a reason, readers said they took “AI-generated” to mean fully automated, with no human oversight anywhere in the chain.
The commercial version is even starker. Researchers at Washington State and Temple ran six experiments with more than a thousand US adults, varying only whether a product description carried the words “artificial intelligence.” Purchase intention fell each time, mediated by emotional trust, and fell most sharply for higher-risk products such as cars and diagnostic tools.
Executives may conclude that disclosing only the minimum required information in the least visible manner is safest. However, this approach is flawed for two reasons.
First, the cost of concealment is higher. Schilke and Reimann also tested third-party exposure, where the AI use came to light without the actor volunteering it. The damage to trust from being found out was greater than the damage from disclosing. Given that machine-readable marking is now mandatory for providers and that platforms are building detection into their pipelines, the odds of an organization keeping quiet successfully are falling every quarter. The choice is between a smaller cost you control and a larger one that you do not.
Second, and this is a deeper problem, the trust penalty attaches to a particular reading of the label rather than to the label itself. Readers penalize what they take to be an absent human. If there is a visible human, the shape of the penalty changes.
Trattner and colleagues at Bergen tested this theory with more than 6,000 participants from the audiences of six major news outlets in the US, UK and Norway. Each saw article previews with images, either bare or carrying a C2PA provenance label at one of three levels of detail. Showing provenance metadata increased how transparent and credible participants judged the image and increased their trust in the outlet publishing it. What separates that finding from the AI-label studies is that a provenance record gives the reader something to inspect. A bare category label leaves them to interpret a word on their own, and the interpretation runs pessimistic.
In another survey, Toff and Simon found that readers rated AI-labeled articles as less trustworthy even while rating them accurate and fair, and that disclosing the sources used to produce the article reduced the effect
Product design should ensure that disclosures include information about human responsibility. A label stating only that a machine was involved may lead to negative assumptions. Including who reviewed the content, their responsibilities, and a contact for complaints provides greater transparency and reassurance.
Four variables you control
Article 50 requires that disclosure information must reach the person “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” and that it must meet applicable accessibility requirements. Beyond that, the law is quiet on the format, leaving four decisions to the product team.
Placement and timing
The Commission’s guidelines eliminate the easy options. Burying disclosure in terms and conditions fails to meet the requirement, as does placing it behind a URL, in technical documentation, or in machine-readable markings. The guidelines recommend combining text, visual and spoken cues (if possible), reasoning that a single channel is easy to miss.
The practical standard is whether a user can recognize the disclosure within four seconds. In chat interfaces, this means providing an initial statement and a persistent indicator, as opening messages may be missed in longer sessions. Voice channels should present the disclosure within the first few seconds, before substantive content. For published materials, the icon or label must be visible upon first exposure and not obscured by overlays.
Granularity
This is where the research really helps and where most legal drafts go wrong.
Prajod and colleagues at CWI Amsterdam ran a controlled study comparing three conditions in a news reading task, running from no disclosure, to a one-line disclosure, to a detailed one that (1) named which production steps used AI, (2) confirmed human oversight and (3) gave a contact for reporting errors.
Trust scores and subscription rates under the one-line condition matched the no-disclosure condition. The detailed condition surpassed both scores. While the sample was small, it directionally matches the broader literature.
Approximately two-thirds of participants preferred the detailed disclosure, citing its transparency and the inclusion of an error-reporting contact. Most who favored the shorter version requested a concise disclosure with an option to access more information if desired. A small number of participants did not notice the disclosure.
The results suggest a two-layer structure. A short, plain first layer conveys the notice at no cost. An interactive second layer holds the detail for the minority who go looking. The EU icon guidance points to the same architecture, noting that when a second layer is used, the icon should indicate that more information is available, and the second layer should be navigable by assistive technology.
Who is named
The transparency dilemma runs through legitimacy, and legitimacy runs through accountability. A disclosure that (1) names the responsible team or function, (2) states what a human reviewed, and (3) gives a route to report an error does more work per word than a longer one that says only that a model was used.
In the EU Act, the public-interest text obligation does not apply where content has undergone human review and a natural or legal person holds editorial responsibility for it. The legislator’s escape hatch is a named accountable human. Companies can build the same structure into disclosures that do not qualify for the exemption to achieve much of the same trust benefit.
Survival
A disclosure that disappears when content is reshared is ineffective. Disclosures are most important when content reaches audiences outside the original channel. While owned platforms allow for controlled rendering, syndication, partner placements, and social media require testing to ensure disclosures persist throughout distribution.
The provenance layer, and its honest limits
Machine-readable marking under Article 50(2) has two components.
Marking
Outputs must carry marks structured so that software can find and extract them without a human in the way. The Act prescribes no technique. Watermarks, signed metadata, cryptographic provenance, and logging and fingerprinting all qualify, alone or in combination, as long as the solution meets four quality requirements. They are (1) effectiveness, (2) reliability, (3) robustness and (4) interoperability. As an example, a watermark that a screenshot erases or a social upload strips fails the robustness hurdle.
Detection
Providers must also make available a mechanism that allows people, authorities, researchers, fact-checkers, and journalists to verify whether a piece of content originated from the system. The Code expects the mechanism to be free and publicly accessible in most cases. While many organizations have scoped the marking work, most have skipped the detection dimension entirely.
The dominant technical answer to the marking requirement is C2PA Content Credentials (version 2.4, April 2026), with more than 6,000 members and affiliates in the coalition and a full conformance program running through the year. The latest version has been moving toward international standardization, and JPEG Trust has taken the earlier version into ISO/IEC 21617-1. The California, Utah and Washington statutes rely on a similar approach and allow a single technical decision to satisfy multiple regimes simultaneously.
Because a program built on optimism often fails the first real test, it is helpful to address the limits.
C2PA manifests are stored in the file container with EXIF and XMP metadata. Most social platforms re-encode images and videos on upload, often removing metadata unless specifically preserved. As of mid-2026, major platforms typically strip or do not retain C2PA manifests, except in limited cases where the platform uses the credential for labeling before discarding it. Organizations should test their own distribution channels rather than relying solely on vendor documentation.
The AI Act creates a marking duty for providers but does not prohibit third parties from removing, altering, or overwriting those marks before content circulates. This is a striking gap compared to copyright law, where knowingly stripping rights management information is an offense with its own remedy. While robustness requirements cover part of the exposure, a determined adversary gets through them. California and Utah are closing that gap and require platforms, starting in January 2027, to prevent the knowing stripping of compliant provenance data or digital signatures from content they distribute.
The evidentiary logic of provenance is asymmetric and matters to anyone who thinks a detection tool solves the problem. While valid credentials on a file tell you something, absent credentials tell you almost nothing because most authentic content in circulation carries no credentials at all and never did. A verification workflow that treats absence as suspicion will drown in false positives.
The Code of Practice on Transparency of AI-Generated Content was published in June 2026, and the Commission and the AI Board have confirmed it as an adequate voluntary tool. About 190 companies and organizations signed the code in the first 60 days, which changes the enforcement posture. Supervisors assess signatories against the commitments rather than running a free-standing technical review of their solution. Non-signatories demonstrate adequacy by other means, individually, to whichever market surveillance authority comes asking, and forgo whatever mitigating weight adherence carries when a fine is set. The Dutch data protection authority has publicly advised providers to sign.
The Code organizes its commitments in four parts.
Implement a marking solution, which for most content types means signed metadata combined with an imperceptible watermark.
Make a detection solution available, generally free and publicly accessible.
Meet the four quality requirements, with an interoperability solution due in February 2027.
Document a compliance process, with regular testing, trained staff and cooperation with market surveillance authorities.
With regard to outsourcing, a provider can build on a watermark embedded by the underlying foundation model or buy the marking from a specialist vendor. The legal duty does not travel with the work. The provider must vet the solution and stand behind it, in the same way a data controller stands behind a processor it appointed.
The exceptions, and how narrow they are
Three statutory exceptions apply to the marking duty. First, systems performing an assistive function for standard editing are out of scope. This includes routine preparation of existing content, such as grammar, spelling, house style, minor cropping or compression. Second, machine translation is treated as an editorial operation. Third, systems that do not substantially alter the input data or its meaning are out, covering transcription, color correction and light stabilization. Systems authorized by law for criminal investigation are also exempt.
The list of what remains in scope is longer and includes AI-generated summaries, substantive rewrites that reshape a text, face replacement, voice synthesis, and composite images of events that never happened.
The guidelines add proportionality carve-outs. Systems embedded in closed physical products from which output cannot leave are exempt. In film, animation, gaming and advertising, only the finished consumer-facing deliverable requires marking, so intermediate outputs within a closed production pipeline can remain unmarked.
Internal business applications can qualify, but only if three conditions are met. The system runs (1) inside a controlled organizational perimeter, (2) output is not destined to circulate beyond it, and (3) safeguards against foreseeable misuse are in place, such as environment isolation and role-based access. Anything consumer-facing loses the safeguard, and few enterprise tools can promise the materials never leave the building.
Four disclosure patterns
To help illustrate the challenge, consider a composite mid-market European retailer with roughly €2 billion in revenue, selling across seven member states. Under Article 50, four of its systems land in four different areas, and the design has to change for each case.
Pattern one: the conversational front door
The retailer runs a customer service assistant on its site and app, built on a third-party platform and branded as its own.
The initial consideration is whether the retailer is classified as a provider or deployer under the Act. If the platform vendor markets the system under its own name, the vendor is the provider and assumes the interaction duty. If the retailer brands the system as its own, it becomes the provider. This designation should be clearly defined in the vendor contract, not left to informal communication.
The disclosure should (1) begin the session with clear language, (2) remain visible throughout the session, and (3) specify how to reach a human representative. Providing this route addresses the requirement and offers accountability, which helps mitigate trust concerns. Companies should avoid including the assistant's name or photograph, as the Commission has indicated that realistic designs are less likely to qualify for the obviousness exception. Additionally, combining a human-like persona with a disclosure may cause confusion.
It is important to consider the handoff mechanics. If a bot handles the opening and a person takes over, the disclosure duty still applies. Where a person reviews the model’s suggestion and makes their own call, Article 50(1) does not apply. A human who pastes the model’s draft without reading it is not, in any sense, in the loop under the guidelines.
Pattern two: the content pipeline
The brand team generates product imagery, lifestyle photography and campaign copy with generative AI tools.
This output is not a deepfake under AI Act guidelines, and the deployer labeling duty under Article 50(4) does not apply. While this is the correct legal interpretation, two factors still apply. If the retailer built or branded the generation tool, it is a provider and owes marking and detection on the outputs. If a synthetic model, a synthesized voice, or an AI-altered image of a real person, place, or event is used in a campaign, the deepfake duty attaches, and the EU icon set is available with the placement rules specified in the Code.
Operationally, maintaining an inventory is essential. The retailer must track which assets in its digital asset management system are machine-generated, which are machine-altered and to what extent, and which tools produced them. Capturing this metadata at the time of generation is cost-effective and avoids the expense and inaccuracy of retrofitting later.
It is important to review agency contracts. If the creative agency decides whether to use generative tools, the agency is considered the deployer and is responsible for disclosure. While this may be legally sufficient, it poses reputational risks since the retailer’s logo appears on the final product.
Pattern three: the agent acting outward
The retailer runs a scheduling agent that books in-home appliance installations by calling and emailing customers to arrange times. blah blah balh
This pattern creates the widest gap between what teams assume and what the guidelines say. Article 50(1) covers systems intended to interact directly with people. For agents, the Commission’s guidelines extend to systems capable of interacting with a person while carrying out their assigned work, including scheduling, handling correspondence, negotiating, entering into agreements, and completing purchases. The trigger is capability. The analysis cannot stop at the primary use case; it must cover every scenario in which contact with a person is reasonably foreseeable.
The guidelines go further. An agent capable of interacting with other agents must account for downstream agents reaching a human, thereby extending the duty to indirect contact. Where the provider cannot predict at design time whether contact will occur, the agent must be built at the architecture and instruction levels to identify itself in every foreseeable case, including when the person on the other side is acting on behalf of a company.
There is a disclosure the other way as well. The guidelines say the person directing the agent should also be told at (1) authorization requests, (2) status updates, (3) validation checkpoints and (4) the start of each new exchange. An agent that quietly accumulates authority across a long-running session is a governance problem long before it is a compliance problem.
For the retailer, the identification line needs to be included in the agent’s system instructions, so it can be tested as a behavior and logged in the same trace that records the agent's actions.
Pattern four: the internal system whose output escapes
Analysts at the retailer use an internal assistant to draft summaries of supplier performance and market conditions.
At first glance, this scenario qualifies for the internal carve-out, as the system operates within organizational boundaries and outputs are intended for colleagues with controlled access. However, the third condition is frequently unmet, as content can easily be shared externally, and safeguards are often insufficient in practice.
The control belongs on the edge rather than on the tool. Anything moving from an internal system to a customer, supplier, regulator, or public channel passes through a defined step in which its origin is recorded, marked, and labeled according to the destination. That step doubles as your evidence file when someone asks about the origin of a specific paragraph.
Owning it
A significant challenge is that Article 50 does not align neatly with any existing function. Legal teams interpret the requirements but cannot draft disclosures suitable for chat interfaces. Product teams manage the interface, while Marketing commissions content without insight into the underlying processes.
Four artifacts help correct the situation, and a program can address them in 3-6 months.
A system register with the role recorded per system
Provider, deployer, or both. The status is reviewed whenever a vendor relationship changes, branding changes, or a system gains generative capabilities.
A content register keyed to the systems
What was generated, by which tool, with what marking, and who reviewed it.
A disclosure pattern library
Develop approved first-layer text and second-layer content for each interaction type. Product copywriters should draft these materials, with legal review rather than authorship, and user testing is essential. Since most users will not access the second layer, it should be tested independently. Those who do are often the most discerning and require particular attention.
An evidence file
Screenshots of live disclosures, the marking standard you selected and why, robustness test results, the reasoning behind any exception you claimed, and the vendor contracts that allocate the roles. This package is much harder to reconstruct after an inquiry lands.
Three metrics are worth reporting upward.
Coverage is the share of in-scope systems carrying a verified compliant disclosure.
Survival is the share of published assets whose provenance data is still intact at the far end of your real distribution path.
Latency is the lag between a system gaining a new capability and the disclosure being updated.
The part that reaches the customer
European enforcement will be uneven for a while. Member states missed the original August 2025 deadline to designate national competent authorities by a wide margin, and designation remains patchy. Identical conduct will trigger an inspection in one member state but not in another during the early cycles. Companies should plan against the strictest national interpretation because a single well-resourced regulator will set the working standard, as we saw under GDPR.
The monetary fine is the wrong thing to organize around. Article 50 is the first part of the AI Act that reaches customers directly with no regulator standing in between. Every time someone opens a chat window on your site or scrolls past an image your brand team made, they run a small private self-assessment of whether you are being straight with them. The high-risk regime arrives in December 2027 and will test whether your documentation withstands professional scrutiny. Article 50 is running a harder test today with an audience that never reads your documentation.
A disclosure written as legal text will satisfy nobody. You absorb the full trust penalty and collect no credit for being honest. Designing the disclosure (1) costs less, (2) keeps open the option of being believed later, and (3) produces the content inventory and provenance plumbing that the next three years of regulation will require regardless.
The calendar is crowded. Machine-readable marking for generative systems already in the European market becomes enforceable on December 2, 2026. In January 2027, the California and Utah platform duties take effect, and a large online platform will owe users a duty to detect, disclose, and inspect provenance data, as well as a duty not to knowingly strip it. By February 2027, Code of Practice signatories are expected to have an interoperability solution in place.
Customers will find out that your systems are AI. Marking is mandatory now, and detection is being built into the distribution layer. The answer reaches them whether you supply it or not. What remains open is whether they hear it from you first, in language you chose, from someone who will answer for it.
Trusted AI is written for executives, board members and senior practitioners building, funding or overseeing AI programs. Have a topic you want covered? Reply to any issue or reach out on LinkedIn.
Sources
Regulation and guidance
Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal 24 July 2026, in force 27 July 2026
EU AI Act (Regulation (EU) 2024/1689), Article 50 and Article 113
European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, adopted 20 July 2026
European Commission, Code of Practice on Transparency of AI-generated Content, final version 10 June 2026, and the associated EU icon set
California AI Transparency Act (SB 942 as amended by AB 853), operative 2 August 2026
Utah HB 276, Digital Content Provenance Standards Act, signed 24 March 2026, effective 1 January 2027
Washington HB 1170, AI-modified content, signed March 2026
Utah AI Policy Act (SB 149, amended by SB 226); California SB 243; New York General Business Law Article 47
FCC Declaratory Ruling 24-17 (8 February 2024), AI-generated voices under the TCPA
Research cited
Schilke, O. and Reimann, M. (2025). The transparency dilemma: how AI disclosure erodes trust. Organizational Behavior and Human Decision Processes, 188, 104405
Altay, S. and Gilardi, F. (2024). People are skeptical of headlines labeled as AI-generated, even if true or human-made, because they assume full AI automation. PNAS Nexus, 3(10)
Trattner, C., Forstner, S. L., Starke, A. D. and Knudsen, E. (2026). C2PA provenance labels increase trust in digital news platforms across Western countries. ICWSM, 20(1), 2267 to 2279
Prajod, P. et al. (2026). Full disclosure, less trust? How the level of detail about AI use in news writing affects readers’ trust. arXiv:2601.09620
Toff, B. and Simon, F. M. (2025). The dilemma of AI disclosure for audience trust in news. International Journal of Press/Politics, 30(4)
Cicek, M., Gursoy, D. and Lu, L. (2024). Adverse impacts of revealing the presence of AI technology in product and service descriptions on purchase intentions. Journal of Hospitality Marketing & Management, 34(1)


