If you are shipping AI into the world in 2026, “trust us, it’s safe” is no longer an acceptable answer.

Regulators in the EU and US are now writing into law what used to be soft best practices: you have to label AI-generated content in certain contexts, explain how high‑risk systems work, and document what data and methods went into your models. At the same time, platforms and AI providers like OpenAI, Google, and Anthropic are layering on their own disclosure and usage rules.

The result is a fast‑moving, slightly confusing patchwork of transparency requirements. But underneath the legalese, the big idea is simple: if your AI system can meaningfully affect people, they should not have to guess if they are talking to a machine, how the system is being used, or what data you are quietly collecting along the way.

This post breaks down the main categories of “must disclose” obligations that are already here or imminent, and what they mean for you in practical terms.

1. Why AI transparency is becoming mandatory, not optional

For years, AI “ethics” conversations focused on voluntary principles: fairness, accountability, explainability. Companies proudly published model cards and principles documents, but there was limited enforcement.

That is changing. In August 2026, the European Commission began enforcing core parts of the EU AI Act, including new transparency requirements for certain AI systems and for “general‑purpose” models like large language models (LLMs). The Commission explicitly frames this as giving people and businesses confidence that AI is developed and used safely and transparently.Source

In the US, the Biden administration’s Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence requires developers of the most powerful models to report safety test results and certain deployment details to the federal government, and directs agencies to set guidance for testing and public reporting about AI use.Source

On top of that, regulators like the US Federal Trade Commission (FTC) have made it clear there is no “AI exemption” from existing consumer protection, privacy, and advertising laws. If you quietly change how you use customer data to train models without clear notice and consent, or bury key disclosures in fine print, you can expect trouble.Source

So transparency isn’t just a “nice to have” for reputation anymore. It is increasingly a regulated requirement.

2. Core transparency obligations under the EU AI Act

The EU AI Act is currently the most detailed framework for AI transparency. It creates several different buckets of obligations depending on the type of system.

2.1. High‑risk AI: explain how it works and how to use it safely

If your system is classified as high‑risk (for example, used in hiring, credit scoring, education, or some safety‑critical functions), Article 13 of the AI Act requires that it be designed to ensure sufficient transparency so that deployers (your customers) understand and can appropriately use the outputs.Source

In practice, that means you must provide:

  • Instructions for use, including:
    • The system’s intended purpose
    • Performance characteristics and known limitations
    • Conditions where it should or should not be used
  • Information needed to interpret outputs correctly
  • When appropriate, information about:
    • Input data specifications
    • Key aspects of the training, validation and testing data sets, relevant to the intended purpose

Think of it as a detailed “owner’s manual” for your model. If you are selling an AI assessment tool to HR teams or a risk model to banks, you cannot just provide a black‑box API with no explanation.

2.2. Transparency to people: deepfakes, chatbots, and emotion recognition

Article 50 of the AI Act imposes direct transparency obligations to end users for certain types of AI systems.Source Providers and deployers must:

  • Inform people they are interacting with an AI system (e.g., a chatbot), unless this is obvious from the context.
  • Disclose when content is synthetic or manipulated (e.g., deepfake audio or video), at the latest when the person is first exposed to it.
  • Inform people when emotion recognition or biometric categorisation systems are in use, except in a narrow set of law‑enforcement situations.

This is where explicit AI labels and on‑screen notices come in. If your marketing team uses a generative video tool to create a synthetic spokesperson, you cannot just drop that into a campaign without marking it as generated or manipulated.

For developers of general‑purpose models (foundation models, LLMs, etc.), the AI Act adds more obligations:

  • Provide a summary of the content used for training (not a full dataset dump, but a meaningful high‑level description).
  • Put in place and publish a policy for complying with EU copyright law, including how you respect “opt‑out” reservations of rights under EU text and data mining rules.Source

Even open‑source models are not completely exempt; they still need to meet some transparency obligations around training data summaries and copyright.

If you are building on top of models like OpenAI’s GPT‑4, Anthropic’s Claude, or Google’s Gemini, expect to see more structured documentation and training summaries in their technical and safety reports as they comply with these rules.

3. US direction: safety testing, reporting, and honest data practices

The US has not passed a comprehensive AI law like the EU (yet), but there are still concrete transparency expectations.

3.1. Reporting large‑scale models and safety testing

The 2023 US Executive Order on AI requires companies developing the most powerful foundation models to:

  • Notify the federal government when they are training large‑scale AI systems that meet certain compute or capability thresholds.
  • Share safety test results and other critical information about these models before broad deployment, to show they do not pose serious national security or safety risks.Source

This is more about government‑facing transparency than end‑user labeling, but if you are building cutting‑edge models, you should assume regulators will expect to see documentation of testing, red‑teaming, and risk mitigation.

3.2. FTC: clear, conspicuous disclosures and no surprise data use

The FTC has repeatedly warned AI companies that using “AI” does not let them sidestep existing consumer protection laws. In its AI guidance, the FTC points out that:

  • Companies have been penalized for quietly disclosing or repurposing user data (e.g., for ad targeting) despite promising confidentiality.
  • Changing terms of service or privacy policies and using buried or confusing disclosures can violate the law.
  • If you retain or use consumer data for new AI‑related purposes, you must provide clear and conspicuous notice and obtain affirmative express consent.Source

If you are using customer inputs to fine‑tune models (for example, chat logs from a customer support bot you deploy), you need a transparent explanation of that in your privacy notices and contracts — not just a vague “we use your data to improve our services” line.

4. Platform and provider rules: disclosure baked into tools

Beyond formal laws, AI providers and major platforms are introducing their own transparency expectations that you have to abide by if you build on them.

OpenAI’s Usage Policies and help center make clear, for example, that:

  • You cannot use their tools to create deceptive synthetic media, fake endorsements, or political astroturfing like fake voter letters or comments.Source
  • You are responsible for making sure your use of their models complies with applicable law, including disclosure and transparency duties.Source

Similar expectations exist for other major players (Google’s Gemini, Anthropic’s Claude, Meta’s Llama ecosystem): label synthetic media, do not mislead people about what is AI‑generated, and respect privacy and consent when training or fine‑tuning.

If you are building an app on top of ChatGPT, Claude, or Gemini, you are effectively bound by two layers of transparency rules:

  1. What the law and regulators require in your jurisdiction.
  2. What your upstream AI provider’s policies require as a condition of access.

Ignoring either can result in account suspension, legal risk, or both.

5. What your company should be disclosing in practice

So what, concretely, should you plan to disclose if you are building or deploying AI systems in 2026? The details will vary, but most organizations should be aiming to cover at least these categories:

  1. AI involvement

    • When users are interacting with an AI system rather than a human (chatbots, voice agents, automated decision tools).
    • When content they see (text, images, audio, video) is substantially AI‑generated or AI‑manipulated, especially in sensitive contexts like news, politics, or advertising.
  2. Purpose and scope

    • What the AI system is designed to do (and not do).
    • What decisions or recommendations it supports (e.g., triaging applications vs. making the final hiring decision).
  3. Data use

    • What data you collect through the AI system (inputs, metadata, logs).
    • Whether and how you use that data for training, fine‑tuning, or evaluating models.
    • What third parties (if any) receive that data, including upstream model providers.
  4. Limitations and risks

    • Known failure modes (e.g., hallucinations, bias tendencies, performance thresholds).
    • Appropriate human oversight requirements (“do not use this output as the sole basis for…”).
  5. User controls

    • How users can opt out of certain data uses where required or appropriate.
    • How they can seek human review or appeal important decisions supported by AI.

Translating this into practice means combining on‑screen notices, policy documents (privacy notices, AI fact sheets), and B2B documentation (model cards, technical annexes).

6. How to operationalize AI transparency in your org

If you are feeling overwhelmed, it helps to think of transparency as a product feature, not just a compliance chore. A practical approach could look like this:

  • Inventory your AI systems.

    • Map out where you use AI today: internal tools, customer‑facing features, third‑party models you call behind the scenes.
    • Flag anything that touches hiring, credit, health, education, public services, or safety‑critical decisions as “high‑risk candidates.”
  • Create a standard “AI disclosure profile” template.

    • For each system, capture: purpose, inputs, outputs, training/fine‑tuning data sources, limitations, and oversight requirements.
    • Use this as the backbone for your model cards, customer documentation, and user‑facing FAQs.
  • Design user‑friendly disclosures.

    • Avoid burying key information in dense legal text. Use layered notices:
      • Short, plain‑language prompts (“You are chatting with an AI assistant. Here is what it does and how we use your data.”)
      • Links to deeper documentation for those who want more detail.
  • Align with upstream provider policies.

    • If you use ChatGPT, Claude, Gemini, etc., review their latest usage and transparency policies.
    • Mirror or extend their expectations in your own terms of service and product UX.
  • Build in review and logging.

    • Keep records of what you disclosed, when, and to whom (particularly in B2B settings).
    • Periodically review and update disclosures as models, data practices, and laws evolve.

You do not have to get it perfect on day one, but you do need a repeatable process rather than ad‑hoc labels and disclaimers sprinkled around your product.

7. Actionable next steps

To make this concrete, here are three steps you can take in the next 30–60 days:

  1. Run a quick AI transparency audit. List your current AI‑powered features and, for each, answer: “Would a reasonable user clearly know AI is involved? Do we clearly explain what happens to their data?” Anywhere the honest answer is “no” becomes a priority.

  2. Draft standard disclosure language. Work with legal and product to create a small library of plain‑language notices for: AI chatbots, AI‑generated or manipulated media, and automated decision support. Reuse and adapt these instead of reinventing them for every new feature.

  3. Prepare for EU and US expectations. Even if you are not EU‑based, assume EU‑style transparency norms will spread. For any high‑impact or high‑risk AI you sell, start building the documentation the EU AI Act expects (intended use, limitations, data summaries) and the testing reports US agencies increasingly want to see.

If you treat transparency as part of the user experience — not just a regulatory checkbox — you will be better positioned as rules tighten and as users become more skeptical about AI‑powered products.