
AI Transparency Rules: What They Actually Say, and What They Don't
European AI transparency rules are narrower than people think. What the law requires, who it applies to, and the exemption most businesses meet.
Ask around and you will hear that European law now forces you to label anything you write with AI. Several agencies are selling compliance services on that basis.
It is not what the law says. The AI transparency rules are real, they apply, and they are much narrower than the panic suggests. Most of what your business publishes is not covered, and the reason is written into the text itself.
We are not lawyers and this is not legal advice. What follows is the regulation quoted directly, so you can see the wording and decide what applies to you.
Do I have to label AI-generated content?
In most business cases, no. The European rules place the marking duty on the companies that build AI systems, not on you. The separate duty to tell readers applies to deep fakes, and to text published to inform the public on matters of public interest. Content that a person reviewed and takes responsibility for is expressly excluded.
Who the rules actually bind
The regulation splits responsibility between two roles, and almost every argument about this topic comes from mixing them up.
Providers are the companies that build and supply the AI systems. OpenAI, Google, Anthropic, Mistral.
Deployers are everyone using those systems in their work. That is you, and us.
Most of the marking obligations land on providers. The disclosure obligations that land on deployers are limited to specific situations.
What providers have to do
Two things matter to you, even though neither is your job.
The first is that people must know when they are talking to a machine. Providers must ensure that systems built to interact directly with people are designed so that "the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect."
That last clause does real work. If your website chatbot is plainly a chatbot, you are not required to put a warning on it.
The second is invisible marking. Providers of systems "generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."
This is already happening. Google DeepMind's SynthID embeds watermarks into AI-generated images, audio, text and video across Google's consumer AI products, and the company describes them as imperceptible to humans but detectable by its own technology.
Worth sitting with for a moment. Text you generate may carry a signal you cannot see, put there by the company whose model you used, on the instruction of European law.
What you have to do
Here is the provision that most articles about this topic either skip or get wrong. Deployers of a system that generates or manipulates text published to inform the public on matters of public interest must disclose that the text was artificially generated or manipulated.
And then, in the same paragraph, the exemption:
"This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."
Read that twice. If a person reviewed the content, and a person or a company takes editorial responsibility for publishing it, the duty to disclose does not apply.
For a business blog, a service page, a newsletter or a social post that somebody edited and signed off, that is the end of the analysis. There are two further conditions before you even reach the exemption: the text has to be published to inform the public, and it has to concern a matter of public interest. A page about your opening hours is neither.
The one place to be careful is deep fakes. Where a deployer generates or manipulates image, audio or video that resembles real people, places or events, the duty to disclose applies and there is no editorial-review exemption for it.
| Situation | Who is responsible | Do you have to tell the reader? |
|---|---|---|
| Blog post drafted with AI, edited and published by you | You, as deployer | No, if a person reviewed it and takes responsibility |
| Chatbot on your site | Provider designs it, you deploy it | Only if it is not obvious that it is a machine |
| Synthetic video of a real person | You, as deployer | Yes |
| Product photo generated from scratch | You, as deployer | Not as a deep fake, if it depicts nothing real |
| Machine-readable marking of the output | The provider | Not your job |
Why "you must label AI content" took hold anyway
Two reasons, and neither of them is the law itself.
The first is that fear moves faster than statutes. A rule with an exemption is harder to summarise than a rule without one, so the exemption falls off in the retelling. By the third article the nuance is gone.
The second is that "compliance" sells. A vague obligation that nobody has read is an excellent thing to sell a service against.
We would rather you read the paragraph and reach your own conclusion, which is why it is quoted above in full, not paraphrased.
What we would actually do in your position
Know which of your tools are providers. If you use a model through an interface, the marking obligation sits with whoever supplies it. That is worth knowing, and it is not worth paying anyone to tell you.
Keep human review real. The exemption depends on it. If nobody reads the draft before it goes out, you have lost the exemption and gained a worse blog at the same time. This is the one place where the legal answer and the quality answer point the same way.
Write down who is responsible. Editorial responsibility is a person or a company, named. For most small businesses that is the owner or whoever runs marketing. It costs nothing to decide and it is the thing the exemption hangs on.
Be honest about synthetic media of real people. This is the part with genuine risk, and the part most businesses never touch anyway.
Do not add disclaimers you do not owe. "This article was written with AI assistance" on a page where a person did the thinking and the editing is not compliance. It undersells your own work.
None of this is a reason to publish unedited machine output. Google does not ban AI-written content, it judges it like everything else, and readers judge it faster than Google does. The legal position and the quality position are different conversations, and passing the first tells you nothing about the second.
Common questions
Does this apply to my business if I am based in Portugal?
Yes. It is a European regulation and it applies directly across member states, Portugal included. It also reaches businesses outside the EU whose AI output is used inside it.
What counts as a matter of public interest?
The regulation does not give a closed list. The ordinary meaning is reporting and commentary on public affairs, not commercial content about your own products and services. If you publish on genuinely public matters, take advice. Do not settle for a blog's word on it.
If I edit AI output heavily, is it still AI-generated content?
For the purposes of the disclosure duty the question is largely answered by the exemption. Human review and editorial responsibility take you out of the obligation regardless of how much of the draft started as machine output.
Can readers tell that I used AI?
Sometimes, and increasingly the detection does not depend on how the text reads. Marking is embedded at generation, so it can survive editing that would fool a person. Treat it as a reason to make the work genuinely yours, not a reason to disguise it.
What happens if I get AI disclosure wrong?
Enforcement sits with national authorities and the penalties in the regulation are set as a share of worldwide turnover. The realistic exposure for a small business publishing edited marketing content is very low, which is the point of this article.
Should we publish an AI policy?
If you produce content regularly, a short internal note on which tools are allowed, who reviews, and who signs off is worth having. Not because the law demands a document, but because it is how you make sure the human review is real and not just assumed.
If you want help turning that into something practical for your team, write to us at hello@saltylavender.com.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council, Article 50, Official Journal of the European Union: eur-lex.europa.eu
- Google DeepMind, SynthID: deepmind.google