Image of hand pressing buttons on a screen

DATA PROTECTION

The EU’s new AI transparency rules: what you need to know

The European Commission has published its Code of Practice on marking and labelling AI-generated content, helping businesses to meet new transparency duties under the EU AI Act.

Didn’t we leave the EU?

Whilst the EU AI Act does not automatically apply in the UK as domestic law, it will apply where a UK business:

  • places an AI system on the EU market
  • puts an AI system into service in the EU or
  • uses AI where the outputs affect people in the EU

In practice, this means that UK technology providers, online platforms, retailers and marketing agencies with EU customers may need to build these requirements into their products, contracts and customer-facing processes.

Transparency under the EU AI Act

The EU’s message is clear: where the use of AI is not obvious, businesses should tell individuals. The Code is voluntary but helps businesses comply with their transparency obligations under the EU AI Act, which apply from 2 August 2026 (with a transitional period until 2 December 2026 for certain systems already on the market).

What are the obligations?

The transparency obligations cover several common business uses of AI:

  • Businesses must tell individuals when they are interacting with an AI system, unless it is obvious from the context. This particularly affects chatbots, virtual assistants and automated customer service
  • Providers of generative AI systems must make AI-generated or AI-manipulated outputs detectable. In practice, this means embedding machine-readable marking that can help identify content as AI-generated
  • Deployers (that is, businesses using an AI system in a professional capacity) must clearly label deepfakes (images or videos resembling real people, places or objects)
  • Deployers must disclose when AI-generated text is published on matters of public interest – for example, AI-assisted material on political, social, economic, health, environmental or other public interest issues. There are some carve-outs, including where a human has reviewed the content or where it falls under editorial responsibility

Why the transparency rules matter

Many organisations have adopted AI tools rapidly, often with little formal oversight. The new obligations require businesses to map their AI uses and decide where notices, labels or technical marking may be needed:

  • Customer-facing businesses may need to update website design, chatbot scripts, app interfaces, social media processes and advertising workflows
  • Technology companies may need product changes to mark AI-generated outputs
  • Media and marketing teams may need new approval steps before publishing AI-generated content

What are the consequences of not complying with the transparency rules?

Non-compliance of the EU AI Act carries real consequences: financial penalties and, often more significantly, reputational damage.

Transparency failures can trigger customer complaints and contractual disputes — particularly in reputation-sensitive industries such as professional services, healthcare, education and media.

Although voluntary, the Code may become a benchmark for regulatory and customer expectations — much as B Corp accreditation has for environmental and social responsibility. The Commission will publicly list signatories in July 2026, giving businesses a clear incentive to sign up and demonstrate their commitment to compliance.

What should your business do now?

Businesses caught by the EU AI Act should, before 2 August 2026:

  • Identify where they use AI
  • Decide what they must disclose or label
  • Review any supplier arrangements
  • Update content and any customer-facing processes

If in doubt, stick to the core principle: make it clear when AI is being used in a way that could mislead people.

For further information as to how we can help your business and its use of AI, please contact our Commercial team by email or call +44(0)3333 231580

About the authors


about the author img

Jay Barnett

Partner

Advises on all areas of commercial law including business contracts, data protection compliance, IT and intellectual property.

Stay connected, sign up for updates

Stay connected

Recent articles

Insights

Data protection update: are you ready for data complaints?

From 19 June 2026, all organisations must have a clear and accessible process for handling data protection complaints.

18/06/2026

Insights

DMH Stallard advises SAVANA on first international acquisition of Gutter Games portfolio

Leading South East law firm DMH Stallard has advised French board game publisher SAVANA SAS on the acquisition of the Gutter Games brand portfolio from Razor Group...

27/05/2026

Insights

Has data protection compliance become a little easier?

Three changes that may simplify your day-to-day compliance and a new complaints’ regime arriving this summer.

07/04/2026

Insights

The Data (Use and Access) Act 2025 and Subject Access Requests

The Data Act 2025 brings a significant update, introducing reforms to the UK GDPR and the Data Protection Act 2018.

07/10/2025

DISCLAIMER:

THIS INFORMATION IS FOR ILLUSTRATIVE PURPOSES AND IS NOT INTENDED TO AMOUNT TO LEGAL ADVICE ON WHICH RELIANCE SHOULD BE PLACED. WE, DMH STALLARD LLP, DISCLAIM ALL LIABILITY AND RESPONSIBILITY ARISING FROM ANY RELIANCE PLACED ON THIS INFORMATION. ANY RELIANCE ON THIS INFORMATION IS SOLELY AT YOUR RISK. The provision of this information does not create a business or professional services relationship. This information is not exhaustive and does not attempt to address every issue relevant to a particular situation. If you require advice on a specific legal issue, please contact a lawyer listed on our website, dmhstallard.com, or send an email to [email protected].