top of page

AI is already part of everyday business. Chatbots handle customer enquiries, generative AI produces text, images and video, and AI tools support everything from marketing and journalism to software development and training.


We have previously covered the key obligations under the EU AI Act and their phased introduction (in Finnish), as well as the use of AI in marketing (in Finnish). This article takes a closer look at the Act’s transparency obligations: when do you need to tell users or the public that AI is involved?

The AI Act’s transparency obligations have applied since 2 August 2026. Their main purpose is to help people recognise when they are interacting with AI or encountering content that AI has generated or manipulated. Disclosure is not required for every use of AI, however. The obligations apply to specific situations defined in the Act.

The European Commission published more detailed guidance on applying these obligations in July 2026. The Finnish Transport and Communications Agency, Traficom, has also published practical guidance for organisations in Finland.

When must people be told they are interacting with AI?

As a general rule, if an AI system is designed to interact directly with people, users must be told that they are dealing with AI rather than a human. This covers, for example, AI-powered website chatbots, voice assistants, interactive AI agents and AI avatars.

Users must receive this information no later than their first interaction with the system, unless the use of AI is already obvious in the circumstances. A reference buried in the terms of use, or a technical marker that users cannot see, will generally not be enough. Simply displaying the service provider’s name may not make it clear that the user is talking to AI either.

How must AI-generated content be technically marked?

The AI Act sets out a separate technical marking obligation for providers of generative AI systems. In practice, this applies to companies such as OpenAI and Anthropic when they offer AI systems in the EU that generate text, images, audio or video.

As a rule, providers must ensure that content generated or manipulated by their systems can be identified as such in a machine-readable format. This obligation therefore generally falls on the AI provider, rather than a business using tools such as ChatGPT or Claude.

The technical method can vary depending on the type of content. For supported AI-generated images, OpenAI uses C2PA provenance metadata and an invisible SynthID watermark. An image can be uploaded to OpenAI’s verification tool, which checks the file for signals indicating its OpenAI origin. The watermark itself is invisible to the human eye.

AI-generated text can also carry machine-detectable markings. Anthropic, for example, has described a text watermarking approach for Claude that creates a detectable statistical pattern in the model’s word choices. To a reader, the text looks ordinary, but the provider’s detection method can identify the watermark.

Technical marking is different from a disclosure that users or the public can see. It does not mean that a business using ChatGPT or Claude must add a visible “AI” label to every piece of content.

When do AI-generated images, video or audio need a disclosure?

One of the most practically significant transparency obligations concerns deepfakes. When AI is used in a professional or other non-personal context to generate or manipulate a deepfake, the content must be accompanied by a clear disclosure that it has been artificially generated or manipulated.

A deepfake is AI-generated or manipulated image, audio or video content that resembles existing people, objects, places, entities or events and falsely appears authentic or truthful.

The term therefore covers more than fabricated videos of celebrities. The obligation may also arise in ordinary commercial or creative work. For example, a realistic AI-generated reconstruction in a documentary, or an apparently authentic scene created with AI for an advertisement, may require disclosure. However, not every AI-generated image or video automatically qualifies as a deepfake.

The Act allows some flexibility for creative works. If a deepfake forms part of an evidently artistic, creative, satirical or fictional work, the use of AI-generated or manipulated content must still be disclosed. The disclosure can, however, be made in a way that does not unnecessarily interfere with the presentation of the work. For more on transparency obligations concerning AI-generated audio, particularly in radio broadcasting, see RadioMedia’s blog (in Finnish).

What about AI-written text?

Not every text written with the help of AI needs a visible AI label.

The disclosure obligation applies to AI-generated or manipulated text published to inform the public about matters of public interest. These may include public administration, fundamental rights, public health, environmental protection, and significant economic, political, scientific or cultural developments. The obligation may therefore cover news articles, scientific publications, investor reports and public notices issued by authorities.

Ordinary advertising content, by contrast, generally falls outside this particular obligation.

There is also an important exception: disclosure is not required if the text has undergone human review or editorial control and a person or legal entity holds editorial responsibility for its publication.

Using AI to draft a news article, for example, does not automatically mean that the finished article must carry an AI label, provided the editorial team reviews the content and takes responsibility for publishing it. Proofreading or correcting grammar alone is not enough. The exception requires substantive review or editorial oversight.

What about emotion recognition and biometric categorisation?

Transparency obligations also apply to emotion recognition and biometric categorisation. People exposed to these systems must be informed clearly and prominently, no later than their first exposure.

Emotion recognition may involve, for example, AI analysing a customer’s voice during a customer service interaction to infer whether they are angry or impatient. Biometric categorisation involves assigning a person to a particular group based on biometric characteristics, such as estimating their age group from facial features.

Informing people does not, in itself, make the use of a system lawful. AI systems used to infer emotions in workplaces and educational institutions are generally prohibited, subject to limited exceptions for medical or safety purposes.

Permitted emotion recognition systems and certain biometric categorisation systems also fall within the AI Act’s rules on high-risk AI. In these cases, both the provider and the deployer—the organisation using the system—face extensive obligations beyond transparency.

Who enforces the obligations, and what are the consequences of a breach?

In Finland, compliance with the transparency obligations is supervised by market surveillance authorities. Traficom is generally responsible, although supervision involving high-risk AI systems may fall to the relevant sector-specific authority.

Intentional or negligent breaches of the transparency obligations may result in an administrative fine. For businesses, the maximum fine is €15 million or 3% of total worldwide annual turnover in the preceding financial year, whichever is higher. For small and medium-sized enterprises, the lower of these two limits applies.

These are maximum amounts. Whether a fine is imposed, and its size, is assessed on a case-by-case basis. Under Finnish law, no fine is imposed if the breach is considered minor or if imposing a fine would be manifestly unreasonable.

What should businesses do now?

Start by identifying where customers, users or the wider public encounter AI in your business. Pay particular attention to customer-facing AI systems and externally published content generated or manipulated using AI.

Practical steps include:

  • Mapping how AI is used in interactions and content that customers or other external audiences encounter.

  • Giving staff clear guidance on when disclosure is required, how to provide it and who is responsible.

  • Establishing a clear process for reviewing AI-generated text where needed.

  • Addressing transparency obligations in contracts with external partners that supply AI solutions or AI-generated content.

The AI Act does not require businesses to disclose every AI-assisted step in their workflow. The key is to recognise when people need to know they are interacting with AI, and when the AI-generated or manipulated nature of content must be explicitly disclosed.

Need help applying the AI Act or assessing how your organisation uses AI? We can help you identify the obligations that apply and put practical processes in place to meet them.

 

Hymyilevä nainen valkoisessa paidassa nojaa tiiliseinään, kädet ristissä.


Lila Kallio

Counsel

+358 41 465 1365









Artificial intelligence has entered the world of marketing quickly and with relatively little friction. Images, videos, audio, advertising copy and campaign ideas can now be created in an instant. From a legal perspective, however, this does not mean that the basic rules of marketing have lost their relevance. Rather, AI places familiar questions in a new context. Is the marketing truthful? Does the recipient understand what they are being shown? Who is responsible for the end result?


Which new rules and guidance should marketers pay attention to?


The current discussion is being shaped by three key sets of materials. First, the International Chamber of Commerce, or ICC, has published guidance on the responsible use of AI in marketing. The guidance supplements the ICC’s marketing rules and emphasises that marketing must be lawful, decent, honest and truthful, regardless of the technology used to create it. The ICC guidance is a form of self-regulation rather than directly binding legislation. In practice, however, it may still be relevant when assessing the level of care that can reasonably be expected from a responsible marketer.


Second, Article 50 of the EU AI Act introduces binding transparency obligations relevant to marketing. Many of these obligations will apply from 2 August 2026. They concern, among other things, situations in which a person interacts with an AI system or is exposed to certain content generated or manipulated by AI. Third, the European Commission has published draft guidelines on Article 50, while a Code of Practice on the labelling of AI-generated content is also being prepared. According to the Commission’s draft, the guidelines are intended to provide practical assistance with interpretation. They do not constitute a binding or final interpretation of the AI Act.


There is no automatic obligation to disclose the use of AI


AI can be used in many different ways and at various stages of the marketing process. It is therefore important to recognise that its use does not need to be disclosed automatically in every situation. The ICC guidance states this quite clearly, and the AI Act does not create a general disclosure obligation either. The mere use of generative AI to create advertising materials or marketing communications does not in itself require disclosure. The key question is whether failing to disclose the use of AI could give the recipient a misleading overall impression. Where that is the case, disclosure may be necessary.


Deepfake content is a particular risk area in marketing


Article 50 of the AI Act makes disclosure of AI use a statutory obligation in certain situations. From a marketing perspective, the most relevant example is deepfake content. Under the AI Act, the deployer of an AI system must disclose when image, audio or video content has been generated or manipulated by AI in a way that constitutes a deepfake. According to the AI Act and the Commission’s draft guidelines, a deepfake is content that resembles existing persons, objects, places, entities or events and could falsely appear to be authentic or truthful.


This definition is significant for marketing because deepfakes are not limited to situations involving the imitation of a well-known person. AI-generated content that realistically depicts an existing location, event or product-use context may also fall within the scope of the deepfake rules where the recipient could mistakenly believe it to be genuine. In a marketing context, this could include an AI-generated video showing realistic “customers” using a product in a seemingly authentic setting.


The ICC guidance takes the assessment one step further from a practical perspective. Where AI is used to create or materially alter the image, voice or other likeness of a real and identifiable person for marketing purposes, the person’s permission should generally be obtained and the limits of that permission respected. In practice, marketers must therefore assess two separate questions. They must determine whether they are entitled to use content depicting the person and whether the use of AI must be disclosed to the audience. Article 50 of the AI Act does not directly address consent, as its focus is on transparency. The Commission’s draft guidelines nevertheless point out that deepfake content may also raise issues relating to data protection, intellectual property rights and personality rights.


Disclosure must be assessed from the recipient’s perspective


Another important consideration is the target audience. Both the ICC guidance and the Commission’s draft guidelines on Article 50 emphasise that the clarity of a disclosure must be assessed from the audience’s perspective. In marketing directed at children, older people or other potentially vulnerable groups, the threshold for disclosing the use of AI may in practice be lower. The disclosure must be presented in a way that the particular audience can understand. A purely technical label, a sentence hidden in the terms of use or a vague reference to AI may not be sufficient. According to the Commission’s draft guidelines, the information must be provided clearly and prominently no later than at the time of the first interaction or exposure. It must not be hidden in user instructions or behind a menu structure.


The draft Code of Practice develops this idea further. It suggests that labels for deepfakes and certain AI-generated texts should be easily noticeable, accessible and appropriate for the relevant type of content. The draft also proposes the development of a common EU-wide AI icon and the possibility of a second layer of information explaining in greater detail which elements of the content have been generated or manipulated by AI. From a practical perspective, another interesting proposal is that the label should, where possible, travel with the content when a video or image is shared across different channels.


Responsibility for AI use must be built into marketing processes


For businesses, this means that the use of AI in marketing is not merely a choice of tool for the creative team. The ICC guidance emphasises that the marketer remains responsible for its marketing even where the campaign has been implemented with the assistance of an agency, influencer, platform operator or AI tool. Organisations should update their internal training and instructions so that everyone involved in marketing understands their responsibilities. The same objective is reflected in the AI literacy obligations under the AI Act. Businesses must ensure that personnel using AI have an adequate understanding of its opportunities, limitations and risks.


In practice, a responsible marketer should address three fundamental issues. First, the business should identify where AI is used in the campaign and whether the end result must be labelled under the AI Act. It should then assess whether failing to disclose the use of AI could create a misleading impression, including in situations where the express disclosure obligations under the AI Act do not apply.

Finally, contracts with advertising agencies, influencers and technology providers should support compliance. The marketer should know when AI has been used to create the final output so that it can fulfil its own obligations where necessary.


The use of AI in marketing is not inherently problematic. On the contrary, it can improve quality, accelerate production and create new possibilities for creative work. However, the more authentic AI-generated content looks and sounds, the more important it becomes to consider whether the recipient understands what they are being shown. In this respect, the ICC guidance and Article 50 of the AI Act point in the same direction. Both serve as reminders that trust lies at the very heart of marketing. Where the use of AI undermines that trust, technical efficiency can quickly turn into legal risk and reputational harm.


Businesses should begin preparing early


Final interpretation and enforcement practice are still developing. The Commission’s guidelines on Article 50 and the Code of Practice remain in draft form. The ICC has also stated that it will update its guidance as technology and industry practices evolve. Businesses should nevertheless begin preparing for the obligations now by updating their processes, internal guidance, contracts and approval procedures. From August 2026 onwards, transparency will in many situations become an increasingly concrete and directly applicable legal obligation.


Hymyilevä nainen seisoo tiiliseinän edessä valkoisessa kauluspaidassa. Kuvassa on Folksin juristi Katri Aarnio.


Katri Aarnio

Counsel

+358 50 306 2031




To receive our articles directly by email, subscribe to the Folks newsletter here.

AI tools are developing at a remarkable pace. Not long ago, an AI-generated image was easy to recognise, but today, the best AI-generated images are so convincing that they can be indistinguishable from genuine photographs. AI can also be used to produce text, audio and video, offering creative industry professionals significant opportunities to accelerate content production and develop new forms of expression.


At the same time, the use of AI raises numerous legal questions. In this blog post, I discuss the legal considerations that companies operating in the creative industries should take into account before introducing AI tools and using them as part of their creative work.


Who owns AI-assisted content, and how can it be protected?


A key question is whether the creator obtains an exclusive right to use and license material produced with the assistance of AI, or whether the result remains freely available for anyone to use. There is no straightforward answer, as it depends on the extent of the human creator’s own creative contribution to the work.


Copyright belongs to the person who creates a work, provided that the work is sufficiently independent and original. Copyright protection always requires a creative contribution by a human, and the assessment is made on a case-by-case basis. Copyright never protects an idea as such, but only the specific form in which the idea is expressed.


When a creative professional uses AI as a tool in their work, the existence of copyright is assessed according to these same principles. Copyright does not arise where a person gives the AI only a general instruction and the AI produces the final content entirely without any creative contribution from the user.


The situation is different if AI is used as part of a broader creative process. If the creator uses AI, for example, to support brainstorming, then creates the content themselves and uses AI only for final refinements, the work is likely to contain enough of the creator’s own creative contribution to qualify for copyright protection.


The use of AI should also be documented in case of potential disputes. Retaining the creator’s own drafts and the prompts used can make it easier to demonstrate which parts of the final result are based on human creative work.


If content is created using generative AI and the result does not qualify for copyright protection, protection may in some cases also be sought through trademarks. For example, Moomin Characters has protected Moomin characters as trademarks. However, it is important to note that a trademark only provides protection in specified classes of goods and services and within a particular geographical area. It does not protect the creative content as such. Its scope and purpose therefore differ from those of copyright protection.


If a creative project involving extensive use of generative AI is being planned, trademark protection may nevertheless be worth considering alongside copyright as a complementary form of protection.


Can AI-generated material be used freely?


Material created with AI is not automatically free from third-party rights. The key questions are which AI service was used to produce the material and how liability has been allocated in the service’s terms of use.


Some AI services use only licensed training data or other material that is not protected by copyright and contractually assume responsibility for ensuring that the materials generated by the AI do not infringe third-party copyrights. In such cases, the service provider bears responsibility for the output to the extent agreed in the terms of use, and the user’s legal risk is substantially lower.

Many widely used services, however, have been trained on extensive datasets collected from the internet, which may also contain copyright-protected material. In most services, the service provider does not contractually assume responsibility for ensuring that the generated content does not infringe third-party rights. Instead, responsibility for using the content remains with the user. Material produced using such services therefore requires careful review before publication.


In summary, there is no universally applicable answer as to whether AI-generated materials may be used freely. The allocation of responsibility depends primarily on the service used and its terms of use, which should be reviewed before AI is introduced as part of content production.


Can confidential information be entered into an AI service?

As a general rule, confidential information should not be entered into an AI service unless the service is specifically intended for business use and its terms and information security have been carefully assessed.


For business purposes, companies should use business or enterprise versions of generative AI services unless they operate a local AI solution on their own servers. In consumer services, such as the free and Plus versions of ChatGPT, materials and prompts entered into the service may, in accordance with the terms of use, be used to train the AI model. In addition, the service provider may reserve broad rights to use and even share material uploaded by users for purposes other than AI model training.

This means that if a company’s employees use consumer licences in their work, they may compromise the confidentiality of information by entering confidential material into the service.


The practical risk may arise, for example, where a screenwriter or copywriter uses a free consumer AI service to refine a text and enters an unpublished script or campaign concept into the service. Under consumer licences, the content may be used to develop AI models, meaning that the material is no longer under the company’s exclusive control. Even if the content does not appear elsewhere in an identical form, there is a risk that recognisable features of the material may be used as part of outputs generated for other users.


It is also important to note that other risks do not disappear even if the use of content for training purposes can be prohibited separately in the service settings or terms of use. Under consumer licences, service providers often do not provide binding guarantees regarding the security of the service. Information entered into the service may therefore be exposed to data breaches or other information security incidents. Protecting confidential information requires selecting a licence suitable for business use and assessing the service’s terms and information security before introducing the AI service.


Can personal data be entered into an AI service?


If personal data, such as a person’s image, voice or name, is entered into an AI service, the General Data Protection Regulation, or GDPR, applies.


The company is responsible for ensuring that the licensing terms of the AI service have been carefully assessed. As part of its compliance with the GDPR, the company must ensure, among other things, that material uploaded to the service is not used to train the AI, that it is possible to enter into the data processing agreement required by the GDPR with the service provider, and that the AI service provides appropriate security for the protection of personal data. In practice, the use of an AI service will generally also require a data protection impact assessment.


The use of AI services under free consumer licences will generally not comply with the GDPR, as service providers often also use uploaded material for their own purposes.


Is it permissible to use AI to generate images or voices of real people?


Particular attention is also required where AI is used to produce images of real people or to create AI-generated copies of a real person’s voice. A person’s image, voice and other identifying features constitute personal data. AI-generated material may also be considered personal data if a specific individual can be identified from it. In such cases, all GDPR requirements apply, including the requirement to inform the individual about the processing of their personal data and the requirement to have a lawful basis for the processing.


In content production, it is also important to recognise that using a person’s image or voice for commercial purposes requires that person’s consent. In 2025, the Helsinki Court of Appeal ordered an underwear company to pay Jasper Pääkkönen EUR 300,000 in compensation for the unauthorised use of his name, image and voice in an extensive advertising campaign. The judgment is not yet final, and the Supreme Court has granted leave to appeal. The obligation to obtain consent also applies where the person’s image or voice has been generated using AI.


When must AI-generated content be labelled as a deepfake?


The EU’s new AI Act introduces transparency requirements concerning deepfakes. The Act will become applicable gradually, and the provisions concerning deepfakes will apply from 2 August 2026.

Deepfakes are AI-generated or AI-manipulated image, audio or video content that resembles existing people, objects, places, entities or events and may falsely appear to the recipient to be authentic or truthful. The transparency obligation is therefore not limited to deepfakes depicting people.

Under the AI Act, deepfakes must be clearly labelled as having been artificially generated or manipulated. However, the Act includes an exception for creative works. Where the content forms part of an evidently artistic, creative, satirical, fictional or similar work or programme, the disclosure may be made in a manner that does not interfere with the display or enjoyment of the work.


For example, a documentary-style television production may use highly realistic AI-generated images or videos to illustrate historical events. If the context does not otherwise indicate that the material is artificial, viewers may believe it to be genuine archival footage. In such a case, the transparency obligation under the AI Act must generally be considered. However, the exception for creative works allows the use of AI to be disclosed in a manner appropriate to the nature of the work, for example in the programme’s end credits, provided that the audience is not left with a false impression of the authenticity of the content.


A breach of the transparency obligation concerning deepfakes may result in an administrative fine under the AI Act.


Checklist for creative industry professionals

Rights: ensure that your own creative contribution is sufficient if you want the final result to qualify for copyright protection.


  • Documentation: document the use of AI and your own creative contribution.

  • Terms of use: review the service terms and determine what rights you receive to the generated content and who is responsible for potential infringements.

  • Business-level licences: only use business-level licences for professional purposes and enter into a data processing agreement where necessary.

  • GDPR and consent: using a person’s image or voice requires compliance with data protection rules and, for commercial use, the person’s consent.

  • Deepfakes: if content has been artificially generated or manipulated, ensure that the disclosure requirements of the AI Act are met.


Would you like to discuss the legal questions surrounding AI? We help companies assess the legal risks and opportunities associated with the use of AI in the creative industries and in other AI-enabled business operations.


Nainen valkoisessa paidassa hymyilee, seisoo tiiliseinää vasten. Taustalla punainen tiilikuviollinen seinä. Folksin Counsel Lila Kallio

Lila Kallio Counsel

+358 41 465 1365









Nainen valkoisessa paidassa hymyilee urbanistisen tiiliseinän edessä. Hänellä on pitkät ruskeat hiukset. Tausta on rosoinen. Folksin counsel Katri Aarnio

Katri Aarnio Counsel

+358 50 306 2031








To receive our articles directly in your inbox, subscribe to the Folks newsletter here.

bottom of page