top of page

Chatbots, deepfakes and AI-generated content: the AI Act’s transparency obligations in practice

4 hours ago
5 min read

AI is already part of everyday business. Chatbots handle customer enquiries, generative AI produces text, images and video, and AI tools support everything from marketing and journalism to software development and training.


We have previously covered the key obligations under the EU AI Act and their phased introduction (in Finnish), as well as the use of AI in marketing (in Finnish). This article takes a closer look at the Act’s transparency obligations: when do you need to tell users or the public that AI is involved?

The AI Act’s transparency obligations have applied since 2 August 2026. Their main purpose is to help people recognise when they are interacting with AI or encountering content that AI has generated or manipulated. Disclosure is not required for every use of AI, however. The obligations apply to specific situations defined in the Act.

The European Commission published more detailed guidance on applying these obligations in July 2026. The Finnish Transport and Communications Agency, Traficom, has also published practical guidance for organisations in Finland.

When must people be told they are interacting with AI?

As a general rule, if an AI system is designed to interact directly with people, users must be told that they are dealing with AI rather than a human. This covers, for example, AI-powered website chatbots, voice assistants, interactive AI agents and AI avatars.

Users must receive this information no later than their first interaction with the system, unless the use of AI is already obvious in the circumstances. A reference buried in the terms of use, or a technical marker that users cannot see, will generally not be enough. Simply displaying the service provider’s name may not make it clear that the user is talking to AI either.

How must AI-generated content be technically marked?

The AI Act sets out a separate technical marking obligation for providers of generative AI systems. In practice, this applies to companies such as OpenAI and Anthropic when they offer AI systems in the EU that generate text, images, audio or video.

As a rule, providers must ensure that content generated or manipulated by their systems can be identified as such in a machine-readable format. This obligation therefore generally falls on the AI provider, rather than a business using tools such as ChatGPT or Claude.

The technical method can vary depending on the type of content. For supported AI-generated images, OpenAI uses C2PA provenance metadata and an invisible SynthID watermark. An image can be uploaded to OpenAI’s verification tool, which checks the file for signals indicating its OpenAI origin. The watermark itself is invisible to the human eye.

AI-generated text can also carry machine-detectable markings. Anthropic, for example, has described a text watermarking approach for Claude that creates a detectable statistical pattern in the model’s word choices. To a reader, the text looks ordinary, but the provider’s detection method can identify the watermark.

Technical marking is different from a disclosure that users or the public can see. It does not mean that a business using ChatGPT or Claude must add a visible “AI” label to every piece of content.

When do AI-generated images, video or audio need a disclosure?

One of the most practically significant transparency obligations concerns deepfakes. When AI is used in a professional or other non-personal context to generate or manipulate a deepfake, the content must be accompanied by a clear disclosure that it has been artificially generated or manipulated.

A deepfake is AI-generated or manipulated image, audio or video content that resembles existing people, objects, places, entities or events and falsely appears authentic or truthful.

The term therefore covers more than fabricated videos of celebrities. The obligation may also arise in ordinary commercial or creative work. For example, a realistic AI-generated reconstruction in a documentary, or an apparently authentic scene created with AI for an advertisement, may require disclosure. However, not every AI-generated image or video automatically qualifies as a deepfake.

The Act allows some flexibility for creative works. If a deepfake forms part of an evidently artistic, creative, satirical or fictional work, the use of AI-generated or manipulated content must still be disclosed. The disclosure can, however, be made in a way that does not unnecessarily interfere with the presentation of the work. For more on transparency obligations concerning AI-generated audio, particularly in radio broadcasting, see RadioMedia’s blog (in Finnish).

What about AI-written text?

Not every text written with the help of AI needs a visible AI label.

The disclosure obligation applies to AI-generated or manipulated text published to inform the public about matters of public interest. These may include public administration, fundamental rights, public health, environmental protection, and significant economic, political, scientific or cultural developments. The obligation may therefore cover news articles, scientific publications, investor reports and public notices issued by authorities.

Ordinary advertising content, by contrast, generally falls outside this particular obligation.

There is also an important exception: disclosure is not required if the text has undergone human review or editorial control and a person or legal entity holds editorial responsibility for its publication.

Using AI to draft a news article, for example, does not automatically mean that the finished article must carry an AI label, provided the editorial team reviews the content and takes responsibility for publishing it. Proofreading or correcting grammar alone is not enough. The exception requires substantive review or editorial oversight.

What about emotion recognition and biometric categorisation?

Transparency obligations also apply to emotion recognition and biometric categorisation. People exposed to these systems must be informed clearly and prominently, no later than their first exposure.

Emotion recognition may involve, for example, AI analysing a customer’s voice during a customer service interaction to infer whether they are angry or impatient. Biometric categorisation involves assigning a person to a particular group based on biometric characteristics, such as estimating their age group from facial features.

Informing people does not, in itself, make the use of a system lawful. AI systems used to infer emotions in workplaces and educational institutions are generally prohibited, subject to limited exceptions for medical or safety purposes.

Permitted emotion recognition systems and certain biometric categorisation systems also fall within the AI Act’s rules on high-risk AI. In these cases, both the provider and the deployer—the organisation using the system—face extensive obligations beyond transparency.

Who enforces the obligations, and what are the consequences of a breach?

In Finland, compliance with the transparency obligations is supervised by market surveillance authorities. Traficom is generally responsible, although supervision involving high-risk AI systems may fall to the relevant sector-specific authority.

Intentional or negligent breaches of the transparency obligations may result in an administrative fine. For businesses, the maximum fine is €15 million or 3% of total worldwide annual turnover in the preceding financial year, whichever is higher. For small and medium-sized enterprises, the lower of these two limits applies.

These are maximum amounts. Whether a fine is imposed, and its size, is assessed on a case-by-case basis. Under Finnish law, no fine is imposed if the breach is considered minor or if imposing a fine would be manifestly unreasonable.

What should businesses do now?

Start by identifying where customers, users or the wider public encounter AI in your business. Pay particular attention to customer-facing AI systems and externally published content generated or manipulated using AI.

Practical steps include:

  • Mapping how AI is used in interactions and content that customers or other external audiences encounter.

  • Giving staff clear guidance on when disclosure is required, how to provide it and who is responsible.

  • Establishing a clear process for reviewing AI-generated text where needed.

  • Addressing transparency obligations in contracts with external partners that supply AI solutions or AI-generated content.

The AI Act does not require businesses to disclose every AI-assisted step in their workflow. The key is to recognise when people need to know they are interacting with AI, and when the AI-generated or manipulated nature of content must be explicitly disclosed.

Need help applying the AI Act or assessing how your organisation uses AI? We can help you identify the obligations that apply and put practical processes in place to meet them.

 

Hymyilevä nainen valkoisessa paidassa nojaa tiiliseinään, kädet ristissä.


Lila Kallio

Counsel

+358 41 465 1365









bottom of page