Do You Need to Tell People You're Using AI? New EU Rules Explained
If your business uses AI to generate content, or to interact directly with customers, you may be wondering whether you now have a legal duty to say so. From 2nd August 2026, the answer in many cases is yes. The EU AI Act's transparency rules require certain AI-generated content and interactions to be clearly disclosed, and the European Commission has also published a voluntary code to help businesses meet that duty in practice. Here is what actually applies, and what to check in your own business.
What the Law Requires
Article 50 of the AI Act sets out specific transparency obligations. Deepfakes and AI-generated or AI-manipulated text that is published on matters of public interest must be clearly labelled as such. Separately, if your business uses an interactive AI system, such as a chatbot on your website, you must inform users that they are interacting with an AI system rather than a person, unless this is already obvious from the context. Providers of systems that generate synthetic audio, image, video or text must also mark that content in a machine-readable format, so it can be detected as AI-generated even where a human label is not visible.
There is a short grace period for systems already on the market before 2nd August 2026, giving those providers until 2nd December 2026 to bring their marking into line. Any system placed on the market on or after 2nd August 2026 needs to comply from day one.
The Voluntary Code That Can Help
These are new obligations, and as such, the European Commission has published a Code of Practice on the transparency of AI-generated content, developed with input from industry, academia and civil society. Signing the code is optional, but it gives businesses a predictable and legally certain route to demonstrating compliance, regardless of where they are established or which national authority regulates them. By the end of July 2026, around 190 organisations across sectors including IT, telecoms, education and retail had signed, roughly half of which were small or recently founded companies. Several major AI developers, including the providers behind widely used generative AI tools, have also committed to the sections of the code that apply to them.
Signing does not automatically prove compliance on its own, but adherence to a code assessed as adequate by the Commission and the AI Board is treated as a strong indicator of good faith and proper process, which matters if a regulator ever asks questions about how you approached these obligations.
What This Means for Your Business Day-to-Day
If you use AI tools to draft content that is then published without significant human review, particularly on matters of public interest, you need a process for labelling that content appropriately. If you have a chatbot, virtual assistant, or any interactive tool on your site or app, check that it makes clear to users they are speaking with an AI system, ideally at the start of the interaction rather than buried in terms and conditions. If your business supplies AI tools to others rather than being the end user, the marking obligations for synthetic content fall on you as the provider, and this is worth reviewing with your technical team now rather than after a customer or regulator raises it.
For many small and medium-sized businesses, meeting this obligation is genuinely straightforward: a short, visible statement that a chatbot is AI-powered, or a simple label on AI-generated marketing content, is often enough to meet the requirements. Where things get more complex is if your business is itself developing generative AI tools, in which case the marking and detection requirements are more technical and worth discussing with a specialist. If you are unsure whether your current AI use falls within these transparency rules, it is worth reviewing your AI tools against the obligations above, and seeking advice where the answer is not clear cut.
Why This Is a Good Moment to Put an AI Policy in Place
If you are reviewing how your business discloses its use of AI to meet the transparency rules above, it is worth using the same moment to put a proper AI policy in place. There is no single UK law that requires every business to have a formal AI policy right now, but the practical reality makes one worthwhile regardless. Staff tend to use AI tools whether or not there is a policy in place, often without telling anyone, which means the real choice is between having visibility and control over that use or having none at all. A written policy is also the clearest way to demonstrate, if a regulator or client ever asks, that your business is meeting its data protection and transparency obligations.
What a Good AI Policy Should Actually Cover
An effective AI policy does not need to be long or technical. For most small and medium sized businesses, a page or two is enough, provided it answers the questions that matter. It should set out which AI tools are approved for use, so staff are not left guessing or defaulting to whatever free tool they find. It should be equally clear about what should never be entered into an AI tool, such as client personal data, financial information, login credentials or anything covered by a non-disclosure agreement, since many AI tools may use submitted data to train their underlying models unless a business-tier agreement says otherwise.
The policy should also say who is responsible for reviewing AI output before it reaches a client or goes into a decision that affects someone, since AI tools can produce plausible-sounding but inaccurate results. It should address the transparency obligations covered above directly, confirming when and how customers are told they are interacting with AI, and who owns the wording used to do that. Finally, it should name someone accountable for keeping the policy current, since AI tools and their terms of service change frequently enough that an annual review is often not sufficient.
If your business already has a wider data protection or acceptable use policy, extending it with a dedicated AI section is often more practical than creating an entirely separate document, since it keeps the rules staff already follow in one place rather than adding a new one for them to remember.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.