AI Transparency: EU Imposes New Strict Rules

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
A New Era of Transparency for AI in Europe
Article 50 of the European Artificial Intelligence Act is now in effect, introducing stringent transparency requirements for companies that use and deploy AI systems across the European Union. This regulation mandates that providers and users of generative AI systems clearly notify users when they are interacting with a machine, and label AI-generated content so that it is easily identifiable.
The aim of these new rules is to address the challenges posed by the rapid advancements in generative AI technologies, which increasingly make it difficult for users to distinguish between interactions with machines and those with humans. Furthermore, AI-generated images are becoming nearly indistinguishable from authentic photographs, and individuals may be exposed to emotional recognition and biometric categorization tools without being informed.
Concerns About Manipulation and Fraud
The European Commission has highlighted the risks of large-scale manipulation and fraud, particularly through identity theft and consumer deception. Article 50 aims to counter these threats by ensuring a deployment of AI that is both responsible and secure throughout Europe.
Obligations of AI Providers
According to Article 50, providers must develop systems that allow users to know they are interacting with AI, unless it is obvious to a reasonably informed person. Systems used by law enforcement for criminal investigations are exempt from this obligation, provided that third-party rights are protected, unless the public can use the system to report a crime.
Providers of systems generating synthetic content, such as audio, images, videos, or texts, must label this content in a way that makes it detectable as artificially generated. This labeling must be machine-readable and interoperable, to the extent technically feasible, while considering implementation costs. Assisted editing that leaves the input provided by the deployer essentially intact does not trigger this requirement; simple photo retouching does not activate it, but an AI-generated replacement does.
Responsibilities of Deployers
Deployers of emotional recognition or biometric categorization systems must inform the individuals concerned about their use. The personal data collected by these systems remains under the jurisdiction of existing data protection laws, such as the GDPR in general cases, the EU institutions' data protection regulation when an EU body manages the system, and the Police Directive for law enforcement contexts.
Regarding deepfakes, artificially generated or manipulated content must be clearly identified. Artistic or satirical works benefit from lighter disclosure, which should not detract from the experience of the work.
Texts intended to inform the public about matters of public interest must also be labeled, unless they have been reviewed by a human with editorial responsibility. Unedited AI content does not meet this requirement.
All disclosures must be made no later than the first interaction or exposure, in a clear, distinct, and accessible manner according to existing accessibility rules. No grace period covers information provided afterward.
Implementation and Compliance
Three entities are responsible for enforcing these rules: national market surveillance authorities, the AI Office for the systems under its supervision, and the European Data Protection Supervisor for EU institutions.
The guidelines provide indications on how providers and deployers can demonstrate their compliance, including by signing up for the Code of Practice on Transparency for AI-Generated Content. Those who choose not to follow this Code must prove their compliance through other means accepted by the Commission.
Other transparency obligations do not have an equivalent code. No code, no shortcut. Informing people that they are speaking to AI is a requirement. Disclosing deepfakes and flagging AI-generated texts of public interest complement the rest, and providers and deployers determine their own appropriate measures, with the guidelines serving as a reference point rather than a checklist.
Defining Roles and Responsibilities
The document specifies what constitutes an interactive AI system, what is considered synthetic content, and the distinction between a deepfake and standardly edited media. The guidelines also address the value chain to determine who is considered a provider or deployer, and how the obligations of Article 50 apply based on this distinction.
Organizations considering adopting the Code of Practice or creating their own labeling method now have an approved reference framework from the Commission, going beyond the raw text of the regulation.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.