The EU AI Act Transparency Obligations are a set of requirements within the Artificial Intelligence Act (Regulation (EU) 2024/1689), a European Union regulation that establishes a common regulatory framework for AI. These obligations apply specifically to AI systems classified as limited-risk, such as chatbots, deepfakes, and other generative tools, and are designed to ensure that users are aware when they are interacting with AI or when content is AI-generated. The transparency duties are a core component of the Act's risk-based approach, which assigns stricter rules to higher-risk applications while allowing lighter oversight for lower-risk ones. The Act entered into force on 1 August 2024, with transparency provisions becoming applicable gradually over the following 6 to 36 months, and it can apply extraterritorially to providers outside the EU if they serve EU users.
The transparency obligations are part of a broader regulatory scheme that classifies AI applications into four risk levels - unacceptable, high, limited, and minimal - plus a separate category for general-purpose AI. Limited-risk systems, which include many generative AI applications, are not subject to the stringent conformity assessments required for high-risk systems, but they must meet specific disclosure requirements. These obligations are intended to foster trust and informed decision-making, allowing individuals to recognize AI involvement and make conscious choices about their interactions. The Act also imposes transparency duties on general-purpose AI models, such as large language models, with reduced requirements for open-source models and additional evaluations for high-capability systems.
Scope and Applicability
The transparency obligations apply to AI systems that interact with individuals or generate content, covering a wide range of sectors and use cases. They are triggered when an AI system is deployed in a professional context, meaning that providers and deployers - not individual users - bear the responsibility for compliance. The Act exempts AI used exclusively for military, national security, or pure scientific research purposes, as well as systems used for non-professional activities. This scope ensures that the obligations target commercial and institutional deployments while avoiding undue burden on personal or research uses.
For limited-risk systems, the key requirement is to inform users that they are interacting with an AI system, unless this is obvious from the context. For example, a chatbot must clearly disclose its AI nature, and AI-generated or manipulated content, such as deepfakes, must be labeled as such. These rules are designed to prevent deception and enable users to evaluate the reliability of information or interactions. The obligations also extend to AI systems that generate or manipulate images, audio, or video, requiring clear marking of synthetic content.
Transparency Requirements for Limited-Risk AI
Limited-risk AI systems, as defined in the Act, include applications that pose minimal potential harm but still require transparency to protect users. The primary duty is to ensure that users are aware they are engaging with an AI, allowing them to make informed choices. This applies to chatbots, virtual assistants, and other conversational interfaces, where the AI nature may not be immediately apparent. Providers must design these systems to disclose their identity clearly, either through explicit statements or contextual cues.
For deepfakes and other synthetic media, the Act mandates that content be labeled as AI-generated or manipulated. This labeling must be clear, noticeable, and appropriate to the medium, ensuring that viewers or listeners can identify synthetic content. The requirement aims to combat misinformation and protect individuals from being misled by realistic but fabricated media. The Act also requires that such labels be technically robust, making them difficult to remove or alter, and that they be applied at the time of creation or distribution.
General-Purpose AI Transparency
In 2023, the draft Act was revised to address the rise of generative AI systems, such as ChatGPT, whose general-purpose capabilities did not fit the main framework. This led to the creation of a dedicated category for general-purpose AI (GPAI) models, which includes foundation models that can perform a wide range of tasks. Transparency requirements for GPAI models are more extensive than for limited-risk systems, reflecting their broader impact. Providers must publish a summary of training data, adopt a copyright policy, and provide technical documentation to downstream users and supervisory authorities.
For open-source models, where weights and design are made publicly available, the transparency duties are reduced: providers must publish a training data summary and a copyright policy, but are exempt from some documentation requirements. Closed-source models must meet broader transparency obligations, including detailed information about the model's capabilities and limitations. High-impact models that pose systemic risks - defined as those requiring more than 10^25 floating-point operations to train - must undergo additional evaluations, including adversarial testing and risk mitigation for bias and security failures.
The General-Purpose AI Code of Practice, published on 10 July 2025, provides practical guidance for compliance. It outlines three main chapters on transparency, copyright, and safety and security, helping providers demonstrate adherence to the AI Act. Participation in the code is voluntary, but it offers a structured approach to meeting the Act's requirements, particularly for complex GPAI systems.
Compliance and Enforcement
The transparency obligations are enforced through the Act's broader compliance mechanisms. Providers must ensure that their AI systems meet the relevant requirements before placing them on the market, and they must maintain documentation to demonstrate compliance. National supervisory authorities, coordinated by the European Artificial Intelligence Board, are responsible for oversight and enforcement. The Board, established by the Act, promotes national cooperation and ensures consistent application of the regulation across member states.
Non-compliance can result in significant penalties, similar to those under the General Data Protection Regulation (GDPR). Fines can reach up to a percentage of a company's global annual turnover, depending on the severity and type of violation. For transparency failures, penalties are typically lower than for high-risk violations but can still be substantial. The Act also allows citizens to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights, though this does not extend to limited-risk systems.
Relationship with Other Regulations
The transparency obligations complement other EU regulations, particularly the GDPR, which governs data protection and privacy. While the AI Act focuses on product safety and transparency, the GDPR addresses individual rights over personal data. Together, they create a comprehensive framework for AI governance, with the AI Act applying extraterritorially to providers outside the EU if they have users within the EU, mirroring the GDPR's reach. This extraterritorial scope means that global AI companies, including those based in the US or Asia, must comply with EU transparency rules when serving EU users.
The Act also interacts with sector-specific regulations, such as those for financial services or healthcare, where additional transparency requirements may apply. In such cases, the AI Act sets a baseline, and sectoral rules can impose stricter obligations. This layered approach ensures that transparency is tailored to the specific risks and contexts of AI use, while maintaining a consistent EU-wide standard.
Impact on AI Development
The transparency obligations have significant implications for AI developers and deployers. They require careful design of user interfaces to include clear AI disclosures, and they necessitate robust labeling mechanisms for synthetic content. For large language models and other generative AI systems, this means implementing features that can identify AI-generated text, images, or audio, which may involve technical solutions like watermarking or metadata embedding.
These requirements also encourage a culture of transparency in the AI industry, promoting accountability and trust. By making AI interactions more transparent, the Act aims to reduce the risk of misuse and to empower users to make informed decisions. However, the obligations also impose compliance costs, particularly for smaller providers, which may need to invest in documentation and labeling infrastructure. The Act's phased implementation, with provisions coming into effect over 6 to 36 months, gives stakeholders time to adapt.
Future Developments
As of 2025, the transparency obligations are being implemented across the EU, with the European Artificial Intelligence Board working to harmonize enforcement. The General-Purpose AI Code of Practice, published in July 2025, is a key tool for compliance, and its adoption will shape how transparency is operationalized for GPAI models. The Act also allows for the list of high-risk applications to be expanded over time, which could affect transparency requirements for certain systems.
The EU's approach is being watched globally, as other jurisdictions consider similar regulations. The transparency obligations, in particular, are seen as a model for balancing innovation with user protection. As AI technology evolves, the Act's provisions may be updated to address new challenges, such as the rise of machine learning techniques or advances in deep learning. The framework's flexibility, with its risk-based categories and delegated acts, is designed to accommodate such changes, ensuring that transparency remains a cornerstone of AI governance in the EU.