Transport and Communications Agency

When do you need to disclose the use of AI?

The EU Artificial Intelligence Act (AI Act) requires you to disclose the use of AI in certain situations. Your obligations depend on whether you provide or deploy an AI system.

On this page

The transparency obligations apply from 2 August 2026. AI-generated content produced or published before this date does not need to be labelled retrospectively.

Find out which obligation applies to you

Different obligations may apply to you depending on whether you provide an AI system or deploy it in your own activities.

An AI system provider is responsible for obligations relating to the features of the system and how the system discloses the use of AI or marks the content it generates.

Under the AI Act, a provider means a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts an AI system into service under its own name or trademark.

If you provide an AI system, you may have obligations relating to the features of the system, disclosing the use of AI and technical marking of content generated or manipulated by AI.

An AI system deployer may have an obligation to inform people about the use of AI or to label content generated by AI. 

Under the AI Act, a deployer means a natural or legal person, public authority, agency or other body that uses an AI system under its authority for purposes other than personal use.

If you deploy an AI system in your own activities, you must in certain situations inform people about the use of AI or label content generated or manipulated by AI.

The same organisation or person may be both a provider and a deployer. More than one transparency obligation may also apply to the same system or content at the same time.

If you provide an AI system for others to use

The transparency obligations for providers apply in particular to:

  • AI systems that interact directly with people
  • AI systems that generate or manipulate text, images, audio or video.

Tell users when they are interacting with AI

If an AI system is intended to interact directly with people, it must be designed so that users know they are interacting with AI.

The interaction may take place through text, speech or physical actions, for example. The system must be able to receive input from the user and produce a response that is relevant to the situation. The interaction may be one-off or continuous.

Examples of such systems include:

  • chatbots and other conversational AI systems
  • AI-powered voice assistants
  • AI agents
  • AI avatars
  • robots that interact with people
  • social media bots.

By contrast, the obligation generally does not apply to systems that do not interact directly with people. These may include spam filters, recommender systems, automated transcription tools and decision-support systems that operate in the background.

Clearly inform users about the use of AI

Users must be informed that they are interacting with AI no later than when the first interaction begins.

You can provide this information, for example, through:

  • text
  • speech
  • a visual indicator
  • a combination of these methods.

Choose the method based on the user group and the context in which the system is used.

Information provided only in terms and conditions or documentation is generally not enough. An invisible technical marker or an unclear description is also not enough to meet the obligation.

In long-term or sensitive interactions, you may also need to remind users during the interaction that they are interacting with AI. This may be particularly important if users could mistake the AI for a human.

You do not need to provide a separate notice if it is obvious to the user that they are interacting with AI.

When assessing whether this is obvious, take into account factors such as:

  • the target audience
  • user characteristics, such as age and digital skills
  • the environment and context in which the system is used
  • the nature of the interaction
  • the expertise of the target audience.

Ensure that AI-generated content is technically marked

If an AI system generates or manipulates text, images, audio or video, the provider must ensure that the content can be detected by machines as artificially generated or manipulated.

The obligation applies both to generative AI systems developed for a specific purpose and to general-purpose AI systems. It may also apply to content generated by AI agents that can be perceived by people.

The obligation has two requirements:

  • content generated or manipulated by AI must be marked in a machine-readable format
  • the content must be detectable as artificially generated or manipulated.

It is therefore not enough simply to add a technical marking. The provider must also ensure that the marking can be detected using a suitable method.

A machine-readable marking can be implemented, for example, using:

  • digital watermarks
  • metadata identifiers
  • cryptographic methods for verifying provenance
  • log data
  • digital fingerprints.

A combination of several methods may also be used.

As far as technically feasible, the solution used must be effective, reliable, robust and interoperable across different systems and technical solutions.

The assessment may take into account:

  • the nature of the content
  • technical limitations
  • costs
  • the state of the art.

Not all technical content needs to be marked

The obligation applies to text, images, audio and video that can be perceived by people, as well as combinations of these types of content.

The obligation generally does not apply, for example, to:

  • outputs intended for machine-to-machine communication that are not exposed to people
  • systems that only organise or recommend existing content
  • systems that only measure, record or transmit data without changing it
  • short sequences of numbers, letters or symbols
  • source code
  • intermediate outputs used in closed-loop product development or industrial environments and not intended for the public.

If you deploy an AI system in your own activities

The transparency obligations for deployers apply in particular to:

  • emotion recognition
  • biometric categorisation
  • deep fakes
  • certain AI-generated or manipulated texts on matters of public interest.

Inform people about emotion recognition or biometric categorisation

If you use an emotion recognition system or a biometric categorisation system, you must inform the people who are exposed to the system that it is being used.

Inform people about emotion recognition or biometric categorisation

If you use an emotion recognition system or a biometric categorisation system, you must inform the people who are exposed to the system that it is being used.

An emotion recognition system aims to identify or infer a person’s emotions or emotional state on the basis of biometric data. For example, the system may analyse facial expressions, voice, speech or body movements.

Such systems may be used, for example, in customer service, education, the workplace or security applications.

A biometric categorisation system assigns people to predefined groups or categories on the basis of biometric data. This may include facial features, voice, fingerprints or other physical or behavioural characteristics.

Biometric categorisation is different from biometric identification of a person.

Clearly inform people in an easily noticeable way if they are subject to emotion recognition or biometric categorisation.

You can provide the information, for example:

  • on a sign or notice at the location
  • on an online service or in an application
  • in a clearly visible notice in the user interface
  • through an audio announcement.

You must provide the information no later than when the person is first exposed to the use of the system.

The information must be clear, understandable, easily noticeable and accessible. A reference only in the terms and conditions, a privacy statement or another document that is difficult to find is generally not enough.

If the system processes personal data or biometric data, you must also comply with data protection legislation. The transparency obligations under the AI Act do not replace data protection requirements.

Label deep fakes

If you use AI in a professional context or for purposes other than purely personal use to generate or manipulate a deep fake, you must clearly disclose that the content has been artificially generated or manipulated.

A deep fake means AI-generated or manipulated image, audio or video content that resembles an existing or possible person, object, place, animal or event so closely that it may appear authentic or truthful.

What matters is not whether the intention is to mislead the audience. The key question is whether the content could actually appear authentic or truthful.

The disclosure must be easy for users to notice and understand without any special technical tools. For example, you can use a visible or audible label.

If the deep fake forms part of an evidently artistic, creative, satirical or fictional work, you may provide the disclosure in a way that does not unnecessarily hamper the display of the work. However, you must still disclose the use of AI.

Disclose the use of AI when publishing text on matters of public interest

The transparency obligation may also apply to text generated or manipulated by AI. It applies when AI-generated or manipulated text is published to inform the public about matters of public interest.

Matters of public interest may include, for example:

  • public administration
  • fundamental rights
  • public health
  • environmental protection
  • consumer safety
  • significant economic, financial, political, scientific or cultural developments in society.

The obligation may apply, for example, to AI-generated or manipulated:

  • news articles
  • scientific publications
  • reports for investors
  • public notices issued by authorities.

It does not generally apply, for example, to fictional novels, poems, standard advertising content or a chatbot response generated for an individual user.

AI-generated or manipulated text on matters of public interest does not need to be labelled if both of the following conditions are met:

  • a human has reviewed the content of the text or the text has been subject to editorial control
  • a natural or legal person is responsible for publishing the text and for its content.

The exception may apply, for example, to newspaper articles subject to editorial control, peer-reviewed blog posts or public notices approved by authorities.

A substantive review of the content may include checking factual accuracy, the trustworthiness of sources and other factual aspects of the text. Proofreading or checking the language alone is not enough.

When do the transparency obligations not apply?

The obligation does not apply where AI is used only to assist with standard editing of existing content.

Standard editing may include improving the language, readability, quality or technical presentation of content without adding new information or changing its meaning.

The obligation applies only when the changes substantially affect the meaning, style or purpose of the content.

The exception also applies where the AI does not substantially alter the content provided by the user or its meaning (semantics).

This must be assessed case by case. The assessment may take into account factors such as the format and type of the content, its style and the extent to which AI has changed the meaning, style or intent of the original content.

Typical minor changes include, for example:

  • correcting grammar and spelling
  • converting file formats
  • reducing noise
  • minor cropping or straightening of an image
  • minor adjustments to colour, brightness or sharpness
  • stabilising video
  • removing red-eye or technical defects
  • assistive technologies that support accessibility without changing the meaning of the content.

By contrast, the marking obligation generally applies if AI substantially changes the meaning or content.

Such changes include, for example:

  • AI-generated translations and summaries
  • adding new elements to an image or video
  • removing objects, people or backgrounds
  • blurring faces
  • changing a person’s appearance
  • significant changes to colour or contrast
  • colourising black-and-white material
  • creating composite images or videos
  • other substantial alteration of the content.

The marking and detection obligation also does not apply to generative AI systems that are lawfully used to detect, prevent, investigate or prosecute criminal offences.

If an AI system is used exclusively for scientific research or development, the transparency obligations do not apply to that use.

The obligations may apply if the system is later used outside the research environment or if the content it generates is used for another purpose.

How to inform people about the use of AI

Notices and labels required under the transparency obligations must be clear and easy to notice.

Users must be informed about the use of AI no later than when the first interaction takes place.

The provider must ensure that this information is provided throughout the lifecycle of the system, including after the system has been placed on the market and put into service.

AI agents are also covered by the rules if they can interact with people while carrying out their tasks.

The method used to provide the information must take all user groups into account. If the system may be used by children, older people or persons with disabilities, for example, the information must be provided in an accessible way that takes their needs into account.

The information can be provided in different ways, such as:

  • text
  • speech
  • visual indicators
  • a combination of these methods.

Information provided only in terms and conditions or documentation, technical markings that users cannot see and unclear or misleading descriptions are generally not enough to meet the transparency obligation.

What you need to be told about the use of AI

When you use a service that uses AI or encounter AI-generated content, you must be informed about the use of AI in certain situations.

Depending on the situation, you must be able to find out that:

  • you are interacting with an AI system rather than a human
  • you are subject to emotion recognition or biometric categorisation
  • an image, audio or video you encounter is an AI-generated or manipulated deepfake
  • published text on a matter of public interest has been generated or manipulated by AI.

The information must be clear, easy to notice and understandable. It should not be hidden in terms and conditions or in another place that is difficult to find.

What the transparency obligations under the AI Act mean

The EU AI Act includes transparency obligations intended to ensure that people can recognise the use of AI in different situations and assess the origin and reliability of the content they encounter.

The aim is to reduce deception, manipulation and the spread of false information.

The transparency obligations apply from 2 August 2026. AI-generated content produced or published before this date does not need to be labelled retrospectively.

The transparency obligations apply in addition to other EU legislation. The use of an AI system may also be subject to requirements concerning, for example, consumer protection, digital services and data protection.

Who supervises compliance with the transparency obligations?

In Finland, compliance with the transparency obligations under the AI Act is supervised by market surveillance authorities.

Traficom supervises compliance with the transparency obligations, with certain exceptions.

For high-risk AI systems, the transparency obligations of providers and deployers are supervised by sector-specific market surveillance authorities.

The European Commission’s AI Office supervises the transparency obligations in certain situations where an AI system is based on a general-purpose AI model and the same provider develops both the model and the system.

AI systems used by EU institutions, bodies and agencies are supervised by the European Data Protection Supervisor.

In Finland, compliance with data protection legislation is supervised by the Office of the Data Protection Ombudsman.

What to do if you suspect a breach of a transparency obligation

You can contact Traficom if you suspect that a transparency obligation under the AI Act has been breached.

Individuals or organisations can contact us if they have reasonable grounds to suspect a breach. If the matter falls within the competence of another authority, we will refer it to the appropriate authority.

When you contact us:

  • tell us which transparency obligation you believe may have been breached
  • describe the situation in which the suspected breach occurred
  • if possible, include a link to the service or content concerned.

You can contact us in Finnish or Swedish. You can also use English if you prefer.

Page was last updated