AI Industry Transparency Guidelines

Explore top LinkedIn content from expert professionals.

  • View profile for Martyn Redstone

    Head of Responsible AI & Industry Engagement @ Warden AI | AI Governance for HR, Recruitment, Staffing & HR Technology

    22,318 followers

    The European Commission has officially published its draft guidelines on AI transparency obligations (Article 50). While much of the recent political debate in Brussels has focused on the delayed timelines for high-risk systems, these new guidelines deal with the immediate requirement for transparency. I have reviewed the 40-page document. Here are the four most critical takeaways for your HR technology strategy: 1️⃣ The end of the 'generic assistant' trap Many recruitment teams use AI chatbots that are given human names or labelled vaguely as 'virtual assistants'. The draft guidelines explicitly target this practice. You must clearly inform candidates about the artificial, non-human nature of the interacting counterpart. A single disclosure buried in your Terms and Conditions is no longer sufficient. The guidelines strongly recommend multi-modal disclosures, such as persistent badges visible throughout the interaction. 2️⃣ Emotion recognition is a prohibited practice The guidelines address the transparency requirements for emotion recognition systems but they include a crucial reminder for the HR sector. The use of emotion recognition is outright prohibited in the workplace. If a vendor pitches an assessment tool claiming to analyse a candidate's facial expressions or vocal tone to infer their emotional state, reject it. It is not just poor science; it is a prohibited practice under the AI Act. 3️⃣ There is no 'grandfathering' for transparency You might assume that because you procured your AI screening tool years ago it is exempt from these new rules. The draft guidelines clarify that while a special grandfathering rule applies to high-risk compliance for legacy systems, it does not apply to transparency obligations. Every AI system you use that interacts with humans or generates synthetic content must be updated to meet these transparency standards regardless of when you bought it. 4️⃣ Mandatory transparency for GenAI communications If your team uses generative AI to draft candidate rejection emails, automate interview feedback, or write job adverts, you can no longer seamlessly pass this off as human-authored. The guidelines dictate that AI-generated synthetic text (or images, audio etc.) must be marked in a machine-readable format and be fully detectable. Furthermore, individuals must be informed clearly at the very first point of exposure. If you rely heavily on AI to mass-produce automated communications, your workflow will require immediate structural updates to remain compliant. The consultation period for these guidelines closes on 3 June 2026. We must stop treating AI transparency as a legal hurdle and start viewing it as a fundamental pillar of candidate trust. I have attached the full draft guidance document below and I have dropped the link to the official consultation in the comments. Are your technology vendors prepared to meet these stringent transparency standards? Are your internally built tools (agents)?

  • View profile for Mateusz Kupiec, FIP, CIPP/E, CIPM

    Institute of Law Studies, Polish Academy of Sciences || Privacy Lawyer at Traple Konarski Podrecki & Partners || DPO || I know GDPR. And what is your superpower?🤖

    27,571 followers

    🤖‼️Today, the AI Office (European Commission) published for public consultation the draft Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 #AIAct. It is a 40-page document, and here are the insights I found most interesting. Article 50 AI Act should not be read as a narrow labelling provision. It creates a horizontal transparency layer for several AI use cases. A key point is the allocation of responsibility. Providers are responsible for transparency-by-design where systems interact directly with people or generate/manipulate synthetic content. Deployers are responsible for using emotion recognition or biometric categorisation systems, or publishing deep fakes or AI-generated public-interest text. The Guidelines also clarify that employees, freelancers or contractors acting under the control of a legal person should not normally be treated as separate deployers. The personal-use exclusion is interpreted narrowly. A natural person creating AI-generated Christmas cards for relatives may fall outside the deployer's obligations, but a person publicly sharing a political deepfake of a local mayor would not. This is important because public dissemination may take the activity outside the purely personal and non-professional sphere, even without economic benefit. For synthetic content, the draft draws an important distinction between machine-readable marking and detectability. Providers must not only mark outputs, but also ensure that detection is possible. Marking alone is not enough. The technical solution should be effective, reliable, robust and interoperable. This points to a compliance architecture involving watermarks, metadata, cryptographic methods, provenance tools, fingerprints, or a combination of these. Mere reproduction, ranking or arrangement of existing content, source code, machine-to-machine outputs, short technical strings, and closed-loop industrial outputs not intended for human interpretation may fall outside Article 50(2). At the same time, agentic AI and multimodal systems may fall within the scope in which their outputs are perceptible to natural persons as text, audio, images, or video. The guidelines explain what consutities a deepfake under Article 50(4) AI Act. A deepfake requires a strong resemblance to real people, objects, places, entities, or events, and a false appearance of authenticity or truthfulness. The intention to deceive is not decisive. The assessment must consider the actual audience, including children, elderly persons and persons with lower digital or AI literacy. Even artistic, fictional or satirical deep fakes are not exempt; they benefit only from a lighter disclosure regime that must not hamper the enjoyment of the work.

  • The European Commission published its first draft of the “Code of Practice on Transparency of AI‑Generated Content” designed as a tool to help organizations demonstrate alignment with the transparency requirements (Art. 50) of the AI Act. Article 50 of the AI Act includes obligations for providers to mark AI-generated or manipulated content in a machine-readable format, and for users who deploy generative AI systems for professional purposes to clearly label deepfakes and AI-text publications on matters of public interest. The document is divided into two sections. The first section covers rules for marking and detecting AI content, applicable to providers of generative AI systems, including to: - Use a Multi‑layered machine-readable marking of AI‑generated content - Use imperceptible watermarks interwoven within content - Adopt a digitally signed “manifest/provenance certificate” for content that can’t securely carry metadata - Offer free detection interfaces/tools, including confidence scoring, and complementary forensic detection that does not rely on active marking - Test against common transformations and adversarial attacks - Use open standards and shared/aggregated verifiers to enable cross-platform detection and lower compliance friction The second section covers labelling deepfakes and certain AI-generated or manipulated text on matters of public interest and is applicable to deployers of generative AI systems, including: - Deepfake labelling - Modality‑specific labelling rules for real-time video, non-real-time video, images, multimodal content, and audio-only - Operational governance: encourages internal compliance documentation, staff training, accessibility measures, and mechanisms to flag and fix missing/incorrect labels.

  • View profile for Jim Reavis

    CEO at Cloud Security Alliance

    17,071 followers

    In all the excitement about the latest model developments and autonomous attacks, it would be easy to miss that the EU AI Act's transparency obligations take effect August 2. Article 50 was not part of the Digital Omnibus deferral. High-risk systems under Annex III genuinely moved to December 2027 — but transparency duties attach to what a system does, not to a risk tier. Conversational, generative, emotion-detecting, deepfake-producing. So if you classified your way through Annex III and found nothing, you may still be in scope. What lands August 2: users must understand they're talking to an AI, disclosed at first interaction, and deployers must disclose deepfakes and AI-generated text on matters of public interest. Up to €15M or 3% of worldwide turnover, with the burden of proof on you. The machine-readable marking obligation got a separate four-month runway, through December 2. Watermark scrubbing has been getting increasingly easier. By the way — CSA's AI Controls Matrix maps to the EU AI Act, giving you an operational controls framework for addressing EU AI Act requirements. Research note and sources in comments. Permanent location for paper: https://lnkd.in/gJnr4VGf AI Controls Matrix download: https://lnkd.in/gen9g3Dy

Explore categories