Wrivio
Get Wrivio
7 min readBy Wrivio Team

AI Disclosure Obligations in 2026: What You Must Say and When

Transparency obligations under Article 50 of the EU AI Act took effect on 2 August 2026, alongside general-purpose AI enforcement powers and the full penalty regime. Unlike the high-risk obligations, which were deferred to December 2027 and August 2028 by the mid-2026 simplification package, these were not delayed.

The resulting question inside a lot of organizations is some version of: do we now have to tell people when we used AI to write something? The answer is narrower than the anxiety, and the gap between the legal requirement and the professional norm is the part worth thinking about.

What The Law Actually Targets

Article 50 obligations attach to specific situations rather than to AI use generally.

Direct interaction with an AI system. Where a person is interacting with an AI system, they should be informed of that, unless it is obvious from the circumstances. This covers chatbots and automated agents that a person is talking to. It does not cover a tool you use privately to tidy your own writing before sending it yourself.

Synthetic or manipulated content. Where content is artificially generated or manipulated in ways that could mislead, marking and disclosure obligations apply. The target here is synthetic media presented as authentic: deepfakes, fabricated recordings, generated images passed off as photographs.

Emotion recognition and biometric categorization. Separate notification duties where these are used.

Rewriting your own email for register is not the object of any of these. You wrote the content, you are sending it, and it says what you mean. The AI adjusted the phrasing, which is what a colleague or a style guide might also have done.

Good running summaries of the tranches are maintained at artificialintelligenceact.eu.

Where It Does Apply To Ordinary Businesses

Four situations where an ordinary company should look carefully.

Customer-facing chat. If an AI answers customers, tell them. This is the clearest and most common application.

Automated outbound communication. Messages generated and sent without a human reviewing each one are closer to the AI-interaction case than a message you drafted and sent yourself.

Generated media in marketing. Synthetic images, voices, or video that a viewer might reasonably take as a real recording. This is where the marking obligations bite.

Anything touching individuals’ rights. Employment, credit, essential services. Different and heavier obligations may apply, and the deferral of high-risk timelines does not remove the transparency layer.

The Professional Norm Is A Separate Question

Law sets a floor. Professional expectations frequently sit above it, and they vary by context in ways no regulation captures.

Where disclosure is generally expected: academic work with an honor code, legal filings in jurisdictions that have adopted certification requirements, anything where the client contract specifies it, and creative work sold as human-authored.

Where it is generally not expected: using a spellchecker, a style guide, a template, or a tool that tightens your own draft. Nobody discloses Word’s grammar suggestions, and the underlying logic extends reasonably to a rewriting tool: you are the author, the content is yours, and the tool improved the phrasing.

Where it is genuinely contested: cover letters and job applications, performance reviews, and condolence or apology messages, where the recipient may reasonably care whether the sentiment was composed by a person.

That third category deserves thought rather than a policy line. We wrote about it in should you disclose you used AI to write an email.

Where The Model Runs Does Not Change The Duty

Worth stating clearly, because the two things get conflated.

Running a model locally on your own machine does not remove a disclosure obligation. The AI Act regulates systems by use and risk, not by where inference happens. If you owe a customer notice that they are talking to an AI, doing the inference on your laptop is irrelevant.

What local processing does help with is a different regime: GDPR. Text that is never transmitted involves no international transfer, no third-party retention, and a much simpler minimization and security story. That is a genuine benefit, and it is not a transparency benefit. There is more in what changes under the EU AI Act in August 2026.

Writing A Disclosure Policy People Can Apply

The failure mode is a policy that requires judgment at the moment of sending, because judgment fails under time pressure. Give categories instead.

Before:

Employees should disclose the use of AI where appropriate and exercise professional judgment regarding transparency obligations in client and public-facing communications.

After:

Three rules. First, if a customer is interacting with an automated system rather than a person, the system must say so; this applies to our support chat. Second, any image, audio, or video in our marketing that was generated or materially altered by AI must be labeled as such in the asset record and, where a viewer could take it as a real recording, in the published material. Third, using AI to edit or tighten your own writing does not require disclosure, since you are the author and the content is yours. If a client contract specifies AI disclosure terms, those terms override these rules, and the contract owner should flag it to the team.

Each of those is answerable without deliberation, which is the only property that matters in a policy. A Wrivio Context for policy writing could say:

Rewrite this as a workplace policy for a general professional audience. Clear and direct, complete sentences, no contractions. Use concrete categories rather than abstract terms like appropriate or as needed. Keep every rule, exception, and precedence statement exactly as written. Do not add approval steps that are not in the original, and do not replace specific instructions with general principles.

Press Ctrl+Shift+Space, run it, and read the diff carefully. Specific rules dissolving back into “exercise judgment” is the exact failure a rewriting pass can introduce, and it undoes the whole point of the document. There is a fuller template in how to write an AI use policy for a small team.

The Honest Position

If a client asks whether you use AI, the answer that holds up is specific rather than either defensive or evasive.

We use AI assistance for drafting and editing our own written work, in the same way we use style guides and templates. The substance, judgment, and conclusions are ours. Confidential client material is processed with a tool that runs locally on our workstations, so document text is not transmitted to any third-party service. We do not use AI to make or materially influence decisions about individuals, and we do not present AI-generated media as authentic recordings.

That is four sentences, it is checkable, and it answers the question the client is actually asking, which is whether their material is safe and whether the thinking is yours.

Common Questions

Do I have to disclose that I used AI to rewrite an email?

Not under Article 50 for tidying your own draft that you then send yourself. Whether a specific client contract or professional code requires it is a separate question worth settling in advance.

Does this apply to businesses outside the EU?

It can. The AI Act has extraterritorial reach where systems are placed on the EU market or output is used in the EU. Non-EU businesses with EU customers should assume it may apply.

What counts as obvious enough not to need disclosure?

A conservative reading is safest: if a reasonable person might think they are talking to a human, say otherwise. The cost of unnecessary disclosure is low; the cost of the reverse is not.

Does local processing exempt us from anything?

From transparency obligations, no. From the hardest parts of GDPR transfer analysis, substantially yes, because there is no transfer.

Download Wrivio for Windows to keep confidential drafting on your own hardware while your disclosure policy handles the rest.