AI News

EU AI Act Transparency Rules for Agencies

Vol. 02 · August 2026

Use a five-field client handoff to identify EU-facing AI work, assign disclosure ownership, and preserve human-review evidence without slowing delivery.

Reed VogtCEO and Head Engineer
PublishedAug 4, 2026
Read Time11 min
Words2,187

EU AI Act Transparency Rules for Agencies

EU AI Act transparency rules for agencies became operational on August 2, 2026. If your consultancy or agency ships AI-assisted client work into Europe, the immediate task is not to label every rough draft: it is to identify the public-facing use, agree who owns the disclosure, and retain evidence of human review. The European Commission says new transparency rules took effect on August 2, while the AI Office and Member State authorities now implement, supervise, and enforce the Act. Its updated AI Act overview was last updated on August 3.

This is practical operating guidance, not legal advice. The EU AI Act's scope, exceptions, contract allocation, and national enforcement deserve qualified advice for a particular engagement. But most client-service teams can make their work much safer this week by replacing vague "we used AI" language with a short, repeatable handoff record.

Key Takeaways

  • August 2, 2026 is the new operational date for relevant Article 50 transparency duties.
  • Review EU-facing chatbots, synthetic media, and public-information content before the client handoff.
  • Separate a provider's technical obligations from a deployer's client-facing disclosure duties.
  • Human review can matter for public-interest text, but it is not a universal exemption.
  • Keep a five-field record: use case, audience, tool, reviewer, and agreed disclosure owner.

What changed in EU AI Act transparency rules for agencies?

Article 50 is no longer simply a calendar item. The Commission announced on July 31 that it would start enforcing AI Act rules and new transparency requirements on August 2; its August 2 news item confirms that the rules took effect and points readers to implementation guidelines. The change matters to a US-led firm when an in-scope system or output is used in the EU—not because every internal brainstorm suddenly becomes a compliance project.

For a client-service owner-operator, start with the work that a person outside your team can encounter: a client website chatbot, a synthetic spokesperson video, a public report, or an automated intake experience. Then distinguish it from private drafting, editing assistance, or a deliverable that a named human has substantively reviewed. That boundary is more useful than a blanket rule about whether a team used an LLM.

The Article 50 scenarios are split between providers and deployers. Cooley's August 3 explanation describes four main categories: AI systems that interact directly with people, synthetic content, emotion-recognition or biometric-categorisation systems, and deepfakes or certain AI-generated public-information text. An agency can be a deployer for a client chatbot or content workflow even when it is not the model provider.

Why this is a delivery issue, not an IT-only issue

Agencies are often the last team to touch the public artifact and the first team a client asks when a disclosure is missing. A campaign page can contain a chat assistant, a video can be synthetic, and a report can be assembled with AI—all inside one statement of work. Treating that as an opaque vendor setting creates avoidable rework at approval time.

The smaller the team, the more important the distinction becomes. You do not need a large governance program to record what was shipped. You need a reliable way to say: what was made, where it appears, who sees it, who reviewed it, what the client approved, and what remains a vendor-level technical question.

The date does not answer every technical question

Do not assume that "AI-generated" has one identical disclosure rule. The Commission's materials, provider documentation, and the final applicable text control. Debevoise's August 3 summary notes that Article 50 covers four categories and that enforcement and supervision have become operational. It also describes technical marking as a separate obligation, with timing and responsibility that can depend on the system and circumstances.

That is why an agency should avoid promising that a visible footer, a platform watermark, or a client policy alone solves every requirement. Make the compliance question visible early, then get a specific legal or vendor answer when the engagement turns on it.

Which client deliverables deserve a first review?

The table is a triage tool, not a legal classification. It helps a consultant or agency decide which work should receive a documented Article 50 check before publication or launch.

Deliverable or systemFirst questionLikely owner to confirmEvidence to retain
Client-facing chatbotDoes a person know they are interacting with AI at first contact?Client product owner and system providerScreenshot, launch URL, disclosure copy, owner approval
Synthetic image, audio, or videoIs it materially generated or manipulated, and how will it be used?Client marketing owner and platform/providerAsset inventory, tool record, distribution plan
Public report or public-interest updateIs AI-generated text being published to inform the public, and was it substantively reviewed?Client executive/editorial ownerSource file, reviewer name, review notes, final copy
Internal working draftWill it stay internal or become a public artifact?Engagement leadDistribution decision and review status
AI-enabled intake or assessmentDoes it interact with people or use sensitive categorisation?Client operations owner and legal counselWorkflow map, vendor terms, escalation path

Use the rows in order. A client-facing chatbot is not just content; it is an interaction. A chatbot disclosure belongs at the point where a person first encounters the system, not buried in a PDF. A public report is not automatically a deepfake, and an ordinary internal draft is not automatically a public-information publication. The point is to force the scope question before the design is locked.

The useful agency deliverable is not a generic AI disclaimer. It is a short, client-approved record that connects the audience, the use case, the review, and the responsible owner.

Ropes & Gray's operational overview is helpful on the caveat: several Article 50 duties remain on their original timeline despite wider AI Act changes. Treat the checklist as a routing device for the relevant decision-maker, not a way to self-certify legal compliance.

How should an agency run the client handoff?

Build the check into the workflow you already use for creative review, source checking, and launch approval. Five fields are enough for a first pass:

  1. Use case: what actually ships—chatbot, image, video, text, or internal draft.
  2. Audience and geography: who can encounter it, including EU availability or targeting.
  3. System role: which part came from a provider and which part the client or agency deploys.
  4. Human review: who checked claims, context, and final publication readiness.
  5. Disclosure owner: whether the agency, client, platform, or provider needs to take the next action.

Put that record next to the deliverable, not in a separate policy folder nobody opens during a Friday launch. If a client is responsible for the website or publishing channel, make that explicit in the handoff. If the agency is publishing on the client's behalf, require a named client approver. If the answer is unclear, pause only the affected asset or experience until the client gets advice; do not claim that a prompt log proves the work is compliant.

For recurring launches, cap the record review at 10 minutes rather than turn it into a meeting. Attach the final capture within 24 hours, revisit it within 48 hours if the client changes audience or distribution, and reserve 30 minutes of escalation only for a high-stakes or unclear use case. Those are delivery-service levels, not legal thresholds.

Example: a fractional CMO shipping a campaign page

Imagine a fractional CMO launches a new landing page for a US company that accepts EU prospects. The page includes an AI chat assistant and a short product video assembled with a generative tool. The lightweight handoff would record the visible chatbot disclosure, whether the video needs a disclosure in its specific use, the model or tool vendor, the page owner, the client approver, and a link to the final launch capture.

That does two things. It makes the client decision fast, and it prevents the agency from becoming the accidental guarantor of a model provider's technical marking capability. It also makes a later update easier: when the client changes regions, vendors, or the chatbot's authority, the team knows exactly what to re-review.

Keep public-information claims under editorial control

Article 50's treatment of text intended to inform the public is especially relevant to research shops, fractional leaders, and communications agencies. A human name in a document is not the same as meaningful editorial control. Have a qualified reviewer check factual claims, source provenance, framing, and final publication. Preserve the version they approved.

This is good client work whether or not a particular exception applies. It reduces the more familiar risk: generic AI copy claiming research, customer outcomes, prices, or commitments that nobody verified. AI News' August 3 coverage is a useful independent signal that the issue has shifted from future policy discussion to live operational decisions.

What should agencies put in their statements of work?

Use the SOW to create clarity, not to dump unbounded legal risk on either side. Describe the intended use, the client-owned publishing surfaces, the agency's review scope, the client's final approval duty, and how material changes are handled. Do not promise compliance with laws you have not assessed or assume a vendor's marketing claim transfers responsibility.

Three clauses or operating rules often help:

  • The client identifies target markets and material public uses before launch.
  • The agency identifies AI-assisted components and completes the agreed review record.
  • The client confirms final disclosure, legal review, and publication approval for its owned surfaces.

That division matches the reality of client work. An agency controls its production process; the client controls many business decisions, channels, and ongoing uses. If the agency is contracted to operate the system itself, expand the review and get counsel involved before launch.

Pro tip (from running ZeroTwo): keep the brief, source links, prompt or tool record, draft versions, reviewer notes, and final client approval together in ZeroTwo. It makes it easier to separate evidence from an AI-generated claim and to rebuild project context without asking a busy client to explain the same engagement twice.

What should not trigger panic?

Not every instance of AI assistance is the same as an in-scope public deployment. Routine spelling help, internal ideation, a private draft that never leaves the team, or a human-authored deliverable that merely used a standard editing function can be materially different from a public-facing AI interaction or a synthetic public artifact. The factual details matter.

The wrong response is to hide AI use or to add a vague badge to everything. The better response is to define the use case, make a proportionate decision, and document the basis. Where the work is high-stakes, public-facing, or reaches EU audiences in an unclear way, bring in specialist advice before making a representation to a client.

Frequently Asked Questions

Do EU AI Act transparency rules apply to US agencies?

They can. A US agency should assess whether an AI system or output is used in the EU, rather than assuming its headquarters determines the answer. The exact scope depends on the engagement, audience, system, and role. For an EU-facing client launch, record the distribution and ownership facts early and have qualified counsel assess the specific legal position.

Does every AI-assisted client deliverable need a label?

No blanket rule is safe. Article 50 distinguishes between direct AI interactions, synthetic content, emotion or biometric uses, and certain public-information text, with different obligations and exceptions. Start by identifying the final use and audience. A visible label may be relevant in some cases, while provider-level technical marking or human editorial review may be the real question in others.

Who owns an AI disclosure: the agency or the client?

It depends on who provides or deploys the system and who controls the public surface. Agencies should not leave that ambiguous. Put a named owner in the handoff record and statement of work. If a client owns the site or publishing channel, its final approval should confirm the disclosure decision; agencies should document their agreed review scope.

What counts as human review of AI-generated text?

Meaningful review should check the final claims, source support, audience context, and publication decision—not merely add a human name after generation. Retain the reviewed version and the reviewer identity. Whether a particular Article 50 exception applies is a legal determination tied to the use case, so seek counsel for material public communications.

What evidence should an agency retain?

Retain the use-case description, audience or territory decision, system or tool record, relevant source files, reviewer notes, final disclosure copy where used, client approval, and a capture of the published experience. Keep the record proportionate to the engagement. It should let a client reconstruct a decision without inventing a bureaucracy for low-risk internal drafts.

What comes next

The next practical signal is how clients, platform vendors, and national authorities translate the Commission's guidelines into implementation expectations. Watch for provider documentation on technical marking, client requests for contract language, and enforcement guidance that clarifies edge cases. The answer will not be to rebuild every workflow. It will be to make the few client-facing decisions explicit before a deliverable goes live.

Disclosure design. Clear, timely disclosure is part of a trustworthy client experience, not a footnote added after launch.

Review evidence. Agencies that can show who reviewed a public claim will spend less time rebuilding context when clients ask how a deliverable was made.

Vendor boundaries. Model and platform capabilities should be verified against current documentation; an agency should not convert a provider marketing statement into a client guarantee.

EU AI Act transparency rules for agencies reward the same discipline that produces better client work: clear scope, credible evidence, and a handoff that leaves no one guessing who owns the next decision.

ZERO · TWO
Reed Vogt
Visionary leader and technical architect behind ZeroTwo's AI platform. Reed combines deep engineering expertise with strategic leadership to drive innovation in conversational AI.
Subscribe →
— Next In This Series —

DeepSeek Harness for Client Delivery: Pilot Checklist

Read next