After the Chatbot · Part 4

EU AI Act Transparency Rules: Start with an AI Inventory

Article 50 transparency rules now apply to certain AI systems and content. This checklist helps small companies find and govern the AI they use.

September 7, 2026

Blog
EU AI Act Transparency Rules: Start with an AI Inventory

Article audio

Listen to article

0:00 0:00

Now Playing

Start playback to see the current phrase.

Transparency obligations for certain AI systems started applying on 2 August 2026. The European Commission published detailed guidance shortly before the deadline. Small companies now need to understand whether customers are interacting with AI, whether public content falls within a disclosure rule, and which providers and systems sit behind those activities.

The Act applies in phases. Earlier rules already covered prohibited practices, AI literacy, governance, and general-purpose AI, while some requirements for high-risk systems have later dates.

Start with an AI inventory so legal and operational owners can assess the uses that actually exist.

A company cannot assess AI risk, transparency, privacy, or accountability until it knows which AI systems are in use. That sounds straightforward. In practice, AI arrives through individual subscriptions, new SaaS features, website plug-ins, marketing tools, recruitment platforms, customer-support systems, and internal experiments.

A manager may believe the company has no formal AI programme while employees use AI every day.

This is Part 4 of After the Chatbot, following Part 3 on preventing AI agent sprawl .

What changed in August 2026?

The AI Act applies different obligations according to the role of the organization, the type of system, and the risk involved.

The European Commission’s Article 50 guidance addresses transparency duties for providers and deployers of certain AI systems. Examples include informing people when they interact with particular AI systems and disclosing certain AI-generated or manipulated content. The Act applies in phases, and the Commission’s AI Act overview explains the wider timetable and risk-based framework.

The exact duty depends on the use case. A public chatbot, an internal writing assistant, an emotion-recognition system, and a generative image tool do not create identical obligations.

Small companies should avoid two common mistakes:

  • assuming every use of generative AI is prohibited or high risk
  • assuming a vendor carries every responsibility because it supplies the model

The provider develops or supplies the AI system. The deployer uses it under its authority. A small company may be a deployer in one workflow and a provider in another, so its role and use still matter.

Compliance can turn into elaborate theatre when nobody owns the underlying process. A short register and clear operating rules are more useful than a ministry of paperwork.

Find the AI hiding inside normal software

An AI inventory should cover more than ChatGPT, Claude, Gemini, and Copilot accounts.

Look for AI inside:

  • customer-support and website chat
  • CRM lead scoring and message drafting
  • recruitment screening and interview analysis
  • accounting and document extraction
  • meeting transcription and summaries
  • marketing content, images, video, and personalization
  • fraud, identity, and security tools
  • productivity suites
  • project-management software
  • website optimization and analytics
  • employee-built automations
  • agents that can update records or send messages

Ask each team which features they use, not which AI products they bought. A familiar software product may have gained new AI functions after the original procurement decision.

Browser histories, expense records, single sign-on logs, vendor lists, automation platforms, and team interviews can all reveal usage. The purpose is visibility, not punishment. Employees may work around controls when the governed route is too slow or impractical.

Build a minimum viable AI register

A small company does not need an enterprise governance platform to begin.

Create one record for each material use:

  • tool or system name
  • provider
  • business purpose
  • internal owner
  • people affected
  • data entered or accessed
  • personal or confidential data involved
  • output produced
  • external actions the system can take
  • human review point
  • customer-facing status
  • applicable disclosure
  • contract and privacy documentation
  • last review date

This register supports several decisions at once. It helps with AI Act assessment, GDPR review, security, access management, procurement, and employee guidance.

It also exposes systems that should be retired because they have no owner or approved purpose.

Start with customer-facing uses

Customer-facing AI deserves early attention because it can influence decisions, make representations on behalf of the company, or create a transparency duty.

Review:

  • website chatbots
  • automated support replies
  • sales qualification
  • personalized recommendations
  • generated product images
  • synthetic presenters or voices
  • AI-generated or manipulated public-interest text published without substantive human review or editorial control
  • agents that send customer communication

For each use, identify what the person sees, whether the AI role is clear, which data is collected, and how a person can reach human support.

Commission guidance says people should be informed clearly from the start of the first direct interaction with an AI system unless that interaction is obvious. Hiding a notice inside a long privacy policy does not meet that practical standard.

EU AI Act disclosure checklist for small companies

Blanket labelling can create confusion and reduce the value of meaningful disclosures.

The AI Act does not treat every spelling correction, internal summary, or AI-assisted draft as the same kind of activity. For public-interest text, substantive human review or editorial control can affect whether labelling is required. Other exceptions and contextual rules can also apply.

The company should therefore:

  1. identify the use
  2. determine its role
  3. classify the relevant risk and transparency questions
  4. document the decision
  5. apply a clear disclosure where required
  6. review the use when the system or purpose changes

Legal advice may be necessary for borderline or higher-risk cases. The operational team still needs to supply the facts.

This article provides practical operational guidance, not legal advice.

Give employees a usable route

An AI policy fails when it only lists prohibitions.

Employees need to know:

  • which tools are approved
  • which data can be used
  • which data needs a private or controlled environment
  • when human review is mandatory
  • which customer-facing actions require approval
  • how to disclose AI use
  • how to request a new tool
  • where to report a mistake or concern

Short examples are more useful than abstract rules. Explain whether an employee may summarize a public report, rewrite internal notes, upload a customer contract, generate a public image, or let an agent send a prospect email.

The policy should distinguish harmless productivity use from work involving personal data, confidential information, public claims, employment, credit, health, safety, or binding decisions.

A practical 30-day response

Week 1: discover

Interview each function, review software and expense records, and create the first AI register.

Week 2: triage

Prioritize customer-facing systems, sensitive data, automated decisions, generated public content, and agents with external actions.

Week 3: control

Assign owners, remove abandoned tools, tighten permissions, create approval rules, and add required disclosures.

Week 4: teach and review

Give employees concrete guidance. Test the customer experience. Review uncertain cases with qualified legal or data-protection support.

Repeat the review quarterly and whenever a vendor adds a significant AI capability.

Frequently asked questions

Does the EU AI Act apply to small companies?

Yes, depending on their role and use of AI. The Commission’s AI Act overview describes measures intended to support smaller companies, but company size does not automatically remove every obligation.

Does every AI-generated article or image need a label?

No blanket rule covers every AI-assisted output in the same way. The obligation depends on the type of content, the use, human review or editorial control, and the organization’s role. Assess the specific case using current Commission guidance .

Is an AI inventory legally required?

The exact record-keeping duty depends on the use and classification. An inventory is the practical foundation for determining which duties apply and for showing how the company reached that decision.

Who should own AI governance?

One senior business owner should be accountable. Legal, data protection, security, HR, marketing, and technical staff should contribute when the use touches their responsibilities.

Can the software vendor handle compliance?

The provider has its own obligations. A company deploying the system still needs to understand how it uses the product, which data is involved, who is affected, and where human oversight belongs.

Make governance part of normal operations

AI governance should work like access management, privacy, or financial control. It needs owners, records, review dates, and an escalation path.

The AI Act creates a clear reason to start. The operational benefit is broader. A company with an accurate AI inventory can reduce duplicate tools, control sensitive data, clarify approvals, and deploy useful agents with greater confidence.

XYZ’s Security Officer can establish technical controls around tools, access, permissions, and incidents. Teams that first need to map systems and operational use cases can start with a Company-Wide Agentic Workflow .

Newsletter

Get new XYZ posts by email

Subscribe to the XYZ mailing list to get new field notes, blog posts, and practical AI thinking in your inbox.

We use this address only for the XYZ mailing list. You can unsubscribe at any time. See our Privacy Policy .

Recommended services

More Services

Related posts

More Posts