This website uses cookies

Read our Privacy policy and Terms of use for more information.

// AI Lessons

The AI Disclosure Audit You Can Run in 30 Minutes

The EU AI Act's transparency rules went live three weeks ago while everyone was reading about the delay. Here's the 30-minute audit that tells you if you're exposed.

I run a media company where AI touches every one of our seven newsletters, and I'll admit something: when the EU agreed in May to push the AI Act's high-risk rules to 2027 and 2028, I mentally filed the whole thing under "future Mark's problem." I suspect half of corporate America did the same.

Then I actually read what got delayed. The high-risk rules moved. The transparency rules in Article 50 — the ones that govern chatbots, AI-generated images, and AI-written content — took effect on August 2, 2026. Three weeks ago. The only piece that got a reprieve is machine-readable watermarking for older systems, and that grace period ends December 2. I nearly missed a media-labeling law while running a media company. That's the kind of thing that keeps compliance officers young.

Find every place AI talks to your customers before a regulator does.

// The Takeaway: The EU AI Act's transparency obligations are already in force — chatbots must disclose they're AI, synthetic images/audio/video that resemble real people or events must be labeled, and AI-written public-interest content needs either a label or documented human editorial control. Penalties run up to €15 million or 3% of global turnover. A 30-minute audit — inventory, chatbot check, media check, text check, vendor email — tells you exactly where you stand.

Start the inventory now → · Thirty minutes. No new tools. One email to your AI vendors.

If your company has customers, users, or even just website visitors in the EU, this applies to you — the AI Act reaches US companies whose AI output is used in the EU, the same extraterritorial playbook as GDPR. And even if you have zero EU exposure, this is where disclosure norms are heading everywhere. Auditing now is cheap. Retrofitting under enforcement isn't.

// The real shift: Compliance here isn't a legal project — it's an inventory project. Article 50 doesn't ask you to stop using AI. It asks you to know where AI output meets a human and say so. The companies that struggle with this won't struggle because labeling is hard. They'll struggle because nobody can produce the list of places AI talks to their customers. The audit is the compliance.

What Article 50 actually requires

Three obligations matter for most businesses, per the European Commission's own FAQ:

First, interaction disclosure: people must know when they're talking to an AI system — chatbot, voice agent, avatar — from the first interaction, unless it's obvious. Second, synthetic media disclosure: if you publish AI-generated or AI-manipulated image, audio, or video content that could pass for authentic — the regulation's word is deepfake, but it covers more than face swaps — you must clearly disclose it, at first exposure. Third, machine-readable marking: providers of generative AI systems must mark synthetic output so it's detectable as AI-generated — this is the piece with the December 2 grace period for systems already on the market before August 2.

There's one exemption that matters enormously for anyone who publishes: AI-generated text intended to inform the public doesn't need a label if it underwent human review or editorial control and a person takes editorial responsibility. The Commission is explicit that superficial checks don't qualify. A named editor who actually reviews the work does. Hold that thought — it's step four.

The thirty-minute audit

  1. Inventory the surfaces (5 minutes). Open a doc and list every place your organization's AI output meets a human: website chatbot, support voice line, AI-generated images in marketing, AI-written blog posts or newsletters, synthetic video, AI avatars in training content. Ask one person from marketing, one from support, and one from sales — those three know where the bodies are buried.

  2. Check the chatbot (5 minutes). Open your own chatbot or voice agent as a customer would. Does the first message say it's AI? If not, the fix is one line in the greeting — "You're chatting with an AI assistant" — and you can ship it today. If a human can take over the conversation, disclose the handoff both ways.

  3. Check the media (10 minutes). For each AI-generated image, video, or audio asset in the inventory, ask one question: could a reasonable person mistake this for a real photo, recording, or event? A stylized illustration, no. A photorealistic scene, a cloned voice, an AI spokesperson — yes, and it needs a visible disclosure at first exposure. Add a caption or an on-screen label. Artistic and satirical work needs only a disclosure that doesn't ruin the piece.

  4. Document editorial control (5 minutes). For AI-assisted articles, newsletters, and reports: write down, in one paragraph per publication, who reviews AI-drafted content before it ships and who holds editorial responsibility. Name a person, not a team. That paragraph is what converts "unlabeled AI text" into "human-reviewed content under editorial control" — the exemption in black and white.

  5. Email your vendors (5 minutes). Send every generative AI vendor you use one question: "Do your outputs carry machine-readable provenance marking — such as C2PA Content Credentials — and what is your Article 50(2) compliance plan for the December 2, 2026 deadline?" Their marking obligation is theirs, but their answer is your evidence of diligence — and their silence is your risk signal before renewal season.

Bonus: the same audit, US edition

No EU exposure? Run steps 1 and 4 anyway. The FTC has been clear that undisclosed AI impersonation and deceptive AI claims are enforcement targets, and state legislatures are moving the same direction. The inventory you build today is the one you'll reuse for whatever arrives here — and "we know exactly where AI touches our customers" is a sentence worth being able to say in any jurisdiction.

Why now

Because the omnibus coverage buried the lede. Everyone read "AI Act delayed to 2027" and relaxed — the high-risk obligations did move to December 2027 and August 2028. But the transparency layer is live now, the watermarking grace period expires December 2, and enforcement authorities get to pick their early examples. On Thursday, the Deep Dive unpacks how this reprieve-that-wasn't happened and what the 2027 timeline really means for your AI roadmap. Today, just run the audit. Thirty minutes now beats a €15 million conversation later.

Your AI Sherpa,

Mark R. Hinkle
Founding Publisher, The AIE Network
Follow me on LinkedIn

If you want to get in contact or give me feedback, reply to this email. I read every single one of them.