Artificial Intelligence in Australia
User transparency
Law / proposed law in Australia
Australia has not enacted a standalone, comprehensive AI Act or another generally applicable AI-specific statute equivalent to the European Union’s AI Act. The current Australian approach is to apply existing technology-neutral laws, sector-specific regulation, enforceable online-safety instruments, public-sector policy and voluntary responsible-AI guidance. Whether a rule applies turns on the use case, the data and parties involved, the sector, the deployment model and the system’s effects.
The National AI Plan, released in early December 2025, sets the Australian Government’s policy direction around three objectives: capturing the opportunity, spreading the benefits, and keeping Australians safe. For regulation, the Government’s stated preference is to build on existing legal and regulatory frameworks. Targeted intervention may still be considered where existing frameworks cannot adequately address a demonstrated risk.
On 15 July 2026, Prime Minister Anthony Albanese announced proposed Australian Standards for AI and the establishment of an Office of AI within the Department of the Prime Minister and Cabinet. The proposal is expected to be considered by National Cabinet in August 2026, with legislation expected in early 2027, and may result in a more targeted mandatory framework for aspects of AI regulation in Australia.
Existing laws potentially relevant to AI include the Privacy Act 1988 (Cth), the Australian Consumer Law, competition law, copyright and other intellectual-property laws, breach of confidence, contract law, defamation, anti-discrimination law, employment and workplace-surveillance law, work health and safety law, product-liability law, directors’ duties, criminal and cybercrime law, the Online Safety Act 2021 (Cth), the Security of Critical Infrastructure Act 2018 (Cth), administrative law, financial-services and prudential regulation, health and therapeutic-goods regulation, education law and state and territory privacy, health-records, surveillance and public-sector laws. The list is not exhaustive, and no single regime governs all AI activity.
AI.gov.au was published in May 2026 as the consolidated Australian Government portal for responsible-AI guidance, tools and resources. It is operated through the National AI Centre within the Department of Industry, Science and Resources.
Automated decision-making transparency under the Privacy Act
From 10 December 2026, an Australian Privacy Principle (APP) entity must include additional information in its privacy policy under APPs 1.7–1.9 where it has arranged for a computer program to make a decision, or to do a thing substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information about the individual is used in operating that program. The policy must describe the kinds of personal information used, the kinds of decisions made solely by those programs and the kinds of decisions for which those programs do something substantially and directly related to making the decision.
These are transparency obligations. They do not, by themselves, create a general right not to be subject to automated decision-making. The Office of the Australian Information Commissioner (OAIC) consulted on implementation guidance in May 2026; the final guidance should be checked before the provisions commence.
State and territory overlays
State and territory laws can be material, particularly for public-sector, health, education, law-enforcement, surveillance and workplace uses. Relevant overlays may include privacy and health-records statutes, information-sharing laws, surveillance-device and workplace-surveillance legislation, public-records requirements, anti-discrimination law and sector-specific governance duties.
Regulatory guidance / voluntary codes in Australia
The current Australian Government framework for voluntary responsible-AI adoption is the National AI Centre’s Guidance for AI Adoption, which was released in October 2025 and is now hosted through AI.gov.au. It is available in a foundations version for early or lower-risk adoption and an implementation-guidance version for more complex or higher-risk uses. The guidance includes an AI screening tool, AI policy guide and template, AI register template and a glossary. The framework is organised around six essential practices:
- Decide who is accountable;
- Understand impacts and plan accordingly;
- Measure and manage risks;
- Share essential information;
- Test and monitor; and
- Maintain human control.
These practices are voluntary and non-binding guidance. They are designed to help organisations operationalise responsible AI consistently with existing Australian laws and risk-management expectations; they do not create an independent cause of action or substitute for sector-specific legal analysis.
Australia’s AI Ethics Principles were published in November 2019. The Voluntary AI Safety Standard, published in September 2024, later expressed responsible-AI practices through ten voluntary guardrails. The current six-practice Guidance for AI adoption is now the principal economy-wide Australian Government responsible-AI adoption guidance. References to the ten guardrails should therefore be understood as historical rather than as the current government framework.
In September 2024, the Department of Industry, Science and Resources released a proposals paper on mandatory guardrails for AI in high-risk settings. The Government has since stated that it will not proceed with those proposals at this time. The paper is therefore a historical consultation document, not law and not a currently progressing legislative regime. Its suggested high-risk criteria may still be useful as background policy material, but they must not be expressed as mandatory obligations.
The Productivity Commission’s final report, Harnessing data and digital technology, issued on 10 December 2025, recommends that AI-specific regulation be used only as a last resort where existing regulatory frameworks cannot be sufficiently adapted to handle AI related harms and technology-neutral regulation is infeasible or cannot adequately mitigate the risks. That recommendation expressly addresses the previous mandatory-guardrails proposal.
Privacy, automated decision-making and cyber guidance
On 21 October 2024, the OAIC released guidance for organisations using commercially available AI products and separate guidance for developers training or adapting generative-AI models. The OAIC emphasises that Privacy Act obligations may apply to personal information in prompts, training or fine-tuning data, system logs or other records where they contain personal information and outputs, including inferred, inaccurate or artificially generated information where it is about an identified or reasonably identifiable individual. The OAIC advises AI developers to take reasonable steps to ensure accuracy in generative AI models, such as implementing quality assurance controls to mitigate the risk of biased or inaccurate output prior to release. Public availability of data does not, by itself, establish that collection or use for model training is lawful.
The Commonwealth Ombudsman’s Automated Decision-Making Better Practice Guide was updated in March 2025 in collaboration with the OAIC and the Attorney-General’s Department. It addresses legality, procedural fairness, transparency, accountability, reviewability and system governance in government decision-making. In January 2026, the OAIC also reported on agencies’ publication of automated-decision operational information under the Freedom of Information Act 1982 (Cth) Information Publication Scheme.
On 23 May 2025, the Australian Signals Directorate’s Australian Cyber Security Centre and international counterparts published AI data-security guidance. It addresses risks across the AI lifecycle, including data-supply-chain compromise, maliciously modified or poisoned data, data drift, provenance, access controls, secure storage and integrity protection.
Commonwealth Government use
Version 2.0 of the Policy for the responsible use of AI in government took effect on 15 December 2025. It applies to non-corporate Commonwealth entities subject to specified exclusions, including defence and national-intelligence contexts, and corporate Commonwealth entities are encouraged to adopt it. The policy requires, among other things, accountable officials, transparency statements, a strategic AI-adoption position, operational governance, accountable use-case owners, internal use-case registers, staff training and impact assessment. Additional senior governance applies to higher-risk in-scope uses. These are government-policy requirements, not general economy-wide law.
The Australian Government released the AI Plan for the Australian Public Service 2025 on 12 November 2025. It is organised around the pillars of Trust, People and Tools and aims to expand safe AI capability, access and adoption across the Australian Public Service.
Appointed supervisory authority in Australia
Australia has not appointed a single statutory authority with general enforcement jurisdiction over all AI systems. There is no central Australian AI regulator equivalent to an authority administering a comprehensive AI Act.
The Australian AI Safety Institute has been announced as a key National AI Plan action and sits within the Department of Industry, Science and Resources. It replaced the previously planned AI Advisory Body, which was discontinued in February 2026. It is intended to perform technical analysis, monitoring, testing and policy-support functions and to support government agencies and existing regulators. It is not an enforcement regulator and does not displace statutory regulators or alter their legal remits.
Existing regulators continue to supervise AI-related conduct within their statutory mandates. Depending on the use case, they include the OAIC for privacy and freedom of information; the Australian Competition and Consumer Commission (ACCC) for competition and consumer protection; the eSafety Commissioner for online safety; the Australian Securities and Investments Commission (ASIC) and the Australian Prudential Regulation Authority (APRA) for financial services, markets and prudential and operational-risk matters; the Therapeutic Goods Administration (TGA) and health regulators for therapeutic goods, medical devices and health uses; workplace, safety and anti-discrimination bodies; cyber security and critical-infrastructure authorities; ombudsmen and administrative-review bodies; and state and territory regulators. A single AI deployment may engage several regulators concurrently.
Definitions in Australia
Australian legislation does not presently contain a single, generally applicable statutory definition of ‘AI system’, ‘AI technology producer’, ‘provider’, ‘deployer’ or ‘user’ for all purposes. Definitions can instead arise within particular statutes, contracts, technical standards or sector-specific rules and must be read in their own context.
The National AI Centre’s current terms page uses an Organisation for Economic Co-operation and Development (OECD)-aligned concept of an AI system: a machine-based system that infers from inputs how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments; AI systems differ in autonomy and post-deployment adaptiveness. The guidance also uses the following non-statutory role descriptions:
- AI deployer: an individual or organisation that supplies or uses an AI system to provide a product or service, whether internally or externally.
- AI technology producer: an organisation or entity that designs, develops, tests and provides AI technologies such as models and components.
- AI platform, product or service provider: an organisation or entity that provides products or services using one or more AI systems.
- AI user: an entity that uses or relies on an AI system.
The OAIC distinguishes the underlying model from the broader AI system in which it is deployed. As an explanatory matter, that broader system may also encompass data, software, interfaces and operational processes. Governance controls and human decision points may be important components of a deployment, but they should be identified as contextual system-design features rather than presented as a verbatim OAIC definition.
Prohibited activities in Australia
Australia has not enacted a comprehensive list of prohibited AI practices equivalent to the prohibited-practices regime in the European Union AI Act. AI-enabled conduct may nevertheless be prohibited, restricted or actionable under existing laws.
Existing legal prohibitions and restrictions
Depending on the facts, existing law may prohibit or regulate unlawful collection, scraping, use or disclosure of personal information; misuse of biometric information; serious invasion of privacy; misleading representations and unfair consumer practices; unlawful discrimination; defamation; copyright infringement; breach of confidence; unauthorised surveillance or workplace monitoring; computer offences, malware and unauthorised access; child sexual exploitation material; financial or professional services supplied without required authorisation; unsafe therapeutic goods or medical devices; and unlawful or procedurally unfair government decision-making.
Online-safety codes, standards and enforcement
The Online Safety Act 2021 (Cth) supports mandatory industry codes and standards for sections of the online industry. The Online Safety Codes and Standards regulate online activities involving class 1 and class 2 material. Phase 1, now referred to as the Unlawful Material Codes and Standards, focuses on class 1A and class 1B material, including seriously harmful content such as child sexual exploitation material, pro-terror material, and extreme crime and violence material. Phase 2, now reflected in the Age-Restricted Material Codes, focuses on class 1C and class 2 material, including online pornography and other age-inappropriate material. AI-generated material is treated in the same way where it falls within the relevant classification category. Requirements can apply to service categories that include designated internet services, including high-impact generative-AI designated internet services where covered by the relevant instrument. The precise obligation depends on the relevant code or standard, service category and risk profile.
The OAIC’s Clearview AI determination remains a leading illustration of existing privacy law being applied to AI-enabled facial recognition and large-scale scraping of images from publicly available online sources.
Government announcements about additional or broader restrictions on non-consensual sexually explicit AI-generated content, app distribution or search access should be described as policy proposals unless and until the relevant legislation or instrument is enacted and commenced. They should be kept separate from existing criminal offences, online-safety instruments and regulator enforcement powers.
High-risk AI in Australia
Australia has no generally applicable statutory classification or compliance regime for ‘high-risk AI’. The expression is currently a governance and policy concept, except where a particular sectoral law or instrument independently imposes risk-based obligations.
The September 2024 mandatory-guardrails proposals paper suggested that a future framework could consider adverse impacts on individual rights, health and safety; groups and collective or cultural rights; and the broader economy, society, environment and rule of law, together with the severity and extent of those impacts. Those proposed criteria never became binding law and the proposal is not proceeding at this time.
The current Guidance for AI adoption uses a risk-scaled approach. Its implementation guidance is directed to more complex or higher-risk uses and recommends stronger accountability, impact analysis, risk management, information sharing, testing, monitoring and human control. As a governance matter, indicators warranting enhanced controls may include significant effects on rights or access to services; impacts on vulnerable people or communities; safety-critical functions; opaque or difficult-to-contest outcomes; large-scale or systemic deployment; material cyber or data risks; and serious consequences from error, bias or model failure.
Organisations using AI in higher-impact contexts should, as a governance recommendation rather than a general statutory command, document use cases and accountabilities, conduct proportionate impact and legal assessments, test and monitor performance, manage data quality and provenance, maintain effective escalation and override processes, enable complaints and contestability, and integrate AI controls with existing privacy, cyber, consumer, safety and sectoral compliance systems.
Controls on generative AI in Australia
Australia has not enacted a generally applicable statute devoted exclusively to generative AI. Generative-AI development and use are regulated through existing laws and, where applicable, sectoral instruments including the Online Safety Act codes and standards.
Privacy and data
Developers and deployers should determine whether training, fine-tuning, retrieval-augmented generation, prompting, logging or other records where they contain personal information, or output handling involves personal information; whether collection, use and disclosure are lawful and fair; whether an APP notice or privacy-policy update is required; whether information is accurate and secure; whether cross-border disclosure rules are engaged; and whether access, correction, retention and deletion obligations apply. Public accessibility does not automatically make data lawful to collect or use for training.
Consent is not universally required for every handling of personal information under the Privacy Act. An entity should determine whether consent is required or relied upon, particularly for sensitive information or secondary uses, and whether another applicable permission or exception is available. The analysis depends on the relevant Australian Privacy Principle and the facts.
The OAIC treats personal information entered into an AI system and personal information contained in system output as potentially regulated, including inferred, inaccurate or hallucinated information about an identified or reasonably identifiable person. The OAIC recommends particular caution with sensitive information and publicly available generative-AI tools.
Cyber security and operational control
AI-specific security analysis should address access control, data leakage, prompt injection, insecure output handling, model inversion or extraction, maliciously modified or poisoned data, supply-chain compromise, model drift, logging, provenance, change control and incident response. Organisations subject to critical-infrastructure, prudential or other cyber security regimes must integrate AI controls with those binding requirements rather than treat AI governance as a standalone exercise.
AI-generated content transparency
The National AI Centre first published voluntary best-practice guidance on AI-generated content transparency, covering labelling, watermarking and metadata recording, on 28 November 2025. The current version, published on 22 April 2026, recommends proportionate disclosure methods such as labelling, watermarking and metadata or provenance measures. This is voluntary best-practice guidance, not a generally applicable statutory labelling regime. Separate binding obligations may arise under consumer, electoral, online-safety, privacy or sector-specific law depending on the content and context.
Enforcement / fines in Australia
Australia has no general, cross-economy AI Act enforcement or penalty regime. AI-specific or AI-relevant obligations may nevertheless be enforced under existing legislation and sectoral instruments. The regulator, cause of action, available remedy and maximum penalty depend on the particular provision, the conduct, the date of contravention and the defendant.
- A serious or repeated interference with privacy under the Privacy Act can attract a maximum civil penalty of AUD 2.5 million for a person other than a body corporate. For a body corporate, the maximum is the greater of AUD 50 million, three times the value of the benefit reasonably attributable to the conduct, or, if that value cannot be determined, 30% of adjusted turnover during the breach turnover period. Other Privacy Act contraventions have different consequences. The statutory tort for serious invasions of privacy also creates a private court pathway, subject to its elements, remedies, defences and exemptions.
- Competition and consumer law. AI-related representations, sales practices or product conduct may engage the Australian Consumer Law and competition law. For many offence and civil-penalty provisions, the maximum corporate penalty for conduct on or after 28 March 2026 is the greater of AUD 100 million, three times the reasonably attributable benefit where that value can be determined, or 30% of adjusted turnover during the breach turnover period where it cannot. Other provisions have lower maxima. The general prohibition on misleading or deceptive conduct under the Australian Consumer Law is not itself a pecuniary-penalty provision, although related conduct may contravene civil-penalty provisions and injunctions, damages, compensation and other remedies may be available.
- Online safety. Non-compliance with a standard, or with a direction to comply with a code, can result in civil-penalty proceedings. The maximum identified in eSafety’s regulatory guidance is 30,000 penalty units per contravention for an individual and five times that amount for a corporation. Different Online Safety Act contraventions may carry different maxima.
- Other regimes. AI uses may also attract regulatory orders, licence consequences, remediation, compensation, injunctions, enforceable undertakings, disqualification, criminal liability or judicial and merits review under financial-services, health, workplace, discrimination, cybercrime, critical-infrastructure, administrative-law and other sectoral regimes. Penalty figures should be rechecked on the publication date and should never be applied without identifying the specific contravention.
User transparency in Australia
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Fairness / unlawful bias in Australia
Australia does not have a single AI fairness statute. Unfair or biased AI outcomes can nevertheless engage Commonwealth, state or territory anti-discrimination laws, employment law, consumer protection, privacy, credit, education, health, administrative law and other sector-specific duties. The applicable protected attributes, tests, exemptions, remedies and responsible parties depend on the relevant statute and context.
The current Guidance for AI adoption addresses fairness through impact analysis, stakeholder engagement, risk management, testing, monitoring and human control. The OAIC identifies bias and discrimination risks where data are incomplete, inaccurate, unrepresentative or encode historical disadvantage. These are guidance propositions unless linked to a specific legal obligation.
As a governance matter, organisations deploying higher-impact AI should test for discriminatory or materially inaccurate outcomes before and after deployment; assess performance across relevant cohorts; document limitations; monitor complaints and drift; maintain escalation and contestability pathways; and ensure that human reviewers have the authority and information needed to correct inappropriate outcomes.
Human oversight in Australia
The sixth essential practice in the current Guidance for AI adoption is to maintain human control. The guidance recommends designing systems and operating processes so that people can supervise, intervene, escalate, override or stop AI use where appropriate to the system’s risk and impact.
Human involvement should be meaningful rather than ceremonial. Reviewers need appropriate expertise, authority, information, independence and time; they should understand relevant system limitations and avoid merely endorsing an automated result. The appropriate form of oversight may range from periodic monitoring for low-impact tools to mandatory approval, dual control, escalation or prohibition of autonomous action in higher-impact contexts.
For government decision-making, human oversight must be assessed alongside statutory authority, lawful delegation, procedural fairness, reasons, evidence, recordkeeping and review rights. For private-sector systems, the necessary controls depend on the consequences of the use case and the privacy, consumer, safety, discrimination, professional, cyber security and sectoral laws engaged. Human review does not cure an otherwise unlawful system or decision.
Transparency is a central feature of Australian responsible-AI policy, but its legal source and effect vary. The current Guidance for AI adoption recommends sharing essential information about AI systems and maintaining human control. The National AI Centre’s AI-generated content guidance recommends proportionate disclosure, labelling, watermarking and provenance measures. These recommendations are voluntary unless another law or instrument makes disclosure mandatory in the relevant context.
Under the Privacy Act, APP entities may need to explain personal-information handling through privacy policies and APP 5 collection notices and to facilitate access and correction. From 10 December 2026, the specific automated decision-making privacy-policy disclosures described in the Automated decision-making transparency under the Privacy Act section will apply to qualifying arrangements. The OAIC’s final implementation guidance should be checked before commencement.
For Commonwealth Government entities within scope, the responsible-use policy requires transparency statements, strategic and operational governance, use-case accountability, registers, training and impact assessment. Administrative law may also require lawful authority, procedural fairness, reasons and reviewability. The OAIC’s January 2026 Information Publication Scheme report recommends improved publication of operational information about automated decision-making by government agencies.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
The Brazilian AI Strategy identifies that a key issue to be addressed is that organisations and individuals that play an active role in the AI lifecycle should commit to transparency and responsible disclosure in relation to AI systems, providing relevant and state of the art information that will promote the general understanding of AI systems, making people aware of their interactions with AI systems, allowing those affected by an AI system to understand the results produced and allowing those adversely affected by an AI system to contest its outcome (para. 5 of ‘Methodology Used’, page 6, Brazilian AI Strategy).
This emphasis on transparency and public understanding has been reinforced by recent federal initiatives, including the 2026 public consultation on the Guide to the Ethical Use of Artificial Intelligence for Brazilian Citizens, launched by the Ministry of Justice and Public Security through the National Secretariat for Digital Rights (Sedigi), which seeks to improve public awareness of AI technologies and promote their safe, informed and responsible use.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
National laws specifically addressing AI have not yet passed in Canada. Bill C-34, if enacted, would require operators of regulated chatbot services to ensure that chatbots that could be mistaken for humans are clearly and prominently identified as AI systems. Operators of regulated social media services would be required to label synthetic content (including deepfakes and AI-generated material) and to label content subject to automated bot amplification.
The Voluntary Code specifies under its Transparency principle that signatories should (with varying levels of obligation, as indicated, depending on whether a signatory is either a developer or a manager of a generative AI system and if the system is available for public use or not):
- publish information on capabilities and limitations of the system;
- develop and implement a reliable and freely available method to detect content generated by the system, with a near-term focus on audio-visual content (e.g., watermarking);
- publish a description of the types of training data used to develop the system, as well as measures taken to identify and mitigate risks; and
- ensure that systems that could be mistaken for humans are clearly and prominently identified as AI systems.
Chatbot-specific obligations
Bill C-34, if enacted, would impose specific obligations on operators of ‘regulated chatbot services’. Operators would be required to implement measures adequate to mitigate the risk that users will be exposed to or communicated harmful content. Operators must also mitigate the following specifically prohibited behaviours:
- posing as a human being in circumstances likely to lead a user to mistake the chatbot for a human;
- posing as a medical, legal, or other licensed professional and providing advice;
- using manipulative engagement techniques to encourage emotional attachment, leading to social withdrawal;
- encouraging self-harm, suicide, or acts causing death or serious bodily harm; and
- other behaviours as specified in regulations.
- Additionally, if a user expresses suicidal ideation, an intention to self-harm, or an intention to cause death or serious bodily harm to another person, the chatbot service must immediately interrupt the interaction and direct the user to crisis intervention services. The bill specifies that the crisis service must connect the user to a human being who is available at the time the user is directed towards them—automated crisis responses alone will not suffice.
The Privacy Principles specify that organisations that develop, provide, or use generative AI technologies must be open and transparent about the collection, use, and disclosure of personal information and the potential risks to individuals’ privacy.
Article 4 of the Chilean AI Bill establishes the main principles applicable to AI systems. Article 4 d) states as follows:
Transparency and explainability
Transparency and explainability: AI systems shall be developed and used by providing adequate traceability and explainability, so that humans can clearly and accurately know and be aware that they are communicating or interacting with an AI system, in those cases where such knowledge would help them make decisions about their rights, safety or privacy, informing recipients, where appropriate, how the system has obtained its predictions or results, as well as the capabilities and limitations of such AI system.
Article 8 of the Chilean AI Bill establishes the rule of Transparency mechanisms (see the High-risk uses section).
Finally, Article 12 of the Chilean AI Bill establishes the following transparency obligation for Limited-Risk AI Systems: Providers and implementers shall try to ensure that these systems are designed and developed in such a way that the AI system, the provider itself or the user, intelligibly and in a timely manner informs such natural persons exposed to an AI system that they are interacting with an AI system, except in situations where this is obvious due to the circumstances and context of use. Article 12 was not amended by the Government indications. However, Article 11 reframes the limited-risk category by reference to the use of a system, and Article 32 would specify the transparency and security conditions and operator obligations applicable to AI systems whose use is classified as limited risk.
The GenAI Measures require service providers to employ effective measures to increase the transparency in generative AI services and to improve the accuracy and reliability of generated content, based on the types and characteristics of the services.
The Deep Synthesis Provisions require deep synthesis services providers to develop and disclose their management rules and platform conventions.
The Recommendation Algorithms Provisions specify that to comply businesses must formulate and disclose the relevant principles, purposes and key operation mechanisms for recommendation algorithm-based services. Users have the right to opt out of the algorithm recommendation services or request the service provider to provide services not targeting their personal characteristics. Service providers must provide users with a convenient option to switch off the algorithmic recommendation services. If users choose to switch off algorithmic recommendation services, the algorithmic recommendation service provider must immediately cease providing the services.
Under the AIGC Labelling Measures, AI-generated content shall be marked with explicit labels and/or implicit labels, depending on the functionality of the underlying AI services and how the AI-generated content can be used:
- "Explicit labels" refer to "visible indicators—such as text, audio, or graphics—added to the AI-generated content or interactive interface, which can be clearly perceived by users."
- "Implicit labels" refer to "technical markers embedded in the data of AI-generated content files, which are not easily perceived by users."
Implicit labels should be embedded in the metadata of generated content files. Explicit labels should be added to AI-generated dialogue simulating natural human interaction, synthetic voices significantly altering personal characteristics, human face images generated or altered by AI, and immersive scenes, as well as other high-risk use cases.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
Criminalization of unauthorized deepfakes in France
Please note that the French Digital Space Law criminalizes the publication of deepfakes of other persons in a way that modifies by AI their image and/or voice without their consent. An offender may face imprisonment (up to one year) and financial penalties (up to 15,000 euros). Such penalties increase when deepfakes are shared through online platforms or involve sexually explicit content.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
User transparency in France
Please note that the French Digital Space Law criminalises the publication of deepfakes of other persons in a way that modifies by AI their image and/or voice without their consent. An offender may face imprisonment (up to one year) and financial penalties (up to EUR 15,000). Such penalties increase when deepfakes are shared through online platforms or involve sexually explicit content.
Please note that the French Influencer Law imposes requirements on influencers to include warnings on images that have been modified using AI. Modified images using filters or AI must include ‘retouched images’ or ‘virtual images’ labels.
In France, the CNCDH Opinion recommends extending the EU AI Act transparency obligations in order to systematically inform people when they are exposed to or required to interact with an AI system and, when they are the subject of a decision, that this decision is based in part or in full on algorithmic processing even when undertaken by private organisations (and currently in France, this information requirement related to AI decision-making only applies with respect to public bodies).
Also, the Senate Report flags multiple transparency‑adjacent issues such as: (i) the black box / explainability issue, which underpins the difficulty of understanding model reasoning, motivating transparency and interpretability requirements in policy frameworks; and (ii) deepfake watermarking/labelling, by noting however that the increasing policy push for watermarking or equivalent measures enables users to recognise synthetic media.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
The KI-MIG does not itself impose substantive transparency obligations – these follow directly from Chapter IV of the EU AI Act – but it does add a national enforcement hook. The market surveillance authorities’ remit expressly covers the transparency obligations for providers and deployers of certain AI systems (Chapter IV of the EU AI Act) as well as the right to an explanation of individual decision-making under Article 86 of the EU AI Act. In addition, section 15(2) of the KI-MIG makes it a finable regulatory offence for a deployer of a high-risk AI system under Article 6(2) in conjunction with Annex III No. 1, 3, 4 or 5 of the EU AI Act to fail to provide an affected person with the explanation required under Article 86 of the EU AI Act, punishable by a fine of up to EUR 50,000.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
User transparency in Greece
In addition to the transparency requirements imposed directly by the AI Act and further elaborated in the European Commission’s soft-law ‘Guidelines on the transparency obligations of providers and deployers of AI systems’, the Greek AI Act Implementation Law establishes a registration obligation for AI systems in the public sector. Before deploying an AI system, public-sector bodies must register it in a centralised registry maintained by the Special Secretariat for Artificial Intelligence and Data Governance. Registration requires detailed information, including the system's purpose, public-interest objective, categories of data processed, technical characteristics and functionalities.
Laws specifically addressing AI have not yet been introduced in Hong Kong.
Transparency and Explainability is the first principle within the Ethical AI Framework, and is described as fundamental. It requires organisations to be able to explain the decision-making processes of the AI applications to humans in a clear and comprehensible manner.
The GenAI Guideline emphasises that AI systems shall fulfil transparency obligations (explainable AI), including regarding data sources and processing methods, and as regards personal data privacy (in accordance with Hong Kong's data protection law). Service Users should explicitly indicate whether generative AI has been involved in content generation or decision-making.
The transparency and interpretability ethical principle set out in the Guidance specifies that organisations should clearly and prominently disclose their use of AI and the relevant data privacy practices while striving to improve the interpretability of automated and AI-assisted decisions, and that transparency and interpretability are instrumental in demonstrating accountability as well as protecting individuals’ rights, freedom and interests in the use of AI. The Model Framework supplements this by stressing that an organisation's use of AI should be transparent to stakeholders, with the level of transparency varying depending on the stakeholder. It specifies: (i) clearly and prominently disclosing the use of AI systems (unless the use is obvious in the context/circumstances); (ii) providing adequate information on the purposes, benefits, limitations and effects of using AI systems in their products/services; and (iii) disclosing the results of risk assessment of the AI systems.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
India currently lacks legislation specific to AI. Consequently, there is no codified framework addressing user transparency within a single regulation. However, transparency is reflected as a foundational value in the India AI Governance Guidelines (through the sutras of Trust, People First and Understandable by Design) and in certain sector-specific frameworks.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
There is no horizontal AI disclosure or labelling law. However:
- The 2023 AI Policy Paper advocates transparency about AI use, proportionate to risk and context.
- The PPA’s draft guidance expects organisations to provide clear information to data subjects about automated processing, including material facts about purposes and effects where appropriate, consistent with existing privacy notice obligations.
- The Financial Sector Report establishes transparency as a core pillar of AI regulation, recommending the integration of disclosure and notification requirements into existing regulatory frameworks. It distinguishes between a basic duty to notify users of AI system use and more detailed disclosure obligations regarding the system's characteristics, limitations and implications, with requirements scaled according to the activity's risk level.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
The Social Principles state that appropriate explanations should be given in suitable cases, such as how the AI data is obtained and used. Also, to allow people to understand the proposal of the AI and make informed decisions, open dialogue may be required regarding the use, adoption and operation of AI.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
User transparency in Latvia
Law on the Artificial Intelligence Centre provides for the establishment of the Artificial Intelligence Centre. The Centre’s consist of a council with nine members (including representatives from ministries, universities, and the private sector), a director acting as the executive body is currently being sought, and a secretariat to be provided by the State Agency for Digital Development.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
User transparency in Malta
Malta’s National Framework highlights the importance of fostering transparency in AI development. The guidance document highlights that when AI systems pose significant consequences to individuals’ lives, a higher level of transparency must be upheld. Transparency about the use and impact of an AI prediction or decision is essential when the impact of such an AI prediction or decision is greater. Organisations are expected to clearly inform users about any potential limitations or risks associated with their AI systems that may adversely impact them.
Malta has not introduced specific national transparency obligations beyond those established under the EU AI Act.
Laws specifically addressing AI have not been introduced in Mauritius yet. However, the Data Protection Act 2017 provides that every controller or processor shall ensure that personal data are processed in a transparent manner in relation to any data subject.
The principles of transparency identified in the Blueprint emphasise that information will be collected once with the citizen’s consent, used responsibly, and protected with the highest privacy and security standards. Citizens will always retain transparency and control over how their personal data is used. Information will flow securely through the ‘whole-of-Government’ ensuring that forms are pre-filled with verified data to simplify user interactions.
The Blueprint further provides that the Government of Mauritius will undertake a comprehensive update of its data protection and privacy laws to strengthen trust in the digital environment. This includes:
- Updating of the Data Protection Act 2017 to be realigned with the European Union General Data Protection Regulation (GDPR).
- The enactment of regulations relating to data protection officers and e-privacy to cater for the protection of data processed through electronic communications networks;
- The Freedom of Information Act to cater for access to public information; and
- The revision of the constitutional right to privacy to cater for data protection and freedom of information.
Laws specifically addressing AI have not been introduced in Mexico yet.
Laws specifically addressing AI have not been introduced in Morocco yet, so there are no specific AI transparency requirements.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Laws specifically addressing AI have not been introduced in New Zealand yet, so there are no specific AI transparency requirements. However, the OPC AI Guidance highlights the importance of transparency when using AI tools in order to mitigate the risk of breaching Information Privacy Principle 3 of the Privacy Act. The AI Guidance for Business provides a transparency checklist for businesses to disclose their AI use. Additionally, the Privacy Amendment Act 2025 introduced Information Privacy Principle 3A (IPP 3A), which came into effect on 1 May 2026 and requires agencies that collect personal information indirectly (i.e., from a source other than the individual concerned) to inform the individual of that collection, unless an exception applies. While not AI-specific, IPP 3A enhances transparency obligations relevant to AI systems that collect or process personal information from third-party sources.
A standalone AI law has not yet been enacted in Nigeria, so there are no AI-specific statutory transparency requirements. The Internet Code of Practice, 2026 includes general obligations regarding transparency in the deployment of AI-enabled services by NCC licensees.
The content on User transparency in the European Union applies in Norway.
The AI Regulation expressly establishes user transparency requirements for high-risk AI systems. Developers and/or implementers must provide users with prior, clear and simple information on the purpose, main functionalities and types of decisions that the AI system may make.
Where relevant, transparency mechanisms may include visible labelling to inform users that a product, service or generated content operates on the basis of AI. Where an AI system makes decisions that impact human rights, affected users must be provided with an explanation of the results in accessible language.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
The PDPL establishes general transparency obligations for personal data processing, including clear notice to data subjects regarding purposes of processing and disclosures, and data subject rights mechanisms, including deletion requests.
SDAIA guidance further recommends implementing mechanisms to ensure explainability of decisions and user notification when generative AI is used.
Laws specifically addressing AI have not yet been introduced in Singapore.
Explainability and transparency constitute one of the guiding principles in the Model Framework. It suggests specific practices such as:
- providing general information on whether AI is used in products and/or services;
- disclosing the manner in which an AI decision may affect an individual consumer; and
- considering the information needs of consumers as they go through the journey of interacting with AI.
The AI Guidelines state that, where an AI system is deployed to provide recommendations, predictions or decisions based on personal data, the organisation must comply with the consent and notification obligations under the PDPA, unless exceptions apply.
The Transparency Guidelines for Generative AI Chatbots set out how generative AI chatbot deployers can provide meaningful transparency to consumers.
The Principles recommend providing explanations regarding:
- what data is used to make AI / data analytics-driven decisions;
- how the data affects such decisions; and
- the potential consequences of such decisions.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
User transparency in the Slovak Republic
The draft law reinforces transparency obligations by incorporating and enforcing the transparency requirements contained in the EU AI Act. Regulatory authorities are empowered to oversee compliance with these obligations and investigate complaints from affected individuals.
Furthermore, the draft law introduces a specific obligation in the Slovak Data Protection Act requiring deployers of certain high-risk AI systems to inform individuals that they are subject to the use of such systems where the EU AI Act so requires.
Transparency is promoted through publication requirements. Decisions adopted by the Office for Digital Integrity under the draft law should be published on the authority's website, thereby increasing public visibility regarding enforcement activities and regulatory expectations.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Laws specifically addressing AI have not been introduced in South Africa, so there are no AI-specific transparency requirements.
Certain notification, labelling and/or explanation obligations are required for high-impact AI and generative AI, as discussed in the High-Risk Uses and Controls on Generative AI sections.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
Article 50 of the EU AI Act sets out transparency obligations for providers and deployers of certain AI systems, including the following:
- Providers of AI systems must ensure that natural persons using an AI system must be informed that they are interacting with an AI system unless this is obvious to the natural person (this obligation excludes AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences).
- Providers of AI systems must ensure that the synthetic outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated (excluding AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences) and must process data in accordance with other relevant EU laws.
- Deployers of emotion recognition or biometric categorisation systems must inform the affected natural persons.
- Deployers of AI systems that generate or manipulate image, audio or video content constituting deep fakes must disclose that the content has been artificially generated or manipulated.
At present, the Draft AI Law Principles (2025) and the Generative AI Guideline (2024) do not expressly impose user transparency obligations.
Laws specifically addressing AI have not been enacted in Türkiye yet. On the other hand, novel amendments made to the Advertising Regulation require advertisements to clearly, understandably and distinguishably disclose the use of AI or other software where this may materially influence consumers’ economic behaviour, or where AI-generated digital characters that are indistinguishable from real persons are used.
Moreover, NAIS sets out an ‘AI Principle’ of ‘Transparency and Explainability’, as follows (page 61 of NAIS):
“Person(s) and organizations involved in the lifecycle of AI systems should ensure that the AI system is transparent and explainable in accordance with its context. People have the right to be informed of a decision that was made based on AI algorithms and to request explanatory information from public institutions and private sector organizations in such cases. It should be possible to explain to the end user and other stakeholders in non-technical terms and in plain language, why, how, where and for what purpose the decisions made based on automatic and algorithmic decisions, the data leading to said decisions and the information obtained from that data are used.”
There is no unified federal law or emirate level law in the UAE that has a primary focus on regulating AI (and therefore no binding obligations in relation to user transparency).
However, the AI Ethics Guide contains a principle of transparency which provides that:
- Developers should build systems whose failures can be traced and diagnosed.
- People should be told when significant decisions about them are being made by AI.
- Within the limits of privacy and the preservation of intellectual property, those who deploy AI Systems should be transparent about the data and algorithms they use.
- Responsible disclosures should be provided in a timely manner and provide reasonable justifications for AI Systems outcomes. This includes information that helps people understand outcomes, like key factors used in decision making.
The DIFC’s Data Protection Regulations also provide that AI Systems must be designed in accordance with the principle of transparency. In particular, AI Systems must ensure that processing of personal data is explainable to data subjects and other stakeholders in non-technical terms, with appropriate supporting evidence. There are also specific notice, evidence and information requirements imposed on Deployers or Operators in relation to applications and website services that employ AI Systems to process personal data.
The principle of appropriate transparency and explainability identified in the White Paper specifies that AI systems should be appropriately transparent and explainable, on the basis that transparency can increase public trust, which can be a significant driver of AI adoption. Separately, existing principles under e.g. the Data Protection Act 2018 and UK GDPR should be considered.
In the context of AI, transparency may involve different types of disclosures, such as the use of a machine learning tool to make consequential decisions about consumers or the use of a chatbot to interact with consumers. The US does not currently have a federal law that specifically mandates transparency in AI systems. Some laws of general applicability, like broad consumer protection laws, may require disclosures about AI to avoid consumer deception. On the state and local level, however, a patchwork of laws has developed requiring transparency in different situations. For example:
- California’s Generative AI: Training Data Transparency Act mandates disclosure of high-level details about the training data used in generative AI systems
- California’s TFAIA requires large ‘frontier’ AI developers to publish transparency reports and annually update a public frontier AI safety framework describing how they assess and mitigate ‘catastrophic risk’, secure unreleased model weights, and respond to critical safety incidents
- Utah’s AI Policy Act mandates verbal or written disclosure when consumers interact with generative AI in regulated service contexts
- New York’s RAISE Act requires large developers to implement and publicly disclose a ‘safety and security protocol’ and report any ‘safety incident’ to mitigate risk
- New York City’s Local Law 144 requires employers to notify candidates when automated employment decision tools are used, and to publish the results of bias audits
These efforts may reflect a growing consensus that transparency is key to responsible AI deployment, particularly in applications such as employment, healthcare, and consumer services. However, the scope and enforcement of transparency obligations vary significantly across jurisdictions, contributing to a fragmented compliance landscape.