Key takeaways
- From 2 August 2026, parts of the EU AI Act will require people to be told when they are interacting with certain AI systems or viewing particular forms of AI-generated content.
- New Zealand firms can be affected where they provide AI-enabled services into Europe, publish content for European audiences, or supply systems whose outputs are used in the EU.
- Even where the EU rules do not directly apply, they provide a useful governance model: identify AI-generated content, assign editorial responsibility and retain evidence of meaningful human review.
On 20 July 2026, the European Commission published detailed guidance on the transparency obligations in Article 50 of the EU AI Act. The rules begin applying on 2 August 2026 and address a deceptively simple question: when should people be told that artificial intelligence is involved?
The answer matters well beyond technology companies. Law firms, accounting practices, consultancies, financial advisers, marketing agencies and other professional services firms are increasingly using AI to prepare reports, answer client questions, create imagery, produce thought leadership and operate customer-facing assistants.
The Commission’s guidance turns transparency from a general ethical principle into a more practical set of requirements covering chatbots, AI agents, synthetic media, deepfakes, public-interest material and biometric technologies.
The rules distinguish between providers and deployers
A central part of the guidance is the distinction between an AI provider and a deployer.
A provider develops an AI system, has one developed, or places it on the market under its own name or brand. A New Zealand company could therefore become a provider if it develops a client-facing AI assistant or packages a third-party model into its own branded product.
A deployer is an organisation using an AI system under its authority for professional purposes. In most cases, a professional services firm using an AI platform internally or in delivering services would be a deployer rather than a provider.
The organisation remains the deployer where staff, contractors or freelancers operate the system on its behalf. Responsibility does not automatically transfer to the individual who typed the prompt or produced the content.
This is a useful governance lesson in its own right. Organisations should not treat AI use as a collection of isolated staff decisions. There needs to be an accountable entity, a clear owner and an agreed process for deciding how the system may be used.
When people must be told they are dealing with AI
Providers of systems that interact directly with people, including certain chatbots, AI agents and digital avatars, must design them so users are informed that they are interacting with AI unless this is already obvious.
The notification should be clear from the start of the first interaction. The Commission says the exception for situations where AI involvement is “obvious” should be interpreted narrowly.
For a New Zealand firm, this could affect:
- a website chatbot that answers prospective client questions;
- an AI agent that collects information before a consultation;
- an automated client-support assistant;
- a branded digital adviser built on a third-party model; or
- an avatar used to deliver professional or educational content.
A small disclaimer buried in terms and conditions is unlikely to achieve the purpose of the rule. The disclosure should appear where the interaction occurs and early enough for the user to understand what they are engaging with.
AI-generated content may need technical marking or visible labels
The obligations operate at two different levels.
Providers of generative AI systems must generally make synthetic text, audio, images and video detectable through effective machine-readable marking. Some exceptions apply, including certain standard editing activities and limited business-to-business or industrial uses.
Deployers face a different obligation. They may need to provide a label that an ordinary person can see or hear, particularly for:
- deepfake images, audio or video;
- AI-generated text about matters of public interest that has not received meaningful human review;
- emotion-recognition systems; and
- biometric categorisation systems.
A machine-readable mark embedded by the software provider does not necessarily replace the deployer’s visible disclosure obligation. The audience may still need to be clearly told what they are seeing or hearing.
The Commission defines deepfakes broadly enough to include manipulated content resembling existing people, places, objects, organisations or events where the result could falsely appear authentic.
That means governance should not be limited to fake videos of public figures. A synthetic client testimonial, fabricated news interview, altered photograph of an actual incident or AI-generated recording imitating a real executive could all raise transparency concerns.
Human review must be substantive
One of the most important parts of the guidance concerns AI-generated text on matters of public interest.
The rules may require clear labelling where AI-generated or manipulated text is published to inform the public about matters such as politics, public administration, justice, public safety, health, financial developments, science or consumer safety.
There is an exemption where the content has undergone human review or editorial control and a person or organisation accepts editorial responsibility. But the Commission makes clear that superficial checking is not enough.
Spell-checking, formatting or correcting grammar does not amount to meaningful human review. The reviewer must examine the substance, apply relevant knowledge and professional judgement, verify sources where appropriate, and have authority to approve, change or reject the material.
For professional services firms, this distinction is critical. A lawyer glancing over an AI-generated client alert is not the same as validating its legal analysis. A consultant correcting the tone of an AI-written report is not necessarily checking its evidence. A director approving a post without reviewing the underlying sources may not provide effective editorial control.
The governance question is therefore not simply, “Was a human involved?” It is, “What did that human actually check, and can the organisation demonstrate it?”
Does the EU AI Act apply to a New Zealand business?
The Act can reach providers established outside Europe where their systems are placed on the EU market or their outputs are used in the EU. A New Zealand firm should assess its position carefully where it:
- supplies an AI-enabled service to European clients;
- operates a system used by staff, customers or contractors in the EU;
- provides a branded AI tool internationally;
- publishes AI-generated public-interest content aimed at European audiences; or
- forms part of an international delivery or technology supply chain.
The transparency requirements begin on 2 August 2026. A limited grace period applies to the machine-readable marking obligation for some systems placed on the market before that date, but most organisations should not assume there is a general transition period. The Commission states that fines can reach €15 million or 3 per cent of total worldwide turnover for the preceding financial year, with proportionality taken into account for small and medium-sized enterprises and small mid-cap companies. (Digital Strategy)
Legal advice may be required to determine whether a particular New Zealand organisation is directly within scope.
Why this matters in New Zealand even without direct EU exposure
New Zealand does not currently have an equivalent general AI labelling law. However, existing law still applies to AI use.
The Fair Trading Act can apply where the presentation of AI-generated material is misleading or deceptive. The Privacy Act 2020 applies where AI tools collect, infer, alter or disclose personal information. Professional duties, confidentiality obligations, intellectual property rules and sector-specific standards may also be relevant.
MBIE’s Responsible AI Guidance encourages businesses to use governance, transparency and explainability to demonstrate responsible AI use. The Office of the Privacy Commissioner has similarly stressed the importance of transparency, privacy risk assessment and safeguards when organisations adopt AI systems. (MBIE)
The EU guidance therefore offers a useful operational benchmark. It shows what a mature transparency regime looks like and what overseas clients may increasingly expect from their New Zealand advisers and suppliers.
What this means for your organisation
Professional services firms should take six practical steps:
- Inventory customer-facing AI. Identify chatbots, agents, avatars, automated intake tools and AI-generated content processes.
- Separate provider and deployer responsibilities. Record whether your organisation built or branded the system, merely uses it, or performs both roles.
- Create a labelling standard. Decide when AI interactions, synthetic media and materially AI-generated content must be visibly disclosed.
- Define meaningful human review. Specify what reviewers must verify, including facts, sources, professional analysis, confidentiality and potential harm.
- Record editorial responsibility. Assign a named person or role with authority to approve, amend or reject AI-assisted public content.
- Check international exposure. Review where users, clients and affected audiences are located, rather than relying only on the location of your New Zealand office.
AI transparency is moving away from broad statements of principle and towards evidence-based operating controls. Organisations that can explain where AI was used, how people were informed and who reviewed the result will be better placed to meet regulatory, client and professional expectations.
Source note
This article is based primarily on the European Commission’s Guidelines on transparency obligations for providers and deployers of AI systems, published on 20 July 2026, together with its Article 50 questions and answers and transparency fact page. (Digital Strategy)
New Zealand context was drawn from MBIE’s Responsible Artificial Intelligence Guidance for Businesses and guidance from the Office of the Privacy Commissioner. (MBIE)
This article provides general information and commentary. It is not legal advice. Organisations should obtain advice about their particular activities, markets and obligations.
Related reading
- Who’s in charge of your AI? Governance and accountability under New Zealand’s Responsible AI Guidance
- The AI Shift in Cyber Risk: What the Five Eyes Call to Action Means for Your Organisation

