The European Union and Australia have introduced new transparency obligations that will impact many New Zealand businesses that use AI tools, chatbots and automated decision-making systems.
EU AI transparency: What the new rules mean for business
Your chatbot could pose EU compliance issues starting next week. If your AI system is made available to users in Europe, the EU’s new transparency rules apply. From 2 August 2026, Article 50 of the EU Artificial Intelligence Law (AI Law) will require those building or using AI to tell people when they are interacting with the AI and to label content generated by the AI.
AI law is extraterritorial. This applies regardless of where the company is established or where its systems operate, as long as the system is available to EU users or its output is used within the EU.
Does EU AI law apply to my business?
Yes, if you develop, provide, or deploy AI systems (including chatbots, virtual assistants, or generative AI tools) that you provide to EU users, or if you use your AI systems to provide AI-enabled services to consumers or businesses in the EU. The same entity can be both a “provider” (an entity that builds an AI product and brings it to market) and a “deployer” (an entity that uses existing AI tools under its own authority in its professional activities). This distinction is important because Article 50 assigns different duties to each role.
four duties
Article 50 imposes four transparency obligations on providers and deployers.
- Tell people that you are talking to an AI (Article 50(1))
Providers of AI systems designed to interact directly with people must develop and design their AI systems in a way that lets users know they are interacting with an AI. This includes chatbots, virtual assistants, automated phone systems, and AI agents. An exception applies where the nature of the AI is obvious to a well-informed, observant, and prudent person. On 8 May 2026, the European Commission published draft guidelines on the implementation of Article 50 (Draft Guidelines). do not have Covers general-purpose chatbots and AI helpdesk tools. - Marking AI-generated content as machine-readable (Article 50(2))
Providers of generative AI systems (including large-scale language models) that produce synthetic speech, images, video, or text must mark their output to indicate that it was produced or manipulated by the AI system. Providers of these systems are required to provide markings in a machine-readable format wherever technically possible. Markings must be effective, interoperable, robust and reliable. Technical feasibility is evaluated objectively.
This obligation does not apply if the AI only performs standard editing auxiliary functions (such as grammar correction) or does not materially change the input data or its meaning. The draft guidelines interpret this carve-out narrowly. For example, summarizing or translating AI-generated text, removing objects from images, or adjusting color or contrast are not exempt. For generative AI systems already placed on the EU market before 2 August 2026, the AI Omnibus Interim Agreement of May 2026 allows providers until 2 December 2026 to meet machine-readable marking requirements. - Disclosure of emotion recognition and biometric classification (Article 50(3))
Deployers of AI systems that identify or infer emotions or use biometric data to classify individuals must notify all individuals exposed to the system that the system is in use. This includes, for example, systems that infer emotions from facial expressions or tone of voice, or assign individuals to categories such as age, gender, or ethnicity. - Deepfakes and AI-generated labeling public interest sentence (Article 50, Paragraph 4)
Adopters who create deepfakes (AI-generated or manipulated content that resembles existing people, objects, places, or events to appear authentic) must disclose that the content is human-generated or manipulated. For deepfakes used in artistic, creative, satirical, fictional, or similar works, the obligation is limited to disclosures that do not interfere with the display or enjoyment of the work.
Adopters who publish AI-generated or AI-manipulated text to inform the public about matters of public interest must also disclose the source of that AI. A carve-out applies when the text is subject to true human editorial review with substantive editorial oversight, rather than simply reading or approving the text, and the person or organization assumes editorial responsibility for publication. The draft guidelines state that pre-publication spell checking and superficial grammar reviews do not constitute true human review.
In all cases, the disclosure must be clear and distinguishable and provided at the latest at the time of the first interaction or disclosure. Disclosures buried in terms of use or footnotes will not be honored. AI systems that are authorized by law to detect, prevent, investigate, or prosecute criminal offenses are exempt from the transparency obligations described above.
Code of Practice: Compliance Benchmark
On 10 June 2026, the European Commission (Commission) published the final Code of Practice on Transparency of Content Generated by AI (the Code). This Code does not create any legal binding beyond the provisions of the AI Act itself. Learn how providers should mark AI-generated content and how deployers should label deepfakes. The Code and the draft guidelines are complementary. While the draft guidelines address the full scope of Article 50 and provide the Commission’s interpretive guidance on its scope and application, the Code focuses in particular on the technical and organizational implementation of Articles 50(2) and 50(4).
Signatories to the Code will enjoy greater confidence from regulators, who will assess compliance against the Code’s standards. Non-signatories must independently demonstrate that they meet Article 50, including through a gap analysis with the Code. In practice, therefore, the Code serves as a compliance benchmark for marking and labeling obligations.
The Code’s key recommendations for providers are:
- It uses a multi-layered approach that combines digitally signed metadata and imperceptible watermarks to mark output and recommend provenance information. Markings must be effective, reliable, robust and interoperable.
- Make detection tools and services freely available to help users verify whether content is AI-generated or manipulated. Findings should be clear, easy to understand, and easy to access.
- Avoid deleting existing transparent marks to prevent tampering by others. Don’t promote tools designed to circumvent machine-readable marks.
- Test, monitor, document and regularly review marking and detection systems. Work with market surveillance authorities to demonstrate compliance.
The code’s key recommendations for implementers are:
- If you publish public deepfakes or AI-generated text, please use the public EU “AI” icon (or equivalent label). Separate icons distinguish content that is completely AI-generated from content that has been manipulated (partially modified) by AI.
- For images, the label must be permanently visible. For videos, labels must appear at the beginning and at regular intervals (at least after interruptions such as ad breaks). For audio-only content, we recommend including an audio disclaimer at the beginning.
- Implement internal processes, training, and review mechanisms to ensure content is labeled correctly. Maintain a channel for users or third parties to report missing or inaccurate labels and quickly fix issues.
Australia: More familiar transparency obligations for automated decision-making
The EU is not the only jurisdiction to tighten transparency rules for technology use.
From 10 December 2026, Australia’s Privacy Act 1988 (Cth) (Australian Privacy Act) will require organizations and institutions bound by the Australian Privacy Principles to disclose in their privacy policies how they use automated decision making (ADM) that could reasonably be expected to have a material impact on the rights or interests of individuals. This obligation takes effect through new APPs 1.7, 1.8, and 1.9.
Australian privacy laws apply to all entities “carrying on business in Australia”. New Zealand companies selling products or services to Australian customers can be exposed, regardless of where the company is established or where its systems are hosted.
Do Australian obligations apply to my business?
This obligation is triggered when an organization (subject to Australian privacy laws) arranges for a computer program to use an individual’s personal information to make a decision, or to do something substantially and directly related to a decision, that is reasonably expected to have a material impact on the rights or interests of the individual. “Computer program” is intended to be interpreted broadly. It also covers machine learning, generative AI tools, and simple rule-based algorithms.
Importantly, the company that “arranged” the ADM is required to disclose. This is not necessarily the entity that builds or operates the technology. If an Australian customer purchases an ADM tool for its own decision-making purposes, that customer may be a disclosing party. If you commercially deploy your own ADM tools in Australia, you will be directly responsible for them.
What do I need to disclose?
Organizations subject to Australian privacy laws must update their privacy policies to include:
- Types of personal information used in the operation of the ADM system.
- Types of decisions made solely by the action of a computer program (e.g., fully automated credit scoring or denial of service). and
- Types of decisions in which a computer program plays a substantial or direct role (for example, an AI system shortlists job applicants before a human makes the final selection).
Disclosures must be clearly expressed and up to date. General boilerplate or overly technical explanations may not meet your obligations.
What should I do now?
Both regimes determine how trading partners assess AI governance and supplier risk. New Zealand businesses that embed transparency compliance into their products and workflows are better positioned as global AI regulation evolves.
- Consider your exposure: Assess whether your AI system can reach users in Europe. In that case, Article 50 of the AI Act will be triggered from August 2, 2026. Assess whether to continue operating in Australia and trigger ADM transparency obligations from 10 December 2026.
- Audit your AI systems. Identify systems that use personal information to make decisions that significantly impact individuals. Australia’s definition of a “computer program” is broad and may include tools that would not normally be considered AI. For the EU, decide whether the system interacts directly with people, generates synthetic content, or generates deepfakes. Each has different Article 50 obligations.
- Prepare the contract flow: It is expected that customers in both jurisdictions will contractually require compliance with transparency.
- Update your disclosures now. If you’re running a customer-facing chatbot, virtual assistant, or AI content tool, make sure to visually signal to users that they’re interacting with an AI. For AI-generated content, implement a labeling process by the August 2, 2026 deadline. For Australia, if your tool includes ADM, please review your privacy policy to ensure it supports ADM before December 10, 2026.
If you have any questions about how the AI Act or Australia’s new privacy law obligations apply to your business, or would like to discuss your compliance approach, please contact one of our experts. We will introduce you to the right person.
This article was co-authored by Daniel Rayner, a lawyer in our corporate and commercial team.
