Yesterday, "We Use AI" Stopped Being a Confession and Became a Filing Requirement
The EU's AI transparency rules landed on 2 August, and Legal can't fix this one. You can't disclose what nobody's written down. Here's the one-page tool that actually works.
The EU's transparency obligations went live on 2 August 2026. Most companies will hand this to Legal — and Legal cannot solve it, because you cannot disclose what nobody has bothered to write down.
The jumper that wasn't there
A shopper looking at a knitted jumper on J.Crew's website noticed something slightly wrong about the model's hand. Then the shadow. Then the way the fabric fell across the shoulder.
The photograph had been generated. There was no label saying so.
What followed was instructive, and not in the way most people assume. The backlash was not really about the technology. A good proportion of the customers doing the complaining use AI at work every day and think nothing of it. The offence was taken at the silence — the sense that a decision had been made on their behalf and quietly not mentioned.
Coca-Cola had already learned the same lesson with its generative holiday advertisement. The criticism was not this is AI; it was you thought we wouldn't notice, and you were nearly right.
Hold on to that distinction, because it is now the entire commercial question. The market has spent two years arguing about whether AI is good or bad for business. It has quietly moved on to a far narrower question — one that has a yes-or-no answer, that a regulator can test, and that you can measurably fail:
Did you say so?
What actually changed on 2 August
On 2 August 2026, the transparency obligations of the EU AI Act — Article 50 — became enforceable. Stated plainly, they require three things:
- Interaction disclosure. If a person is interacting with an AI system rather than a human, they must be informed.
- Synthetic content marking. AI-generated or manipulated content must be marked in a machine-readable format.
- Deepfake labelling. Manipulated likenesses and synthetic media presented as real must be visibly labelled.
Two details are being lost in the commentary, and both are the ones that will cost people money.
It is not the high-risk regime, and that is why it caught people out
The obligations everyone had been budgeting for — the full high-risk compliance apparatus — were deferred. Standalone Annex III systems now have until 2 December 2027; AI embedded in regulated products under Annex I has until August 2028. The EU deferred that timeline because national authorities and harmonised technical standards were not ready, not because it changed its mind about the requirements.
A great many businesses read the delay headline in July, felt a wave of relief, and stopped reading. The delay applies to the part that didn't land yesterday. The part that did land, landed yesterday — and it is the part with the widest reach.
It attaches to the situation, not the sector
Article 50 is not a technology-industry rule. It applies wherever the specified situations occur, which means it lands on businesses that do not think of themselves as AI companies at all:
- A clinic running a patient-facing chatbot for triage or appointment scheduling.
- A fashion label or homeware brand generating campaign and product imagery.
- A logistics operator whose customer service line answers with a synthesised voice.
- A financial services firm whose first-line support is an AI assistant.
- A professional services practice whose “personalised” outreach emails are drafted at scale.
In practice, Article 50 is relevant to almost every business using generative AI to produce content or to talk to customers. And it is not the only instrument moving in this direction — New York's AI disclosure law, the first of its kind in the United States, took effect in June 2026. The regulatory direction of travel is settled even where the detail is not.
The commercial case is stronger than the legal one
If compliance were the only argument, my advice would be to do the minimum competently and get back to work. It isn't the only argument, and this is the part I'd want a board to sit with.
The consumer research has been pointing the same way for a year. Roughly 33% of consumers say that a brand's use of AI worsens their perception of it, against about 16% who say it improves it. Read alone, that looks like a compelling argument for keeping quiet.
Then read the next finding: around 90% of consumers want brands to disclose their use of AI.
Those two numbers are only contradictory if you assume the objection is to the technology. It isn't. People are not asking you to stop using AI — they have largely accepted that you will. They are asking not to be deceived by it. In every well-documented backlash of the past eighteen months, the damage came from the concealment rather than from the tool.
Which produces an unusual and useful situation: the regulator and the customer are now asking for the same thing, for entirely different reasons. Those moments are rare enough that they deserve to be acted on rather than admired.
Why this is an operations problem, not a legal one
Here is where I expect most organisations to go wrong over the next quarter.
Transparency will be handed to Legal, or to whoever holds the compliance folder. A policy will be produced. It will state, accurately, that the company discloses its use of AI where required by applicable law. It will be reviewed, approved, circulated and filed.
And it will be worth almost nothing — because it answers a question nobody was actually asking.
The hard question is not should we disclose? The hard question is:
Where, precisely, does AI touch a customer in this business?
Almost no organisation can answer that on demand. I have watched companies in three different sectors attempt it, and they surface the same three findings every time.
One: marketing has been generating for eighteen months and logging nothing. Imagery, product descriptions, campaign copy, social variants. No record of which assets, which tool, which version, which prompt. The work is out in the world and unattributable.
Two: there is an AI layer in customer service that the board did not know was live. This is the one that consistently shocks people. It rarely arrives as a procurement decision. It arrives as a feature update inside a helpdesk or CRM product that was switched on by default, configured by someone junior, and never escalated — because nobody thought of it as buying AI.
Three: once you start counting, the volume of AI-touched output is a rounding error away from “everything.”
None of that is a legal problem. It is a visibility problem — the same one that sits underneath almost every failed improvement programme I have ever been called into. You cannot disclose what you have not inventoried, you cannot govern what you cannot see, and you cannot improve what nobody owns.
The uncomfortable framing, which I'd offer to any executive team: if you cannot produce that inventory within the month, you do not have a compliance gap. You have a management-visibility gap — and disclosure is simply the first outside party to ask about it. It will not be the last.
The Disclosure Ledger
This is the tool I use, and its virtue is that it is small enough to actually get built. One table. Most SMEs can complete a serviceable first version in a day; a mid-sized group needs perhaps a fortnight and one determined owner.
One row per customer-facing touchpoint. Four columns.
01
Touchpoint. Where AI meets a human being. Be granular and be exhaustive: the live chat window, the phone line, the email auto-reply, the product photograph, the campaign copy, the recommendation engine, the application screening step, the appointment triage flow, the “personalised” onboarding sequence. Include anything that arrived as a vendor feature update — that is where the surprises are.
02
What the customer would assume. If you said nothing at all, what would a reasonable, non-technical person believe was happening here? Answer honestly rather than defensively. Most people still assume that a photograph of a product is a photograph of that product; that a named individual signing an email wrote it; that a voice on a phone belongs to a person. Those assumptions are shifting, but not as fast as your industry press implies.
03
The gap. The distance between column 2 and reality. This gap is your entire risk surface — legal and reputational alike. Where there is no gap, there is nothing to disclose: nobody has ever felt betrayed to learn that their spam filter is automated. Where the gap is wide — the customer assumes a human and there is none, assumes a photograph and there was no camera — you act, and you act first.
04
The tell. The disclosure itself, in the customer's language, at the moment of contact. Not in the footer. Not on page fourteen of the terms of service. Not in a cookie-style banner everyone has been trained to dismiss. If the disclosure requires the customer to go looking, it is decoration.
Then: sort by column 3, work top-down, and stop when the remaining gaps are trivial.
That is the whole method. It is deliberately unimpressive. It will also get you further in a week than a policy document will in a quarter, because it produces the one artefact the policy assumes already exists.
Three tests before you sign anything off
Once the ledger exists, run each significant row through three tests.
1. The screenshot test
If a customer screenshotted this touchpoint and posted it with the caption “did you know…”, would it hurt?
J.Crew failed this test. So did Coca-Cola. It costs nothing to run, it requires no legal expertise, and in my experience it predicts real-world outcomes considerably better than a formal review does — because it tests the thing that actually causes damage, which is the sensation of having been quietly handled.
Run it with someone who does not work in marketing. Marketing has been swimming in this for two years and has lost the ability to be surprised.
2. The handover test
Can the customer reach a human being in one move?
Disclosure without an exit is a taunt. Telling someone they are speaking to a bot while trapping them in a loop is worse than saying nothing at all — it is a confession with no remedy attached, and it converts a neutral experience into a grievance.
This is also, quietly, where the upside lives. One large bank made its AI service layer explicit and enforced consistent disclosure and compliance behaviour across both automated and human responses; satisfaction scores in the pilot rose by around 12%. Disclosed properly, with a visible route to a person, AI service reads as confidence rather than cost-cutting. The customers who wanted a human get one faster. The customers who just wanted an answer at 11pm get that too.
3. The provenance test
Six months from now, can you demonstrate what was generated, by which system, on what date, and who approved it?
This is the test everybody skips, and it is the only one that matters if a disclosure is ever contested — by a regulator, a customer, a journalist or a court.
It is also the test with the largest strategic dividend, and this is the connection almost nobody is making. Provenance logging is the same infrastructure that makes AI output measurable. Roughly 80% of the work involved in moving AI from pilot to production is data engineering, governance, workflow integration and measurement — not modelling. Fewer than 20% of AI pilots reach enterprise-scale production, MIT has found that about 95% deliver no measurable P&L impact, and yet firms that do reach production report average returns around 1.7x, with cost savings of 26–31% in functions like supply chain, finance and people operations.
The difference between those two populations is not model quality. It is whether the organisation knows what it is running.
Provenance is that discipline, arriving with a legal deadline attached. If you were struggling to fund the governance work on its own merits, Article 50 has just written your business case for you.
Don't over-label
One warning, because the pendulum always swings too far.
Do not staple a disclaimer to every keystroke. If your invoice reminders, your rota, your stock forecast and your internal meeting notes all announce themselves as AI-assisted, customers will stop reading disclosures altogether — and the one that genuinely mattered will be ignored along with the rest. Disclosure fatigue is a real cost, and it is self-inflicted.
Label the deception surface: the places where a reasonable person would assume a human and there isn't one, or would assume a photograph and there wasn't a camera. Everything else is noise dressed up as virtue, and it dilutes the signal you actually need people to receive.
The healthcare operators I have seen handle this best label the patient-facing conversation clearly and say nothing at all about the scheduling engine behind it. That is exactly the right instinct. The patient cares a great deal about who is answering their question about a symptom. No patient in history has felt betrayed to discover that an algorithm proposed Tuesday at 2pm.
The same logic scales across sectors. A fitness studio should disclose that its “coach check-in” message was generated; it does not need to disclose that its class capacity was forecast. A finance team should disclose an AI-drafted client communication; it does not need to announce that the reconciliation ran on rules. Disclose where trust is transferred, not where work is done.
What I would do this week
The temptation will be to convene a working group. Resist it. This is a week of work for one determined person with the authority to ask awkward questions.
- Monday — build the ledger. One page. Every customer-facing touchpoint, no exceptions. Specifically ask each function whether any AI capability arrived as part of a software update rather than a purchase; that question surfaces roughly half of what is missing.
- Tuesday — sort by gap. Anything where a customer would assume a human and finds a machine, or assumes a photograph and finds a render, goes to the top. Everything below the trivial line gets left alone deliberately — and you write down that it was deliberate.
- Wednesday — write the tells. Plain language, at the point of contact, with a route to a person. Have someone outside marketing read them.
- Thursday — turn on provenance logging. What was generated, by which system, when, approved by whom. Imperfect logging that starts on Thursday beats perfect logging that starts next quarter.
- Friday — run the screenshot test on your top five rows, with someone who has no stake in the answer.
By the following Monday you will have something most of your competitors will not have until Christmas: a defensible, evidenced account of where AI touches your customers. The organisations that treat this as a twelve-month compliance programme will spend considerably more and arrive with considerably less.
The point
Article 50 does not ask whether your model is any good. It asks whether you can state, plainly and at the moment of contact, where AI touched the customer — and prove it afterwards.
That is not a legal capability. It is an operational one. And it happens to be precisely the capability that separates the small minority of AI projects that reach production from the large majority that quietly die in pilot: knowing what you actually run, who owns it, and how you would evidence it if asked.
The regulation is simply the first time somebody outside your business has asked you to prove it.
It will not be the last — and the answer you can give this month is a reasonable proxy for how well you are running the place.
I'm Jade Elliott, founder of Anchor Lotus Consulting. I help companies of every kind turn messy operations into systems that scale — and turn AI from a pilot into something that actually runs in the business, can be measured, and can be defended. Eight years of unglamorous operational work sits underneath that: data quality, process redesign, cost visibility, reporting, adoption and change management. If your organisation cannot currently produce a one-page ledger of where AI touches your customers, that is the place to start — and it is a far better conversation to have now than after somebody else asks for it.


