SkarpSkarp

Chapter 17 of 25

Transparency and General-Purpose AI Obligations

The Act regulates what people must be told and what downstream developers must receive. Article 50’s public-facing disclosures sit alongside the classification, documentation, copyright and systemic-risk duties imposed on general-purpose AI model providers.

27 min readen

Map of the Chapter: Who Owes What?

The compliance map

Article 50 concerns transparency to people. Articles 51 to 56 concern general-purpose AI models, their providers, systemic risk, and codes of practice.

Provider and deployer

Providers design, develop, document, and supply information. Deployers operate systems in a use context and owe several exposure and content disclosures.

Read conditions exactly

Shall is mandatory; may is discretionary. Exceptions and qualifiers such as "unless", "where", and "to the extent" define the duty's actual scope.

Article 50(1)-(3): Interaction, Synthetic Outputs, and Exposure

Direct interaction notice

Article 50(1) requires design and development so the natural persons concerned are informed that they are interacting with an AI system, unless that fact is obvious to the specified reasonably informed person.

Machine-readable synthetic-output marking

Article 50(2) requires providers of systems generating synthetic audio, image, video, or text to ensure the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.

Feasibility and exceptions matter

Technical solutions must meet effectiveness, interoperability, robustness, and reliability requirements only as far as technically feasible, considering content limits, cost, and the state of the art.

Systems exposing people

Article 50(3) makes deployers inform people exposed to emotion-recognition or biometric-categorisation systems and process personal data under the listed instruments, as applicable.

Article 50(4)-(7): Deep Fakes, Public-Interest Text, and Timing

Deep-fake disclosure

For a deep fake, Article 50(4) says deployers shall disclose that the content has been artificially generated or manipulated, subject to its stated criminal-offence exception.

Artistic and fictional works

For evidently artistic, creative, satirical, fictional, or analogous work, disclosure is limited to the existence of generated or manipulated content and must not hamper display or enjoyment.

Text for public information

Text published to inform the public on matters of public interest requires disclosure, unless the specified criminal-law exception applies or both human editorial conditions are satisfied.

When information is due

Article 50(5) requires clear, distinguishable information at the latest at the time of the first interaction or exposure and requires conformity with applicable accessibility requirements.

Quiz: Applying Article 50

Choose the most accurate answer under the supplied text.

A deployer publishes AI-generated text intended to inform the public about a public-health issue. The text received human editorial review, and a publisher holds editorial responsibility. What does Article 50(4) say?

  1. Disclosure is never required for text.
  2. The disclosure obligation does not apply where those two editorial conditions are met.
  3. Disclosure is required only if the text includes images.
  4. Disclosure is required unless the text is artistic or satirical.
Show Answer

Answer: B) The disclosure obligation does not apply where those two editorial conditions are met.

For public-interest text, the supplied text creates an exception where the AI-generated content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. Both conditions are stated together.

Articles 51 and 52: When a Model Has Systemic Risk

Two routes to classification

Article 51(1) classifies a model with systemic risk through high-impact capabilities or an equivalent-capabilities-or-impact decision by the Commission using Annex XIII criteria.

The compute presumption

High-impact capabilities are presumed when the cumulative amount of computation used for its training measured in floating point operations is greater than 1025.

The two-week notice

A provider must notify the Commission without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met.

Reassessment is not immediate

A reassessment request needs objective, detailed, and new reasons. Providers may request reassessment at the earliest six months after the designation decision.

Articles 52(6), 53, and 54: Documentation and the Value Chain

A published list, with safeguards

The Commission must publish and update the list of systemic-risk models, while observing intellectual property, confidential business information, and trade-secret protections.

Technical documentation

Article 53 requires providers to draw up and keep up-to-date the technical documentation of the model, including its training and testing process and the results of its evaluation.

Downstream developers need usable information

Documentation must enable providers of AI systems to have a good understanding of the capabilities and limitations of the general-purpose AI model and comply with their Regulation obligations.

Copyright and training summary

Providers must maintain a copyright-compliance policy and publicly provide a sufficiently detailed training-content summary according to an AI Office template.

Article 54: The Authorised Representative as a Compliance Link

Before Union placement

A third-country provider must appoint, by written mandate, an authorised representative established in the Union before placing a general-purpose AI model on the Union market.

Ten-year retention

The representative must retain the Annex XI documentation and provider contact details for a period of 10 years after the general-purpose AI model has been placed on the market.

A real compliance function

The mandate covers verification, providing requested documentation, cooperation with authorities, and being addressed instead of or alongside the provider.

Termination duty

If the representative considers or has reason to consider the provider is acting contrary to its obligations, it shall terminate the mandate and immediately inform the AI Office.

Article 55: Extra Duties for Systemic-Risk Model Providers

The additional layer

Article 55 adds duties to Articles 53 and 54. A systemic-risk provider remains responsible for baseline documentation, information, copyright, summary, and representative duties.

Adversarial testing

Evaluation includes conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks.

Union-level systemic risks

Providers must assess and mitigate possible systemic risks at Union level, including their sources, arising from development, placing on the market, or use.

Incidents and cybersecurity

Providers must report relevant serious-incident information and possible corrective measures without undue delay, and ensure adequate cybersecurity for the model and physical infrastructure.

Decision Exercise: Build the Compliance Trail

Start with classification

Identify the Article 51 threshold presumption, then apply Article 52's notification rule. Do not confuse a presumption with a separate statutory notification deadline.

Follow the information trail

Article 53 moves technical and usable capability-and-limitation information from the model provider to downstream AI-system providers.

Separate public duties by actor

For synthetic-output marking, start with Article 50(2) and the provider. For deep-fake and public-interest-text disclosure, start with Article 50(4) and the deployer.

Add Article 55 only after systemic risk

Systemic-risk status adds adversarial testing, Union-level risk mitigation, serious-incident reporting, and cybersecurity; it does not erase Articles 53 and 54.

Article 56: Codes of Practice and the Fallback Rules

What codes are for

Article 56 makes the AI Office encourage and facilitate Union-level codes of practice to contribute to proper application of the Regulation, taking international approaches into account.

Minimum subject matter

Codes should cover at least Articles 53 and 55: current information, training-summary detail, Union-level systemic-risk identification, and proportionate risk assessment and management.

Participation and measurement

Providers, authorities, civil society, industry, academia, downstream providers, and experts may participate or support. Codes should use clear objectives and, where appropriate, key performance indicators.

Past deadlines and fallback

Codes of practice shall be ready at the latest by 2 May 2025. If the stated 2 August 2025 condition occurred, the Commission may provide common rules by implementing acts.

Flashcards: Exact Duties and Triggers

Flip each card, then say the article number and the actor before revealing the answer.

Article 50(1): What must directly interactive AI systems communicate?
Providers shall ensure that **the natural persons concerned are informed that they are interacting with an AI system**, unless that is obvious from the specified reasonably informed person's perspective.
Article 50(2): What is the synthetic-output rule?
Providers shall ensure **the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated**.
Article 50(5): When is Article 50 information due?
In a clear and distinguishable manner **at the latest at the time of the first interaction or exposure**, and conforming to applicable accessibility requirements.
Article 51(2): What is the computation presumption?
A model is presumed to have high-impact capabilities when **the cumulative amount of computation used for its training measured in floating point operations is greater than 1025**.
Article 52(1): What is the notification deadline?
The provider must notify **without delay and in any event within two weeks after that requirement is met or it becomes known that it will be met**.
Article 53: What four baseline items are required?
Up-to-date technical documentation; downstream information and documentation; a copyright-and-related-rights compliance policy; and a publicly available sufficiently detailed training-content summary.
Article 55: Name the four added systemic-risk duty areas.
Model evaluation including adversarial testing; Union-level systemic-risk assessment and mitigation; serious-incident tracking, documentation, and reporting; and cybersecurity protection.
Article 56(9): What are the two dates?
Codes of practice shall be ready by 2 May 2025. The fallback condition is assessed by 2 August 2025.

Final Quiz: Identify the Accurate Compliance Statement

Select the statement that preserves the supplied text's actor, trigger, and qualification.

Which statement is accurate under the supplied text?

  1. Any free and open-source general-purpose AI model is exempt from all Article 53 and Article 54 obligations, including when it presents systemic risks.
  2. A systemic-risk model provider must perform model evaluation, including conducting and documenting adversarial testing, and must assess and mitigate possible systemic risks at Union level, including their sources.
  3. A deep-fake disclosure is unnecessary whenever content is creative, even if it is not evidently artistic, creative, satirical, fictional, or analogous work or programme.
  4. Article 52 allows a provider to request reassessment immediately after designation if it disagrees with the Commission.
Show Answer

Answer: B) A systemic-risk model provider must perform model evaluation, including conducting and documenting adversarial testing, and must assess and mitigate possible systemic risks at Union level, including their sources.

Option B accurately reflects Article 55(1)(a) and (b). Option A is wrong because the Article 53(2) and Article 54(6) exceptions do not apply to general-purpose AI models with systemic risks. Option C overstates the artistic-work qualification, which applies only where the content forms part of an evidently artistic, creative, satirical, fictional, or analogous work or programme and only limits the form of disclosure. Option D is wrong because reassessment may be requested at the earliest six months after the designation decision.

Key Terms

deployer
The actor using an AI system to whom the supplied text assigns specified exposure notices and disclosures for deep fakes and certain public-interest text.
provider
The actor to whom the supplied text assigns system design, development, model documentation, information, copyright-policy, training-summary, and certain notification duties.
deep fake
Image, audio, or video content generated or manipulated by an AI system that triggers the Article 50(4) deployer disclosure rule when it constitutes a deep fake.
serious incident
An event about which Article 55(1)(c) requires relevant information and possible corrective measures to be tracked, documented, and reported without undue delay.
codes of practice
Union-level instruments encouraged and facilitated under Articles 50(7) and 56 to support implementation of the specified obligations.
adversarial testing
Testing that Article 55(1)(a) requires providers of systemic-risk models to conduct and document with a view to identifying and mitigating systemic risks.
machine-readable format
The required form of synthetic-output marking in Article 50(2), coupled with detectability as artificially generated or manipulated.
general-purpose AI model
The category of model addressed in Chapter V. The supplied excerpt sets out classification and provider obligations but does not define the term.
high-impact capabilities
Capabilities evaluated under Article 51(1)(a) using appropriate technical tools and methodologies, including indicators and benchmarks.
authorised representative
A Union-established representative appointed by written mandate by a third-country provider before placing a general-purpose AI model on the Union market, subject to the stated exception.
presumption of conformity
The result Article 53(4) and Article 55(2) attach to compliance with European harmonised standards, only to the extent those standards cover the relevant obligations.
general-purpose AI model with systemic risk
A general-purpose AI model classified under Article 51 and Article 52, which is subject to Article 55 in addition to Articles 53 and 54.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself