The European Commission published guidelines on 20 July to help organisations understand their compliance requirements. These helpfully break them down per the below table:
| Provision | Type of AI system/output | Transparency obligation | Exceptions or special regimes |
|---|
| Art. 50(1) | AI systems directly interacting with natural persons | Providers must develop and design the AI system in such a way that the natural persons concerned are informed they are interacting with an AI system. | Exceptions 1) if the artificial origin of the interaction is obvious, or 2) the system is authorised by law to detect, prevent, investigate or prosecute criminal offences, unless the system is available to the public to report a criminal offence. |
| Art. 50(2) | AI systems generating or manipulating synthetic image, video, audio or text content | Providers must ensure the AI system’s outputs are marked in a machine-readable format and detectable as artificially generated or manipulated with technical solutions that are effective, interoperable, robust and reliable. | Exceptions if 1) the AI system performs an assistive function for standard editing or does not substantially alter the input data or the semantics thereof, or 2) the AI system is authorised by law to detect, prevent, investigate or prosecute criminal offences. |
| Art. 50(3) | Emotion recognition or biometric categorisation AI systems | Deployers must inform the natural persons exposed to the system of AI system’s operation. | Exception if the AI system is permitted by law to detect, prevent or investigate criminal offences. |
| Art. 50(4) | AI systems generating or manipulating deep fake or text published to inform the public on matters of public interest | Deployers must disclose that the content has been artificially generated or manipulated. | Exceptions if 1) the AI system is authorised by law to detect, prevent, investigate or prosecute criminal offence, or 2) if the text publication has undergone human review or editorial control and is subject to editorial responsibility. Special disclosure regime applies to deep fakes part of artistic, creative, fictional, satirical or analogous works or programmes. |
These may have broad application, considering both the presence of AI chatbots and the use of AI generated content many organisations may now be in scope for meeting these obligations.
The interactive system test
There is a four-part test that the Commission includes in its guidelines:
- Is it an AI system within the definition and scope of the AI Act?
- Is it intended to interact with people? This needs to be bi-directional, and the AI system must display a genuine conversational or responsive character.
- Is the interaction direct? This means the interaction must be real-time or near real-time and excludes where there is a human mediator (i.e. where a human has sought a response from an AI system and then shared that response with another human, while the output may be the same the interaction with the AI system is not direct).
- Is the interaction with natural persons? This may seem obvious but given the advancements in agentic AI but also use of AI in a closed physical environment, such as in manufacturing, it is important to note.
- Is it obviously an AI system? Where it is obvious that the system is AI then the requirements do not apply. You need to assess this based on the target audience and the context of the interaction.
If yes is the answer to 1 - 4 above then Art. 50(1) applies. If you answered yes to 5 then you have an exception and the article does not apply. Another exception exists where the system is authorised by law for law enforcement purposes.
The Deepfake test
Deepfakes as above, must be considered in light of the target audience and context of the organisation. For example, people are more trusting of banks and doctors so are less likely to critically assess content as being AI generated or not, so the test might be stricter. Apply a three-test approach to evaluate if something is a deepfake:
- Is the resemblance noticeable? Although it doesn't have to be identical to the original subject. AI-generated content must depict subjects that could plausibly exist. For example, deepfakes featuring mythical creatures in real-world settings are not covered by the definition, whereas simulated individuals who resemble real people may qualify as deepfakes.
- Is the content capable of deceiving viewers? This must be assessed regardless of the intentions of the deployer. The Code emphasises that this evaluation depends on the actual audience rather than a hypothetical observer. Deployers should recognise that children, elderly people and those with limited AI knowledge will encounter these deep fakes.
- Does it include edits that might alter meaning or context? Minor technical edits made by AI, such as adjusting lighting, correcting colour, reducing noise or enhancing sound typically do not result in content being classified as a deepfake, since they don’t substantially affect perceived truthfulness. However, more extensive changes may impact authenticity.
If you answered Yes to any of the above it is possible that you are dealing with a deepfake and the transparency obligations will apply. This means a label or icon must be applied to the content.
Next steps for Irish businesses
The first thing, if not already done, is to know what AI is being used in the organisation, then to assess uses of AI and determine where the requirements of Article 50 may apply. For chatbots, while the technical control remains with the providers, make sure to fully consider the role of the organisations, including if it has assumed the role of the provider by placing it on the market under its own label.
Where the organisation uses AI generated content, add a test to the approval process for publishing that content that enables the identification of deepfakes.
Our teams can help critically assess the systems plus the use cases and can also help build governance structures to enable ongoing monitoring and assessment. To learn more, get in touch with our team below.