AIG-016 AI Interaction and Output Disclosure
Description
Users interacting with an AI system are informed that they are doing so, unless it is unambiguous from context. For systems that generate synthetic audio, image, video or text content, outputs are marked as AI-generated using a machine-readable mechanism, and for deep fake or synthetic media outputs the generation is disclosed to affected parties. Disclosure mechanisms are tested so that they are not trivially removable. People subject to a decision that an AI system makes or informs are told that the system was used, at the point the decision is communicated to them. A published route lets such a person ask for an explanation, and an explanation is given within a defined period covering the part the system played in the decision and the main elements of the decision itself. Where a system presents a persona or converses in natural language, a recorded review of its interface, completed before release and repeated after any change to the persona, identifies the cues that would lead a user to attribute human status, feelings or a body to the system, including human images, statements of feeling and humanoid or cyborg imagery and records for each cue whether it was kept with a stated reason or removed.
Rationale
Undisclosed AI interaction is deceptive, and disclosure is a base-level trust requirement for AI-mediated services as well as a regulatory obligation in most jurisdictions. The population subject to a decision is wider than the population interacting with the system: a person refused a service never sees the interface at all, so a disclosure built into the product reaches none of them. AIG-017 holds the explainability capability and its limits, which is the raw material; AIG-016 holds the notice and the answer owed to the individual, with an intake route and a clock. The interface review exists because a disclosure at first contact is unsaid by every later cue that presents the system as a person, which is where the human-AI configuration risk in NIST AI 600-1 lands. The review does not forbid a persona; it records the decision to keep each cue, so that a cue survives on a reason and not by default. The user-facing half of OWASP ASI09, risk badges and confidence cues on an agent's recommendations, is still not stated here and remains the gap that row names. Detection of synthetic or manipulated media coming in, before a system relies on it as evidence, is AIG-057; this control marks and discloses what the organisation itself generates.
Applicability (9 profiles)
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Notifying affected persons (Art.26.7) and the Art.86 explanation route are the deployer's at high risk. Deep fake and public-interest text disclosure (Art.50.4) is the deployer's where it publishes the content. Interaction disclosure and machine-readable marking are built by the provider; the deployer confirms they are active in its configuration. Worker notification before workplace use (EU-AI-Art.26.6) is dispositioned to this profile and has no canonical control yet.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.26(11) binds every deployer of a high-risk Annex III system, so both seats: a person subject to a decision the system makes or informs is told the system was used. Art.86(1) adds the right to obtain clear and meaningful explanations of the role the system played in the decision and the main elements of the decision taken, with the Annex III point 2 area excluded and with room for Union or national law to restrict it. The public body's own duty to give reasons for an administrative decision runs alongside and is not restated here: this row tests the notice and the explanation route, not the legality of the decision.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Framework Mappings (34)
| IAM-17 | Output Modification and Special Authorization | informative |
| EU-AI-Art.26.7 | Deployer Obligations — Notification to Affected Individuals | full |
| EU-AI-Art.50.1 | Transparency Obligations — AI Interaction Disclosure | full |
| EU-AI-Art.50.2 | Transparency Obligations — Synthetic Content Marking | full |
| EU-AI-Art.50.4 | Transparency Obligations — Deep Fake Disclosure | full |
| EU-AI-Art.86 | Deployer Obligations — Right to Explanation of Individual Decision-Making | full |
| A.8.2 | System documentation and information for users | informative |
| GV-1.2-001 | Trustworthy AI Characteristics Integration | GV-1.2-001 | informative |
| GV-4.3-001 | AI Testing and Information Sharing Practices | GV-4.3-001 | partial |
| GV-5.1-002 | External Stakeholder Feedback Integration | GV-5.1-002 | full |
| GV-6.1-003 | Third-Party AI Risk Policies | GV-6.1-003 | partial |
| GV-6.1-008 | Third-Party AI Risk Policies | GV-6.1-008 | informative |
| MG-2.2-003 | Deployed AI System Value Maintenance | MG-2.2-003 | partial |
| MG-2.2-007 | Deployed AI System Value Maintenance | MG-2.2-007 | informative |
| MG-3.2-006 | Pre-Trained Model Monitoring | MG-3.2-006 | informative |
| MP-2.3-004 | Scientific Integrity and Testing Considerations | MP-2.3-004 | informative |
| MP-3.4-001 | Operator Proficiency Processes | MP-3.4-001 | partial |
| MP-5.1-001 | Impact Likelihood and Magnitude Documentation | MP-5.1-001 | partial |
| MP-5.1-002 | Impact Likelihood and Magnitude Documentation | MP-5.1-002 | informative |
| MP-5.1-003 | Impact Likelihood and Magnitude Documentation | MP-5.1-003 | full |
| MS-1.1-001 | AI Risk Measurement Approach Selection | MS-1.1-001 | partial |
| MS-1.1-002 | AI Risk Measurement Approach Selection | MS-1.1-002 | informative |
| MS-1.1-007 | AI Risk Measurement Approach Selection | MS-1.1-007 | informative |
| MS-2.10-002 | AI Privacy Risk Examination | MS-2.10-002 | informative |
| MS-2.2-002 | Human Subject Evaluation Requirements | MS-2.2-002 | informative |
| MS-2.5-004 | AI System Validity and Reliability | MS-2.5-004 | full |
| MS-2.7-002 | AI System Security and Resilience Evaluation | MS-2.7-002 | informative |
| MS-2.7-003 | AI System Security and Resilience Evaluation | MS-2.7-003 | informative |
| MS-2.7-005 | AI System Security and Resilience Evaluation | MS-2.7-005 | partial |
| MS-2.8-003 | AI Transparency and Accountability Risks | MS-2.8-003 | informative |
| MS-3.3-002 | User and Community Feedback Processes | MS-3.3-002 | partial |
| MS-4.2-001 | Trustworthiness Measurement with Expert Input | MS-4.2-001 | informative |
| MEASURE 2.8 | AI Transparency and Accountability Risks | informative |
| ASI09 | Human-Agent Trust Exploitation | partial |
Evidence (4)
UI or API configuration demonstrating that AI interaction disclosure is presented to users before or at the point of first interaction with an AI system.
Example: Chatbot system prompt configuration (exported from AWS Bedrock / Azure OpenAI deployment config) showing mandatory opening disclosure message 'This response is generated by an AI assistant'; UI component config showing AI badge rendered on all AI-generated responses
Test: Review the AI interaction disclosure implementation. Verify: (1) disclosure is presented before or at first AI interaction, inspected on the live system or in its configuration, (2) disclosure is not dismissible before being read, (3) for synthetic media outputs a machine-readable marking mechanism is configured and tested, (4) disclosure cannot be trivially removed by end-user action, (5) where the system makes or informs decisions about people, the notice that it was used is shown at the point the decision is communicated, including to people who never see the product interface.
Disclosure mechanism test report confirming that AI interaction disclosure and synthetic content marking have been tested for robustness and correct rendering across supported interfaces.
Example: AI Disclosure QA Test Report v1 (TestRail, exported 2026-01-20), covering 6 user interface entry points, disclosure rendering on mobile and desktop, watermark persistence after image download, and synthetic media label display in API responses
Test: Request the disclosure mechanism test report. Verify: (1) test cases cover all customer-facing interfaces, (2) synthetic content marking is tested for persistence (e.g. watermark survives format conversion), (3) test results show pass against expected disclosure behaviour, (4) report is dated within the last 12 months or after last significant UI change.
Log of explanation requests from people subject to a decision an AI system made or informed, with the date received, the date answered and the explanation issued.
Example: Explanation request log 2026 H1, with issued explanations
Test: Request the explanation request log. Verify: (1) the intake route is published where an affected person would find it rather than only in internal documentation, (2) every request in the period was answered within the defined response period, (3) each explanation names the system, states the part it played in the decision and sets out the main elements of the decision rather than pointing the person at generic documentation, (4) a refusal, if any, records the ground relied on, (5) requests arriving through a channel other than the published route were still logged and answered.
The interface persona review for each system that presents a persona or converses in natural language: the cues found that would lead a user to attribute human status, feelings or a body to the system, the decision on each cue with its reason and the dates of the review before release and after each persona change.
Example: Persona review for the support assistant, version 4 of 11 August 2026, following the avatar change of release 2026.8.
Test: Verify: (1) a review exists for every system in the inventory that presents a persona or converses in natural language, (2) the first review pre-dates the system's release record, (3) each persona change in the release history has a review dated after it, (4) each cue kept carries a stated reason and each cue removed is absent from the live interface, checked on the running system, (5) the review names the cue categories the control lists, human images, statements of feeling and humanoid or cyborg imagery, with a finding recorded against each.
Questions (3)
Are users of your AI systems informed that they are interacting with an AI before or at the point of first interaction?
Undisclosed AI interaction is deceptive and a regulatory obligation in most jurisdictions. Disclosure must be presented before interaction begins and should not be easily dismissed or hidden.
For AI systems that generate synthetic content or converse with users, which of the following disclosure mechanisms are in place?
All four mechanisms apply to generative AI systems producing synthetic media. Organisations using AI only for classification or decision-support (not synthetic media generation) should note which apply and which do not. The persona review item applies to any system with a name, an avatar or a conversational voice: it asks whether someone looked at the interface for human images, statements of feeling and humanoid imagery and recorded a decision on each.
For AI systems that make or inform decisions about people, which of the following are in place?
Options run from the most commonly in place to the least. The population here is wider than the users of the product: a person refused a service never sees the interface, so a disclosure built into the product reaches none of them. An explanation that points the reader at published model documentation does not set out the main elements of their decision.