<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Lawyer Against The Machine]]></title><description><![CDATA[Law, power, and human judgment in the age of AI — clear writing on AI compliance, responsibility, and the risks of blind automation]]></description><link>https://www.dzhamal.net</link><image><url>https://substackcdn.com/image/fetch/$s_!BCLi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3d8ada34-f9cb-4dc6-9247-99ae3c28ba06_1280x1280.png</url><title>Lawyer Against The Machine</title><link>https://www.dzhamal.net</link></image><generator>Substack</generator><lastBuildDate>Fri, 14 Aug 2026 06:34:14 GMT</lastBuildDate><atom:link href="https://www.dzhamal.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Dzhamal Statsenko]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[dzhamalstatsenko@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[dzhamalstatsenko@substack.com]]></itunes:email><itunes:name><![CDATA[Dzhamal Statsenko]]></itunes:name></itunes:owner><itunes:author><![CDATA[Dzhamal Statsenko]]></itunes:author><googleplay:owner><![CDATA[dzhamalstatsenko@substack.com]]></googleplay:owner><googleplay:email><![CDATA[dzhamalstatsenko@substack.com]]></googleplay:email><googleplay:author><![CDATA[Dzhamal Statsenko]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[EU AI Act Timeline 2026–2028: What Was Delayed and What Still Applies]]></title><description><![CDATA[Article 50 still applies from August 2026. High-risk AI deadlines now move to December 2027 and August 2028.]]></description><link>https://www.dzhamal.net/p/eu-ai-act-timeline-2026-2028</link><guid isPermaLink="false">https://www.dzhamal.net/p/eu-ai-act-timeline-2026-2028</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Wed, 29 Jul 2026 15:01:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2TNr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2TNr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2TNr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2TNr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33a15754-2118-4343-b779-78d886c1be7f_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1317352,&quot;alt&quot;:&quot;EU AI Act timeline showing the main compliance deadlines from 2 August 2026 to 2 August 2028.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/208891132?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="EU AI Act timeline showing the main compliance deadlines from 2 August 2026 to 2 August 2028." title="EU AI Act timeline showing the main compliance deadlines from 2 August 2026 to 2 August 2028." srcset="https://substackcdn.com/image/fetch/$s_!2TNr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!2TNr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33a15754-2118-4343-b779-78d886c1be7f_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The EU AI Act applies in stages. Article 50 transparency rules remain applicable from 2 August 2026, while selected obligations for existing generative AI systems, high-risk AI and regulated products apply later</figcaption></figure></div><p>The EU AI Act was not postponed as a whole. Article 50 transparency obligations apply from 2 August 2026. A limited transition for providers of certain existing synthetic-content systems ends on 2 December 2026. The main rules for Annex III high-risk AI systems now apply from 2 December 2027, while the rules for high-risk AI embedded in regulated products under Annex I apply from 2 August 2028. These dates reflect Regulation (EU) 2026/1744, which amended the original timetable. This guide explains who is affected by each deadline and what organisations should do next.</p><p><strong>By <a href="https://www.dzhamal.net/about">Dzhamal Statsenko</a>, lawyer and AI governance consultant based in the Netherlands | Last reviewed: 29 July 2026</strong></p><p>The most common mistake is to assume that the entire AI Act was postponed. It was not. The organisations receiving the most additional time are providers and deployers of high-risk AI systems. Ordinary businesses using chatbots or publishing synthetic content may still face transparency duties from 2 August 2026.</p><p>This article gives a practical EU AI Act timeline for companies, deployers, providers, professional users of AI tools, publishers, NGOs, media organisations and other organisations operating in or affecting the EU market.</p><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Table of Contents:</span></mark></strong></p><p>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/eu-ai-act-deadlines-at-a-glance">EU AI Act Deadlines at a Glance</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/what-regulation-eu-20261744-delayedand-what-it-did-not">What Regulation (EU) 2026/1744 Delayed&#8212;and What It Did Not</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/what-applies-in-2026">What Applies in 2026</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/what-applies-in-2027">What Applies in 2027</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/what-applies-in-2028">What Applies in 2028</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/which-deadline-applies-to-your-organisation">Which Deadline Applies to Your Organisation?</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/rules-already-applicable">Rules Already Applicable</a>|<br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/special-transition-rules-for-existing-systems">Special Transition Rules for Existing Systems</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/practical-takeaway">Practical Takeaway</a><br>&#9643;&#65039; <a href="http://Practical Takeaway">Frequently Asked Questions</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/208891132/official-sources-and-disclaimer">Official Sources and Disclaimer</a></p><h2>&#129001; EU AI Act Deadlines at a Glance</h2><ul><li><p><strong>2 August 2026:</strong> Article 50 transparency obligations and most remaining AI Act provisions apply.</p></li><li><p><strong>2 December 2026:</strong> the limited Article 50(2) transition ends for certain existing synthetic-content systems, and additional prohibited practices apply.</p></li><li><p><strong>2 August 2027:</strong> providers of older GPAI models must complete compliance with applicable GPAI obligations; Member States must have AI regulatory sandboxes operational.</p></li><li><p><strong>2 December 2027:</strong> principal requirements for high-risk AI systems classified under Article 6(2) and Annex III apply.</p></li><li><p><strong>2 August 2028:</strong> principal requirements for high-risk AI systems classified under Article 6(1) and Annex I apply.</p></li></ul><h2>&#129001; What Regulation (EU) 2026/1744 Delayed&#8212;and What It Did Not</h2><p><strong>Article 50 transparency duties generally:</strong> not generally delayed. They apply from <strong>2 August 2026</strong>, including transparency requirements for certain AI interactions, emotion-recognition and biometric-categorisation systems, deepfakes, and certain AI-generated public-interest texts.</p><div class="callout-block" data-callout="true"><p><em>The applicable obligation depends on the organisation&#8217;s role. Providers are responsible for designing interactive AI systems to inform users and for implementing machine-readable marking of synthetic outputs. Deployers are responsible for disclosures concerning emotion recognition, biometric categorisation, deepfakes and certain public-interest text publications.</em></p></div><p><strong>Article 50(2) limited grace period:</strong> Providers of synthetic-content systems placed on the market before 2 August 2026 have until <strong>2 December 2026</strong> to comply with the machine-readable marking and detection obligation.</p><p><strong>Annex III high-risk AI:</strong> the main requirements now apply from <strong>2 December 2027</strong>.</p><p><strong>Annex I high-risk AI in regulated products:</strong> the main requirements now apply from <strong>2 August 2028</strong>.</p><p><strong>Regulatory sandboxes:</strong> Member States must have AI regulatory sandboxes operational by <strong>2 August 2027</strong>.</p><p><strong>New prohibitions:</strong> additional prohibited AI practices concerning non-consensual intimate material and child sexual abuse material apply from <strong>2 December 2026</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jx2k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jx2k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 424w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 848w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 1272w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jx2k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png" width="1200" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1609198,&quot;alt&quot;:&quot;Comparison of EU AI Act transparency rules that remain applicable in August 2026 and high-risk AI requirements postponed to 2027 and 2028.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/208891132?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Comparison of EU AI Act transparency rules that remain applicable in August 2026 and high-risk AI requirements postponed to 2027 and 2028." title="Comparison of EU AI Act transparency rules that remain applicable in August 2026 and high-risk AI requirements postponed to 2027 and 2028." srcset="https://substackcdn.com/image/fetch/$s_!Jx2k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 424w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 848w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 1272w, https://substackcdn.com/image/fetch/$s_!Jx2k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdb05063-5f7b-40de-8346-b2eac62b36f1_1200x800.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The EU AI Act was not postponed as a whole. Article 50 transparency requirements generally remain applicable from 2 August 2026, while the principal requirements for selected high-risk AI systems were moved to 2027 and 2028</figcaption></figure></div><p><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">Regulation (EU) 2026/1744</a> was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amended the original AI Act timetable rather than replacing the AI Act as a whole.</p><h2>&#129001; What Applies in 2026</h2><h3>&#128467; 2 August 2026: Transparency Rules Still Apply</h3><p>For many organisations, 2 August 2026 remains the most important practical compliance date. The AI Act did not move all transparency obligations to 2027 or 2028.</p><p>Article 50 applies to specific transparency situations. These include informing people when they interact with an AI system, disclosing certain emotion-recognition and biometric-categorisation systems, labelling deepfakes, and disclosing certain AI-generated or AI-manipulated public-interest texts. The European Commission explains the provider and deployer distinction in its <a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act">Article 50 transparency FAQ</a>.</p><p>Article 50 does not mean that every AI-assisted email, design, illustration or internal draft needs a visible label. The question is what the system does, what content is produced, whether the content could falsely appear authentic or truthful, and whether the organisation is acting as provider or deployer.</p><p>For a deeper treatment of labels, deepfakes, watermarking and fines, see my detailed guide to <a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026">EU AI Act Article 50 transparency rules</a>.</p><h3>&#128467; 2 December 2026: Limited Article 50 Transition and New Prohibitions</h3><p>The 2 December 2026 date is often misunderstood. It is not a general postponement of Article 50 and it does not move every transparency duty to December.</p><p>Providers of synthetic-content systems placed on the market before 2 August 2026 must comply with the machine-readable marking and detection obligation under Article 50(2) by 2 December 2026. This limited transition is different from deployer disclosure duties for deepfakes and other transparency obligations that apply from 2 August 2026.</p><p>Regulation (EU) 2026/1744 also introduces additional prohibited AI practices concerning non-consensual intimate material and child sexual abuse material that start to apply from 2 December 2026.</p><h2>&#129001; What Applies in 2027</h2><h3>&#128467; 2 August 2027: Older GPAI Models and Regulatory Sandboxes</h3><p>Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with applicable GPAI obligations by 2 August 2027 under <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111">Article 111 transitional rules</a>.</p><p>This date matters mainly for providers of GPAI models, not for ordinary companies that simply use AI tools. Businesses using GPAI-powered services should still ask vendors how they are handling documentation, transparency, copyright-policy and systemic-risk obligations where relevant.</p><p>Member States also have until 2 August 2027 to ensure that national AI regulatory sandboxes are operational under <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-57">Article 57 on AI regulatory sandboxes</a>.</p><h3>&#128467; 2 December 2027: Annex III High-Risk AI</h3><p>The main requirements for high-risk AI systems classified under Article 6(2) and Annex III now apply from 2 December 2027 under the amended <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113">Article 113 application timetable</a>.</p><p>This category can affect AI systems used in areas such as employment, worker management, education, creditworthiness, access to essential services, law enforcement, migration, border control, administration of justice and democratic processes.</p><p>For employers, banks, schools, public authorities and HR technology providers, the extra time should not be treated as a reason to wait. Annex III systems require classification, risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.</p><h2>&#129001; What Applies in 2028</h2><p>The main requirements for high-risk AI systems classified under Article 6(1) and Annex I now apply from 2 August 2028 under the amended <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113">Article 113 application timetable</a>.</p><p>This concerns certain high-risk AI systems embedded in regulated products or performing safety functions, including certain medical devices, in-vitro diagnostic devices, lifts, toys and radio equipment covered by the Union product-safety legislation listed in Annex I.</p><p><strong>Separate sector-specific arrangements may apply to machinery, aviation and motor vehicles.</strong></p><p>The later date recognises that these systems interact with sector-specific conformity assessment and product-safety regimes. Manufacturers should still map AI components early because product development and certification cycles can be long.</p><h2>&#129001; Which Deadline Applies to Your Organisation?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KXQs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KXQs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 424w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 848w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 1272w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KXQs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png" width="1200" height="750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1508457,&quot;alt&quot;:&quot;EU AI Act deadlines for small businesses, generative AI providers, GPAI model providers, employers, banks, schools, public authorities and regulated product manufacturers.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/208891132?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="EU AI Act deadlines for small businesses, generative AI providers, GPAI model providers, employers, banks, schools, public authorities and regulated product manufacturers." title="EU AI Act deadlines for small businesses, generative AI providers, GPAI model providers, employers, banks, schools, public authorities and regulated product manufacturers." srcset="https://substackcdn.com/image/fetch/$s_!KXQs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 424w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 848w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 1272w, https://substackcdn.com/image/fetch/$s_!KXQs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6eb3f157-9981-443c-93cd-8e08a85d614e_1200x750.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The applicable EU AI Act deadline depends on the organisation&#8217;s role, the AI use case and the system&#8217;s risk category. Ordinary businesses may face transparency duties in 2026, while providers and deployers of high-risk systems may have later deadlines</figcaption></figure></div><h3>&#128994; Small businesses, creators and marketing teams</h3><p><strong>Main practical date:</strong> 2 August 2026. A small business may be directly affected if it provides an interactive AI system under its own name or trademark, or acts as a professional deployer using emotion recognition, biometric categorisation, deepfake content or unreviewed AI-generated public-interest texts. Merely using an off-the-shelf AI tool does not automatically make the business responsible for every Article 50 obligation.</p><p>It is still sensible to check whether a chatbot installed on a company website informs users that they are interacting with AI, and whether the vendor has designed the system to support the provider-side obligations.</p><p>Ordinary AI-assisted advertising copy or clearly fictional illustrations do not automatically require an AI label.</p><p>For nonprofit organisations, the same role-based analysis matters; see my separate guide to <a href="https://www.dzhamal.net/p/eu-ai-act-for-ngos">AI compliance for NGOs</a>.</p><h3>&#128994; Providers of existing generative AI systems</h3><p><strong>Main date: 2 December 2026.</strong> This concerns providers of systems placed on the market before 2 August 2026 that generate synthetic audio, images, video or text. They receive a limited transition period for the technical marking and detection obligation under Article 50(2).</p><h3>&#128994; Providers of older GPAI models</h3><p><strong>Main date: 2 August 2027.</strong> Providers of general-purpose AI models placed on the market before 2 August 2025 must complete compliance with the applicable GPAI obligations.</p><h3>&#128994; Employers, banks, schools and public authorities</h3><p><strong>Main date: 2 December 2027.</strong> This may apply when AI influences recruitment, employment, education, creditworthiness, insurance, public benefits, migration, law enforcement or justice.</p><h3>&#128994; Manufacturers of regulated products</h3><p><strong>Main date: 2 August 2028.</strong> This concerns certain high-risk AI systems embedded in medical devices and other regulated products or performing a safety function.</p><h2>&#129001; Rules Already Applicable</h2><p>The EU AI Act entered into force on 1 August 2024. Its obligations apply progressively.</p><p>Since 2 February 2025, prohibited AI practices and AI literacy requirements have applied. Under the amended <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4">Article 4 on AI literacy</a>, providers and deployers must take measures to support the development of AI literacy among staff and other persons operating or using AI systems on their behalf, taking account of their knowledge, experience and the context of use.</p><p>AI literacy also matters for workplace governance. Employees cannot follow an AI policy they do not understand; for workplace AI risks, see my article on <a href="https://www.dzhamal.net/p/shadow-ai-contracts-chatgpt">shadow AI and employee use of ChatGPT</a>.</p><p>Since 2 August 2025, GPAI obligations have applied for providers of general-purpose AI models placed on the market from that date, with transitional rules for older models.</p><h2>&#129001; Special Transition Rules for Existing Systems</h2><p><strong>Existing high-risk AI systems:</strong> High-risk AI systems placed on the market or put into service before the relevant Chapter III application date are generally subject to the high-risk requirements only if they undergo significant changes in their design from that date.</p><p><strong>High-risk AI for public authorities:</strong> Providers and deployers of high-risk AI systems intended to be used by public authorities must comply by <strong>2 August 2030</strong>.</p><p><strong>Large-scale EU IT systems:</strong> Certain AI components of the large-scale information systems listed in Annex X that were placed on the market or put into service before 2 August 2027 must comply by <strong>31 December 2030</strong>.</p><p><strong>Older GPAI models:</strong> GPAI models placed on the market before 2 August 2025 must comply with the applicable GPAI obligations by <strong>2 August 2027</strong>.</p><p>These special transition rules are set out in <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111">Article 111</a>.</p><h2>&#129001; Practical Takeaway</h2><p>The EU AI Act timeline is now more nuanced than a simple August 2026 deadline. Transparency duties still matter in 2026. Older GPAI models and national sandboxes matter in 2027. Annex III high-risk AI systems now move to December 2027. High-risk AI in regulated products moves to August 2028.</p><p>The best next step is to build an AI inventory and classify each AI system by role, risk category, function, deployment context and deadline. For a broader implementation roadmap, use the <a href="https://www.dzhamal.net/p/eu-ai-act-2026-checklist">practical EU AI Act checklist for companies</a>.</p><p><strong>Not sure which EU AI Act deadline applies to your organisation?</strong> I help companies, NGOs, media teams and professionals map their AI use, identify their legal role and build practical AI governance rules before the relevant deadline.</p><h2>&#128172; Frequently Asked Questions</h2><h3>&#10068;Did the EU AI Act start on 2 August 2026</h3><p>No. The EU AI Act entered into force on 1 August 2024. Most of its remaining applicable provisions begin to apply from 2 August 2026, subject to specific transitional periods.</p><h3>&#10068;Was the EU AI Act delayed</h3><p>Only partially. Article 50 transparency rules remain applicable from 2 August 2026. The principal requirements for Annex III high-risk systems were moved to 2 December 2027, while the rules for high-risk AI embedded in regulated products were moved to 2 August 2028.</p><h3>&#10068;What changes on 2 December 2026</h3><p>A limited transition for providers of certain existing synthetic-content systems ends, and new prohibited AI practices concerning non-consensual intimate content and child sexual abuse material begin to apply.</p><h3>&#10068;Who has until 2 December 2027</h3><p>Providers and deployers of Annex III high-risk AI systems, including certain systems used in employment, education, credit assessment, public services, migration, law enforcement and justice.</p><h3>&#10068;Do small businesses need to comply from 2 August 2026</h3><p>Potentially, yes, but the answer depends on role and use case. A small business may be directly affected if it provides an interactive AI system under its own name or trademark, or acts as a professional deployer using emotion recognition, biometric categorisation, deepfake content or unreviewed AI-generated public-interest texts. Merely using an off-the-shelf AI tool does not automatically make the business responsible for every Article 50 obligation.</p><h3>&#10068;Must every AI-generated image be labelled</h3><p>No. The AI Act does not impose a universal visible-label requirement on every AI-generated image. However, providers of generative AI systems may have to embed machine-readable markings under Article 50(2). Businesses and other deployers must provide a human-visible disclosure principally where the content qualifies as a deepfake and could falsely appear authentic or truthful.</p><h3>&#10068;When do high-risk AI rules apply</h3><p>High-risk AI systems classified under Article 6(2) and Annex III apply from 2 December 2027. High-risk AI systems classified under Article 6(1) and Annex I apply from 2 August 2028.</p><h2>&#129001; Official Sources and Disclaimer</h2><ul><li><p><a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">Regulation (EU) 2024/1689</a> &#8212; the original EU AI Act.</p></li><li><p><a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">Regulation (EU) 2026/1744</a> &#8212; the Digital Omnibus on AI amendments.</p></li><li><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act">European Commission AI Act implementation timeline</a>.</p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act">European Commission Article 50 transparency FAQ</a>.</p></li><li><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-111">Article 111 transitional rules for existing systems and GPAI models</a>.</p></li><li><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-113">Article 113 entry into force and application timetable</a>.</p></li><li><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-57">Article 57 AI regulatory sandboxes</a>.</p></li></ul><p>This timeline is based on Regulation (EU) 2024/1689, Regulation (EU) 2026/1744, the European Commission&#8217;s AI Act Service Desk and the Commission&#8217;s Article 50 guidance. It was last reviewed on 29 July 2026.</p><p>This article provides general information and does not constitute legal advice. The classification of an AI system and the applicable deadline depend on its intended purpose, functionality, deployment context and the role of the organisation involved.</p><p>Subscribe to <strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Lawyer Against The Machine</span></mark></strong> for practical analysis of AI regulation, compliance and digital risk in Europe.</p><p style="text-align: center;"><span>I will continue writing about this in plain language</span><br>See you in the next piece<br><br>Cheers,</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hkqm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Shadow AI at Work: What Happens When Employees Upload Work Documents and Contracts to ChatGPT?]]></title><description><![CDATA[The contract may not become public. But your employee may still have transferred confidential or protected company data without authorisation.]]></description><link>https://www.dzhamal.net/p/shadow-ai-contracts-chatgpt</link><guid isPermaLink="false">https://www.dzhamal.net/p/shadow-ai-contracts-chatgpt</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Sat, 18 Jul 2026 08:18:29 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e4bdd0e1-e3b5-406e-9c2e-cf2907760d5a_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jpJO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jpJO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jpJO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1251228,&quot;alt&quot;:&quot;Illustration representing shadow AI in the workplace. A distracted office employee is drawn toward ChatGPT by a ghost-like figure while a boxed human brain sits between them, illustrating the hidden risks of uploading company files and confidential information to AI tools&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration representing shadow AI in the workplace. A distracted office employee is drawn toward ChatGPT by a ghost-like figure while a boxed human brain sits between them, illustrating the hidden risks of uploading company files and confidential information to AI tools" title="Illustration representing shadow AI in the workplace. A distracted office employee is drawn toward ChatGPT by a ghost-like figure while a boxed human brain sits between them, illustrating the hidden risks of uploading company files and confidential information to AI tools" srcset="https://substackcdn.com/image/fetch/$s_!jpJO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!jpJO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa27b134-6d5e-48b4-b2a7-b29996e737c7_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Shadow AI is not just employees using ChatGPT. It is the loss of visibility over how company information is shared with AI tools</figcaption></figure></div><p><strong>By <a href="https://www.dzhamal.net/about">Dzhamal Statsenko</a>, lawyer and AI governance consultant based in the Netherlands | </strong><em><span data-color="#00c853" style="color: rgb(0, 200, 83);">Last reviewed: 17 July 2026</span></em></p><p><strong>An employee receives a 40-page contract from a supplier.</strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Instead of spending several hours</span></strong> reviewing it, the employee <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">uploads the contract to ChatGPT</span></strong> and asks the tool to summarise the agreement, identify risky clauses and draft an email to the supplier.</p><p>&#128104;&#8205;&#128188; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">From the employee&#8217;s perspective</span></strong>, this is not a security incident. It is productivity.</p><p>&#127970; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">From the company&#8217;s perspective</span></strong>, something more important may have happened: confidential information may have been sent to an external AI provider through a personal account, without approval, without a security assessment and without anyone knowing how the document will be stored, processed or deleted. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That is shadow AI</span></strong> in its most practical form: <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">ordinary employees using useful AI tools outside the organisation&#8217;s visibility and control.</span></strong></p><blockquote><p><em>The contract does not automatically become public. But the employee may still have transferred personal, confidential or legally protected information to an external service without authorisation.</em></p></blockquote><p>The problem is not simply that employees are using ChatGPT. The problem is that companies often have no visibility, no rules and no safe workflow.</p><h2>&#129001; Key Takeaways</h2><p>&#9643;&#65039; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Uploading a company document to ChatGPT</span></strong> does not automatically make it public, but it may still create an unauthorised external data transfer</p><p>&#9643;&#65039; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Turning off model training</span></strong> does not automatically make the upload authorised, lawful or consistent with an NDA</p><p>&#9643;&#65039; Consumer ChatGPT and organisation-managed business products have materially different controls, but <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">neither removes the need for internal approval</span></strong></p><p>&#9643;&#65039; Contracts and work documents may contain personal data, trade secrets, privileged communications, commercial terms and <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">information protected by confidentiality clauses</span></strong></p><p>&#9643;&#65039; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A practical AI usage policy should approve</span></strong> four things before company information enters an AI system: <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the tool | the account | the data | the task</span></strong></p><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Table of Contents:</span></mark></strong></p><p>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/what-is-shadow-ai">What Is Shadow AI? </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/why-employees-upload-work-documents-to-chatgpt">Why Employees Upload Work Documents to ChatGPT </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/the-four-approvals-rule">The Four Approvals Rule</a> <br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/what-happens-to-confidential-information-uploaded-to-chatgpt">What Happens to Confidential Information Uploaded to ChatGPT? </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/consumer-chatgpt-vs-business-products">Consumer ChatGPT vs Business Products </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/ai-data-security-is-not-just-about-model-training">AI Data Security Is Not Just About Model Training </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/contracts-ndas-trade-secrets-gdpr-and-legal-privilege">Contracts, NDAs, Trade Secrets, GDPR and Legal Privilege </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/what-to-do-if-an-employee-has-already-uploaded-a-contract">What to Do If an Employee Has Already Uploaded a Contract </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/can-employees-use-chatgpt-for-company-data">Can Employees Use ChatGPT for Company Data? </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/what-companies-should-ban-or-restrict">What Companies Should Ban or Restrict </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/how-to-create-an-ai-usage-policy-for-employees">How to Create an AI Usage Policy for Employees </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/ai-literacy-under-the-eu-ai-act">AI Literacy Under the EU AI Act </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/practical-shadow-ai-checklist-for-employers">Practical Shadow AI Checklist for Employers </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/frequently-asked-questions">Frequently Asked Questions </a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/i/207442748/conclusion">Conclusion</a></p><h2>&#129001; What Is Shadow AI?</h2><p>Shadow AI is the <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">use of AI systems inside an organisation without formal approval</span></strong>, security review or effective oversight.</p><p>It can include an <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">employee using a personal ChatGPT account</span></strong> to analyse a contract, a manager uploading an HR spreadsheet to an AI assistant, a developer copying proprietary source code into a coding model, or a team connecting an AI application to company email or cloud storage <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">without approval</span></strong>.</p><p>Shadow AI is <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">similar to shadow IT, but it can be harder to see.</span></strong> A conventional unapproved application may store a file. A generative AI tool may analyse the file, extract information from it, combine it with prompts, produce new content and make the result easy to copy into other systems.</p><blockquote><p><em>The employee may believe they are only asking a question. The company may actually be creating a new data flow.</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Wah!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Wah!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Wah!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2f28979-7661-430b-8676-f39738a81bf5_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1133467,&quot;alt&quot;:&quot;Illustration of shadow AI in the workplace. An office employee secretly uses ChatGPT on a smartphone under a desk while a manager stands behind, symbolising the use of AI tools outside company governance and approval&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of shadow AI in the workplace. An office employee secretly uses ChatGPT on a smartphone under a desk while a manager stands behind, symbolising the use of AI tools outside company governance and approval" title="Illustration of shadow AI in the workplace. An office employee secretly uses ChatGPT on a smartphone under a desk while a manager stands behind, symbolising the use of AI tools outside company governance and approval" srcset="https://substackcdn.com/image/fetch/$s_!4Wah!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!4Wah!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2f28979-7661-430b-8676-f39738a81bf5_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Shadow AI often begins when employees use AI tools outside approved company processes&#8212;not because they are acting maliciously, but because they are trying to work faster</figcaption></figure></div><p>SHRM&#8217;s 2026 workplace AI research found that <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">46% of workers believed their organisation&#8217;s AI policies prevented them from experimenting with tools that could improve their work, and 30% said they had knowingly violated organisational AI rules.</span></strong> Reported violations included using tools still under review, using unapproved accounts and uploading confidential organisational data to unapproved systems. See <a href="https://www.shrm.org/topics-tools/research/navigating-ai-in-the-workplace/full-report">SHRM&#8217;s 2026 workplace AI research</a>.</p><p>This is why shadow AI should not be treated only as employee misconduct. Employees often use unapproved AI because it solves a real problem faster than the official workflow.</p><h2>&#129001; Why Employees Upload Work Documents to ChatGPT</h2><p>Employees using ChatGPT at work are not necessarily trying to evade security controls. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">They may be trying to</span></strong> summarise a long document, translate a contract, compare two versions of an agreement, restructure a report, draft a response to a client or understand a difficult clause.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The immediate benefit is visible. The information-security consequence is not.</span></strong></p><blockquote><p><em>A seemingly ordinary document may contain customer names, employee information, signatures, bank details, negotiated prices, internal comments, source code, litigation strategy, legal advice, passwords, API credentials or trade secrets.</em></p></blockquote><p>&#128314;The employee sees a document<br>&#128314;The security team sees a data transfer<br>&#128314;The privacy team sees a new processing activity<br>&#128314;The lawyer sees confidentiality, privilege and contractual obligations</p><p>That difference in perspective is the centre of the shadow AI problem.</p><h2>&#129001; The Four Approvals Rule</h2><p>Before an employee uploads company information to an AI system, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the organisation should be able to confirm four things.</span></strong></p><h3>1&#65039;&#8419; Approved Tool</h3><p>The company has reviewed the AI provider, contractual terms, security measures, retention practices, subprocessors and relevant privacy controls.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Practical question:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>Has this specific AI tool been approved for this category of company information?</p><h3>2&#65039;&#8419; Approved Account</h3><p>The employee is using the correct organisation-managed account rather than a personal account, where company policy requires one.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Practical question:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>Is the employee using an account controlled by the organisation, with the right administrative settings and auditability?</p><h3>3&#65039;&#8419; Approved Data</h3><p>The information falls within a category that the company permits the AI system to process. Restricted information has been removed, anonymised or moved to a specially approved environment.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Practical question:</span></strong> Does the document contain personal data, confidential terms, privileged material, trade secrets or information restricted by an NDA?</p><h3>4&#65039;&#8419; Approved Task</h3><p>The purpose is permitted, proportionate and subject to appropriate human review. The employee is not delegating an important legal, financial, employment or customer decision to an AI system without oversight.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Practical question:</span></strong> Is the AI being used for a permitted support task, or is it being asked to make or replace a decision that requires professional responsibility?</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Approved tool. Approved account. Approved data. Approved task.</span></strong></p><p>If one answer is <em>&#8220;no&#8221;</em> or <em>&#8220;unknown&#8221;</em>, stop and escalate the proposed use before company information is uploaded.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k3LG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k3LG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k3LG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1177998,&quot;alt&quot;:&quot;Illustration of a manager attempting to control ChatGPT, symbolising the Four Approvals Rule and the need to approve AI tools, user accounts, company data and permitted tasks before employees use generative AI at work&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of a manager attempting to control ChatGPT, symbolising the Four Approvals Rule and the need to approve AI tools, user accounts, company data and permitted tasks before employees use generative AI at work" title="Illustration of a manager attempting to control ChatGPT, symbolising the Four Approvals Rule and the need to approve AI tools, user accounts, company data and permitted tasks before employees use generative AI at work" srcset="https://substackcdn.com/image/fetch/$s_!k3LG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!k3LG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56d253ff-b46c-4a3d-ae4c-000d152c2138_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Effective AI governance is not about punishing ChatGPT. It is about approving the right tool, account, data and task before company information is shared</figcaption></figure></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The value of this rule is that it works for non-lawyers.</span></strong> Employees do not need to analyse every clause of the GDPR or every vendor term. They need a simple checkpoint that tells them when to pause and ask Legal, Privacy, Security or management before using AI.</p><h2>&#129001; What Happens to Confidential Information Uploaded to ChatGPT?</h2><p>A document uploaded to ChatGPT does <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">not automatically become public</span></strong>. It is also inaccurate to claim that every uploaded document is automatically incorporated into a model and shown to other users.</p><p>The correct answer depends on the product, account type, data controls, retention settings, whether Temporary Chat is used, whether memory is active, whether apps or GPTs are involved and whether the conversation or project is shared.</p><p>OpenAI states that content submitted through <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">consumer services may be used to improve its models</span></strong> depending on the user&#8217;s settings. Users can switch off the relevant training control, after which new conversations will not be used to improve the models. See <a href="https://help.openai.com/en/articles/7039943-data-usage-for-consumer-services-faq">OpenAI&#8217;s consumer data usage guidance</a>.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Normal chats may remain saved in the account until the user deletes them.</span></strong> Deleted chats and associated files are generally scheduled for deletion from OpenAI systems within 30 days, subject to exceptions such as legal, security or prior de-identification requirements. See <a href="https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt">OpenAI&#8217;s chat and file retention policy</a>.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Temporary Chats</span></strong> do not appear in chat history and are not used to improve OpenAI&#8217;s models. OpenAI may nevertheless retain a copy for a limited safety period. See <a href="https://help.openai.com/articles/8914046-temporary-chat-faq">OpenAI&#8217;s Temporary Chat guidance</a>.</p><div class="callout-block" data-callout="true"><ul><li><p>These settings matter, but they do not resolve the whole legal question</p></li><li><p>Turning off training does not amend an NDA</p></li><li><p>Temporary Chat does not give an employee authority to disclose a trade secret</p></li><li><p>Deleting a conversation does not retroactively approve the original transfer</p></li><li><p>A personal paid account does not automatically become a company-controlled environment</p></li></ul></div><h2>&#129001; Consumer ChatGPT vs Business Products</h2><p>One of the most important ChatGPT data privacy distinctions is the difference between consumer services and organisation-managed business products.</p><p>OpenAI states that it does not use inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu and the API to train its models by default. See <a href="https://openai.com/enterprise-privacy/">OpenAI&#8217;s business data privacy commitments</a>.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That makes an organisation-managed workspace materially different from an employee independently using a personal account.</span></strong></p><p>However, a safer account is not the same as an approved use case.</p><p>Even in a business environment, an <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">organisation must still decide</span></strong> which employees may use the system, which documents may be uploaded, whether personal data is permitted, when Legal, Privacy or Security approval is required, and which outputs require human review.</p><h2>&#129001; AI Data Security Is Not Just About Model Training</h2><p>Discussions about ChatGPT data privacy often focus on one question: <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">will the provider train a model on this document?</span></strong></p><p>That is important, but it is only one part of AI data security.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A complete assessment should also ask</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>where the document is stored, for how long, who controls the account, whether the conversation can be shared, whether administrators can access or delete it, whether external apps are enabled, whether the company can obtain audit information and what happens when the employee leaves.</p><p>The legal and security risks include unauthorised disclosure, excessive retention, insufficient vendor due diligence, insecure integrations, weak access controls, loss of an audit trail and unclear responsibility.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A generative AI data leakage strategy must therefore cover the entire data lifecycle, not only model training.</span></strong></p><div class="callout-block" data-callout="true"><p>For many organisations, the weak point is not the AI provider itself. It is the missing internal ownership: nobody knows who approved the tool, who reviews new use cases, who checks integrations, who trains employees and who investigates mistakes</p></div><h2>&#129001; Contracts, NDAs, Trade Secrets, GDPR and Legal Privilege</h2><p>Using ChatGPT for contracts can be useful. An AI tool may help an employee summarise obligations, compare drafts, extract deadlines, prepare questions for a lawyer or rewrite a clause in clearer language.</p><p>But the<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">legal risk may begin before the system produces its first answer.</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oNw6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oNw6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oNw6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1211736,&quot;alt&quot;:&quot;Conceptual illustration of confidential company information leaking through a ChatGPT conversation. A person holds a smartphone displaying ChatGPT while water flows from an opened head through the phone into a glass held by a red symbolic hand, representing risks involving contracts, trade secrets, personal data and legally protected information&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Conceptual illustration of confidential company information leaking through a ChatGPT conversation. A person holds a smartphone displaying ChatGPT while water flows from an opened head through the phone into a glass held by a red symbolic hand, representing risks involving contracts, trade secrets, personal data and legally protected information" title="Conceptual illustration of confidential company information leaking through a ChatGPT conversation. A person holds a smartphone displaying ChatGPT while water flows from an opened head through the phone into a glass held by a red symbolic hand, representing risks involving contracts, trade secrets, personal data and legally protected information" srcset="https://substackcdn.com/image/fetch/$s_!oNw6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!oNw6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32d8d134-82cd-4c53-84fb-e798f6f1896a_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Once confidential information leaves your organisation, the legal question is whether the disclosure was authorised, necessary and properly governed</figcaption></figure></div><h3>&#128994; Contractual Confidentiality and NDAs</h3><p>A company may have promised that certain information will be disclosed only to employees, professional advisers or authorised service providers. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Uploading that information to an unapproved AI service may fall outside the permitted categories.</span></strong></p><p>Whether the disclosure breaches a particular contract depends on the wording of the confidentiality clause, the nature of the information, the AI provider&#8217;s contractual role, the account configuration and the safeguards in place.</p><blockquote><p>An employee cannot assume that a disclosure is permitted merely because <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the recipient is software rather than a human being</span></strong></p></blockquote><h3>&#128994; Trade Secrets</h3><p>Under the EU trade-secret framework, information generally qualifies as a trade secret where it is secret, has commercial value because it is secret and has been subject to reasonable steps to keep it secret. See the <a href="https://eur-lex.europa.eu/eli/dir/2016/943/oj/eng">EU Trade Secrets Directive</a>.</p><p>One accidental upload does not automatically destroy trade-secret protection.</p><blockquote><p>However, a pattern of <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">uncontrolled disclosure</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>could make it more difficult for a company to demonstrate that it consistently took reasonable steps to preserve secrecy</p></blockquote><h3>&#128994; GDPR and Personal Data</h3><p>In Europe, uploading a company document to an AI service may involve the processing of personal data. Personal data can appear in employment contracts, invoices, customer complaints, internal investigations, CVs, signed documents, emails and spreadsheets.</p><p>The GDPR requires personal data to be processed lawfully, fairly and transparently, limited to what is necessary and protected through appropriate technical and organisational measures. It also establishes requirements concerning processors, security and high-risk processing. See the <a href="https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng">General Data Protection Regulation</a>.</p><blockquote><p>An unauthorised upload may constitute a personal data breach<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">depending on the facts</span></strong></p></blockquote><p>Reportability requires a separate risk assessment, including what data was uploaded, who could access it, what safeguards applied and what consequences may follow for individuals.</p><h3>&#128994; Legal Privilege and Professional Confidentiality</h3><p>The position becomes particularly sensitive when employees upload legal advice, correspondence with lawyers, litigation documents, investigation reports, settlement strategy or materials prepared in anticipation of proceedings.</p><blockquote><p>Disclosure to an external AI system<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">may create an argument that confidentiality or privilege has been compromised</span></strong>. It would be too broad, however, to say that every use of AI automatically waives privilege</p></blockquote><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Recent US federal decisions have reached different conclusions</span></strong> concerning privilege and generative AI. The American Bar Association describes this as a developing and fact-specific area. See the <a href="https://www.americanbar.org/groups/law_practice/resources/law-technology-today/2026/when-does-client-use-of-ai-waive-privilege/">American Bar Association analysis of AI and privilege</a>.</p><p>ABA Formal Opinion 512 also emphasises that lawyers using generative AI remain responsible for competence, confidentiality, communication and supervision. See <a href="https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-opinion-512.pdf">ABA Formal Opinion 512</a>.</p><p>The privilege discussion above primarily concerns the United States. Legal professional privilege and professional secrecy differ across European jurisdictions.</p><h2>&#129001; What to Do If an Employee Has Already Uploaded a Contract</h2><p>Do not begin by assuming that the contract is now public. Do not delete every record before understanding what happened. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Start with a structured assessment.</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q7-r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q7-r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q7-r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1209879,&quot;alt&quot;:&quot;Illustration of an internal investigation after confidential information was uploaded to an AI tool. A detective examines a mysterious green spill while a ghost-like figure leaves through an open door, symbolising hidden risks, incident response and the investigation of AI-related data disclosures&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of an internal investigation after confidential information was uploaded to an AI tool. A detective examines a mysterious green spill while a ghost-like figure leaves through an open door, symbolising hidden risks, incident response and the investigation of AI-related data disclosures" title="Illustration of an internal investigation after confidential information was uploaded to an AI tool. A detective examines a mysterious green spill while a ghost-like figure leaves through an open door, symbolising hidden risks, incident response and the investigation of AI-related data disclosures" srcset="https://substackcdn.com/image/fetch/$s_!Q7-r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Q7-r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a55abb9-c21d-4014-a0a4-f47d7c54dffa_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">If a contract has already been uploaded to an AI tool, the priority is not blame. It is understanding what happened, assessing the risk and responding quickly</figcaption></figure></div><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 1:</span> Establish the Facts</h3><p>Identify which AI service was used, whether the account was personal or company-managed, what document or text was uploaded, which prompts were entered, whether the conversation was shared, whether outputs were copied and whether external apps or connectors were enabled.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 2:</span> Classify the Information</h3><p>Check whether the material contained personal data, customer information, privileged communications, trade secrets, credentials, confidential pricing, intellectual property, NDA-restricted information or regulated financial, medical or employment information.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 3:</span> Preserve Relevant Evidence</h3><p>Before deleting the conversation, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">preserve the information necessary to investigate the incident</span></strong>, where legally and operationally appropriate. This may include screenshots, timestamps, prompts, outputs, account information, file names, sharing settings and relevant logs.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 4:</span> Contain the Incident</h3><p>Depending on the circumstances, the company may need to delete the conversation or file, revoke a shared link, disconnect an integration, reset exposed credentials, restrict the account, contact the provider or suspend the affected workflow.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 5:</span> Assess Legal Obligations</h3><p>Legal, Privacy and Security teams should assess whether company policy was breached, whether an NDA or contract was violated, whether privilege may have been affected, whether trade-secret remediation is necessary and whether the event qualifies as a personal data breach.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">Step 6:</span> Fix the Workflow</h3><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The final question should be:</span></strong> why did the employee need to use an unapproved tool?</p><p>Perhaps there was no approved AI environment. Perhaps the policy was too vague. Perhaps the authorised tool did not perform the task. Perhaps employees were never trained.</p><blockquote><p>Disciplining one employee will not solve a structural problem if the workflow remains broken.</p></blockquote><p>A useful post-incident review should therefore ask whether the employee had a safe alternative. If the official process takes two weeks and the unapproved tool gives a useful first draft in one minute, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the organisation should expect repeated policy breaches unless it fixes the workflow.</span></strong></p><h2>&#129001; Can Employees Use ChatGPT for Company Data?</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Yes, in appropriate circumstances.</span></strong></p><p>The answer should not be a universal ban or unrestricted permission. Employees should use ChatGPT for company data <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">only where the Four Approvals Rule is satisfied.</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DseC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DseC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!DseC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!DseC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!DseC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DseC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1256590,&quot;alt&quot;:&quot;Illustration of ChatGPT under organisational control. A small ghost-like AI character sits inside a cage while a person stands nearby, symbolising the use of AI tools within company policies, approved data rules and AI governance controls&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of ChatGPT under organisational control. A small ghost-like AI character sits inside a cage while a person stands nearby, symbolising the use of AI tools within company policies, approved data rules and AI governance controls" title="Illustration of ChatGPT under organisational control. A small ghost-like AI character sits inside a cage while a person stands nearby, symbolising the use of AI tools within company policies, approved data rules and AI governance controls" srcset="https://substackcdn.com/image/fetch/$s_!DseC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!DseC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!DseC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!DseC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27c0db39-ae82-4b2e-920d-a5c0986eb725_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Employees can often use ChatGPT for work&#8212;but only within clear rules about approved data, approved tasks and organisational AI governance</figcaption></figure></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Low-risk examples may include</span></strong> summarising public information, rewriting approved marketing content, brainstorming with synthetic data, translating non-confidential text or restructuring a public job advertisement.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Higher-risk examples</span></strong> may require a business environment and additional approval: internal policies, commercial contracts, customer correspondence, operational reports and internal presentations.</p><p>For many teams, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the practical compromise is a redaction workflow.</span></strong> Before a document is uploaded, employees remove names, signatures, pricing, unique identifiers, privileged comments and other details that are not necessary for the task. </p><blockquote><p>Redaction is not a magic solution, but it can reduce risk where the organisation has approved the tool and the use case</p></blockquote><h2>&#129001; What Companies Should Ban or Restrict</h2><p>A useful AI usage policy for employees should not simply say: <em>&#8220;Do not share confidential information.&#8221;</em> That is too vague.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A practical policy should classify data.</span></strong></p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#9989; Green:</span> Generally Permitted in Approved Tools</h3><p>Public information, approved marketing materials, synthetic data, public job advertisements and non-confidential templates.</p><h3><span data-color="#f1c232" style="color: rgb(241, 194, 50);">&#9888;&#65039; Amber:</span> Restricted to Approved Business Environments</h3><p>Internal procedures, draft presentations, routine commercial correspondence, low-risk operational reports and contracts that have been reviewed and appropriately redacted.</p><h3><span data-color="#cc0000" style="color: rgb(204, 0, 0);">&#128680; Red:</span> Prohibited Without Specific Authorisation</h3><p>Passwords, credentials, API keys, health data, special-category personal data, privileged legal advice, litigation materials, M&amp;A documents, unreleased financial results, trade secrets, protected source code, customer databases, security architecture and information restricted by an NDA.</p><h2>&#129001; How to Create an AI Usage Policy for Employees</h2><p>An effective AI usage policy should make safe behaviour easier. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It should not exist only to punish mistakes after they occur.</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5t2f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5t2f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5t2f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1249209,&quot;alt&quot;:&quot;Illustration of a hand repeatedly writing &#8220;I won&#8217;t use ChatGPT anymore&#8221; on a sheet of paper, symbolising that an effective AI usage policy should provide practical guidance rather than simply banning employees from using AI tools&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of a hand repeatedly writing &#8220;I won&#8217;t use ChatGPT anymore&#8221; on a sheet of paper, symbolising that an effective AI usage policy should provide practical guidance rather than simply banning employees from using AI tools" title="Illustration of a hand repeatedly writing &#8220;I won&#8217;t use ChatGPT anymore&#8221; on a sheet of paper, symbolising that an effective AI usage policy should provide practical guidance rather than simply banning employees from using AI tools" srcset="https://substackcdn.com/image/fetch/$s_!5t2f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!5t2f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826c22f5-5556-46c1-b3ac-d4a53006792d_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">An effective AI usage policy is not a punishment. It gives employees clear rules for using AI safely, responsibly and confidently</figcaption></figure></div><p>At minimum, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">it should define the AI systems covered</span></strong>, list approved tools and accounts, explain data classifications, describe permitted and prohibited uses, set rules for personal data, require human verification, address records and retention, control integrations and define incident-reporting steps.</p><p>The policy should also <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">explain how employees can request approval for a new AI use case.</span></strong> Without a realistic approval route, people may treat the policy as a wall rather than a governance system.</p><p>Human oversight is especially important where AI supports legal conclusions, financial analysis, employee decisions, customer communication or public-facing content. This connects directly with broader questions of <a href="https://www.dzhamal.net/p/autonomous-ai-world-models-governance">human oversight and autonomous AI governance</a>.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For nonprofit organisations</span></strong>, the same logic applies in a more resource-constrained setting: policies should be practical, role-specific and proportionate. I discuss this separately in <a href="https://www.dzhamal.net/p/eu-ai-act-for-ngos">AI compliance for NGOs</a>.</p><h2>&#129001; AI Literacy Under the EU AI Act</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Article 4 of the EU AI Act has applied since 2 February 2025.</span></strong> The European Commission explains that AI literacy measures should be appropriate to the context and take account of employees&#8217; technical knowledge, experience, education and training, the use context and the affected persons. See <a href="https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers">European Commission guidance on AI literacy</a>.</p><blockquote><p>This does not mean that every employee must complete the same generic course</p></blockquote><p>A receptionist using an AI chatbot, an HR manager reviewing AI-assisted CV summaries, a lawyer using ChatGPT for contract triage and a developer using a coding assistant <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">need different training.</span></strong></p><p>For shadow AI prevention, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI literacy should explain</span></strong> what may not be uploaded, how approved tools must be used, when to escalate, why model training is not the only risk and why human responsibility remains necessary.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Training should use examples from the organisation&#8217;s own work:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>contracts, HR files, customer support messages, fundraising documents, policy drafts, board papers or technical documentation. Generic warnings rarely change behaviour unless employees recognise the documents they actually handle.</p><p>For broader company readiness, this connects with the <a href="https://www.dzhamal.net/p/eu-ai-act-2026-checklist">EU AI Act 2026 compliance checklist</a>.</p><h2>&#129001; Practical Shadow AI Checklist for Employers</h2><p>&#9643;&#65039; Inventory where employees already use AI tools<br>&#9643;&#65039; Identify personal accounts used for work tasks<br>&#9643;&#65039; Classify documents by sensitivity before AI use<br>&#9643;&#65039; Approve specific AI tools and accounts<br>&#9643;&#65039; Define green, amber and red data categories<br>&#9643;&#65039; Restrict uploads of privileged, confidential and regulated information<br>&#9643;&#65039; Review vendor terms, retention, security and administrative controls<br>&#9643;&#65039; Train employees by role, not with one generic slide deck<br>&#9643;&#65039; Create a clear reporting route for accidental uploads<br>&#9643;&#65039; Keep evidence of decisions, approvals and remediation<br>&#9643;&#65039; Revisit the policy when new AI features, connectors or business workflows are introduced<br>&#9643;&#65039; Test whether employees understand the policy by asking them to classify real examples from their daily work</p><h2>&#128172; Frequently Asked Questions</h2><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Can employees upload contracts to ChatGPT</span></h3><p>Only if the tool, account, data and task have been approved. A contract may contain confidential terms, personal data, trade secrets or privileged material. A personal ChatGPT account is usually not the right environment for unredacted company contracts unless the organisation has expressly authorised that use.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Is it safe to upload company documents to ChatGPT</span></h3><p>It depends on the product, account, settings, contract, data category and use case. The safer question is not &#8220;is ChatGPT safe?&#8221; but &#8220;has this specific workflow been approved for this specific information?&#8221;</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Does ChatGPT use company data for training</span></h3><p>OpenAI says consumer-service content may be used to improve models depending on user settings, while ChatGPT Business, Enterprise, Edu and API inputs and outputs are not used for model training by default. Training is only one issue; storage, retention, disclosure and authorisation still matter.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Does turning off training make an upload safe</span></h3><p>Not necessarily. Turning off training addresses one use of the data. It does not amend an NDA, approve an external transfer, resolve GDPR questions, control retention or create internal corporate authority.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Can deleting the chat remove the legal risk</span></h3><p>Deletion may reduce continuing exposure, but it does not erase the fact that a potentially unauthorised transfer occurred. The company may still need to assess confidentiality, privacy, security, privilege and contractual consequences.</p><h3><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Should companies ban ChatGPT completely</span></h3><p>A total ban may be appropriate for some environments or data categories. But broad bans can push AI use into personal accounts and invisible workflows. A stronger long-term approach is usually approved tools, clear restrictions, training, monitoring and realistic incident response.</p><h2>&#129001; Conclusion</h2><p>The debate about employees using ChatGPT is often framed incorrectly.</p><p>The question is not whether AI is good or bad. It is not whether every uploaded contract will become public. It is not whether companies can prevent every employee from experimenting with AI.</p><blockquote><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The real question is</span></strong> whether the organisation knows which AI systems are being used, what information is entering them, which accounts are involved, which purposes are permitted and who remains responsible</p></blockquote><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Employees will continue using AI because it solves real problems.</span></strong></p><p>Companies that respond only with prohibition may push that activity into personal accounts, private devices and invisible workflows.</p><p>The real risk is not that employees use AI. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The real risk is that companies have no visibility, no rules and no safe workflow.</span></strong></p><h2>&#129001; Does Your Organisation Know What Employees Are Uploading?</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I help European businesses and NGOs</span></strong> identify shadow AI use, assess confidential-data risks and build practical AI governance systems.</p><p>This may include a Shadow AI Risk Review, an AI usage policy, a review of existing ChatGPT workflows, employee AI literacy training, or a<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">practical workshop for management, Legal, HR or Compliance teams.</span></strong></p><p>The goal is not to stop employees from using AI. The goal is to make sure they can use it without turning productivity into an avoidable legal incident.</p><p><strong><a href="https://www.dzhamal.net/about">Request a Shadow AI Risk Review</a></strong></p><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Related Reading:</span></mark></strong></p><p>&#9643;&#65039; <a href="https://www.dzhamal.net/p/eu-ai-act-2026-checklist">EU AI Act 2026: What Companies Need To Do Before August</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/p/eu-ai-act-for-ngos">AI Compliance for NGOs: How the EU AI Act Changes Nonprofit Work</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026">EU AI Act transparency and AI labelling obligations</a><br>&#9643;&#65039; <a href="https://www.dzhamal.net/p/autonomous-ai-world-models-governance">Autonomous AI and World Models: Who Will Control the Matrix?</a></p><h2>Scope, Methodology and Legal Disclaimer</h2><p>This article primarily focuses on EU data protection, confidentiality and AI governance. The privilege discussion includes recent US developments and should not be applied automatically to other jurisdictions.</p><p>Legal professional privilege and professional secrecy differ by jurisdiction. Companies should <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">obtain jurisdiction-specific advice before drawing conclusions</span></strong> about privilege, confidentiality or reporting duties.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The analysis is based on</span></strong> official OpenAI documentation, EU legislation, European Commission guidance, American Bar Association materials and workplace research. It is intended as a practical governance guide, not as academic peer review.</p><p><em>This article provides general information and does not constitute legal advice.</em></p><p style="text-align: center;"><span data-color="#00c853" style="color: rgb(0, 200, 83);">I will continue writing about this in plain language</span><span><br>See you in the next piece</span><br><br><span>Cheers,</span></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hkqm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/207442748?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hkqm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!Hkqm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc35e4e83-49d9-4474-8f92-95fc4e5d480c_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span><br></span></p>]]></content:encoded></item><item><title><![CDATA[Autonomous AI and World Models: Who Will Control the Matrix?]]></title><description><![CDATA[The next generation of AI may not just generate answers. It may plan, decide, and act in the physical world. Regulation must catch up before autonomy becomes the default.]]></description><link>https://www.dzhamal.net/p/autonomous-ai-world-models-governance</link><guid isPermaLink="false">https://www.dzhamal.net/p/autonomous-ai-world-models-governance</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Fri, 10 Jul 2026 15:35:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vEX3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vEX3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vEX3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vEX3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:837132,&quot;alt&quot;:&quot;Autonomous AI and World Models: Who Will Control the Matrix?&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206361304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Autonomous AI and World Models: Who Will Control the Matrix?" title="Autonomous AI and World Models: Who Will Control the Matrix?" srcset="https://substackcdn.com/image/fetch/$s_!vEX3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!vEX3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3d2e3ee-72b1-4dfb-ab20-2f89f49ded9a_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Table of Contents:</span></mark></strong></p><p>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/from-language-models-to-autonomous-ai">From Language Models to World Models</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/what-are-ai-world-models">What Are AI World Models?</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/when-ai-starts-to-act">When AI Starts to Act</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/ai-regulation-must-focus-on-authority">Why AI Regulation Must Focus on Authority</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/the-matrix-must-have-boundaries">The Matrix Must Have Boundaries</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/the-matrix-needs-a-black-box">Why Autonomous AI Needs a Black Box</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/human-oversight-must-mean-real-control">Human Oversight and Real Control</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/test-scenarios-not-just-answers">Testing Autonomous AI</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/who-will-be-responsible-for-the-matrix">Who Is Liable When AI Fails?</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/europes-role-in-regulating-autonomous-ai">Europe&#8217;s Role in AI Regulation</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/what-companies-should-do-now">What Companies Should Do Now</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206361304/who-controls-the-matrix">Who Controls the Matrix?</a></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Today&#8217;s AI produces answers</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">. The next generation may make decisions</span>, execute plans, and act in the physical world.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That changes the legal question completely.</span></strong></p><p>Companies will no longer compete solely over whose chatbot writes better text, produces better images, or gives better answers. The next technological war may be fought over autonomous AI systems that can <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">understand their environment, predict consequences, and carry out tasks independently.</span></strong></p><p>One of the leading advocates of this direction is <strong><a href="https://en.wikipedia.org/wiki/Yann_LeCun"><span data-color="#00c853" style="color: rgb(0, 200, 83);">Yann LeCun</span></a></strong>, a <a href="https://en.wikipedia.org/wiki/Turing_Award">Turing Award</a> winner and one of the most influential researchers in modern AI. He played a major role in the development of deep learning and computer vision, founded Facebook AI Research, better known as FAIR, and later served as <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Meta&#8217;s Chief AI Scientist.</span></strong></p><p>In late 2025, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">LeCun left Meta and founded </span><a href="https://amilabs.xyz/"><span data-color="#00c853" style="color: rgb(0, 200, 83);">AMI Labs</span></a></strong>, short for Advanced Machine Intelligence. The company is developing systems designed to <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">understand the real world</span></strong>, retain memory, plan actions, and predict their consequences.</p><p>In March 2026, AMI Labs <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">raised more than $1 billion from investors</span></strong> including <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Nvidia, Bezos Expeditions, Samsung, Toyota Ventures, and Temasek.</span></strong></p><div class="callout-block" data-callout="true"><p><em>When a team leaves a large corporation to create an independent company, the process is often described as a <a href="https://en.wikipedia.org/wiki/Corporate_spin-off">corporate spin-off</a>. Sometimes the original corporation later acquires the start-up or brings the team back through an acquihire. Whether AMI Labs will follow that path remains unknown.</em></p></div><p>But the underlying bet is clear.</p><p>Investors have placed <a href="https://amilabs.xyz/updates">more than $1 billion</a> on the <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">idea that AI can predict possible futures</span></strong> by building an internal model of the world &#8212; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">a kind of Matrix.</span></strong></p><p>Inside this digital reality, AI could calculate what happens if a robot moves an object, an industrial machine changes speed, or an autonomous agent performs a sequence of actions.</p><p>Today&#8217;s AI predicts the next word. AMI Labs wants<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> to build AI that predicts what happens next</span></strong> in the real world.</p><p></p><h2>&#129001; From Language Models to Autonomous AI</h2><p>Modern language models can write contracts, code, articles, and scripts. They can even create the impression of a meaningful conversation. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But they do not understand the physical world.</span></strong> They can describe reality without actually <em>&#8220;seeing&#8221;</em> it.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A child learns differently.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>A child watches, moves, touches objects, falls, breaks things, and observes the consequences. This is how a child learns that a glass can shatter and that a moving object cannot stop instantly.</p><p>The next stage of AI development will not be based on language alone. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It will involve </span><a href="https://en.wikipedia.org/wiki/World_model_(artificial_intelligence)"><span data-color="#00c853" style="color: rgb(0, 200, 83);">world models</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);">.</span></strong></p><p>A world model is an internal representation that allows an AI system <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">to predict how an environment may change after a particular action.</span></strong></p><div class="callout-block" data-callout="true"><p><em>This would be a kind of Matrix in which AI could simulate events, compare possible actions, and calculate their consequences. A situation could be paused, rewound, or fast-forwarded to see where a particular decision might lead.</em></p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cU_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cU_j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cU_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:453527,&quot;alt&quot;:&quot;A world model predicts an event&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206361304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A world model predicts an event" title="A world model predicts an event" srcset="https://substackcdn.com/image/fetch/$s_!cU_j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!cU_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1ef4dff6-0447-4507-8fdb-bdb03329668b_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A language model predicts a word. A world model predicts an event.</p><p></p><h2>&#129001; What Are AI World Models?</h2><p>A world model would learn from events in the real world through video, images, sensor data, and information about the movement of physical objects.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Its purpose would be to predict what happens after a particular action.</span></strong></p><p>These systems could understand space, plan actions, and assess consequences before they occur. Combined with robotics and autonomous agents, they could <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">move artificial intelligence from passive content generation into active participation</span></strong> in the physical world.</p><div class="callout-block" data-callout="true"><p><em>Imagine that a world model knows your health status, daily routine, location, habits, and what is happening around you. It could advise you whether to leave home, which route to take, and how likely you are to encounter danger.</em></p></div><p>It would not literally see the future. But the more data it receives, the more persuasive its predictions may become. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">At some point, people may begin treating an algorithmic forecast as if it were an inevitable event.</span></strong></p><p>The next wave of autonomous AI may be driven by robots, drones, medical equipment, autonomous vehicles, and systems that manage critical infrastructure.</p><p>These technologies will be built to create a safer and more predictable &#8212; supposedly <em>&#8220;perfect&#8221;</em> world.</p><p>But if a system knows too much, constantly <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">calculates our behaviour, and decides which choices are safe or correct</span></strong>, people may gradually lose their freedom to choose.</p><p>A world designed to protect us <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">could become a human Matrix</span></strong> in which every move has already been calculated by an algorithm.</p><p></p><h2>&#129001; When AI Starts to Act</h2><p>Today, AI analyses data, creates text, produces images, and generates realistic video.</p><p>Its output is still largely passive and, in a sense, <em>&#8220;two-dimensional.&#8221;</em> The system creates something, and a human decides what to do with it. <a href="https://abnormal.ai/glossary/autonomous-ai">Autonomous AI</a> could change that model.</p><div class="callout-block" data-callout="true"><p><em>These systems may be able to construct and execute sequences of actions based on mathematical calculations, sensor data, and experience of the physical world. They will not merely recommend a decision. They may carry it out without asking for human approval at every stage.</em></p></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That creates an entirely new level of risk.</span></strong></p><p>An error in an AI-generated text is one thing. A synthetic system making decisions that affect someone&#8217;s life, safety, or future is something else entirely.</p><p>This is why <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">autonomous AI governance</span></strong> cannot focus only on outputs, transparency, or content labelling.</p><p>It must also address what the system is authorised to do.</p><p></p><h2>&#129001; AI Regulation Must Focus on Authority</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">One AI system may only provide information. Another may recommend a decision. A third may make decisions and take action independently.</span></strong></p><p>The level of risk therefore depends not only on the model itself, but also on the authority it has been given.</p><p>AI regulation should define which technical actions a system may perform and under what circumstances it may act without human approval. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This must become a core part of AI risk management.</span></strong></p><p>Companies need to know not only which model they are using, but also which tools it can access, which systems it can control, and what consequences its actions may produce.</p><p>The real regulatory target is no longer artificial intelligence as an abstract concept. It is AI&#8217;s access to the real world and its ability to affect it.</p><p></p><h2>&#129001; The Matrix Must Have Boundaries</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Every autonomous AI system must have limits.</span></strong></p><p>When it opens another door, there <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">must eventually be a brick wall</span></strong> behind it that it cannot bypass.</p><div class="callout-block" data-callout="true"><p><em>Each system should have a clearly defined task, a limited area of operation in the physical or digital world, a specific set of available tools, and a clear list of prohibited actions.</em></p></div><p>At a critical moment, it must stop acting independently and hand control back to a human.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">These boundaries must not exist only in internal policies.</span></strong> They should be built into the technical design of the system.</p><p>But our experience with language models shows that<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> people quickly become accustomed to convenience.</span></strong> They stop checking the output and gradually hand more control to the machine.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CH9x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CH9x!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CH9x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/de45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:752029,&quot;alt&quot;:&quot;In practice, they begin following the system&#8217;s recommendations automatically&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206361304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="In practice, they begin following the system&#8217;s recommendations automatically" title="In practice, they begin following the system&#8217;s recommendations automatically" srcset="https://substackcdn.com/image/fetch/$s_!CH9x!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!CH9x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fde45b9d6-8453-4de5-86e3-cc69429b3a90_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The human remains in charge on paper. In practice, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">they begin following the system&#8217;s recommendations automatically.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The core principle should therefore be simple:</span></strong> AI must not exceed its authority and must remain under meaningful human control.</p><p>Similar requirements are already appearing in <strong>European law</strong>. <strong><a href="https://eur-lex.europa.eu/eli/reg/2023/1230/oj/eng"><span data-color="#00c853" style="color: rgb(0, 200, 83);">Regulation (EU) 2023/1230 on machinery</span></a></strong> entered into force on 19 July 2023, while most of its provisions will <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">apply from 20 January 2027</span></strong>.</p><div class="callout-block" data-callout="true"><p><em>The Regulation provides that control systems with fully or partially self-evolving behaviour must not cause machinery to perform actions beyond its defined task and operating space. Human intervention and the safe stopping of machinery must also remain possible.</em></p></div><p></p><h2>&#129001; The Matrix Needs a Black Box</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Like an aircraft, every autonomous AI system should have its own </span><a href="https://artificialintelligenceact.eu/article/12/"><span data-color="#00c853" style="color: rgb(0, 200, 83);">black box</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);">.</span></strong></p><p>When a system makes a mistake, it must be possible to reconstruct the entire sequence of events. Logging will therefore become one of the central elements of AI governance.</p><div class="callout-block" data-callout="true"><p><em>Logs are likely to become a primary source of evidence for regulators, courts, insurers, and technical experts investigating disputes involving autonomous systems.</em></p></div><p>They should record the model version, the assigned task, the available data and tools, the actions performed, and every significant interaction between the system and a human operator.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">They should also show why a particular operation was continued or stopped.</span></strong></p><p><strong><a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026"><span data-color="#00c853" style="color: rgb(0, 200, 83);">The EU AI Act</span></a></strong> already requires automatic record-keeping for high-risk AI systems.</p><p>Autonomous models interacting with the physical world will require a much more detailed standard. Their logs must <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">show not only the final outcome, but also the full chain </span></strong>of decisions and actions that produced it.</p><p>Without such a black box, identifying the cause of an error and allocating responsibility will be extremely difficult.</p><p></p><h2>&#129001; Human Oversight Must Mean Real Control</h2><p>When a company claims that a human remains involved in decision-making, that involvement <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">must not be merely formal.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A specific employee should be responsible for monitoring the autonomous system.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>That person should receive alerts about important actions and have the power to approve an operation, stop the process, or prohibit a particular action entirely.</p><p>This is only possible when the employee understands the system&#8217;s capabilities and limitations. They must know when the AI can be trusted and when its decision must be challenged or reversed.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The problem is that there are currently too few specialists with that level of expertise. </span></strong>A human should not simply sit next to the system and be treated as formally responsible. They must retain real authority over it and have the technical ability to intervene.</p><p>At the same time, human oversight <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">must not become mindless button-pushing</span></strong>, with an employee automatically approving hundreds of decisions they do not understand.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Real oversight means having the ability to understand, challenge, and stop the system.</span></strong></p><p></p><h2>&#129001; Test Scenarios, Not Just Answers</h2><p>A language model can be tested with benchmark tasks and carefully designed prompts. An autonomous system <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">must be tested in both real and simulated scenarios.</span></strong></p><div class="callout-block" data-callout="true"><p><em>We need to understand how it behaves during an emergency, whether it can stop safely when a threat appears, and whether its behaviour changes after an update. These checks must be continuous, not limited to the period before a product enters the market.</em></p></div><p>Every update, configuration change, expansion of authority, or connection to a new tool may introduce new risks. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Cybersecurity must also be part of the assessment</span></strong>, especially when an autonomous agent can access infrastructure, financial systems, personal data, or physical equipment.</p><p>A serious AI risk management process must therefore include continuous testing, monitoring, incident reporting, and reassessment.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Large numbers of specialists will be needed to test, evaluate, and supervise these systems.</span></strong></p><p>They will also have to keep learning throughout their careers, because the technology will change faster than the instructions governing its use.</p><p></p><h2>&#129001; Who Will Be Responsible for the Matrix?</h2><p><strong><a href="https://www.dzhamal.net/about"><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI liability</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);"> will become one of the most difficult legal questions.</span></strong></p><div class="callout-block" data-callout="true"><p><em>One company may build the model, another may integrate it into equipment, a third may provide the infrastructure, a fourth may configure it, and a fifth may deploy it in the real world.</em></p></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Responsibility cannot therefore be placed entirely on the developer or entirely on the user.</span></strong></p><p>Future liability rules will need to consider who defined the system&#8217;s purpose, who gave it access to data and tools, who set the limits of its capabilities, and who controlled the risks.</p><p>Separate liability may arise for a person or company that had the power to stop the system but failed to do so. The updated <strong><a href="https://eur-lex.europa.eu/eli/dir/2024/2853/oj/eng"><span data-color="#00c853" style="color: rgb(0, 200, 83);">EU Product Liability Directive</span></a></strong> already covers software and AI systems.</p><p>An AI developer or provider may be treated as a manufacturer. Liability may extend to defects arising from updates, upgrades, or continued learning when those processes remain under the manufacturer&#8217;s control.</p><p>However, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">liability does not arise automatically after every update.</span></strong> It is still necessary to establish a defect, actual damage, a causal link, and which party controlled the system.</p><p>When another party makes a substantial modification after the product has entered the market, that party may become responsible if it places the modified system back on the market. Even these rules <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">may prove insufficient for autonomous AI.</span></strong></p><p>Additional measures may be needed, including mandatory liability insurance, financial guarantees, and a clear allocation of responsibility between developers, integrators, operators, and deployers.</p><p></p><h2>&#129001; Europe&#8217;s Role in Regulating Autonomous AI</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Europe is already building the foundations of autonomous AI governance.</span></strong></p><p>The <strong><a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026"><span data-color="#00c853" style="color: rgb(0, 200, 83);">EU AI Act</span></a></strong> introduces requirements relating to risk management, documentation, logging, transparency, and human oversight of high-risk systems.</p><p>The <strong><a href="https://eur-lex.europa.eu/eli/reg/2023/1230/oj/eng"><span data-color="#00c853" style="color: rgb(0, 200, 83);">EU Machinery Regulation</span></a></strong> addresses the safety of autonomous equipment, the limits of its operation, human intervention, and the ability to stop a process safely.</p><p>For now, however, these rules remain separate. In the future, AI regulation, product safety law, machinery regulation, cybersecurity requirements, and product liability rules will have to be connected and continuously updated.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI is developing too quickly.</span></strong></p><p>By the time a robot appears in almost every home, there may still be no comprehensive legal framework capable of governing everything it can do.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Legal futurism in AI governance</span></strong> is therefore not speculation about a distant future. It is an attempt to create rules today that may one day protect our entire world.</p><p></p><h2>&#129001; What Companies Should Do Now</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Companies do not need to wait for fully autonomous AI before preparing for it.</span></strong></p><p>They should already <strong><a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026?open=false#%C2%A7ai-watermarking-and-c2pa-metadata-content-credentials-and-ai-content-detection"><span data-color="#00c853" style="color: rgb(0, 200, 83);">map which AI systems they use</span></a></strong>, what data and tools those systems can access, which decisions they influence, and who has the authority to stop them.</p><p>They should also define operational limits, retain meaningful logs, test emergency scenarios, assign clear human responsibility, and determine how liability is divided between developers, integrators, operators, and deployers.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This is the practical foundation of autonomous AI governance.</span></strong></p><p>The technology may still be developing, but the control structure should not begin after the first serious failure.</p><p></p><h2>&#129001; Who Controls the Matrix?</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">No one knows whether Yann LeCun&#8217;s bet will succeed exactly as he expects.</span></strong></p><p>But the direction of travel is already clear. Future autonomous AI systems are likely to combine language models, sensors, planning, reasoning, and physical action.</p><p>Artificial intelligence is becoming less <em>&#8220;two-dimensional.&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!clb3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!clb3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!clb3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!clb3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!clb3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!clb3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:777906,&quot;alt&quot;:&quot;It is no longer simply a typewriter that produces text on command. It is gradually turning into something closer to a PlayStation&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206361304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="It is no longer simply a typewriter that produces text on command. It is gradually turning into something closer to a PlayStation" title="It is no longer simply a typewriter that produces text on command. It is gradually turning into something closer to a PlayStation" srcset="https://substackcdn.com/image/fetch/$s_!clb3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!clb3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!clb3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!clb3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8499c0e-fddb-4ae5-95f3-80bb51eb5237_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="callout-block" data-callout="true"><p><em>It is no longer simply a typewriter that produces text on command. It is gradually turning into something closer to a PlayStation: a complete environment with multiple scenarios and the ability to interact with the world.</em></p></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">We need to start building the rules for this machine today. </span></strong>Otherwise, tomorrow we may be left behind with technically perfect legislation designed for yesterday&#8217;s technology.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Today, the main question is:</span></strong> <em>&#8220;Was this text created by AI?&#8221;</em></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Tomorrow, the question will be different:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><em>&#8220;Who authorised the AI to act? Within what limits? And who had the power to stop it?&#8221;</em></p><p>The task is not to predict the exact date when <em>&#8220;real&#8221;</em> artificial intelligence will arrive.</p><p>The task is to build the system that will control it.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The world has changed.</span></strong></p><p style="text-align: center;"><a href="https://www.dzhamal.net/about">Dzhamal Statsenko</a> is a lawyer and AI governance consultant writing about European AI regulation, accountability, and the risks of autonomous systems.</p><p style="text-align: center;"><span>See you in the next piece.</span><br><br><span>Cheers,</span></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EcIR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EcIR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EcIR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206361304?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EcIR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!EcIR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1183bd4c-7fb5-428e-9b7b-bd3673554f40_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"></p>]]></content:encoded></item><item><title><![CDATA[GPT-5.6 and the End of AI’s Belle Époque: The New Battle for AI Control]]></title><description><![CDATA[The release of GPT-5.6 shows how AI governance is becoming a struggle between U.S. power, European regulation, corporate control, and public oversight.]]></description><link>https://www.dzhamal.net/p/ai-control-us-europe-regulation</link><guid isPermaLink="false">https://www.dzhamal.net/p/ai-control-us-europe-regulation</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Wed, 08 Jul 2026 20:44:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9XZB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9XZB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9XZB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9XZB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1171472,&quot;alt&quot;:&quot;GPT-5.6 and the new battle for AI control, showing the shift from model performance to AI governance and regulation.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206180652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="GPT-5.6 and the new battle for AI control, showing the shift from model performance to AI governance and regulation." title="GPT-5.6 and the new battle for AI control, showing the shift from model performance to AI governance and regulation." srcset="https://substackcdn.com/image/fetch/$s_!9XZB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!9XZB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a8dea17-34f2-43ab-a12c-1727d11152eb_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Table of Contents:</span></mark></strong><br><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/the-american-approach-ai-regulation-through-power-not-law">U.S. AI Regulation: Power Over Law</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/coding-biology-and-cybersecurity-why-ai-safety-is-no-longer-optional">Why AI Safety Now Matters</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/openai-is-building-ai-model-governance-from-the-inside">OpenAI&#8217;s Internal AI Governance</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/who-should-control-ai">Who Should Control AI?</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/the-new-american-control-model">The New U.S. Control Model</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/competition-between-ai-companies">AI Competition: Speed vs Safety</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/from-model-power-to-governance-power">From Better Models to Better Governance</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/what-this-means-for-business-ai-compliance-is-infrastructure">AI Compliance for Business</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/the-european-context-ai-policy-through-law">Europe&#8217;s AI Policy Through Law</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/206180652/main-conclusion">Conclusion: The Battle for AI Control</a></p><p>The real question is no longer which AI model is stronger. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The real question is who controls it.</span></strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lawyer Against The Machine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That is the divide now emerging between the American and European approaches to AI regulation &#8212; and GPT-5.6 makes it impossible to ignore.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">On 8 July, OpenAI unveiled GPT-5.6.</span></strong> But this was not just another model launch. It was a signal that the AI debate has entered a new phase.</p><p>For years, every major AI release was treated as a technical race. People asked whether the new model was more powerful, faster, cheaper, more convenient, better at coding, better at reasoning, or better at passing benchmarks.</p><p>That era is ending.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Now the central questions are different.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>Who controls the model? Who decides when it can enter the market? Under what conditions does it become available to users? Who defines acceptable risk? And who regulates its public use?</p><p>GPT-5.6 is not only a product release. It is a case study in the new politics of AI governance, AI safety, and AI control.</p><p></p><h2>&#129001; The American Approach: AI Regulation Through Power, Not Law</h2><p>The U.S. government was actively involved in the release of GPT-5.6. OpenAI eventually brought the model to market, but before doing so, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the company spent a long time working through the issue with the federal government in a hands-on, ad hoc process.</span></strong></p><p>This matters.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aezi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aezi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!aezi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!aezi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!aezi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aezi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3fae9b17-d557-4130-ad75-39908413c606_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1188197,&quot;alt&quot;:&quot;U.S. AI regulation through government negotiations, national security concerns, and closed-door AI oversight.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206180652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="U.S. AI regulation through government negotiations, national security concerns, and closed-door AI oversight." title="U.S. AI regulation through government negotiations, national security concerns, and closed-door AI oversight." srcset="https://substackcdn.com/image/fetch/$s_!aezi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!aezi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!aezi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!aezi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3fae9b17-d557-4130-ad75-39908413c606_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">U.S. law does not require a special licence or formal approval to release this kind of AI model.</span></strong> Legally, OpenAI did not need to obtain <em>&#8220;permission&#8221;</em> from the government. But when money, power, and AI national security are involved, formal legal requirements are rarely the whole story.</p><p>This episode shows that the <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">United States already sees powerful AI models not merely as commercial products,</span></strong> but as technologies capable of affecting national security.</p><p>And frankly, that concern is justified.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This is where the contrast with Europe becomes clear.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The United States has effectively chosen manual AI regulation:</span></strong> closed consultations, negotiations, testing, and direct interaction between government officials and the company.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The European Union has taken a different path.</span></strong> Europe does not currently have frontier AI companies with the same global scale, infrastructure, and market power as the leading U.S. players. In that sense, Europe is more a consumer of foreign AI products than the main producer of them.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That is why the EU has chosen legal AI regulation:</span></strong> the <a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026">AI Act</a>, formal obligations, documentation, transparency, risk assessment, AI compliance, and oversight.</p><p>Put simply, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the United States regulates AI through political and administrative power. </span></strong>Europe regulates AI through law.</p><p></p><h2>&#129001; Coding, Biology, and Cybersecurity: Why AI Safety Is No Longer Optional</h2><p>GPT-5.6 is not just a text model for writing articles, emails, or short answers. Models of this kind have moved far beyond text.</p><p>They are about programming, agentic tasks, cybersecurity, vulnerability discovery, automated analysis, and <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">potentially even the creation of prohibited substances or biological weapons.</span></strong></p><p>This is where the dual-use problem becomes unavoidable.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The same model can be useful and dangerous at the same time.</span></strong> It can help security specialists write patches, detect vulnerabilities, and protect systems. But similar capabilities can also be used in the opposite direction: <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">to identify weaknesses, automate attacks, or lower the barrier to dangerous knowledge.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Biology is another example.</span></strong> AI can support medicine, research, diagnostics, and drug development. At the same time, these technologies can be used for dangerous purposes if access is not controlled.</p><p>That is why the old argument that <em>&#8220;it is just a tool&#8221;</em> is becoming less convincing.</p><p>The more powerful the model becomes, the less it looks like ordinary software and the more it resembles a strategic resource. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I would not call AI a weapon. It is a new kind of resource.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>Its power is not limited by how much of it exists on the planet, but by how effectively and safely society can use it.</p><p>In the right hands, such a resource can be medicine. In the wrong hands, it can become a problem.</p><p>This is why AI safety can no longer be treated as a decorative layer added after launch. It is becoming a condition for access, legitimacy, and control.</p><p></p><h2>&#129001; OpenAI Is Building AI Model Governance From the Inside</h2><p>OpenAI is trying to manage risk inside the company itself. It does this through model restrictions, safety mechanisms, request monitoring, access levels, and internal security procedures.</p><p>In other words, OpenAI is not simply building a model. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It is building an entire control infrastructure around the model.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This is already a form of AI model governance.</span></strong> The company decides how the model behaves, who can access certain capabilities, which requests are blocked, which risks are monitored, and which users or use cases receive more trust.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But that raises the main question: who decides that the model is safe enough?</span></strong></p><p>In the United States, this is effectively decided through interaction between OpenAI and the government. A significant part of <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">that process takes place behind closed doors:</span></strong> without broad public access, without independent journalists, without civil society, and without external experts having real influence.</p><p>Society receives the finished product, but has almost no influence over how that product was tested, which risks were considered acceptable, and why the model was allowed into public use in the first place.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Europe has chosen a different path:</span></strong> protection through legal regulation. But Europe faces another problem. It is extremely difficult to regulate a system you do not fully understand.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI moves faster than legislation.</span></strong> That means there is a real risk that the law becomes outdated before it is even fully applied.</p><p></p><h2>&#129001; Who Should Control AI?</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">At the moment, many of the most important decisions are made by the company itself.</span></strong></p><p>OpenAI decides which risks are acceptable, which requests should be blocked, who receives access, which features should be restricted, which scenarios are dangerous, and which are permissible.</p><p>Yes, the company has expertise. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But the company also has a commercial interest.</span></strong> Its decisions can be influenced by investors, corporate clients, politicians, government agencies, competitors, and the market.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">From society&#8217;s point of view, this creates a serious imbalance.</span></strong></p><p>Society did not choose for AI of this scale to become part of everyday life. But now it is forced to live in a world where these models already influence business, education, media, security, politics, and access to information.</p><p>This is the missing layer in current AI governance: real AI oversight that is independent, technically competent, and not captured by either governments or corporations.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qi6b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qi6b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qi6b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1459505,&quot;alt&quot;:&quot;European AI regulation through the AI Act, compliance duties, transparency, risk assessment, and legal oversight.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206180652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="European AI regulation through the AI Act, compliance duties, transparency, risk assessment, and legal oversight." title="European AI regulation through the AI Act, compliance duties, transparency, risk assessment, and legal oversight." srcset="https://substackcdn.com/image/fetch/$s_!Qi6b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Qi6b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76ea7f80-7744-44df-bf44-10ff0e761e01_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In my view, the only logical long-term solution is the<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">creation of an independent supervisory body.</span></strong> Such a body must be technically competent enough to understand the technology and independent enough to protect society from abuse by both governments and commercial companies.</p><p>Perhaps such a body will be created one day. Until then, we risk remaining puppets in the hands of Big Brother.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For now, the situation looks very different.</span></strong> Governments and corporations have obtained a new strategic resource, but they do not yet fully understand its <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">long-term consequences.</span></strong></p><div class="callout-block" data-callout="true"><p><em>It resembles the moment when the Spanish brought enormous amounts of gold from the New World to Europe, without understanding that this resource could transform the economy and lead to serious consequences.</em></p></div><p>Something similar may happen with AI. The technology looks like a source of power, profit, and influence. But if it is integrated into society incorrectly, it can create systemic risks.</p><p></p><h2>&#129001; The New American Control Model</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The American approach does not require a mandatory licence to release an AI model.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>Instead, a voluntary system of interaction between the government and developers is emerging.</p><p>This may include preliminary government access to certain frontier models, testing, risk assessment, and national security consultations.</p><p>This is not strict regulation in the classical sense. But it is no longer a completely free market either.</p><p>The company is effectively cooperating with government bodies. That makes it difficult to predict what the next wave of AI releases will look like a year from now &#8212; especially because <a href="https://openai.com/uk-UA/index/previewing-gpt-5-6-sol/">OpenAI&#8217;s products</a> are used not only in the United States, but also in Europe, Asia, Africa, and other regions.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For other countries, this is also an AI national security problem.</span></strong> If a foreign AI product is used inside a country, it can potentially influence elections, political attitudes, the information environment, public health, education, data security, and critical systems.</p><p>That is why states will increasingly consider restrictions, controls, or localisation requirements for foreign AI products.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI has long since become a strategic technology.</span></strong> Future model releases will not be discussed only as technological events. They will be governance events.</p><p></p><h2>&#129001; Competition Between AI Companies</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">There is another factor: competition.</span></strong></p><p>While one company goes through checks, negotiates with the government, and delays its release, competitors may bring their models to market faster.</p><p>For example, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Elon Musk&#8217;s xAI may use release speed as a competitive advantage.</span></strong> If OpenAI negotiates with the government for months, while another player completes the process in weeks, that player gains an advantage in publicity, users, and profit.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This creates a direct tension between AI safety and speed.</span></strong></p><p>Powerful models must be tested. But the market does not like waiting. It pressures companies to release faster. If one company becomes too cautious, another can take its place.</p><p>That means AI regulation does not only affect safety. It also affects competition.</p><p></p><h2>&#129001; From Model Power to Governance Power</h2><p>In the past, AI companies mainly competed over whose model was better. That is no longer enough.</p><p>The winner will not simply be the company that builds the most powerful model. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The winner will be the company that can scale AI safely, quickly, and predictably.</span></strong></p><p>Companies now need to improve not only the models themselves, but also the governance systems around them: access, control, security, monitoring, compliance, documentation, interaction with government, and risk management.</p><p>This is the new frontier of AI model governance.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The problem is that the regulatory framework either does not exist or becomes outdated almost immediately. </span></strong>And if lawmakers want to regulate AI effectively, they first need to understand the technology deeply.</p><p>Without that, regulation becomes formal, delayed, and weak.</p><p></p><h2>&#129001; What This Means for Business: AI Compliance Is Infrastructure</h2><p>For business, this story means that AI tools can no longer be selected only by price or response quality.</p><p>Companies now need to ask harder questions.</p><p>What data is transferred to the model? Who has access to that data? How is it logged? Where is it stored? What restrictions does the provider impose? How often do the rules of use change? What guarantees does the provider give? Can the provider maintain access to the model after new negotiations with the government or regulator? How could future releases affect the company&#8217;s operations?</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI is becoming part of the infrastructure of almost every organisation.</span></strong></p><p>Dependence on an external AI provider is no longer just a technical issue. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It is a question of business resilience</span></strong>, AI compliance, security, and strategic planning.</p><p>This is where AI risk management becomes practical. It is no longer enough to ask whether a tool works. A company must understand how the tool is governed, what risks it creates, how those risks are monitored, and <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">what happens when the provider changes the rules.</span></strong></p><p>For businesses, AI control is now part of operational control.</p><p></p><h2>&#129001; The European Context: AI Policy Through Law</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Europe follows a formal approach through the </span><a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026"><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI Act</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);">.</span></strong> This approach is built around documentation, transparency, risk assessment, cybersecurity, labelling, oversight, and the responsibility of providers, suppliers, and users.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It is a legalistic approach.</span></strong> Europe is trying to build a system of rules before the technology fully escapes control.</p><p>But the problem is obvious: AI develops too quickly. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A law written today may already be insufficient tomorrow.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The United States and the European Union are taking different paths</span></strong>, but they are reaching the same general conclusion: powerful AI models can no longer be treated as ordinary software.</p><p>The United States is relying on flexibility, voluntary interaction with government, and national security. But this approach is too closed and too administrative.</p><p>The EU is relying on legal certainty, documentation, oversight, AI compliance, and responsibility. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But this approach may be too slow for a technology that changes faster than legislation.</span></strong></p><p>Neither the American nor the European model looks ideal.</p><p>In my view, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">the most logical solution would be an external independent AI regulator.</span></strong> Not just another bureaucratic office, but a technically competent institution capable of responding quickly to change, understanding real risks, and controlling the use of AI by both governments and private companies.</p><p></p><h2>&#129001; Main Conclusion</h2><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI governance is no longer a theoretical topic. It is a practical necessity.</span></strong></p><p>Organisations must control not only what AI generates. They must also consider risks connected with model access, data, future releases, dependence on providers, changing rules, and government intervention.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7EBj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7EBj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7EBj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1100098,&quot;alt&quot;:&quot;Abstract visual of frontier AI governance, showing how GPT-5.6 shifts the debate from model performance to regulation, safety, and control.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206180652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Abstract visual of frontier AI governance, showing how GPT-5.6 shifts the debate from model performance to regulation, safety, and control." title="Abstract visual of frontier AI governance, showing how GPT-5.6 shifts the debate from model performance to regulation, safety, and control." srcset="https://substackcdn.com/image/fetch/$s_!7EBj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!7EBj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4697467-11b1-4235-bbb1-070cc3d18d8a_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.dzhamal.net/p/eu-ai-act-2026-checklist"><span data-color="#00c853" style="color: rgb(0, 200, 83);">For companies</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);">,</span> AI is a question of infrastructure, security, AI risk management, and predictability.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For governments,</span></strong> AI is a question of control, national security, and influence.</p><p>The main question is no longer which model is stronger.</p><p>The main question is <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">who decides which model becomes available to the world, under what conditions, and how predictably that access will expand.</span></strong></p><p></p><p style="text-align: center;"><span data-color="#00c853" style="color: rgb(0, 200, 83);">I will continue writing about this in plain language.</span></p><p style="text-align: center;"><span>See you in the next piece.</span><br><br><span>Cheers,</span></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wedi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wedi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!wedi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!wedi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!wedi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wedi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/206180652?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wedi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!wedi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!wedi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!wedi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcada308-0f97-4c3c-b1fc-4987a479f3a3_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"><span><br></span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lawyer Against The Machine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Compliance for NGOs: How the EU AI Act Changes Nonprofit Work]]></title><description><![CDATA[Many nonprofits use AI for grants, translations, social media and public communication. After the EU AI Act, &#8220;use it carefully&#8221; is no longer enough.]]></description><link>https://www.dzhamal.net/p/eu-ai-act-for-ngos</link><guid isPermaLink="false">https://www.dzhamal.net/p/eu-ai-act-for-ngos</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Tue, 07 Jul 2026 19:17:54 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/587049b6-4810-4e84-852d-cd8d59c4808c_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A few days ago, an NGO contacted me with a question:<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">what should they do about the AI Act</span></strong> if they are not a technology company, but already use AI in their daily work?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vwjz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vwjz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vwjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1001442,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/205911357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vwjz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!vwjz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2a3dca85-0b6a-40ed-b23a-902c515ae7e3_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I am publishing my reply.</span></strong></p><div><hr></div><p>Dear Mr. ***,</p><p>In your situation, I would not recommend treating the AI Act as a law that applies only to large technology companies. That is a common mistake.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Yes, your organisation does not develop its own AI system</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">.</span> However, if you use AI in your work &#8212; for example, to prepare texts, translations, social media content, grant applications, educational materials, volunteer selection, or to process incoming requests &#8212; <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">you may still qualify as a deployer</span></strong>. In other words, you may be regarded as an organisation that uses an AI system under its own responsibility.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For an NGO, this is particularly important.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">First, your organisation probably faces the same reality as many NGOs: limited budgets, small teams, and too many urgent tasks.</span></strong> That is why AI can look very attractive. It can help you prepare grant applications faster, translate documents, draft publications, respond to people, create presentations, and automate routine work.</p><p>But this is exactly why you need to be especially careful. AI should not become an <em>&#171;invisible employee&#187;</em> whom nobody supervises.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Second, NGOs often work with vulnerable groups:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>refugees, migrants, children, elderly people, people with low income, victims of violence, or individuals who depend on accurate information on important matters. An AI mistake in this context is not just a badly written text. It can become incorrect advice, a lost opportunity, a denial of assistance, or a serious loss of trust in your organisation.</p><p>That is why simply telling staff to <em>&#8220;use AI carefully&#8221;</em> is no longer enough.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I would recommend that you adopt an internal AI policy.</span></strong> This policy should describe which AI tools your organisation uses, who is allowed to use them, what data must not be uploaded into AI systems, who reviews the output, and in which cases the use of AI must be specifically recorded.</p><p>I would also recommend appointing a <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">person within the organisation who is responsible for AI governance.</span></strong> This does not necessarily have to be a newly hired employee. However, there should be someone who understands where AI is being used in the organisation, what risks arise, who checks the materials, and where evidence of such review is kept.</p><p>Separately, I would conduct a <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">short training session for employees and volunteers.</span></strong> <br><br><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">They need to understand a few basic rules:</span></strong> sensitive personal data must not be uploaded without a proper legal basis; AI-generated text must not be published without review. AI must not be used for decisions that may affect a person&#8217;s access to assistance, services, education, work, or another important opportunity without a separate risk assessment.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">All texts created or substantially prepared with the help of AI should be reviewed by a human.</span></strong> This is especially important for legal information, social guidance, educational materials, public statements, materials intended for vulnerable groups, or texts concerning matters of public interest.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">And here, it is important to be precise: </span></strong>it is not enough to say, <em>&#171;we checked it&#187;</em>. It is better to record who reviewed the material, when it was reviewed, which sources were used, and what changes were made after the AI output was produced.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The same applies to images, audio, and video.</span></strong> If your organisation uses AI-generated or AI-manipulated visual, audio, or video content, especially in public communications, you should think about labelling and transparency in advance. In certain cases, the AI Act requires disclosure that content has been artificially generated or manipulated. For an NGO, this is not only a legal issue, but also a matter of trust.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I would pay special attention to grant applications.</span></strong> Many NGOs already use AI to prepare applications for subsidies and grants. In itself, this is not necessarily prohibited. However, you need to understand exactly how AI was used: did it only help structure the text, translate material, suggest wording, or did it effectively generate the substance of the application?</p><p>If a donor or grant provider requires disclosure of AI use, this should be done. If there is no such requirement, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I would still recommend having an internal protocol:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>who prepared the application, which AI tool was used, for which part of the work, who checked the facts, the budget, the impact data, the legal statements, and the final version.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For an organisation with ANBI status</span></strong>, this is particularly important from a reputational perspective. An NGO exists on the basis of trust: the trust of society, donors, partners, the state, and the people it serves. Coming under the attention of a regulator because of chaotic AI use is not only a sanctions risk. It is also a risk of losing public trust.</p><p>You should also separately assess whether any of your AI use falls into the high-risk category. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Not every use of AI by an NGO is high-risk.</span></strong> For example, using AI to draft a social media post is usually not the same as using AI to assess a person.</p><p>However, the risk becomes much higher if AI helps select candidates for employment or volunteer positions, allocate assistance, assess requests, prioritise cases, or influence access to education, social support, housing, consultation, or another important service.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">In such cases, you need more than just a manual check.</span></strong> You need proper control: competent human oversight, monitoring of the system&#8217;s operation, clear instructions, log retention, and the ability to demonstrate why a particular decision was made.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.dzhamal.net/subscribe?"><span>Subscribe now</span></a></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">As a minimum, I would recommend that your organisation:</span></strong></p><ol><li><p>prepare an AI inventory &#8212; a list of all AI tools used by the organisation</p></li><li><p>adopt an internal AI policy</p></li><li><p>appoint a person responsible for AI governance</p></li><li><p>train employees and volunteers</p></li><li><p>prohibit the upload of sensitive data without a separate legal basis</p></li><li><p>introduce mandatory human review for public-facing materials</p></li><li><p>keep a log of AI use in sensitive processes</p></li><li><p>separately assess high-risk scenarios</p></li><li><p>establish rules for labelling AI-generated content</p></li><li><p>retain evidence of review for at least six months, and for important processes, preferably longer</p></li></ol><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">My main advice is this:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>do not ban AI, but put it under control.</p><p>NGOs value AI because it saves time. That is understandable. But after the AI Act, the key question will be different: can your organisation prove that it controls the process?</p><p>If the answer is &#171;no&#187;, then the problem is not AI. The problem is the absence of governance.</p><p style="text-align: center;">Regards,<br>Dzhamal Statsenko</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w7_A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w7_A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w7_A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/205911357?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w7_A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!w7_A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F357ec71a-a738-42f1-bfad-4dee8b60ca4c_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div><hr></div><h2>Legal and regulatory framework to attach to the letter</h2><ol><li><p><strong>Regulation (EU) 2024/1689 &#8212; <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">Artificial Intelligence Act</a></strong></p></li><li><p><strong>Article 3 AI Act &#8212; <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">Definitions</a></strong></p></li><li><p><strong>Article 4 AI Act &#8212; <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4">AI literacy</a></strong></p></li><li><p><strong>Article 6 AI Act and Annex III &#8212; <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">High-risk AI systems</a></strong></p></li><li><p><strong>Article 26 AI Act &#8212; <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26">Obligations of deployers of high-risk AI systems</a></strong></p></li><li><p><strong>Article 27 AI Act &#8212; <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-27">Fundamental Rights Impact Assessment</a></strong></p></li><li><p><strong>Article 50 AI Act &#8212; <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50">Transparency obligations</a></strong></p></li><li><p><strong><a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice</a> on Transparency of AI-Generated Content</strong></p></li></ol>]]></content:encoded></item><item><title><![CDATA[EU AI Act 2026: What Companies Need To Do Before August]]></title><description><![CDATA[From 2 August 2026, important EU AI Act transparency rules will start applying across Europe.]]></description><link>https://www.dzhamal.net/p/eu-ai-act-2026-checklist</link><guid isPermaLink="false">https://www.dzhamal.net/p/eu-ai-act-2026-checklist</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Mon, 06 Jul 2026 15:03:20 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d64edd9e-6c11-4c9d-9f04-f469dd74bea4_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This matters <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">not only for companies based in the European Union</span></strong>. It also matters for companies outside the EU if they offer products, services, AI systems, or AI-generated content in the EU market.</p><p>The EU AI Act 2026 deadline is not just a legal date on paper. It is a practical warning for businesses: if your company uses AI, you need to know where it is being used, who is responsible for it, and whether people need to be told that they are interacting with AI.</p><p><strong>EU AI Act compliance starts with three questions:</strong></p><p>&#10068;Where do we use AI<br>&#10068;Who controls or deploys the AI system<br>&#10068;Do customers, users, employees, or the public need to know that AI is involved</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Here is a practical EU AI Act compliance checklist for 2026.</span></strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ed5N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ed5N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ed5N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:944910,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/205503196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ed5N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Ed5N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15e731dc-7ebb-4b48-9956-a2f00cbb1b65_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>1&#65039;&#8419; Identify where AI is already being used</h2><p>The first step is to look honestly at your business processes and answer a question:</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Where are we already using AI</span></strong></p><p>This may include chatbots, advertising, written content, images, videos, HR tools, customer support, legal drafts, reports, internal documents, translation tools, meeting summaries, analytics, or content creation.</p><p>Many companies think they do not use AI. In reality, AI may already be present in several departments.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span> </strong>a company says it does not use AI. But the marketing team creates images with an AI tool, customer support uses a chatbot, and HR screens CVs with the help of AI software. That company is already using AI. It is simply not managing it properly.</p><p>Before the AI Act August 2026 deadline, companies should hold an internal meeting, go through all key business processes, and record even minimal use of AI.</p><p></p><h2>2&#65039;&#8419; Define your role under the EU AI Act</h2><p>The EU AI Act does not treat every business in the same way. If your company creates an AI system and sells it to others, that is one level of responsibility.</p><p>If your company only uses someone else&#8217;s AI tool, that is another level of responsibility. But using someone else&#8217;s AI system does not mean there is no responsibility at all.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example: </span></strong>if a law firm uses ChatGPT or another AI tool to prepare draft documents, it did not create that AI system. But the law firm is still responsible for how it uses the output, whether the result is checked by a human, and whether the client is misled about the role of AI.</p><p>This is why EU AI Act compliance is not only a technical issue. It is also a governance issue.</p><p>Every company should know whether it acts as a provider, deployer, importer, distributor, product manufacturer, or simply as a business user of AI.</p><p></p><h2>3&#65039;&#8419; Tell people when they are interacting with AI: EU AI Act transparency obligations</h2><p>One of the most important AI Act transparency obligations for companies is disclosure. If a person is communicating not with a real employee, but with an AI chatbot or AI assistant, they should understand this.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A company should not pretend that a machine is a human being.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong> a website has a chatbot with a human name, a human photo, and a friendly conversational style. It answers like a member of staff. In that situation, the company should clearly tell users that they are interacting with an AI assistant.</p><p>This does not need to be dramatic. It can be simple:</p><blockquote><p><em>&#8220;You are chatting with an AI assistant.&#8221;</em></p></blockquote><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The main point is clarity.</span></strong> Users should not be tricked into believing they are speaking with a human when they are not.</p><p></p><h2>4&#65039;&#8419; AI Act transparency rules for AI-generated content</h2><p>The EU AI Act transparency rules also matter for AI-generated and AI-manipulated content. If a company creates written content, images, videos, voices, advertisements, reports, or public communications with the help of AI, it may need to clearly state that the content was created or modified by AI.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This may be done through a visible label, metadata, a watermark, a technical marker, or another method.</span></strong></p><p>The exact solution will depend on the type of content, the risk, the audience, and the context.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong> a brand publishes a realistic AI-generated image of a person holding its product. People may think it is a real photograph. They may believe that a real person was photographed for the campaign.</p><p>In that situation, the company should decide in advance whether a label such as <em>&#8220;created with AI&#8221;</em> or <em>&#8220;AI-generated image&#8221;</em> is needed.</p><p>AI labelling should not be decided at the last minute, after the campaign is already live. It should be part of the content creation process before publication.</p><p></p><h2>5&#65039;&#8419; Be especially careful with deepfakes</h2><p>Deepfakes are one of the clearest risk areas under the AI Act transparency obligations.</p><p>A deepfake is content where AI creates or changes a face, voice, photo, or video in a way that makes it look real. This is risky because people may believe that someone said or did something when they did not.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong> a company creates a video where a well-known person appears to recommend its product. Even if the company sees it as a joke, parody, or creative advertisement, viewers may believe the person really said it. In this situation, very clear labelling is needed.</p><p>If AI makes something fake look real, the disclosure must be obvious enough for people to understand what they are seeing.</p><p></p><h2>6&#65039;&#8419; Use AI carefully for matters of public interest</h2><p>Not every AI-generated text needs the same level of labelling or legal review. But if the content concerns important public issues, the risk is much higher.</p><p>This may include <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">politics, war, migration, health, public safety, elections, people&#8217;s rights, financial matters, education, or access to public services.</span></strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong> an AI-generated text about store discounts is one thing. An AI-generated text about refugee rights, elections, medical advice, or emergency rules is completely different. In those areas, a mistake may harm people.</p><p>For this reason, companies should treat public-interest AI content as a separate risk category.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Before publishing this type of content, they should check:</span></strong></p><p>&#10068;Is AI involved<br>&#10068;Was the output reviewed by a qualified human<br>&#10068;Could people rely on this information to make an important decision<br>&#10068;Does the content need an AI label or disclosure</p><p>This is where EU AI Act compliance connects directly with trust, reputation, and public responsibility.</p><p></p><h2>7&#65039;&#8419; GPAI and the Code of Practice</h2><p>The EU AI Act also includes rules for general-purpose AI models, often called GPAI. This is where the GPAI Code of Practice becomes relevant.</p><p>GPAI obligations mainly concern providers of general-purpose AI models. These are companies that develop or place powerful AI models on the market. For ordinary companies that only use AI tools, the situation is different.</p><p>A small business using a third-party AI writing tool is usually not the provider of a GPAI model. But this does not mean GPAI is irrelevant.</p><p><strong>Companies should still ask practical questions about the AI tools they use:</strong></p><p>&#10068;Does the supplier explain how the AI system works<br>&#10068;Does the tool support transparency and labelling<br>&#10068;Can the company keep records of AI-generated content<br>&#10068;Does the supplier provide documentation, terms, safety information, or compliance materials<br>&#10068;Does the tool make it possible to preserve metadata, watermarks, or other AI markers</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>a marketing agency uses an AI image generator for client campaigns. The agency may not be the provider of the underlying general-purpose AI model.</p><p>But it still needs to know whether the tool allows AI-generated content to be labelled, whether metadata is preserved, and whether the client can later prove how the content was created.</p><p>This is why the GPAI Code of Practice matters even for companies that are not AI developers.</p><p>It gives the market a practical direction: transparency, documentation, copyright awareness, safety, and accountability are becoming part of normal AI governance.</p><p></p><h2>8&#65039;&#8419; Do not assume that an AI policy is enough</h2><p>Many companies will respond to the EU AI Act by writing an AI policy. That is useful, but it is not enough. A document saying <em>&#8220;we use AI responsibly&#8221;</em> will not solve the problem by itself. Companies need evidence.</p><p><strong>They should be able to show:</strong></p><ul><li><p>which AI tool was used</p></li><li><p>who used it</p></li><li><p>what content or decision it helped create</p></li><li><p>who reviewed the output</p></li><li><p>where the content was published</p></li><li><p>why it was labelled or not labelled</p></li><li><p>what risk assessment was done</p></li><li><p>what human oversight existed</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example: </span></strong>a company launches an AI-generated advertising campaign. Six months later, a regulator, customer, journalist, or business partner asks questions. If the company cannot show who created the content, who checked it, and why there was no AI label, a general AI policy will not be enough.</p><p>EU AI Act compliance is not only about having a policy. It is about being able to prove what happened.</p><p></p><h2>9&#65039;&#8419; Check whether you use high-risk AI systems</h2><p>Some AI systems are treated more seriously because they can affect people&#8217;s lives, rights, opportunities, or access to essential services. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">This is the area of AI Act high-risk systems.</span></strong></p><p>High-risk AI may include systems used in employment, education, access to services, migration, law enforcement, safety, or other sensitive areas.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong> if a company uses AI to select job candidates, rank applicants, assess employees, or support promotion decisions, this is not just a productivity tool. It can affect a person&#8217;s career and income. </p><p>That is why this type of AI should be reviewed very carefully.</p><p><strong>Companies should ask:</strong></p><p>&#10068;Do we use AI in hiring or HR<br>&#10068;Do we use AI to evaluate people<br>&#10068;Do we use AI to make or support decisions about access to services<br>&#10068;Do we use AI in a regulated or sensitive sector<br>&#10068;Could the AI system affect someone&#8217;s legal position, rights, money, job, education, safety, or status</p><p>The phrase <em>&#8220;EU AI Act high risk&#8221;</em> should not be treated as abstract legal language.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For companies, it means this:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>if AI can seriously affect a person&#8217;s life, the compliance burden is higher.</p><p></p><h2>&#128287; EU AI Act penalties for non-compliance</h2><p>Companies should also understand the risk of penalties. EU AI Act penalties can be serious.</p><p>For certain violations, fines may reach up to EUR 15 million or up to 3% of the company&#8217;s total worldwide annual turnover, whichever is higher.</p><p>This does not mean that every mistake will automatically lead to the maximum fine. But it does mean that AI compliance can no longer be ignored.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Example:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>a small company launches an AI chatbot but does not tell people that they are speaking with AI. If the company has EUR 2 million in annual worldwide turnover, 3% equals EUR 60,000. This may be more than poor customer service. It may become a legal and financial problem.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Another example:</span></strong> a larger company publishes realistic AI-generated content in a sensitive public-interest area without proper review, labelling, or records. If the company has EUR 100 million in annual worldwide turnover, 3% equals EUR 3 million. But because EUR 15 million is higher, the possible maximum fine may reach EUR 15 million. If questions arise later, the company may need to explain not only what it published, but also how the content was created, reviewed, approved, and disclosed.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.dzhamal.net/subscribe?"><span>Subscribe now</span></a></p><h2>&#10071;&#65039;What companies should do now</h2><ol><li><p>Map where AI is used inside the business</p></li><li><p>Identify the company&#8217;s role and responsibility</p></li><li><p>Check whether users interact with AI systems</p></li><li><p>Review AI-generated content and labelling needs</p></li><li><p>Create rules for deepfakes and synthetic media</p></li><li><p>Treat public-interest content with special care</p></li><li><p>Check whether GPAI tools and suppliers provide enough documentation</p></li><li><p>Review whether any AI use may fall into high-risk AI systems</p></li><li><p>Keep evidence of AI use, human review, and publication decisions</p></li><li><p>Train staff before the rules become a problem</p></li></ol><p></p><p>You can find more detailed information in my full article: <a href="https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026"><span data-color="#00c853" style="color: rgb(0, 200, 83);">Up to &#8364;15 Million or 3% of Global Turnover: EU AI Act Compliance for AI-Generated Content in 2026</span></a></p><p style="text-align: center;">See you in the next piece.</p><p style="text-align: center;">Cheers,</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AqqA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AqqA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AqqA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/205503196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AqqA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!AqqA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17e023aa-6aa3-44fa-bcca-a8c3d88d6563_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p style="text-align: center;"></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Lawyer Against The Machine! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Up to €15 Million or 3% of Global Turnover: EU AI Act Compliance for AI-Generated Content in 2026]]></title><description><![CDATA[Article 50 of the EU AI Act brings new transparency obligations for AI-generated content in 2026, including AI labels, watermarking, deepfake disclosure, C2PA, compliance duties and fines up to &#8364;15 million or 3% of global turnover.]]></description><link>https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026</link><guid isPermaLink="false">https://www.dzhamal.net/p/eu-ai-act-article-50-ai-labels-2026</guid><dc:creator><![CDATA[Dzhamal Statsenko]]></dc:creator><pubDate>Sat, 04 Jul 2026 16:06:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2e6311b4-afb6-412a-a816-68a13866dd4c_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0zLj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0zLj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0zLj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1010249,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0zLj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!0zLj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe6d0ef74-6bb7-4eee-8514-46b46541ecec_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><mark data-color="#00c853" style="background-color: rgb(0, 200, 83); color: rgb(255, 255, 255);"><span data-color="#0b0f0d" style="color: rgb(11, 15, 13);">Table of Contents:</span></mark></strong><br><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/why-2026-will-be-a-turning-point-for-every-business-using-ai">Why 2026 Matters</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/article-50-of-the-eu-ai-act-transparency-obligations-in-plain-language">Article 50 Explained</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/eu-ai-act-2026-timeline-when-article-50-transparency-rules-apply">Key Dates and Timeline</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/eu-ai-act-fines-up-to-15-million-or-3-of-global-turnover-for-transparency-violations">Fines and Penalties</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/provider-vs-deployer-under-the-eu-ai-act-who-is-responsible-for-ai-content-labelling">Provider vs Deployer</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/code-of-practice-for-ai-generated-content-why-it-matters-even-if-it-is-voluntary">The AI Content Code of Practice</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/ai-generated-content-labels-metadata-watermarks-detection-tools-and-eu-icons">What AI Labelling Means</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/ai-watermarking-and-c2pa-metadata-content-credentials-and-ai-content-detection">Watermarks, Metadata and C2PA</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/deepfakes-under-the-eu-ai-act-where-the-disclosure-line-is-drawn">Deepfakes</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/ai-generated-advertising-and-marketing-the-most-tense-compliance-area">Advertising and Marketing</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/publishers-and-media-ai-generated-texts-on-matters-of-public-interest">Publishers and Media</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/eu-ai-act-compliance-checklist-what-businesses-should-do-before-2-august-2026">Business Compliance Checklist</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/open-questions-ai-watermarking-metadata-loss-and-the-grey-zone">Open Questions</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/main-conclusion-the-ai-label-is-the-beginning-of-ai-compliance">Main Conclusion</a><br>&#9643;&#65039;<a href="https://www.dzhamal.net/i/204532282/eu-ai-act-2026-faq-ai-labels-watermarking-fines-and-article-50">FAQ</a></p><p>In 2026, labels such as <em>&#8220;Made with AI&#8221;</em> or <em>&#8220;You are now interacting with AI&#8221;</em> will no longer be voluntary. You will be required to disclose this. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">If you fail to do so, your company may face a significant fine.</span></strong></p><p>The new EU law requires people to understand when they are interacting with AI or viewing content created by AI under Article 50 of the <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">EU Artificial Intelligence Act</a>, Regulation (EU) 2024/1689.</p><p>These rules will <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">start applying on 2 August 2026</span></strong>. For some AI systems that were already on the market before that date, a transitional period will apply until 2 December 2026.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>On paper, this looks like a serious attempt to tame a wild beast. In practice, it feels more like officials walking up to a giant killer whale with a sewing needle, a whistle, and a sign saying: &#8220;Please behave transparently.&#8221;</em></p><p><em>The law is trying to bring order to a world where AI has already learned how to write, speak, draw, fake faces, imitate voices, and produce content faster than a regulator can open a new PDF document.</em></p><p><em>We are being offered labels, watermarks, and disclosure rules. But the real question is different: will this stop the chaos, or will it simply create a new and expensive bureaucracy around AI? Below, I explain why I tend to believe the second option is more likely.</em></p></div><p><strong>&#128314;This will not simply be a </strong><em><strong>&#8220;created by AI&#8221;</strong></em><strong> label placed on an image. There will be many interesting new requirements.</strong></p><p>The new rules apply to the entire system of working with AI-generated content:</p><p>&#9643;&#65039;Developers of AI systems will have to redesign the internal architecture of their products<br>&#9643;&#65039;Businesses will have to change how they control content and services</p><p><strong>&#128314;Here are concrete examples of how this will work once the new rules enter into force:</strong></p><p>&#9643;&#65039;If a customer is interacting with AI, they must be informed of this, unless it is already obvious</p><p>&#9643;&#65039;If an AI system creates text, images, audio, or video, that content must be technically recognisable as having been created or modified by AI</p><div class="callout-block" data-callout="true"><p>&#128483; <em>According to the logic of the people who designed these rules, the ideal AI product must become slightly worse so that the state can feel safer.</em></p><p><em>Not too smooth. Not too invisible. Not too convenient.</em></p><p><em>It must come with labels, signals, warnings, and traces, so that every step can be checked. It is as if businesses are being told: &#8220;Create innovation, but not too much. Let the user always see the seams.&#8221;</em></p><p><em>In my view, this is a dangerous logic. Instead of real control over AI, we may end up with a market of products artificially damaged for the sake of formal legal compliance.</em></p></div><p>&#9643;&#65039;If AI creates a deepfake, it will be necessary to disclose that the content is artificial or has been modified</p><div class="callout-block" data-callout="true"><p>&#128483; <em>This is where I see the main risk: legal AI will become less convenient, more regulated, and more &#8220;noisy&#8221; for the user.</em></p><p><em>Illegal or grey-market AI, on the other hand, will start to look faster, cleaner, and more attractive: no labels, no warnings, no digital traces, and no questions.</em></p><p><em>In other words, regulation may accidentally create the perfect advertisement for the shadow AI industry.</em></p><p><em>The white market will explain, label, and document. The grey market will simply say: &#8220;Upload your file here. We will remove everything.&#8221;</em></p></div><p>&#9643;&#65039;If AI-generated text is published to inform the public on a matter of public interest, it must be disclosed that the text was created or modified by AI. If the text has gone through human review or editorial control, disclosure may not be required</p><div class="callout-block" data-callout="true"><p>&#128483; And this is where I see a hole the size of a truck.</p><p>The law says: if an AI-generated text concerns a matter of public interest, disclose the use of AI. Fine. But who decides what counts as a matter of public interest?</p><p>Brussels? A platform? An editor? A court? Or the person who yesterday searched Google to find out why their stomach hurt after seafood pasta?</p><p>For different people, &#8220;important&#8221; means completely different things.</p><p>And then there is the magical formula: &#8220;human review&#8221;. But if a person simply ticks a box, does not check the facts, and does not understand the meaning of the text, that is not control. That is a theatrical performance called &#8220;we comply with the law&#8221;.</p><p>The idea is right. The implementation may turn out to be very weak.</p></div><p>&#9643;&#65039;The explanation that a product was made with AI must be clear, visible, accessible, and provided before the first interaction or at the first display</p><div class="callout-block" data-callout="true"><p>&#128483;Here it is: the cyberpunk of 2026.</p><p>The state says: &#8220;Label AI content.&#8221;<br>The market replies: &#8220;Fine, now let us build a tool that quietly removes all of that.&#8221;</p><p>As a result, instead of transparency, we may get a new game of hide-and-seek: legal companies will add labels, grey services will help bypass them, and the ordinary user will once again be left alone with the question: is this real or not?</p></div><p>&#9643;&#65039;Violations of the transparency rules may result in fines of up to EUR 15 million or up to 3% of the company&#8217;s total worldwide annual turnover for the preceding financial year, whichever is higher. A more lenient cap applies to small businesses and start-ups</p><div class="callout-block" data-callout="true"><p>&#128483; In my view, this rule shows the real danger of the whole structure.</p><p>We are told: &#8220;We are protecting people from deception and AI chaos.&#8221; That sounds right. But then you open the section on fines &#8212; up to EUR 15 million or 3% of global turnover &#8212; and you realise that this is also a powerful tool of pressure against companies.</p><p>Businesses are already dependent on AI. They have integrated it into advertising, customer support, texts, images, and products.</p><p>And now they are being told: &#8220;Here are the rules. It is almost impossible to comply with them perfectly, but if you make a mistake &#8212; you pay.&#8221;</p><p>I am not against regulating AI. I am against regulation that looks like a trap: first the market was accelerated, and then a turnstile with a very expensive ticket was placed at the entrance.</p></div><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I have gone through all the key points of the new EU law on AI regulation.</span></strong> Keep reading if you are interested in the details of this adventure, as I will go through each new rule in detail.</p><p></p><h2>&#129001; Why 2026 Will Be a Turning Point for Every Business Using AI</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qzsg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qzsg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qzsg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1022144,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qzsg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!Qzsg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb3f67375-bfee-453a-b3e9-8fcb2dfcb620_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagine an ordinary internet feed: a video of a politician, a customer review, a news story, a photo from the scene of an event, a voice message, an advertising banner, a post by an expert.</p><p>Today, each time, you ask yourself the same question: <span data-color="#00c853" style="color: rgb(0, 200, 83);">is this real, or was it made by AI?</span></p><p>This is exactly the question the EU Artificial Intelligence Act is trying to address.</p><p><strong>For a long time, AI-generated content was discussed as a matter of trust, ethics, and platform rules:</strong></p><p>&#10068;Should AI-generated images be labelled<br>&#10068;Should deepfakes be banned<br>&#10068;Should it be disclosed when an article was written with the help of AI<br>&#10068;Should watermarks be voluntary or mandatory</p><p>In 2026, this discussion moves into the legal field &#8212; although, in my view, into a rather crooked and bumpy one.</p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Article 50 of the EU AI Act</a> introduces transparency rules for certain AI systems and for certain materials created or modified with the help of AI.</p><p>The European Commission explains these rules as a way to protect people from deception, manipulation, and threats to the information environment.</p><p>And this law is not only about political deepfakes before elections.<span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It will affect the ordinary digital life of each of us:</span></strong></p><ul><li><p>an advertising video in which a person never actually said those words</p></li><li><p>a &#8220;real&#8221; review that never existed</p></li><li><p>a random Facebook news story without clear editorial responsibility</p></li><li><p>an image of an event that looks documentary, but was created by a machine</p></li><li><p>a voice, face, or text that we trust without understanding where it came from</p></li></ul><p>The problem is not that AI creates content. <span data-color="#00c853" style="color: rgb(0, 200, 83);">The problem is that this content increasingly looks real.</span></p><p>This logic is directly reflected in <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/recital-133">Recital 133 of the EU AI Act</a>. It states that AI systems can generate large volumes of synthetic content that is becoming increasingly difficult to distinguish from authentic content. This creates risks of disinformation, manipulation, fraud, impersonation, and consumer deception.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>In simple terms: mass disinformation used to be an elite weapon. It was something governments, oligarchs, and large media businesses with huge budgets could afford. Now that weapon has become almost an everyday object. A smartphone, an AI service, a couple of prompts &#8212; and any schoolchild, activist, or anonymous account can create a video, text, or image that looks convincing. That is why regulators are so nervous: the factory of influence no longer costs millions. It fits in your pocket.</em></p></div><p>For this reason, providers of AI systems must implement technical solutions that make it possible to label and detect AI-generated or AI-modified content.</p><p><strong>&#128314;When speaking about the new law, the expression &#8220;AI label&#8221; is too narrow.</strong></p><p>This is not about a small notice saying &#8220;created by AI&#8221;. <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">It is about an entire chain of transparency:</span></strong></p><ul><li><p>a person must understand when they are interacting with AI</p></li><li><p>content must carry a machine-readable technical signal &#8212; meaning that when you upload an AI-generated image directly to a social network, the platform should be able to understand and detect it</p></li><li><p>deepfakes and certain AI-generated texts on matters of public interest must be labelled for people</p></li><li><p>companies must be able to prove to the regulator that they have actually implemented a process, not just written a policy document &#8212; in my view, this is exactly where governments will start making money. But there is also good news: at these stages, companies will need to hire lawyers who understand this field, such as myself</p></li><li><p>platforms, metadata, standards, and detection tools must work together</p></li></ul><p><strong>&#128314;The bad news: every business will have to bear ongoing costs to monitor AI transparency.</strong></p><p>This is no longer a task for one lawyer writing a compliance policy. The new rules will affect product teams, engineers, marketing departments, newsrooms, advertising agencies, brands, security teams, procurement departments, and everyone who works with content.</p><p>If an organisation creates, buys, publishes, or distributes AI-generated content, there will come a moment when AI transparency becomes part of normal operational work.</p><h3>&#129001; Article 50 of the EU AI Act: Transparency Obligations in Plain Language</h3><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50">Article 50</a> sets out transparency obligations for providers and users of certain AI systems. It is not limited only to &#8220;high-risk&#8221; AI systems, even though a large part of the EU AI Act is built around that category.</p><p>An AI system may not be considered high-risk, but it may still fall under Article 50. For example: a chatbot, an image generator, a synthetic voice tool, an AI marketing tool, or an AI-generated news summary.</p><p>In other words, if a system interacts with people or creates content, it may have transparency obligations even without being classified as high-risk.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">The main groups of these obligations are:</span></p><p><strong>&#128994; AI Systems That Interact Directly with People</strong></p><p>If an AI system interacts directly with a person, that person must immediately understand that they are dealing not with a human, but with AI. Providers of AI systems must think in advance about exactly how they will inform the user that they are interacting with AI.</p><p><strong>There is only one possible exception:</strong> where it is already obvious from the context that the person is interacting with AI. In other words, an ordinary attentive user should be able to understand this without any additional explanation.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">Such systems include, for example:</span></p><ul><li><p>chatbots</p></li><li><p>voice AI assistants, where the assistant may briefly state by voice that it is an AI system</p></li><li><p>interactive AI avatars, where the avatar may have a visible label or on-screen notice</p></li></ul><div class="callout-block" data-callout="true"><p>&#128483;<em> You probably already have this corporate character in your company: a chatbot with a human face, giving useless advice with a serious expression, failing to solve the problem, and protecting the user until the very end from the terrible danger of speaking to a real customer support agent.</em></p><p><em>Now, apparently, this needs to be made slightly more legal: remove the human avatar, replace it with Robocop, and honestly tell people that they are dealing with a machine. Please do not forget to do this &#8212; at least for the mental health of your customers.</em></p></div><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">What matters here is not how &#8220;smart&#8221; the system is</span> or how human-like it appears. What matters is whether there is direct contact between a person and an AI system.</p><p>If such contact exists, the user must clearly understand that they are interacting with AI.</p><p>This information cannot be hidden somewhere in general terms of service or in a long privacy policy. The notice must be clear, visible, and accessible from the very first interaction.</p><p>A person should not have to guess who they are communicating with. They should immediately understand that they are interacting with an AI system.</p><p><strong>&#128994; Machine-Readable Labelling of AI Content</strong></p><p>Providers of AI systems, including general-purpose AI systems, must ensure technical labelling of content if their systems generate synthetic text, images, audio, or video, so that such content can be technically identified as artificially created or modified.</p><p>This is the technical core of the AI labelling regime.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UnUk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UnUk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UnUk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1206401,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UnUk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!UnUk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55a52a56-dd41-4fd0-8066-b10d1e03a778_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is not only about a visible note saying &#8220;created by AI&#8221;. The law requires AI-generated content to be detectable by technical means. These solutions must be as effective, interoperable, robust, and reliable as technically feasible.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>The key phrase is &#8220;as technically feasible&#8221;. And this is where the magic begins.</em></p><p><em>The law wants AI-generated content to be technically recognisable. But the digital world itself is built in such a way that a file can easily pass through dozens of transformations: uploading, compression, re-saving, format changes, publication, downloading, and reposting.</em></p><p><em>After all of that, the beautiful label may remain only as a memory in a lawyer&#8217;s report.</em></p><p><em>So the real question is not whether a label can be added. The question is whether it will survive contact with the real internet.</em></p></div><p><strong>&#128314;Exceptions:</strong> this may not be required where the AI system performs only an assistive function for standard editing, does not substantially alter the input data, or does not change its meaning. There are also separate exceptions for the use of AI systems authorised by law for law enforcement purposes.</p><p>The same may apply to grammar checking, file compression, minor image cropping, or light colour correction, provided that the meaning of the content does not change.</p><p>But creating a synthetic product scene, replacing a face, generating artificial voice-over, or producing a fictional image of a real public figure will trigger the obligation to comply with this rule.</p><p><strong>&#128994; Emotion Recognition and Biometric Categorisation</strong></p><p>If a company uses AI to understand a person&#8217;s emotions or to assign them to a particular group based on external characteristics, that person must be informed.</p><p>For example, if AI analyses a person&#8217;s face, voice, or behaviour and draws conclusions from it, the person must know that they are being analysed by an AI system. The company must also comply with personal data protection rules.</p><p><strong>In short:</strong> if AI is doing something to a person invisibly, the person must know about it.</p><p><strong>&#128994; Deepfakes and AI-Generated Texts on Matters of Public Interest</strong></p><p><a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">The European Commission explains</a> a deepfake as an image, audio, or video created or manipulated by AI that resembles existing persons, objects, places, events, or entities and could falsely appear to a person to be authentic.</p><p>If a user of an AI system creates or modifies an image, audio, or video in such a way that it becomes a deepfake, they must clearly disclose that the content has been artificially created or manipulated.</p><p><strong>There is also a separate rule for AI-generated texts.</strong></p><p>If AI-generated or AI-modified text is published for the purpose of informing the public on a matter of public interest, it must be disclosed that AI was used in its creation.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>This is where I have serious doubts.</em></p><p><em>News organisations are unlikely to start massively and honestly writing: &#8220;AI assisted in the creation of this text.&#8221; Such a label immediately affects readers&#8217; trust, the author&#8217;s reputation, and the perceived value of their work.</em></p><p><em>It is much more convenient to say: &#8220;The material underwent editorial review&#8221; &#8212; and close the issue.</em></p><p><em>Formally, everything looks fine. In reality, the reader may never know who wrote the text: a journalist, AI, or a journalist who simply clicked &#8220;improve style&#8221;.</em></p></div><p><strong>&#128314;The good news: this does not apply to every AI-generated text.</strong></p><p>A private letter, an internal draft, a product description, or an advertising text does not automatically fall under this rule. The key condition is that the text is published for a broad audience and concerns a matter of public interest.</p><p>Disclosure is also not required if the text has undergone human review or editorial control and a specific person or organisation takes responsibility for the publication.</p><p></p><h3>&#129001; EU AI Act 2026 Timeline: When Article 50 Transparency Rules Apply</h3><p>The EU AI Act was published in the Official Journal of the European Union on 12 July 2024 and entered into force shortly afterwards. The Regulation generally <a href="https://datamatters.sidley.com/2026/06/24/eu-ai-act-transparency-obligations-preparing-for-compliance-by-2-august-2026/"><span data-color="#00c853" style="color: rgb(0, 200, 83);">starts applying from 2 August 2026</span></a>. However, some provisions apply earlier or later.</p><p>For Article 50, the key date is 2 August 2026. This is when the transparency obligations generally start to apply.</p><p>&#9643;&#65039;<span data-color="#00c853" style="color: rgb(0, 200, 83);">On 2 February 2025</span>, the prohibitions on certain AI practices and AI literacy obligations started to apply<br>&#9643;&#65039;<span data-color="#00c853" style="color: rgb(0, 200, 83);">On 2 August 2025</span>, certain governance rules, sanctions, and obligations for general-purpose AI models started to apply<br>&#9643;&#65039;<span data-color="#00c853" style="color: rgb(0, 200, 83);">On 2 August 2026</span>, the transparency obligations under Article 50 start to apply</p><p>There is also another important transitional date.</p><p>For AI systems that were already placed on the market before this date, a transitional period applies <span data-color="#00c853" style="color: rgb(0, 200, 83);">until 2 December 2026</span>.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>Do not wait for the moment when someone from above finally explains everything in simple language. The key date is already known: 2 August 2026.</em></p><p><em>By that date, companies need to put their AI processes in order: where AI is used, who is responsible for it, where a label is required, where human review is needed, and what evidence must be preserved.</em></p><p><em>The problem is not whether you are allowed to use AI. The problem is whether you will be able to prove that you used it lawfully, transparently, and under control.</em></p><p><em>If you need a legal analysis of your processes for compliance with the new EU AI Act, you can contact me for a consultation. The earlier you do this, the fewer risks you will face later.</em></p><p><em>And subscribe to my newsletter, so you do not wake up one day in a world where AI is already regulated while your business is still living by the rules of 2023.</em></p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.dzhamal.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.dzhamal.net/subscribe?"><span>Subscribe now</span></a></p><h3>&#129001; EU AI Act Fines: Up to &#8364;15 Million or 3% of Global Turnover for Transparency Violations</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AlIb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AlIb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AlIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:810608,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AlIb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!AlIb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F709bf0f0-6759-4b8b-9078-9291ed569aa9_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99">Article 99 of the EU AI Act</a> sets out sanctions for violations of the transparency rules.</p><p>For non-compliance with Article 50, providers and users of AI systems may face <span data-color="#00c853" style="color: rgb(0, 200, 83);">administrative fines of up to EUR 15 million or up to 3% of the total worldwide annual turnover</span> for the preceding financial year &#8212; whichever amount is higher.</p><p>For small and medium-sized enterprises, including start-ups, a more lenient rule applies: the lower of the two limits is used &#8212; either the percentage of turnover or the fixed amount.</p><p>But this does not make the obligation symbolic. Regulators may apply not only fines, but also warnings or other non-monetary measures.</p><p><strong>&#128314;The fine is only part of the risk. <span data-color="#00c853" style="color: rgb(0, 200, 83);">The main problem for business is evidence.</span></strong></p><p>If a company publishes AI-generated advertising, uses a synthetic voice in customer support, distributes AI-generated summaries on matters of public interest, or integrates a generative tool into its product, it may need to show:</p><ul><li><p>which AI system was used</p></li><li><p>what content was created</p></li><li><p>what label was applied</p></li><li><p>what metadata was preserved</p></li><li><p>whether the AI-generated content could be technically detected</p></li><li><p>who reviewed and approved the publication</p></li></ul><div class="callout-block" data-callout="true"><p>&#128483;<em> If the state grabs a company by the throat, the payment will not be metaphorical. It will be made in very real money.</em></p><p><em>I think many businesses will first become frightened and start banning AI inside their companies. This may look cautious, but it will be expensive: less speed, more manual work, more frustrated employees, and the feeling that everyone has suddenly been sent back to pre-AI workflows.</em></p><p><em>Then comes the &#8220;denial phase&#8221;: &#8220;We do not use AI.&#8221;</em></p><p><em>Then the &#8220;bargaining phase&#8221;: &#8220;All right, where can we use it safely?&#8221;</em></p><p><em>And finally, the &#8220;acceptance phase&#8221;: &#8220;Without AI, we are losing money.&#8221;</em></p><p><em>And at that moment, you will need a lawyer who understands not only the law, but also the machine itself.</em></p><p><em>Get in touch. I can help you bring AI under control, build internal rules for your business, and reduce the risk of punishment by the state.</em></p></div><p><strong>&#128314;What This Looks Like in Concrete Numbers:</strong></p><p>Suppose a company violates the rules of Article 50 &#8212; for example, it launches an AI chatbot for customers but fails to inform users that they are interacting with an AI system.</p><p>Under Article 99 of the EU AI Act, such a violation may result in a fine of up to EUR 15 million or up to 3% of the total worldwide annual turnover for the preceding financial year &#8212; whichever amount is higher.</p><p>For small and medium-sized enterprises, including start-ups, a more lenient rule applies: the lower of the two limits is used.</p><p>&#128994; <span data-color="#00c853" style="color: rgb(0, 200, 83);">Example 1.</span> A Start-Up with Annual Turnover of EUR 1 Million</p><p>3% of EUR 1 million = EUR 30,000.</p><p>If the company qualifies as an SME or start-up, the maximum limit will not be EUR 15 million, but up to EUR 30,000.</p><p>&#128994; <span data-color="#00c853" style="color: rgb(0, 200, 83);">Example 2.</span> A Medium-Sized Company with Annual Turnover of EUR 20 Million</p><p>3% of EUR 20 million = EUR 600,000.</p><p>If the company falls within the SME definition, the maximum limit will be up to EUR 600,000, because this is lower than EUR 15 million.</p><p>&#128994; <span data-color="#00c853" style="color: rgb(0, 200, 83);">Example 3.</span> A Large Company with Annual Turnover of EUR 100 Million</p><p>3% of EUR 100 million = EUR 3 million.</p><p>For a large company, the higher amount applies. Between EUR 3 million and EUR 15 million, the higher amount is EUR 15 million. This means the maximum fine may reach up to EUR 15 million.</p><p>&#128994; <span data-color="#00c853" style="color: rgb(0, 200, 83);">Example 4.</span> A Large International Platform with Annual Turnover of EUR 1 Billion</p><p>3% of EUR 1 billion = EUR 30 million.</p><p>In this case, 3% of turnover is higher than the fixed amount of EUR 15 million. Therefore, the maximum fine may reach up to EUR 30 million.</p><p><strong>In other words, the rule works as follows:</strong></p><p>&#9643;&#65039;for large businesses: EUR 15 million or 3% of worldwide turnover &#8212; whichever is higher<br>&#9643;&#65039;for small and medium-sized enterprises, including start-ups: EUR 15 million or 3% of turnover &#8212; whichever is lower</p><p><strong>&#10071;&#65039;Important:</strong> this does not mean that the regulator will automatically impose the maximum fine. The specific amount will depend on the circumstances: the nature of the violation, its duration, scale, consequences, the size of the company, the degree of responsibility, cooperation with the regulator, and whether the company attempted to correct the violation.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>This may become a very attractive revenue mechanism for public budgets: large companies, large turnovers, large fines.</em></p><p><em>But then the old game will begin in a new form. In the past, businesses looked for tax havens. Now they may start looking for AI havens &#8212; digital islands, jurisdictions, and services where AI can be used without European labels, reports, and fear of the regulator.</em></p><p><em>As a result, the law that was supposed to make AI more transparent may push part of the market into places where there will be no transparency at all.</em></p></div><p></p><h3>&#129001; Provider vs Deployer Under the EU AI Act: Who Is Responsible for AI Content Labelling</h3><p><a href="https://digital-strategy.ec.europa.eu/en/library/draft-guidelines-implementation-transparency-obligations-certain-ai-systems-under-article-50-ai-act">Article 50</a> distinguishes between the obligations of providers and deployers of AI systems.</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Provider</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">:</span> the person or company that develops an AI system, or has it developed, and then places it on the market or puts it into service under its own name or brand. The provider is responsible for the system itself: how it is designed, what technical labels it applies, and whether AI-generated content can be detected.</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Deployer</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">:</span> the person or company that uses an AI system under its own responsibility. The deployer is responsible for the specific use of the system: why it is used, what content is published, where that content is placed, and whether disclosure to people is required. <em><span data-color="#00c853" style="color: rgb(0, 200, 83);">*Personal, non-professional use does not fall into this category.</span></em></p><p><strong>&#128314;But in real life, things are more complicated.</strong></p><p>One company may be both a provider and a deployer at the same time. A brand may use a third-party image generator. An agency may create AI-generated advertising for a client. A platform may provide AI tools while also hosting the content created with them. A publisher may use a general-purpose AI model inside its editorial system.</p><p>That is why the key question is not only <em>&#8220;who bought the tool&#8221;</em>. The real question is who controls the system, the use case, and the publication of the result.</p><p>Article 50 does not apply only to companies registered in the EU. If AI-generated content is used in the European Union, non-European actors may also fall within the scope of these rules.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example</span></strong>, an advertising company from a third country uses an AI system to create a deepfake of a celebrity for an advertisement shown in the EU. Such a company may be considered a deployer within the scope of the EU AI Act.</p><p></p><h3>&#129001; Code of Practice for AI-Generated Content: Why It Matters Even If It Is Voluntary</h3><p>On 10 June 2026, the European Commission published the final <a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content">Code of Practice on transparency for AI-generated content</a>.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">This is a practical guide</span> for companies on how to properly inform people that a text, image, video, voice, or other type of content was created with the help of AI.</p><p>The Code was prepared by independent experts. The AI Office, the dedicated EU body dealing with AI-related matters, also participated in the process.</p><p>Signing up to this Code is voluntary. In theory, a company may say: <em>&#8220;We will not sign the Code. We will do everything our own way.&#8221;</em></p><p>But Article 50 of the EU AI Act itself remains mandatory.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">In other words:</span></strong> the Code is voluntary, but the law is not.</p><p>In practice, the Code serves one main purpose: it shows companies how they can comply with the requirements of Article 50.</p><p>The Code has two main parts.</p><p>&#128994; <strong>The first part is for providers of AI systems:</strong> companies that create or provide AI tools. For example, services that generate text, images, video, voice, or other materials.</p><p>They must think about how to ensure that AI-generated content can be:</p><ul><li><p>labelled</p></li><li><p>recognised</p></li><li><p>technically detected</p></li></ul><p><strong>&#128994; The second part is for companies and organisations that use AI systems.</strong></p><p>For example, if a company uses AI to create a deepfake, synthetic voice, AI-generated video, or text on a matter of public interest, it must clearly disclose that AI was used.</p><p>Companies that sign the Code will be able to use it as evidence:</p><p><em>&#8220;We comply with Article 50 not only in words, but according to clear rules.&#8221;</em></p><p>Companies that do not join the Code may still comply with the law in another way. But then they will have to prove themselves that their transparency system is sufficiently reliable.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">That is why the Code of Practice may become a real market standard</span></strong>. If a company uses the Code, it will be easier to explain to the regulator that it tried to comply with the law. If a company does not use the Code, it needs to have its own strong, clear, and well-documented system.</p><p><strong>Otherwise, the regulator&#8217;s question will be very simple:</strong></p><p><em>&#8220;All right, you did not use the Code. Then show us exactly how you complied with Article 50.&#8221;</em></p><div class="callout-block" data-callout="true"><p>&#128483; <em>This is the illusion of choice in its purest form.</em></p><p><em>You are told: &#8220;No one is forcing you.&#8221;</em></p><p><em>And then a system is created in which not complying with the rules becomes too dangerous, too expensive, and too foolish.</em></p><p><em>Business finds itself in a beautiful position: it did not write the rules, it had no real control over their meaning, but it will be the one paying for mistakes.</em></p><p><em>Do you dislike this new legislative reality?</em></p><p><em>Then welcome back to the world of typewriters, goose feathers, and offices without AI.</em></p></div><p></p><h3>&#129001; AI-Generated Content Labels: Metadata, Watermarks, Detection Tools and EU Icons</h3><p>Labelling is not one icon and not one phrase saying <em>&#8220;created by AI&#8221;</em>. It is a multi-layered system: metadata, watermarks, detection tools, and clear notices for people.</p><p><strong>&#128994; Metadata</strong></p><p>The Code of Practice expects companies to record information in metadata about whether content was created or modified with the help of AI, where the file format supports metadata. This information should be protected by a digital signature. If the time of creation or modification is available, a protected timestamp should also be added.</p><p>Metadata helps transfer information about the origin of content between tools, platforms, and archives.</p><p>But metadata has a weak point: it is easily lost. For example, when content is uploaded to social media, compressed, converted into another format, or re-saved. That is why metadata alone is not enough.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>I can already see this new industry appearing: &#8220;remove AI traces online&#8221;, &#8220;hide metadata&#8221;, &#8220;no registration and no loss of quality&#8221;. Everything as usual: the law creates a rule, the market creates a button to bypass the rule.</em></p><p><em>But I have only one question: why did no one panic this much earlier, when people spent years building their personal lives on Tinder using FaceApp, filters, retouching, and photos from five years ago? That was also artificial reality &#8212; just without a watermark and an EU regulation.</em></p></div><p><strong>&#128994; Watermarks</strong></p><p>The Code also expects AI-generated or AI-modified content to contain a watermark.</p><p>Watermarks are useful because they may remain embedded inside an image, audio, video, or text even when ordinary metadata has been removed.</p><p>But they are not perfect either. They can be weakened by cropping, reformatting, re-recording, translation, paraphrasing, or deliberate attacks.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>Again, this feels like an idea from the Stone Age: if we cannot truly control AI, let us at least make life harder for those who operate legally. Excellent plan.</em></p><p><em>The white market will receive labels, reports, checks, fines, and costs. The grey market will receive customers, money, and freedom from rules.</em></p><p><em>In the end, instead of controlling AI, we may create a new underground AI economy where no one labels anything, declares anything, or pays taxes.</em></p></div><p><strong>&#128994; Preserving Existing Labels</strong></p><p>The Code expects companies to make efforts to preserve existing metadata and labels when an AI system uses content as input and then modifies it. Usage policies, terms of service, or documentation should also prohibit the intentional removal or damaging of such labels, except in lawful cases.</p><p><strong>&#128994; Detection Tools</strong></p><p>The Code expects companies to provide detection tools so that users can check whether content was created or modified by a specific AI system.</p><p>This is because machine-readable labelling only makes sense if someone is actually able to read it.</p><p><strong>&#128994; EU Icons for AI-Generated Content</strong></p><p>The European Commission has <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">published specific icons</a> for labelling AI-generated content.</p><p>In simple terms, these are small symbols that can be placed next to a text, image, video, or audio file so that a person immediately understands: artificial intelligence was used here.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">These icons are not decorative</span>. Their purpose is to help an ordinary person quickly understand that the content in front of them is not fully <em>&#8220;human&#8221;</em> content, but material that was created or modified with the help of AI.</p><p>The icons may be used in several situations:</p><ul><li><p>when content was fully created by AI</p></li><li><p>when real content was partly modified by AI</p></li><li><p>when the content is a deepfake</p></li><li><p>when AI-generated text is published to inform the public on a matter of public interest</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example</span></strong>, if AI fully creates a video showing a fictional event, the <em>&#8220;Fully AI-generated&#8221;</em> icon may be used.</p><p>If there was a real photograph, but AI replaced a person&#8217;s face or changed an important part of the image, the <em>&#8220;Partially AI-modified&#8221;</em> icon may be used.</p><p>If a company publishes an AI-generated news summary or an explanation of a matter of public interest without proper human editorial review, this may also require disclosure.</p><p><strong>&#128314;The EU icons are voluntary.</strong></p><p>A company is not required to use these exact icons. It may create its own labelling, for example: <em>&#8220;Created with AI&#8221;</em>, <em>&#8220;Image modified by AI&#8221;</em>, or <em>&#8220;You are viewing AI-generated content&#8221;</em>.</p><p>But the obligations under <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50">Article 50 of the EU AI Act</a> remain mandatory. In other words, a company may choose not to use the EU icon, but it cannot simply stay silent if the law requires disclosure.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">The label must be clear, visible, and accessible.</span> A person should see it at the moment of first contact with the content &#8212; not after they have already believed the video, read the text, or shared the post.</p><p>The icon should not be hidden by other interface elements. Where possible, it should remain attached to the content even if the content is downloaded or forwarded further.</p><p>This is a way of telling the person: <em>&#8220;Be careful, this material was created or modified with the help of artificial intelligence.&#8221;</em></p><p>For businesses, this is also a matter of evidence. <span data-color="#00c853" style="color: rgb(0, 200, 83);">A company must be prepared to show not only the icon, but the entire logic behind it: </span>where AI was used, what content was created, why this type of labelling was chosen, who checked it, and how the user could see it.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">It is like a road sign on the road:</span> the sign itself matters, but behind it there must be rules, markings, responsibility, and control.</p><p></p><h3>&#129001; AI Watermarking and C2PA: Metadata, Content Credentials and AI Content Detection</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5z26!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5z26!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!5z26!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!5z26!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!5z26!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5z26!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1187028,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5z26!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!5z26!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!5z26!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!5z26!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F617233a4-8091-4817-a0f3-8e395dc621f9_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="callout-block" data-callout="true"><p>&#128483; <em>In simple terms, the law wants every piece of AI-generated content to have a passport: who created it, where it was modified, what happened to it afterwards, and whether this can be proven.</em></p><p><em>The problem is that, on the real internet, these &#8220;passports&#8221; are often lost faster than luggage on a cheap airline.</em></p></div><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50">Article 50 of the EU AI Act</a> requires AI-generated content to be not only understandable to people, but also technically detectable. In other words, if a text, image, video, or audio file was created or modified with the help of AI, the system must help make this recognisable.</p><p>But the law does not force everyone to use one specific technology. It says something simpler: the solution must be sufficiently reliable, effective, interoperable, and robust &#8212; as far as this is possible with current technology.</p><p><a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/recital-133">Different methods</a> may be used, including:</p><ul><li><p>watermarks</p></li><li><p>metadata</p></li><li><p>cryptographic signatures</p></li><li><p>activity logs</p></li><li><p>digital fingerprints</p></li><li><p>other methods for detecting AI-generated content</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">In practice, this works as several layers of protection.</span></strong></p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Metadata</span></strong> is technical information inside the file. It may show that the content was created by AI, which tool was used, and when it was created</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A cryptographic signature</span></strong> is like a digital seal. It helps verify whether the metadata was changed after the file was created</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A watermark</span></strong> is a visible or hidden signal inside the content. It helps determine whether a text, image, video, or audio file is connected to AI</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">A digital fingerprint</span></strong> is a unique trace of a file. It helps recognise the content or modified versions of it</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Detection tools</span></strong> help platforms, users, and regulators check AI labelling</p><p>&#9643;&#65039;<strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Internal company logs</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>show who created the content, who reviewed it, who approved it, and where it was published</p><p>The <a href="https://spec.c2pa.org/specifications/specifications/2.4/explainer/Explainer.html">C2PA standard</a> and related Content Credentials are especially important.</p><p>C2PA is an open standard that helps show the provenance of digital content: where a file came from, how it was changed, and whether AI was used in the process.</p><p>C2PA does not prove that the information is true. It shows where the file came from, what changes were made, and whether the provenance data can be trusted.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example</span></strong>, if a photo has <em>Content Credentials</em>, a person can view the history of that photo. But this does not mean that the news story or caption attached to the photo is automatically true.</p><p>The European transparency Code places strong emphasis on <a href="https://iptc.org/news/eu-ai-transparency-code-of-practice-june-2026/">digitally signed metadata</a>, invisible watermarks, the preservation of labels, and information about content provenance.</p><p>There is no perfect solution yet. A 2025 <a href="https://arxiv.org/abs/2503.18156">study</a> showed that only some AI image generators already use sufficiently developed practices for watermarking and labelling deepfakes.</p><p>Another <a href="https://arxiv.org/abs/2511.03641">study</a> on watermarks for large language models points to a similar problem: there is still no single solution that perfectly meets all the requirements of the AI Act at once &#8212; reliability, interoperability, effectiveness, and robustness.</p><p>Businesses should not wait for the perfect technology. They need to <span data-color="#00c853" style="color: rgb(0, 200, 83);">start building a reasonable system now</span>: using metadata, watermarks, C2PA, or other suitable solutions, documenting internal processes, and preserving evidence.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>The main mistake is to think that it is enough to simply add a label saying &#8220;made with AI&#8221;. It is not.</em></p><p><em>A company must be ready to prove that AI was used lawfully, transparently, and under control.</em></p><p><em>This means that companies should already be thinking not about a beautiful five-page policy, but about a real system: who trains employees, who checks the processes, who preserves evidence, and who is responsible if the regulator asks questions.</em></p><p><em>And yes, it is better to look for a lawyer who understands AI regulation today. Tomorrow, everyone will be looking for one.</em></p><p><em><span data-color="#00c853" style="color: rgb(0, 200, 83);">If you need an analysis of your AI processes for compliance with the new EU AI Act, you can contact me directly.</span></em></p></div><div class="directMessage button" data-attrs="{&quot;userId&quot;:524168409,&quot;userName&quot;:&quot;Dzhamal Statsenko&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><h3>&#129001; Deepfakes Under the EU AI Act: Where the Disclosure Line Is Drawn</h3><p>Deepfakes are one of the most sensitive points under Article 50. The European Commission <span data-color="#00c853" style="color: rgb(0, 200, 83);">describes a </span><a href="https://arxiv.org/abs/2412.09961"><span data-color="#00c853" style="color: rgb(0, 200, 83);">deepfake</span></a><span data-color="#00c853" style="color: rgb(0, 200, 83);"> as</span> an image, audio, or video created or manipulated by AI that resembles existing persons, objects, places, events, or entities and may falsely appear to a person to be authentic.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">In practice, difficult questions immediately arise:</span></strong></p><p>&#10068; If only the background is replaced, is that already a deepfake<br>&#10068; If AI slightly improves a person&#8217;s face, is that a substantial modification<br>&#10068; If a synthetic voice is used with the actor&#8217;s consent, is a label required<br>&#10068; Should a historical reconstruction be labelled<br>&#10068; What should be done with a stylised image if it is based on a real person<br>&#10068; What if an advertising character is not a real person, but strongly resembles a well-known public figure</p><p>This is where the grey zone begins.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The EU AI Act leaves room for disputes:</span></strong> what counts as synthetic manipulation, where ordinary editing ends, and how significant a modification must be before a disclosure obligation arises.</p><p>For businesses, the safer approach is to be conservative.</p><p>If content creates the impression of a real face, place, event, or statement, but was actually created or modified by AI, the risk under Article 50 is high.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Particular care is needed with:</span></strong></p><ul><li><p>political communication</p></li><li><p>news and public-interest content</p></li><li><p>advertising using images of celebrities or realistic testimonials</p></li><li><p>synthetic voices</p></li><li><p>images of real people in fictional circumstances</p></li><li><p>videos that imitate real events</p></li></ul><div class="callout-block" data-callout="true"><p>&#128483; <em>This is where the real legal circus will begin: is it enough to write once at the beginning of a video, &#8220;this is a deepfake&#8221;? Or should the warning remain visible throughout the entire video, like a sign saying &#8220;caution, wet floor&#8221;?</em></p><p><em>The main dispute will not be whether there was a label. The main dispute will be whether the viewer actually understood that they were being warned.</em></p><p><em>And then a completely different story begins: deepfakes as a tool of crime.</em></p><p><em>In my view, a simple principle should apply here: robbery with a toy gun is still robbery if the victim believes the gun is real. The same should apply to AI. If a fake face, voice, or video is used to deceive someone, it should not be treated as a technological trick. It should be treated as a real instrument of crime.</em></p></div><p>If a person could believe that something is real, even though it was created or modified by AI, it is safer to disclose the AI origin of the content.</p><p></p><h3>&#129001; AI-Generated Advertising and Marketing: The Most Tense Compliance Area</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YZlh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YZlh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YZlh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:981206,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YZlh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!YZlh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d623ae9-17c7-40bc-97de-363a12323548_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Advertising teams are already using generative AI for product images, backgrounds, models, voice-overs, banners, personalisation, creative testing, and localisation.</p><p>In June 2026, <a href="https://www.reuters.com/legal/litigation/ai-generated-ads-should-be-exempt-eu-transparency-rules-retail-association-says-2026-06-19/">Reuters</a> reported that a retail association had called for <span data-color="#00c853" style="color: rgb(0, 200, 83);">AI-generated advertising to be exempt from the EU transparency rules.</span></p><p><strong>The industry&#8217;s argument is understandable:</strong> if every advertising material where AI was used even slightly has to be labelled, this will create costs, unnecessary friction, and confusion for consumers.</p><p>But Article 50 does not contain a general exemption for advertising.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The regulator&#8217;s logic is simple: advertising can also mislead people.</span></strong></p><ul><li><p>A synthetic model may look like a real customer</p></li><li><p>An AI-generated product image may show features the product does not actually have</p></li><li><p>A synthetic review may imitate a real buyer</p></li><li><p>A synthetic celebrity may create the false impression of endorsement</p></li></ul><p>The analysis by <a href="https://www.gleisslutz.com/en/know-how/ai-transparency-advertising-european-commissions-guidelines-ai-act">Gleiss Lutz</a> also emphasises that <span data-color="#00c853" style="color: rgb(0, 200, 83);">advertisers and advertising service providers need to prepare</span>, because AI-generated product images, synthetic voice-overs, and AI-generated testimonials are already widely used in the industry.</p><p>The closer an advertisement is to a real person, a real event, an actual product feature, or a statement of public importance, the stronger the argument for clear labelling becomes.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>Marketing will have to live in a world of rules that do not yet fully understand what they want to become.</em></p><p><em>Today, this looks like the draft of a new Bible of AI regulation: the general idea is already there, but the commandments will still be rewritten.</em></p><p><em>In two or three years, clearer practice will appear. In five years, we may perhaps see real legislation built on this foundation.</em></p><p><em>For now, businesses are being asked to pray, comply, and hope they have understood the text correctly.</em></p></div><p></p><h3>&#129001; Publishers and Media: AI-Generated Texts on Matters of Public Interest</h3><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">Not every text written with the help of AI will automatically need to be labelled.</span></p><p><strong>The rule applies to a specific situation:</strong> when an AI system has created or modified a text, and that text is published to inform people on a matter of public interest.</p><p>If the text may influence public opinion, people&#8217;s safety, elections, health, rights, money, or the understanding of laws, it should be treated with greater caution.</p><p><strong>&#10068;Who does this specifically concern:</strong></p><ul><li><p>news organisations</p></li><li><p>reviews of laws and political decisions</p></li><li><p>short AI-generated summaries of court decisions</p></li><li><p>health and safety materials</p></li><li><p>election-related information</p></li><li><p>financial and regulatory warnings</p></li><li><p>important public statements by companies</p></li></ul><p><strong>&#128314;Important:</strong> Article 50 does not prohibit journalists, newsrooms, or publishers from using AI.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example</span></strong>, AI may be used for a draft, structure, translation, short summary, or editorial assistance.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">The regulator&#8217;s main question will be this:</span> was there real human control afterwards?</p><p>If a person reviewed the text, corrected errors, checked the facts, edited the material, and the newsroom took responsibility for the publication, disclosure of AI use may not be required.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">If AI helped write a draft, this does not necessarily create a problem. </span>But if AI wrote the text itself and it was immediately published for the public without disclosing that it was AI-generated, this may already be a violation.</p><p>Even if you checked everything and decided that labelling is not required, it is still better to preserve the full internal process of creating the material inside the newsroom:</p><p>&#10068;which AI tool was used<br>&#10068;who reviewed the text<br>&#10068;which facts were checked<br>&#10068;who bears editorial responsibility<br>&#10068;how the process was documented</p><p>This way, if necessary, you can use this record to confirm that the text was reviewed and edited by a human.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>Companies should not wait for panic. They should start building a protection system now: document AI use, record interactions with the media, train employees, review business processes, and look in advance for specialists in AI law.</em></p><p><em>Because when the regulator comes with questions, it will not be enough to say: &#8220;We tried.&#8221;</em></p><p><em>The regulator will want to see documents, processes, logs, responsible people, and evidence.</em></p><p><em>Preventive measures today are not bureaucracy. They are insurance against fines tomorrow.</em></p></div><p></p><h3>&#129001; EU AI Act Compliance Checklist: What Businesses Should Do Before 2 August 2026</h3><p>Preparing for Article 50 is not about writing a beautiful document &#8220;about AI ethics&#8221; that sits in a folder and no one ever opens.</p><p>Ask yourself a simple question: where does our product, text, advertising, video, voice, or image come into contact with AI?</p><p>Businesses need a simple working system: where we use AI, what content it creates, who is responsible for it, where a label is required, and what evidence we preserve.</p><p>The goal is to make sure that, at every stage of working with AI, the company understands where a risk of violating the law may arise.</p><p><strong>&#128994; Create a Map of AI Content</strong></p><p>First, you need to understand where your organisation uses AI. Record all places where AI creates, changes, or helps publish content:</p><p>&#8226; image generators<br>&#8226; video generators<br>&#8226; synthetic voice-over tools<br>&#8226; chatbots and virtual assistants<br>&#8226; AI avatars<br>&#8226; marketing AI tools<br>&#8226; editorial systems<br>&#8226; translation and localisation tools<br>&#8226; automatic summaries</p><p>Separately, check external contractors: agencies, designers, marketers, editors, and IT teams. If a contractor uses AI for your company, this must also be included in the map.</p><p><strong>&#128994; Separate the Roles: Who Is the Provider and Who Is the Deployer of AI</strong></p><p>Determine what role your organisation plays. You may be:</p><p>&#8226; a provider of an AI system<br>&#8226; a deployer of an AI system<br>&#8226; both provider and deployer at the same time</p><p>This is important to record in contracts.</p><p>For example, the provider of an AI tool may be responsible for machine-readable labelling. But the company that publishes a deepfake, advertisement, or AI-generated text on a matter of public interest may still be responsible for clear disclosure to people.</p><p>You cannot shift everything onto &#8220;the service that generated the image&#8221;. If you publish the content, you may also have responsibility.</p><p><strong>&#128994; Divide Content into Categories</strong></p><p>After mapping your AI use, you need to understand what type of AI content you have and divide it into categories:</p><p>&#8226; a person directly interacts with an AI system<br>&#8226; AI creates audio, images, video, or text<br>&#8226; AI only slightly edits content without changing its meaning<br>&#8226; there is a risk of a deepfake<br>&#8226; AI creates text on a matter of public interest<br>&#8226; the text is reviewed by a human and there is editorial responsibility<br>&#8226; the content is created for a specific lawful purpose, for example law enforcement</p><p>This will help you quickly understand where a label is needed, where disclosure is required, and where the risk is lower.</p><p><strong>&#128994; Choose Technical Measures</strong></p><p>If you are the provider of an AI system, check the technical side:</p><p>&#10068;what metadata is recorded<br>&#10068;whether digital signatures are used<br>&#10068;whether watermarks are applied<br>&#10068;whether AI-generated content can be detected<br>&#10068;whether labelling is preserved during export<br>&#10068;what happens during compression, upload, or format conversion<br>&#10068;how the user can verify the origin of the content</p><div class="callout-block" data-callout="true"><p>&#128483; <em>AI-generated content must be recognisable. A person must understand that what they are seeing is a synthetic image, video, or text &#8212; not just another &#8220;beautiful creative&#8221;.</em></p><p><em>And this is where a new race will begin.</em></p><p><em>Some companies will be able to integrate the requirements of Article 50 carefully: without ugly labels, without destroying trust, and without killing the product. They will remain in the white zone and continue making money.</em></p><p><em>Others will pretend to comply: formal labels, unclear signals, checkboxes for lawyers. That is the grey zone.</em></p><p><em>And some will simply move into the black zone and work without rules.</em></p><p><em>But the more mature AI regulation becomes, the less air there will be left in the grey zone.</em></p></div><p><strong>&#128994; Think About How Your Customer Will See That They Are Dealing with Synthetic Content</strong></p><p>If an AI label or warning is required, it must be understandable:</p><ul><li><p>not hidden at the bottom of the page</p></li><li><p>not buried in long terms of use</p></li><li><p>not written in grey text that no one reads</p></li></ul><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">The information must be clear, visible, accessible, and shown no later than the first contact or first view.</span></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Examples</span> of how this should be implemented:</strong></p><ul><li><p>a chatbot must immediately say that it is an AI system</p></li><li><p>a deepfake must be labelled as artificially created or modified</p></li><li><p>an AI-generated text on a matter of public interest must include an explanation that it is generated text, but only if there is no human editorial control</p></li></ul><p><strong>&#128994; Train Your Team to Work Transparently with AI</strong></p><p>Even a good policy will not help if the team does not understand how to apply it. A marketer, designer, editor, product manager, or social media specialist <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">must know exactly:</span></strong></p><p>&#10068;when to apply an AI label<br>&#10068;when to go to the legal team<br>&#10068;when to preserve metadata<br>&#10068;when labelling must not be removed<br>&#10068;when human review is required<br>&#10068;how to record who approved the publication.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>Training should not be about beautiful words. It should be about real working situations.</em></p><p><em>Your employees must understand: here AI can be used safely; here a label is required; here evidence must be preserved; and here it is better not to be a hero and to ask a lawyer immediately.</em></p><p><em>In my blog, I already explain these topics in simple language. This may be enough for an initial introduction to the AI Act. But if you want me to personally conduct a practical training session for your team, you can contact me.</em></p></div><div class="directMessage button" data-attrs="{&quot;userId&quot;:524168409,&quot;userName&quot;:&quot;Dzhamal Statsenko&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p>&#128994; Preserve Evidence</p><p>If the regulator asks you, <em>&#8220;How did you comply with Article 50?&#8221;</em>, it will not be enough to say: <em>&#8220;We tried.&#8221;</em> You will need to show documents and traces of the process to reduce the risk of a fine.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">I recommend creating and preserving records of the following:</span></strong></p><ul><li><p>an AI content policy</p></li><li><p>creation and publication logs</p></li><li><p>records of the labelling applied</p></li><li><p>evidence of human review</p></li><li><p>contracts with providers and contractors</p></li><li><p>results of detection tool testing</p></li><li><p>records of team training</p></li><li><p>assessments of exceptions</p></li><li><p>incident response procedures</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Preparing for Article 50 is not one document. It is a system.</span></strong></p><p><strong>&#128314;</strong>If you cannot prove that you did everything correctly, then for the regulator it may look as if you did not do it at all.</p><p>To build an effective system that helps protect you from risks, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">it should answer the following questions:</span></strong></p><ul><li><p>where AI is used in your business processes</p></li><li><p>what content is created with the help of AI</p></li><li><p>who is responsible for creating AI-generated content</p></li><li><p>where a <em>&#8220;made with AI&#8221;</em> label is required</p></li><li><p>where human review of the product is required</p></li><li><p>what evidence of AI product review is preserved</p></li></ul><div class="callout-block" data-callout="true"><p>&#128483; <em>An AI label should not become a fire drill right before publication. It should become a normal part of content production.</em></p><p><em>This is a new reality, and businesses will no longer be able to simply ignore it.</em></p><p><em>It was the same with cigarettes. First, there was beautiful packaging, advertising, lifestyle branding, and no panic. Then came warnings, restrictions, and new rules of the game.</em></p><p><em>AI will follow a similar path: at first, everyone will think that labels damage the product. Then the market will get used to living with them.</em></p></div><p></p><h3>&#129001; Open Questions: AI Watermarking, Metadata Loss and the Grey Zone</h3><p>The EU transparency regime looks strong and logical. But in practice, <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">it still leaves many questions unanswered.</span></strong></p><p><strong>&#128314;The Technology Is Not Fully Ready Yet.</strong></p><p>The law requires labelling methods to be effective, interoperable, robust, and reliable. But technical standards are still developing.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example</span></strong>, C2PA can help confirm the provenance of content. But this standard is not yet used everywhere. In addition, metadata can disappear when content is uploaded, compressed, edited, or published on social media.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>My 12-year-old daughter can almost instantly recognise AI-generated videos, AI images, and even AI music. My mother, on the other hand, may send me a touching video of &#8220;real&#8221; little beavers, and I have to choose whether to explain to her that it is AI or simply not ruin her mood.</em></p><p><em>And this is the whole problem. One generation already sees synthetic content almost instinctively. Another still perceives it as reality.</em></p><p><em>But if a child is able to notice these signs, then there are recurring patterns in the content. And if there are patterns, sooner or later technologies will appear that can recognise them better than humans.</em></p></div><p><strong>&#128314;Watermarks Are Not Always Reliable</strong></p><p>Watermarks in images can degrade after processing, cropping, or format conversion. Watermarks in text are, frankly, almost absurd.</p><p>Research on <a href="https://arxiv.org/abs/2511.03641">watermarks</a> for large language models still does not offer an adequate solution.</p><p><strong>&#128314;Content Passes Through Too Many Hands</strong></p><p>The same file can go through a long chain:</p><ol><li><p>the AI system provider applies a label</p></li><li><p>the user adds a watermark</p></li><li><p>the platform compresses or changes the file</p></li><li><p>another person downloads it</p></li><li><p>a third party reposts it</p></li></ol><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Who is responsible, and what evidence remains?</span></strong></p><p><strong>&#128314;It Is Not Always Clear Where Simple Editing Ends and AI Manipulation Begins.</strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Sometimes AI simply helps:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>it corrects a text, improves the quality of an image, or translates material.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But sometimes AI seriously changes the meaning:</span> </strong>it creates a new face, voice, scene, event, or statement.</p><p>The line between <em>&#8220;ordinary AI assistance&#8221;</em> and <em>&#8220;substantial AI manipulation&#8221;</em> is not always obvious. That is why businesses need their own internal rules now, <span data-color="#00c853" style="color: rgb(0, 200, 83);">without waiting for the first court decisions and fines.</span></p><p><strong>&#128314;AI Advertising Will Remain a Disputed Area.</strong></p><p>Marketing and retail will insist that not every <strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">AI-generated advertisement should be labelled. Their argument is understandable:</span></strong> if every banner, image, or background carries a label, this may overload the user and make them think that all visual information is synthetic fiction.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Supporters of AI transparency will argue the opposite:</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>advertising can also mislead people, especially when it uses synthetic people, voices, reviews, products, or celebrities.</p><p>For this reason, AI advertising will most likely become one of the most disputed areas.</p><div class="callout-block" data-callout="true"><p>&#128483;<em> And this is where designers and photographers may suddenly regain their market.</em></p><p><em>While everyone argues about how to label AI-generated content correctly, manual work may become expensive again. The absence of a &#8220;made with AI&#8221; label may become a mark of quality.</em></p><p><em>Companies used to be proud of using new technologies. Now they may start being proud of the opposite: &#8220;This was made by a human.&#8221; And people may start paying for that again.</em></p></div><p><strong>&#128314;The Code of Practice Is Voluntary, but Ignoring It Is Risky.</strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The Code of Practice is formally voluntary.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>An organisation may choose not to sign it and still comply with the law in other ways.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But there is an important nuance:</span></strong> the Code may become a practical reference point for the market and regulators. If a company follows the Code, it will be easier to show that it tried to comply with the rules. Later, this may also make it easier to win new contracts and develop in the market.</p><p>If a company does not follow the Code, it will have to work harder to prove that its own measures were sufficient. That may not sound very convincing to clients and investors.</p><p>The law is already moving faster than ordinary business processes. That is why it is better to build a system in advance, rather than search for explanations after the regulator asks the first question.</p><p></p><h3>&#129001; Main Conclusion: The AI Label Is the Beginning of AI Compliance</h3><p>The AI label coming in 2026 is not simply a notice saying <em>&#8220;made with AI&#8221;</em>. It is a new system of control.</p><p><span data-color="#00c853" style="color: rgb(0, 200, 83);">Businesses will need not only to apply a label, but also to prove:</span></p><p>&#10068;where AI was used<br>&#10068;what content it created or modified<br>&#10068;who reviewed it<br>&#10068;where the user saw the warning<br>&#10068;what evidence the company preserved</p><p>For providers of AI systems, the main work will be technical. They will need to build metadata, watermarks, machine-readable labelling, and AI content detection tools into their products.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For deployers of AI systems, the main work will be organisational.</span></strong> They need to understand in advance when content may qualify as a deepfake, when a text concerns a matter of public interest, when an AI label is required, and when human review may be sufficient.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For marketers, publishers, and newsrooms, the main lesson is simple:</span></strong> AI transparency must be considered before publication, not after.</p><p>If a video has already spread across social media, an advertisement has already been launched, or a text has already been read by thousands of people, it may be too late to remember the label. The original file, metadata, and review history may already have been lost.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For platforms and AI tools, the main challenge is preserving technical signals.</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>If the label disappears during upload, compression, editing, or reposting, the entire system loses its meaning.</p><p>The EU wants to make AI-generated content understandable both to people and to machines. The idea is right. But the technology is not yet perfect, businesses are not ready, and people will still look for ways to bypass inconvenient rules.</p><p><strong>The market will split into three zones:</strong></p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#9643;&#65039;The white zone</span></strong><span data-color="#00c853" style="color: rgb(0, 200, 83);"> </span>&#8212; companies that honestly integrate AI transparency into their processes. They will spend money on lawyers, engineers, team training, and evidence systems.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#9643;&#65039;The grey zone</span></strong> &#8212; companies that apply labels only formally. On paper, everything will look fine, but in practice no one will understand who created the content, where the metadata is, or why the label disappeared.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#9643;&#65039;The black zone</span></strong> &#8212; services and users that remove labels, bypass the rules, and operate outside normal regulation.</p><div class="callout-block" data-callout="true"><p>&#128483; <em>That is why I do not think this law will completely stop the chaos around AI.</em></p><p><em>It will not tame the beast. It will simply build an expensive fence around it, put up a sign saying &#8220;Caution: AI&#8221;, and hire lawyers to check whether the sign is hanging correctly.</em></p><p><em>And the beast, as usual, will find a hole in the fence.</em></p></div><p><strong>More likely, the law will create a new and expensive infrastructure around AI.</strong></p><ul><li><p>Some will pay for compliance</p></li><li><p>Some will make money from compliance</p></li><li><p>Some will bypass compliance</p></li><li><p>And some will pay fines</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">But for businesses, the main question is already clear.</span></strong></p><p>Not: <em>&#8220;Can we use AI?&#8221;</em></p><p>The real question is this:</p><p><em>&#8220;Can we prove that we used AI transparently, lawfully, and under control?&#8221;</em></p><p>The companies in the strongest position will not be those that add a <em>&#8220;created with AI&#8221;</em> note at the last moment.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The strongest position will belong to those that understand in advance:</span></strong></p><ul><li><p>where AI is used</p></li><li><p>who is responsible for it</p></li><li><p>where a label is required</p></li><li><p>where human review is required</p></li><li><p>what evidence must be preserved</p></li><li><p>what to do if the regulator asks questions</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The AI label is not the end of the work.</span></strong></p><p><strong>It is the beginning of a new reality:</strong> AI can still be used, but it is no longer possible to pretend that no one needs to understand where exactly it was used.</p><p></p><h3>&#128172; EU AI Act 2026 FAQ: AI Labels, Watermarking, Fines and Article 50</h3><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;When Do the Rules for AI-Generated Content Start Applying</span></strong></p><p>The main date is 2 August 2026. From this date, the transparency obligations under <a href="https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50">Article 50 of the EU AI Act</a> start to apply.</p><p>For some AI systems that were already on the market before 2 August 2026, a transitional period applies until 2 December 2026.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Does Every AI-Generated Text Need to Be Labelled</span></strong></p><p>No. Not every AI-generated text needs to be labelled.</p><p>The rule applies to texts that are:</p><ul><li><p>created or modified by AI</p></li><li><p>published for a broad audience</p></li><li><p>intended to inform people on a matter of public interest</p></li></ul><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">For example:</span></strong> news, elections, health, laws, people&#8217;s rights, safety, and finance.</p><p>An ordinary email, draft, product description, or internal document does not automatically fall under this rule.</p><p>If the text was reviewed by a human, edited by a newsroom, and responsibility for the publication was taken by a person or organisation, labelling may not be required.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Are the EU Icons Mandatory</span></strong></p><p>No. The EU icons are not mandatory.</p><p>But the obligation to disclose AI-generated content remains mandatory where Article 50 applies. In other words, a company may choose not to use the specific <a href="https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content">EU icon</a>, but it cannot remain silent if the law requires that a person be informed.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">Important: </span></strong>the icon itself does not prove that a company complies with the law.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Is C2PA Mandatory</span></strong></p><p>No. The law does not require the use of one specific standard.</p><p><a href="https://spec.c2pa.org/specifications/specifications/2.4/explainer/Explainer.html">C2PA</a> is useful because it helps show the provenance of a file: who created it, how it was changed, and whether AI was used.</p><p>But Article 50 does not require a specific technology. It requires a result: AI-generated content must be understandable to people and technically recognisable.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;Does AI-Generated Advertising Need to Be Labelled</span></strong></p><p>Not always, but the risk is often high. The law does not contain a general exemption for advertising.</p><p>Labelling may be required if the advertisement:</p><ul><li><p>uses a deepfake</p></li><li><p>shows a synthetic person</p></li><li><p>uses an AI-generated voice</p></li><li><p>imitates a real customer or celebrity</p></li><li><p>shows a product in a way that may make people believe in false features</p></li><li><p>concerns a matter of public interest</p></li></ul><p>If AI-generated advertising may look like an authentic scene and mislead a person, it should be treated with caution.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">&#10068;What Fines Are Possible</span></strong></p><p>For violating the transparency obligations under Article 50, the fine may be:</p><ul><li><p>up to EUR 15 million</p></li><li><p>or up to 3% of the company&#8217;s annual turnover</p></li></ul><p>The higher amount applies. For small and medium-sized enterprises, including start-ups, a more lenient rule applies.</p><p><strong><span data-color="#00c853" style="color: rgb(0, 200, 83);">The key point is this:</span></strong> companies are not fined simply for using AI.</p><p>The risk arises when a company uses AI but does not explain this to people, does not preserve evidence, and cannot show that it acted transparently.</p><p></p><p style="text-align: center;"><strong>If you have read this far, thank you.</strong></p><p style="text-align: center;">AI regulation may look technical, but in reality it is about trust: who created what, who checked it, who is responsible, and whether people can still understand what is real.</p><p style="text-align: center;"><span data-color="#00c853" style="color: rgb(0, 200, 83);">I will continue writing about this in plain language.</span></p><p style="text-align: center;">See you in the next piece.<br><br>Cheers,</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s5L0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s5L0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s5L0!,w_2400,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png" width="268" height="139.36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;large&quot;,&quot;height&quot;:260,&quot;width&quot;:500,&quot;resizeWidth&quot;:268,&quot;bytes&quot;:15043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.dzhamal.net/i/204532282?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-large" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s5L0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 424w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 848w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 1272w, https://substackcdn.com/image/fetch/$s_!s5L0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F018bfe78-5031-4c3e-b4c5-204995f85f1e_500x260.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><br></p>]]></content:encoded></item></channel></rss>