# The EU AI Act beyond the basics: the obligations most guides forget

*A practical guide to what the AI Act requires beyond the "5 transparency checks" everyone is talking about.*

Since August 2, 2026, the EU AI Act is fully applicable. Most online guides — and most LinkedIn carousels — focus on the same five points: disclose chatbots, inventory your AI tools, label AI-generated images and videos, disclose AI-written content on matters of public interest, and be careful when you cross the line from "deployer" to "provider."

Those five points are correct, but they are not the whole picture. This guide covers the obligations that usually get left out, organized into four blocks: additional transparency duties, high-risk system obligations, extra duties when you become a provider, and the cross-cutting layer of privacy and contracts.

## Transparency obligations (Article 50)

Article 50 of the AI Act contains **four** transparency obligations, below there's the complete list, including the points you may already know and the ones most guides skip.

### 1.1 Disclose when AI interacts with people

If you use chatbots, automated DM responders (e.g., Manychat), or voice assistants, people must know they are interacting with an AI system. The disclosure must be clear, timely, and placed where the interaction happens — not buried in a footer or a terms-of-service page.

### 1.2 Label AI-generated and manipulated content (synthetic media)

Images, audio, and video generated or manipulated by AI must be disclosed as such. This applies to the content you publish — social posts, ads, landing pages — and it is why many creators now add visible labels to AI-generated visuals.

### 1.3 Disclose AI-written text on matters of public interest

If you publish AI-generated text to inform the public on matters of general interest — health, money, rights, environment, politics, consumer topics — you must disclose it. Your options are two: label the text as AI-written, or rework it substantially yourself. Changing a few words is not enough.

### 1.4 Emotion recognition and biometric categorization

If you deploy systems that infer emotions from voice or facial analysis, or that classify people into categories based on biometric data (age, gender, origin, behavioral traits), you must clearly inform the individuals exposed to these systems. This is a specific obligation for deployers and it applies even when the system is "just" an analytics feature inside a larger product.

### 1.5 Deepfakes: realistic synthetic or manipulated content

Labeling "this image is AI-generated" is not enough when the content is — or looks — realistic. If you publish a manipulated video of a real person, a cloned voice, or any audio/image/video that could be mistaken for authentic footage of real events or real people, you must disclose that the content has been **artificially generated or manipulated**, in a way that is clearly visible to the audience.

### 1.6 AI-generated text: the editorial responsibility exception

The disclosure duty for texts on matters of public interest has an important exception: it does not apply if the text has undergone substantial human review with genuine editorial responsibility. The bar is higher than "changing a few words": a human must actually review, edit, and take editorial ownership of the final content.

**If that happens, disclosure is no longer mandatory — but the responsibility is real, not cosmetic.**

### 1.7 Machine-readable marking (if you are a provider)

If you provide systems that generate synthetic content (text, audio, image, video), it is not enough to add a visible disclaimer.

You must ensure that outputs are **marked in a machine-readable format** and detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, and robust — to the extent technically feasible.

**Think watermarks, metadata standards, and detection tooling, not just a label in the corner.**

---

## Extra obligations for high-risk systems (as a Deployer)

The five-point checklists mostly cover "limited risk" systems. The moment you use a system classified as **high-risk** under Annex III of the AI Act — credit scoring, CV screening, decisions affecting access to benefits or services, certain education, health, or safety systems — a much heavier set of deployer obligations kicks in.

### 2.1 Use the system according to its instructions

You must operate the system within the parameters, context, and input data conditions defined by the provider. Using a high-risk system "off-label" puts you out of compliance immediately.

### 2.2 Competent human oversight

Oversight must be assigned to people with adequate **competence, training, and authority**, and they must be given the support needed to intervene on the system's outputs. A nominal "human in the loop" who rubber-stamps every output does not satisfy this requirement.

### 2.3 Monitoring and incident reporting

You must monitor the system's operation and, in case of incidents or malfunctions affecting health, safety, or fundamental rights, inform the provider or distributor and the relevant supervisory authority.

### 2.4 Log retention

Logs automatically generated by the high-risk system must be retained for a minimum period (generally at least six months), so that decisions can be reconstructed in case of disputes or audits.

### 2.5 Informing individuals subject to decisions

When a high-risk system makes or supports decisions about natural persons — refusing a service, assessing creditworthiness, screening job applications — the affected individuals must be informed that a high-risk AI system was used.

### 2.6 Informing workers before workplace deployment

Before putting a high-risk system into service in the workplace (performance evaluation, activity monitoring, shift allocation), you must inform employees and their representatives that they will be subject to its use.

### 2.7 Fundamental Rights Impact Assessment (FRIA)

For certain categories of high-risk systems, a formal **FRIA** is required *before* deployment: a structured assessment of the system's impact on fundamental rights — not only privacy, but also non-discrimination, freedom of expression, and other protected rights.

---

## If you become a Provider: the obligation stack changes

When you build tools on top of third-party APIs (Claude, ChatGPT, open-source models) and sell them to clients — for example, an automation that sends them an AI-generated report every day — you may stop being a deployer and become a **provider** under the AI Act.

## 3.1 Risk management system

You must design and maintain a continuous risk management process: identify risks, mitigate them, and reassess them over the system's entire lifecycle.

## 3.2 Data quality and data governance

Requirements apply to the quality, representativeness, and governance of the data used to train, validate, and test the system, with the explicit goal of reducing bias and foreseeable risks.

## 3.3 Technical documentation and traceability

Detailed documentation on how the system works, its versions, datasets, and testing is mandatory, so that authorities and deployers can understand it and use it correctly.

## 3.4 Transparency toward deployers

You must make the system transparent enough for your clients to interpret its outputs and use it appropriately: clear instructions for use are not optional — they are a legal requirement.

## 3.5 Conformity assessment and CE marking

For many high-risk systems, a conformity assessment is required before placing the system on the market, including CE marking — the same logic that applies to other regulated products.

## 3.6 Registration in the EU database

Certain high-risk systems must be registered in the dedicated European database for high-risk AI systems before being deployed or sold.

---

## The cross-cutting layer: privacy, contracts, and internal governance

The AI Act does not replace existing law — it stacks on top of it: to actually protect an online business that uses AI, you also need to handle the following.

## 4.1 GDPR and DPIA

If the system processes personal data — and it almost always does — all GDPR obligations remain in force: lawful basis, data minimization, security, data subject rights, and a **Data Protection Impact Assessment (DPIA)** for high-risk processing – AI laws (such as Italy's Law 132/2025) add further transparency duties on top.

## 4.2 Clear written notice to clients

Beyond the "this response was generated by AI" disclaimer, good practice — and increasingly the law — requires a **written notice** describing how AI is used in your services, provided before the service is delivered.

## 4.3 Contractual clauses

Contracts with clients should include specific clauses on responsibility, usage limits, transparency, human oversight, and data processing. Without them, liability in case of problems is ambiguous — and ambiguity favors no one.

## 4.4 Internal AI systems register

A register is mandatory for high-risk systems, but maintaining an internal inventory of **all** AI systems in use — including limited-risk tools and forgotten subscriptions — is strongly recommended and aligns with national guidance. Your "list of every AI you use" is the starting point, not the end point.

## 4.5 Staff training

Guidelines push toward periodic training of your team on risks, transparency, privacy, and correct AI usage; under the AI Act's AI literacy requirement, this is not just best practice — it's an obligation.

---

## What is actually at stake

Non-compliance with transparency obligations can lead to fines of up to **15 million euros or 3% of global annual turnover**, whichever is higher.

### For prohibited practices, the ceiling rises to 35 million euros or 7% of turnover. For high-risk system violations, fines can reach 15 million euros or 3% as well.

The real risk for most online businesses is not the maximum fine — it is the combination of regulatory exposure, contractual disputes with clients, and reputational damage when AI use comes to light without proper disclosure.

---

## Implementation checklist for your company

1. **Map every AI system in use,** including consumer licenses activated by employees, and register each processing as a separate entry in the article 30 record with purposes, data categories, recipients and extra-EU transfers made explicit.
2. **Migrate corporate accounts from consumer plans to enterprise plans** with a signed data processing agreement, because consumer tiers like ChatGPT Plus or Claude Pro offer no valid DPA and configure a structural GDPR violation.
3. **Evaluate providers with documented[ zero data retention and EU data residency](https://regolo.ai/pricing/)**, verifying that the non-retention policy is contractual and technically auditable rather than merely declared on marketing pages.
4. Produce a legitimate interest assessment before any training or fine-tuning on personal data, version it with a certified date and review it periodically following the EDPB three-step test.
5. **Draft the DPIA for systems meeting article 35 criteria**, especially automated customer service, candidate screening and large-scale customer scoring, integrating the AI Act dimension where the system qualifies as high risk.
6. **Adopt an internal AI usage policy listing authorized tools,** prohibited data categories in prompts and escalation procedures, since only 19 percent of Italian users declare exclusive use of corporate tools.
7. **Implement an audit trail of critical automated decisions with input, prompt, output and human-review logs,** kept in the controller's own systems and rigorously separated from the provider's ephemeral infrastructure.
8. **Extend incident response to AI-specific scenarios**, including prompt injection, data leakage from model outputs and notification to the supervisory authority within the 72 hours required by the regulation.

---

### Disclosure

This guide is for informational purposes and does not constitute legal advice – for specific compliance decisions, consult a qualified lawyer familiar with the AI Act, GDPR, and applicable national legislation.

---

## Frequently asked questions

## What does zero data retention mean in practice

It means the provider handles data exclusively in memory for the duration of a single request and keeps no copy on disk, in logs or in training datasets, which reduces both the GDPR audit perimeter and the exfiltration risk in the event of an infrastructure breach.intellistack+1

## Does zero data retention make the organization fully gdpr compliant

No, because provider-side non-retention covers only the storage-limitation principle, while the controller retains full responsibility for transparency notices, processing records, the DPA, the DPIA and the automated-decision audit trail regardless of the vendor's architecture.

## Can European open models replace frontier american models

It depends on the workload, because Mistral Large 3 competes with American frontier models on numerous benchmarks and runs in self-hosting under Apache 2.0, while EuroLLM-22B excels at European multilingual tasks and national models like Minerva cover Italian linguistic specialization.

## How do we verify that a provider truly honors zero data retention

By requesting contractual and technical evidence: DPA clauses explicitly prohibiting retention and reuse, documentation of logging architectures, independent certifications and, where possible, third-party audits confirming the effective absence of payload persistence.

---

## Ship Private AI. Not Infrastructure.

You have the private RAG architecture. Now give it an inference layer built for production.

**Regolo** gives European teams fast, OpenAI-compatible access to Mistral, Llama, Qwen, DeepSeek, GLM, and more — with zero data retention, EU data residency, and no new SDK to learn.

Change your `base_url`. Keep your LangChain code. Start shipping.

### 🚀 [Start your 30-day free trial →](https://regolo.ai/?utm_source=blog&utm_medium=cta&utm_campaign=private-rag)

Build, test, and deploy with no infrastructure to maintain.
**No credit card. No migration project. No compromise on data control.**

### 💬 [Join the Regolo Discord →](https://discord.gg/bqGrVJHeF)

Meet builders working on private RAG, local LLMs, LangChain, Ollama, and production AI systems. Share your setup, get feedback from the community, and speak directly with the Regolo team.

### 🤝 [Talk to an AI Infrastructure Engineer →](https://regolo.ai/contact?utm_source=blog&utm_medium=cta&utm_campaign=private-rag)

Running a sensitive workload, scaling beyond a proof of concept, or assessing a managed EU inference provider? Get a tailored architecture and commercial proposal for your team.

### 📂 [Clone the GitHub repository →](https://github.com/regolo-ai/tutorials/)

Get the full implementation from this guide: ingestion scripts, ChromaDB setup, hybrid retrieval, the **30-Question RAG Floor**, evaluation examples, and deployment configuration.

> **Private AI should not require a private data center.**
> Regolo gives your team an EU-native path from local experimentation to production-grade inference.

---

### Build with Regolo

- **Discord:** [Join the community →](https://discord.gg/bqGrVJHeF)
- **GitHub:** [Explore open-source workflows →](https://github.com/regolo-ai/tutorials/)
- **X / Twitter:** [Follow @regolo\_ai →](https://x.com/regolo_ai)
- **Reddit:** [Join the community →](https://www.reddit.com/r/regolo_ai/)
- **Documentation:** [Read the API docs →](https://docs.regolo.ai)
- **Contact:** [Talk to the team →](https://regolo.ai/contact)

---

*Built with ❤️ by the Regolo team. Questions? [regolo.ai/contact](https://regolo.ai/contact)* or chat with us on [Discord](https://discord.gg/bqGrVJHeF)