AI Industry Transparency Guidelines

Explore top LinkedIn content from expert professionals.

Summary

AI industry transparency guidelines are rules and recommendations that require companies to clearly explain how their artificial intelligence systems work, disclose key information about their models, and ensure people know when they're interacting with AI-generated content. These guidelines are designed to build trust, protect consumers, and prevent misuse of AI in areas like hiring, healthcare, and elections.

  • Disclose AI usage: Always inform people when they're interacting with an AI, whether it's a chatbot, automated email, or synthetic image, making the disclosure easy to spot and understand.
  • Document data sources: Keep track of where your AI training data comes from, and make this information publicly available to help others understand how your model was built.
  • Mark synthetic content: Clearly label AI-generated text, images, or audio so users can reliably detect what is real and what is artificial, using tools like watermarks or metadata.
Summarized by AI based on LinkedIn member posts
  • View profile for Martyn Redstone

    Head of Responsible AI & Industry Engagement @ Warden AI | AI Governance for HR, Recruitment, Staffing & HR Technology

    22,186 followers

    The European Commission has officially published its draft guidelines on AI transparency obligations (Article 50). While much of the recent political debate in Brussels has focused on the delayed timelines for high-risk systems, these new guidelines deal with the immediate requirement for transparency. I have reviewed the 40-page document. Here are the four most critical takeaways for your HR technology strategy: 1️⃣ The end of the 'generic assistant' trap Many recruitment teams use AI chatbots that are given human names or labelled vaguely as 'virtual assistants'. The draft guidelines explicitly target this practice. You must clearly inform candidates about the artificial, non-human nature of the interacting counterpart. A single disclosure buried in your Terms and Conditions is no longer sufficient. The guidelines strongly recommend multi-modal disclosures, such as persistent badges visible throughout the interaction. 2️⃣ Emotion recognition is a prohibited practice The guidelines address the transparency requirements for emotion recognition systems but they include a crucial reminder for the HR sector. The use of emotion recognition is outright prohibited in the workplace. If a vendor pitches an assessment tool claiming to analyse a candidate's facial expressions or vocal tone to infer their emotional state, reject it. It is not just poor science; it is a prohibited practice under the AI Act. 3️⃣ There is no 'grandfathering' for transparency You might assume that because you procured your AI screening tool years ago it is exempt from these new rules. The draft guidelines clarify that while a special grandfathering rule applies to high-risk compliance for legacy systems, it does not apply to transparency obligations. Every AI system you use that interacts with humans or generates synthetic content must be updated to meet these transparency standards regardless of when you bought it. 4️⃣ Mandatory transparency for GenAI communications If your team uses generative AI to draft candidate rejection emails, automate interview feedback, or write job adverts, you can no longer seamlessly pass this off as human-authored. The guidelines dictate that AI-generated synthetic text (or images, audio etc.) must be marked in a machine-readable format and be fully detectable. Furthermore, individuals must be informed clearly at the very first point of exposure. If you rely heavily on AI to mass-produce automated communications, your workflow will require immediate structural updates to remain compliant. The consultation period for these guidelines closes on 3 June 2026. We must stop treating AI transparency as a legal hurdle and start viewing it as a fundamental pillar of candidate trust. I have attached the full draft guidance document below and I have dropped the link to the official consultation in the comments. Are your technology vendors prepared to meet these stringent transparency standards? Are your internally built tools (agents)?

  • View profile for Dr. Barry Scannell
    Dr. Barry Scannell Dr. Barry Scannell is an Influencer

    AI Law & Policy | Partner in Leading Irish Law Firm William Fry | Appointed to Irish AI Advisory Council | Member of the Board of Irish Museum of Modern Art | PhD in AI & Copyright

    61,383 followers

    Yesterday, the AI Office published the third draft of the General-Purpose AI Code of Practice, a key regulatory instrument for AI providers seeking to align with the EU AI Act. Developed with input from 1,000 stakeholders, the draft refines previous versions by clarifying compliance requirements and introducing a structured approach to regulation. GPAI providers must meet baseline obligations on transparency and copyright compliance, while models classified as having systemic risk face additional commitments under Article 51 of the AI Act. The final version, expected in May 2025, aims to facilitate compliance while ensuring AI models adhere to safety, security, and accountability standards. The Code introduces the Model Documentation Form, requiring AI providers to disclose key details such as model architecture, parameter size, training methodologies, and data sources. Transparency obligations include specifying the provenance of training data, documenting measures to mitigate bias, and reporting compute power and energy consumption. GPI providers must also outline their models’ intended uses, with additional requirements for systemic-risk models, including adversarial testing and evaluation strategies. Documentation must be retained for twelve months after a model is retired, with copyright compliance mandatory for all providers, including open-source AI. GPAI providers must establish formal copyright policies and comply with strict data collection rules. Web crawlers cannot bypass paywalls, access piracy sites, or ignore the Robot Exclusion Protocol. The Code also requires providers to prevent AI-generated copyright infringement, mandate compliance in acceptable use policies, and implement mechanisms for rightsholders to submit copyright complaints. Providers must maintain a point of contact for copyright inquiries and ensure their policies are transparent. For AI models with systemic risk, the Code introduces a Safety and Security Framework, aligning with the AI Act’s high-risk requirements. Providers must assess risks in areas such as cyber threats, manipulation, and autonomous AI behaviours. They must define risk acceptance criteria, anticipate risk escalations, and conduct assessments at key development milestones. If risks are identified, development may need to be paused while safeguards are implemented. GPAI providers must introduce technical safeguards, including input filtering, API access controls, and security measures meeting at least the RAND SL3 standard. From 2 November 2025, systemic-risk models must undergo external risk assessments before release. Providers must maintain a Safety and Security Model Report, report AI-related incidents within strict timeframes, and implement governance structures ensuring responsibility at all levels. Whistleblower protections are also required. With the final version expected in May 2025, AI providers have a short window to prepare before the AI Act takes full effect in August.

  • View profile for Kevin Klyman

    AI Policy @ Stanford + Harvard

    18,700 followers

    Our paper on transparency reports for large language models has been accepted to AI Ethics and Society! We’ve also released transparency reports for 14 models. If you’ll be in San Jose on October 21, come see our talk on this work. These transparency reports can help with: 🗂️ data provenance ⚖️ auditing & accountability 🌱 measuring environmental impact 🛑 evaluations of risk and harm 🌍 understanding how models are used   Mandatory transparency reporting is among the most common AI policy proposals, but there are few guidelines available describing how companies should actually do it. In February, we released our paper, “Foundation Model Transparency Reports,” where we proposed a framework for transparency reporting based on existing transparency reporting practices in pharmaceuticals, finance, and social media. We drew on the 100 transparency indicators from the Foundation Model Transparency Index to make each line item in the report concrete. At the time, no company had released a transparency report for their top AI model, so in providing an example we had to build a chimera transparency report with best practices drawn from 10 different companies.   In May, we published v1.1 of the Foundation Model Transparency Index, which includes transparency reports for 14 models, including OpenAI’s GPT-4, Anthropic’s Claude 3, Google’s Gemini 1.0 Ultra, and Meta’s Llama 2. The transparency reports are available as spreadsheets on our GitHub and in an interactive format on our website. We worked with companies to encourage them to disclose additional information about their most powerful AI models and were fairly successful – companies shared more than 200 new pieces of information, including potentially sensitive information about data, compute, and deployments. 🔗 Links to these resources in comment below!   Thanks to my coauthors Rishi Bommasani, Shayne Longpre, Betty Xiong, Sayash Kapoor, Nestor Maslej, Arvind Narayanan, Percy Liang at Stanford Institute for Human-Centered Artificial Intelligence (HAI), MIT Media Lab, and Princeton Center for Information Technology Policy

  • View profile for Mateusz Kupiec, FIP, CIPP/E, CIPM

    Institute of Law Studies, Polish Academy of Sciences || Privacy Lawyer at Traple Konarski Podrecki & Partners || DPO || I know GDPR. And what is your superpower?🤖

    27,428 followers

    🤖‼️Today, the AI Office (European Commission) published for public consultation the draft Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 #AIAct. It is a 40-page document, and here are the insights I found most interesting. Article 50 AI Act should not be read as a narrow labelling provision. It creates a horizontal transparency layer for several AI use cases. A key point is the allocation of responsibility. Providers are responsible for transparency-by-design where systems interact directly with people or generate/manipulate synthetic content. Deployers are responsible for using emotion recognition or biometric categorisation systems, or publishing deep fakes or AI-generated public-interest text. The Guidelines also clarify that employees, freelancers or contractors acting under the control of a legal person should not normally be treated as separate deployers. The personal-use exclusion is interpreted narrowly. A natural person creating AI-generated Christmas cards for relatives may fall outside the deployer's obligations, but a person publicly sharing a political deepfake of a local mayor would not. This is important because public dissemination may take the activity outside the purely personal and non-professional sphere, even without economic benefit. For synthetic content, the draft draws an important distinction between machine-readable marking and detectability. Providers must not only mark outputs, but also ensure that detection is possible. Marking alone is not enough. The technical solution should be effective, reliable, robust and interoperable. This points to a compliance architecture involving watermarks, metadata, cryptographic methods, provenance tools, fingerprints, or a combination of these. Mere reproduction, ranking or arrangement of existing content, source code, machine-to-machine outputs, short technical strings, and closed-loop industrial outputs not intended for human interpretation may fall outside Article 50(2). At the same time, agentic AI and multimodal systems may fall within the scope in which their outputs are perceptible to natural persons as text, audio, images, or video. The guidelines explain what consutities a deepfake under Article 50(4) AI Act. A deepfake requires a strong resemblance to real people, objects, places, entities, or events, and a false appearance of authenticity or truthfulness. The intention to deceive is not decisive. The assessment must consider the actual audience, including children, elderly persons and persons with lower digital or AI literacy. Even artistic, fictional or satirical deep fakes are not exempt; they benefit only from a lighter disclosure regime that must not hamper the enjoyment of the work.

  • View profile for Katharina Koerner

    Senior Architect AI Governance | Agent Governance | Privacy & Security | ISO/IEC 42001 | NIST AI RMF

    45,038 followers

    Yesterday, the California Department of Justice, Attorney General’s Office (AGO), issued an advisory to provide guidance to consumers and entities that develop, sell, and use AI about their rights and obligations under California law. The "Legal Advisory on the Application of Existing California Laws to Artificial Intelligence" outlines: 1) Unfair Competition Law (Bus. & Prof. Code, § 17200 et seq.): Requires AI systems to avoid deceptive practices such as false advertising of capabilities and unauthorized use of personal likeness, making violations of related state, federal, or local laws actionable under this statute. 2) False Advertising Law (Bus. & Prof. Code, § 17500 et seq.): Prohibits misleading advertisements about AI products' capabilities, emphasizing the need for truthfulness in the promotion of AI tools/services. 3) Competition Laws (Bus. & Prof. Code, §§ 16720, 17000 et seq.): Guard against anti-competitive practices facilitated by AI, ensuring that AI does not harm market competition or consumer choice. 4) Civil Rights Laws (Civ. Code, § 51; Gov. Code, § 12900 et seq.): Protect individuals from discrimination by AI in various sectors, including employment and housing. 5) Election Misinformation Prevention Laws (Bus. & Prof. Code, § 17941; Elec. Code, §§ 18320, 20010): Regulate the use of AI in elections, specifically prohibiting the use of AI to mislead voters or impersonate candidates. 6) California's data protection laws ensuring oversight of personal and sensitive information: The California Consumer Privacy Act (CCPA) and the California Invasion of Privacy Act (CIPA) set strict guidelines for transparency and the secure handling of data. These regulations extend to educational and healthcare settings through the Student Online Personal Information Protection Act (SOPIPA) and the Confidentiality of Medical Information Act (CMIA). In addition, California has enacted several new AI regulations, effective January 1, 2025: Disclosure Requirements for Businesses: - AB 2013: Requires AI developers to disclose training data information on their websites by January 1, 2026. - AB 2905: Mandates disclosure of AI use in telemarketing. - SB 942: Obligates AI developers to provide tools to identify AI-generated content. Unauthorized Use of Likeness: - AB 2602: Ensures contracts for digital replicas include detailed use descriptions and legal representation. - AB 1836: Bans use of deceased personalities’ digital replicas without consent, with hefty fines. AI in Elections: - AB 2355: Requires disclosure for AI-altered campaign ads. - AB 2655: Directs platforms to identify and remove deceptive election content. Prohibitions on Exploitative AI Uses: - AB 1831 & SB 1381: Expand prohibitions on AI-generated child pornography. - SB 926: Extends criminal penalties for creating nonconsensual pornography using deepfake technology. AI in Healthcare: - SB 1120: Requires licensed physician oversight on AI healthcare decisions.

  • The European Commission published its first draft of the “Code of Practice on Transparency of AI‑Generated Content” designed as a tool to help organizations demonstrate alignment with the transparency requirements (Art. 50) of the AI Act. Article 50 of the AI Act includes obligations for providers to mark AI-generated or manipulated content in a machine-readable format, and for users who deploy generative AI systems for professional purposes to clearly label deepfakes and AI-text publications on matters of public interest. The document is divided into two sections. The first section covers rules for marking and detecting AI content, applicable to providers of generative AI systems, including to: - Use a Multi‑layered machine-readable marking of AI‑generated content - Use imperceptible watermarks interwoven within content - Adopt a digitally signed “manifest/provenance certificate” for content that can’t securely carry metadata - Offer free detection interfaces/tools, including confidence scoring, and complementary forensic detection that does not rely on active marking - Test against common transformations and adversarial attacks - Use open standards and shared/aggregated verifiers to enable cross-platform detection and lower compliance friction The second section covers labelling deepfakes and certain AI-generated or manipulated text on matters of public interest and is applicable to deployers of generative AI systems, including: - Deepfake labelling - Modality‑specific labelling rules for real-time video, non-real-time video, images, multimodal content, and audio-only - Operational governance: encourages internal compliance documentation, staff training, accessibility measures, and mechanisms to flag and fix missing/incorrect labels.

  • View profile for Kevin Pomfret

    Attorney, Author:| Space, AI, Digital Twins, Smart Cities, Mobility, Autonomy

    9,639 followers

    Businesses that offer generative AI systems or services in California should be aware that the state's Generative AI Training Data Transparency Act takes effect on January 1, 2026. It imposes documentation and disclosure obligations on developers of such systems released on or after January 1, 2022. Specifically, covered developers must post on their website documentation describing the data used to train, test, validate, or fine-tune the system, including: · Sources or owners of datasets and how they support the system’s intended purpose. · The size of datasets (ranges permitted; estimates for dynamic datasets). · Types and characteristics of data points and labeling practices. · Whether datasets include copyrighted, trademarked, or patented material versus public domain content. · Whether datasets were purchased or licensed. · Whether datasets include personal information or aggregate consumer information as defined under California law. · Any cleaning, processing, or modifications performed and their purposes. · Data collection periods, including whether collection is ongoing, and the dates first used in development. · Whether synthetic data generation was used, and the functional need for it if included. There are certain exemptions, including if the system (i) is made available only to a federal entity exclusively for national security, military or defense purposes (ii) or made available solely to a hospital medical staff member. Businesses offering generative AI systems and services in California should consider taking the following next steps: · Conducting a data provenance and licensing assessment for all covered systems released since January 1, 2022. · Building a standardized disclosure template aligned with the statute’s enumerated elements to support publication before January 1, 2026 and at each substantial modification. · Establishing change‑management triggers so that retraining or fine‑tuning that materially affects performance prompts updated disclosures. · Mapping exemptions, if any apply, and document the basis for relying on them. #geospatiallaw #geoai

  • View profile for Montgomery Singman 🔜 PGC Shanghai / ChinaJoy
    Montgomery Singman 🔜 PGC Shanghai / ChinaJoy Montgomery Singman 🔜 PGC Shanghai / ChinaJoy is an Influencer

    Managing Partner @ Radiance Strategic Solutions | xSony, xElectronic Arts, xCapcom, xAtari

    27,940 followers

    On August 1, 2024, the European Union's AI Act came into force, bringing in new regulations that will impact how AI technologies are developed and used within the E.U., with far-reaching implications for U.S. businesses. The AI Act represents a significant shift in how artificial intelligence is regulated within the European Union, setting standards to ensure that AI systems are ethical, transparent, and aligned with fundamental rights. This new regulatory landscape demands careful attention for U.S. companies that operate in the E.U. or work with E.U. partners. Compliance is not just about avoiding penalties; it's an opportunity to strengthen your business by building trust and demonstrating a commitment to ethical AI practices. This guide provides a detailed look at the key steps to navigate the AI Act and how your business can turn compliance into a competitive advantage. 🔍 Comprehensive AI Audit: Begin with thoroughly auditing your AI systems to identify those under the AI Act’s jurisdiction. This involves documenting how each AI application functions and its data flow and ensuring you understand the regulatory requirements that apply. 🛡️ Understanding Risk Levels: The AI Act categorizes AI systems into four risk levels: minimal, limited, high, and unacceptable. Your business needs to accurately classify each AI application to determine the necessary compliance measures, particularly those deemed high-risk, requiring more stringent controls. 📋 Implementing Robust Compliance Measures: For high-risk AI applications, detailed compliance protocols are crucial. These include regular testing for fairness and accuracy, ensuring transparency in AI-driven decisions, and providing clear information to users about how their data is used. 👥 Establishing a Dedicated Compliance Team: Create a specialized team to manage AI compliance efforts. This team should regularly review AI systems, update protocols in line with evolving regulations, and ensure that all staff are trained on the AI Act's requirements. 🌍 Leveraging Compliance as a Competitive Advantage: Compliance with the AI Act can enhance your business's reputation by building trust with customers and partners. By prioritizing transparency, security, and ethical AI practices, your company can stand out as a leader in responsible AI use, fostering stronger relationships and driving long-term success. #AI #AIACT #Compliance #EthicalAI #EURegulations #AIRegulation #TechCompliance #ArtificialIntelligence #BusinessStrategy #Innovation 

  • View profile for Raymond Sun
    Raymond Sun Raymond Sun is an Influencer

    Tech Lawyer & Developer | Founder at LegalQuants | Tracking AI Regulation | @techieray @LegalQuants

    30,278 followers

    “Trust but verify”.   ^ That’s the 3-word summary of the policy approach proposed by the Joint California Policy Working Group on AI Frontier Models (attached below).   Even if you’re not based in California, this is a fantastic rulebook on AI policy and regulation.   It's one of the more nuanced and deeply-thought papers that cuts past the generic “regulation v innovation” debate, and dives straight into a specific policy solution for governing frontier models (with wisdom draw from historical analogies in tobacco, energy, pesticides and car safety).   Here’s my quick summary of the “trust but verify” model.   1️⃣ TRANSPARENCY In a nutshell, the “trust but verify” approach is rooted in transparency, which is essential for building “trust”. But transparency is such a broad concept, so the paper neatly breaks it down in terms of: ▪️ Data acquisition ▪️ Safety practices ▪️ Security practices ▪️ Pre-deployment testing ▪️ Downstream impact ▪️ Accountability for openness There’s nuance and different transparency mechanisms to each area. However, transparency alone doesn’t guarantee accountability or redress. In fact, the paper warns us about “transparency washing” – i.e. where policymakers (futilely) pursue transparency for the sake of it without achieving anything. Transparency needs to be tested and verified (hence the “verify”).   2️⃣ THIRD PARTY RISK ASSESSMENT This supports the “verify” aspect, and the idea of “evidence-based transparency” (i.e. transparency that you can actually trust). This is not just about audits and evaluations, but also specific things like: ▪️ researcher protections (i.e. safe harbour / indemnity protections for public interest safety research) ▪️ responsible disclosure (i.e. infrastructure is needed to communicate identified vulnerabilities to affect parties)   3️⃣ WHISTLEBLOWER PROTECTION This means legal safeguards to protect retaliation against whistleblowers who report misconduct, fraud, illegal activities, etc. It might be the secret to driving *real* corporate accountability in AI.   4️⃣ ADVERSE EVENT REPORTING A reporting regime for AI-related incidents (similar to data breach reporting regimes) help with identification and enforcement + regulatory coordination and information sharing + analytics. 5️⃣ SCOPE What type of frontier models should be regulated? The paper suggests these guiding principles: ▪️ "Generic developer-level thresholds seem to be generally undesirable given the current AI landscape"   ▪️ "Compute thresholds are currently the most attractive cost-level thresholds, but they are best combined with other metrics for most regulatory intents"   ▪️ "Thresholds based on risk evaluation results and observed downstream impact are promising for safety and corporate governance policy, but they have practical issues" 👓 Want more? See my map which tracks AI laws and policies around the world (see link in 'Visit my website'). #ai #tech #airegulation #policy #california

  • View profile for Anurag(Anu) Karuparti

    Agentic AI Strategist @Microsoft (35K+) | Applied AI Architect | Author - Generative AI for Cloud Solutions | LinkedIn Learning Instructor | Responsible AI Advisor | Ex-PwC, EY | Marathon Runner

    34,822 followers

    𝟐𝟎 𝐄𝐧𝐭𝐞𝐫𝐩𝐫𝐢𝐬𝐞 𝐀𝐈 𝐂𝐨𝐦𝐩𝐥𝐢𝐚𝐧𝐜𝐞 𝐑𝐞𝐪𝐮𝐢𝐫𝐞𝐦𝐞𝐧𝐭𝐬 𝐁𝐞𝐟𝐨𝐫𝐞 𝐘𝐨𝐮 𝐃𝐞𝐩𝐥𝐨𝐲 𝐀𝐈 Most AI Failures in enterprises are not Technical. They are Compliance Failures. Before deploying AI into Production,  Here are the 20 Non-Negotiables: 1. Appoint AI Accountability Leader   Assign a senior executive responsible for AI compliance, oversight, and reporting. 2. Establish Cross-Functional AI Board   Include legal, security, HR, data, and business teams for governance and approvals. 3. Define Legal AI Role   Clarify provider versus deployer obligations and compliance responsibilities. 4. Maintain Technical Documentation   Document architecture, data sources, performance metrics, and intended use limitations. 5. Disclose AI Usage Transparently   Notify users about AI interactions and synthetic content usage. 6. Publish Model Transparency Reports   Document purpose, performance across demographics, limits, and out-of-scope scenarios. 7. Implement Logging and Audits   Track inputs, outputs, versions, and decisions for investigations and traceability. 8. Ensure Decision Explainability   Provide meaningful explanations and enable human review of high-impact decisions. 9. Create Comprehensive AI Inventory   Document all AI systems, APIs, models, and embedded SaaS tools. 10. Develop AI Acceptable Use Policy   Define permitted uses, prohibited activities, and approved data types. 11. Classify AI Risk Levels   Categorize systems into prohibited, high, limited, or minimal risk tiers. 12. Conduct Formal Risk Assessments   Identify harms, discrimination risks, and safety issues before deployment. 13. Test for Bias Regularly   Evaluate outputs across protected groups and document mitigation steps. 14. Review Third-Party AI Risk   Assess vendor compliance, contracts, liabilities, and regulatory responsibilities. 15. Govern Training Data Legality   Track licenses, avoid unauthorized scraping, and respect copyrights. 16. Perform Required DPIAs   Assess high-risk personal data processing under GDPR and similar regulations. 17. Confirm Lawful Data Basis   Verify consent, contractual necessity, or legitimate interest before processing data. 18. Apply Data Minimization Rules   Limit data usage and enforce strict retention schedules. 19. Secure AI Infrastructure Assets   Protect pipelines, weights, APIs, and model endpoints with strong controls. 20. Support Data Subject Rights   Enable access, correction, deletion, restriction, and automated decision opt-outs. The real shift in enterprise AI is this. From model performance to governance readiness. From proof of concept to regulatory durability. If your AI cannot pass audit, it cannot scale. Compliance is not friction. It is infrastructure. PS: If you found this valuable, join my weekly newsletter where I document the real-world journey of AI transformation. ✉️ Free subscription: https://lnkd.in/exc4upeq #EnterpriseAI #AIGovernance #ResponsibleAI

Explore categories