top of page

Disclosing AI in Employee Comms: A Practical Checklist

The EU AI Act's Article 50 transparency obligations applied across the Union on 2 August 2026. Employees should know when they are talking to a machine, and when a leader video or a high-stakes note is synthetic. Before you write a single label, sort the duties by who they bind. Article 50 puts most of its weight on providers, meaning the companies that build AI systems and place them on the market. Two of its paragraphs land on deployers, which is what your organisation becomes the moment it runs a benefits bot or publishes a synthetic clip.


This post describes what the Regulation says and where each duty sits. It does not tell you what your organisation must do, because that turns on facts about your systems and jurisdictions that your counsel holds and this post does not. IC owns the operational layer, the label an employee sees and the disclosure copy an employee reads.


Who Article 50 binds, and who it does not


Article 50(1) binds providers. They have to design systems that interact directly with people so those people know they are dealing with AI. That duty carries a condition on its face. It applies "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use" (Article 50, European Commission AI Act Service Desk). The Commission's own FAQ on Article 50 says that exception "should be interpreted in a restrictive manner, given that it deprives people of transparency," and asks providers to judge obviousness against an average person who is reasonably well-informed, circumspect and observant. Two things follow for IC. Your vendor decides whether to rely on that carve-out, and a bot named "Ava" with a human-sounding greeting is a poor place to rely on it.


Article 50(2) also binds providers. A provider placing a system that generates synthetic audio, image, video or text content has to mark the output in a machine-readable format so it is detectable as artificially generated or manipulated. This paragraph carries the one phase-in that internal communicators keep missing. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, left the 2 August 2026 applicability date for Article 50 alone but added a short runway for the marking duty. The Commission's FAQ describes "a limited grace period ... envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content," with providers of those systems required to comply "only as from 2 December 2026." So ask each vendor when the system was placed on the market. A tool your team bought last month has no runway at all, and content generated before August does not need retroactive marking.


Article 50(3) binds you. This is the paragraph aimed squarely at workplace deployers, and it is the one most disclosure checklists skip. "Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable." The threshold is exposure rather than interaction, which is a lower bar than the chatbot case. An employee who walks past a camera never types anything and is still owed the notice.


Article 50(4) binds you as well. Deployers who generate or manipulate image, audio or video content that resembles real people or events have to disclose that the content is artificially generated or manipulated. The same paragraph covers AI-generated text published to inform the public on matters of public interest, and it carves out text that went through human editorial review with a named person or organisation holding editorial responsibility. Most employee communications are not published to inform the public, so the text limb rarely reaches an intranet post. The deepfake limb reaches a synthetic leader video the day you publish it.


Article 50(5) sets the timing for all of it. The notice has to arrive "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure," and it has to meet accessibility requirements. A disclosure buried three exchanges into a chat fails that wording on its face.


Emotion inference sits behind a harder line than disclosure


Article 50(3) tells you to inform people about an emotion recognition system. Article 5 tells you that in a workplace you probably cannot run one at all.


Article 5(1)(f) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons" (Article 5, European Commission AI Act Service Desk). That prohibition has applied since 2 February 2025, eighteen months before the transparency rules, and the Digital Omnibus did not touch it. Disclosing a prohibited practice does not make it permitted, so test Article 5 before you reach for Article 50.


The scope matters, because IC teams run sentiment tooling constantly. The Commission's guidelines on prohibited AI practices, published on 4 February 2025, tie the prohibition to the Act's definition of an emotion recognition system, which rests on inference from biometric data. On that reading, a tool that scores facial expression in a recorded town hall or voice affect on a manager call falls inside the ban, while a tool that scores the wording of open-text survey comments falls outside it. Practitioner commentary treats that biometric limit as a real narrowing of the red line rather than a settled comfort, so treat a vendor claim of "sentiment analysis" as a question to ask. Find out what the system measures before you decide which article you are in.


Label synthetic media without turning notes into legal footers


Over-labeling and under-labeling both fail. If a routine chat reply carries a three-paragraph AI notice, people stop reading notices. If a synthetic CEO video lands without a signal, people stop trusting video.


Use visible, plain labels at the point of consumption for high-impact synthetic media, meaning AI-generated or manipulated audio and video of leaders, along with any clip an employee could mistake for a real recording. Put the label where the eye hits first, in the caption or the intro slate, rather than in a footer few people open on a phone. That placement is what Article 50(4) and Article 50(5) point at when your own team publishes the asset.


For written internal content, calibrate to stakes. A draft that a human rewrote and signed off may need only an internal provenance mark so reviewers run a full verification pass. High-stakes pieces that employees will treat as official guidance need a short line saying AI assisted the draft, naming the human who approved the facts and giving a contact for questions. Agree the label language once with legal and brand so teams reach for the same few phrases. None of that written-content labeling comes from Article 50, which is worth saying out loud to a nervous stakeholder. It is craft, and it is how you keep trust between the paragraphs the law does cover.


Chatbot disclosure, where the duty is your vendor's and the experience is yours


If employees use a benefits bot or an HR FAQ assistant, Article 50(1) puts the design duty on whoever provides that system. Your leverage is procurement and acceptance testing. Ask the vendor to state in writing that the system self-discloses at first interaction, and ask whether they rely on the "obvious" exception anywhere in the flow.


Then judge the experience you are handing employees, which is a higher bar than the Regulation sets. Good first-screen disclosure names the system as AI and sets expectations for what it can answer. It also offers a working path to a human when the question turns sensitive, and that path has to hold under load. A friendly first name with a buried line after three exchanges clears none of it.


Inventory the bots you already run. Note which tools face staff and whether the disclosure shows up in each channel the bot lives in, then put a name against the intro copy. If a third party hosts the experience, you still own whether the employee experience is honest, and you still answer for it internally when it is not.


Honest disclosure plus targeted delivery


Disclosure is a communication. Employees need the rule at the moment they open the bot or watch the video. File the policy on the intranet as reference, and put the live notice in the product and media surfaces where the interaction happens. Article 50(5) says the same thing in colder language when it asks for the notice at the latest at first interaction or exposure.


Segment the audiences. Leaders and managers need decision rules covering which content carries a label and who approves synthetic media, and anyone about to open a specific assistant needs onboarding at first use. Creators in IC and HR need the label library plus the stop rules for high-risk content. One all-staff blast rarely serves those groups equally.


Choose channels for reach. Put chatbot disclosure inside the product surface and media labels on the asset. Put the broader standard where people open messages, which for most workforces means email and whichever chat tool sits on the phone. Then confirm the notice landed for the groups most likely to be misled or most likely to publish unlabeled content.


Segment-level engagement signals, including from tools like Cerkl Broadcast when you have them, turn a disclosure campaign into a follow-up list. If your analytics are coarser, assign managers a short confirmation pass for the audiences that matter.


A one-page disclosure checklist for IC


Copy this into the runbook. Each item names the party the duty falls on, so you brief legal on the right things and stop chasing your vendor's homework.


  • Yours as deployer. Inventory each employee-facing AI system and each pipeline that produces synthetic or model-heavy content, and record which company provides it and when it was placed on the market.


  • Yours as deployer. Run that inventory against Article 5 before Article 50. Anything that infers employee emotions from biometric data comes out of the stack, whatever label you were planning to attach.


  • Yours as deployer, Article 50(3). Inform the people exposed to any emotion recognition or biometric categorisation system that the system is operating, and process the personal data under the GDPR.


  • Yours as deployer, Article 50(4). Disclose artificial generation or manipulation when your team publishes synthetic audio or video that resembles real people or events.


  • Your vendor's, Article 50(1). Self-disclosure at first interaction for systems that interact directly with employees. Put it in the contract and the acceptance test, and ask whether they lean on the "obvious" carve-out.


  • Your vendor's, Article 50(2). Machine-readable marking of generated output. Ask for the placing-on-the-market date, since a system that predates 2 August 2026 has until 2 December 2026 and a newer one does not.


  • Craft standard, no statute behind it. Plain-language label copy agreed with legal and brand, stored where creators reach for it.


  • Craft standard, no statute behind it. Manager briefing on which content carries a label and how to answer "was this written by AI?"


  • Craft standard, no statute behind it. Stop rules that hold regardless of the Regulation. No unlabeled synthetic leader media, and no high-stakes claim from an AI draft without a named human verifier.


  • Yours as deployer. Re-run the inventory quarterly as tools change and as vendors ship marking against the December date.


Article 50 raises the minimum for transparency, and it raises it in different places for you and for the companies that sell you software. Employees judge you on whether the disclosure arrived early and in plain words. Label the content that could deceive them and disclose the systems they are exposed to, then treat that notice like any other message that has to land.


 
 
 

Comments


bottom of page