AI governance and business
The EU’s AI Transparency Rules Are Live. Estonian Companies Need a Process, Not Just a Label
From chatbots to synthetic media, the new obligations require businesses to know whether they provide an AI system, deploy one, or publish its output.
The European Union’s artificial-intelligence rules moved from preparation into daily business operations on 2 August 2026. Article 50 of the AI Act now requires transparency in several situations where people interact with AI or encounter content generated or manipulated by it.
For Estonian companies, the immediate challenge is not to attach an “AI-generated” label to everything. The challenge is to identify which systems and outputs fall within the rules, which role the company plays, and where disclosure must appear in the customer or publishing journey.
The distinction matters because the obligations are divided between providers — organisations that develop an AI system or place it on the market under their name — and deployers, which use an AI system under their authority. A business may be a deployer in one workflow and a provider in another.
Four situations require particular attention
The European Commission’s Article 50 guidelines group the practical obligations around four types of exposure.
First, providers of AI systems intended to interact directly with natural persons must design them so that people are informed that they are interacting with AI, unless this is obvious to a reasonably well-informed and observant person in the circumstances. A customer-service chatbot, automated sales assistant or conversational support tool therefore needs a clear notice at the point of interaction when its nature is not already evident.
Second, providers of systems that generate synthetic audio, images, video or text must make outputs detectable as artificially generated or manipulated in a machine-readable format. The law calls for techniques that are effective, interoperable, robust and reliable as far as technically feasible. This is a product and delivery-pipeline requirement, not merely a sentence added by the end user.
Third, deployers of emotion-recognition or biometric-categorisation systems must inform people exposed to those systems. Data-protection rules continue to apply separately. In workplace and education settings, some uses of emotion recognition are prohibited rather than merely subject to disclosure, so a label cannot make a prohibited practice lawful.
Fourth, deployers must disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. The text rule contains an important exception where the content has undergone human review or editorial control and a person or organisation carries editorial responsibility. That exception should not be treated as a casual checkbox: the review and responsibility must be real.
The new deadline does not cover every use of AI
The Commission states that the majority of AI systems remain in the minimal- or no-risk category. Internal use of an AI tool for drafting, translation or idea generation does not automatically require every resulting document to carry a public label.
At the same time, internal use is not outside governance. Article 4 of the AI Act has required providers and deployers to support the AI literacy of staff and other people operating AI on their behalf since February 2025. The Commission’s updated guidance says no particular certificate or mandatory governance structure is required, but organisations should adapt literacy measures to their systems, people and risks and may keep internal records of training and guidance.
The practical rule is therefore proportionality, not absence of control. A spelling assistant and a public-facing voice clone should not pass through the same approval route.
The 2026 Digital Omnibus changed part of the calendar
The original AI Act calendar was amended in July 2026 by Regulation (EU) 2026/1744. The general transparency obligations still apply from 2 August 2026. However, providers of synthetic-content systems placed on the market before that date have until 2 December 2026 to bring the machine-readable marking required by Article 50(2) into compliance.
The same amendment moved the main requirements for stand-alone high-risk systems to 2 December 2027 and for high-risk systems embedded in products covered by specified safety legislation to 2 August 2028. Those later dates do not postpone the transparency duties that are already applicable.
This separation is important for budgeting. A company can plan a longer conformity programme for a genuinely high-risk system while still correcting chatbot notices, content labelling and editorial workflows now.
A workable operating model for an Estonian company
Compliance becomes manageable when it is organised as a business process rather than a one-off legal memo.
- Create an AI register. List customer-facing, employee-facing and publishing tools, their owners, vendors, purposes and affected people.
- Record the company’s role. For each use case, identify whether the company is a provider, deployer, importer, distributor or merely the recipient of an output. Confirm difficult cases with specialist advice.
- Map public touchpoints. Locate chat windows, automated calls, generated media, public-interest publications and any biometric or emotion-related functions.
- Build disclosure into the product. The notice should appear no later than the first interaction or exposure. Machine-readable marking should survive the normal publishing and export pipeline.
- Define editorial control. Name the person who reviews public-interest text, document what was checked and make responsibility visible inside the organisation.
- Obtain evidence from suppliers. Contracts and onboarding records should state which Article 50 measures the vendor supplies, what metadata can be lost during export and how updates are communicated.
- Train by role. Customer service, marketing, product, HR and management face different risks. Guidance should reflect the systems they actually use.
Estonia’s Consumer Protection and Technical Regulatory Authority says it is to take a competent-authority role in AI-system supervision and that transparency oversight will include informing people about AI interactions and marking synthetic content. Its business page also directs companies to the European Commission’s AI Act Compliance Checker and invites questions about implementation.
Trust is an operating asset
Transparency is sometimes described only as a compliance cost. For a small, digitally intensive economy, it is also infrastructure for trust. Customers are more willing to use automation when they know when a machine is speaking, who remains responsible and how to escalate to a person.
The companies that handle the new rules well will not be those that place the largest number of warnings on their websites. They will be those that make the origin of automated interaction clear without damaging usability, preserve evidence through the content chain and keep human responsibility visible.
The deadline has passed. The useful management question is now concrete: can the company show where AI is used, what role it plays, what people are told and who owns the decision?
Information was checked on 4 August 2026. The article provides general business analysis and is not individual legal, compliance or data-protection advice. Classification and obligations depend on the facts of each system and use case.
Main sources
- EUR-Lex: Regulation (EU) 2024/1689, including Article 50
- EUR-Lex: Regulation (EU) 2026/1744, Digital Omnibus on AI
- European Commission: Article 50 transparency guidelines
- European Commission: AI literacy questions and answers
- TTJA: artificial-intelligence systems and supervision in Estonia
Martin Repinski