{"id":33560,"date":"2026-09-10T16:16:11","date_gmt":"2026-09-10T14:16:11","guid":{"rendered":"https:\/\/it.andersen.com\/?p=33560"},"modified":"2026-09-10T16:16:50","modified_gmt":"2026-09-10T14:16:50","slug":"ai-transparency-an-indispensable-pairing","status":"publish","type":"post","link":"https:\/\/it.andersen.com\/en\/ai-transparency-an-indispensable-pairing\/","title":{"rendered":"AI &amp; transparency: an indispensable pairing"},"content":{"rendered":"\n<p><strong>Transparency <\/strong>has long been a cornerstone of the European legal framework, from the protection of personal data to consumer protection. With <strong>the AI Act<\/strong>, however, it takes on a specific role: to reduce the information asymmetry created by the opacity of many artificial intelligence systems. In this issue of the <strong>Compliance &amp; Risk Management <\/strong>Newsletter, professionals from Andersen\u2019s<strong> 231\/Privacy<\/strong> Service Line have explored the relationship between the <strong>principle of transparency and the use of AI systems<\/strong>, with a view to highlighting the ever-increasing importance of adopting compliance measures capable of mitigating risks arising from the use of such systems, thereby strengthening organisational <strong>governance<\/strong>.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI ACT: New Transparency Rules for Businesses and Professionals\u00a0<\/h2>\n\n\n\n<p>As of August 2, 2026, the obligations provided for in <strong>Article 50 of the AI ACT <\/strong>shall apply. Unlike the requirements for high-risk systems, they depend on the system\u2019s features and use. <strong>Providers <\/strong>of systems intended to interact directly with people must <strong>inform them <\/strong>that they are interacting with an AI, unless this is already evident. Providers of generative systems must also make synthetic outputs detectable in a machine-readable format. <strong>Deployers<\/strong> also have specific duties: those using emotion recognition or biometric categorisation systems must inform the individuals concerned; those disseminating deepfakes or certain AI-generated texts of public interest must disclose their artificial origin, subject to the exceptions provided for.&nbsp;<\/p>\n\n\n\n<p>Not everyone, therefore, is subject to the same obligations. For businesses and professionals<strong>,<\/strong> the first step is <strong>to identify their role \u2013 whether as a provider or a deployer \u2013 and to map out systems, outputs and recipients<\/strong>. Transparency thus becomes an operational obligation: knowing who does what, towards whom and by what means.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Regulating the Use of AI in the Workplace Through the Code of Ethics\u00a0<\/h2>\n\n\n\n<p>Artificial intelligence is rapidly becoming integrated into business processes, offering new opportunities for efficiency and innovation, whilst at the same time introducing unprecedented risks: from the management of personal data and confidential information to the misuse of AI tools by employees.&nbsp;<\/p>\n\n\n\n<p>In this context, the <strong>Code of Ethics <\/strong>can serve as one of the tools through which a company defines the fundamental principles and rules for the responsible use of artificial intelligence.&nbsp;<\/p>\n\n\n\n<p>It can set out certain <strong>general principles of conduct<\/strong>, which must then be put into practice through policies, procedures and operational instructions. These include, for example, transparency in the use of AI, a ban on entering confidential information into unauthorised tools, human verification of outputs, and a ban on using AI for unlawful or discriminatory purposes.&nbsp;<\/p>\n\n\n\n<p>The Code of Ethics may also expressly refer to the need to use only <strong>AI tools approved by the company, <\/strong>thereby becoming <strong>a<\/strong> genuine <strong>\u2018framework\u2019 for AI governance<\/strong>, capable of guiding individual behaviour and strengthening a culture of compliance, in coordination with the system of corporate procedures, controls and responsibilities.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Information requirement for emotion recognition and biometric categorization\u00a0<\/strong><\/h2>\n\n\n\n<p>Anyone using <strong>emotion recognition <\/strong>or <strong>biometric categorisation <\/strong>systems as part of their business must <strong>inform <\/strong>the individuals concerned in advance about how the system works and must process <strong>personal data <\/strong>in accordance with data protection legislation (GDPR).&nbsp;&nbsp;<\/p>\n\n\n\n<p>On the operational side, it is therefore essential <strong>to identify the AI systems in use <\/strong>(e.g. access gates and attendance monitoring, contact centers with voice tone analysis, retail analytics on customers\u2019 faces), <strong>specifying one\u2019s role <\/strong>(provider or deployer, or both). Furthermore, it is advisable to check whether the system is subject to <strong>the prohibition <\/strong>set out in Article 5: from 2 February 2025, emotion recognition in the workplace and in educational establishments (except for medical or security purposes) and biometric categorisation aimed at inferring sensitive data will be prohibited.&nbsp;<\/p>\n\n\n\n<p>If the systems used are not subject to the ban, you must provide <strong>a notice in a clear and distinguishable manner<\/strong>, at the latest at the time of first exposure.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Although the obligations for high-risk systems have been postponed until 2 December 2027 (Digital Omnibus), breaching transparency obligations already exposes organisations to <strong>fines <\/strong>of up to \u20ac15 million or 3 per cent of annual global turnover. It is therefore advisable to review the notices in place and examine the contractual clauses in agreements with suppliers.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Risk Manager\u2019s Added Value in AI Governance\u00a0<\/h2>\n\n\n\n<p><strong>Risk management<\/strong> often enters an organisation only after damage has occurred or a threat has become impossible to ignore. With <strong>AI<\/strong>, however, waiting means falling behind: we are in an exploratory phase where opportunities and consequences evolve together.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The <strong>Risk Manager <\/strong>plays a pioneering role: researching, understanding and anticipating, because great capabilities can have equally significant impacts.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The method remains that of <strong>risk assessment<\/strong>: identification, analysis and evaluation of risks, followed by <strong>risk treatment<\/strong>. Discriminatory content, unverified AI outputs in production or disclosure of confidential data are different but <strong>interconnected risks<\/strong>&nbsp;<\/p>\n\n\n\n<p>The limited availability of historical data makes it difficult to estimate probability and impact, but it is necessary to draw up a <strong>risk map <\/strong>and compare the residual risk with the <strong>risk appetite<\/strong>. A non-critical error may be tolerable if it occurs less frequently than human error; exposure to data breaches or cyber-attacks, however, is not. The Risk Manager\u2019s added value emerges in the development of a risk treatment plan. It is therefore essential to define <strong>authorised GenAI tools<\/strong>, internal guidelines and <strong>procedures<\/strong>, and technical measures to ensure data<strong> security<\/strong>, as well as <strong>to train <\/strong>staff on AI and keeping management informed. Not simply bans, but concrete tools that transform risk into informed adoption and AI into <strong>value for the business<\/strong>.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Transparency has long been a cornerstone of the European legal framework, from the protection of personal data to consumer protection. With the AI Act, however, it takes on a specific role: to reduce the information asymmetry created by the opacity of many artificial intelligence systems. In this issue of the Compliance &amp; Risk Management Newsletter, [&hellip;]<\/p>\n","protected":false},"author":125,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[50],"tags":[],"class_list":["post-33560","post","type-post","status-publish","format-standard","hentry","category-insights"],"acf":[],"_links":{"self":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/users\/125"}],"replies":[{"embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/comments?post=33560"}],"version-history":[{"count":2,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33560\/revisions"}],"predecessor-version":[{"id":33564,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/posts\/33560\/revisions\/33564"}],"wp:attachment":[{"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/media?parent=33560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/categories?post=33560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/it.andersen.com\/en\/wp-json\/wp\/v2\/tags?post=33560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}