An AI information notice is the public document explaining how your AI systems process personal data. It answers the GDPR, not Article 50 of the AI Act, which requires disclosure at the moment of interaction. You need both.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
An AI information notice is the public document explaining how your AI systems process personal data. It answers the GDPR, not Article 50 of the AI Act, which requires disclosure at the moment of interaction. You need both, and confusing them is the most common mistake we see in 2026.
Since 2 August 2026, the transparency obligations of Regulation (EU) 2024/1689 apply in full. Many companies believe a paragraph added to their privacy policy settles the matter. It does not, and the European Commission said so explicitly in the guidelines it published on 20 July 2026. For the wider picture, our AI Act compliance guide for SMEs and nonprofits sets out the framework. This article focuses on the drafting itself.
The GDPR notice and the AI Act transparency disclosure target different people, at different moments, with different content.
The GDPR information notice addresses people whose personal data you process. It is written, published and available at any time. The French data protection authority uses the exact phrase general information notice in its AI guidance: it is the mechanism to use when individual information is impossible or would require disproportionate effort, under Article 14(5)(b) of the GDPR.
The Article 50 disclosure addresses people exposed to an AI system, whether or not personal data is involved. It happens at the moment of interaction or exposure. A visitor opening your AI chatbot must know they are talking to a machine before typing the first message. No notice buried in a footer performs that function.
In practice, an SME running a conversational assistant on its website needs both. The underlying logic of each regime is compared in our article on the AI Act and the GDPR.
As soon as you process personal data through an AI system and cannot inform each person individually.
The table below covers the situations SMEs meet most often.
| Use case | Published GDPR notice | AI Act Article 50 disclosure |
|---|---|---|
| Customer support chatbot on the website | Yes, Article 13 wording in the form or chat window | Yes, from the first interaction |
| Automated CV screening | Yes, candidates informed at collection | Not under Article 50, but check the high-risk regime |
| AI-generated marketing visuals | Depends on the data processed | Machine marking by the provider, visible disclosure if the output resembles a real person |
| Automatic meeting transcription | Yes, participants informed before recording | No, unless emotion recognition is involved |
| Sentiment analysis on customer calls | Yes | Yes, exposed persons must be informed |
| Training dataset built by scraping | Yes, general notice indicating the sources | No |
Two useful caveats. First, the GDPR obligation has existed since 2018 and did not wait for the AI Act. Second, if your systems fall under the prohibited practices of Article 5, no notice will make them lawful. Emotion recognition on employees, for instance, is banned in the workplace, not merely subject to disclosure.
Four distinct obligations, split between providers and deployers, and none of them takes the form of a published document.
For providers, meaning those who develop a system or have it developed and place it on the market under their own name: inform people that they are interacting with an AI unless it is obvious, and mark generated content in a machine-readable format. The Commission guidelines state that the obvious exception must be read restrictively, against the standard of a reasonably well-informed and observant average person.
For deployers, meaning the large majority of SMEs using off-the-shelf tools: inform people exposed to emotion recognition or biometric categorisation systems, and clearly label deepfakes as well as text published to inform the public on matters of public interest.
Three points that are regularly misread, all confirmed in the Commission FAQ last updated on 24 July 2026:
Enforcement sits with national market surveillance authorities, and fines can reach 15 million euros or 3 % of worldwide turnover, with proportionality taken into account for SMEs. The detail is in our article on AI Act sanctions.
The Articles 13 and 14 items, plus a plain explanation of how the system works.
Regulators are clear on this: the technical complexity of an AI system does not excuse an unreadable notice. The recommended approach is layered information, with the controller identity, purposes and individual rights at the first level, and complete detail one click away.
The expected blocks:
Two AI-specific additions. If you cannot identify the people in your dataset, say so under Article 11 of the GDPR and specify what additional information they can provide to enable identification. And if your model has memorised training data, explain the risk of that data being regurgitated and the measures taken to limit it.
Six blocks are enough, provided each one is filled with your actual details rather than generic wording.
Block 1, who processes and why. Name the entity, give a working contact address, state the purpose in one sentence a customer understands. Example: our assistant answers questions about opening hours, pricing and order tracking.
Block 2, what data and where it comes from. Separate what the person enters from what you obtain elsewhere. For indirect collection with many sources, information by categories of sources is accepted, naming the main ones.
Block 3, how the AI intervenes. This is the block most often rushed. Say whether the system decides, suggests or merely rephrases. State whether a human is involved, at which point, and what that changes for the person.
Block 4, how long and where it goes. Retention of conversations, recordings and training data. Processors, hosting providers, server locations.
Block 5, rights and how to exercise them. An address, a response time, and where relevant the statement that identification is not possible.
Block 6, version and date. A notice without an update date loses its evidential value at the first inspection.
Five pitfalls appear in almost every notice we review during audits.
A dedicated page, two clicks from any page of the site, reviewed at least twice a year.
A page separate from the general privacy policy is not mandatory, but it makes compliance easier to demonstrate and easier to read. If you prefer a single document, add a clearly identified section on AI-related processing with a clickable table of contents.
On maintenance, the starting point is always the same: knowing what you actually run. An up-to-date inventory of AI tools in service, each with its provider, purpose, data processed and status under the AI Act, is what keeps the notice true. It is also the first deliverable of any serious AI audit. On the exact scope of obligations depending on your role, our article on who the AI Act applies to clarifies the provider and deployer distinction, which drives everything else.
Does every company need an AI information notice?
No. It becomes mandatory as soon as you process personal data through an AI system without being able to inform each person individually. A company using generative AI purely internally, on documents containing no personal data, has no notice to publish but remains subject to the other obligations of the regulation.
What is the difference between an information notice and an internal AI policy?
The notice faces outwards: customers, candidates, users, anyone whose data you process. The internal AI policy faces your staff and sets the rules for using the tools. The two documents feed each other but do not replace each other.
Do we have to label content generated before August 2026 retroactively?
No. The Commission states that content generated before 2 August 2026 does not need retroactive labelling. It nonetheless encourages deployers to do so where possible.
Must a chatbot announce it is an AI even when that is obvious?
The obligation falls away when the artificial nature is obvious to a reasonably well-informed average person. The July 2026 guidelines call for a restrictive reading of that exception. For an SME, displaying the notice costs nothing and removes any argument.
Who enforces this and what is actually at stake?
National market surveillance authorities. Fines can reach 15 million euros or 3 % of worldwide turnover for transparency breaches, with proportionality taken into account for SMEs and small mid-cap companies.
Is the code of practice on transparency of AI-generated content mandatory?
No, adhering to it is voluntary. It does provide legal predictability and a recognised way to demonstrate compliance. Providers and deployers who do not sign up must demonstrate compliance by other means and can expect more requests for information.
Do our teams need training to write this notice?
Drafting belongs to legal and the data protection officer, but it requires knowing what each tool actually does. That is where the subject becomes operational. Our article on Article 4 of the AI Act and AI literacy covers what remains required after the 2026 amendment.
We work on the part that usually stalls: building the real list of AI systems in service, qualifying the company role for each one, then producing the two transparency mechanisms expected. In practice that means an annotated inventory, a notice drafted from your actual processing operations, and a checklist of disclosures to embed in your interfaces.
Framing happens upfront with your teams, because a notice written without the people who use the tools rarely describes reality. Our AI training for business includes this compliance component so teams recognise when a use case triggers an obligation.
If you want to know where you stand, the free 30-minute audit maps the starting point and identifies the priority gaps. For the full picture of what applies to your organisation, go back to the AI Act compliance guide for SMEs and nonprofits.
Book your free audit at cal.com/growthperf/audit-gratuit.