RSS Amplifier

BehaviorAl · Jul 22, 2026

Nowe zasady transparentności AI: zgodne nie znaczy zauważone [New AI transparency rules]

0
Sign in to vote or save

Kasia Szczesna · BehaviorAl

Artykuł 50 AI Act wprowadza obowiązek transparentności wobec systemów AI. Komisja Europejska podsumowała go właśnie w przystępnej formie, więc warto przejść przez konkrety, zanim przejdę do tego, co moim zdaniem w tym podsumowaniu jest pominięte.

Przepisy dotyczą czterech sytuacji. Dostawcy systemów AI muszą projektować je tak, żeby użytkownik wiedział, kiedy rozmawia z AI oraz kiedy ma do czynienia z treścią wygenerowaną lub zmodyfikowaną przez AI, jeśli jej pochodzenie da się w wiarygodny sposób zweryfikować. Podmioty wdrażające systemy AI muszą z kolei informować użytkowników, gdy są poddawani rozpoznawaniu emocji lub kategoryzacji biometrycznej, oraz gdy mają do czynienia z deepfake’ami albo tekstem publikowanym w sprawach istotnych publicznie, który powstał bez nadzoru redakcyjnego człowieka.

Treść trzeba oznaczać na dwóch poziomach. Dostawcy generatywnych systemów AI muszą stosować znacznik odczytywalny maszynowo, umożliwiający wykrycie, że treść (tekst, obraz, wideo, audio) została wygenerowana lub zmodyfikowana przez AI, chyba że system pełni funkcję wspomagającą przy standardowej edycji albo nie zmienia istotnie danych wejściowych dostarczonych przez podmiot wdrażający. Podmioty wdrażające muszą z kolei jawnie i w sposób dostrzegalny dla człowieka oznaczyć deepfake’i oraz teksty w sprawach publicznych.

Za brak zgodności grożą kary do piętnastu milionów euro albo do trzech procent globalnego rocznego obrotu firmy, z zasadą proporcjonalności dla małych i średnich przedsiębiorstw. Instytucje unijne mogą zapłacić do siedmiuset pięćdziesięciu tysięcy euro. Systemy generatywne wprowadzone na rynek przed drugim sierpnia dostają okres przejściowy na dostosowanie znakowania do grudnia dwa tysiące dwudziestego szóstego roku.

Nadzór sprawują krajowe organy nadzoru rynku, Urząd ds. AI dla systemów pod jego bezpośrednim nadzorem oraz Europejski Inspektor Ochrony Danych, gdy dostawcą lub podmiotem wdrażającym jest instytucja unijna.

To solidny, potrzebny fundament. I właśnie dlatego przez chwilę chcę się przy nim zatrzymać, zamiast od razu przejść do tego, czego moim zdaniem brakuje.

Przepis mówi, co ma zostać oznaczone i kto za to odpowiada. Nie mówi nic o tym, czy oznaczenie zostanie w ogóle zauważone, ani czy zostanie właściwie zrozumiane w momencie, w którym ma znaczenie.

To dokładnie ten problem, o którym pisałam wcześniej, opisując efekt niewidzialności AI. Ludzie systematycznie nie zauważają sygnałów informujących, że rozmawiają z maszyną, zwłaszcza gdy interakcja jest płynna, empatyczna i dopasowana do ich oczekiwań. Im lepiej zaprojektowany jest system pod kątem użyteczności, tym łatwiej przeoczyć subtelny, prawnie wymagany znacznik gdzieś w rogu ekranu.

Artykuł 50 zakłada, że wystarczy dostarczyć informację, żeby użytkownik podjął świadomą decyzję. To założenie od dawna kwestionuje ekonomia behawioralna. Człowiek nie przetwarza informacji w próżni. Przetwarza ją w kontekście obciążenia poznawczego, presji czasu, przyzwyczajenia do interfejsu i tego, ile uwagi w danym momencie jest w stanie poświęcić. Znacznik odczytywalny maszynowo spełnia literę prawa. Nie gwarantuje, że dotrze do świadomości człowieka w momencie, w którym podejmuje on decyzję.

Widziałam to wielokrotnie w pracy z klientami, jeszcze zanim ktokolwiek mówił o AI Act. Informacja prawnie wymagana i informacja rzeczywiście zauważona to często dwie różne rzeczy, oddzielone decyzjami projektowymi, które nie mają nic wspólnego z tekstem przepisu. Rozmiar czcionki. Miejsce na ekranie. Moment w ścieżce użytkownika, w którym komunikat się pojawia. Czy pojawia się raz, czy jest przypominany. Czy wymaga aktywnego potwierdzenia, czy tylko biernego przescrollowania.

To nie jest krytyka przepisu. Artykuł 50 robi dokładnie to, co powinna robić dobra regulacja, czyli wyznacza minimalny, egzekwowalny standard. Problem pojawia się, gdy firmy traktują spełnienie tego standardu jako punkt końcowy, a nie punkt startowy.

Zgodność prawna odpowiada na pytanie, czy znacznik istnieje. Projektowanie behawioralne odpowiada na pytanie, czy ten znacznik faktycznie zmienia to, jak człowiek interpretuje sytuację, w której się znajduje. To są dwa różne pytania i dwa różne zestawy kompetencji, a firmy, które je zlewają w jedno, kończą z produktem technicznie zgodnym z prawem i jednocześnie bezużytecznym z punktu widzenia realnej ochrony użytkownika.

Właśnie w tej przestrzeni, między literą przepisu a rzeczywistym zachowaniem człowieka, pracuję od lat. To ta sama warstwa, o której pisałam przy okazji frictionless AI, tylko oglądana z innej strony. Tam pytanie brzmiało, ile tarcia zostawić, żeby użytkownik zachował zdolność do myślenia. Tutaj pytanie brzmi, jak zaprojektować obowiązkowy komunikat tak, żeby rzeczywiście dotarł do świadomości, zamiast zniknąć w tle płynnego interfejsu.

Drugi sierpnia wyznacza twardy termin prawny. Nie wyznacza terminu, do którego trzeba zrozumieć, jak ludzie faktycznie zauważają, przetwarzają i reagują na informację, że rozmawiają z maszyną. Ta praca dopiero się zaczyna, i to niezależnie od tego, czy firma jest już zgodna z przepisem.

Pracujesz nad tym, jak w Twoim produkcie ma wyglądać oznaczenie AI, żeby nie tylko spełniało literę Artykułu 50, ale rzeczywiście działało? Chętnie o tym porozmawiam. Link w komentarzu.

On August 2, rules I have been waiting for a long time come into force, and at the same time they leave me a little uneasy.

Article 50 of the AI Act introduces a transparency obligation for AI systems. The European Commission just summarized it in an accessible format, so it is worth going through the specifics before I get to what I think that summary leaves out.

The rules cover four situations. Providers of AI systems must design them so users know when they are talking to an AI and when they are looking at content generated or modified by AI, provided its origin can be reliably verified. Deployers of AI systems, in turn, must inform users when they are subject to emotion recognition or biometric categorization, and when they encounter deepfakes or text published on matters of public interest that was produced without human editorial review.

Content has to be marked at two levels. Providers of generative AI systems must apply a machine-readable mark that enables detection of content (text, image, video, audio) generated or modified by AI, unless the system performs an assistive function for standard editing or does not substantially alter the input data supplied by the deployer. Deployers, in turn, must clearly and perceivably label deepfakes and text on matters of public interest.

Non-compliance can trigger fines up to 15 million euros or up to 3 percent of a company’s global annual turnover, with a proportionality principle for small and medium enterprises. EU institutions can be fined up to 750,000 euros. Generative systems placed on the market before August 2 get a transition period to bring their marking into compliance until December 2026.

Oversight falls to national market surveillance authorities, the AI Office for systems under its direct supervision, and the European Data Protection Supervisor when an EU institution is the provider or deployer.

This is a solid, necessary foundation. And that is exactly why I want to pause on it for a moment before moving to what I think is missing.

The regulation says what needs to be marked and who is responsible for it. It says nothing about whether the mark will actually be noticed, or properly understood at the moment it matters.

This is exactly the problem I wrote about earlier when describing the AI invisibility effect. People systematically fail to notice signals indicating they are talking to a machine, especially when the interaction is smooth, warm, and matched to their expectations. The better a system is designed for usability, the easier it becomes to miss a subtle, legally required mark tucked into a corner of the screen.

Article 50 assumes that supplying information is enough for a user to make an informed decision. Behavioral economics has long challenged that assumption. A person does not process information in a vacuum. They process it under cognitive load, time pressure, habituation to the interface, and however much attention they have left to give in that moment. A machine-readable mark satisfies the letter of the law. It does not guarantee it will reach a person’s awareness at the moment they are making a decision.

I have seen this repeatedly in client work, long before anyone was talking about the AI Act. Legally required information and information that is actually noticed are often two different things, separated by design decisions that have nothing to do with the text of the regulation. Font size. Placement on screen. The moment in the user journey where the message appears. Whether it appears once or is repeated. Whether it requires active acknowledgment or just gets scrolled past passively.

This is not a criticism of the regulation. Article 50 does exactly what good regulation should do: it sets a minimum, enforceable standard. The problem arises when companies treat meeting that standard as the finish line rather than the starting point.

Legal compliance answers the question of whether a mark exists. Behavioral design answers the question of whether that mark actually changes how a person interprets the situation they are in. These are two different questions requiring two different sets of expertise, and companies that collapse them into one end up with a product that is technically compliant with the law and, at the same time, useless from the standpoint of actually protecting the user.

This is exactly the space I have worked in for years, between the letter of the regulation and how a person actually behaves. It is the same layer I wrote about in the context of frictionless AI, just viewed from the other side. There, the question was how much friction to leave in place so the user keeps the capacity to think. Here, the question is how to design a mandatory disclosure so it actually reaches someone’s awareness instead of disappearing into the background of a smooth interface.

August 2 sets a hard legal deadline. It does not set a deadline for understanding how people actually notice, process, and act on the information that they are legally owed. That work is only just beginning, regardless of whether a company is already compliant with the regulation.

Working on how your AI disclosure should look so it doesn’t just satisfy the letter of Article 50, but actually works? I would be glad to talk it through.

No posts

Read the original on behavioralinsight.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.