AI in Operations

AI Transparency Has Become an Operating Process

Photo by Markus Spiske (@markusspiske) on Unsplash

For European companies, the discussion around AI governance changed on 2 August 2026. 

That was the date when important transparency provisions of the EU AI Act became applicable and the European Commission’s AI Office and national authorities began exercising broader enforcement powers. Providers of relevant generative AI systems must support identification of AI-generated material, while deployers face disclosure requirements in areas including deepfakes and certain AI-generated public-interest content.

The regulation is usually discussed as a legal development. Inside a company, it creates an operational problem. Before an organisation can label AI-generated material correctly, it has to know where AI enters the production process. Many companies do not.

AI is already buried inside ordinary software

Few businesses now use AI through a single clearly defined system. Marketing teams generate images. Communications teams use language models to edit text. Designers rely on generative functions embedded in creative software. Customer-service platforms produce responses automatically. Employees use meeting assistants, transcription tools and browser extensions.

AI increasingly arrives as a feature inside software the company already owns. That makes the inventory problem difficult. An organisation can ban one public chatbot and still have dozens of AI functions operating elsewhere. The first compliance challenge therefore has little to do with model performance. Someone needs to map the workflow.

Companies need to know what happened to a piece of content

Consider a corporate video. Employees wrote the original script. A language model edited it. An AI voice generated one language version. Software replaced the speaker’s lip movements for another market. A human editor assembled the final film.

Is it AI-generated?

Which components require disclosure?

Who records those decisions?

The European Commission’s 2026 guidance makes distinctions between different forms of synthetic and manipulated material and provides examples intended to clarify the application of Article 50. Companies therefore need provenance information inside the content workflow. That can include the model or application used, the type of transformation performed, whether a human reviewed the result and which disclosure rule applies when the material is published. Compliance moves upstream into production.

Marketing cannot solve this alone

The operational responsibility crosses several departments. Procurement needs to understand what AI capabilities a software product contains. IT needs an inventory of approved applications. Legal and compliance teams need to interpret disclosure requirements. Communications and marketing teams need publication rules.

Cybersecurity teams need to know which systems send company information to external models. Business units need procedures that employees can actually follow.

The organisations most likely to struggle are those that treat AI governance as a policy document owned by one department.

A policy can state what employees should do.

An operating system determines whether they can realistically do it.

Metadata may become part of corporate governance

The next step is likely to be technical.

Instead of asking employees to remember every disclosure requirement manually, companies can preserve information about AI involvement as material moves through internal systems.

A generated image can carry provenance information. A content-management system can record whether a text received human editorial review. Approved AI tools can produce logs showing which transformations they performed.

This creates a governance trail without requiring an employee to reconstruct the creative process six months later.

The approach also helps outside regulation.

If a disputed image appears online, the company can establish how the original was produced. If a customer challenges an automated interaction, records can identify the system involved. If an AI supplier changes its model, the company knows which workflows depend on it.

Transparency becomes useful operational data.

The AI register will become as ordinary as the software register

Companies already maintain inventories of laptops, licences, suppliers, databases and access permissions.

AI will increasingly require its own version.

The useful register will go beyond a list of models.

It should connect the AI system to a business owner, a purpose, approved data, external providers, affected workflows and the controls applied to its output.

That sounds administrative.

It becomes valuable when models change quickly and AI capabilities appear inside applications without a separate procurement decision. Companies cannot govern systems they do not know they are using.

Regulation is forcing companies to understand their own production chain

The immediate reaction to AI transparency rules may be to add labels. The deeper effect could be more valuable. Companies are being pushed to document how synthetic content, automated decisions and AI-assisted work actually move through the organisation. That exposes forgotten software, unclear ownership and workflows built around individual experimentation.

For enterprises, compliance should therefore begin before the label appears. It begins with a more basic question:

Where did AI enter the process?

Companies that can answer that reliably will find the rest of AI governance considerably easier.