arrow-downcircle-playclosecrossdowndownward-rightdropdown-arrow-transparentdropdown-arrowemail-solidemailfacebook-solidfilterhamburgerillustration-aucklandillustration-wellingtonlayer-groupleftlinkedIn-solidlinkedIn-whitelinkedInloadermenuphonerestartrightsearchtwitter-solidupward-right-lgupward-rightvCard

AI transparency: Global obligations for New Zealand businesses

  • Legal update

    30 July 2026

AI transparency: Global obligations for New Zealand businesses

The European Union (EU) and Australia are introducing new transparency obligations that will affect many New Zealand businesses using AI tools, chatbots and automated decision-making systems.

EU AI transparency: What the new rules mean for your business 

Your chatbot may pose an EU compliance problem from next week. If your AI system reaches European users, the EU’s new transparency rules apply to you. From 2 August 2026, Article 50 of the EU Artificial Intelligence Act (the AI Act) requires anyone who builds or uses AI to tell people when they are interacting with it, and to label the content it produces. 

The AI Act has extraterritorial reach. It applies regardless of where a business is incorporated or where its systems operate, so long as those systems are made available to EU users or their outputs are used within the EU.

Does the EU AI Act apply to my business?

Yes, if you develop, provide, or deploy AI systems (including chatbots, virtual assistants, or generative AI tools) that reach EU users, or if you use an AI system to deliver AI-enabled services to EU consumers or businesses. The same entity can be both a “provider” (an entity that builds and places an AI product on the market) and a “deployer” (an entity that uses an existing AI tool under its own authority in professional activities). The distinction matters because Article 50 allocates different obligations to each role.

The four obligations

Article 50 imposes four transparency obligations, split between providers and deployers. 

  1. Tell people they are talking to AI (Article 50(1)) 
    Providers of AI systems designed to interact directly with people must develop and design the AI system in such a way that users are informed they are interacting with AI. This covers chatbots, virtual assistants, automated phone systems, and AI agents. An exception applies where the AI nature is obvious to a reasonably well-informed, observant and circumspect person. On 8 May 2026, the European Commission published draft guidelines on the implementation of Article 50 (the Draft Guidelines), which indicate the “obvious AI” exception will not cover general-purpose chatbots or AI help-desk tools. 
  2. Mark AI-generated content so machines can read it (Article 50(2))
    Providers of generative AI systems (including large language models) that produce synthetic audio, images, video, or text must mark those outputs to show they have been generated or manipulated by an AI system. The providers of those systems must enable marking in a machine-readable format, so far as technically feasible. The marking must be effective, interoperable, robust, and reliable. Technical feasibility is assessed objectively. 
    The obligation does not apply where the AI performs only an assistive function for standard editing (such as grammar correction) or does not substantially alter the input data or its meaning. The Draft Guidelines construe this carve-out narrowly. For example, AI-generated summaries or translations of text, object removal from images, or colour and contrast adjustments do not qualify for the exemption. For generative AI systems already on the EU market before 2 August 2026, the AI Omnibus provisional agreement of May 2026 grants providers until 2 December 2026 to meet the machine-readable marking requirement.
  3. Disclose emotion recognition and biometric categorisation (Article 50(3))
    Deployers of AI systems that identify or infer emotions or that categorise individuals using their biometric data must inform every individual exposed to the system that it is in use. This covers, for example, systems that infer sentiment from facial expressions or voice tone, or that assign individuals to categories such as age, gender, or ethnicity. 
  4. Label deepfakes and AI-generated public interest text (Article 50(4))
    Deployers who produce deepfakes (which are AI-generated or manipulated content resembling existing persons, objects, places or events that would falsely appear authentic) must disclose the content has been artificially generated or manipulated. For deepfakes used in artistic, creative, satirical, fictional or analogous works, the obligation is limited to disclosure that does not hamper display or enjoyment of the work. 
    Deployers publishing AI-generated or AI-manipulated text to inform the public on matters of public interest must also disclose its AI origin. A carve-out applies where the text has been subject to genuine human editorial review, being substantive editorial oversight, not merely reading or approving the text, and a person or organisation assumes editorial responsibility for publication. The Draft Guidelines indicate that spell-checking or a superficial grammatical review before publication does not constitute genuine human review.

In each case, disclosure must be clear, distinguishable, and provided at the latest at the time of first interaction or exposure. Disclosure buried in terms and conditions or footnotes does not comply. AI systems authorised by law to detect, prevent, investigate, or prosecute criminal offences are exempt from the transparency obligations described above.

The Code of Practice: Your compliance benchmark

On 10 June 2026, the European Commission (Commission) published its final Code of Practice on Transparency of AI-Generated Content (the Code). The Code does not create binding legal obligations beyond those in the AI Act itself. It explains how providers should mark AI-generated content, and how deployers should label deepfakes. The Code and the Draft Guidelines are complementary. The Draft Guidelines address the full scope of Article 50 and provide the Commission’s interpretive guidance on its scope and application, while the Code focuses specifically on the technical and organisational implementation of Articles 50(2) and 50(4).

Signatories to the Code receive increased regulatory trust, and supervisory authorities will assess compliance against the Code’s standards. Non-signatories must independently demonstrate they meet Article 50, including through a gap analysis against the Code. So, in practice, the Code is the compliance benchmark for marking and labelling obligations.

The Code’s key recommendations for providers are:

  • Mark outputs using a multi-layered approach combining digitally signed metadata and imperceptible watermarking, with provenance information encouraged. Markings should be effective, reliable, robust and interoperable.
  • Make detection tools or services freely available so users can verify whether content was AI-generated or manipulated. Detection results should be clear, understandable and accessible.
  • Avoid removing existing transparency markings and discourage tampering by others. Do not promote tools designed to circumvent machine-readable marks.
  • Test, monitor, document and regularly review marking and detection systems. Cooperate with market surveillance authorities to demonstrate compliance.

The Code’s key recommendations for deployers are:

  • Use the publicly available EU ‘AI’ icon (or an equivalent label) when disclosing deepfakes and AI-generated published text. Separate icons distinguish fully AI-generated content from AI-manipulated (partially modified) content.
  • For images, labels should be persistently visible. For video, labels should appear at the beginning and at regular intervals (at minimum after interruptions such as advertising breaks). For audio-only content, an audible disclaimer is recommended at the outset.
  • Implement internal processes, training and review mechanisms to ensure content is correctly labelled. Maintain channels for users or third parties to report missing or incorrect labelling, and correct issues promptly.
Australia: A closer-to-home transparency obligation for automated decision-making

The EU is not the only jurisdiction tightening transparency rules for technology use.

From 10 December 2026, Australia’s Privacy Act 1988 (Cth) (the Australian Privacy Act) will require organisations and agencies bound by the Australian Privacy Principles to disclose in their privacy policies how they use automated decision-making (ADM) that could reasonably be expected to significantly affect individuals’ rights or interests. The obligation takes effect through new APPs 1.7, 1.8 and 1.9.

The Australian Privacy Act applies to any entity that “carries on business in Australia”. New Zealand businesses that sell products and services to customers in Australia are likely caught, regardless of where the business is incorporated or where its systems are hosted.

Does the Australian obligation apply to my business?

The obligation is triggered where an organisation (that is subject to the Australian Privacy Act) has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, using that individual’s personal information. “Computer program” is intended to be interpreted broadly. It covers machine learning, generative AI tools, and also simple rule-based algorithms.

Importantly, the entity that “arranged for” the ADM bears the disclosure obligation. This is not necessarily the entity that built or operates the technology. If an Australian customer procures your ADM tool for its own decision-making, the customer is likely the disclosing entity. If you deploy your own ADM tool commercially in Australia, you may bear the obligation directly.

What must be disclosed?

An organisation caught by the Australian Privacy Act must update its privacy policy to include:

  • the kinds of personal information used in the operation of its ADM systems;
  • the kinds of decisions made solely by the operation of computer programs (for example, a fully automated credit score or service denial); and
  • the kinds of decisions for which the computer program performs a substantial or direct role (for example, an AI system shortlisting job applicants before a human makes the final selection).

The disclosure must be clearly expressed and up to date. Generic boilerplate or overly technical descriptions are unlikely to satisfy the obligation.

What should you do now?

Both regimes will shape how trading partners assess AI governance and supplier risk. New Zealand businesses that build transparency compliance into their products and workflows now are better positioned as global AI regulation develops.

  • Consider your exposure: Assess whether your AI systems reach European users. If so, Article 50 of the AI Act will be triggered from 2 August 2026. Assess whether you carry on business in Australia, triggering the ADM transparency obligation from 10 December 2026. 
  • Audit your AI systems: Identify which systems use personal information in decisions that significantly affect individuals. The Australian definition of “computer program” is broad and may capture tools you would not ordinarily think of as AI. For the EU, determine whether your systems interact directly with people, generate synthetic content, or produce deepfakes, as each attracts a distinct Article 50 obligation.
  • Prepare for contractual flow-down: Expect customers in both jurisdictions to impose transparency compliance contractually. 
  • Update your disclosures now: If you operate a customer-facing chatbot, virtual assistant, or AI content tool, ensure you have a visible disclosure informing users they are interacting with AI. For AI-generated content, implement labelling processes before the 2 August 2026 deadline. For Australia, if your tool involves ADM, review your privacy policy to confirm it addresses ADM ahead of 10 December 2026.

Contact one of our experts if you have questions about how the AI Act and/or the new Australian Privacy Act obligations apply to your business or would like to discuss a compliance approach. We can put you in touch with the right people.


This article was co-authored by Danielle Rayner, a Solicitor in our Corporate and Commercial team.