GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-016 AI Interaction and Output Disclosure

Tier 2+AIGenerativeProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Users interacting with an AI system are informed that they are doing so, unless it is unambiguous from context. For systems that generate synthetic audio, image, video or text content, outputs are marked as AI-generated using a machine-readable mechanism, and for deep fake or synthetic media outputs the generation is disclosed to affected parties. Disclosure mechanisms are tested so that they are not trivially removable. People subject to a decision that an AI system makes or informs are told that the system was used, at the point the decision is communicated to them. A published route lets such a person ask for an explanation, and an explanation is given within a defined period covering the part the system played in the decision and the main elements of the decision itself. Where a system presents a persona or converses in natural language, a recorded review of its interface, completed before release and repeated after any change to the persona, identifies the cues that would lead a user to attribute human status, feelings or a body to the system, including human images, statements of feeling and humanoid or cyborg imagery and records for each cue whether it was kept with a stated reason or removed.

Rationale

Undisclosed AI interaction is deceptive, and disclosure is a base-level trust requirement for AI-mediated services as well as a regulatory obligation in most jurisdictions. The population subject to a decision is wider than the population interacting with the system: a person refused a service never sees the interface at all, so a disclosure built into the product reaches none of them. AIG-017 holds the explainability capability and its limits, which is the raw material; AIG-016 holds the notice and the answer owed to the individual, with an intake route and a clock. The interface review exists because a disclosure at first contact is unsaid by every later cue that presents the system as a person, which is where the human-AI configuration risk in NIST AI 600-1 lands. The review does not forbid a persona; it records the decision to keep each cue, so that a cue survives on a reason and not by default. The user-facing half of OWASP ASI09, risk badges and confidence cues on an agent's recommendations, is still not stated here and remains the gap that row names. Detection of synthetic or manipulated media coming in, before a system relies on it as evidence, is AIG-057; this control marks and discloses what the organisation itself generates.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Enterprise AI Deployerstablerequiredrole duty

Notifying affected persons (Art.26.7) and the Art.86 explanation route are the deployer's at high risk. Deep fake and public-interest text disclosure (Art.50.4) is the deployer's where it publishes the content. Interaction disclosure and machine-readable marking are built by the provider; the deployer confirms they are active in its configuration. Worker notification before workplace use (EU-AI-Art.26.6) is dispositioned to this profile and has no canonical control yet.

GPAI Model Providerstablerequiredcore

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

High-Risk Provider (EU)stablerequiredcore

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Public Body Deployer (EU)stablerequiredrole duty

Art.26(11) binds every deployer of a high-risk Annex III system, so both seats: a person subject to a decision the system makes or informs is told the system was used. Art.86(1) adds the right to obtain clear and meaningful explanations of the role the system played in the decision and the main elements of the decision taken, with the Annex III point 2 area excluded and with room for Union or national law to restrict it. The public body's own duty to give reasons for an administrative decision runs alongside and is not restated here: this row tests the notice and the explanation route, not the legality of the decision.

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

DORA ICT Provider (EU)stablerequiredcore

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

NIS2 Cloud Provider (EU)stablerequiredcore

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Framework Mappings (34)

IAM-17Output Modification and Special Authorizationinformative
EU-AI-Art.26.7Deployer Obligations — Notification to Affected Individualsfull
EU-AI-Art.50.1Transparency Obligations — AI Interaction Disclosurefull
EU-AI-Art.50.2Transparency Obligations — Synthetic Content Markingfull
EU-AI-Art.50.4Transparency Obligations — Deep Fake Disclosurefull
EU-AI-Art.86Deployer Obligations — Right to Explanation of Individual Decision-Makingfull
A.8.2System documentation and information for usersinformative
GV-1.2-001Trustworthy AI Characteristics Integration | GV-1.2-001informative
GV-4.3-001AI Testing and Information Sharing Practices | GV-4.3-001partial
GV-5.1-002External Stakeholder Feedback Integration | GV-5.1-002full
GV-6.1-003Third-Party AI Risk Policies | GV-6.1-003partial
GV-6.1-008Third-Party AI Risk Policies | GV-6.1-008informative
MG-2.2-003Deployed AI System Value Maintenance | MG-2.2-003partial
MG-2.2-007Deployed AI System Value Maintenance | MG-2.2-007informative
MG-3.2-006Pre-Trained Model Monitoring | MG-3.2-006informative
MP-2.3-004Scientific Integrity and Testing Considerations | MP-2.3-004informative
MP-3.4-001Operator Proficiency Processes | MP-3.4-001partial
MP-5.1-001Impact Likelihood and Magnitude Documentation | MP-5.1-001partial
MP-5.1-002Impact Likelihood and Magnitude Documentation | MP-5.1-002informative
MP-5.1-003Impact Likelihood and Magnitude Documentation | MP-5.1-003full
MS-1.1-001AI Risk Measurement Approach Selection | MS-1.1-001partial
MS-1.1-002AI Risk Measurement Approach Selection | MS-1.1-002informative
MS-1.1-007AI Risk Measurement Approach Selection | MS-1.1-007informative
MS-2.10-002AI Privacy Risk Examination | MS-2.10-002informative
MS-2.2-002Human Subject Evaluation Requirements | MS-2.2-002informative
MS-2.5-004AI System Validity and Reliability | MS-2.5-004full
MS-2.7-002AI System Security and Resilience Evaluation | MS-2.7-002informative
MS-2.7-003AI System Security and Resilience Evaluation | MS-2.7-003informative
MS-2.7-005AI System Security and Resilience Evaluation | MS-2.7-005partial
MS-2.8-003AI Transparency and Accountability Risks | MS-2.8-003informative
MS-3.3-002User and Community Feedback Processes | MS-3.3-002partial
MS-4.2-001Trustworthiness Measurement with Expert Input | MS-4.2-001informative
MEASURE 2.8AI Transparency and Accountability Risksinformative
ASI09Human-Agent Trust Exploitationpartial

Evidence (4)

observationobservationmanual

UI or API configuration demonstrating that AI interaction disclosure is presented to users before or at the point of first interaction with an AI system.

Example: Chatbot system prompt configuration (exported from AWS Bedrock / Azure OpenAI deployment config) showing mandatory opening disclosure message 'This response is generated by an AI assistant'; UI component config showing AI badge rendered on all AI-generated responses

Test: Review the AI interaction disclosure implementation. Verify: (1) disclosure is presented before or at first AI interaction, inspected on the live system or in its configuration, (2) disclosure is not dismissible before being read, (3) for synthetic media outputs a machine-readable marking mechanism is configured and tested, (4) disclosure cannot be trivially removed by end-user action, (5) where the system makes or informs decisions about people, the notice that it was used is shown at the point the decision is communicated, including to people who never see the product interface.

reportdocumentmanual

Disclosure mechanism test report confirming that AI interaction disclosure and synthetic content marking have been tested for robustness and correct rendering across supported interfaces.

Example: AI Disclosure QA Test Report v1 (TestRail, exported 2026-01-20), covering 6 user interface entry points, disclosure rendering on mobile and desktop, watermark persistence after image download, and synthetic media label display in API responses

Test: Request the disclosure mechanism test report. Verify: (1) test cases cover all customer-facing interfaces, (2) synthetic content marking is tested for persistence (e.g. watermark survives format conversion), (3) test results show pass against expected disclosure behaviour, (4) report is dated within the last 12 months or after last significant UI change.

recorddocumentmanual

Log of explanation requests from people subject to a decision an AI system made or informed, with the date received, the date answered and the explanation issued.

Example: Explanation request log 2026 H1, with issued explanations

Test: Request the explanation request log. Verify: (1) the intake route is published where an affected person would find it rather than only in internal documentation, (2) every request in the period was answered within the defined response period, (3) each explanation names the system, states the part it played in the decision and sets out the main elements of the decision rather than pointing the person at generic documentation, (4) a refusal, if any, records the ground relied on, (5) requests arriving through a channel other than the published route were still logged and answered.

recorddocumentmanual

The interface persona review for each system that presents a persona or converses in natural language: the cues found that would lead a user to attribute human status, feelings or a body to the system, the decision on each cue with its reason and the dates of the review before release and after each persona change.

Example: Persona review for the support assistant, version 4 of 11 August 2026, following the avatar change of release 2026.8.

Test: Verify: (1) a review exists for every system in the inventory that presents a persona or converses in natural language, (2) the first review pre-dates the system's release record, (3) each persona change in the release history has a review dated after it, (4) each cue kept carries a stated reason and each cue removed is absent from the live interface, checked on the running system, (5) the review names the cue categories the control lists, human images, statements of feeling and humanoid or cyborg imagery, with a finding recorded against each.

Questions (3)

boolean

Are users of your AI systems informed that they are interacting with an AI before or at the point of first interaction?

Undisclosed AI interaction is deceptive and a regulatory obligation in most jurisdictions. Disclosure must be presented before interaction begins and should not be easily dismissed or hidden.

multi

For AI systems that generate synthetic content or converse with users, which of the following disclosure mechanisms are in place?

Machine-readable marking of AI-generated outputs (e.g. C2PA metadata, watermark)Visible label or badge indicating AI-generated contentDisclosure to affected parties when synthetic media depicts real individualsRobustness testing confirming the marking cannot be trivially removedA recorded review of a persona-bearing interface for cues that present the system as human, before release and after a persona changeNone of the above

All four mechanisms apply to generative AI systems producing synthetic media. Organisations using AI only for classification or decision-support (not synthetic media generation) should note which apply and which do not. The persona review item applies to any system with a name, an avatar or a conversational voice: it asks whether someone looked at the interface for human images, statements of feeling and humanoid imagery and recorded a decision on each.

multi

For AI systems that make or inform decisions about people, which of the following are in place?

Affected people are told that an AI system was used in the decisionA published route for an affected person to ask for an explanationA defined period within which an explanation is givenExplanations state the part the system played in the decisionExplanations set out the main elements of the decision itselfNone of the above

Options run from the most commonly in place to the least. The population here is wider than the users of the product: a person refused a service never sees the interface, so a disclosure built into the product reaches none of them. An explanation that points the reader at published model documentation does not set out the main elements of their decision.