AI disclosure, consent and privacy checklist
People should know when they are dealing with AI, what happens to the data they give it, and how to say no. Some of this is now law. In the EU, Article 50 of the AI Act (Regulation (EU) 2024/1689) sets transparency obligations for chatbots, AI-generated content and deep fakes, and it has applied since 2 August 2026.
This checklist turns those obligations, and the privacy guidance that sits around them, into design checks. Each legal item quotes or paraphrases the official text and links to it on EUR-Lex or the regulator's site, so you can read the source rather than our summary.
It is a design checklist, not legal advice. Whether an obligation applies to you depends on your role (the AI Act separates providers, who develop or place a system on the market, from deployers, who use one), where you operate and what the system does. Check the specifics with your legal team.
Download the PDF
AI disclosure, consent and privacy checklist as a print-ready PDF (A4, 145 KB). Everything in it is also free to read on this page.
How to use it
Start by writing down your role for each AI system you use: provider, deployer, or both. Article 50's paragraphs are addressed to one or the other, and the sections below say which.
Then walk every screen where AI appears or AI output is shown, and every place you collect data the AI uses.
Ticks are saved in this browser only. Nothing you tick here is sent to UX Pickle.
Tell people they are interacting with AI
EU AI Act Article 50(1), addressed to providers.
This is the Article 50(1) duty for systems “intended to interact directly with natural persons”. When in doubt, assume it is not obvious. EU AI Act, Article 50(1) (EUR-Lex)
Article 50(5): the information must be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”. EU AI Act, Article 50(5) (EUR-Lex)
Article 50(5) also requires the information to “conform to the applicable accessibility requirements”. EU AI Act, Article 50(5) (EUR-Lex)
Apple: never trick someone into thinking they're interacting with, or viewing content authored by, a human when they aren't. PAIR gives the same advice. Apple HIG: Generative AI
People share different things with a person than with a bot; they should know which one is reading.
Label AI-generated content
Article 50(2) for providers, Article 50(4) for deployers.
Article 50(2). It doesn't apply where the system only performs an assistive function for standard editing or doesn't substantially alter the input. Provenance standards such as C2PA Content Credentials are one way to attach machine-readable marks. EU AI Act, Article 50(2) (EUR-Lex)
Article 50(4), first subparagraph, addressed to deployers. For evidently artistic, creative, satirical or fictional work, the duty is limited to disclosing it in a way that doesn't spoil the work. EU AI Act, Article 50(4) (EUR-Lex)
Article 50(4), second subparagraph. Newsrooms, public bodies and companies publishing public-information content should decide which side of the exception each workflow is on. EU AI Act, Article 50(4) (EUR-Lex)
Apple: clearly identify when and where you use AI. Labels next to the content work better than a notice in settings. Apple HIG: Generative AI
AI content travels. A label that only exists inside your app disappears the moment someone shares the image.
Article 50(3), addressed to deployers. Note that some uses of emotion recognition, such as in workplaces and education, are prohibited outright under Article 5. EU AI Act, Article 50(3) (EUR-Lex)
Explain data use
Apple asks apps to clearly disclose how the app and its model use and store personal information, and to explain the benefit concisely. Apple HIG: Generative AI
Apple: make sure people know their information may be sent to a server, show what is shared, and help them understand what may be stored off-device. Apple HIG: Generative AI
Apple asks you to articulate whether the model uses personal information for training. The FTC has warned that model-as-a-service companies that break their privacy commitments may be liable. FTC: AI Companies: Uphold Your Privacy and Confidentiality Commitments
People can't make an informed choice about sharing without knowing how long it's kept.
Apple notes model outputs can inadvertently contain sensitive information. Apple HIG: Generative AI
Consent, opt-outs and control
Apple: ask permission before using personal information and usage data; get explicit permission for sensitive data used for improvement or storage. Under the GDPR you also need a lawful basis for each purpose. Apple HIG: Generative AI
Apple asks for a clear way to opt out after permission is given. PAIR recommends letting people reset personalisation or turn features off entirely. PAIR: Feedback + Control
Consent obtained through a design that steers people isn't the free choice it claims to be.
The FTC has said it may be unfair or deceptive to adopt more permissive data practices and inform people only through a surreptitious, retroactive change to the terms or privacy policy. FTC: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive
Automated decisions about people
Article 22(1) gives people the right not to be subject to such decisions based solely on automated processing; where they are allowed, Article 22(3) requires at least the right to human intervention, to express their view and to contest the decision. GDPR, Article 22 (EUR-Lex)
The safeguards in Article 22(3) only help if people can find them. ICO: Guidance on AI and data protection
Microsoft's G11: make clear why the system did what it did. For decisions covered by GDPR Article 22, Articles 13 to 15 also require meaningful information about the logic involved. Microsoft HAX: Guidelines for Human-AI Interaction
Sources
- Regulation (EU) 2024/1689 (AI Act), Official Journal, EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- European Commission: Code of Practice on marking and labelling of AI-generated content (10 June 2026)
- AI Act Service Desk: Article 50
- Regulation (EU) 2016/679 (GDPR), EUR-Lex
- ICO: Guidance on AI and data protection
- FTC Technology Blog: AI Companies: Uphold Your Privacy and Confidentiality Commitments (9 January 2024)
- FTC Technology Blog: AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive (13 February 2024)
- C2PA: Content Credentials specification
- Apple Human Interface Guidelines: Generative AI
- PAIR: Feedback + Control
- Microsoft HAX: Guidelines for Human-AI Interaction
Checked against these sources on 3 October 2026. Spotted something out of date? Email hi[at]uxpickle.com.