AI disclosure, consent and privacy checklist

Checklist · 23 items · Updated

People should know when they are dealing with AI, what happens to the data they give it, and how to say no. Some of this is now law. In the EU, Article 50 of the AI Act (Regulation (EU) 2024/1689) sets transparency obligations for chatbots, AI-generated content and deep fakes, and it has applied since 2 August 2026.

This checklist turns those obligations, and the privacy guidance that sits around them, into design checks. Each legal item quotes or paraphrases the official text and links to it on EUR-Lex or the regulator's site, so you can read the source rather than our summary.

It is a design checklist, not legal advice. Whether an obligation applies to you depends on your role (the AI Act separates providers, who develop or place a system on the market, from deployers, who use one), where you operate and what the system does. Check the specifics with your legal team.

Download the PDF

AI disclosure, consent and privacy checklist as a print-ready PDF (A4, 145 KB). Everything in it is also free to read on this page.

How to use it

Start by writing down your role for each AI system you use: provider, deployer, or both. Article 50's paragraphs are addressed to one or the other, and the sections below say which.

Then walk every screen where AI appears or AI output is shown, and every place you collect data the AI uses.

0 of 23 done

Ticks are saved in this browser only. Nothing you tick here is sent to UX Pickle.

Tell people they are interacting with AI

EU AI Act Article 50(1), addressed to providers.

  • This is the Article 50(1) duty for systems “intended to interact directly with natural persons”. When in doubt, assume it is not obvious. EU AI Act, Article 50(1) (EUR-Lex)

  • Article 50(5): the information must be given “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”. EU AI Act, Article 50(5) (EUR-Lex)

  • Article 50(5) also requires the information to “conform to the applicable accessibility requirements”. EU AI Act, Article 50(5) (EUR-Lex)

  • Apple: never trick someone into thinking they're interacting with, or viewing content authored by, a human when they aren't. PAIR gives the same advice. Apple HIG: Generative AI

  • People share different things with a person than with a bot; they should know which one is reading.

Label AI-generated content

Article 50(2) for providers, Article 50(4) for deployers.

  • Article 50(2). It doesn't apply where the system only performs an assistive function for standard editing or doesn't substantially alter the input. Provenance standards such as C2PA Content Credentials are one way to attach machine-readable marks. EU AI Act, Article 50(2) (EUR-Lex)

  • Article 50(4), first subparagraph, addressed to deployers. For evidently artistic, creative, satirical or fictional work, the duty is limited to disclosing it in a way that doesn't spoil the work. EU AI Act, Article 50(4) (EUR-Lex)

  • Article 50(4), second subparagraph. Newsrooms, public bodies and companies publishing public-information content should decide which side of the exception each workflow is on. EU AI Act, Article 50(4) (EUR-Lex)

  • Apple: clearly identify when and where you use AI. Labels next to the content work better than a notice in settings. Apple HIG: Generative AI

  • AI content travels. A label that only exists inside your app disappears the moment someone shares the image.

  • Article 50(3), addressed to deployers. Note that some uses of emotion recognition, such as in workplaces and education, are prohibited outright under Article 5. EU AI Act, Article 50(3) (EUR-Lex)

Explain data use

  • Apple asks apps to clearly disclose how the app and its model use and store personal information, and to explain the benefit concisely. Apple HIG: Generative AI

  • Apple: make sure people know their information may be sent to a server, show what is shared, and help them understand what may be stored off-device. Apple HIG: Generative AI

  • Apple asks you to articulate whether the model uses personal information for training. The FTC has warned that model-as-a-service companies that break their privacy commitments may be liable. FTC: AI Companies: Uphold Your Privacy and Confidentiality Commitments

  • People can't make an informed choice about sharing without knowing how long it's kept.

  • Apple notes model outputs can inadvertently contain sensitive information. Apple HIG: Generative AI

  • Apple: ask permission before using personal information and usage data; get explicit permission for sensitive data used for improvement or storage. Under the GDPR you also need a lawful basis for each purpose. Apple HIG: Generative AI

  • Apple asks for a clear way to opt out after permission is given. PAIR recommends letting people reset personalisation or turn features off entirely. PAIR: Feedback + Control

  • Consent obtained through a design that steers people isn't the free choice it claims to be.

  • The FTC has said it may be unfair or deceptive to adopt more permissive data practices and inform people only through a surreptitious, retroactive change to the terms or privacy policy. FTC: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive

Automated decisions about people

  • Article 22(1) gives people the right not to be subject to such decisions based solely on automated processing; where they are allowed, Article 22(3) requires at least the right to human intervention, to express their view and to contest the decision. GDPR, Article 22 (EUR-Lex)

  • The safeguards in Article 22(3) only help if people can find them. ICO: Guidance on AI and data protection

  • Microsoft's G11: make clear why the system did what it did. For decisions covered by GDPR Article 22, Articles 13 to 15 also require meaningful information about the logic involved. Microsoft HAX: Guidelines for Human-AI Interaction

Sources

Checked against these sources on 3 October 2026. Spotted something out of date? Email hi[at]uxpickle.com.