Blog

AI Transparency – We Have Been Here Before

August 13, 2026 · By GM GREENE

The EU AI Act Is Now Enforceable. Are You Within Scope?

On 2 August 2026, the European Union’s AI transparency obligations came into force. The arguments against them are word for word what we heard about the free web in the 1990s. We should pay attention to how that argument ended.

EU AI Act transparency label and the free web argument — AI transparency obligations 2026
On 2 August 2026, something significant happened that most professionals are not yet aware of. The transparency obligations of the EU Artificial Intelligence Act became enforceable. From that date, providers and deployers of AI systems that interact directly with people must ensure those people know they are interacting with an AI. AI-generated content published to inform the public on matters of public interest must be labelled. Deepfakes must be disclosed as artificially generated. Fines for non-compliance run to €15 million or 3% of worldwide annual turnover, whichever is higher.

The EU AI Act applies globally to anyone whose AI outputs reach people in the European Union. If you use AI to produce content that anyone in the EU reads, you are within scope. This is not hypothetical future regulation. It is the law, now, in the territory where most of my readers live and work.

I want to make an argument about why this matters beyond the compliance question. Because I have heard the arguments against this legislation before. Not similar arguments. The same ones, almost word for word. And I remember how the last version of that argument ended.

The 1990s Called. It Wants Its Rhetoric Back.

When the World Wide Web was new, the argument against regulating it was consistent and, in many cases, sincere. The technology was too complex for legislators to understand. Regulation would stifle innovation before it had a chance to develop. The market would self-correct any problems that emerged. Leave it alone and the technology would find its own equilibrium, beneficial to everyone.

The people making this argument were not all wrong about everything. The early web was genuinely difficult for legislators to understand. Some proposed regulation of the period was ill-conceived. The technology did produce extraordinary innovation that nobody had planned.

But the deregulatory environment those arguments successfully defended produced something else alongside the innovation. It produced the conditions in which a small number of commercial interests were able to position themselves as the gatekeepers of the digital world before any regulatory framework existed to prevent it. The innovation commons that Lawrence Lessig described in The Future of Ideas was progressively enclosed. Not through a single dramatic event, but through a series of legal, architectural, and commercial decisions made in the absence of governance, by the people best positioned to exploit that absence.

The Internet’s very design built a neutral platform upon which the widest range of creators could experiment. The legal architecture surrounding it protected this free space so that culture and information could flow freely. But this structural design changed, both legally and technically.

Lessig wrote that in 2001. He was describing what had already happened. The window for a different outcome had closed without most people noticing it was open.

The AI transparency debate is producing the same arguments from recognisably similar interests. Too complex. Too soon. Will stifle innovation. The market will self-correct.

I do not find these arguments more persuasive the second time.

What the Legislation Actually Requires

Before arguing about AI transparency, it is worth being precise about what Article 50 of the EU AI Act actually demands, because the gap between what it requires and what its opponents claim it requires is itself revealing.

The transparency obligations fall into four categories

  1. AI systems that interact directly with people must be designed so that those people can be informed they are interacting with an AI. Note: can be informed, not that a banner must appear at all times. The obligation is about design capability, not constant interruption.
  2. Providers of generative AI systems producing synthetic audio, image, video or text must mark that content in a machine-readable format enabling automated detection. This is a technical requirement aimed at detection systems, not at human readers.
  3. Deployers using AI to create deepfakes must disclose that the content is artificially generated or manipulated. There is an explicit exemption for evidently artistic, creative, satirical, or fictional work, where the disclosure need only acknowledge that AI was involved without hampering the work itself.
  4. AI-generated text published with the purpose of informing the public on matters of public interest must be labelled as AI-generated. This is the obligation most directly relevant to journalism, public communications, and the kind of long-form writing this site produces.

These are not onerous requirements. They are, in most cases, things that any honest communicator would do voluntarily. The disclosure that AI was involved in producing content is not a threat to creativity or innovation. It is information that readers have a reasonable interest in possessing.

The European Commission published guidelines on 20 July 2026 clarifying implementation. A voluntary Code of Practice on AI-generated content has been established, with several major providers already signed on. Signatories benefit from a presumption of conformity. Non-signatories face closer scrutiny and must demonstrate compliance through other means.

The Argument Against Disclosure Is Always Made Loudest by Those Who Benefit from Invisibility

The deeper argument for AI transparency is not about compliance. It is about the conditions under which trust in information can be maintained in an environment where AI-generated content is increasingly indistinguishable from human-produced content.

When I published my book, Well… How Did We Get Here?, I disclosed that it was written in collaboration with AI. I made the same disclosure in the essays on this site. Not because any regulation required it. Because I believed readers had a right to know, and because the argument of the book itself, about who builds our technological systems and on what terms, made the disclosure intellectually necessary. I could not write about the importance of understanding how technology shapes the information environment without being transparent about the tools I used to produce that information.

The EU AI Act is, in one reading, the institutionalisation of exactly that ethic. It is saying: people interacting with AI systems, or reading AI-generated content, have a right to know. That right should not depend on the voluntary goodwill of individual producers. It should be a legal baseline.

The argument against this is that it imposes costs, creates uncertainty, and may disadvantage European AI providers relative to competitors in less regulated environments. These arguments have some validity. Compliance costs are real. Regulatory uncertainty is genuinely difficult for smaller operators.

But the argument assumes that the status quo, in which AI content circulates without systematic disclosure, is a neutral baseline. It is not. The status quo advantages the producers of AI content over the consumers of it. It allows the scale and pervasiveness of AI in the information environment to remain invisible to the people most affected by it. That invisibility is not neutral. It is a distribution of power, and it favours specific interests.

This is precisely the dynamic Lessig identified in the 1990s internet debate. The argument for leaving the architecture alone always benefits whoever currently controls the architecture. The free web argument was made most loudly by the people best positioned to benefit from the absence of governance. The AI transparency argument is being made most loudly by the people best positioned to benefit from the absence of disclosure requirements.

ISO 42001

When I posted my Computer Says No article on LinkedIn last month, one of the most substantive responses came from a professional who works with the ISO 42001 standard for AI management systems. It was a welcome comment and guided me to an area I hadn’t yet researched. The commenter noted that she raises AI governance in every professional discussion she participates in, and that the essay described exactly the gap she works to close.

ISO 42001, published in 2023, is the international standard for AI management systems. I am by no means an expert in this field so I welcome correction. My take is that it establishes a framework for organisations to manage AI responsibly, covering risk assessment, transparency, accountability, and human oversight. It is not legislation. It is a voluntary framework that organisations adopt to demonstrate responsible AI governance.

The relationship between ISO 42001 and the EU AI Act is the relationship between professional best practice and legal minimum. Organisations that have adopted ISO 42001 already have the governance architecture to meet the EU AI Act’s transparency obligations, because the standard was designed with accountability and transparency as foundational principles. For them, the legislation codifies what they have already built.

For organisations that have not adopted such frameworks, the legislation creates a floor. A minimum below which it is now unlawful to operate in the EU market. That floor is not the ceiling. The most responsible approach to AI governance reaches considerably higher. But having a floor matters. The 1990s internet did not have one, and the consequences of that absence are still with us.

Deregulation Did Not Protect the Commons. It Created the Conditions for Its Capture

It is worth being precise about what the free web argument produced, because the narrative of the 1990s internet is often told selectively.

The open, deregulated early internet did produce extraordinary creativity and innovation. The World Wide Web, email at scale, open source software, the early blogosphere: these were genuine achievements of a lightly governed digital commons. The argument for leaving the architecture alone had real evidence behind it during that period.

What the argument did not anticipate, or what its most commercially motivated proponents chose not to mention, was that the absence of governance created conditions for capture. By the time the consequences of that capture were visible to ordinary users, the architecture had already been redesigned around commercial interests. The platform monopolies, the attention economy, the surveillance infrastructure: these were not accidents of the free web. They were its products, in the conditions that actually existed.

The reigning assumption was that a free marketplace would protect the public and keep the Internet free and open.

It did not. Not because the marketplace is inherently incapable of producing good outcomes, but because the specific market conditions that existed, with massive asymmetries of information, capital, and technical capacity between the large platforms and everyone else, were not conditions in which self-correction was likely.

The AI market has similar characteristics. The largest AI providers have resources and technical capabilities that dwarf those of any regulator and most of their commercial competitors. In the absence of governance requirements, the architecture will be designed around their interests. This is not a prediction. It is a description of how unregulated technology markets have consistently behaved.

The 1990s Promised a Meritocracy of Ideas. We Got a Marketplace of Attention

I want to be careful about one thing. The EU AI Act’s transparency obligations are a beginning, not a solution. Knowing that you are interacting with an AI system does not tell you how that system was trained, on whose data, with whose values encoded into its outputs. Knowing that a piece of text was AI-generated does not tell you whether it is accurate, whether the AI’s outputs were reviewed by a human with relevant expertise, or what commercial or political interests shaped the prompt that generated it.

Transparency is a prerequisite for accountability, not a substitute for it. The requirement to label AI-generated content creates the conditions in which more substantive questions can be asked. It does not answer those questions by itself.

This is where the meritocracy argument becomes important. A genuinely meritocratic information environment, one in which the best ideas and the most accurate information rise to the top regardless of their origin, requires that the origin be known. You cannot evaluate the source of information you cannot identify. AI transparency is not the enemy of meritocracy. It is one of its conditions.

The 1990s internet was sold as a meritocracy of ideas: the best information would rise, the worst would sink, gatekeepers would be bypassed, and the marketplace of ideas would flourish. What we got was a marketplace of attention, in which the most engaging content won regardless of its accuracy, and in which the architecture was quietly redesigned to serve the interests of those who monetised engagement. Transparency requirements are part of the attempt to recover something closer to the original promise.

A Personal Note on Disclosure

I disclosed AI collaboration in my book before any legislation required it. I disclose it in these essays. I do this not because I am required to and not because I think AI collaboration is something to be ashamed of. I do it because I believe the people who read what I write have a right to know how it was produced.

The EU AI Act now requires, in certain contexts, what I was already doing voluntarily. I do not find that threatening. I find it clarifying. It suggests that the ethic of disclosure I had arrived at independently is one that the regulatory process has also concluded is appropriate. That convergence is worth noting.

Whether the legislation is well-drafted, whether its enforcement will be effective, whether it will achieve its stated goals: these are legitimate questions that professionals and policymakers will be arguing about for years. The answers are not obvious.

But the underlying principle, that people have a right to know when they are interacting with or reading the outputs of AI systems, and that this right should not depend entirely on the goodwill of producers, seems to me both correct and insufficient. Correct, because the information matters. Insufficient, because transparency alone does not address the deeper questions of power, accountability, and whose interests the architecture serves.

Those deeper questions are the ones Lessig was asking in 2001. We are still asking them. The EU AI Act is one attempt at a partial answer. It is worth engaging with seriously, rather than dismissing with arguments we have already heard, from interests we have already seen.

Sources

European Commission (2026) Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems under the EU AI Act. Brussels: European Commission, 20 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai [Accessed August 2026].

European Parliament and Council of the European Union (2024) Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L Series. Article 50: Transparency obligations for providers and deployers of certain AI systems.

International Organisation for Standardisation (2023) ISO/IEC 42001:2023 — Information technology, Artificial intelligence, Management system. Geneva: ISO.

Lessig, L. (2001) The Future of Ideas: The Fate of the Commons in a Connected World. New York: Random House.

Lessig, L. (1999) Code and Other Laws of Cyberspace. New York: Basic Books.

Read the Book

Well… How Did We Get Here? is available now in paperback and Kindle, worldwide.

Get the Book