← Publications et interventions

20 min read

Transparency Is Not a Single Regime: The AI Act's Information Obligations Tested Against Their Implementation

The postponement of the obligations relating to high-risk systems, secured in June 2026, leaves in place on 2 August 2026 only the informational layer of Regulation (EU) 2024/1689. This accident of scheduling brings to light what scholarship most often treats as a unity: the transparency of the AI Act is not a homogeneous legal regime, but the assembly of at least three regimes distinct in their addressees, their required content, their timing and their sanction regime. The analysis of this stratification leads to a second proposition: the effectiveness of these obligations is a property neither of the norm, nor of the regulated organisation, nor of the technical device that gives it form, but of the triangle they compose. It is therefore played out largely outside the text — in the documentary practices of regulated actors and in the work of a layer of private intermediaries that fixes, upstream of any authentic interpretation, what the obligation is deemed to require.

Introduction: what a disjointed timeline reveals

On 2 August 2026, Regulation (EU) 2024/1689 was to reach its principal turning point. It will reach it, but shorn of what was to constitute its core.

The simplification package known as the Digital Omnibus on AI, proposed by the Commission on 19 November 2025, was the subject of a political agreement in the night of 6 to 7 May 2026, of a European Parliament vote on 16 June 2026 and of a final Council approval on 29 June1. It postpones to 2 December 2027 the application of the obligations relating to the stand-alone high-risk systems of Annex III, and to 2 August 2028 those relating to systems embedded in the regulated products of Annex I. It leaves untouched, however, both Article 50 and the obligations bearing on providers of general-purpose models, applicable since 2 August 2025 and whose performance becomes genuinely liable to sanction as from 2 August 2026.

The result deserves to be stated plainly. The Artificial Intelligence Act will enter into general application within a few days with, for the essential part of its immediately enforceable normative burden, a set of information obligations: informing the person who interacts with a system, marking synthetic content, documenting general-purpose models, maintaining the summary of training content. The technical documentation of high-risk systems — the documentation structured by Articles 11 to 13 and Annex IV, and which constituted the principal object of the preparatory work — must wait for December 2027.

This dissociation is not merely an agenda inconvenience for legal departments. It is an analytical revealer, and it is on that account that it is taken here as a point of departure. For, in order to sever the timeline in this way, the legislator had to divide. It had to identify, within what the Regulation presents under a single banner, sets that can be dissociated: dissociable in time, which presupposes that they are dissociable in their logic. A unitary legal regime does not split into two dates without there appearing a line of fracture that pre-existed it.

The thesis defended here proceeds from this observation. The transparency obligations of the AI Act do not form a homogeneous legal category; they constitute a stratified assembly of at least three regulatory regimes whose addressees, required content, conditions of effectiveness and characteristic pathologies do not coincide (I). This stratification has a direct consequence for theory: the conditions under which an information obligation produces a regulatory effect, as identified by a now consolidated body of scholarship, must be assessed regime by regime, and not globally (II). It has a more unsettling consequence for practice: in the interval separating the prescription from its application, the effective content of the obligation is fixed elsewhere than in the text — through the organisational appropriation of regulated actors (III), and through the work of a layer of private intermediaries whose function is not to advise but to produce the very legibility of the norm (IV). In conclusion, an attempt will be made to identify the requirements that a private information device would have to satisfy in order to support the effectiveness of these obligations rather than to replicate their pathologies.

I. One word, three regimes

The Regulation employs the term transparency in contexts so diverse that one must begin by undoing its apparent unity. Four criteria suffice to distinguish the regimes it covers: the addressee of the information, the moment at which it is due, the required content, and the sanction regime attached to its default. Applied to the relevant provisions, these criteria reveal three sets that overlap at no point.

A. Transparency-as-information: Article 50

The first regime targets the natural person. Article 50 requires the provider to ensure that systems intended to interact directly with persons are designed in such a way that those persons are informed that they are interacting with an artificial intelligence system, unless this is apparent from the context; it requires the marking, in a machine-readable format, of generated synthetic content; it requires the deployer to disclose the use of an emotion recognition or biometric categorisation system, as well as the disclosure of manipulated content amounting to a deep fake2. The breach exposes the actor to a fine of up to fifteen million euros or three per cent of total worldwide annual turnover3.

The structure of this obligation is that of a one-off item of information, due at the moment of first interaction or exposure, in an intelligible form, to a non-professional addressee who has not requested it. It presupposes neither retention, nor traceability, nor documentary production. Its characteristic pathology is readily identifiable, because it is already known: it is that of the ritual notice, of which the cookie-consent banner offers the best-documented precedent. An obligation to inform that does not define what the information is to enable one to decide produces a display, not a decision.

B. Transparency-as-documentation: Articles 11 to 13, 53 and 55

The second regime targets the supervisory authority and the value chain. It groups together provisions rendered homogeneous by their common addressee despite the difference of the systems they target: the technical documentation of high-risk systems, drawn up before placing on the market and kept up to date, the content of which is fixed by Annex IV; the automatic logging; the instructions for use intended for the deployer4; and, for providers of general-purpose models, the technical documentation, the information of downstream providers, the copyright compliance policy and the sufficiently detailed summary of the content used for training5.

Here, the information is not due at a moment but maintained over time; it is not intended to enable a decision but to permit control; its addressee is professional, equipped and, in principle, a requesting party. Its characteristic pathology is the inverse of the previous one: it is not the ritual, it is documentary performativity — the progressive substitution of documentary compliance for substantive compliance, when the production of the file becomes the object of the organisational effort and the quality of the system ceases to be its measure.

C. Transparency-as-market: Articles 49 and 71

The third regime targets the public and third parties. The registration in the EU database of the high-risk systems of Annex III, part of the information of which is publicly accessible, institutes a market transparency: it is addressed to no one in particular and to everyone in general — competitors, researchers, journalists, civil society, public purchasers6. It may be noted, moreover, that the retention, in the text finally adopted, of the registration obligation bearing on the provider who itself qualifies its system as not being high-risk constitutes one of the points on which the co-legislators departed from the initial simplification proposal: the traceability of self-qualification was deemed non-negotiable.

The pathology characteristic of this third regime is of yet another order. A transparency without a determined addressee has no mechanism of demand: no one is in a position to observe that a registration is missing, since no one is in a position to know what ought to be found there. Its effectiveness depends entirely on the existence of third-party actors disposed to make use of it, a condition that the Regulation does not create and cannot create.

D. What the distinction imposes

Three addressees, three temporalities, three contents, three sanction regimes, three pathologies. One struggles to identify what would authorise treating these sets as species of a single genus, other than the word that designates them. The unified doctrinal characterisation of the transparency of the AI Act is not merely useless: it is misleading, because it leads one to transpose from one regime to another conditions of effectiveness that do not apply there, and to impute to one the pathologies of the other.

The timeline resulting from the omnibus does no more than confirm, by institutional means, what the analysis suggested: these regimes let themselves be separated because they were already separate.

II. What regulation through information requires in order to function

Transparency is not a value in the economy of the Regulation; it is an instrument. It belongs to what a body of scholarship consolidated since the 1990s analyses as a distinct regulatory regime, neither prescriptive nor incentive-based, in which the obligation imposed on the operator to produce and disseminate information stands as the means of acting on its behaviour7.

The central contribution of this scholarship consists in a proposition whose consequences are rarely drawn. Disclosure modifies behaviour only if the information produced inserts itself into the effective decision cycle of its addressee: at the moment when the addressee decides, in the format in which it decides, with the granularity that allows it to compare. Fung, Graham and Weil make this the criterion of discrimination between disclosure devices that work and those that, formally complied with, remain without effect. Information that is accurate, complete and published at the wrong moment produces nothing. Information that is accurate, complete and published for an addressee who has neither the time, nor the means, nor the interest to process it produces nothing more.

Applied regime by regime, this criterion yields heterogeneous results, and that is precisely what forbids a global assessment.

For Article 50, the addressee’s decision cycle is, in most configurations, non-existent. The person informed that they are interacting with an artificial intelligence system most often has no decision to take at that moment: they have no available alternative, they have no term of comparison, and the service they are requesting becomes neither better nor worse by virtue of the notice. The information is due; it is not actionable. The provision will likely find its usefulness elsewhere than in its immediate effect on the addressee — in the progressive constitution of a social norm of expectation, and in its later evidentiary use, notably as regards synthetic content.

For the technical documentation, the addressee is identified and professional, which apparently satisfies the criterion. The difficulty shifts towards means: the effectiveness of a documentary regime presupposes an authority in a position to exploit the files it receives, which is a question of resources, technical competences and control doctrine, not a question of normative drafting. To date, the gap between the required documentary volume and the exploitation capacity of national authorities is the major unknown of the mechanism, and the eighteen-month postponement does not resolve it — it defers it.

For the European register, the criterion is not applicable as things stand, since the addressee is not determined. The effectiveness of this transparency depends on an ecosystem of use — academic research, specialised journalism, strategic litigation, demanding public procurement — whose existence is a hypothesis and not a given.

Three regimes, three diagnoses of effectiveness with no common measure. It is hard to see how a unified doctrine of “the” transparency of the Regulation could account for this dispersion.

III. Where the content of the obligation is fixed

There remains the most unsettling question, and the least addressed: while scholarship characterises and the timeline shifts, who writes the effective content of the obligation?

A. Endogeneity, and its European form

The work of Lauren Edelman on the endogeneity of law has established a now well-documented mechanism: organisations subject to an indeterminate legal obligation do not wait for it to be specified. They elaborate their own interpretations, build internal devices that materialise what they consider to be compliance, stabilise sectoral conventions — and frequently see these constructions subsequently ratified by courts and supervisory authorities, which adopt as a criterion of legality what the market had adopted as a criterion of good practice8. The legal meaning of the obligation is thus shaped in return by those whom it binds.

The conditions for this mechanism are met almost to the point of caricature in the case before us. The determining notions — the “sufficiently detailed” character of the summary of training data, the adequacy of the technical documentation, the clarity and intelligibility of the information due to the natural person — are open standards. Authentic interpretation falls to the Court of Justice, which will not be seised for several years. The supervisory authorities are being constituted. The harmonised standards, which were to provide the presumption of conformity, are not available at the hoped-for pace. And the December 2027 postponement adds eighteen months to this interval.

This point deserves to be underlined, for it is generally presented back to front. The postponement is commented upon as a lightening of the burden, and it is one; it is also, and more profoundly, a transfer of interpretive initiative. For eighteen additional months, what it means to “adequately document” a high-risk system will continue to stabilise in practices, file templates, firm methodologies and audit frameworks — that is, outside any judicial control. When the obligation becomes enforceable, it will encounter a content already constituted, and the authority that claims to depart from it will have to justify its departure in the light of a state of the art that it will not have produced.

The European form of this phenomenon nevertheless presents a singularity that it would be wrong to pass over in silence: endogeneity is here in part institutionalised rather than clandestine. The code of good practice relating to general-purpose models, drawn up under the aegis of the AI Office together with the actors concerned, and the template for the summary of training content published by that same Office, constitute avowed co-regulation devices: the content of the obligation is there explicitly co-produced with the regulated actors, within a public framework, according to a known procedure. This is a significant difference from the American model described by Edelman, and it calls for a nuanced assessment. Open co-production has the merit of traceability; it does not cancel out the asymmetry of technical competence that structures it, nor the fact that adherence to a code of good practice functions as a powerful presumption of conformity.

B. The intermediary layer

Alongside the regulated actors themselves, a second category of actors participates in this fixing, and it has not, to our knowledge, been theorised as such in the literature devoted to the Regulation.

Specialised law firms, public-affairs and compliance consultancies, conformity assessment bodies, vendors of risk-governance solutions, regulatory-intelligence platforms: these actors do not produce norms, and that is what long allowed them to be held analytically negligible. Their function is more modest in appearance and more decisive in practice. They produce the legibility of the norm. They select what, within a regulatory flow become unmanageable for any ordinary organisation, deserves to be flagged; they qualify what belongs to the text, to the non-binding guideline, to the position of a national authority or to market practice; they rank urgency; they translate provisions into operational obligations.

Each of these operations is an operation of selection, and therefore of power. A flag omitted does not exist for the addressee. A guideline presented without mention of its lack of binding force becomes, for the hurried reader, law. A national authority’s position translated into an “obligation” propagates as such into the internal frameworks of the organisations that receive it. Informational mediation is neither neutral nor purely instrumental: it contributes to fixing the effective meaning of the obligation before anyone has had to interpret it authentically.

The theory of the private production of law provides here some points of support — the work of Benoît Frydman on global law, that of Gunther Teubner on constitutional fragments, that of Fabrizio Cafaggi on transnational private regulation9 — but it does not exactly capture the phenomenon. These works analyse private actors that produce norms. The intermediaries in question here do not produce norms: they produce access to norms, an operation situated upstream and whose reach is broader, since it conditions what will even be perceived as applicable.

One observation deserves to be added, although it exceeds the scope of this contribution. This intermediary layer is, for its most capitalised part, largely non-European. The audit methodologies, the governance frameworks, the professional certifications and the platforms that structure the operational understanding of the European Regulation are for the most part produced by American actors. The Union exports its norm; the interpretive value of that norm is captured elsewhere. The formula of a reverse Brussels effect is not exaggerated, and the phenomenon would deserve a study of its own.

IV. The normative conditions of an information device

If the diagnosis is accurate, the practical conclusion cannot be that one ought to dispense with intermediaries. The complexity of the European digital regulatory corpus makes mediation inevitable; the organisation that claimed to do without it would only produce it internally, less well. The useful question is therefore that of the requirements such a device must satisfy in order to support the effectiveness of transparency obligations rather than to aggravate their pathologies.

Five conditions appear capable of being identified.

  1. Source traceability. Every assertion must be attached to an identified and directly accessible document. A synthesis whose origin cannot be traced substitutes its own authority for that of the text, and this substitution is the very mechanism of the distortion.
  2. Qualification of normative status. The distinction between the Regulation, delegated acts, guidelines devoid of binding force, national authorities’ positions, harmonised standards and market practice must be explicit and systematic. This is the most frequently disregarded condition, and the one whose default produces the heaviest effects.
  3. Dating and versioning. A shifting corpus makes it necessary to know on what date an assertion was accurate and what has modified it. The timeline resulting from the omnibus provides an immediate demonstration of this: a note drafted in April 2026 on the Regulation’s deadlines is today false, and nothing in its form signals this to its reader.
  4. Making explicit the margin of interpretation. A device that presents as settled what is disputed transfers to its user a risk that the user cannot assess. Where scholarship is divided, the division is part of the information due.
  5. Non-substitution for judgement. An information device must be designed to equip a decision, not to render it superfluous. The requirement is not rhetorical: it has concrete translations in the design of interfaces, and it is directly contradicted by the commercial arguments that promise automated compliance.

These conditions are neither technical nor procedural: they are normative, in that they condition the capacity of the device to serve a regulatory regime founded on the mandatory production of information. They also provide, incidentally, a grid for critically evaluating existing devices — including those that the author of these lines contributes to developing, which it is more honest to mention than to leave to be guessed10.

Conclusion

The 2nd of August 2026 will not render artificial intelligence systems transparent. It will render certain information mandatory, which is an entirely different thing, and the gap between the two propositions constitutes the real space of the legal work to come.

This gap will not be reduced by the precision of the text alone, because its source does not lie in the text’s imprecision. It lies in the fact that transparency, as a regulatory instrument, is never a property of the norm alone. It is a property of the triangle composed by the obligation, the organisation that executes it and the device that gives the information its form. The European legislator directly commands only the first vertex. The other two are built in an interval that it does not control, and that it has just lengthened by eighteen months.

This is not a defect of drafting. It is the ordinary condition of a regulation that has chosen to govern through information rather than through prohibition, and that must accept to recognise that this choice makes it dependent on those who put that information into circulation. To recognise this dependence would already be to exercise it with greater lucidity.

Bibliography

Normative and institutional sources

  • Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, OJ L, 2024/1689, 12 July 2024.
  • Regulation (EU) 2026/… of the European Parliament and of the Council amending Regulation (EU) 2024/1689 (“Digital Omnibus on AI”), adopted by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026.
  • European Commission, proposal for a regulation amending Regulations (EU) 2024/1689 and (EU) 2018/1139, 2025/0359(COD), 19 November 2025.
  • AI Office, code of good practice for general-purpose AI models, 2025.
  • AI Office, template for the public summary of the content used to train general-purpose AI models, 2025.

Regulation through information and regulatory transparency

  • ALEMANNO A., “Unpacking the Principle of Openness in EU Law: Transparency, Participation and Democracy”, European Law Review, vol. 39, no. 1, 2014.
  • CURTIN D. and MENDES J., “Transparence et participation : des principes démocratiques pour l’administration de l’Union européenne”, Revue française d’administration publique, no. 1, 2011.
  • FUNG A., GRAHAM M. and WEIL D., Full Disclosure. The Perils and Promise of Transparency, Cambridge, Cambridge University Press, 2007.
  • HOFMANN H. C. H., ROWE G. C. and TÜRK A. H., Administrative Law and Policy of the European Union, Oxford, Oxford University Press, 2011.
  • SUNSTEIN C. R., Simpler. The Future of Government, New York, Simon & Schuster, 2013.

Sociology of compliance and endogeneity of law

  • EDELMAN L. B., Working Law. Courts, Corporations, and Symbolic Civil Rights, Chicago, University of Chicago Press, 2016.
  • EDELMAN L. B. and STRYKER R., “A Sociological Approach to Law and the Economy”, in The Handbook of Economic Sociology, Princeton, Princeton University Press, 2005.
  • LANGE B., “Compliance Construction in the Context of Environmental Regulation”, Social & Legal Studies, vol. 8, 1999.
  • PARKER C., The Open Corporation. Effective Self-Regulation and Democracy, Cambridge, Cambridge University Press, 2002.
  • TALESH S. A., “How Dispute Resolution System Design Matters: An Organizational Analysis of Dispute Resolution Structures and Consumer Lemon Laws”, Law & Society Review, vol. 46, 2012.

Private production of law and pluri-normativity

  • CAFAGGI F., “New Foundations of Transnational Private Regulation”, Journal of Law and Society, vol. 38, 2011.
  • FRYDMAN B., Petit manuel pratique du droit global, Brussels, Bruylant, 2014.
  • FRYDMAN B., “A Pragmatic Approach to Global Law”, in H. MUIR WATT and D. FERNÁNDEZ ARROYO (eds.), Private International Law and Global Governance, Oxford, Oxford University Press, 2014.
  • TEUBNER G., Constitutional Fragments. Societal Constitutionalism and Globalization, Oxford, Oxford University Press, 2012.

Data governance and legal design

  • HILDEBRANDT M., Law for Computer Scientists and Other Folk, Oxford, Oxford University Press, 2020.
  • MANTELERO A., Beyond Data. Human Rights, Ethical and Social Impact Assessment in AI, The Hague, Asser Press, 2022.
  • STALLA-BOURDILLON S., “Identifiability as a Data Risk: Is a Uniform Approach to Anonymisation About to Emerge in the EU?”, European Journal of Risk Regulation, 2025.

Footnotes

  1. Commission proposal of 19 November 2025, 2025/0359(COD); political agreement of 6 and 7 May 2026; European Parliament vote of 16 June 2026 (423 in favour, 57 against, 174 abstentions); Council approval of 29 June 2026. The definitive Official Journal reference is to be inserted. ↩
  2. Regulation (EU) 2024/1689, Art. 50, paras. 1 to 5. ↩
  3. Ibid., Art. 99, para. 4. ↩
  4. Ibid., Arts. 11 to 13 and Annex IV. ↩
  5. Ibid., Arts. 53 and 55. ↩
  6. Ibid., Arts. 49 and 71, as well as Art. 6, para. 4, as regards the registration of systems self-qualified as not being high-risk. ↩
  7. FUNG A., GRAHAM M. and WEIL D., Full Disclosure. The Perils and Promise of Transparency, Cambridge, Cambridge University Press, 2007; SUNSTEIN C. R., Simpler. The Future of Government, New York, Simon & Schuster, 2013. ↩
  8. EDELMAN L. B., Working Law. Courts, Corporations, and Symbolic Civil Rights, Chicago, University of Chicago Press, 2016. ↩
  9. FRYDMAN B., Petit manuel pratique du droit global, Brussels, Bruylant, 2014; TEUBNER G., Constitutional Fragments, Oxford, Oxford University Press, 2012; CAFAGGI F., “New Foundations of Transnational Private Regulation”, Journal of Law and Society, vol. 38, 2011. ↩
  10. The author is developing Euridium, a regulatory-intelligence platform. This contribution takes up, in condensed form, the hypotheses of a research project in progress. ↩