What Does Your Privacy Policy Say About AI?
Lees dit in het Nederlands →$ grep -i "ai" privacy-policy.md
What does your privacy policy say about AI?
The AI Act does not require a paragraph in your privacy policy. That's the first thing to clear up, because half of marketing land sells on that misunderstanding. What actually applies from 2 August 2026 is narrower and more concrete: if someone is talking to an AI, they need to know it. Below is what that means, what is not your obligation, and why the GDPR hits you harder than the AI Act. We are not lawyers.
Ever since the AI Act came into existence, a trade has sprung up in "AI compliance checks". Much of it sells fear of rules that don't apply to you.
This post is our own stocktake, made to know where we stand ourselves. We haven't had a lawyer look at it, and you should know that before reading on. It's a map, not advice.
01 / the short versionDoes the AI Act require anything in your privacy policy?
No. Those are two different laws with two different subjects.
Your privacy policy is a GDPR document. It's about personal data: which you collect, for what, for how long, and with whom you share it. The AI Act is about AI systems and their risks. There's overlap in practice, but one law doesn't dictate what goes in the other's document.
What doesn't follow from that: that you don't need to write anything down. There are two reasons to do it anyway, and they're in blocks 4 and 5.
The question isn't whether it's required. The question is whether you can explain it when someone asks.
02 / the one rule that probably applies to youWhen does Article 50 apply?
When someone is talking directly to an AI and doesn't realise it.
Article 50, first paragraph, boils down to this: if a human is talking to an AI system, they must be told. Enforcement starts 2 August 2026.
There's an exception that settles most discussions: it doesn't apply if it's clear from the circumstances. Someone who clicks a button that says "chat with our assistant" already knows.
Concretely, for an average business:
Short version: if you don't have AI talking directly to customers, Article 50 probably doesn't affect you.
03 / what isn't yours to worry aboutWhich obligations sit with the model provider?
More than compliance-package vendors tell you.
Two obligations that often get placed on the wrong shoulders:
Machine-readable marking of AI-generated content (Article 50, second paragraph) rests with the party offering the generating system. If you use a supplier's language model, that's their obligation, not yours.
Labelling AI texts (fourth paragraph) only applies to texts published to inform the public on matters of general interest ā journalism, in short. And even there an exception applies when a human retains editorial control. Your newsletter or your quote doesn't fall under this.
Another misunderstanding that costs money: the heavy obligations in the Act apply to high-risk systems, and that's a defined list ā recruitment and selection, credit scoring, education, biometrics, government services. Sales, marketing and internal automation aren't on it.
One warning about the dates. There's an amendment package that would push the high-risk date from August 2026 to December 2027. At the time of writing, formal publication of that had not been confirmed. Don't present that delay as a settled fact to a client.
04 / what weighs heavierWhy is the GDPR the real work?
Because it already applies, is already enforced, and does ask something of your privacy policy.
The questions that actually matter in practice are almost all GDPR questions:
- Does personal data go to a language model? Then that provider is a processor and belongs in your list and your data processing agreement.
- Where is it processed? The big providers are based in the United States. That's allowed, but it requires justification, not silence.
- Does the system make decisions about people? Article 22 GDPR sets limits on decisions made solely through automated means that affect someone.
- Is data used to train models? Usually not under business subscriptions, but check it and write down what you found.
That last one is the most common mistake: companies promise "a human always checks" and then never set that up. A promise you keep but can't prove has to be reconstructed the moment there's a complaint.
05 / the six questionsSo what do you actually write down?
Answer these six and you have the content. The format comes after.
- Which AI do you use for what? One line per application.
- Does personal data go into it? If so: which, and whose.
- Who is the provider and where do they process? Name and country.
- Does it talk directly to customers? If so, Article 50 applies and you add that line.
- Does a human check before anything goes out? And can you prove it?
- What happens if someone objects? Who picks that up.
We answered these six for ourselves and landed on one relevant exposure: the moment a system we build starts talking directly to a client's customers. Everything else is minimal risk.
Our own advice to ourselves, incidentally, was stricter than the law requires: note that a report was drafted by AI, even when it isn't required. If your proposition is that you automate work, hiding the fact that you do it is the worst possible signal.
Do I need an AI paragraph in my privacy policy?+
What exactly does Article 50 require?+
Do I need to label AI texts?+
Does my business fall under the heavy obligations?+
Is this legal advice?+
Want this figured out for your own situation?
Book a call
We'll look at where your time is leaking and tell you honestly whether we can do anything about it. Often the answer is: you can do this yourself. Then we'll say so, and you'll have spent thirty minutes on a clear answer.
This text was produced with AI support and reviewed and approved by a human before publication.