Flag AI services in your privacy policy, straight from the generator

In short

The EU AI Act’s transparency rules apply from August 2, 2026. You can now mark any service in the Privacy and Cookie Policy Generator as AI-powered, pick the type of interaction it involves, and the generator writes the matching disclosure clauses into your privacy policy.

The EU Artificial Intelligence Act (AI Act, Regulation (EU) 2024/1689) sets transparency rules for AI systems that interact with people, and they apply from August 2, 2026. Chatbots and virtual assistants, tools that generate text, images, audio or video, emotion recognition: those rules can reach all of it.

If you have seen headlines about the AI Act being delayed, they refer to something else. The AI Omnibus (Regulation (EU) 2026/1744) entered into force on July 27, 2026 and moved the obligations for high-risk AI systems out to December 2027 and August 2028. The transparency rules were not deferred: the August 2, 2026 date is unchanged.

Here’s the practical part. Two obligations now land on the same services. The AI Act asks you to disclose the AI at the moment someone interacts with it. The GDPR, as it always has, asks your privacy policy to describe the processing, and that now has to account for an AI layer most policies were never written for. Until now, there was no clean way to describe it. You’d add a service to your policy, and the generator would document cookies, data types, and legal bases, but nothing that reflected the AI layer sitting on top.

That’s what we changed.

What the AI Act asks for

Article 50 of the AI Act covers transparency at the point of interaction. In plain terms, people should know when they’re dealing with an AI system rather than a person, and when content they’re looking at came from one. It covers four broad situations:

  • Chatbots and virtual assistants
  • AI-generated images, audio, and video
  • Emotion recognition and biometric categorization
  • Synthetic media and deepfakes

These are disclosure duties rather than documentation duties: a label when the chatbot opens, a marking on generated content. The documentation side comes from the GDPR, which requires your privacy policy to explain what the processing involves: what the system does, what data it handles, and on what basis. The two obligations sit on top of each other, and the AI layer is the part most existing policies don’t describe.

The generator covers the policy side. For the disclosure at the point of interaction, most established chatbot and AI tools already label themselves, so in practice their vendor handles it. The obligation stays with you either way, so it’s worth confirming rather than assuming. And if you built the interface yourself, whether that’s a custom chat or your own front end against a model API, no vendor is covering it for you and you’ll need to add that label where the interaction starts.

What’s new in the generator

The AI option is a new attribute on services you’ve already added. Open a service in the Privacy and Cookie Policy Generator, and alongside the options you already configure (data types, categorization, legal basis) you’ll find the AI option. Turn it on, then select which interaction types apply to that service. One service can involve more than one: a support assistant might both converse with users and generate content.

The AI option shown on a service in the iubenda Privacy and Cookie Policy Generator

Save, and the generator adds the relevant Article 50 disclosure for that service to your privacy policy. It describes the type of AI interaction, what data the system processes, and the disclosure that applies. You get the clauses on both of our policy layouts, so it works whichever version your documents use.

An Article 50 AI disclosure clause generated in a privacy policy

Because the flag lives on the service, you keep control. Our scan detects what runs on your site and suggests services, and you decide which ones use AI. That matters for anything built in-house: a custom model, an internal recommendation engine, a script your developers wrote against a model API. No scanner classifies those reliably, so you set the flag yourself.

Set it up in three steps

  1. Enter the Privacy and Cookie Policy Generator for your site and go to your services
  2. Turn on the AI option for each service that uses AI, then select the interaction types that apply
  3. Save and republish your policy
Walkthrough of turning on the AI option for a service and saving the policy

That’s the whole thing. If you manage policies for clients across several sites, it’s the same three steps per site, in the panel you already work in.

Custom privacy policy templates work differently. We update those on request, not automatically, so the AI clauses won’t appear on their own. Get in touch with our support team and we’ll add them for you.

What’s coming next

Two things are already in progress.

Automatic detection

Right now you set the flag yourself. Next, our scan will surface it for services it recognizes as AI-powered, so known chatbot widgets and AI tools arrive pre-marked and you just confirm.

Terms and conditions clauses

If you’re not only using AI but building your product on top of a third-party model, the AI Act also looks for clarity on who is responsible for what between the model provider and you as deployer. Standard terms templates don’t cover that ground: liability for wrong or biased outputs, ownership of generated content, monitoring duties. We’re adding a clause category for it in the Terms and Conditions Generator.

The AI option is live in the Privacy and Cookie Policy Generator. If you already know which of your services run AI, updating your policy takes a few minutes.

Follow us on: