What Does Your Privacy Policy Say About AI?

← back to home

Pillar 01 // Ownership
transparency.md

$ grep -i "ai" privacy-policy.md

What does your privacy policy say about AI?

The AI Act does not require a paragraph in your privacy policy. That's the first thing to clear up, because half of marketing land sells on that misunderstanding. What actually applies from 2 August 2026 is narrower and more concrete: if someone is talking to an AI, they need to know it. Below is what that means, what is not your obligation, and why the GDPR hits you harder than the AI Act. We are not lawyers.

DD DataDrift Digital • 16 June 2026 • 7 min

Ever since the AI Act came into existence, a trade has sprung up in "AI compliance checks". Much of it sells fear of rules that don't apply to you.

This post is our own stocktake, made to know where we stand ourselves. We haven't had a lawyer look at it, and you should know that before reading on. It's a map, not advice.

01 / the short versionDoes the AI Act require anything in your privacy policy?

No. Those are two different laws with two different subjects.

Your privacy policy is a GDPR document. It's about personal data: which you collect, for what, for how long, and with whom you share it. The AI Act is about AI systems and their risks. There's overlap in practice, but one law doesn't dictate what goes in the other's document.

What doesn't follow from that: that you don't need to write anything down. There are two reasons to do it anyway, and they're in blocks 4 and 5.

The question isn't whether it's required. The question is whether you can explain it when someone asks.

02 / the one rule that probably applies to youWhen does Article 50 apply?

When someone is talking directly to an AI and doesn't realise it.

Article 50, first paragraph, boils down to this: if a human is talking to an AI system, they must be told. Enforcement starts 2 August 2026.

There's an exception that settles most discussions: it doesn't apply if it's clear from the circumstances. Someone who clicks a button that says "chat with our assistant" already knows.

Concretely, for an average business:

YESA chatbot on your site that customers talk to. Say it's an AI. One line at the top of the conversation is enough.
YESA phone assistant that answers calls. Here the risk of confusion is greatest, so the obligation is clearest.
NOA report or quote drafted with AI and sent by you. That's not an interaction with a system.
NOInternal tools used only by you and your team. You already know.

Short version: if you don't have AI talking directly to customers, Article 50 probably doesn't affect you.

03 / what isn't yours to worry aboutWhich obligations sit with the model provider?

More than compliance-package vendors tell you.

Two obligations that often get placed on the wrong shoulders:

Machine-readable marking of AI-generated content (Article 50, second paragraph) rests with the party offering the generating system. If you use a supplier's language model, that's their obligation, not yours.

Labelling AI texts (fourth paragraph) only applies to texts published to inform the public on matters of general interest — journalism, in short. And even there an exception applies when a human retains editorial control. Your newsletter or your quote doesn't fall under this.

Another misunderstanding that costs money: the heavy obligations in the Act apply to high-risk systems, and that's a defined list — recruitment and selection, credit scoring, education, biometrics, government services. Sales, marketing and internal automation aren't on it.

One warning about the dates. There's an amendment package that would push the high-risk date from August 2026 to December 2027. At the time of writing, formal publication of that had not been confirmed. Don't present that delay as a settled fact to a client.

04 / what weighs heavierWhy is the GDPR the real work?

Because it already applies, is already enforced, and does ask something of your privacy policy.

The questions that actually matter in practice are almost all GDPR questions:

  • Does personal data go to a language model? Then that provider is a processor and belongs in your list and your data processing agreement.
  • Where is it processed? The big providers are based in the United States. That's allowed, but it requires justification, not silence.
  • Does the system make decisions about people? Article 22 GDPR sets limits on decisions made solely through automated means that affect someone.
  • Is data used to train models? Usually not under business subscriptions, but check it and write down what you found.

That last one is the most common mistake: companies promise "a human always checks" and then never set that up. A promise you keep but can't prove has to be reconstructed the moment there's a complaint.

05 / the six questionsSo what do you actually write down?

Answer these six and you have the content. The format comes after.

  • Which AI do you use for what? One line per application.
  • Does personal data go into it? If so: which, and whose.
  • Who is the provider and where do they process? Name and country.
  • Does it talk directly to customers? If so, Article 50 applies and you add that line.
  • Does a human check before anything goes out? And can you prove it?
  • What happens if someone objects? Who picks that up.

We answered these six for ourselves and landed on one relevant exposure: the moment a system we build starts talking directly to a client's customers. Everything else is minimal risk.

Our own advice to ourselves, incidentally, was stricter than the law requires: note that a report was drafted by AI, even when it isn't required. If your proposition is that you automate work, hiding the fact that you do it is the worst possible signal.

Frequently asked questions
Do I need an AI paragraph in my privacy policy?+
The AI Act doesn't require it — that's a GDPR document and the two laws have different subjects. But the GDPR can require something the moment personal data goes to a language model: that provider is then a processor and belongs in your overview. So the practical question isn't whether it's required, but whether you can explain it.
What exactly does Article 50 require?+
That someone talking directly to an AI system knows it. Enforcement starts on 2 August 2026. An exception applies when it's clear from the circumstances — someone clicking "chat with our assistant" already knows. If you don't have AI talking directly to customers, this article probably doesn't affect you.
Do I need to label AI texts?+
Only for texts published to inform the public on matters of general interest, and even there an exception applies when a human retains editorial control. Your newsletter, quote or blog post doesn't fall under this. Machine-readable marking of generated content is, moreover, the model provider's obligation, not yours.
Does my business fall under the heavy obligations?+
Probably not. Those apply to high-risk systems, and that's a defined list: recruitment and selection, credit scoring, education, biometrics, government services. Sales, marketing and internal automation aren't on it. Watch the dates: there's an amendment package that would shift the high-risk date, but formal publication of that had not been confirmed at the time of writing.
Is this legal advice?+
No. This is our own stocktake, made to know where we stand ourselves, and no lawyer has reviewed it. Use it as a map, not as advice. If you're in a regulated sector or process special categories of personal data, you should talk to someone qualified for that.
30 minutes, free, no sales pitch

Want this figured out for your own situation?

Book a call

We'll look at where your time is leaking and tell you honestly whether we can do anything about it. Often the answer is: you can do this yourself. Then we'll say so, and you'll have spent thirty minutes on a clear answer.

→ Book a call (30 min)

This text was produced with AI support and reviewed and approved by a human before publication.