All insights
Industry newsAug 26, 2026Source: Traficom

Finland's Traficom publishes AI Act transparency guidance

Governance team mapping Traficom AI transparency duties to notices, machine-readable labels, authorities, and evidence

Finland's Transport and Communications Agency, Traficom, has published practical guidance on the EU AI Act's transparency duties. The guidance matters because Article 50 has applied since 2 August 2026, and it turns a broad legal requirement into concrete questions about who must disclose AI use, what must be labelled, and which Finnish authority may supervise the obligation.

The publication does not create a new law or replace the European Commission's interpretation. It is national implementation guidance for organisations operating in Finland. Teams should treat it as a prompt to verify their own systems, notices, labelling controls, and evidence, not as a conclusion that every AI output needs the same label.

What Traficom clarified

Traficom says the transparency duties cover several different situations. People must be told when they interact directly with an AI system unless that fact is obvious from the context. Providers of systems that generate synthetic audio, images, video, or text must make the output detectable in a machine-readable format. Deployers of emotion-recognition or biometric-categorisation systems must inform affected people. Deepfakes generally require disclosure, while AI-generated text published to inform the public on matters of public interest can also trigger a disclosure duty.

The details depend on the role, system, and use case. Traficom notes that the public-interest text duty has an exception where a human has reviewed the content or exercised editorial control and a person or organisation carries editorial responsibility. This is not a general exemption from governance. It changes the disclosure analysis and makes the review record important.

The agency also states that content created before 2 August 2026 does not need to be labelled retroactively. The European Commission's Article 50 FAQ confirms that limited transition point and says pre-existing systems receive a grace period only until 2 December 2026 for the technical duties to mark and detect synthetic output.

Enforcement is divided across authorities

Traficom explains that Finland's market-surveillance authorities enforce the AI Act within their assigned sectors. Traficom is one of those authorities and has a general supervisory role outside defined exceptions. Sector authorities supervise certain high-risk systems. The EU AI Office may supervise transparency obligations for some general-purpose AI systems, the European Data Protection Supervisor covers EU institutions, and Finland's Data Protection Ombudsman remains responsible for applicable data-protection rules.

That distribution is operationally important. A single AI service may touch several regimes and authorities. An organisation should identify its provider, deployer, importer, or distributor role, map the use case to the relevant Article 50 paragraph, and record which authority and adjacent rules may apply.

The EU code is useful, but voluntary

The Commission published a voluntary Code of Practice on marking and labelling AI-generated content. Its FAQ says signatories can use the code to demonstrate compliance with the covered obligations. Non-signatories may use another adequate approach, but authorities may ask them for more information about how they comply.

This distinction is easy to lose in internal summaries. Joining the code is not the legal obligation. The obligation comes from Article 50. The code is one compliance route, and an alternative route still needs a defensible design and evidence.

What teams should check now

An evidence-led review can start with five questions:

  1. Where can a person reasonably mistake an AI interaction for a human interaction?
  2. Which systems generate synthetic media or public-interest text, and can the output be detected in a machine-readable way?
  3. Which deployer notices are shown for emotion recognition, biometric categorisation, or deepfake use?
  4. Where does a human review or editorial-control exception apply, and who carries editorial responsibility?
  5. What logs, release records, notice copies, and technical tests prove the chosen control works?

The answers belong in the system inventory and control map. Maetra's framework library can help teams connect obligations to controls, while the AI Act readiness evidence checklist provides a practical starting point for proof collection.

Maetra analysis

The most useful signal in Traficom's guidance is not a universal label format. It is the need to separate roles, content types, and exceptions. A chatbot notice, a deepfake disclosure, and machine-readable synthetic-content marking are different controls with different owners and evidence.

Teams that use one generic "AI generated" policy risk missing both technical provider duties and deployer-facing notices. A stronger approach is to maintain a decision record for every relevant system: applicable role, content class, user context, chosen notice or marking mechanism, test result, exception reasoning, owner, and review date.

Traficom's guidance is specific to Finnish supervision, and the Commission FAQ is general EU guidance. Neither source is a substitute for legal advice on a particular deployment. Together, however, they give governance teams a current and testable basis for closing Article 50 evidence gaps.

Sources

Traficom AI guidanceEU AI Act Article 50AI transparencyFinland AI regulation
Finland's Traficom publishes AI Act transparency guidance | Maetra Insights