What This Template Covers
The AI system transparency template covers four structured disclosure and documentation areas that together meet the transparency requirements of the EU AI Act, UK GDPR, and related ICO guidance. The user-facing AI disclosure section covers what users must be told about AI involvement in a product or service. The EU AI Act requires that AI systems interacting with humans in real time identify themselves as AI unless it is obvious from context. Beyond the legal minimum, good user-facing disclosure covers: what data the AI uses, what decisions or outputs it produces, what the AI's limitations are, and how users can seek human review if they wish. The model card structure section provides a standardised format for documenting each AI model used in the product. Model cards capture: the model's purpose, its performance characteristics, its known limitations and failure modes, the data it was trained on, and the steps taken to evaluate bias and fairness. Model cards are standard practice at AI-mature organisations and are increasingly expected by enterprise buyers in procurement due diligence. The decision explanation framework covers how automated or AI-assisted decisions can be explained to individuals affected by them. Under GDPR Article 22, individuals have the right not to be subject to solely automated decisions that produce legal or similarly significant effects, and the right to an explanation when such decisions are made. The framework provides a template for producing meaningful explanations. The EU AI Act transparency obligation checklist maps the specific transparency obligations in Articles 13, 14, 50, and 52 of the EU AI Act to the actions required for compliance, with a column for the responsible team and the completion status.
How to Use This Template Step by Step
Step one: inventory your AI systems. List every AI component in your product: each model used, each automated decision point, each AI-generated output presented to users. For each item, note whether it involves real-time interaction with a natural person (triggering EU AI Act Article 52 disclosure obligations), whether it produces decisions that significantly affect individuals (triggering GDPR Article 22 obligations), and whether it falls into any EU AI Act high-risk category (Annex III). Step two: draft the user-facing AI disclosure for each AI interaction point. The disclosure should be in plain language, proportionate to the context (a brief inline label is appropriate in many cases, a longer disclosure is appropriate for significant automated decisions), and accessible to users before they interact with the AI system. The disclosure must include at minimum: that the user is interacting with or being affected by an AI system, the purpose of the AI system, and where relevant, that a human review option is available. For high-risk AI systems under the EU AI Act, additional disclosures about the system's capabilities and limitations are required. Step three: complete a model card for each AI model used. Model card sections: intended use (what the model is designed to do and what it should not be used for), performance metrics (accuracy, precision, recall, or task-specific metrics across the evaluation dataset), limitations (what inputs or contexts the model performs poorly on), training data summary (what type of data was used, its scope and any known biases), bias and fairness evaluation results, and the monitoring approach for detecting performance degradation in production. Step four: develop the decision explanation framework. For each automated decision point, define: the factors used in the decision, how each factor is weighted, the output categories and what they mean, the threshold that produces each decision outcome, and the plain-language explanation template for each outcome. Test the explanation template with a non-technical person to verify it is genuinely understandable. Step five: complete the EU AI Act transparency obligation checklist. Work through Articles 13 (transparency and information for users of high-risk AI), 14 (human oversight measures), 50 (transparency obligations for certain AI systems), and 52 (transparency obligations for AI systems interacting with natural persons). For each obligation, record whether it applies to your system, who is responsible for compliance, and the current status.
Section-by-Section Walkthrough
The user-facing disclosure section should be designed for the context in which it appears. An AI chatbot should identify itself as AI at the start of every conversation, or at minimum on the first interaction. An AI-assisted decision (loan assessment, content recommendation, job screening) needs a more detailed disclosure that explains the role of AI in the decision and the user's rights. An AI-generated document (contract, report, code) should be clearly labelled as AI-generated. The label format and placement should be designed into the product UI, not added as a legal notice that users never see. The model card format in this template follows the Google model card standard, which is the most widely adopted format and is referenced by the ICO in its guidance on AI transparency. For products sold into enterprise markets, the model card is increasingly a procurement requirement. Buyers want to understand what AI they are buying, how it was evaluated, and what its known limitations are. The decision explanation framework section is where the GDPR Article 22 obligation translates into product design. A meaningful explanation under Article 22 is not "an algorithm assessed your application." It is: "Your application was assessed on three factors: credit history (positive, you have no defaults in the past 36 months), income-to-debt ratio (borderline, your ratio is 3.2x, our threshold is 3.5x), and employment status (positive, you are in full-time employment). The application was declined due to the income-to-debt ratio being below our threshold. You can request a manual review by calling the number below." This level of specificity is what the law requires for significant automated decisions. The EU AI Act checklist section should note that the Act is being applied in the EU from August 2026 for most obligations, with the UK government's AI regulation approach evolving separately. UK products sold into EU markets must comply with EU AI Act obligations for those sales. The checklist should be reviewed by legal counsel with AI regulation expertise before being used as a compliance certification.
Common Mistakes This Template Prevents
The most common AI transparency mistake is treating disclosure as a one-time legal notice in the terms of service. No user reads the terms of service to understand whether they are interacting with AI. Effective transparency means disclosure at the point of interaction, in plain language, proportionate to the significance of the AI's role. This template's user-facing disclosure section requires designing disclosures for specific UI contexts, not drafting legal boilerplate. The second mistake is completing a model card for the purpose of checking a compliance box rather than for genuine transparency. A model card that says "the model performs well across all demographics" without supporting evidence is worse than no model card, because it implies bias has been evaluated when it has not. Complete model cards with honest, specific evaluation results, including any areas of underperformance. The third mistake is not having a human review process for significant automated decisions. GDPR Article 22 requires that organisations provide a means for individuals to obtain human review of automated decisions that produce significant effects. Products that automate significant decisions without a human review path are non-compliant. The decision explanation framework section includes a human review process as a required element. The fourth mistake is not updating transparency documentation when AI models change. If you update the underlying model, change the prompt architecture, or modify the decision logic, the model card, the user-facing disclosure, and the explanation framework may need to be updated. Build documentation review into the AI model update process.
Customisation Tips for Different Project Types
For customer-facing chatbots and conversational AI, the user-facing disclosure needs to address two specific EU AI Act Article 52 scenarios: a chatbot that could be mistaken for a human must identify itself as AI, and deepfake or synthetic media content must be labelled as AI-generated. Design the disclosure for the conversation interface specifically: a persistent label, a first-message disclosure, or a profile indicator are all valid approaches for chatbot identification. For AI-assisted hiring or HR tools, the model card and decision explanation framework sections need to include a fairness assessment across protected characteristics under the Equality Act 2010: gender, race, age, disability. The ICO's guidance on AI in recruitment and HR sets out specific expectations for fairness testing and explanation capability. EU AI Act Annex III lists employment-related AI systems as high-risk, triggering additional conformity assessment requirements. For financial services AI used in credit assessment, fraud detection, or insurance underwriting, the FCA's guidance on algorithmic systems is the sector-specific reference alongside the EU AI Act and UK GDPR. FCA-regulated firms must be able to explain AI-assisted decisions to customers on request, and must be able to demonstrate to the FCA that AI systems do not produce outcomes that discriminate against protected groups. For NHS-connected products or AI used in healthcare decision support, the MHRA's AI as a Medical Device guidance applies if the AI is involved in clinical decision-making. NHS Digital's standards for AI in health require transparency to patients about AI involvement in their care. These requirements are more stringent than commercial sector transparency requirements and should be reviewed with NHS Digital or a regulatory affairs specialist.