fix: correct Article 26 citation and add Article 50 section

Address Greptile review:
- P1: Article 26(6) → Article 26(5) for deployer log retention
- P1: Add dedicated Article 50 section for user-facing transparency
  (was referenced in scope section but had no corresponding section)
This commit is contained in:
Bipin Rimal 2026-03-23 12:43:35 +05:45
parent 9de47978b4
commit 980b60cda1

View file

@ -151,7 +151,7 @@ class ComplianceLogger(CustomLogger):
litellm.callbacks = [ComplianceLogger()]
```
Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(6) for deployers; Article 18 requires 10 years for providers).
Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(5) for deployers; Article 18 requires 10 years for providers).
## Article 13: Transparency
@ -184,6 +184,30 @@ What you need to build for Article 14 compliance:
LiteLLM provides the **logging and hook infrastructure** to build human oversight on top of. The oversight logic itself — review queues, approval workflows, kill switches — lives in your application layer.
## Article 50: Transparency for AI-interacting systems
Article 50 applies to **all AI systems that interact directly with users**, not just high-risk systems. If your LiteLLM deployment powers a chatbot, virtual assistant, or any interface where a user communicates with AI-generated responses, you must:
1. **Inform users they are interacting with an AI system** — before or at the start of the interaction
2. **Mark AI-generated content** — if the system generates text, audio, images, or video that could be mistaken for human-created content, it must be machine-readable as AI-generated (Article 50(2))
3. **Disclose deepfakes** — if the system generates or manipulates content depicting real people or events, this must be disclosed (Article 50(4))
LiteLLM itself does not handle user-facing disclosure — it operates at the API gateway layer. Your application must implement the disclosure:
```python
# Example: Add AI disclosure header to responses
response = litellm.completion(model="gpt-4", messages=messages)
# Your application layer adds the disclosure
user_response = {
"content": response.choices[0].message.content,
"ai_disclosure": "This response was generated by an AI system.",
"model_used": response.model, # Transparency: which model answered
}
```
Article 50 obligations exist **independently of Annex III classification**. Even if your system is not high-risk, this section applies.
## GDPR considerations
LiteLLM processes user prompts. If those prompts contain personal data: