diff --git a/docs/my-website/docs/eu-ai-act-compliance.md b/docs/my-website/docs/eu-ai-act-compliance.md index 93ecada079f..c8f4d339433 100644 --- a/docs/my-website/docs/eu-ai-act-compliance.md +++ b/docs/my-website/docs/eu-ai-act-compliance.md @@ -151,7 +151,7 @@ class ComplianceLogger(CustomLogger): litellm.callbacks = [ComplianceLogger()] ``` -Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(6) for deployers; Article 18 requires 10 years for providers). +Whichever option you choose, connect to a persistent backend with a retention policy of at least 6 months (Article 26(5) for deployers; Article 18 requires 10 years for providers). ## Article 13: Transparency @@ -184,6 +184,30 @@ What you need to build for Article 14 compliance: LiteLLM provides the **logging and hook infrastructure** to build human oversight on top of. The oversight logic itself — review queues, approval workflows, kill switches — lives in your application layer. +## Article 50: Transparency for AI-interacting systems + +Article 50 applies to **all AI systems that interact directly with users**, not just high-risk systems. If your LiteLLM deployment powers a chatbot, virtual assistant, or any interface where a user communicates with AI-generated responses, you must: + +1. **Inform users they are interacting with an AI system** — before or at the start of the interaction +2. **Mark AI-generated content** — if the system generates text, audio, images, or video that could be mistaken for human-created content, it must be machine-readable as AI-generated (Article 50(2)) +3. **Disclose deepfakes** — if the system generates or manipulates content depicting real people or events, this must be disclosed (Article 50(4)) + +LiteLLM itself does not handle user-facing disclosure — it operates at the API gateway layer. Your application must implement the disclosure: + +```python +# Example: Add AI disclosure header to responses +response = litellm.completion(model="gpt-4", messages=messages) + +# Your application layer adds the disclosure +user_response = { + "content": response.choices[0].message.content, + "ai_disclosure": "This response was generated by an AI system.", + "model_used": response.model, # Transparency: which model answered +} +``` + +Article 50 obligations exist **independently of Annex III classification**. Even if your system is not high-risk, this section applies. + ## GDPR considerations LiteLLM processes user prompts. If those prompts contain personal data: