KBD-specific briefing
Current as of 4 August 2026

The EU AI Act: implications for KBD

KBD does not need to become an AI-model company. The practical issue is knowing when KBD is using AI as a creative tool, deploying an AI system, integrating a client’s regulated product, or delivering content that must be disclosed.

Bottom line

Ordinary branding, static marketing sites, presentation design, and conventional web development are usually low-risk. KBD’s meaningful AI Act exposure is concentrated in AI-powered web experiences, synthetic media, AI-generated public-interest content, and projects involving high-impact decisions.

What changes for KBD?

AI becomes part of project governance. KBD should track what tool was used, what data entered it, who reviewed the result, whether disclosure is required, and which party is legally responsible for the deployed system.

KBD’s likely exposure by activity

This is a practical triage model—not a substitute for project-specific legal classification.

Activity
Likely exposure
What matters
Traditional brand and web work

Static sites, CMS work, branding, decks, ordinary forms

Low

Privacy, copyright, accessibility, security, and ordinary client obligations still apply.

AI-assisted creative production

Brainstorming, image concepts, copy drafts, design assistance

Low–medium

Approved tools, confidential-data controls, licensing, human review, and asset provenance.

Synthetic media

AI voice, avatars, realistic image/video manipulation, deepfakes

Medium

Disclosure, machine-readable marks where required, likeness permissions, and proof of client approval.

Chatbots and AI agents

Sales assistants, event concierges, AI search, voice interfaces

Immediate

Tell people they are interacting with AI; provide clear escalation and preserve the client’s role and responsibilities.

High-impact client systems

Hiring, credit, education, essential services, biometrics

High / conditional

Escalate early. KBD may be an integrator or downstream provider and the UI must support the client’s safeguards.

Web development: chatbots and agents

The most immediate web-development change is transparency at the interface.

From 2 August 2026

Build disclosure into the experience

Covered interactive AI systems generally need to tell people that they are interacting with AI at or before the first meaningful interaction. A hidden privacy-policy disclosure is not a good implementation pattern.

  • Make the disclosure clear and accessible.
  • Keep it visible across web, mobile, event, and voice versions.
  • Provide a human fallback or escalation path where appropriate.
  • Do not let the interface imply that an AI agent is a human employee.
Role matters

Decide who is provider and deployer

If KBD launches an AI feature under KBD’s own name or brand, KBD may have provider responsibilities. If KBD builds an AI experience for a client under the client’s brand, the client may be the deployer while KBD is an integrator or downstream provider.

The contract label alone does not decide this. Actual control, branding, intended purpose, and deployment responsibilities matter.

The European Commission says AI agents are not a separate legal category. Existing rules for AI systems and general-purpose AI models can apply to them, including transparency from August 2026 and high-risk obligations on the later timetable.

Creative work: provenance becomes a deliverable

KBD’s design and storytelling work creates a practical need for a lightweight chain of custody for AI-assisted assets.

Synthetic content

Assets that deserve special handling

  • Realistic AI-generated or altered people and places
  • Deepfake-style video or photography
  • Synthetic voice or cloned speech
  • AI avatars and virtual presenters
  • AI-generated text on matters of public interest

Standard assistive editing may fall within an exception, but KBD should not assume that every generative edit is “just editing.”

Recommended record

Keep an asset provenance note

  • Tool or model used
  • Source files and permissions
  • Whether client-confidential material was uploaded
  • Whether a person’s face, voice, likeness, or style was involved
  • Required disclosure or machine-readable marking
  • Human reviewer and client approval

AI-generated public-interest copy

Article 50 addresses AI-generated text published to inform the public about matters of public interest when it has not undergone human review or editorial control. For relevant client work, KBD should assign a real human editor who takes responsibility for accuracy, framing, and publication—not merely someone who glances at the output.

High-risk client projects

KBD does not need to classify every technology client as high-risk, but it does need a reliable escalation trigger.

Escalate

Employment

Candidate ranking, résumé filtering, targeted job advertising, worker monitoring, performance evaluation, promotion, or termination.

Escalate

Access and eligibility

Creditworthiness, essential services, insurance risk or pricing, benefits, or other consequential eligibility decisions.

Escalate

Other sensitive sectors

Education, law enforcement, migration, courts, democratic processes, critical infrastructure, and certain biometric systems.

Front-end work can still matter

A marketing site for an AI company is not automatically high-risk. But if KBD builds the interface through which a high-risk system makes or communicates decisions, KBD may need to support intended-purpose documentation, human oversight, user information, logging, escalation paths, and change control. KBD should not silently treat a regulated decision product as ordinary website work.

A lightweight KBD AI operating model

KBD does not need a large compliance department to start. It needs consistent project hygiene.

Inventory tools and projects

List internal AI tools, client-facing AI features, synthetic-media projects, agents, personalization, and automated decision work.

Classify the use

Classify the application, not just the model. The same model can be ordinary for copy drafting and high-risk for applicant ranking.

Control confidential data

Do not place unreleased strategy, credentials, personal data, or proprietary source files into unapproved consumer AI tools.

Assign a human owner

Every external deliverable needs a person responsible for accuracy, rights, disclosure, brand fit, and client approval.

Update the SOW

Document roles, approved tools, source-data permissions, disclosures, provenance, likeness rights, change control, and incident cooperation.

Preserve evidence

Keep enough of the prompt/tool/source/review trail to explain what KBD delivered without creating unnecessary retention risk.

Recommended next steps

A practical first pass for KBD over the next 90 days.

Name an AI ownerGive one person responsibility for the inventory, policy, and escalation path.
Inventory current workStart with chatbots, agents, synthetic media, personalization, and client decision systems.
Approve toolsSet rules for client data, model training, enterprise accounts, retention, and source-file uploads.
Create reusable UI patternsBuild accessible chatbot, agent, deepfake, and AI-content disclosure components.
Add an intake questionAsk whether the project touches hiring, credit, education, benefits, biometrics, or other consequential decisions.
Update proposals and SOWsAssign roles and responsibilities before a client-facing AI feature is built.
Create an asset recordTrack tools, sources, permissions, labels, reviewers, and approvals for synthetic content.
Train the teamDesigners, developers, strategists, and account leads should recognize the escalation triggers.

Important qualification

This is a practical business briefing, not legal advice. Whether KBD is a provider, deployer, downstream provider, or merely a service contractor depends on the facts of a particular project. Employment, credit, education, healthcare, biometric, public-interest, and client-regulated-product work should receive project-specific legal review.

← Return to the general EU AI Act explainer