# Do You Have to Disclose AI Recording? The 2026 Rules

> EU AI Act transparency rules took effect 2 August 2026, and consent laws still apply. Here's when you must disclose AI recording, and how to do it.
- **Author**: Sami AZ
- **Published**: 2026-09-07
- **URL**: https://klu.so/blog/ai-recording-disclosure-rules-2026

---

In most cases, yes, and 2026 tightened it. Two separate sets of rules apply. First, recording-consent law: many US states and many countries require the consent of every participant before a conversation is recorded, including California, Florida, Illinois, Maryland, and Pennsylvania. Second, AI transparency law: the EU AI Act's Article 50 obligations became enforceable on 2 August 2026, requiring people to be told when they are interacting with an AI system and requiring certain AI-generated content to be marked, with fines up to EUR 15 million or 3% of worldwide annual turnover. The practical takeaway is to say plainly, at the start, that you are recording and that AI will transcribe and summarize it, and to get agreement. Recording only your own voice afterward, which is what a personal app like Flint is for, avoids the participant-consent question altogether. This is general information, not legal advice.

For a few years, AI notetakers spread through professional life faster than anyone's policies. That grace period is over. In 2026 the rules became specific and enforceable, and "the bot just joins automatically" stopped being a defensible default.

Two Different Rules People Confuse

Most of the confusion in this area comes from treating one question as if it were two, or the reverse. There are genuinely two separate obligations, and you can satisfy one while breaching the other.

Recording consent is about capturing a conversation at all. It is long-standing law, it varies by jurisdiction, and in many places it requires permission from everyone in the conversation, not just you. This applies whether the recorder is a tape deck or an AI notetaker.

AI transparency is newer. It is about telling people that AI is involved, and marking content that AI generated. This is what changed in August 2026 in the EU, and it applies on top of consent law rather than instead of it.

What Changed on 2 August 2026

The transparency obligations in Article 50 of the EU AI Act, Regulation (EU) 2024/1689, began to apply on 2 August 2026, and the European Commission's AI Office and national authorities began enforcing the Act on the same date. The Commission adopted guidelines on these obligations on 20 July 2026.

Broadly, Article 50 requires organisations to disclose when people are interacting with an AI system, to disclose when emotion-recognition or biometric-categorisation systems are used on them, and to ensure certain AI-generated or manipulated content is identifiable. Chatbots have to identify themselves as automated. Deepfakes need labelling. Machine-generated or edited content must carry machine-readable marks so it can be detected automatically. Non-compliance can trigger fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher.

A few important details. These obligations are not limited to systems classified as high risk; they apply to any AI system used in the four situations Article 50 covers, which makes them relevant to a very large number of ordinary businesses. The Act applies globally to providers, deployers, importers, and distributors placing AI on the EU market or whose AI outputs are used in the EU, so a company outside Europe can still be in scope. And the obligations split between providers, who build and place systems on the market, and deployers, who use a system under their own authority, which for most readers means you are a deployer.

One timing nuance worth knowing: the provider-side machine-readable marking obligation under Article 50(2) has a four-month transition for generative systems already on the EEA market before 2 August 2026, giving those providers until 2 December 2026. The bulk of Article 50 is already live. There is also a voluntary Code of Practice on Transparency of AI-Generated Content, published by the AI Office, which signatories can use to demonstrate compliance and which includes a set of labelling icons; signing brings a degree of presumption of conformity and a more favourable enforcement posture.

Also note the guidelines carve out the obvious: disclosure is not required where interaction with an AI system is sufficiently obvious, though whether that applies is highly context-specific and depends on the expectations of the people involved. That is not a licence to stay quiet about a recording.

Recording Consent Has Not Gone Anywhere

None of the above replaces consent law, which is often the more immediate risk for someone using a notetaker in a meeting.

Several jurisdictions require participant consent before a conversation is recorded, including California, Florida, Illinois, Maryland, and Pennsylvania, with rules differing elsewhere and getting more complicated on cross-border calls where participants sit in different jurisdictions. Automatic recording by an AI notetaker can create exposure before anyone has thought to ask, which is precisely the failure mode: the tool joins, it records, and nobody said anything.

There is a related biometric dimension. A voice recording contains a voiceprint, and in Illinois voiceprints are biometric identifiers under the state's Biometric Information Privacy Act, which requires notice and informed consent before collection along with a retention and destruction policy. Privacy advocates have raised concerns that some AI notetakers generate voiceprints without meaningful consent from the people in the room.

What Good Disclosure Actually Sounds Like

The practical version of all this is short, and doing it well takes about eight seconds at the start of a conversation.

Say that you are recording, say that an AI tool will transcribe and summarize it, say roughly what happens to the recording afterward, and ask if everyone is comfortable. Then wait for an answer rather than treating silence as agreement. If someone objects, take notes by hand or dictate your own summary afterward instead.

For recurring or professional relationships, put it in writing once rather than negotiating it every time. Many practitioners now address recording and AI use directly in engagement letters, contracts, or onboarding documents, so the position is documented rather than assumed. If you publish AI-generated content in contexts the rules cover, that is a separate labelling question, and the Code of Practice icons exist for it.

Two things to avoid. Do not rely on a notetaker's own "Notetaker has joined" banner as your disclosure, since it announces a participant, not what happens to the data. And do not assume a vendor's privacy policy satisfies your obligations; you are typically the deployer, and the duty sits with you.

The Quieter Reason to Think About This

There is a practical cost to recording that has nothing to do with regulators. People say less when a permanent AI-generated transcript is being produced, and the thing they leave out is often the thing you most needed to hear. In client work, hiring, performance conversations, and anything sensitive, the candour you lose can be worth more than the notes you gain. That is worth weighing before you default to recording everything.

Where a Personal Voice App Fits

There is a simpler pattern that avoids most of this, and it is what a personal voice notes app is actually for.

Instead of recording the conversation, be present in it, then dictate your own note immediately afterward. You are recording only your own voice, so participant-consent rules are not engaged, and you are creating your own summary rather than a verbatim third-party artefact of someone else's words. It is the same thing people have always done with a dictaphone, and it captures what mattered better than a transcript does.

Flint is built for exactly that. Capture is one press, and on iPhone you can start from the Action Button or Lock Screen widget, so a note takes seconds while the detail is fresh. Flint turns it into a clean structured note rather than a raw transcript, keeps everything searchable so you can ask across your notes later, and is a personal note taker rather than a meeting bot, so nothing joins a call or announces itself to anyone. It is local-first, so your notes stay on your device rather than in a vendor's archive, and it is a one-time $12.

To be clear about limits, since this is a compliance topic: Flint is a consumer app, not a compliance product. It does not provide consent logging, audit trails, DPAs, or any certification, and it makes no claim to satisfy the AI Act, BIPA, or any consent statute on your behalf. It is local-first rather than fully offline, meaning some AI processing happens in the cloud, so assess it as a vendor under your own rules. If you record other people with any tool, the disclosure duty is yours. If you work in a regulated profession, the ethics layer sits on top of all of this, which we cover in what lawyers should check before using an AI notetaker.

Flint is available on the App Store and on Google Play.

Frequently Asked Questions

Do I legally have to tell people I am recording? In many jurisdictions yes, and several require consent from every participant, including California, Florida, Illinois, Maryland, and Pennsylvania. Rules differ elsewhere and get more complex when participants are in different jurisdictions, so check the position that applies to you.

Do I have to disclose that AI is being used, not just that I am recording? Under the EU AI Act's Article 50 obligations, applicable from 2 August 2026, people must be told when they are interacting with an AI system in the situations the Article covers, and certain AI-generated content must be identifiable. That sits alongside, not instead of, recording-consent law.

What are the penalties for getting AI transparency wrong? Non-compliance with the transparency obligations can attract fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, with proportionality taken into account for smaller companies. Enforcement is by national market surveillance authorities and the AI Office.

Does the EU AI Act apply to companies outside Europe? It can. The Act applies to providers, deployers, importers, and distributors that place AI systems on the EU market or whose AI outputs are used within the EU, so being based elsewhere does not automatically put you outside its scope.

Is a "Notetaker has joined" banner enough disclosure? Treat it as insufficient on its own. It signals that a participant joined, not that a conversation is being recorded, transcribed, and stored, nor what happens to the data afterward. Say it out loud and get agreement.

How do I avoid the consent problem entirely? Do not record the conversation. Be present, then dictate your own note straight afterward. You are recording only your own voice, so participant-consent rules are not engaged, and you still get an accurate contemporaneous record.

The simplest way to stay clear of recording and AI disclosure problems is not to record other people at all. Be in the room, then capture your own note the moment it ends. Flint makes that one press, keeps it on your device, and costs $12 once. Download Flint on the App Store or Google Play.

This article is general information, not legal advice. The EU AI Act, its guidelines and codes of practice, and recording-consent and biometric statutes vary by jurisdiction and continue to develop, including phased implementation dates. Verify the current position and your own obligations before relying on any of it.
---
- [All articles](https://klu.so/blog)