How Communicators Can Lead on AI Transparency
By Lorra M. Brown
October 2026
For the past year, my research partner, Peter Duda, managing director and head of crisis at H/Advisors, and I have been developing an AI Reputational Governance framework that examines AI’s reputational risks.
It draws on confidential interviews with C-suite communication and public affairs executives, our AI Reputation Governance Survey of senior PR and marketing professionals (fielded May-September 2026), analysis of AI-related incidents, and ongoing regulatory tracking.
We’ll share our full findings at PRSA ICON 2026 in Orlando, Fla., on Oct. 20. One area of our research examines how the world’s largest economies are approaching AI transparency, and what those differences mean for communicators operating globally. The discrepancy is significant.
The European Union’s AI Act transparency requirements took effect Aug. 2, requiring certain AI systems to disclose when people are interacting directly with AI and requiring generative AI providers to mark AI-generated or manipulated content in machine-readable form, with added labeling requirements for deepfakes and certain AI-generated text on matters of public interest.
California’s AI Transparency Act also began Aug. 2, deliberately aligned with the EU’s timeline. It requires covered providers of large, publicly accessible generative AI systems to offer detection capabilities for AI-generated content.
China has required AI-generated content labeling since September 2025. South Korea’s AI Basic Act took effect in January 2026 with its own transparency requirements for generative AI. Japan takes a softer approach, asking companies to “cooperate,” while Singapore skipped legislation altogether in favor of voluntary frameworks.
U.S. policy is just as inconsistent: Lawmakers in 45 states have introduced bills, and at least 27 states have enacted 85 new AI-related laws as of press time.
Overwhelmed yet? Me too. And for communicators running global campaigns or advising multinational clients, this means “we’re compliant” depends on where you are, which law applies, and how your organization uses or deploys AI.
Here are five ways communicators can navigate global compliance messaging and lead board-level strategic counsel.
1. Flag the provider-deployer distinction
The EU AI Act distinguishes between the company that provides an AI system and the organization that deploys it. This means a company using a third-party AI system in a customer-facing application may still have deployer obligations, even though another company built the technology.
The European Commission makes clear that an organization can remain the “deployer” even when contractors or third parties operate the system on its behalf, under its responsibility and control. Boards often overlook these essential distinctions.
This isn’t a knowledge gap unique to this provision: in our survey, board AI governance literacy ranked lowest of the four literacy domains we measured, trailing general AI awareness, risk literacy, and reputation literacy.
It also reminds us of a misconception emerging in our research. One CCO at a technology company pointed to the false sense of security organizations have about vendor-built AI, noting that leaders often “believe the risks sit with their vendors, and that they can protect themselves through legal contracts.” This does not eliminate an organization’s own responsibilities or vulnerability.
Before launching a global campaign, communicators should ask legal and compliance: What role does the organization play under the law in each market? The answer determines who owns the disclosure and governance obligation and preempts issues before they affect reputation.
2. Skip the one-size-fits-all disclosure
A single global disclosure template can overcomply in one market and be non-compliant in another. The EU, China and California each define adequate disclosure differently, as outlined above, and a boilerplate label won’t work. A market-by-market transparency guide, built by communications alongside legal and compliance, is more useful than a universal template.
Most organizations don’t have that guide yet. In our survey, only 18% said their organization has a proactive external AI compliance communication strategy, 26% have none, and 24% only communicate reactively.
Translating legal requirements into disclosure language stakeholders understand is an essential communications-led initiative.
3. Set the governance cadence, not just a compliance calendar
AI regulation moves fast. That speed is where communicators can add strategic value legal alone can’t provide. A C-suite respondent in our research put the underlying problem plainly: Leaders “think about legal compliance and cyber security,” but “the technology is moving far too fast for governance to keep up.”
California’s operative date has already moved once, and the EU has staggered implementation across distinct categories of AI systems. “We checked, and we’re compliant” is a snapshot, not a governance strategy; a check from six months ago is already stale by the next launch.
Building a regulatory review into the launch calendar itself, not an annual audit, catches problems while they’re still fixable, not after they’ve become a headline.
4. Map the law, then own the tracking
“Europe” and “Asia” aren’t useful categories for AI compliance planning. The jurisdictions above span a wide range, from the EU’s comprehensive, risk-based framework to Singapore’s voluntary governance tools, often with little in common beyond the word “AI.” Don’t make assumptions. Instead, work with legal and compliance to map obligations to the specific use case instead.
That mapping only holds up if someone owns it, and almost no one does. Our research found that only 24% of senior communication and reputation professionals surveyed said their organization has a dedicated function tracking evolving AI regulation.
Most rely on legal counsel’s periodic briefings, which work for a single authority but break down across four or five regulatory markets, each with different definitions, deadlines and obligations. Shared governance workflows position your organization ahead of those constantly playing catch-up.
5. Separate the disclosure from the narrative
Meeting a market’s disclosure requirement and earning stakeholder trust in it are two different jobs and treating them as one is where efforts fall short. Communication professionals should work with legal and compliance to determine what’s legally required, then build the plain-language narrative.
One health-care-sector director in our research put the stakes plainly: “Many view AI risk primarily as a technology, legal or cybersecurity issue rather than a trust issue. Reputational damage can stem from how AI decisions are communicated and experienced by employees, customers and investors.”
Legal compliance and stakeholder trust do not always align. Helping audiences understand your organization’s position and AI use turns legal compliance into earned trust.
Readiness on a global scale
Regulatory Communication Readiness is one of the dimensions I’m examining through our AI Reputational Governance project. In our survey, it ranked as a mid-tier exposure area among senior practitioners, even domestically.
Multiply that challenge across disparate global regulatory regimes, each with different definitions of AI, transparency requirements and implementation dates, and the governance gap compounds quickly. We see the same pattern emerging with AI regulation that we see inside organizations: Adoption and building are moving faster than governance.
AI transparency can’t be treated as a series of disconnected legal disclosures; it must become a shared governance function, with communications helping connect the technical requirement to the human experience.
By the time this article is published, there will most certainly be more regulatory changes and AI developments. That’s the challenge and the opportunity for communicators: to guide C-suite leaders and boards to lead through these changes, not just react to them.
The AI Reputational Governance framework we’re developing is designed to help communicators lead in that moving landscape by connecting regulatory readiness to the larger questions of reputation, organizational risk and stakeholder trust.
