News
EU transparency rules raise AI compliance demands on NGOs
European regulators have tightened the practical expectations around generative AI at the moment the bloc’s transparency rules take effect. The European Commission’s guidance published on 20 July says providers and deployers must help people recognise AI interactions and identify certain AI-generated or manipulated content.
The GDPR remains the first gate for sensitive NGO data
The EDPB’s 8 July guidance says the GDPR applies to web scraping whenever personal data is collected, stored, organised or retrieved. That matters beyond organisations building foundation models. An NGO assembling a searchable knowledge base, summarising case notes, translating testimony or analysing public communications may still be processing personal data if individuals can be identified directly or indirectly.
The Board says organisations should pay close attention to purpose limitation, transparency, accuracy and data minimisation. It recommends using reliable sources, recording timestamps and validating information before it is used in AI training. Where special-category data—such as health, biometric, political or religious information—is involved, organisations need both a lawful basis under Article 6 and an applicable exception under Article 9.
Anonymisation now requires a context-specific judgment
The EDPB’s accompanying anonymisation guidance rejects the idea that data is simply anonymous in the abstract. Whether information relates to an identifiable person can depend on the entity assessing it, the means reasonably likely to be used and the purpose or effect of the processing.
The framework tests whether there is record isolation, linkage or inference. If any of those risks remain, an organisation must conduct further analysis rather than assume that removing names is sufficient. For NGOs, the practical consequence is significant: beneficiary records, hotline transcripts, safeguarding reports and narrative monitoring data can retain identifying value even after obvious identifiers have been removed.
AI Act transparency duties are now moving into daily workflows
From 2 August, the AI Act’s Article 50 requirements apply to certain interactive and generative systems. Providers must design systems to tell people when they are interacting with AI and mark outputs in machine-readable form where technically feasible. Deployers must disclose deepfakes and certain AI-generated text published to inform the public on matters of public interest when there has been no human review or editorial control.
That creates a direct operational question for NGOs publishing reports, campaign material, emergency updates and public-facing translations. A human review process may affect whether a disclosure duty applies in a particular case, but it does not replace wider obligations around accuracy, confidentiality, security and lawful processing under the GDPR.
The regulatory timetable is clearer but not simpler
The AI Omnibus entered into force on 27 July and delayed the application of many high-risk rules to 2 December 2027, with rules for high-risk AI embedded in physical products moving to 2 August 2028. The Commission said the extension would allow more time for standards and national oversight arrangements.
For most NGOs, the delay is breathing room rather than a compliance holiday. The organisation’s role, the purpose of the system and the type of data involved still determine its obligations. Boards and senior teams will need inventories of AI use, documented data flows, supplier assurances, retention rules, disclosure practices and escalation routes for errors or rights complaints. The EDPB’s web-scraping guidance remains open for consultation until 30 October, leaving room for civil-society organisations to shape how the rules are interpreted in practice.

