Skip to content
Daily AI Intel

AI Ethics & Society · AI Transparency and Explainability

Are AI companies required to disclose how their models work?

Disclosure requirements for AI companies vary significantly by jurisdiction and use case — some regions, like the European Union, have introduced specific transparency and documentation obligations for certain AI systems, while in many other places disclosure remains largely voluntary or limited to narrow, high-risk applications rather than a general legal requirement.

Key takeaways

  • No single global law requires AI companies to fully disclose how their models work in all cases.
  • Some jurisdictions, including the European Union, have introduced binding transparency obligations for certain categories of AI systems, particularly higher-risk applications.
  • Many disclosure practices, such as publishing model cards or safety reports, remain voluntary rather than legally mandated in much of the world.
  • Disclosure requirements often distinguish between general information about a system and proprietary technical details companies are not required to reveal.
  • This is a rapidly evolving regulatory area, and requirements applicable to a given company can change as new laws take effect.

No Universal Requirement, but a Growing Patchwork

Whether an AI company is legally required to disclose how its models work depends heavily on where it operates, what kind of AI system it’s deploying, and what specific use case is involved. There is no single global law mandating comprehensive disclosure of AI model internals. Instead, what exists is a growing but uneven patchwork of regulations, voluntary industry practices, and sector-specific rules that together shape how much companies actually reveal about their systems.

This patchwork reflects the fact that AI regulation is still a relatively young and fast-developing area of law and policy in most parts of the world, with different governments taking notably different regulatory approaches.

How Regulatory Approaches Differ

Some jurisdictions have moved further than others in establishing binding transparency obligations. The European Union’s regulatory framework for AI, for example, takes a risk-tiered approach, imposing more significant documentation, transparency, and disclosure requirements on AI systems classified as higher risk, while applying lighter requirements to lower-risk applications. Even under such frameworks, though, required disclosures generally focus on things like a system’s intended purpose, risk assessments, and certain operational information, rather than requiring companies to reveal proprietary technical details such as full training data, model weights, or exact algorithms.

In many other jurisdictions, comprehensive AI-specific disclosure laws are still being developed or don’t yet exist in comprehensive form, meaning companies operating in those regions may face few binding legal requirements to disclose model details, beyond general obligations that might apply under existing consumer protection, product safety, or sector-specific laws (such as rules governing financial services or healthcare).

Voluntary Disclosure Fills Some of the Gap

In the absence of universal legal mandates, many AI companies have adopted voluntary disclosure practices, at least to some degree. These often take the form of published documents such as model cards or system cards, which describe a model’s intended uses, known limitations, and safety testing, as well as broader research papers or safety reports. The scope, consistency, and rigor of these voluntary disclosures vary considerably from company to company, and critics have noted that voluntary transparency can be inconsistent or selectively favorable to the company’s public image, since there’s no external enforcement mechanism requiring completeness or accuracy in the way binding regulation would provide.

Bottom Line

AI companies are not universally required to disclose how their models work — some jurisdictions, notably the European Union, have introduced binding transparency requirements for certain categories of AI systems, but in much of the world, disclosure remains a mix of narrower legal obligations and voluntary industry practice, and the overall regulatory landscape continues to evolve.

Go deeper

Frequently asked questions

Does the EU AI Act require companies to disclose their model's inner workings?

The EU AI Act introduces tiered obligations based on a system's assessed risk level, including documentation and transparency requirements for certain AI systems, particularly higher-risk ones. It does not generally require companies to disclose full proprietary technical details such as exact training methods or complete source code.

Do AI companies voluntarily publish any information about how their models work?

Yes, many companies publish some level of voluntary disclosure, such as model cards, system cards, or safety and research reports describing a model's capabilities, limitations, and intended uses, though the depth and consistency of these disclosures vary considerably across companies.

Why might a company be reluctant to fully disclose how its AI model works?

Companies often cite competitive concerns, since detailed technical disclosures could reveal trade secrets to competitors, as well as potential security risks, since detailed disclosure could make it easier for bad actors to exploit or misuse a system.

Sources

  1. [1]OECD.AI Policy Observatory — OECD
  2. [2]National Institute of Standards and Technology — National Institute of Standards and Technology
ET

Written by Editorial Team

Last updated July 25, 2026

Get one well-sourced answer a week

No spam. Unsubscribe anytime.