The EU AI Act does not require a label on every AI-assisted asset. It creates specific marking and disclosure duties for specific providers, deployers and content.
Article 50 contains four operational groups of transparency duties: human interaction with AI, machine-readable marking of synthetic content, notice for emotion-recognition or biometric-categorisation systems, and disclosure by deployers of deepfakes and certain public-interest text. The European Commission’s July 2026 guidelines confirm these obligations apply from 2 August 2026.
That is broader than AI products, but narrower than “label everything made with AI.”
The useful question is not whether an AI tool touched the file. It is which Article 50 role, content type and publication context applies.
First identify your role
Regulation (EU) 2024/1689, the AI Act, distinguishes providers from deployers.
A provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market under its own name or trademark. A deployer uses an AI system under its authority, except for personal non-professional use.
A marketing team using a third-party image generator will usually examine deployer obligations. A company offering its own generative system must also examine provider obligations. A white-label arrangement can change the analysis.
Record the system and model, supplier, who offers it under which name, intended purpose, who operates it, output types, publication context and target market. Do not assign responsibility from the software invoice alone.
Provider marking and deployer disclosure are different
Article 50(2) requires providers of AI systems that generate synthetic audio, image, video or text to ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The methods must be effective, interoperable, robust and reliable as far as technically feasible.
This is a provider-side technical obligation. It is not the same as a visible caption written by the brand publishing an asset.
Article 50(4) creates deployer-side disclosure duties for image, audio or video content constituting a deepfake, and for AI-generated or manipulated text published to inform the public on matters of public interest.
The second category has an exception where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility. The deepfake duty has tailored treatment for evidently artistic, creative, satirical or fictional work, where disclosure must be appropriate and must not hamper display or enjoyment.
Machine-readable provenance and a human-facing disclosure solve different problems. A mature workflow decides when it needs one, the other or both.
The amendment that actually changed the timing
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026 and amends the AI Act. It defers the high-risk obligations under Article 6(2) and Annex III to 2 December 2027, and those under Article 6(1) and Annex I to 2 August 2028.
For Article 50 it introduces a four-month transitional period for machine-readable marking, so providers who placed generative systems on the market before 2 August 2026 are not forced into immediate disruption.
That transitional period is easy to over-read. It softens the marking timetable for pre-existing systems. It does not postpone the deployer disclosure duties, and it does not create a general grace period for publishing undisclosed deepfakes.
One practical warning, learned while preparing this piece. An EU document number is not self-explanatory. The same number can exist in both the L series, which carries legislation, and the C series, which carries notices. Verify the document type, title and CELEX record before you change a compliance date on the strength of a number.
A generated product scene is not automatically a deepfake
The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content resembling existing persons, objects, places, entities or events that would falsely appear authentic or truthful.
A clearly stylised abstract image is not automatically a deepfake merely because it is generated. A fabricated photograph of a real executive endorsing a product is a much clearer risk. A synthetic product demonstration could mislead under consumer law even if it falls outside the deepfake definition.
Ask whether the content resembles something real, whether a reasonable viewer would read it as authentic, whether the context signals fiction, whether it makes a product or endorsement claim, and whether the use is artistic or satirical.
Article 50 is not the only rule. Advertising, unfair-commercial-practice, intellectual-property, data-protection and personality-rights analysis may still apply.
Public-interest text is not every caption
The text disclosure duty concerns AI-generated or manipulated text published to inform the public on matters of public interest. That can reach corporate publishing, public-affairs content, news-like explainers and issue communications. It does not turn every product description or social caption into public-interest text.
The human-review and editorial-responsibility exception is operationally important. A person changing two words is not a credible editorial process merely because the file now has a human save event.
Build a review record: source material, factual claims checked, reviewer, substantive changes, approval, accountable publisher, publication version.
The Commission’s Article 50 code of practice is voluntary, while the underlying legal duties are not. The code separates provider marking from deployer labelling, which is a useful structure even for organisations that do not sign it.
AI interaction needs notice unless it is obvious
Article 50(1) requires providers of AI systems intended to interact directly with natural persons to design them so people are informed they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect person.
For a customer-facing assistant, review first-contact notice, persistent identity, handoff to a person, limitations, conversation storage, and the error and complaint route.
Calling the system “Mia” with a portrait and no explanation makes the interaction less obvious, not more. A tiny footer disclaimer after the first exchange is not a strong design.
The information must be provided clearly and distinguishably at the latest at the time of first interaction, and must conform to applicable accessibility requirements.
C2PA can carry provenance, not legal certainty
The C2PA technical specification defines a system of signed manifests associating an asset with provenance assertions and actions. Content Credentials can record origin and edits in a machine-verifiable chain.
That makes C2PA relevant to provider marking and downstream asset handling. It does not answer every legal question. Credentials can be removed by unsupported platforms. Screenshots and re-encoding break the chain. A signed manifest records assertions, not the truth of every depicted claim. A missing credential does not prove human origin. Visible disclosure may still be required.
Build a disclosure matrix before publishing
| Output | Role | Article 50 trigger | Machine mark | Visible disclosure |
|---|---|---|---|---|
| Customer chatbot | provider or deployer | direct interaction | system-dependent | first interaction |
| Generated product image | deployer | deepfake assessment | preserve if present | context-dependent |
| Synthetic spokesperson video | deployer | likely deepfake | preserve | yes, appropriate |
| Public-interest article | deployer | Article 50(4) text | preserve if present | unless review exception applies |
| Internal concept board | deployer | not publicly exposed | preserve internally | generally none |
Add consumer-claim, rights and privacy checks beside the AI Act analysis. The matrix is a routing device, not legal advice.
Preserve evidence through the production chain
An exported file usually moves through generation, retouching, layout, compression, content management, social upload and platform transformation. Test whether machine-readable information survives each step.
Keep the original output, the prompt or instruction record where appropriate, model and version, generation date, editor, source assets, review and final export. This is the production log described in turning a creative brief into a controlled generation system.
Do not publish sensitive prompts or personal data merely to prove provenance. Evidence retention and public disclosure are separate decisions.
How we handle this
Origin defines disclosure language and placement so it is clear without overwhelming the work. Scale checks how platforms preserve, remove or supplement provenance when content becomes an ad.
We map the provider, deployer, reviewer and escalation roles before an AI workflow reaches publication. That is the same operating principle as the AI operating model: ownership and evidence come before autonomy.
Tell us the system, output type, market and publication context. Those inputs determine the review path. The fact that AI was used does not determine the legal answer by itself.
Sources
EUR-Lex, Regulation (EU) 2024/1689, the AI Act.
EUR-Lex, Regulation (EU) 2026/1744, Digital Omnibus on AI.
European Commission, final Article 50 transparency guidelines.
European Commission, Code of Practice on Transparency of AI-Generated Content.
C2PA technical specification 2.4.
Sources and EU-level status checked 30 July 2026. Role, scope, exceptions and disclosure form require use-specific legal review.