All research articles

Generative AI

AI content labeling: who must comply with EU AI Act Article 50, and which exemptions apply

Article 50 for decision-makers: the four sets of obligations, the exemptions, the deadlines, and an implementation that survives everyday operations

AI content labeling illustrated: a wall of screens showing AI-generated images, each carrying a glowing AI label, a hand attaching one more label to a screen, a visible AI Generated mark in the bottom right corner

Labeling AI-generated content has been a legal obligation in the EU since 2 August 2026. Article 50 of Regulation (EU) 2024/1689, better known as the AI Act, requires that people learn when they are dealing with AI: in a chat, in a generated image, in a deepfake, in machine-written text. The idea is simple. Applying it is not, because the obligations attach to different roles, and individual cases are decided more often by the exemptions than by the basic rule.

This article sorts out the legal situation for decision-makers who are not lawyers: who AI content labeling actually applies to, which exemptions exist, which deadlines and fines are on the table, and what a workable implementation looks like.

What applies since 2 August 2026

Article 50 bundles four sets of obligations with different addressees.

The first concerns conversation. Whoever provides an AI system that interacts directly with people must design it so that the person learns they are communicating with an AI (paragraph 1). This is the chatbot rule.

The second concerns generation. Providers of generative systems producing audio, images, video or text must mark the outputs in a machine-readable format as artificially generated or manipulated; the solutions used must be effective, interoperable, robust and reliable (paragraph 2). No reader ever sees this layer; it is meant for machines.

The third concerns special systems. Deployers of emotion recognition or biometric categorisation systems, that is, systems sorting people into categories on the basis of their biometric data, must inform the persons affected (paragraph 3).

The fourth concerns publication. Deployers must disclose deepfakes, and they must disclose AI-generated text that is published to inform the public on matters of public interest (paragraph 4). This is where deepfake disclosure lives, a part much talked about.

Across all of this runs paragraph 5: the information must be clearly recognizable, at the latest at the first interaction or exposure, and it must meet accessibility requirements.

Who the obligations fall on

The AI Act distributes its duties along two roles. Simplified: the provider develops an AI system or places it on the market; the deployer uses it under its own responsibility. For labeling this means: the machine-readable marking (paragraph 2) and the chatbot transparency (paragraph 1) are provider obligations. The disclosure of deepfakes and of public-interest AI text (paragraph 4) and the information duty for emotion recognition (paragraph 3) sit with deployers.

For a mid-sized company the picture is clearer than the debate suggests. A company using AI images in its marketing acts as a deployer. The visible disclosure duty of paragraph 4 attaches to deepfakes and to published AI text on matters of public interest, not to every generated image. A company running a chatbot on its website uses a system whose design duty under paragraph 1 sits with the provider; in practice that is settled at purchase: check before embedding whether the provider delivers the transparency, because a violation becomes visible exactly where your own customer talks to the bot.

Breaches of Article 50 can hit providers and deployers alike. For small and medium-sized enterprises, including start-ups, a separate ceiling applies: of the two amounts in the fine framework, the lower one is their cap (Article 99(6)). The framework itself follows in the section on deadlines and sanctions.

The exemptions

The basic rules would be quickly told if the exemptions did not decide everyday cases. Five matter in practice.

Obviousness: the information duty of paragraph 1 lapses when it is obvious from the point of view of an informed person that they are interacting with an AI.

Assistive editing: the marking duty of paragraph 2 does not cover functions that merely assist with editing without substantially altering the input data. Where exactly assistance ends and substantial alteration begins is a question of the individual case.

Art and satire: for artistic, creative or satirical works, the deepfake disclosure is reduced to a notice that a manipulation exists. The work does not have to be placarded; the notice of its existence suffices.

Editorially accountable text: AI text on matters of public interest need not be disclosed if it has undergone human editorial review and a person carries editorial responsibility for it. For companies doing content marketing this is the exemption that matters most: reviewed text with a named person behind it stays free of the disclosure duty of paragraph 4; unreviewed output does not.

Law enforcement: uses authorized by law for law enforcement purposes are exempt from paragraphs 1 and 2. Irrelevant for most companies, listed for completeness.

Deadlines and sanctions

The principle is unambiguous: the transparency obligations apply since 2 August 2026 (Article 113). A grace period exists, but it is narrower than it is often presented. It covers only the marking duty of paragraph 2, and only generative systems placed on the market before 2 August 2026. For those legacy systems the marking duty starts on 2 December 2026. Everything else applies without transition: the chatbot transparency, the deployer duties for deepfakes and texts, and the marking duty for every system newly placed on the market since the cut-off date.

The grace period comes from the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 27 July 2026, six days before the Article 50 start date. That act postponed the high-risk deadlines (Annex III to 2 December 2027, Annex I to 2 August 2028) and left the start of the transparency obligations untouched. Whoever hoped the omnibus would also move the labeling rules hoped in vain; the four-month legacy window for paragraph 2 is all it changed here. The Commission explains the transition details in its FAQ on the Article 50 transparency obligations.

There is no retroactivity: content generated before 2 August 2026 does not have to be labeled after the fact; the Commission encourages voluntary labeling.

Violations of Article 50 by providers or deployers carry fines of up to 15,000,000 euros or 3 percent of total worldwide annual turnover, whichever amount is higher (Article 99(4)(g)). For SMEs, including start-ups, the lower of the two amounts is the cap.

This article is an editorial summary, not legal advice.

A workable implementation

The machine-readable marking is a provider obligation. For companies that buy generative systems rather than build them, the question moves into procurement: does the system mark its outputs in machine-readable form, and does the marking survive your own processing chain? For orientation, the Commission has issued guidelines on the transparency of AI-generated content and promotes a voluntary Code of Practice; signatories can use it to demonstrate compliance. The guidelines flesh out, among other things, when the AI nature of an interaction counts as obvious and where human editorial review ends and merely superficial checking begins.

For deployers, workable mostly means processes: where in the company could deepfakes or public-interest AI texts arise, who decides on their disclosure, and who carries editorial responsibility for published AI text, by name?

No reader sees the machine-readable marking. What readers see is the visible label, and it pays off even where it is not prescribed: as disclosure on your own initiative, before someone else does it for you.

If you want to label your own AI images visibly: label AI images for free in your browser.

The images are not uploaded; the processing runs locally in the browser. One classification belongs next to it: the tool sets visible labels. It does not fulfill the machine-readable marking duty of paragraph 2, and no watermark on its own establishes legal compliance; the visible label is the part of transparency people perceive, while the machine-readable layer remains the systems' job.

Labeling in the bigger picture

The labeling obligation is the legislator's answer to a flood this series has already measured: AI slop, the mass publication of unreviewed AI content. The legal rules and the quality debate converge on the same principle. The AI Act demands a recognizable origin for the artificial; the quality debate demands a person who stands behind the content. The editorial exemption of paragraph 4 makes that explicit: reviewed, accountable text is treated differently from unreviewed output. The law thereby rewards curation, exactly the review routine whose absence clutters the web and makes GenAI pilots fail inside companies.

A label does not replace curation. "AI-generated" says where content comes from, not whether it is right. But it is the precondition for readers and machines to tell reviewed content apart from the stream of the unreviewed.

Reading list

  1. Regulation (EU) 2024/1689, EUR-Lex - the regulation itself; the transparency obligations sit in Article 50.
  2. European Commission, FAQ on the transparency obligations under Article 50 - transition periods, guidelines and the voluntary Code of Practice.
  3. AI Act Explorer, Article 50 - the article in full text with context.
  4. AI Act Explorer, Article 99 - the fine framework including the SME rule.

Related articles

About the author

Guido Winger works at myBytes on making published claims stand up to scrutiny. More on how we work: AI consulting for SMEs.