EU AI Act AI-Generated Content Labelling Rules: Business Compliance Before 2 August 2026

A practical guide to EU AI Act content labelling: Article 50 triggers, legacy-system timing, provider and deployer duties, and a business compliance workflow.

EU AI Act AI-Generated Content Labelling Rules: Business Compliance Before 2 August 2026
Table of contents

EU AI Act AI-Generated Content Labelling Rules: Business Compliance Before 2 August 2026

The EU AI Act AI-generated content labelling rules move from policy planning to operational compliance on 2 August 2026. For founders, publishers, product owners, and marketing teams, the practical task is not to stamp a warning on every sentence touched by software. It is to identify the relevant role, content type, technical marking duty, and visible disclosure duty, then preserve evidence that the control worked.

Last updated: June 2026

The European Commission published the final Code of Practice on marking and labelling AI-generated content on 10 June 2026. Joining that Code is voluntary. Article 50 of the AI Act is law, and its transparency obligations are mandatory where they apply. This guide separates those two layers and turns them into an implementation workflow. It provides general information—not legal advice; obtain advice on your products, jurisdictions, and facts.

Official European Commission visual for the AI-generated content labelling code

Source: European Commission

Article 50 establishes binding transparency duties for specified providers and deployers of AI systems. The Code of Practice is a voluntary compliance aid: signatories can use its common specifications, labels, and governance measures to demonstrate a structured approach. A company may decline to sign the Code and still must satisfy applicable law.

This distinction matters in board papers and vendor contracts. A practical reading of the EU AI Act AI-generated content labelling rules starts with the binding text, not Code membership. “We did not sign the Code” is not an exemption from Article 50. Conversely, “we signed the Code” should not be treated as proof that every product, publication, and deployment is compliant.

The Commission’s final Code arrived before the 2 August 2026 application date. It gives providers, deployers, and downstream publishers a common language for machine-readable marking and human-facing labels. It also reduces the risk that every platform invents a visually incompatible warning.

The legal analysis begins with four questions:

  1. Is the system or deployment within the AI Act’s territorial and material scope?
  2. Is the business acting as a provider, deployer, publisher with editorial responsibility, or more than one of these?
  3. Does the output or interaction fall into an Article 50 category?
  4. Is an exception relevant, such as standard editing that does not substantially alter the input, or qualifying human review and editorial responsibility for public-interest text?

Those questions are more useful than a universal “AI used” checkbox. For a broader view of how companies combine several models behind one product, read the guide to AI orchestration models. A model router, content generator, image tool, and publishing system can create a chain in which different entities hold different duties.

Provider duties are not the same as publisher duties

A provider builds or places the relevant AI system on the market under its name, while a deployer uses an AI system under its authority. A publisher may also be a deployer, but the terms are not interchangeable. The correct control depends on which entity controls output generation, publication, and editorial decisions.

Business situation Likely operational role Main Article 50 question Typical control owner Evidence to retain Visible label always required?
Company offers a generative image API Provider Can synthetic output be marked in a machine-readable, detectable format? Product and ML engineering Test reports, version records, marking specification Not necessarily by the provider at every downstream display
Brand uses the API for a fictional campaign video Deployer and publisher Is the result a deepfake or otherwise subject to disclosure? Marketing and legal Asset provenance, approval, final label screenshot Often required for a deepfake, subject to the legal context
Newsroom publishes AI-drafted public-policy text Deployer and publisher Was there genuine human review and editorial control with an accountable person or entity? Editor in chief Revision history, named approval, publication record Not if the statutory human-review/editorial-responsibility exception is satisfied
Support team operates an AI chatbot Deployer; vendor may be provider Is the person informed that they are interacting with AI? Product operations Interface capture, language tests, escalation logs The interaction disclosure normally matters unless obvious from context
Designer uses AI for minor colour correction Deployer Is this standard editing without substantial alteration of input or semantics? Creative operations Source file, edit log, tool setting Not merely because an AI-assisted edit occurred
Marketplace distributes third-party generators Depends on branding and contractual control Has the marketplace become a provider or only an intermediary? Product counsel and procurement Contracts, UI claims, system architecture Requires a fact-specific assessment

The provider-side rule focuses heavily on technical provenance. Providers of systems that generate synthetic audio, image, video, or text must support output marking in a machine-readable format and make it detectable as artificially generated or manipulated, subject to the exact statutory limitations. The solution should be effective, interoperable, robust, and reliable as far as technically feasible.

The deployer-side rules focus on communication in defined situations. They include informing people when they interact directly with an AI system unless that fact is obvious to a reasonably well-informed and observant person, and disclosing deepfake content. Article 50 also addresses certain AI-generated or manipulated text published to inform the public on matters of public interest.

That public-interest text rule contains an important exception. If the AI-generated content has undergone human review or editorial control and a natural or legal person holds editorial responsibility, the disclosure obligation for that category does not apply. This is not a casual “someone glanced at it” defence. A business should be able to show meaningful review, authority to change or reject the material, and accountable publication ownership.

Not every AI-assisted text needs a label

The Act does not create a blanket duty to label every email, product description, spelling correction, or document in which AI played any part. The content type, purpose, degree of alteration, responsible role, and relevant exception all matter. A proportionate classification process is therefore more accurate than indiscriminate labelling.

Three examples show the boundary:

  • A lawyer uses a tool to correct punctuation without changing meaning. Standard editing that does not substantially alter the input or its semantics is different from generating a new public-interest article.
  • A company publishes an AI-drafted analysis of an election. That is much closer to text intended to inform the public on a matter of public interest, so the disclosure rule and editorial-review exception require careful assessment.
  • A retailer generates a purely fictional product background. The provider’s machine-readable marking duty may apply to the generator, while the retailer must separately consider whether the final visual is a deepfake or creates another disclosure trigger.

The practical mistake is to collapse technical marking and visible disclosure into one concept. A machine-readable mark is meant to travel with content and support detection by systems. A visible label informs a person at the relevant point of exposure. Some workflows need both; others need one; some fall outside the specified disclosure categories.

Official EU icon proposed for identifying AI-generated content

Source: European Commission AI labelling icons

Teams building images and advertising assets can compare this approach with practical generation workflows in best AI image prompts for 2026. The creative technique is not the compliance decision: the final use, realism, subject, and publication context determine what further analysis is needed.

A seven-step implementation procedure before 2 August

A defensible programme joins legal classification, product engineering, editorial controls, and evidence retention. The following procedure is detailed enough for a first operational pass in practice, but each organisation should adapt it to its architecture, risk profile, and advice.

  1. Inventory systems and output paths. List customer-facing chatbots, image and video generators, copy tools, voice systems, internal copilots, content-management integrations, and vendor APIs. Record the legal entity operating each system, the markets served, the model vendor, launch date, and every downstream publishing channel.
  2. Map roles by use case, not by company name. A business can be a deployer for an internal writing assistant and a provider for a branded customer product. Document who determines the system’s name and purpose, who changes the model or interface, who initiates generation, and who decides to publish the result.
  3. Classify output and interaction triggers. Create separate flags for direct AI interaction, synthetic audio, image, video, or text, deepfakes, emotion-recognition or biometric-categorisation uses, and public-interest text. Then record possible exceptions without treating them as automatic approvals.
  4. Implement technical marking at the provider layer. Engineering should choose a machine-readable method compatible with the final Code and relevant specifications, test whether marks survive ordinary transformations, and document reliability limits. Do not claim that a mark is indestructible; cropping, transcoding, screenshots, retyping, or unsupported platforms may weaken detection.
  5. Place visible disclosures at the point of exposure. A disclosure buried in terms of service may not inform a person when the content or interaction is encountered. Product and editorial teams should test label wording, prominence, accessibility, mobile display, language, and persistence when an asset is shared.
  6. Build human review as a real control. For public-interest text, identify an accountable editor, require source checks, preserve substantive changes, and give the reviewer authority to stop publication. A timestamp alone does not demonstrate editorial responsibility. A written policy should define what reviewers check and how exceptions are escalated.
  7. Create an evidence and incident loop. Keep system versions, marking test results, label screenshots, approval records, vendor attestations, and known failures. Monitor whether platforms strip metadata or labels. When a control fails, record the affected assets, corrective action, republication decision, and customer communication.

For teams that create their own AI applications, the practical AI app development guide provides useful architecture context. Add the compliance fields during product design; retrofitting provenance and disclosure after a content pipeline has spread across five systems is slower and harder to test.

What a usable label system looks like

An effective label should answer a human question without overstating certainty: was this content generated or materially manipulated by AI, and where can the person learn more? The associated machine signal should help platforms and investigators detect provenance, while the visible design should survive the interfaces in which users actually encounter the content.

Good implementation choices include:

  • plain wording that distinguishes generation from minor assistance;
  • placement near the content rather than only on a remote policy page;
  • accessible contrast and descriptive text for users who cannot see an icon;
  • a detail page explaining the tool category, scope, and known limitations;
  • retention of the label when content is embedded, reposted, or downloaded where technically possible;
  • a fallback visible notice where machine-readable provenance is stripped.

Poor choices include a tiny icon with no explanation, a label that disappears after a video starts, or a claim that detection is infallible. The EU icons are intended to encourage recognisable communication, but an icon is one interface element, not the whole governance system.

Alternative official EU icon for AI-generated content labelling

Source: European Commission AI labelling icons

Official European Commission video explaining the wider AI regulatory context

Source: European Commission policy page

Content teams can use the same distinction when working with AI video creation tools: production capabilities explain what can be generated, while the publication analysis determines whether and how it should be disclosed.

Legacy systems and the 2 December transition

The general Article 50 application date is 2 August 2026. Commission guidance describes a transition for relevant systems placed on the market before that date, with compliance expected by 2 December 2026. Businesses should treat this as a bounded implementation window for qualifying legacy systems, not a universal four-month postponement.

Precision is important. First, confirm that the system was genuinely placed on the market before 2 August and that the cited transition applies to the particular requirement and role. Second, do not postpone deployer or publication controls merely because one provider-side legacy implementation may have additional time. Third, document the system version: a material change after the application date could affect how the transition is analysed.

A useful transition register contains:

Field Example entry Why it matters
System and version Media Generator 4.2 Prevents a later release being confused with a legacy version
Market date 18 May 2026 Supports the claimed pre-application status
Legal role Provider for branded service Connects the transition to the correct duty holder
Missing control Machine-readable mark fails after MP4 export Defines the engineering gap rather than using a vague status
Interim measure Persistent visible disclosure plus export warning Reduces exposure while the technical fix is tested
Owner and deadline Product lead, 15 November 2026 Creates accountable delivery before 2 December
Evidence Release note, test suite, approval record Makes the conclusion auditable

The safest planning assumption is that new systems launched on or after 2 August should be ready from launch. A company should not describe the December date as a grace period for all AI content or all actors.

Northstar Media in Berlin: a practical composite scenario

This is a practical composite scenario, not a report about a verified company. Northstar Media operates in Berlin in June 2026 with four publishing channels, two external model providers, and a monthly output of 1,200 images, 80 short videos, and 150 policy articles.

Its first inventory finds 11 workflows. The product team owns a customer chatbot; marketing produces synthetic presenters; the newsroom uses AI for research and first drafts; designers use automatic colour correction. Treating all 11 workflows alike would create both over-labelling and compliance gaps.

Northstar classifies the chatbot interaction separately and adds a direct notice before the first response. For synthetic presenters that depict realistic people or events, it conducts a deepfake analysis, preserves provenance, and adds a visible notice near the player. For policy articles, editors retain drafts, citations, changes, and named approval to establish meaningful human review and editorial responsibility. Colour correction remains documented as standard editing where it does not substantially alter input or semantics.

The company spends six weeks implementing controls: two weeks on inventory and contracts, three on technical and interface testing, and one on a simulated incident. Its compliance record does not say “all AI is labelled.” It explains why each workflow receives a machine mark, visible disclosure, both, or neither. That reasoning is the valuable asset.

Common implementation failures

Most failures come from unclear ownership rather than an absence of icons. A marketing team assumes the model vendor handles visible disclosure; the vendor assumes the publisher controls the final interface. The resulting asset reaches the public with neither a reliable machine signal nor an understandable notice.

Watch for these recurring problems:

  1. Confusing Code membership with legal coverage. The Code is voluntary; Article 50 obligations are not optional where they apply.
  2. Labelling every assisted sentence. This creates noise and ignores the Act’s categories, standard-editing distinction, and public-interest editorial exception.
  3. Relying only on vendor contracts. Contract promises must be matched by output tests, version monitoring, and downstream controls.
  4. Using editorial review as a rubber stamp. Review should be substantive, accountable, and documented.
  5. Assuming metadata always survives. Test screenshots, social uploads, compression, export, and syndication.
  6. Hiding notices in policies. Inform people in a clear and timely way at the relevant interaction or exposure point.
  7. Ignoring non-EU headquarters. Territorial scope can reach providers and deployers outside the EU when the statutory conditions are met.

Teams designing multilingual publishing controls may find the workflow lessons in writing structured AI-assisted content useful, provided the compliance decision remains independent of the writing technique.

If you are also tracking international programmes, grants, and professional opportunities, browse the current listings on Truescho; it is an opportunities hub, not a legal or AI-compliance service.

Enforcement exposure and proportionate governance

For undertakings, Article 99 provides a maximum fine category of up to the higher of EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year for certain infringements. SMEs are subject to the lower applicable ceiling under Article 99(6). This is potential legal exposure, not an automatic fine for every labelling error; authorities consider the legal basis, facts, seriousness, duration, cooperation, and other relevant factors.

Boards should avoid two extremes. The first is dismissal because a final enforcement action has not yet occurred. The second is presenting the maximum ceiling as the inevitable outcome of one operational defect. A mature risk record describes the applicable duty, affected reach, duration, mitigation, and evidence without sensationalising the number.

Procurement should also ask providers for:

  • the output-marking method and supported formats;
  • known transformations that degrade detectability;
  • version-change notification;
  • testing documentation and interoperability information;
  • incident reporting and remediation commitments;
  • clear allocation of responsibilities for downstream labels.

These questions are especially important when comparing broad AI tools for business content. Feature lists rarely explain what happens to provenance after an asset moves through a design tool, social scheduler, and content delivery network.

Frequently asked questions

Does Article 50 apply to a company outside the European Union?

It can. The AI Act has territorial rules that may cover non-EU providers or deployers when their systems or outputs have the required connection to the EU market. Headquarters location alone is not decisive. Map where the system is offered and where its output is used, then obtain advice on the specific facts.

What counts as a deepfake under the EU AI Act?

The Act describes AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, entities, or events and would falsely appear authentic or truthful. Context matters. A visible disclosure may be adapted for evidently artistic, satirical, creative, or fictional works without obstructing enjoyment of the work.

Is machine-readable marking required for every text output?

Provider duties cover synthetic text output within Article 50, subject to the statutory design, feasibility, and editing limitations. That technical duty is distinct from a publisher’s visible disclosure. It does not mean every person must place a warning beside every AI-assisted sentence, especially where the activity is standard editing without substantial semantic change.

Are AI-assisted edits exempt from labelling?

Not automatically. Standard editing assistance that does not substantially alter input data or its semantics is treated differently, but a business must assess what the tool actually changed. Generating a new realistic scene or rewriting a public-interest article is not equivalent to correcting spelling, adjusting colour balance, or formatting an existing document.

Do legacy AI systems have until 2 December 2026?

Commission guidance describes a transition to 2 December for relevant systems placed on the market before 2 August 2026. Do not apply that date to every duty, deployment, or later system version. Record the original market date, role, version, outstanding control, and basis for relying on the transition.

Is signing the Code of Practice mandatory?

No. Participation in the final Code of Practice is voluntary. Its specifications and governance commitments can help organisations implement and demonstrate compliance. The underlying Article 50 obligations remain binding where applicable, whether or not a company signs. Code membership also does not remove the need for product-specific testing and legal analysis.

Does human review remove every disclosure obligation?

No. The relevant exception concerns specified AI-generated or manipulated text published to inform the public on matters of public interest when it has undergone human review or editorial control and an accountable person holds editorial responsibility. It does not erase separate duties for chatbot interactions, deepfakes, biometric uses, or provider-side machine marking.

Conclusion: build an evidence chain, not an icon library

The EU AI Act AI-generated content labelling rules require a role-based system: inventory the workflow, classify the legal trigger, implement technical and visible controls, test them in real channels, and preserve evidence. Keep the voluntary Code separate from mandatory Article 50 duties, and treat the December legacy transition as a scoped provision rather than a blanket delay.

For opportunities that may matter to founders and professionals beyond this compliance project, review Truescho’s current opportunities hub. For a binding decision on the Act, consult qualified counsel with the full product and publication facts.

Official sources