The European Union’s new AI-transparency rules started applying on August 2, 2026, but the practical requirement is not “put an AI label on everything made with AI.”

Article 50 of the EU AI Act creates different duties for different actors. AI-system providers must build disclosure and machine-readable marking into certain systems. Businesses, publishers and other professional users—called deployers—must visibly disclose specific uses such as deepfakes and unreviewed AI-written text about matters of public interest.

A normal AI-assisted email, edited product description or stylised illustration is not automatically subject to a visible public label. The important questions are what the system does, how realistic or informative the output is, who publishes it, and whether a qualified human substantively reviewed it.

Rule check: August 4, 2026. Article 50 applies from August 2, 2026. The European Commission published final implementation guidelines on July 20 and an official quick-facts page updated July 29. The EU’s Code of Practice and labelling icons are voluntary tools; the underlying legal duties are not. This article is an operational explainer, not legal advice.

The quick answer

Visible disclosure is most clearly required in these cases:

  • a person is interacting directly with an AI system and that fact is not already obvious;
  • an organisation uses emotion-recognition or biometric-categorisation technology on people;
  • AI creates or materially manipulates realistic image, audio or video content that could falsely appear authentic—a deepfake;
  • AI-generated or manipulated text is published to inform the public about a matter of public interest without substantive human review or editorial control.

Separately, providers of systems that generate synthetic text, audio, images or video generally need to make outputs machine-readable and detectable as AI-generated or manipulated, where technically feasible.

The visible label and the machine-readable mark are related but different duties.

First separate the provider from the deployer

Many confusing summaries collapse two roles into one.

RoleTypical exampleMain Article 50 responsibility
ProviderA company develops and offers an AI chatbot, image generator or content system under its own nameBuild interaction notices and machine-readable output marking into the system
DeployerA retailer, publisher, agency, school or other organisation uses an AI system professionallyInform people about emotion/biometric systems and visibly disclose covered deepfakes or unreviewed public-interest text

A company can hold both roles. For example, an agency that develops its own branded customer chatbot and deploys it on client websites may have provider duties for the system and deployer duties for its use.

Hiring a freelancer or contractor does not necessarily move responsibility away from the organisation when the system is still operated on its behalf and under its control.

What providers need to build into AI systems

1. Tell people when they are interacting with AI

A provider of an AI system designed for direct two-way interaction must ensure people are informed that they are dealing with AI, unless that is obvious to a reasonably informed and observant person in the circumstances.

A clearly branded “AI assistant” usually presents less ambiguity than a support widget using a human name, portrait and conversational design without disclosure.

The information must be clear and distinguishable and provided no later than the first interaction. Accessibility requirements also apply.

2. Add machine-readable marks to generated content

Providers of systems generating synthetic text, audio, images or video must generally make outputs detectable as artificially generated or manipulated. The technical measure must be effective, interoperable, robust and reliable as far as technically feasible.

This is closer to provenance metadata, watermarking or another detection mechanism than to a large visible badge placed over every output.

The provider-side marking duty has important limits. It does not apply when the AI merely assists with standard editing or does not substantially alter the supplied input or its meaning. A basic crop, spelling correction or light adjustment is therefore different from generating a new scene, replacing a face or materially rewriting a factual publication.

What professional users need to disclose visibly

Deepfakes

Article 50 defines the covered category around realistic deception rather than around every generated picture.

A deepfake is AI-generated or manipulated image, audio or video content that appreciably resembles an existing person, object, place, organisation or event and could falsely appear authentic or truthful.

Likely covered examples include:

  • cloning a real executive’s voice for a promotional recording;
  • placing a public figure into footage of an event that did not happen;
  • furnishing an authentic photograph of an empty property with realistic AI-generated interiors without making the alteration clear;
  • materially modifying real news footage so viewers could mistake it for an authentic record.

A visible disclosure must be clear and distinguishable at the latest when the person first sees or hears the content.

Evidently artistic, fictional, satirical or creative works are not simply excluded. Instead, the disclosure can be made in an appropriate way that does not spoil the normal display or enjoyment of the work.

AI-written text on matters of public interest

The text rule is narrower than “all AI copy must be labelled.” Three elements matter:

  1. the text is published;
  2. its purpose is to inform the public;
  3. it concerns a matter of public interest.

The Commission’s guidance includes areas such as politics, public administration, justice, fundamental rights, public safety, health, environmental protection, consumer safety, and economic, financial, scientific or cultural developments relevant to public debate.

Examples that may fall within scope include an automatically generated public-health article, a political explainer, a financial-policy report or a news summary published without substantive editorial review.

Routine private correspondence, internal notes and ordinary commercial copy are not automatically public-interest publications merely because AI helped write them.

Human review can remove the text-labelling duty—but not any review will do

AI-generated public-interest text does not require the Article 50 disclosure when it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

The Commission describes meaningful human review as deliberate examination of the substance by someone with relevant knowledge and professional judgement. Editorial control means having genuine authority to approve, alter or reject the content for substantive reasons, including fact-checking and assessing source reliability.

These are unlikely to be enough by themselves:

  • running a spelling or grammar checker;
  • accepting an AI draft after a quick skim;
  • checking formatting but not factual claims;
  • assigning a person nominal responsibility without giving them authority to change or reject the text.

A useful internal test is:

Could the reviewer explain the important claims, identify the sources, reject the draft, and accept responsibility for the published result?

When the answer is no, the organisation should not rely casually on the human-review exemption.

The four-case decision table

Use caseVisible disclosure?Other likely action
Website chatbot that could be mistaken for a personUsually yes, unless interaction with AI is obviousProvider designs the first-interaction notice
Fully synthetic decorative illustration that does not pretend to document realityNot automatically under the deepfake ruleProvider may still need machine-readable marking
Real photograph materially altered to show a believable event or condition that did not existUsually yesKeep the disclosure with downloaded or reshared versions where practicable
AI-drafted article about public health, economics or politics with no substantive editorYesLabel clearly at first exposure
AI-drafted public-interest article fact-checked and approved by a responsible editorArticle 50 text label may not be requiredPreserve evidence of the review and editorial responsibility
Private AI-assisted email or internal summaryGenerally outside the public-interest publication ruleOther privacy, employment or sector rules may still apply
Emotion-recognition tool assessing people in a workplace or serviceYes, inform exposed peopleData-protection and other AI Act requirements may also apply

This table is a screening tool, not a substitute for analysing the actual system and context.

Do the rules affect organisations outside the EU?

Potentially, yes.

The Commission says the AI Act applies to public and private actors inside and outside the EU when they place an AI system or general-purpose model on the EU market, put an AI system into service in the EU, use it in the EU, or its use affects people located in the EU.

A non-EU software provider offering a generative product to EU customers should not assume that its incorporation address keeps it outside scope. A non-EU publisher or business should assess the rule when its AI system is used in the EU or produces output used there.

The exact territorial analysis can become complicated, especially for global websites, outsourced workflows and systems operating across several entities. That is a sensible point to obtain specialist advice rather than relying on a generic footer.

The optional EU icons are not the law itself

The European Commission has published free icons for:

  • a general AI-involvement indication;
  • AI GENERATED;
  • AI MODIFIED.

Their use is optional. A business can use another clear disclosure method, provided it meets the legal requirement. Conversely, placing the official icon somewhere obscure does not automatically establish compliance.

The Commission recommends that disclosures be visible at first exposure, avoid overlays that hide them, remain available when content is reshared or downloaded where feasible, and use accessible plain language. Its own user testing found better recognition when the icon was accompanied by text.

For many organisations, “AI-generated reconstruction” or “Voice generated using AI” will communicate more clearly than an unexplained symbol alone.

The limited transition rule

Article 50 began applying on August 2, 2026. Outputs already generated and made available before that date do not need to be labelled retroactively under the new rule, although voluntary disclosure may still be useful.

The Commission also describes a limited transition until December 2, 2026 for the provider-side machine-readable marking obligation for certain generative systems already placed on the market before August 2. That transition does not create a broad four-month holiday for every chatbot notice or every new deepfake publication.

Organisations should document which system version and output date they are relying on rather than treating “existing AI” as a universal exemption.

A 30-minute compliance triage

1. Inventory public-facing AI uses

List chatbots, voice systems, image tools, automated publishing, synthetic presenters, product visualisation and any emotion or biometric analysis. Include systems operated by agencies and contractors.

2. Assign the role

For each use, record whether the organisation is the provider, deployer or both. Name the entity that controls the system and the entity that publishes the output.

3. Classify the exposure

Ask whether people are:

  • directly interacting with AI;
  • exposed to emotion recognition or biometric categorisation;
  • seeing realistic manipulated media;
  • reading AI-generated public-interest text.

4. Record the review gate

For public-interest text, identify the person with subject knowledge and real authority to approve, modify or reject the substance. Record the sources checked and the final approval.

5. Check the label and provenance path

Confirm that visible disclosures appear at first exposure and survive the normal download or sharing flow where required. Ask the system provider what machine-readable marking it adds and whether later editing strips it.

6. Keep evidence

Store the system version, publication date, disclosure wording, placement decision, review record and person responsible. The voluntary Code of Practice can provide a useful benchmark even for organisations that do not sign it.

Common mistakes

Labelling every AI-assisted sentence

Over-labelling can obscure the rule’s purpose and train readers to ignore warnings. Focus first on the covered interaction, deepfake, public-interest and biometric cases.

Article 50 requires information at first interaction or exposure. A generic policy page that users never see may not provide a clear and distinguishable disclosure in context.

Assuming a human name equals human review

Naming an editor is not the same as substantive review, authority and responsibility. Preserve a real editorial process.

Relying only on visible labels

Providers also have a separate machine-readable marking duty. A caption can inform a viewer while failing to preserve provenance for platforms and detection tools.

Assuming an AI vendor handles every obligation

The vendor may handle system-level marking, while the deployer remains responsible for how a deepfake or public-interest publication is presented to people.

Enforcement and penalties

The Commission’s current quick-facts guidance says Article 50 enforcement can involve national market-surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor for EU institutions.

It lists maximum fines of €15 million or 3% of total worldwide annual turnover for companies, with proportionality considerations for smaller businesses. The maximum is not an automatic penalty for every imperfect label; enforcement must consider the circumstances and applicable legal framework.

The practical lesson is not to panic-label every use. It is to make a documented, defensible decision about the uses most clearly covered.

What to watch next

  • National authorities will develop enforcement practice, which should clarify what disclosure placement works in real products.
  • Technical standards for robust and interoperable machine-readable marking will continue evolving.
  • The December transition for certain existing provider systems will end.
  • Platforms may introduce stricter contractual labelling rules than Article 50 itself.
  • Courts and regulators will eventually test the boundaries of “deepfake,” “public interest,” meaningful human review and territorial scope.

Conclusion

The EU’s new rule is not a universal sticker requirement for anything touched by AI.

It is a layered transparency system: tell people when they are interacting with AI, preserve machine-readable provenance for generated outputs, disclose realistic deceptive media, label unreviewed AI text that informs the public on important matters, and inform people exposed to emotion or biometric analysis.

The most useful next step is a short inventory and decision record. Identify the role, the audience exposure, the realism or public-interest purpose, the human-review gate and the disclosure method. That produces a more reliable compliance process than adding “made with AI” to everything—or to nothing.

Sources

Written and reviewed by /lico

Just writing down my thoughts, interests, and the things I learn along the way.