How to Label AI-Generated Content Under the EU AI Act
How to label AI-generated content under EU AI Act Article 50: covered media, key exceptions, optional icons, penalties, and a practical compliance workflow.

The EU AI Act’s transparency rules have been enforceable since August 2, 2026. If your organization publishes synthetic media, operates a chatbot, or uses certain biometric tools, “we used AI somewhere” is not a sufficient compliance strategy. Article 50 assigns different duties to AI system providers and deployers, and only some content requires a visible label.
This guide explains how to label AI-generated content under the EU AI Act, which exceptions matter, and how to build a practical review process. It is operational guidance, not legal advice; confirm your organization’s scope and edge cases with qualified EU counsel.
The EU AI Act labeling rules at a glance
The European Commission’s Article 50 guidelines, updated on August 6, 2026, separate the rules into provider and deployer obligations.
Providers must design covered systems so that:
- People are explicitly informed when they interact directly with an AI system.
- Synthetic text, image, audio, and video outputs carry machine-readable marks that enable detection, subject to technical feasibility and stated exceptions.
Deployers—organizations using an AI system under their authority—must inform people when they are exposed to:
- Emotion-recognition or biometric-categorization systems.
- Deepfake image, audio, or video.
- AI-generated or manipulated text about a matter of public interest when it lacks human review or editorial control.
The obligations apply from August 2, 2026. The Commission says enforcement is handled by national market-surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor for EU institutions.
The Commission’s quick-facts page lists potential fines of up to €15 million or 3% of a company’s total worldwide annual turnover, with proportionality for small and medium-sized enterprises and small mid-cap companies. Actual exposure depends on the violation and applicable enforcement process.
First determine whether you are a provider or deployer
A common mistake is treating every participant in the content chain as if it has the same duty.
A provider develops an AI system or has one developed and places it on the market or puts it into service under its name or trademark. A company offering an image generator, voice-cloning service, or interactive AI assistant may be a provider.
A deployer uses an AI system under its authority, outside a personal non-professional activity. A publisher generating an illustration with a third-party model, a retailer operating an AI support bot, or an employer using an emotion-recognition tool may be a deployer.
One organization can occupy both roles. For example, a company that substantially modifies a third-party system and offers the resulting product under its own name may need a role analysis beyond “we are only a customer.” Record the determination for every system rather than relying on a company-wide label.
What AI-generated content needs a visible label?
Article 50 does not impose a visible “made with AI” badge on every AI-assisted asset. The correct decision depends on the content and how it is published.
| Scenario | Visible disclosure? | Practical treatment |
|---|---|---|
| Customer talks directly to an AI chatbot | Yes | Disclose that it is AI no later than the first interaction, unless this is obvious to a reasonably informed user |
| AI-generated image, audio, or video falsely appears to show a real person, object, place, entity, or event | Yes | Treat it as a deepfake and add a clear, perceivable label |
| AI-generated news or public-interest text with no human review or responsible editor | Yes | Put a clear disclosure where readers encounter it |
| Public-interest text reviewed by a human with editorial responsibility | Article 50’s deployer disclosure has an exception | Document the review and named editorial responsibility; voluntary disclosure may still be sensible |
| Clearly artistic, fictional, creative, or satirical deepfake | Limited disclosure still applies | Disclose in a way that does not hamper display or enjoyment of the work |
| Routine AI editing that does not substantially alter the input or its meaning | Provider marking exception may apply | Document why the change is standard editing rather than synthetic manipulation |
| Fully synthetic product illustration that does not falsely appear authentic | Not automatically a deepfake | Check other duties and your voluntary policy before deciding |
The legal definition of a deepfake is narrower than “any AI image.” The Commission describes it as AI-generated or manipulated image, audio, or video resembling existing persons, objects, places, entities, or events that would falsely appear authentic or truthful.
That distinction matters. A clearly fantastical abstract illustration may not need a visible deployer label under the deepfake rule. A fabricated video of a real CEO announcing a merger almost certainly demands a different response.
For broader context on risk classes and implementation dates, see NextPJ’s EU AI Act compliance guide.
Human review is a process, not a checkbox
The public-interest text exception applies when the publication has undergone human review or editorial control and a natural or legal person holds editorial responsibility. Merely opening an AI draft, correcting a typo, or clicking “approve” is weak evidence of meaningful review.
A defensible editorial workflow should require a reviewer to:
- Verify factual claims against reliable sources.
- Check quotations, names, dates, figures, and links.
- Evaluate whether important context is missing or misleading.
- Review for privacy, defamation, copyright, discrimination, and safety risks.
- Make substantive corrections where needed.
- Record who accepted editorial responsibility and when.
Keep the review record with the content item. The goal is not paperwork for its own sake; it is evidence that a responsible human controlled publication.
How to create a compliant label
The AI Act requires the disclosure to be clear and distinguishable. The Commission’s EU icon guidance recommends making it perceivable by the time of first exposure, placing it where overlays do not obscure it, and preserving it when content is downloaded or reshared.
Use plain language at first exposure
A label should say what happened, not hide behind vague wording such as “enhanced.” Practical wording can include:
- AI-generated image: This image was created with generative AI.
- AI-modified video: This video was altered with AI and is not an authentic recording of the depicted event.
- AI assistant: You are interacting with an AI assistant.
- Unreviewed public-interest text: This text was generated by AI and has not received human editorial review.
These examples are starting points, not official safe-harbor language. Adapt the wording to the actual manipulation and context.
Make the disclosure accessible
Use sufficient size and contrast. Add meaningful alternative text or an accessible label for an icon, avoid unexplained abbreviations, and leave time-limited disclosures on screen long enough to read. Do not place the only disclosure behind a tooltip that keyboard or screen-reader users cannot reach.
Preserve the label outside your website
A caption that disappears when an image is downloaded will not travel with the asset. For high-risk media, consider both a visible disclosure and durable provenance metadata. The C2PA standard is one way to attach cryptographically verifiable provenance information; it is not named as the only permitted Article 50 method. NextPJ’s Content Credentials verification guide explains how that verification layer works.
The current C2PA 2.4 specification can support interoperability, but metadata can still be stripped by platforms. Test every distribution path instead of assuming the original file’s credentials survive.
The optional EU icons do not replace compliance
The Commission provides three optional icon treatments for basic AI involvement, fully AI-generated content, and partially AI-modified content. The icons are free to use, but the Commission explicitly says using an icon does not establish legal compliance by itself.
If you use them:
- Pair the icon with plain-language text when space allows; Commission user testing found better performance with a text label.
- Display it at first exposure.
- Keep it clear of overlays.
- Ensure it remains visible in downloaded or reshared content when required.
- Follow the Code of Practice placement rules if your organization is a signatory.
The Code of Practice on Transparency of AI-generated Content is voluntary, while Article 50 is binding. The Commission and AI Board have recognized the code as an adequate way for signatories to demonstrate compliance with marking and labeling duties. Organizations choosing another method must be able to show that it is equivalently adequate.
A seven-step compliance workflow
1. Inventory systems and publication channels
List every chatbot, generator, editing tool, voice system, biometric system, and automated publishing workflow. Include vendors, owners, audiences, regions, and output formats.
2. Assign roles and obligations
For each system, record whether your organization is a provider, deployer, or both. Map the relevant Article 50 duty rather than applying one generic policy.
3. Classify each output
Use a publication gate that distinguishes deepfakes, public-interest text, standard edits, creative works, and other synthetic content. Escalate uncertain cases before release.
4. Apply visible and machine-readable measures
Deployers should add the required human-facing disclosure. Providers should ensure covered synthetic outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, as far as technically feasible under the law.
5. Test the complete distribution chain
Export, upload, download, reshare, transcode, and screenshot representative assets. Check whether visible labels remain perceivable and whether provenance information survives. Record platform-specific failure points.
6. Preserve evidence
Store the system version, content classification, disclosure used, human reviewer, publication date, and results of provenance tests. Retain vendor documentation supporting machine-readable marking claims.
7. Audit vendors and train staff
Contracts should state who supplies machine-readable marks, what happens when a platform strips them, and how incidents are handled. Train editors, marketers, support teams, and product owners to recognize covered scenarios.
Important exceptions and transition details
The Commission identifies several limits:
- Law-authorized use for detecting, preventing, investigating, or prosecuting criminal offenses can be exempt from deployer disclosure.
- Artistic, creative, satirical, fictional, and analogous works receive a limited form of disclosure that should not hamper enjoyment.
- Human-reviewed public-interest text with assumed editorial responsibility is exempt from the specific deployer labeling duty.
- Generative AI systems placed on the market before August 2, 2026 receive a grace period for the provider marking obligation until December 2026 under the amended rules.
- Deepfakes created before August 2, 2026 do not require retroactive labeling under the Commission’s current quick facts, although labeling is encouraged.
Do not turn an exception into a blanket policy. Record the facts supporting it for each content type and review the decision when the system, use case, or law changes.
Conclusion
EU AI Act AI content labeling is not a universal badge requirement. It is a role-based system: providers handle interaction notices and machine-readable marking, while deployers handle disclosures for biometric exposure, deepfakes, and certain unreviewed public-interest text.
The most reliable implementation combines a clear label at first exposure, accessible presentation, durable provenance where practical, documented human review, and testing across every publication channel. Start with the Commission’s July 2026 guidelines, then use the voluntary code and icons to make your process consistent and auditable.
Related Articles

How to Measure AI ROI: A 90-Day Scorecard
A practical 90-day AI ROI scorecard for connecting total cost, quality, time savings, and risk to realized business value.

Claude Opus 5 Migration Guide: Costs and Checklist
A practical Claude Opus 5 migration guide covering API pricing, breaking changes, effort settings, prompt caching, safety fallbacks, and a production rollout checklist.

Learn AI Agents in 5 Days: A Practical 2026 Plan
A practical five-day plan to learn AI agents by building one guarded pilot, with tools, evaluations, security checks, monitoring, and rollback.