EU AI content labelling, and what actually needs a label

The AI Act's transparency rules have applied since 2 August 2026, and most of what advertisers brace for is not in them. The machine-readable marking duty sits with whoever built the generative tool. What lands on the advertiser is narrower, and on a normal campaign it is a single instrument: a visible label on a deep fake. Here is the test that decides which assets need one, the icon that goes on them, and the four things a label does not buy you.

Who has to mark AI content, and who has to label it

Article 50 of the AI Act splits its duties between two roles, and almost every argument about AI labelling turns out to be an argument about which role you are in. The provider is the company that puts an AI system on the market. The deployer is anyone who uses one in the course of professional activity. A brand, an in-house studio, a media agency and a freelance retoucher are all deployers. Essentially none of them is ever a provider.

The two roles are handed different instruments. Article 50(2) requires synthetic output to be marked in a machine-readable way, which means watermarks, signed metadata and fingerprints, Google's SynthID being the best-known example. That duty is discharged inside the tool, by the company that shipped it. Article 50(4) requires a visible label on deep fakes, and that one belongs to the deployer.

So a deployer does not apply the invisible watermarks, and cannot. The only exposure on the marking side is destroying what the tool already embedded, which is why metadata handling appears later in this piece as a compliance question rather than as housekeeping.

Keeping those two words apart prevents most of the confusion on this subject. A watermark is machine-readable and somebody else's job. A label is human-readable and yours.

Machine-readable marking is the vendor's job, the visible label is yours Two panels side by side under one line of text explaining that Article 50 splits the duty. Left, headed the tool vendor's job: machine-readable marking, meaning watermarks, signed metadata and fingerprints, which Article 50(2) places on whoever put the generative tool on the market rather than on the advertiser. Right, highlighted, headed your job: one visible label on the asset, perceivable at first exposure, under Article 50(4), which is the whole of the deployer's duty on synthetic media. A wider panel underneath, headed the one way you can break the vendor's half, warns that stripping metadata on export destroys the marking the tool already embedded, and that asserting human origin on AI output is not a grey area. Article 50 splits the duty: machine-readable marking for whoever built the tool, a visible label for whoever publishes. The tool vendor's job Machine-readable marking: watermarks, signedmetadata, fingerprints. Article 50(2) puts it onwhoever put the generative tool on the market,not on you. You cannot add it, and should not try. Your job One visible label, on the asset, perceivable atfirst exposure. Article 50(4). This is the wholeof the deployer's duty on synthetic media, andit is the only instrument you actually control. The one way you can break the vendor's half Stripping metadata on export destroys the marking the tool already embedded, and asserting human originon AI output is not a grey area. Leave Content Credentials on, and export with metadata intact. Open full size
The split that decides everything else. The tool vendor owes the machine-readable marking, the advertiser owes one visible label, and the only way to break the vendor's half is to strip what it embedded on the way out of the studio.

Two dates and one number are worth writing down. The obligations have applied since 2 August 2026. Generative systems that were already on the market by then have until 2 December 2026 to meet the machine-readable marking duty, which is a question to put to a vendor rather than one to solve in a studio. Breaches of Article 50 sit under Article 99(4), at up to €15 million or 3% of worldwide annual turnover, whichever is higher.

The three questions that decide whether an asset needs a label

Three questions, and you stop at the first one that resolves.

1) Did a generative AI feature touch this asset at all? Generative fill, expand and remove count, as do voice synthesis, style transfer, text-to-image and text-to-video. Ordinary sliders, presets and non-generative filters do not. If nothing generative touched it, there is nothing to do and nothing to record.

2) Does the result show a real person, product, place or event, in a way a viewer could reasonably take as authentic? "Real" includes plausibly real. An invented person who reads as a photograph of somebody counts. A sphinx flying over the Eiffel Tower does not, and that is close to the example the Commission's own guidance uses.

3) Did AI change what is true about that subject? A face, a voice, a body, the product itself, or an event that did not happen. If AI only touched context, surroundings, light or cleanup, the answer is no.

Three yeses make a deep fake, and a deep fake needs to carry a label.

One procedural rule is worth borrowing whole. When the second and third questions are genuinely close to the line, treat the asset as a deep fake and put the decision in front of whoever owns quality. Ambiguity resolves upward. A label on something that did not strictly need one costs a corner of the frame; a missing label on something that did is the failure the regulation was written about.

Standard editing, a real difference, and a deep fake: the three buckets

Those questions sort every asset into one of three buckets, and only the third carries a legal duty.

The three buckets, and which one carries a label Three panels stacked under one line of text giving the three questions that decide the outcome, stopping at the first that resolves: whether generative AI touched the asset, whether the result shows something real, and whether AI changed what is true about it. Top panel, A, standard editing with nothing to do: crop, colour, contrast, sharpening, dust and red-eye removal, blurring a bystander's face, rescaling, or extending an edge already in the frame. Middle panel, B, where AI made a real difference but nothing real is misrepresented: invented backgrounds, fantasy imagery, non-real characters, an AI voice for an openly fictional one, tagged in production with no public label owed. Bottom panel, highlighted, C, the deep fake and the only one that carries a label: a real or plausibly real person, product, place or event, altered or fabricated so it could pass as authentic, with the EU icon going on the asset itself before it leaves. Three questions, stopping at the first that resolves: did generative AI touch it, does it show something real, did AI change what is true? A. Standard editing. Nothing to do Crop, colour, contrast, sharpening, dust and red-eye removal, blurring a bystander's face, rescaling, orextending an edge that was already in the frame. The picture still shows what the camera saw. B. A real difference, but nothing real misrepresented Invented backgrounds, fantasy imagery, non-real characters, an AI voice for an openly fictional one. We tagthe file in production so it stays traceable. No public label is owed. C. Deep fake. The only bucket that carries a label A real or plausibly real person, product, place or event, altered or fabricated so it could pass as authentic.The EU icon goes on the asset itself, before it leaves. Open full size
The three outcomes of the test. Standard editing needs nothing, a genuine AI contribution that misrepresents nothing gets tagged in production but no public label, and only a deep fake carries the EU icon. The middle bucket is the one most people over-label.

Bucket A is standard editing, and it is deliberately generous. The regulation's own exempt list covers edge completion, pixel filling for an aspect-ratio change, background removal where the background was visible in the original, and colour and contrast work. So extending a brick wall that is already in the photograph is bucket A and needs nothing at all. Inventing a wall that was never there, behind a real person, is bucket C.

Bucket B is where AI made a real difference and nothing real is misrepresented. Invented backgrounds, fantasy imagery, characters who are plainly not people, an AI voice for an openly fictional one. There is no labelling duty here. We still tag these files, because in six months somebody will need to know, but that tag is ours and not a disclosure.

Bucket C is the deep fake: a real or plausibly real person, product, place or event, altered or fabricated so that it could pass as authentic. It is the only bucket the labelling duty reaches, and it is the whole job.

Material generated before 2 August 2026 does not need retroactive labelling. Nobody has to go back through the archive.

The EU AI labelling icon, and which variant to use

The Commission publishes the icon set itself. It is free to use, needs no attribution, and has been user-tested across member states, which is a better starting point than a bespoke badge nobody recognises. Three variants ship: AI GENERATED for work that is fully generated, AI MODIFIED for work with real source material that AI meaningfully changed, and a bare AI mark for use with your own wording or an interactive second layer.

The three EU AI labels, and what each one means Three rows, each pairing an official EU label with its meaning. Top, the AI GENERATED mark, a white rounded pill carrying dark lettering: fully AI-generated, with no human source material beyond the prompt. Middle, the AI MODIFIED mark in the same style: real source material, changed by AI so it alters what the picture asserts. Bottom, the plain AI mark, a white circle with dark lettering: the base mark, for a custom text label or an interactive second layer. A highlighted line underneath states that only a deep fake has to carry one of these. AI GENERATED Fully AI-generated. No human source material beyond the prompt. AI MODIFIED Real source material, changed by AI so it alters what the picture asserts. AI The base mark, for a custom text label or an interactive second layer. Only a deep fake has to carry one of these. Open full size
The three published marks, in their white variants. Which one an asset needs follows from whether AI generated it outright or altered real source material, and only a deep fake needs any of them.

The design rules are short. The capitalised acronym AI is the main visual element and stays in English, including in a Finnish or German version of the same campaign. The letters keep equal vertical dimension and their proportions when the mark is resized. Size and colour may adapt to the layout as long as the mark stays legible and recognisable against its background, which is why the set ships in black, white and both of those at 50% transparency. Download it once, keep it with the brand assets, and do not redraw it.

Where the label goes, and how that changes per medium

Placement is where good intentions usually come apart, because a label that technically exists and is never seen satisfies nothing. Three rules hold across every medium:

After that it depends on what the asset is:

Medium What to do
Still image Icon top right, embedded in the file
Video Icon at the start, at intervals through the run, and after every break, because clips and screenshots travel. Where only part of the video is a deep fake, carry the icon across that part
Audio only A short spoken disclaimer in plain language at the beginning, in the content's language or in English
Audio with a screen The spoken disclaimer and the icon on screen
Video or image with sound Icon always. Audio disclosure is supplementary and never a replacement
Print, out-of-home, packaging Icon on the artwork. There is no first-exposure moment to defer to
Internal-only material Disclosure may sit in the interface or the room rather than in the asset, as long as people know before they see it

Where a platform offers its own "AI-generated" switch, use it and the embedded icon. The switch is a courtesy to the platform, and the icon is the compliance measure.

AI-written text is mostly out of scope

Text is where the rules are widely over-read. AI-written text needs a label only when three things hold at once: it is published, it is intended to inform the public, and it concerns a matter of public interest, which means politics, government, justice, fundamental rights, security, health or the environment.

Marketing copy is not a matter of public interest. Most commercial content is simply out of scope, and no amount of AI in the drafting changes that.

Even in scope there is a clean exemption: text that a person has reviewed and takes editorial responsibility for. The condition is that the person is identifiable and their contact details are published. An organisation that already has a human own every published word satisfies this by working normally.

That exemption is why this page carries a byline and a fact-checker at the footer of it, naming the actual model that drafted it and the person who checked it. It is not decoration.

The diagrams on this page are AI-generated too, drawn as vector code by the same model. Run them through the three questions above and the second one fails immediately: none of the three shows a real person, product, place or event, only a schematic panel of boxes, icons and short text illustrating a rule. No label applies to them either.

What an AI label does not buy you

A label makes AI involvement visible. It does not make the content lawful, and four things sit entirely outside it.

The regulator's own examples of what is not artistic are all advertisements: teleshopping-style product demonstrations, synthetic influencers testing a sponsored product. A photoreal render of a building that has not been built, or a lifestyle shot of a product in a room that does not exist, lands in the same place. Cinematic treatment does not make an advertisement a film. Assume standard labelling for commercial work.

Worked examples

The rows marked (EU) come from the Commission's own lists. The rest apply the same test to ordinary studio work.

Case Bucket Why
Extending a brick wall already in the shot to fill a wider crop A Edge completion and aspect-ratio fill are named standard editing
Removing a bin from the background of a product shot A The background was visible in the original, and the meaning is unchanged
Blurring a bystander's face A Named standard editing
Colour grading a campaign image with an AI tool A Cosmetic, no change of meaning
Sphinx flying over the Eiffel Tower (EU) B Could not plausibly be real
Mice arguing about cheese in a cheese advertisement (EU) B Openly fictional, so nobody is deceived
A fully AI-generated fantasy landscape for a poster B Nothing real is depicted
An AI voice for an openly fictional character (EU) B No deception about who is speaking
A real car shown against an AI-generated background (EU) B The product itself is untouched and not misrepresented
An AI-generated stock-style photo of an invented "customer" C It reads as a photograph of a real person
Swapping or substantially reshaping a model's face C A named semantic change
Cloning a client executive's voice for a campaign C Realistic speech in a specific person's voice
A synthetic avatar of a chief executive thanking staff (EU) C A named deep fake example
An AI-generated influencer endorsing a real product (EU) C Named, and explicitly not artistic
A product image that makes the product look better than reality (EU) C A named deep fake example
Two real athletes composited into a stadium that is not there (EU) C A named deep fake example
A photoreal render of an unbuilt building, presented as a photograph C A plausibly real place, fabricated so it reads as authentic
A riot, a crowd or a news-like scene generated whole C A plausible event that reads as authentic

How we handle it

Provenance and labelling are part of the deliverable here, not paperwork bolted on at the end. In the order it actually happens:

Every asset is classified before it leaves. One of the three buckets, decided on the questions above, recorded against the job. Without that record, "did we label that one?" becomes unanswerable a year later, which is the real failure mode on a busy account rather than anybody deciding to hide something.

Filenames carry the bucket. A file AI generated outright and a file AI meaningfully changed get different tags, always as the last element before the extension, so whoever opens it in six months knows which mark it needs. The filename is not a disclosure and we never present it as one: it is stripped on upload and invisible to your audience. It is a production signal, and the label is the compliance measure.

Metadata survives the whole chain. Exports carry their metadata rather than going out as "copyright only". Content Credentials stay switched on wherever a tool offers them, so a Coalition for Content Provenance and Authenticity (C2PA) signature the tool wrote travels with the file. No metadata cleaner, no stripping step, no "optimise for web" pass that quietly discards it. And the inverse, which matters as much: we do not assert human origin on something AI made.

Bucket C leaves already labelled. We do not deliver an unlabelled deep fake with a note asking you to add the icon.

The delivery message names the assets. Which files are AI-generated or AI-modified, that the label must not be cropped out or replaced downstream, and that metadata has to survive your own publishing chain. On recurring work that belongs in the contract instead of in a message every time, which is what the Code of Practice asks deployers to arrange. It is voluntary, and it is also the only EU-recognised way to demonstrate compliance, so we follow it as written.

And the refusal. Asked to take a label off a deep fake, we will not, and we will say so in writing. It is your exposure as much as ours.

All of that fits how we already make content and creative: human-made, AI-accelerated, and labelled honestly.

This is how we read the rules, not legal advice. We make the technical side work and document it so your compliance people have less to do, and we are not your lawyers. A novel case, and anything involving a real person's likeness, belongs with counsel.

Written by Claude (Opus 5), fact-checked by Niklas Rantanen and Google Gemini

#ai #regulation #compliance

This document was digitally signed by Niklas Rantanen on 30 August 2026.