EU AI content labelling rules before 2 August 2026
The EU approved a code for AI-generated content transparency. Learn what AI Act Article 50 requires from 2 August and how companies should prepare.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 10 July 2026
- READING TIME
- 9 min read
- TOPIC
- Compliance
Additional EU AI Act transparency obligations begin applying on 2 August 2026. For organisations using generative AI, the key July development came when the European Commission assessed the Code of Practice on Transparency of AI-Generated Content as an adequate tool supporting Article 50(2), (4) and (5).
The distinction is important: the code is voluntary, while obligations in the regulation are mandatory. Not every item created with AI requires the same label. Companies must classify their role, system and publication context before selecting an icon.
What the Commission approved
In its 9 July opinion, the Commission said the code adequately covers the relevant Article 50 obligations and can facilitate effective implementation. It contains two main areas:
- commitments for providers of generative systems on machine-readable marking and detectability;
- commitments for deployers on disclosure of deepfakes and specified AI-generated or manipulated text.
Signing provides a more predictable route to demonstrating compliance, but is not immunity. The Commission states that adherence is not conclusive evidence of compliance. Authorities can still assess whether declared mechanisms work.
The official FAQ set 22 July 2026 at 18:00 CEST for inclusion in the initial signatory list. Organisations can join later, but joining does not postpone the law’s application date.
Machine-readable provenance and visible disclosure differ
The first layer applies to providers of systems generating audio, images, video or text. Article 50 of the AI Act requires output to be marked in machine-readable format and detectable as artificially generated or manipulated, as far as technically feasible, considering content type and the state of the art.
The second layer concerns a person or organisation publishing specified material. Deepfake audio, images or video require disclosure to the audience. Similar duties cover AI-generated or manipulated text published to inform the public on matters of public interest.
A file may therefore contain provenance metadata while a website also displays a human-readable label. One mechanism does not automatically replace the other. The code’s policy page treats provider and deployer responsibilities separately.
What does not automatically require a label
The claim that every AI-assisted item must carry an “AI” badge is inaccurate. Scope depends on the organisation’s role, system, content and use.
The AI Act provides an exception for public-interest text that has undergone human review or editorial control where a natural or legal person holds editorial responsibility. A symbolic approval click is weak evidence. Organisations should document what was reviewed, by whom and who owns the final publication.
For clearly artistic, creative, satirical or fictional works, deepfake disclosure should not hamper enjoyment of the work. Specific exceptions also apply to legally authorised law-enforcement use.
Systems interacting directly with people are another Article 50 area. Users should be informed that they are interacting with AI unless this is obvious to a reasonably informed person in the circumstances. Apply this alongside the controls in our secure chatbot deployment guide.
Company preparation plan
- Inventory systems and content flows. Record which tools create text, image, audio or video, who publishes output and for what purpose.
- Determine the legal role. A provider placing a system on the market has different duties from a marketing team using a third-party model.
- Classify content risk. Separate deepfakes, real-person media, public-interest communication, chatbots and internal drafts.
- Test provenance persistence. Check export, compression, resizing and real publishing platforms—not only the generator.
- Design human-readable disclosure. It must be accessible and visible in context. The Commission also provides EU icons for AI-generated content.
- Document editorial control. Define acceptance criteria, owner, revision trail and publication responsibility.
- Retain evidence. Sample files, detection results, screenshots and change logs demonstrate operation better than policy text alone.
Detection remains imperfect
Machine-readable markers can be removed and detectors can be wrong. The code does not promise perfect detection of arbitrary internet content. Screenshots, repeated compression and rewritten text may lose provenance signals.
A mature process combines marking at source, provenance, visible disclosure, editorial control and documentation. From 2 August, the objective is not a mandatory badge on every AI-assisted artefact. It is a specific transparency regime for defined providers, deployers, systems and content.
Sources: Commission and AI Board opinion, Code of Practice, signatory FAQ, EU AI Act.

