# The EU AI Act: what content must be labelled from August 2026

Source: https://unrivals.com/blog/eu-ai-act-labelling-ai-generated-content/
Site: UNRIVALS · Language: en · Updated: 2026-08-21

> Headlines said the AI Act had been postponed. What moved was the high-risk chapter. The transparency obligations have applied since 2 August 2026, and they land on what a company publishes every day.

---
The AI Act is Regulation (EU) 2024/1689, and since **2 August 2026** its transparency obligations apply in full. They ask two things of the company doing the publishing. A photorealistic AI-generated visual depicting people, products, places or events carries a visible label. Text published to inform the public on matters of public interest carries one too, unless it has been through a human review process with editorial responsibility assumed by someone identifiable. Producing content with AI remains permitted. What the law regulates is the disclosure of it, in defined situations.

Thirteen days before that date, on 20 July 2026, the European Commission published its [final Guidelines on the Article 50 transparency obligations](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations), together with a code of practice and an official icon set for labelling AI-generated content. The Guidelines are the document that matters in practice, because they translate the regulation into concrete production situations.

## What did the AI Omnibus actually postpone?

The simplification package known as the AI Omnibus entered into force on 27 July 2026 and pushed the high-risk system obligations to December 2027 and August 2028. Press coverage compressed that into "the AI Act has been delayed", and the confusion started there. Article 50 was not postponed. Article 4 was not postponed. The prohibited practices stayed where they were. The part of the regulation that touches marketing, communication and published content came into application on schedule.

| What | Date | Status today |
|---|---|---|
| Prohibited practices (Art. 5) and AI literacy (Art. 4) | 2 February 2025 | in force, penalties since 3 August 2026 |
| General-purpose AI model obligations and governance | 2 August 2025 | in force |
| **Transparency, Article 50** | **2 August 2026** | **in force** |
| Marking for generative systems already on the market | 2 December 2026 | transition period |
| High-risk systems, Annex III | 2 December 2027 | postponed by the Omnibus |
| High-risk systems embedded in products, Annex I | 2 August 2028 | postponed by the Omnibus |

The Omnibus also brought in two things that rarely make the summaries. It banned systems generating non-consensual sexually explicit content, including nudification apps, and it strengthened the European AI Office.

## What does Article 50 require, clause by clause?

Article 50 holds four separate obligations with different addressees. Mixing them up produces most of the unnecessary panic, because a company takes on duties that belong to the model provider and walks past the ones that are genuinely its own.

**50(1), direct interaction with an AI system.** A person must be told clearly that they are dealing with an AI system. The Guidelines spell out what does not count, namely a mention buried in terms and conditions, the generic word "assistant", a machine-readable mark on its own, and a platform-level disclaimer of the "services on this website use AI" variety. Agents fall squarely in here. An agent that books, handles correspondence or sends messages must disclose both its artificial nature and on whose behalf it acts, in any situation where interaction with a natural person is reasonably likely.

**50(2), machine-readable marking.** This obligation belongs to the provider of the generative system, meaning OpenAI, Anthropic, Google, Midjourney or fal.ai. A company using those models has nothing to configure here.

**50(3), emotion recognition and biometric categorisation.** The duty to inform sits with the deployer. It becomes relevant for facial sentiment analysis, emotional targeting or mood detection tools in retail.

**50(4), visible labelling.** This is the obligation that reaches an ordinary company, and it falls on whoever decides to publish. Two categories must be disclosed visibly, at the point of first exposure, namely deepfakes and text published on matters of public interest without editorial control.

![Diagram of the AI Act timeline showing Article 50 transparency in force from 2 August 2026 and high-risk obligations postponed to 2027 and 2028](https://unrivals.com/assets/blog/eu-ai-act-labelling-ai-generated-content/01-calendar-ai-act.jpg)

What the Omnibus moved, and what came into application on schedule.

## Do you have to label AI-generated images?

If the image is photorealistic and depicts people, products, places or events that could plausibly exist, the answer is yes. This is where the real exposure sits, because the legal definition looks nothing like the popular meaning of the word deepfake.

During the public consultation, many participants asked the Commission to narrow the "existing" criterion to persons and places that do or did exist. The Commission declined. The final Guidelines establish that content depicts an existing subject if that subject exists, could plausibly exist, or could plausibly have existed. The direct consequence is that a photorealistic portrait of an entirely invented person falls inside the definition. So do digital replicas of real people, realistic avatars and AI personas, and a person's voice or performance.

![Photorealistic portrait of a woman who does not exist, AI-generated, carrying the official EU AI GENERATED label in the lower right corner](https://unrivals.com/assets/blog/eu-ai-act-labelling-ai-generated-content/03-persoana-care-nu-exista.jpg)

The woman in this photograph does not exist. The image is AI-generated and carries the official EU label, because the Guidelines cover invented people too.

The only remaining valve is the fourth criterion, appearing falsely authentic. The Guidelines require a holistic assessment covering the degree of resemblance to reality, the underlying message, the intended and reasonably foreseeable distribution context, the medium, and the composition and expectations of the foreseeable audience. Where an audience does not expect content to be authentic, that content may fall outside the definition even when it is synthetic. Bird & Bird notes, fairly, that this assessment will be hard to operationalise, since it forces a judgement call on every piece.

On advertising, the Commission gave explicit examples, and they are worth reading as written.

| Situation | Verdict |
|---|---|
| Real product photographed against an AI-generated background | acceptable without a label, provided the ad does not mislead about the real product |
| AI image that makes the product look different or better than it is | deepfake, label required |
| Photorealistic human or non-human characters, AI-generated | label required |
| Product shots generated entirely with AI | label required |

The regulation does contain a lighter regime for content that is evidently artistic, creative or satirical, where disclosure can be made without spoiling the work. The final Guidelines narrow that opening sharply. Purely informative or commercial content does not benefit from the relaxed regime, and where informative and creative character mix, the informative character always prevails. Every advertising example in the Guidelines is classified as not benefiting, and Bird & Bird concludes that the scope for relying on relaxed labelling in an advertising context looks very narrow.

One technical detail decides whether your label works at all. The display rules in the code of practice require the label to stay visible when content is redistributed or downloaded. For social media that means a disclaimer written only in the caption does not cover a visual that qualifies as a deepfake. The label has to live on the image.

## When does AI-written text need a label?

The labelling duty applies to one category of text, namely text published to inform the public on matters of public interest. The Guidelines define that broadly and include public administration, fundamental rights, health, the environment, consumer protection, plus economic, financial, political, scientific and cultural developments with social relevance. In advertising and PR, the duty can reach AI-generated claims about products and press material touching health, safety, environment, economy or finance. Companies using AI for corporate reporting or investor communication sit in the same category.

The valve is what matters most in practice. The obligation does not apply where the text has undergone human review or editorial control and where a natural or legal person assumes editorial responsibility for publication. Both conditions are cumulative, and the Guidelines read the exception narrowly. Skimming a draft is not a review process. What is required is a real workflow with an identifiable person taking responsibility.

Davis+Gilbert points out that this exception is [particularly significant for agencies and communications professionals](https://www.dglaw.com/eu-ai-act-guidance-expands-ai-disclosure-rules-for-advertisers-and-pr-teams/) folding AI into existing creative workflows. Translated into operations, a well-documented human review process removes the labelling duty on text entirely, and it remains the cheapest route to compliance on the written side.

## What is the watermark in AI models, and who does it bind?

A watermark is the invisible technical marking a model provider embeds in its outputs so they can be detected automatically as AI-generated. The obligation belongs to the provider, not to the company using the model. [Anthropic implemented text watermarking in August 2026](https://www.anthropic.com/news/claude-text-watermark), alongside roughly 190 signatories of the code of practice on transparency of AI-generated content.

The mechanism is simpler than it sounds. A language model picks words one at a time, and at each step several plausible candidates compete, with the choice between them normally random. The watermark changes the source of that randomness, using a key held by the provider together with the preceding words. For a reader the text stays identical. For whoever holds the key, the sequence becomes verifiable.

Three points are worth keeping. The watermark identifies the model rather than the person or company that wrote the prompt, since neither the mark nor the key carries identifying information. Light editing probably does not remove it, while a full rewrite does, at which point it becomes debatable whether the text still counts as AI-generated. Images run on different technology, namely [C2PA content credentials](https://c2pa.org/), a cryptographically signed note in the file metadata, the same open standard camera manufacturers use.

The expensive confusion is a different one. A machine-readable mark does not release you from the visible label, and the visible label does not stand in for the mark. They are two separate obligations with two different addressees, and the Guidelines state plainly that a marking only a machine can read does not satisfy the duty to inform a human being.

## Which content needs a label and which does not

The table below is a working orientation rather than legal advice. Rows requiring a case-by-case call are marked as such, because the Guidelines demand the holistic assessment described above.

| What you publish | Visible label | Documented human review |
|---|---|---|
| One-to-one email to a prospect | no, this is not publication to the public | advisable |
| Commercial newsletter with no public-interest claims | no | advisable |
| Brand copy or landing page with no public-interest claims | no | advisable |
| Blog article on a neutral commercial topic | no | yes, as a safety net |
| Blog article on health, money, environment, science or politics | yes, unless you have documented review | yes, the preferable route |
| AI-generated press release | yes, unless you have documented review | yes |
| Text-only social post | depends on the topic | yes |
| Poster or banner with photorealistic AI people | yes | not applicable |
| Poster or banner with graphics, stylised illustration, typography | no | not applicable |
| Product shot with a real product on an AI background | no, provided it does not mislead | not applicable |
| Product shot generated entirely with AI | yes | not applicable |
| Video of a real person filmed for real, with subtitles and motion graphics | no | not applicable |
| Video with an AI avatar or cloned voice | yes | not applicable |
| Before and after generated or retouched with AI | yes | not applicable |
| Chatbot or agent on a website | yes, disclosed in the interface | not applicable |
| Agent sending messages on someone's behalf | yes, plus on whose behalf it acts | not applicable |
| Translation, proofreading, stylistic polish | no, this is standard editing | not applicable |
| Alt text, short captions, interface labels | no, outside scope | not applicable |

![Decision tree for labelling AI-generated content, with branches for photorealistic imagery, public-interest text and conversational interfaces](https://unrivals.com/assets/blog/eu-ai-act-labelling-ai-generated-content/02-arbore-decizie.jpg)

Three questions separate content that needs a label from content that does not.

## Where sector rules cut deeper than the AI Act

Healthcare is the clearest case of a sector where professional regulation bites harder than the European regulation does. Marketing for a clinic is not a high-risk system and does not appear in Annex III, so the strict regime with conformity assessment and technical documentation stays out of the picture. What does apply is that health sits explicitly among matters of public interest, so AI-written text about conditions, treatments or prevention needs documented human review, while AI-generated patient imagery, synthetic before and after shots or doctor avatars fall under the deepfake regime.

Romania offers a worked example of the second layer. [Decision 20/2025 of the Romanian College of Physicians](https://legislatie.just.ro/Public/DetaliiDocument/302792), in force since 1 January 2026, defines medical advertising as any communication that directly or indirectly promotes a provider's services or image, and it requires evidence-based, verifiable, non-comparative material. It prohibits guaranteed outcomes, superlative claims, a physician lending their image or voice to promotional productions outside their own institution's page, and before-and-after patient imagery. A production workflow that satisfies that decision will almost automatically satisfy the AI Act on the text side, while the reverse does not hold. The same logic applies in financial services, pharmaceuticals and any other regulated sector across the Union. Before you map the AI Act onto your content, check which professional body already regulates it more tightly.

## What happens where a member state cannot yet enforce?

The obligations apply regardless, and the practical exposure shifts rather than disappears. Romania is the instructive case. The government designated its competent authorities by memorandum on 12 March 2026, roughly seven months after the European deadline, naming the communications regulator as market surveillance authority and single point of contact.

![Empty official office at dusk with a stack of unsigned papers under a single lamp, AI-generated image labelled as such](https://unrivals.com/assets/blog/eu-ai-act-labelling-ai-generated-content/04-birou-fara-lege.jpg)

The duty has applied since 2 August. What one member state still lacks is the law giving its authorities a mechanism to inspect and fine.

 What is missing is the national act setting out control procedures and the penalty regime, and a government memorandum does not by itself confer enforcement powers. Until that law enters into force, [the authorities cannot issue fines](https://www.juridice.ro/843172/ai-act-se-aplica-in-romania-dar-nu-poate-fi-inca-sanctionat-ce-inseamna-vidul-legislativ-national-pentru-operatori.html) for AI Act breaches. At European level the ceiling for an Article 50 breach reaches 15,000,000 € or 3% of total worldwide annual turnover, whichever is higher.

Read honestly, a national enforcement gap changes the urgency without changing the duty. The obligations exist and apply. What is missing in that one jurisdiction is the mechanism to establish and sanction a breach. Exposure stops being theoretical the moment you operate in another member state, a complaint reaches an authority elsewhere, or your audience crosses a border. Contractual and reputational risk stays intact throughout, because a large client running its own compliance programme will demand guarantees from its suppliers whatever the local regulator can do today. The law will arrive, and obligations do not reset retroactively when it does.

## What is already due, whatever the size of your company

Article 4, AI literacy, is the most ignored obligation and the only one already open to penalties. It applies to any organisation providing or using AI systems in the European Union, with no employee threshold and no carve-out for small companies. The Omnibus softened the wording from ensuring a sufficient level of AI literacy to supporting its development, which turns it into an obligation of means rather than result. It was neither removed nor postponed, and national market surveillance authorities have been able to sanction non-compliance since 3 August 2026.

In practice this means a documented measure covering the people who use AI inside the company. It remains the cheapest of every obligation described here, and the only one already overdue.

## What to do on Monday morning

The sequence that produces the most effect for the least effort runs like this. Start by inventorying the content that goes out to the public and run it through the table above, to see where you hold photorealistic visuals and where you publish on matters of public interest. Then formalise human review on the text side, with a named person who signs off, because that is where the obligation disappears entirely. Put the label on the images that need one, embedded in the file so it survives redistribution. Disclose conversational assistants in the interface rather than in the footer. Document your AI literacy measure, the one duty already due.

All five moves share a single requirement. They need a production process that knows what it publishes and who answers for it, so a company that already runs one pays for compliance in documentation instead of money. A company without one discovers that the problem sits in how it works rather than in the regulation. If you want to see what a [content system with memory, rules and accountability](/ai-brain) looks like in place of improvisation, we can walk through your situation and show you where the chain breaks.

## Frequently asked questions

**Does the AI Act ban the use of AI in marketing?**
No. The regulation does not prohibit producing content with AI. It requires transparency in defined situations, meaning a visible label on photorealistic visuals that would appear authentic and on public-interest text published without editorial control.

**Is a disclaimer in the caption enough for an AI-generated image?**
Not when the image qualifies as a deepfake. The display rules require the label to remain visible after redistribution or download, which means it has to be embedded in the image itself.

**Do I have to label a blog article written with AI assistance?**
It depends on the topic and the process. If the article informs the public on a matter of public interest and nobody reviewed it or assumed editorial responsibility, the label becomes mandatory. A documented review process with an identifiable author removes the duty.

**Who is responsible, the company or the content partner?**
The Article 50(4) obligation falls on whoever decides to publish. The Guidelines do not settle the split between a company and the partner producing its content, which is why lawyers recommend an explicit contractual clause.

**What about content published before 2 August 2026?**
The transparency obligations apply to content generated and published from that date. For generative systems already on the market there is a transition period until 2 December 2026 on the technical marking side, an obligation that sits with the provider.

## Editorial note

This article was researched and written with AI assistance, went through human review, and editorial responsibility for its publication rests with the signed author, Daniel Ene, for UNRIVALS. The photorealistic images in this article are AI-generated and carry the corresponding label. The material is informational and does not replace legal advice.

## Sources

- [AI Act, European Commission](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
- [Regulation (EU) 2024/1689, full text](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689)
- [Guidelines on transparency obligations, Article 50](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations)
- [Code of practice on transparency of AI-generated content](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content)
- [Official EU labelling icons](https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content)
- [Bird & Bird on the final Guidelines](https://www.twobirds.com/en/insights/2026/european-commission-adopts-final-guidelines-on-ai-act-article-50-transparency-obligations-first-impr)
- [Davis+Gilbert on advertising and PR](https://www.dglaw.com/eu-ai-act-guidance-expands-ai-disclosure-rules-for-advertisers-and-pr-teams/)
- [Anthropic on how the text watermark works](https://www.anthropic.com/news/claude-text-watermark)
- [Decision 20/2025, Romanian College of Physicians](https://legislatie.just.ro/Public/DetaliiDocument/302792)
