The EU AI Act is Regulation (EU) 2024/1689 on artificial intelligence, and since 2 August 2026 its transparency obligations have applied in full. For a company that publishes, they ask two things.

An AI-generated image, video or voice that would falsely appear authentic carries a visible label. Text published to inform the public on matters of public interest carries one too, unless it has been through human review and someone holds editorial responsibility for it.

TL;DR. Producing content with AI remains permitted, and the regulation only asks you to disclose it in defined situations. The duty falls on whoever decides how AI is used, the deployer. In our work the deployer is us, so we treated the regulation as a production-process problem and wrote our rules before publishing this article.

We write about the AI Act as people who apply it. We use language and image models every day, for ourselves and for the companies we work with, so every paragraph below concerns us directly.

This article is informational and does not replace advice from a lawyer who knows your situation. What it does offer is an exact reading of the legal text, a clear account of what the Commission has published, and a description of what we decided to do about it.

Thirteen days before the deadline, on 20 July 2026, the European Commission published its Guidelines on the Article 50 transparency obligations, alongside a code of practice on marking and labelling AI-generated content. The Guidelines matter in practice, because they translate the regulation into concrete production situations.

What did the AI Omnibus actually postpone?

The AI Omnibus pushed back the rules for high-risk systems, while Article 50 transparency came into application on schedule. The simplification package was proposed on 19 November 2025 and entered into force on 27 July 2026. Headlines compressed that into “the AI Act has been delayed”, and much of the confusion still in circulation started there.

According to the Commission’s official implementation timeline, the regulation entered into force on 1 August 2024 and became applicable on 2 August 2026. Rules for high-risk systems listed in Annex III now apply from 2 December 2027, and those for systems embedded in products under Annex I from 2 August 2028.

Article 50, Article 4 and the prohibited practices kept their dates. The part of the regulation that touches marketing, communication and published content has already applied for almost two months.

What Date Status today Source
Prohibited practices (Art. 5) and AI literacy (Art. 4) 2 February 2025 applies European Commission, 2026
General-purpose AI model obligations and governance 2 August 2025 applies European Commission, 2026
Transparency, Article 50 2 August 2026 applies European Commission, 2026
New prohibitions added by the Omnibus 2 December 2026 upcoming JURIDICE.ro, 2026
High-risk systems, Annex III 2 December 2027 postponed by the Omnibus European Commission, 2026
High-risk systems embedded in products, Annex I 2 August 2028 postponed by the Omnibus European Commission, 2026

The Omnibus brought two further changes that rarely make the summaries. It banned systems that generate non-consensual sexually explicit content, including nudification apps, and it simplified the AI literacy requirement for companies, giving the Commission and member states a stronger role. Both appear in the Commission’s announcement of 27 July 2026.

What does Article 50 require, paragraph by paragraph?

Article 50 holds four obligations with different addressees, and most of the unnecessary worry comes from mixing them up. A company ends up taking on duties that belong to the model provider while walking past the ones that are genuinely its own. The quotations below come from the official text of Regulation (EU) 2024/1689 on EUR-Lex.

Art. 50(1), direct interaction. Providers design systems that talk to people so that “the natural persons concerned are informed that they are interacting with an AI system”, unless that is obvious. The legal duty sits with the provider, yet the company that puts an assistant on its website decides whether the disclosure stays visible in the interface.

Art. 50(2), machine-readable marking. Providers of generative systems ensure that outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated”. This belongs to the companies that build the models, such as Anthropic, OpenAI or Google, and a company that only uses those models has nothing to configure here.

Art. 50(3), emotion recognition and biometric categorisation. Deployers of these systems inform the people exposed to them. The paragraph becomes relevant for facial expression analysis, emotional targeting or mood detection tools in retail.

Art. 50(4), visible labelling. This is the duty that reaches an ordinary company. Deployers generating deep fakes “shall disclose that the content has been artificially generated or manipulated”. The same rule covers text published on matters of public interest, with an exception we discuss separately, because almost all compliance work on the written side depends on it.

Art. 50(5), timing. The information must be provided “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”. A disclaimer in the site footer or buried in the terms and conditions arrives too late and too far from the content it describes.

Diagram of the AI Act timeline showing Article 50 transparency in force from 2 August 2026 and high-risk obligations postponed to 2027 and 2028
What the Omnibus moved, and what came into application on schedule.

Who is the deployer when a partner produces your content?

The deployer is the person under whose authority the AI system is used, meaning whoever decides whether AI is used and how. Technical control over the model is not required. The Commission’s Guidelines settle the case where a company commissions content from a partner, and Bird & Bird’s analysis of 22 July 2026 summarises it clearly.

A company that merely commissions a creative agency to produce an advertisement, without deciding whether and how the agency uses AI, is not a deployer, and the obligation sits with the agency. Employees, contractors and other external staff working within a company’s procedures and under its control are not separate deployers. The label follows decision-making control over AI use.

For us, the consequence is direct. When we decide that a text is written with a model, which model and how it is reviewed, the deployer is us, not the company we work for and not the model provider.

Our internal compliance file also records the limit of a contract, which can govern the relationship between the parties but does not change who took the decision.

The reverse case exists as well. If a company decides by itself where AI is used and under which rules, and the partner only executes, the labelling duty stays with that company, and the process behind it needs to exist in writing.

Do you have to label AI-generated images?

Yes, if the image is photorealistic and depicts people, objects, places or events that could plausibly exist. This is where the real exposure sits, because the legal definition of a deep fake is far broader than the everyday meaning of the word.

During the public consultation, many respondents asked the Commission to read “existing” in the deep fake definition as covering only what exists or has existed. According to Bird & Bird’s reading of the final Guidelines, the Commission declined.

A subject counts as existing if it exists, can plausibly exist or could plausibly have existed, so a photorealistic portrait of an invented person stays inside the definition. The Guidelines also name digital replicas of real people and realistic AI avatars or personas.

Photorealistic portrait of a woman who does not exist, AI-generated, carrying the official EU AI GENERATED label in the lower right corner
The woman in this photograph does not exist. The image is AI-generated and carries the official EU label, because the Guidelines cover invented people too.

For a company using an AI-generated spokesperson, the conclusion is simple. Even though the person in the image does not exist, the image needs a label, because the audience reads that face as a real human being.

The only remaining valve is the falsely-authentic criterion. The Guidelines call for an overall assessment made from the perspective of the reasonably foreseeable audience, with a lower threshold where that audience includes children or other vulnerable groups. Bird & Bird expects this assessment to be challenging for many organisations to operationalise, since it often requires case-by-case decisions.

On advertising, the Commission gave concrete examples, and they are worth reading as written.

Situation Verdict Source
Real product shown against an AI-generated background acceptable without a label, provided the ad does not mislead about the product, its characteristics or use Guidelines, via Bird & Bird
AI image that makes the product look different from, or better than, reality deep fake, label required Guidelines, via Bird & Bird
Photorealistic portrait of an invented person inside the definition, label required Guidelines, via Bird & Bird
Realistic AI avatar or persona used as a spokesperson inside the definition, label required Guidelines, via Bird & Bird

The regulation does contain a lighter regime for content forming part of an “evidently artistic, creative, satirical, fictional or analogous work or programme”. There, disclosure can be made in a way that does not spoil the work. For advertising, that door is nearly closed.

Every advertising example in the Guidelines is classified as not benefiting from the reduced regime, and Bird & Bird concludes that the scope for relying on it in advertising appears very narrow. An advertisement that calls itself creative remains, in the Commission’s reading, commercial content.

The rule in our internal file puts the label on the image itself. A post description disappears once the image is downloaded or reshared, while Article 50(5) requires the information to reach people at the first exposure, wherever they happen to see the image.

When does AI-written text need a label?

Text needs a label when it is published to inform the public on matters of public interest and nobody holds editorial responsibility for it. The condition comes from Art. 50(4), and the exception has two parts that must both be met.

The law exempts text where “the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content”. The first part is a process. The second is a person who answers for the result.

Skimming a draft meets neither condition. A review process without an identifiable signatory meets only the first, which is not enough. The exception works only when there is both a real workflow and a person or company willing to put its name to the publication.

In our reading, public interest covers far more than politics. Health, the environment, consumer protection, the economy and finance all fall inside it, which pulls in press releases, investor communication and blog articles that give advice on money or health.

For a company that writes a lot with AI, the exception matters more than the label. A documented review process with a named person who signs off removes the labelling duty on text, however much of the text the model produced.

The share of AI in an article appears nowhere in the regulation, and what counts is whether a human answers for it.

What is the watermark in AI models, and who does it bind?

A watermark is the invisible technical marking a provider embeds in generated text so that it can be recognised automatically as model output. It answers Art. 50(2), and it is the model provider’s duty.

Anthropic explained on 14 August 2026 how the Claude text watermark works, after signing, in July 2026 and alongside roughly 190 other signatories, the EU Code of Practice on Transparency of AI-generated Content. Other major model developers signed the same code.

The mechanism is simpler than it sounds. A model writes one word after another, and where several words fit equally well, the choice is settled at random.

The watermark changes the source of that randomness, using a key held by the provider and a few preceding words, so whoever holds the key can estimate how likely it is that the model wrote the text.

Three details from Anthropic’s explanation matter to a company. The watermark carries no identifying information and cannot be traced to a specific person, organisation or chat. Light editing probably will not remove it completely, while a complete rewrite in which every word is replaced will.

The third detail is the legal one. According to the same explanation, the watermark does not change who owns a piece of text or who is legally responsible for it. It only helps test whether the model produced or processed the content.

This is where an expensive confusion begins. The marking in paragraph 2 and the visible label in paragraph 4 are separate duties with different addressees. A mark only a machine can read does not inform the person reading the text, so it cannot stand in for review and editorial responsibility.

There is also a positioning consequence. Anthropic already offers a detection API in private preview, for regulators, media, researchers and enterprises that must verify the marking for their own compliance. The gap between raw model output and text written and owned by a person becomes measurable from the outside for the first time.

Which content needs a label, and which does not?

The table below is our working orientation, built on Article 50 and the examples in the Guidelines, and it is not legal advice. Rows marked “depends” need a case-by-case call, exactly as the overall assessment described above requires.

What you publish Visible label Documented human review
One-to-one email to a prospect no, this is not publication to the public advisable
Commercial newsletter with no public-interest claims no advisable
Brand copy or landing page with no public-interest claims no advisable
Blog article on a neutral commercial topic no yes, as a safety net
Blog article on health, money, environment, science or politics yes, unless you have documented review yes, the preferable route
AI-generated press release yes, unless you have documented review yes
Text-only social post depends on the topic yes
Poster or banner with photorealistic AI people yes not applicable
Poster or banner with graphics, stylised illustration, typography no not applicable
Product shot with a real product on an AI background no, provided it does not mislead not applicable
Product shot generated entirely with AI depends, yes if it passes for a real photograph not applicable
Video of a real person filmed for real, with subtitles and motion graphics no not applicable
Video with an AI avatar or cloned voice yes not applicable
Before and after generated or retouched with AI yes not applicable
Chatbot or agent on a website yes, disclosed in the interface not applicable
Agent sending messages on someone’s behalf yes, plus on whose behalf it acts not applicable
Translation, proofreading, stylistic polish no, this is standard editing not applicable
Alt text, short descriptions, interface labels no, in our reading not applicable
Decision tree for labelling AI-generated content, with branches for photorealistic imagery, public-interest text and conversational interfaces
Three questions separate content that needs a label from content that does not.

The table has one limit worth saying plainly. It describes what gets published, yet it does not say who decided to use AI for each piece. Without that answer, even the best table cannot tell you who applies the label.

On which layer of a company is EU AI Act compliance solved?

EU AI Act compliance is solved on layer L3, orchestration and memory, and from there it reaches the other three. In our method a company works across four layers, from L1, performance marketing, and L2, revenue and commercial process, up to L3, orchestration and memory, and L4, positioning and category architecture.

L1, performance marketing. This layer holds ad visuals, banners and clips, exactly where photorealistic portraits and AI-“improved” products appear. The deep fake label is decided here, on every creative, before it enters a campaign.

L2, revenue and commercial process. This is where the website chatbot, the agent answering messages and the contracts with partners live. Paragraph 1 requires people to know they are talking to an AI system, and the contract is where you write down who decides on AI use.

L3, orchestration and memory. This layer holds the process that knows what gets published and who answers for it, meaning documented review, production rules and a log of decisions. The editorial exception in paragraph 4 is won or lost on this layer, because it requires a real process and a signatory.

L4, positioning and category architecture. This is where the market decides whether to trust what you say. In a market where raw model text becomes detectable, a company that signs what it publishes shows that it stands behind its own words, and that trust compounds over time.

The EU AI Act across the four layers of a company Four stacked layers, from L1 at the bottom to L4 at the top. Layer L3, documented review with a signatory, is marked in red, because that is where the editorial exception is won. THE AI ACT ACROSS THE COMPANY L4 · POSITIONING trust in what you sign L3 · ORCHESTRATION documented review and a signatory L2 · REVENUE disclosed chatbot and clear contracts L1 · PERFORMANCE label on the photorealistic visual
The label shows on L1, yet it is decided on L3, where the process knows what was produced with AI.

Order matters here. A company that labels on L1 without a process on L3 will label erratically, sometimes too much and sometimes not at all, because nobody knows what was produced with AI or who decided. For the full picture of the memory layer, we wrote separately about the AI Brain, explained for founders.

How do we work as an AI deployer ourselves?

We work with AI every day and we are deployers in the regulation’s sense, so we started with our own compliance file. We wrote it in August 2026, built on Article 50, on the Guidelines and on the enforcement situation in our home market, and on 26 September 2026 we adopted the five working rules it sets out. Since then they are the rules our production follows.

The first rule concerns images. It requires disclosure of a photorealistic visual that depicts a person, a place or an event, including an invented but plausible person. Abstract graphics, clearly stylised illustration and a generated background behind a real product stay unlabelled, as long as they do not mislead. The images in our articles are AI-generated and we say so openly, as the note at the end of this piece does.

The second rule concerns text. On matters of public interest, the rule requires documented review, with a person who takes responsibility for publication, and a quick “fine by me” on a draft does not count as review. Two of us read and check our articles before they go out, Daniel Roșca and I. On medical content, the text is also corrected by the physicians of the clinic we work for. They check the medical side, while the responsibility under the regulation for how we use AI stays with us.

The third rule concerns responsibility. It does not shift to the model provider or to the company we work for, as long as the decisions about AI use are ours. The fourth rule separates text from visuals, since the editorial exception covers text and there is no equivalent for images.

The fifth rule concerns advertising platforms, which have their own requirements for declaring AI-generated content, separate from the regulation. On Meta we declare ads with AI-generated visuals in Ads Manager, and we check the requirements of the other platforms, LinkedIn, TikTok and YouTube, one by one.

On this blog, every article goes through a mechanical rule check, a register check and a fluency reading recorded in a log, and publication requires the explicit approval of the person who signs. I sign this article, and the editorial note at the end states what AI produced and who answers for it.

We described separately how we use AI in marketing AI as a four-zone system. The rules above are the accountability part of that same system, the part that decides what goes out to the public and under whose signature.

Why do we treat the EU AI Act as a process problem?

Three principles from our methodology explain why EU AI Act compliance is solved through the way a company works. Labels and contract clauses come afterwards.

The first is infrastructure before marketing. It states that a company rarely has a marketing problem and far more often lacks infrastructure, meaning systems, channels, positioning and a brand foundation, and that marketing built on a weak base burns money.

Applied to the AI Act, the principle shows where compliance breaks. The label is the visible part, while what is usually missing is the process that knows what was produced with AI and who approved it. A company without that process risks paying lawyers to reconstruct after the fact what it could have documented at the time.

The second principle describes AI as a cognitive processor and a cognitive extension of the person using it, with output quality depending on how precisely you tell it where to think.

Article 50(4) says the same thing in legal language. The model can write the text, yet editorial responsibility is held by a person, and the exception exists only while a human decides and answers.

We developed that idea in our piece on AI as a cognitive processor in marketing. The European regulation took this division of labour and turned it into a legal condition for text that informs the public.

The third principle holds that AI learns from dialogue. It states that a methodology settles into an AI system through accumulated dialogue, and that a system trained on that body of work surfaces the recurring principles by itself and turns them into reusable rules.

For compliance, that has a practical consequence. Every decision about a label or a review should be saved together with its reason. Only then can evidence of review be shown to a client or an authority.

Where do sector rules cut deeper than the AI Act?

In regulated sectors, a professional body often constrains marketing more tightly than the European regulation does. Marketing for a clinic is not a high-risk system, so the strict regime with conformity assessment stays out of the picture.

What applies from the AI Act is narrower, namely the text rule for matters of public interest and the deep fake regime for generated imagery.

Romania offers a documented example of the second layer. Decision no. 20 of 24 September 2025 of the Romanian College of Physicians was published in the Official Gazette no. 918 of 6 October 2025 and, under its Article 14, has applied since 1 January 2026.

The decision defines medical advertising as any form of communication meant to promote, directly or indirectly, the services, products, facilities or image of a healthcare provider. It requires real, verifiable and relevant information that does not mislead patients.

It also bars a medical unit from obliging a doctor or a patient to associate their image or voice with advertising pursued for financial or commercial gain. An AI-generated patient shown displaying a result sits uneasily with the requirement for real and verifiable information.

The file’s rule for healthcare starts from there. A workflow that satisfies the professional body is almost automatically compliant with the AI Act on text, while the reverse does not hold.

The same logic applies in financial services, pharmaceuticals and any other regulated sector, so before mapping the AI Act onto your content, check which professional body already regulates it more tightly.

Can you be fined where national enforcement is not yet in place?

The obligations apply regardless, and the practical exposure shifts rather than disappears. The regulation binds directly in every member state, while fines depend on national laws that set out procedures and penalties, and those laws are arriving at different speeds.

Romania is a documented case. The government designated its competent authorities, including the communications regulator ANCOM, by memorandum on 12 March 2026, yet the law setting out inspection procedures and penalties was still being drafted in August 2026. A government memorandum does not by itself confer inspection and sanctioning powers.

Empty official office at dusk with a stack of unsigned papers under a single lamp, AI-generated image labelled as such
The duty has applied since 2 August. What one member state still lacks is the law giving its authorities a mechanism to inspect and fine.

Alexandra Crasoveanu, who wrote the analysis published by JURIDICE.ro on 13 August 2026, names the mistake precisely, in Romanian. „Ar fi însă o eroare de analiză să se concluzioneze că, în absența legii naționale, obligațiile pot fi ignorate fără consecințe.”

In English, it would be an analytical error to conclude that the obligations can be ignored without consequences just because the national law is missing.

At European level, Article 99(4) of Regulation (EU) 2024/1689 sets administrative fines of up to 15,000,000 EUR or 3% of total worldwide annual turnover, whichever is higher. The transparency obligations fall in that category, as JURIDICE.ro also notes in 2026.

For SMEs, including start-ups, paragraph 6 of the same article reverses the rule, so whichever of the two amounts is lower applies. The maximum is a ceiling, and national law will set the concrete regime.

The practical exposure comes from three directions. The obligations have applied since 2 August and are not suspended, and for general-purpose models the Commission holds its own enforcement powers regardless of any national law. Exposure also becomes concrete when you operate in another member state or when your audience crosses a border.

Contractual and reputational risk stays intact. Breaching a legal obligation can ground civil liability, and a large client running its own compliance programme will ask its suppliers for guarantees, whatever a national authority can do today.

What is already due, whatever the size of your company?

Article 4, AI literacy, has applied since 2 February 2025 to any organisation providing or using AI systems, with no employee threshold. The original text of the regulation asks providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff”.

The Omnibus simplified that requirement for companies, with the Commission and member states taking a stronger role in promoting AI literacy, according to the announcement of July 2026. The obligation remains, and only its form was relaxed.

In practice this means a documented measure covering the people who use AI inside the company, from who may use which model to what they check before publication. Of every obligation described here, it is the easiest to resolve and also the one that has applied for the longest.

What should you do on Monday morning?

The sequence that produces the most effect for the least effort has five steps, and you can start all of them this week.

  1. Inventory the content that goes out to the public and run it through the table above, to see where you hold photorealistic visuals and where you publish on matters of public interest.
  2. Decide who chooses to use AI for each type of content, because that answer determines who the deployer is.
  3. Formalise human review on text, with a named person who signs off, because that is where the labelling duty disappears entirely.
  4. Put the label on the images that need one, directly on the image, and disclose conversational assistants in the interface, at the first interaction.
  5. Document your AI literacy measure, the duty that has applied for the longest.

All five steps ask for the same thing, a production process that knows what it publishes and who answers for it. A company that already runs one pays for compliance in documentation, while a company without one discovers that the problem sits in how it works, which the regulation merely makes visible.

If you want to see where the chain breaks in your company, from the visual in an ad to the person who signs the text, ask for a diagnostic. We will show you which layer is missing a process and what is worth documenting first.

Frequently asked questions

Does the EU AI Act ban the use of AI in marketing?

No. The regulation does not prohibit producing content with AI. It requires transparency in defined situations, meaning a visible label on photorealistic visuals that would appear authentic and on public-interest text published without human review and without a person holding editorial responsibility.

Is a disclaimer in the post description enough for an AI-generated image?

For an image that qualifies as a deep fake, the safe option is a label placed on the image itself. Art. 50(5) requires the information to be clear and distinguishable at first exposure, and a post description is lost as soon as the image is downloaded or reshared.

Do I have to label a blog article written with AI assistance?

It depends on the topic and the process. If the article informs the public on a matter of public interest and nobody reviewed it or holds editorial responsibility, the label becomes mandatory. A documented review process with an identifiable author removes the duty.

Who is responsible, the company or the partner producing the content?

Whoever decides whether and how AI is used. According to the Guidelines, a company that merely commissions an advertisement without deciding on AI use is not a deployer, and the obligation sits with the partner who took that decision. A contract clarifies the relationship between the parties but does not change who decided.

Does the model’s watermark release me from the visible label?

No. The watermark is the model provider’s duty under Art. 50(2), and it is read by a machine. The visible label and the editorial exception in paragraph 4 are separate obligations that concern the person who sees the content.

Editorial note

This article was researched and written with AI assistance, was read and checked by the author and by Daniel Roșca, and editorial responsibility for its publication rests with the signed author, for UNRIVALS. The photorealistic images in this article are AI-generated and carry the corresponding label. Sources were re-checked on 26 September 2026.

The material is informational and does not replace advice from a lawyer. For a concrete decision, especially in a regulated sector, it is worth consulting a lawyer who knows your situation.

Sources

Legal text is quoted only from EUR-Lex, and the application timeline comes from the European Commission’s official pages.