Guides
EU AI Act: Do You Have to Label AI Images From Aug 2?
The EU AI Act transparency rules apply from August 2, 2026. What Article 50 actually requires when you publish AI images, video, and ad creative.

On August 2, 2026, the EU AI Act's transparency rules go live. If you generate AI images, run an AI persona account, or ship AI-made ad creative to anyone in Europe, Article 50 now applies to you. Not to your tool vendor alone: to you, the person hitting publish.
This is a practitioner's guide for the creator with a Midjourney subscription and an Instagram account rather than for a compliance department. Here is what the rules require, which of your work they touch, and the short list of things worth doing about it this week.
The short answer: do you have to label AI images?
It depends on what the image shows, not on whether AI made it.
There is no blanket EU obligation to stamp "AI-generated" on every synthetic image. The Act splits the job in two, and that split decides which of your work needs a label:
| Article 50(2) | Article 50(4) | |
|---|---|---|
| Who | The provider — the tool that generated it | The deployer — you, publishing it |
| What | Mark outputs as artificially generated | Disclose that the content is artificially generated |
| Form | Machine-readable. Metadata and watermarking, invisible to a viewer | Human-facing. Something a person actually reads |
| Trigger | All synthetic image, audio, video, text output | Only content that is a deepfake as the Act defines it |
Two consequences follow directly from that split.
Article 50 does not require a visible watermark on your images. The marking duty is machine-readable and it belongs to the model provider. Nothing in Article 50 tells you to burn "Made with AI" into a corner of the frame.
Your disclosure duty is narrower than "anything AI touched", but it is human-facing when it bites. It attaches to deepfakes, and the Act's definition of that word is doing a lot of work. We get to it below.
Are you a provider or a deployer? (You are almost certainly a deployer)
Every obligation in the Act is addressed to a role, so before anything else, find yours. The definitions are in Article 3 of Regulation (EU) 2024/1689.
A provider is whoever develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. That is Black Forest Labs, Google, OpenAI, Midjourney. It is also you, if you wrap a model in your own product and sell it under your brand.
A deployer is, verbatim:
a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity
So: you use the tool, you are the deployer. And note the carve-out at the end, reinforced by Article 2(10), which says the Regulation does not apply to deployers who are natural persons using AI systems "in the course of a purely personal non-professional activity".
That carve-out is real but it is thinner than people want it to be. Making AI art for your own amusement is outside the Act. The moment the activity is professional — a monetised creator account, a brand, a freelancer delivering client work, an AI persona running affiliate links — you are a deployer with Article 50(4) obligations. There is no follower threshold and no revenue floor. "Professional" is the line, not "big".
If you are outside the EU: territorial scope
Article 2(1) sets the territorial scope, and point (c) catches:
providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union
A creator in Austin whose AI-generated campaign runs to European audiences is inside that wording. This is the same extraterritorial architecture the GDPR made everyone familiar with, and it is deliberate.
The honest caveat: "output used in the Union" is not defined anywhere in the Act, and we could not find an authoritative Commission interpretation of it. Whether an organically-reaching Instagram post counts as output "used in the Union" the same way a paid campaign targeting Germany does is genuinely unsettled. Plan for the broad reading and you will not have to revisit it.
Article 50(4): the one that is actually yours
Here is the deployer obligation in full, from the Official Journal text:
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
Everything turns on "deep fake", which Article 3(60) defines as:
AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful
Read that as a two-part test, because both limbs have to be satisfied:
- Does it resemble something that exists? A real person, a real place, a real event, a real object or entity.
- Would it falsely appear authentic? Would an ordinary viewer take it for a real photograph or recording of that thing?
Now apply it to work people actually make:
| What you published | Deepfake? | Why |
|---|---|---|
| Photoreal AI persona presented as a real person | Yes, in substance | Resembles a human being and reads as authentic photography. The safest reading of the definition, and the highest-risk case if you get it wrong |
| A real celebrity, politician, or your CEO, synthesised | Yes, clearly | Existing person, appears authentic. This is the paradigm case |
| Photoreal AI product shot of your actual product | Likely yes | "Objects" is in the definition, and a photoreal render passes as a photograph |
| A real landmark or storefront, AI-generated | Likely yes | "Places" is in the definition |
| Obvious illustration, 3D render, or stylised art | No | Fails the "falsely appear authentic" limb |
| Invented fantasy character in an invented world | No | Fails both limbs — nothing existing is resembled |
| AI upscale, denoise, or colour grade of a real photo | No | Assistive editing that does not substantially alter the content |
The pattern: photorealism plus a real referent triggers it; style and invention do not. Which means the sharpest exposure sits precisely on the most commercially popular AI output right now — photoreal people, photoreal products, photoreal places.
Note also the second subparagraph of 50(4), which covers AI-generated text published to inform the public on matters of public interest. It carries its own escape hatch: the duty does not apply where the text underwent human review or editorial control and a person or company holds editorial responsibility for it. If you run an edited publication, that clause is the one to read closely.
How the artistic and creative exception works
The clause narrows the obligation rather than removing it. Where the content forms part of an evidently artistic, creative, satirical or fictional work, the duty is limited to disclosing the existence of generated content "in an appropriate manner that does not hamper the display or enjoyment of the work".
So you still disclose, but you get to do it in the credits rather than across the frame. A film can put it in the end titles; a fiction series can note it in the description. The narrower duty attaches to the work being evidently creative, not to the label you give it, so it does not reach a photoreal persona presented to an audience as a real influencer.
How and when the disclosure has to appear
Article 50(5) sets the manner:
The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.
Three practical constraints hide in that sentence. Clear and distinguishable rules out burying it in a hashtag wall. At first exposure rules out putting it below a "more" fold that a scrolling viewer never opens. Accessible means a screen reader has to reach it, which quietly rules out disclosure that exists only as pixels baked into an image.


What applies on August 2, and what quietly moved
The timeline in the original 2024 text is no longer the timeline in force, so it is worth setting out the current dates precisely.
On July 8, 2026 the EU adopted Regulation (EU) 2026/1744, the Digital Omnibus on AI. It was published in the Official Journal on July 24 and entered into force three days later. It amended the AI Act's application dates. Not a proposal, not a draft: law, already in force.
Article 50 was not delayed. Transparency lands on August 2, 2026 as originally scheduled. What moved was the high-risk regime.
| Date | What |
|---|---|
| Aug 1, 2024 | Entry into force |
| Feb 2, 2025 | Prohibited practices (Article 5) and the AI literacy duty (Article 4) |
| Aug 2, 2025 | General-purpose AI model obligations, governance, and the penalty regime |
| Aug 2, 2026 | General application. Article 50 transparency — chatbot disclosure, synthetic-content marking, deepfake disclosure |
| Dec 2, 2026 | Article 50(2) marking for generative systems already on the market before Aug 2, 2026 (new Article 111(4)). Also the new Article 5 prohibitions below |
| Dec 2, 2027 | Annex III high-risk systems — moved back from Aug 2, 2026 |
| Aug 2, 2028 | Annex I embedded high-risk systems — moved back from Aug 2, 2027 |
Two things in there matter to you directly.
Your tools got four extra months; you did not. The Omnibus inserted a new Article 111(4) giving providers whose generative systems were already on the market before August 2, 2026 until December 2, 2026 to comply with the machine-readable marking duty. Deployer disclosure under 50(4) has no such grace period. It bites on day one. So for the next four months you may well be publishing output from a major model that carries no provenance metadata at all, while your own duty to disclose is already live. Do not assume your tool has covered you.
A new prohibition lands December 2, 2026 that is aimed squarely at image generation. The Omnibus added prohibited practices covering AI systems that generate or manipulate realistic imagery of an identifiable person's intimate parts, or of an identifiable person in sexually explicit conduct, without that person's explicit consent, alongside a prohibition on AI-generated child sexual abuse material. These sit in the top penalty tier. For deployers the prohibition applies where you use the system for the purpose of generating such material. If you run any kind of open-ended image service, that is a content-policy item on your December roadmap, not a legal-department abstraction.
The tools: who marks, who does not
Article 50(2) is your provider's problem, but it becomes your problem the moment you need to demonstrate that AI-made content was properly marked. The landscape as of today is uneven:
- Google embeds SynthID across its Gemini, Imagen and Veo outputs, and added C2PA Content Credentials during 2026.
- OpenAI went C2PA-conformant and began embedding SynthID in generated images on May 19, 2026, with a public verification tool. Images, not video.
- Adobe Firefly has the most complete Content Credentials implementation of any major generator.
- Midjourney does not implement C2PA. Its outputs carry unsigned metadata that a single command-line tool strips.
- xAI's Grok takes the opposite approach: a visible watermark you cannot turn off. Per xAI's own FAQ, "Generated images and videos include a Grok watermark to indicate that the content was created with AI. There is no setting to remove the watermark." Its documentation makes no mention of C2PA or embedded provenance metadata.
- Any open-weights model you run locally marks nothing. There is no provider in the loop to impose it, and this is the structural hole no standard currently closes.
The uncomfortable follow-on: even where marking exists, it is fragile. C2PA manifests are metadata, and metadata gets stripped by re-encoding, screenshots, and platform pipelines — the C2PA project says so itself. That is precisely why OpenAI and Google stack a pixel-level watermark underneath the metadata layer. Treat provenance metadata as a signal that survives sometimes, not a guarantee, and never as a substitute for your own disclosure.
One more gap worth knowing: Article 50(2) asks for solutions that are effective and interoperable "as may be reflected in relevant technical standards", and there is no harmonised European standard for Article 50. C2PA is the de facto answer, but it is not named in the Act, and it remains a draft in the ISO process rather than a published standard. In practice that means providers are implementing Article 50(2) against the generally acknowledged state of the art, which is the benchmark the Article itself names, rather than against a certified one.
The Code of Practice, and the guidelines that landed thirteen days ago
Two official instruments arrived just before the deadline, and both are worth knowing about because they are the cheapest available evidence of good faith.
The Code of Practice on Transparency of AI-generated Content was finalised on June 10, 2026, and the Commission and the AI Board have confirmed it as an adequate voluntary tool for demonstrating compliance. The Commission's framing is exact and worth repeating: "Even though adherence to the code is voluntary, the transparency requirements under article 50 of the AI Act are legal obligations." Roughly 190 organisations had signed by the end of July, Meta among them.
The Commission also published guidelines on the transparency obligations shortly before the rules took effect. The useful line for anyone who is not going to sign a code of practice: providers and deployers who decline to adhere "will have to demonstrate compliance with obligations for marking and labelling of AI-generated content through alternative equivalently adequate means". Translation: nobody is forcing you into the Code, but if you skip it, the burden of showing you did something equivalent is yours.
Penalties, and what enforcement will realistically look like
Article 99 sets the ceilings. For breaches of Article 50 specifically, which the Article lists explicitly among the non-compliance grounds:
- Prohibited practices: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
- Article 50 transparency and most other obligations: up to €15 million or 3% of worldwide turnover, whichever is higher.
- Supplying incorrect information: up to €7.5 million or 1%.
- SMEs and start-ups: whichever of the two figures is lower, not higher. If you are a small company, the euro cap is a ceiling, not a floor.
Those are ceilings, and the practical picture sits a long way below them.
Enforcement runs through national market surveillance authorities, and Member States have been slow to stand them up. European Parliament research reported that as of March 2026 the list of notified single contact points "comprised eight single contact points, out of 27". As of today we found no AI Act enforcement action, fine, or formal investigation by any national authority or the AI Office — not one, anywhere. There is a live Commission proceeding against X over Grok, but it was opened under the Digital Services Act and concerns systemic risk rather than AI Act marking obligations.
So the near-term risk to a solo creator is not a nine-figure fine. It is more mundane and more likely: a complaint from a competitor or a member of the public, an advertising-standards or consumer-protection body reaching for the nearest applicable rule, a platform enforcing its own disclosure policy against your account, or a client contract that now includes an AI disclosure warranty you cannot honour. The AI Act's first practical effect on small creators will arrive through platforms and contracts, not through regulators.
Platform rules move faster than the law
Worth keeping in view, because in practice these will constrain you sooner than any authority will. YouTube requires disclosure of realistic synthetic content and reads C2PA credentials to apply its label automatically. TikTok has been the most aggressive, auto-labelling via C2PA since 2024 and adding its own invisible watermarking. Meta labels under "AI info". X does not currently publish an AI-content labelling policy.
None of these map cleanly onto Article 50, and none of them discharge your obligation. Platform AI policy is a moving target — the labels, their placement, and what triggers them have all changed more than once in two years, and they will change again. Build a disclosure habit that survives a platform rewriting its rules, rather than one that depends on a specific toggle continuing to exist.
What a solo creator or small brand should actually do this week
Realistically, this is an afternoon of work, most of it once.
- Sort your output into two buckets. Photoreal-and-references-something-real on one side, stylised-or-invented on the other. Only the first bucket needs deployer disclosure. If you have never done this, it is the highest-value hour in this list, because most creators discover the deepfake bucket is smaller than they feared and more concentrated than they expected.
- Write one disclosure line and reuse it. "This image is AI-generated." That is sufficient. It does not need legal language, and legal language makes it worse by burying the point.
- Put it where a viewer meets it first. Top of the caption, not the end of a hashtag block. Alt text as well as visible text, because 50(5) requires accessibility. On video, in the description and spoken or on-screen early.
- Turn on every platform AI-disclosure toggle you have. It is free, it is evidence of good faith, and on several platforms it is already contractually required of you independent of the Act.
- Check whether your generator marks its output. Run a file through a Content Credentials verifier. If the answer is no, your caption is doing all the work, and you should know that rather than assume otherwise.
- Handle AI personas explicitly. If you run a synthetic influencer, put the disclosure in the bio, not only in individual posts. A persona is a continuous representation, and a viewer's first exposure is often the profile.
- Keep a note of what you did and when. A dated page describing your disclosure practice costs nothing today and is the difference between "we have a policy" and "we will get back to you" if anyone ever asks.
- Diarise December 2, 2026. The provider marking grace period ends and the new prohibitions apply.
Labelling every asset you publish as a defensive reflex goes further than the Act asks. The line it draws is between content that could mislead someone about reality and content that obviously could not. Label what the definition catches, and leave your stylised work alone.
Where this connects to the rest of your stack
The disclosure question is easiest to answer at the point of generation rather than at the point of publishing, because that is when you still know what a given asset is. A photoreal persona shot, a stylised illustration and an upscale of a real photograph have very different obligations attached, and by the time three hundred files are sitting in a folder, nobody can tell them apart.
That is also the argument for keeping personas, products and campaigns as declared, persistent things rather than as one-off prompts. If you are building a synthetic creator, our guide to creating an AI influencer covers the production side, and AI-generated ads covers the campaign side. Both are now workflows with a disclosure step attached.
The short version
- Article 50 applies from August 2, 2026. It was not delayed by the Digital Omnibus, though the high-risk regime was pushed to December 2027 and August 2028.
- You are a deployer, not a provider, unless you ship a model under your own brand. Purely personal non-professional use is out of scope; monetised creator work is not.
- Your duty is to disclose deepfakes: photoreal content resembling a real person, place, object or event that would pass as authentic. Stylised and invented work is not caught.
- The machine-readable marking duty belongs to your tool vendor, and vendors whose systems shipped earlier have until December 2, 2026. Yours starts on day one.
- No visible watermark is required. A clear line at first exposure is.
- Ceilings run to €15 million or 3% of turnover for Article 50 breaches, lower of the two for SMEs — but there is not yet a single AI Act enforcement action anywhere, and most Member States have not finished designating authorities.
- Being outside the EU does not exempt you if your output is used in the Union.
We will update this post as the first enforcement decisions, national implementations and further Commission guidance land.




