EU AI Act · Article 50 in force · marking deadline 2 December 2026
EU AI Act · Article 50(2) and 50(4)

Do you need to label AI-generated content under the EU AI Act?

Two duties, not oneMarking ≠ labellingThe decision, in order

The short version surprises most people: most AI-generated content on a normal website does not need a visible label. An AI-drafted product description, an illustration for a blog post, a generated background image on your pricing page — none of those carries a labelling duty under Article 50 in the ordinary case.

What confuses this is that the Act imposes two different duties on AI-generated content, they land on different parties, and only one of them is a label a human reads. Getting them apart is the whole job.

On this page Two duties, one topicThe decision, in orderThe provenance gap nobody ownsIf you do label: where it goesLabelling more than the law requiresWhat an external check can and cannot see Common questions

Two duties, one topic#

Article 50(2) — machine-readable marking. Providers of AI systems that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This is invisible to readers: provenance metadata embedded in the file, typically C2PA Content Credentials or IPTC fields. It applies to essentially all generative output, well beyond the sensitive categories. And it is a duty on whoever provides the generative system — the model or tool vendor — not on you for publishing the result.

Article 50(4) — visible disclosure. Deployers must visibly disclose in two situations only: deepfakes, and AI-generated or manipulated text published to inform the public on matters of public interest. This is the label a reader sees, and it is the one that lands on the website owner.

So the honest answer to "do I need to label this?" is: probably not visibly, but the file should be marked, and that marking is probably being stripped somewhere in your pipeline.

The decision, in order#

1. Is it a deepfake?

The Act's definition is narrower than everyday usage: AI-generated or manipulated image, audio or video content that resembles existing persons, places or events and would falsely appear to a person to be authentic or truthful. Generated art, abstract imagery, an obviously synthetic illustration, a product render that depicts nothing real — not deepfakes. A synthetic photo of a real street, a generated video of a real executive, a voice clone of a real person — yes.

If yes: visible disclosure required. There is a narrower regime for evidently artistic, creative, satirical or fictional work, where the disclosure must not spoil the display of the work, but the disclosure itself does not disappear.

2. Is it text published to inform the public on matters of public interest?

News-style content on matters of public concern. Your pricing page, a product description and internal documentation sit outside it. If yes, a visible disclosure is required unless the text has undergone human review and a natural or legal person holds editorial responsibility for it. That carve-out does a lot of work, and it is the subject of its own page: do AI-written finance, health, legal or news articles need a label?

3. Neither?

No visible label required under Article 50. You may still want one — more on that below — and the machine-readable marking duty on the generative system still exists regardless.

The provenance gap nobody owns#

Here is where the two duties collide in practice.

Article 50(2) is satisfied at the point of generation: the tool embeds C2PA Content Credentials or equivalent provenance metadata in the file. But between the generator and your published page, that metadata passes through an upload, an image optimiser, a resize, a format conversion, and a CDN — and metadata stripping is the default behaviour of most of that chain, not an unusual failure. Content that left the generator correctly marked routinely arrives on your site bare.

Whose problem is that? Strictly, 50(2) binds the provider, and you are not it. Practically, the unmarked file is on your domain, and the "is this AI?" question gets asked about your page. Nobody in your stack currently owns this, which is why it goes unnoticed.

Two things to do about it: check what your published files actually carry (download a few and inspect the metadata), and know which of your tools mark output in the first place — our per-generator guides cover what each tool embeds by default and what strips it. The mechanics of marking, and why metadata alone is fragile, are in C2PA vs watermarking vs metadata.

If you do label: where it goes#

Where a visible label is required, Article 50(5) sets the placement: clear and distinguishable, at the latest at the time of first exposure. First exposure differs by format — on the image, at the start of playback, near the headline rather than after the body. The Commission's Code of Practice on Transparency of AI-Generated Content, confirmed as adequate for demonstrating compliance, includes a uniform set of EU icons and text labels. Using them is not the only way to disclose, but it is the clearest signal of good faith available.

The official EU icons, when each applies, and where the label goes by format.

Labelling more than the law requires#

Plenty of publishers label AI-assisted content that carries no legal duty at all, and there are decent reasons to:

One rule is cheaper than a judgement call per asset
"We label AI-generated imagery" is a policy a team can execute. "We label it when it resembles existing persons, places or events and would falsely appear authentic" is a determination someone has to make, correctly, under deadline.
Platform and marketplace rules are their own regime
Several major platforms require AI-content disclosure independently of the AI Act, with their own definitions and their own enforcement.
Other jurisdictions are not aligned
California SB 942 has its own scope and its own definitions, and became operative the same day.

The cost is that a label on everything dilutes the signal, and over-labelling has its own honesty problem — declaring something AI-generated when a human wrote it is its own kind of inaccurate statement. Pick a policy, write it down on a public page, and apply it consistently.

What an external check can and cannot see#

Worth being precise, because this is where automated tooling gets oversold.

An external scan can observe: whether published media carries machine-readable provenance marking, whether visible AI-content labels appear on article-like pages, and whether an AI-use or editorial policy page exists.

It cannot observe: whether a given image is in fact AI-generated, whether a human reviewed a given article, or who holds editorial responsibility for it. We do not attempt statistical AI-text detection and we never report a compliance verdict — Article 50(4) turns on your own declaration and your own editorial process, which no crawler can inspect. What a scan gives you is the observable half, dated and sealed. The free scan samples your published media for provenance marking and checks article-like pages for visible labels.

Check both signals at once. One free scan samples your published media for machine-readable provenance marking and checks article-like pages for visible labels, sealed into a dated record. Run the free scan →

Common questions

Does every AI-generated image on my website need a visible label?

No. Article 50(4) requires visible disclosure in two situations only: deepfakes, and AI-generated text published to inform the public on matters of public interest. An AI illustration for a blog post, a generated background image, or an AI-drafted product description carries no visible labelling duty in the ordinary case. The separate machine-readable marking duty under Article 50(2) still applies to the generative system's output, but that falls on the provider.

What counts as a deepfake under the AI Act?

The definition is narrower than everyday usage: AI-generated or manipulated image, audio or video content that resembles existing persons, places or events and would falsely appear to a person to be authentic or truthful. Generated art, abstract imagery and product renders depicting nothing real are not deepfakes. A synthetic photo of a real street, a generated video of a real executive, or a voice clone of a real person is.

What is the difference between marking and labelling?

Marking, under Article 50(2), is machine-readable, invisible to readers, and a provider duty — provenance metadata such as C2PA Content Credentials embedded in the file. Labelling, under Article 50(4), is a visible human-facing deployer duty. It applies only to deepfakes and public-interest AI text. You can satisfy one and fail the other in either direction.

Our images arrive on the site without any provenance metadata. Whose problem is that?

Strictly, Article 50(2) binds the provider of the generative system, not you for publishing the result. Practically, the unmarked file is on your domain and the question gets asked about your page. Between the generator and your published file sit an upload, a resize, a format conversion, an optimiser and a CDN, and stripping ancillary data is the default behaviour of most of that chain — which is why content that left the generator marked routinely arrives bare.

Should we label AI content even when the law does not require it?

It is a defensible choice. One rule is cheaper to execute than a per-asset legal judgement, several major platforms require AI-content disclosure under their own definitions, and other jurisdictions are not aligned with the EU. The cost is dilution, and over-labelling has its own honesty problem. Pick a policy, publish it, and apply it consistently.

Sources and further reading

Last updated September 2026. Informational only, not legal advice: this page describes what the text of the EU AI Act says and what an external check can observe, not whether any particular site complies. Corrections welcome at hello@disclosureproof.com.