The EU AI labeling obligation: what companies really need to label (and what not)

The EU's AI labeling obligation is here. That much has been clear for a while — yet many still don't know what the new rules actually mean in practice. For weeks, deadlines, fine amounts and scare stories have been circulating, some of them contradicting each other. Million-euro penalties for every unlabeled image. Mandatory disclosure for all AI-written text. And, in parallel, the all-clear: the AI Act has supposedly been postponed anyway.

In marketing departments, this leads to two reactions that both miss the mark. Some preemptively put an AI notice under every single piece of content. Others sit tight because they read somewhere that everything has been delayed.

In reality, the actual scope of the new obligations is fairly manageable — and for the vast majority of companies, only one thing genuinely changes. Time to shed some light, and to offer some reassurance.

What applies now

First, let's clear up a rumor: the labeling obligation is not being postponed. Some deadlines from the so-called Digital Omnibus are indeed being pushed back, but they concern an entirely different part of the EU AI Act — high-risk applications in recruiting, credit scoring and critical infrastructure.

The transparency obligations laid down in Article 50 of the regulation are applicable as of August 2, 2026.

The good news: this article contains just four obligations. Two of them address the providers of AI, and two their deployers.

Provider or deployer: who has to do what?

More good news: if you are reading this article, chances are very high that you are a deployer — which means only two new obligations apply to you.

Providers develop an AI system and bring it to market under their own name. That's OpenAI, Anthropic, Google, Midjourney or ElevenLabs. Their obligations are mostly technical: watermarks, signed metadata, detection tools.

Deployers, on the other hand, use an AI system under their own professional responsibility. That's agencies (like us), publishers, editorial teams, marketing departments, medical practices, associations, public authorities. The term "deployer" is deliberately broad and covers any professional use outside the purely private sphere.

Most companies are therefore deployers. For them, two obligations remain: disclosure for AI-generated image, audio and video content and — within narrow limits — for text.

A detail for everyday work: employees who use AI under instructions do not count as deployers in their own right. The responsibility sits with the company.

Most companies are deployers. Only two of the four Article 50 obligations apply to them.

Image, audio and video: this is where the real risk sits

As of August 2, deployers must disclose when image, audio or video content has been generated or manipulated by AI and qualifies as a so-called deepfake.

The term is somewhat misleading, though — colloquially we know it mainly as fabricated celebrity videos. The regulation means something considerably broader. Three criteria must come together:

  1. Resemblance to a person, an object, a place, an entity or an event
  2. Existence — it is enough that what is shown could plausibly exist
  3. A false appearance of authenticity, i.e. the capacity to mislead someone about whether it is real

The last two points are where most people miscalculate: a photorealistic, entirely invented face already meets the criterion, because such a person could plausibly exist — and such an image is also capable of misleading someone about its authenticity. The AI model in your social ads campaign is therefore subject to labeling, even though no real person was recreated.

Three criteria decide whether AI content counts as a deepfake. The second one surprises most people.

Also covered: AI avatars in explainer videos, cloned voices, AI lip-sync in translations of real footage, digital doubles, de-aging. The consent of a depicted person protects you against personality-rights claims — it does not exempt you from the labeling obligation.

The second surprise: intent to deceive is irrelevant. What matters is how the audience perceives the content, with particular regard to vulnerable groups such as children or the elderly. Good intentions in the creative process are not an argument.

Text: barely anything changes

For text, a much narrower rule applies — and it affects very few companies.

Labeling is required for AI-generated or AI-manipulated text that is published to inform the public on matters of public interest. The EU Commission counts among these politics, public administration, justice, fundamental rights, public security, public health, environmental protection and consumer safety.

Promotional copy falls outside. So do product descriptions, newsletters, social posts and landing pages. It becomes relevant for patient information, health guides, articles on consumer or environmental topics, and anything that presents itself as journalism.

And even there, an exemption applies: if the text has undergone human review or editorial control and a person carries editorial responsibility, the obligation lapses. If you have a working approval process, nothing changes here.

One caveat belongs in the picture. The Commission defines the exemption rather narrowly. What's required is a deliberate substantive review by someone with subject-matter expertise, with the authority to change or reject content, including fact-checking and source verification. Spell-checking explicitly does not qualify, nor does a cursory skim. The process should be documented and assigned to a named person — otherwise the exemption is worthless in a dispute.

What the label actually has to look like

The regulation demands disclosure in a clear and unambiguous manner, at the latest at first contact, and accessible.

The EU Commission's final guidelines of July 20, 2026 and the accompanying voluntary Code of Practice spell out what that means.

  1. The label belongs in the content. The recommended placement is directly in the image or video, for instance in the top right corner. A note in the caption or the Instagram copy does not suffice under this reading.
  2. Metadata alone is not enough. Deployers cannot rely on the machine-readable marking their tool embeds. The disclosure must be perceivable without technical aids.
  3. For spots, the label appears at the beginning and is repeated after interruptions, such as an ad break. For livestreams, the Code recommends a permanently visible icon.
  4. For pure audio, an audible notice takes the place of the mark. Under 30 seconds, a notice at the start suffices; for longer tracks it is repeated.
  5. For digital visuals, the label must travel with automated placements so it remains visible at first glance in every format.
The label belongs in the content itself, not in the caption.

On design: the EU provides a free icon set, in black and white, each also at 50 percent transparency, as SVG and PNG. Its use is voluntary. The German advertising industry's umbrella association notes in its July 20 guidance that the letters "AI" (or German "KI") or another recognizable designation are also permissible, and that the EU icon can serve as a template for your own. If you have to label anyway, you can translate the mark into your own visual language.

What does not need to be labeled

This part usually gets lost in the current coverage, even though it cuts the workload in half.

  1. Standard editing. Light and color correction, light cropping, denoising, removing incidental background noise. Such interventions do not normally change perceived authenticity.
  2. The obviously fictional. Cartoon characters, talking animals, mythical creatures, science-fiction scenarios. In its guidelines, the Commission cites a sphinx flying over the Eiffel Tower and mice arguing about cheese in human language. If everyone immediately recognizes it as fiction, no notice is needed.
  3. AI-generated backgrounds in advertising visuals, provided the background does not mislead about the advertised product. This clarification is new in the July 20 guidance.
  4. Purely internal use. If you use AI for research, meeting minutes, drafts or analyses without publishing the result, no obligation is triggered.
  5. Existing content. Content created before August 2 does not have to be labeled retroactively. If you re-run a campaign subject to labeling after the cutoff date, however, you label it.
  6. Promotional copy, see above.
Six exemptions that cut the workload in half.

Who is responsible — and what happens if labeling goes wrong?

An uncomfortable piece of information we'd rather state ourselves: outsourcing production does not shift the obligation.

The deployer remains the company under whose responsibility and control the system is used. Whether an agency, a freelancer, a photographer or a production company creates the assets changes nothing. Whoever buys AI content buys the responsibility along with it. A concrete step follows from this: disclosure duties about AI use belong in contracts and briefings, as does the handover of any existing provenance metadata. That metadata should survive export and upload processes — something many CMS and image pipelines currently do not guarantee.

Responsibility stays with the client. The more likely risk is a competitor’s warning letter.

For missing labels, the regulation provides for fines of up to 15 million euros or 3 percent of global annual revenue. That hurts and cannot be argued away — but for a mid-sized business it is more of a theoretical ceiling.

The practically more likely trouble comes from a different direction. Competitors and qualified associations can issue warning letters over violations under Section 3a of the German Unfair Competition Act (UWG) and sue for injunctive relief. The German competition watchdog Wettbewerbszentrale has explicitly announced it will do so. The reason this comes faster than with other regulatory topics: compliance can be checked from the outside with the naked eye. A missing label is documented with a screenshot. No file inspection, no experts, no access to internal processes required.

And over-labeling? There are no sanctions for that. The damage lies elsewhere. Inconsistent labeling documents arbitrariness and weakens your argument if a piece of content ever genuinely lacks a notice. Add to that an effect that advertising-impact studies show: content marked as AI-generated tends to be rated worse by consumers. Label everything indiscriminately, and you pay that price even where no obligation exists.

The bottom line, and what remains open

For companies with a working editorial process, less changes on August 2 than the current coverage suggests. The effort concentrates on image, audio and video content that could pass as real. Establish one clear rule there and apply it consistently, and you have handled the bulk of it.

Full legal certainty does not exist as of the cutoff date. Guidelines and Code of Practice are legally non-binding; ultimately, only the European Court of Justice can interpret Article 50 authoritatively. Both documents are nevertheless likely to establish themselves as the market standard, because authorities and courts will orient themselves by them.

What remains unresolved for now is the treatment of hybrid formats — elaborately produced commercials between art and commerce, say. Here the individual case decides. How responsibilities will be divided between the German Federal Network Agency and the state media authorities for advertising is also something practice will have to show.

The essentials in brief

  • Article 50 applies from August 2, 2026. What was postponed are the high-risk obligations.
  • Most companies are deployers. For them, labeling image, audio and video content is what matters.
  • Even entirely invented, photorealistic subjects count as deepfakes. Intent to deceive is irrelevant.
  • Text is generally unaffected, provided a documented editorial review exists.
  • The label belongs in the image. The tool's metadata is not enough for deployers.
  • Standard editing, the obviously fictional, internal use and existing content remain label-free.
  • Responsibility stays with the client, even when an agency produces.
  • The realistic risk is a competitor's warning letter under Section 3a UWG.

*Legal status: July 27, 2026. This article is a practitioner's assessment from an agency perspective and does not replace legal advice. Authoritative are the wording of the EU AI Act, the EU Commission's final guidelines of July 20, 2026, and their interpretation by authorities and courts.

Unsure what needs labeling in your organization?

In a free 30-minute call, we'll look at your published content together: which visuals, spots and texts fall under Article 50, which don't, and what a label that fits your brand looks like. Afterwards, you'll know exactly what to do.

Richard RufRedaktion
Richard Ruf