Contents
- 1. Start with your role: providers and deployers owe different duties
- 2. Does AI-written text need a label?
- 3. Human review earns an exemption, but it has to be substantive
- 4. Deepfakes, and the exception for art and satire
- 5. If you run a chatbot
- 6. Whose job is machine-readable marking? C2PA and the deadlines
- 7. The deadlines in order: the next one is December 2, 2026
- 8. A checklist for each role
- FAQ
"Apparently it is illegal to publish an AI-written article without saying it is AI-generated" — that line started showing up everywhere once the remaining provisions of the EU AI Act became generally applicable on August 2, 2026. And when you hear the fine can reach 15 million euros or 3% of worldwide turnover, it is hard to shrug off.
Here is the conclusion first. For most independent writers and company blogs, no disclosure duty arises. The text spells out an exemption: it does not apply where the content has undergone human review and someone holds editorial responsibility for the publication (Article 50(4)). But it also says, just as clearly, that a quick skim is not enough to earn that exemption.
This article sorts out what you actually have to do, role by role. Every figure and every reading of the text is limited to what could be confirmed against the EU AI Act itself and the practical guidance from the European Commission AI Office.
Disclosing AI-Generated Content
EU AI Act Article 50 — next deadline December 2, 2026
Source: EU AI Act Article 50
1. Start with your role: providers and deployers owe different duties
This is the single most misread part of the provision. For one and the same piece of AI-generated content, Article 50 places completely different duties on the provider and on the deployer.
The side that builds an AI system and puts it on the market. OpenAI, Google, Anthropic, and any company that builds and ships its own service with generative AI inside it.
Duty: mark the output in a machine-readable way, and make it clear when a chatbot is an AI.
The side that puts that AI to work. A blogger writing articles with ChatGPT, a designer making images with Midjourney, a company using AI internally.
Duty: disclose deepfakes, and AI-generated text that meets certain conditions.
Which means an individual has no real reason to agonize over watermarking their AI output. Machine-readable marking is a provider duty, not your job. The part that concerns you is disclosure.
If you are an individual blogger writing and publishing with ChatGPT, your role is deployer. Read the rest of this article on that footing.
2. Does AI-written text need a label?
The second half of Article 50(4) is the provision about text. Disclosure is required only when both of the following hold.
① The text was generated or manipulated by AI
② It is published for the purpose of informing the public on matters of public interest
The decisive word is purpose, in the second condition. The practical guidance explains that the test is not the topic itself but the purpose of the party publishing it. Two pieces on the same climate subject can be treated differently: an article put out to inform the public of the facts versus a write-up promoting your own product.
And even where the second condition does apply, this is where the real point begins.
3. Human review earns an exemption, but it has to be substantive
The text contains an explicit carve-out. The disclosure duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
For most publishers, that is the answer. Even if an AI writes the draft, no disclosure duty arises under the text so long as you read it, correct it, and publish it standing behind what it says. A newsroom with an editorial desk sits in exactly the same structure.
There is a condition attached, however. The practical guidance states in so many words that the review must be substantive and must not be confined to superficial matters or a formal sign-off.
You read the AI draft, check the facts, fix the errors, rework the structure, and publish. It is clear who is accountable.
Auto-posting generated text without reading it. Fixing the typos and shipping. No way to tell from outside who is accountable.
The question has quietly shifted from whether you attach a label to how you make the thing. Run a process with substantive review and you are exempt; run none and you are not. It looks like a disclosure problem and turns out to be an editorial-process problem — that, to me, is the most practical implication of this provision.
4. Deepfakes, and the exception for art and satire
Separately from text, deepfakes carry a disclosure duty of their own. The text treats a deepfake as content that falsely appears to be authentic or truthful, and requires the deployer who generates or manipulates it and then publishes it to disclose as much. Using image generation or video generation to depict real people or real events is precisely this case.
There is an exception, though. Where the work is evidently artistic, creative, satirical or fictional, the duty is relaxed. What is asked for is not full disclosure but making the existence of generated or manipulated content known in an appropriate manner that does not hamper the display or enjoyment of the work.
In other words, you do not have to paste a full-screen "this film contains AI-generated footage" card over the opening titles. Putting it in the credits or the work information is enough, and the design is deliberately built so as not to chill creative work.
Read the other way, though, "it is art, so nothing is needed" is wrong. What is relaxed is the manner of disclosure, not whether it happens at all.
5. If you run a chatbot
If there is an AI chatbot on your site, Article 50(1) comes into play. An AI system that interacts directly with people must let them know they are dealing with an AI — and that is a provider duty.
The text does add that this is unnecessary where it is obvious to a reasonably well-informed person. The thinking is that if the thing is named an AI assistant and sits in an interface that plainly reads as a chatbot, that in itself serves as the notice. There is no need to make it announce "I am an AI" every single time.
If you embed generative AI in your own service and offer it to others, you stand on the provider side. When you draft internal guidelines, settling up front whether your company is a provider or a deployer makes separating the duties far easier.
6. Whose job is machine-readable marking? C2PA and the deadlines
Article 50(2) is the part moving fastest on the technical side right now. Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable format and make it detectable as artificially generated or manipulated.
The text names no specific technology, but it asks for solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. On top of that, the Code of Practice on Transparency of AI-Generated Content, published by the European Commission AI Office on June 10, 2026, set out what implementations should aim at.
Embedded straight into the file with a cryptographic signature and a timestamp. The example the Code of Practice names outright is C2PA Content Credentials.
A signal embedded without affecting how the content looks. It acts as the layer that survives once the metadata has been stripped away.
An approach that matches content against a registry. The Code of Practice places it as an option rather than a requirement.
The point is that any one of them alone falls short. The Code of Practice holds that no single technique is sufficient on its own and calls for layering them. Metadata is easily wiped by a screenshot or a re-encode, so you pair it with a watermark — that is the reasoning.
Two deadlines follow. Generative AI systems that were already on the market before August 2, 2026 have to meet the machine-readable marking requirements by December 2, 2026. And interoperable arrangements for detecting watermarks have to be in place by February 2, 2027.
7. The deadlines in order: the next one is December 2, 2026
| Date | What happens | Whose concern |
|---|---|---|
| August 2, 2026 | The remaining provisions become generally applicable. Enforcement of the Article 50 transparency duties and the general-purpose AI rules begins | Everyone |
| December 2, 2026 | The transition period for machine-readable marking of systems already on the market ends | Providers |
| February 2, 2027 | Deadline for having interoperable watermark detection in place | Providers |
| December 2, 2027 | Annex III high-risk duties (hiring, credit, education, law enforcement and the like) | Organizations running those activities |
| August 2, 2028 | Annex I embedded high-risk duties (medical devices, machinery, vehicles and the like) | Manufacturers of those products |
⚠️ Any explainer telling you the high-risk rules took full effect on August 2, 2026 is out of date. The Digital Omnibus amendment pushed the high-risk duties back to December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The original dates were August 2, 2026 and August 2, 2027.
8. A checklist for each role
If you read the AI draft, correct it and publish it standing behind it, no text disclosure duty arises. You need to disclose only when you put out images or video that make real people or events look authentic.
Name who carries editorial responsibility and build a workflow where review never becomes a formality. That is where the exemption comes from, so fixing the process is the real work.
You are a provider. Machine-readable marking (C2PA and similar) and chatbot notices become obligations. Your dates are December 2, 2026 and February 2, 2027.
Art, satire and fiction are relaxed, not exempt. Credits or work information are enough, so pick a form that does not hamper enjoyment.
A closing word on the scope of this article. What is written here is what can be read out of the EU AI Act text and the European Commission Code of Practice, and it is not legal advice on any individual case. Where the line around matters of public interest falls, and how much review counts as substantive, are ultimately things that will settle through practice and case law. If high-risk activities such as hiring, credit scoring or healthcare are involved, run it past your legal team.
FAQ
Q1. Is it illegal to publish a ChatGPT-written blog post without an AI-generated label?
In most cases no label is needed. The disclosure duty in Article 50(4) is aimed at AI-generated text published for the purpose of informing the public on matters of public interest, and even then it does not apply where the content has undergone human review or editorial control and someone holds editorial responsibility. If you read the AI draft, verify it, correct it and publish, you fall within that exemption. The review does have to be substantive, though: the practical guidance states plainly that fixing typos or a formal sign-off is not enough.
Q2. Does any of this reach me if I am outside the EU?
You can be in scope if you offer services within the EU or publish for an EU audience. Publishing that stays entirely inside your own country outside the EU is not directly covered, but the idea of labeling AI output is spreading across jurisdictions, so building the process now is worth doing regardless.
Q3. Do I have to watermark AI-generated images myself?
As an individual deployer, generally no. Machine-readable marking is the duty Article 50(2) places on providers, which means it is work for the likes of OpenAI and Google. That said, if you publish images or video that make real people or real events look authentic, that is a deepfake and you carry a separate disclosure duty as the deployer.
Q4. How large is the fine?
Breaching the transparency duties carries up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. It is easy to confuse this with the figure of up to 35 million euros or 7%, but that applies to prohibited practices such as social scoring, which sit at a different tier.
Q5. Does adopting C2PA satisfy the obligation on its own?
C2PA Content Credentials is the mechanism the European Commission Code of Practice names as an example, but the Code holds that no single technique is sufficient on its own and calls for a layered approach that combines provenance metadata with an imperceptible watermark. The reason is that metadata is lost to a screenshot or a re-encode, so on its own it struggles to meet the robustness requirement.
Q6. What happens if a film or a game uses AI-generated footage?
For work that is evidently artistic, creative, satirical or fictional, the duty is relaxed. What is asked for is not full disclosure but making the existence of generated or manipulated content known in an appropriate manner that does not hamper the display or enjoyment of the work. Noting it in the credits or the work information fits that. Note that this is a softer manner of disclosure, not an exemption from it.
Q7. What do I need to do, and by when?
The deployer disclosure duties have already applied since August 2, 2026. On the provider side, machine-readable marking has a deadline of December 2, 2026 for systems that were on the market before August 2, 2026, and interoperable watermark detection has a deadline of February 2, 2027. The high-risk system duties fall on December 2, 2027 (Annex III) and August 2, 2028 (Annex I), pushed back from the dates originally set.
Sources
- EU AI Act Article 50 (text)
The four transparency duties, the split between providers and deployers, the machine-readable marking requirements, and the exceptions for law enforcement, artistic works and editorial responsibility - Practical guidance on Article 50
Why matters of public interest turn on the purpose of publication rather than the topic, why review has to be substantive, and what the softened disclosure for artistic works means - EU AI Act implementation timeline
The December 2, 2026, February 2, 2027, December 2, 2027 and August 2, 2028 dates - European Commission AI Act Service Desk
What became applicable on August 2, 2026, and how the transition periods are meant to work
Related articles
- How to write corporate AI usage guidelines — the EU AI Act seen from the internal-policy side
- Getting started with AI image generation — the territory where the deepfake disclosure duty bites
- Getting started with AI video generation — the same, and be especially careful with real people