Domain insights

AI Labelling Rules for Websites in the EU: What Businesses Need to Do Under the AI Act

Understand EU AI Act website transparency: chatbot notices, deepfake labels, public-interest text, provider duties and the limited December 2026 deadline.

AI and website compliance
AI Labelling Rules for Websites in the EU: What Businesses Need to Do Under the AI Act

AI is now part of ordinary website work.

A small business may use AI to draft product descriptions. A support team may install an AI chatbot. A marketing agency may generate product images. A publisher may use AI to prepare articles. An ecommerce company may create synthetic video advertisements that look almost indistinguishable from camera footage.

That raises a practical question:

When does a website have to tell visitors that AI was involved?

Since 2 August 2026, the transparency obligations in Article 50 of the European Union's AI Act are in application. They require transparency in several specific situations, but they do not create a blanket rule saying that every sentence, image, or page touched by AI must carry an "AI-generated" badge.

That distinction matters.

A business can easily overreact and label everything. It can also make the opposite mistake and assume that using a third-party AI tool means the tool provider carries all responsibility.

The real answer depends on four things:

  1. what type of AI system is being used;
  2. whether the business is the provider or the deployer of that system;
  3. what kind of content or interaction reaches the public;
  4. whether an exception, such as meaningful human review and editorial responsibility, applies.

This guide explains those rules in practical language for website owners, ecommerce businesses, agencies, publishers, developers, and organizations that use AI online.

First, the date that matters: 2 August 2026

The EU AI Act entered into force on 1 August 2024 and has been phased in over time.

For website transparency, the important date is:

2 August 2026

That is when Article 50's transparency obligations became applicable.

The timeline is useful because AI compliance did not arrive as one single deadline.

DateWhat happened
1 August 2024The EU AI Act entered into force
2 February 2025Prohibited AI practices and AI literacy obligations started to apply
2 August 2025Governance rules and obligations for general-purpose AI models started to apply
10 June 2026The final Code of Practice on Transparency of AI-Generated Content was completed
20 July 2026The European Commission published Article 50 transparency guidelines
2 August 2026Article 50 transparency obligations became applicable
2 December 2026Limited grace period ends for certain pre-existing AI systems, but only for Article 50(2) machine-readable marking obligations
Article 50 applies from 2 August 2026. December concerns only the limited marking grace for pre-existing systems. The dates and explanations are also available in the table above.
Article 50 applies from 2 August 2026. December concerns only the limited marking grace for pre-existing systems. The dates and explanations are also available in the table above.

This last date needs special attention.

There is not a general grace period until December for all website AI labelling.

The European Commission explains that the limited grace period applies only to AI systems placed on the market before 2 August 2026 and only to the provider-side requirement under Article 50(2) to make AI-generated or manipulated content machine-readable and detectable.

For those pre-existing systems, that specific requirement must be met by 2 December 2026.

The other transparency obligations, including relevant chatbot disclosure, deepfake disclosure, and disclosure of certain public-interest AI text, apply from 2 August 2026.

The Commission also states that content generated before 2 August 2026 does not need to be labelled retroactively, although voluntary transparency is encouraged where practical.

The biggest misunderstanding: not all AI content needs a visible label

The phrase "AI labelling obligation" sounds broader than the law actually is.

For a typical website, there is no rule saying:

"If AI helped create this, add an AI label."

Instead, Article 50 targets specific transparency risks.

The most relevant website situations are:

  • a person is directly interacting with an AI system;
  • an AI provider generates synthetic text, audio, images, or video that must carry machine-readable marking;
  • a business publishes an AI-generated or manipulated deepfake;
  • a business publishes AI-generated or manipulated text about matters of public interest without adequate human review and editorial responsibility;
  • a business uses emotion recognition or biometric categorisation systems involving natural persons.

Most ordinary commercial websites will mainly care about the first four.

Provider or deployer? Your role changes your obligations

The AI Act separates responsibilities across the AI value chain.

Understanding your role is more useful than asking whether your company "uses AI."

Provider

A provider is broadly the person or organization that develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trademark.

Examples can include:

  • a company selling an AI chatbot platform;
  • a software vendor offering an AI image generator;
  • a business commissioning its own AI system and offering it under its own brand;
  • a company outside the EU placing an AI system on the EU market.

Providers carry important Article 50 responsibilities, including designing directly interactive AI systems so that people are informed they are interacting with AI and implementing machine-readable marking for relevant synthetic content.

Deployer

A deployer is a person or organization using an AI system under its authority for professional purposes.

Examples include:

  • an ecommerce business using a generative AI tool for advertising;
  • a company operating an AI chatbot on its website;
  • a publisher using a generative AI system in an editorial workflow;
  • an advertising agency generating synthetic campaign material;
  • a freelancer using AI as part of a commercial service.

Employees acting under the direction of their company are generally not separate deployers. The organization remains the deployer when the system is used under its authority.

Purely personal, non-professional use is outside this deployer definition.

That means a business owner and a consumer using the same AI tool can have very different compliance positions.

Does the rule only apply to businesses located in the EU?

No.

The territorial reach is broader.

The AI Act can apply to:

  • providers placing AI systems or general-purpose AI models on the EU market, even when the provider is outside the EU;
  • deployers established or located in the EU;
  • providers and deployers outside the EU where the output produced by the AI system is used in the EU.

This matters to global websites.

A company in Latin America, North America, Asia, or elsewhere should not assume that it is outside the AI Act simply because its headquarters are not in Europe.

If the business offers AI systems into the EU or uses AI outputs in the EU, the scope needs to be assessed.

Rule 1: AI chatbots and direct AI interaction

This is probably the most common Article 50 issue for ordinary business websites.

If an AI system is designed to interact directly with natural persons, the provider must design and develop it so that people are informed that they are interacting with AI.

The Commission's guidance says this notice should be provided from the start of the first interaction, unless it is already obvious to a reasonably well-informed, observant person that the interaction is with AI.

A simple notice can work:

"You're chatting with our AI assistant."

Or:

"This conversation is handled by an AI support assistant. You can request human support at any time."

The message does not need to sound threatening.

The goal is simply to prevent a visitor from believing that a human employee is answering when an AI system is actually handling the conversation.

Who is legally responsible for the chatbot disclosure?

Article 50(1) places the system-design obligation on the provider.

If you use a third-party chatbot, the vendor may already build the disclosure into the interface.

But website operators should still verify what visitors actually see.

A technically compliant feature hidden behind poor design may still create unnecessary risk and confusion.

And if your organization develops the chatbot, has it developed, and places it into service under your own name or trademark, your role may move closer to that of a provider.

Do not decide your legal role based only on who wrote the code.

Branding, control, contractual structure, and how the system is placed into service can matter.

Rule 2: machine-readable marking of AI-generated content

Article 50(2) creates a separate obligation for providers of AI systems that generate synthetic:

  • audio;
  • images;
  • video;
  • text.

The provider must ensure that outputs are marked in a machine-readable format and can be detected as artificially generated or manipulated.

The technical solution must be effective, interoperable, robust, and reliable as far as technically feasible.

This can involve technologies such as metadata, provenance information, or other machine-detectable techniques.

For the ordinary website owner, the critical point is this:

This is primarily a provider-side technical obligation.

If you use a third-party image generator, you normally are not expected to invent your own invisible watermarking technology simply because you downloaded an image.

However, this provider-side machine-readable marking does not replace the separate visible disclosure that a deployer may need when publishing a deepfake.

The two obligations solve different problems.

One helps machines detect AI-origin content.

The other helps people understand what they are seeing.

Technical marking and human-facing disclosure are separate duties. Metadata alone does not replace a required visible or audible notice.
Technical marking and human-facing disclosure are separate duties. Metadata alone does not replace a required visible or audible notice.

Rule 3: deepfakes need disclosure

This is where website owners, agencies, advertisers, and content teams need to pay close attention.

The AI Act defines deepfake content around AI-generated or manipulated images, audio, or video that resemble real or plausibly real persons, objects, places, entities, or events and would falsely appear authentic or truthful to a person.

The Commission's 2026 guidance explains that the analysis is contextual.

Relevant questions include:

  • How closely does the content resemble reality?
  • What message does the content communicate?
  • Where will it be published?
  • Who is expected to see it?
  • Would that audience reasonably think the material is authentic?

If the answer points toward deception or false authenticity, disclosure may be required.

Example: AI-generated executive portrait

Imagine a company creates a realistic AI image of a fictional "customer" and places it beside a testimonial.

A visitor could reasonably believe that the person exists and gave the quoted testimonial.

That creates a much more serious transparency problem than an obvious illustration of a cartoon robot.

Example: AI-generated office photo

A company creates a photorealistic image showing a large modern office and publishes it on its "About Us" page in a way that makes visitors believe it is the company's real facility.

Even if no actual office was copied, the image may create a false impression of an authentic place or event.

The context matters.

Example: clearly illustrated hero graphic

A website uses an obvious 3D illustration, cartoon, surreal graphic, or artistic scene that a reasonable visitor would not mistake for documentary photography.

That is less likely to meet the deepfake concept because the audience is not being led to believe it is authentic footage of reality.

The law is concerned with false authenticity, not with banning creative AI imagery.

How should a deepfake be labelled?

The deployer must disclose the AI-generated or manipulated nature of the content by the time a person is first exposed to it.

The disclosure must be:

  • clear;
  • distinguishable;
  • understandable;
  • perceivable without requiring special technical tools;
  • compatible with applicable accessibility requirements.

For visual content, that normally means a visible label.

For audio, an audible disclosure may be appropriate.

A business should not assume that invisible metadata alone is enough.

The Commission explicitly states that deployers cannot rely only on the provider's machine-readable marking to satisfy the human-facing deepfake disclosure obligation.

Simple wording can be enough:

"AI-generated image"

"This video contains AI-generated or AI-altered content"

"Synthetic media created with AI"

Placement matters.

A disclosure hidden in a privacy policy several clicks away is not the same as telling the user at first exposure.

What about artistic, fictional, or satirical content?

The AI Act provides special treatment for content that forms part of an evidently artistic, creative, satirical, fictional, or analogous work.

Transparency can still be required, but disclosure should be made in an appropriate way that does not unnecessarily interfere with the enjoyment or display of the work.

This is another reason a universal "AI GENERATED" banner across every creative image is not the right interpretation.

Context matters.

Rule 4: AI-generated text about matters of public interest

This is the most misunderstood text rule.

Deployers of AI systems that generate or manipulate text must clearly disclose AI involvement when the text is published for the purpose of informing the public on matters of public interest.

The Commission says the text needs to satisfy three basic conditions:

  1. it is published;
  2. it informs the public;
  3. it deals with a matter of public interest.

Examples of public-interest topics can include:

  • politics and democratic processes;
  • public administration;
  • justice and law enforcement;
  • fundamental rights;
  • public security;
  • public health;
  • environmental protection;
  • consumer safety;
  • significant economic, financial, political, scientific, or cultural developments relevant to public debate.

This is broader than political journalism.

A financial analysis, public-health article, environmental report, or consumer-safety warning could fall within the category depending on purpose and context.

Does an AI-written product description need a label?

Usually, not for Article 50(4) merely because AI helped write it.

A standard ecommerce description for a pair of shoes is not automatically a publication on a matter of public interest.

Likewise, ordinary marketing copy, an About page, or a routine service description does not become public-interest content simply because it is publicly accessible.

But context can change the answer.

A page discussing the health safety of a medical product, environmental claims, financial developments, or consumer safety could move closer to public-interest territory.

The safest approach is not to classify content by website section alone.

Classify it by what the text is trying to tell the public.

Human review can remove the text-labelling requirement

Article 50 includes an important exception for public-interest text.

A disclosure is not required when the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

This is highly relevant to professional websites and publishers.

But "human review" means more than clicking Publish after reading the first paragraph.

The Commission's guidance explains that review should involve deliberate examination of the substance by people with relevant knowledge and professional judgment.

Editorial control involves the real authority to:

  • approve;
  • alter;
  • reject;
  • fact-check;
  • verify the substance and sources.

A superficial grammar check is not enough.

Running AI text through a spell checker is not enough.

Changing a headline is not enough.

The exception is designed for genuine editorial responsibility.

A practical editorial workflow

A business using generative AI for important website articles can create a simple internal process:

  1. AI produces a draft.
  2. A named human reviewer checks factual claims.
  3. Sources are verified independently.
  4. Legal, medical, financial, or technical claims receive appropriate specialist review.
  5. The reviewer can change or reject the content.
  6. A person or company accepts editorial responsibility for publication.
  7. The review is documented.

This is good publishing practice even beyond the AI Act.

AI can accelerate drafting.

It should not make accountability disappear.

What about an article explaining the EU AI Act?

This is a useful example.

If a business uses AI to assist in drafting an article about the EU AI Act, the topic clearly concerns a matter of public interest.

If the text were published without meaningful human review or editorial control, Article 50(4) could require disclosure.

If the article is substantively reviewed, sources are checked, corrections are made where needed, and an identified publisher accepts editorial responsibility, the statutory exception may apply.

This shows why "AI helped write it" is not the final legal question.

The editorial process matters.

Emotion recognition and biometric categorisation

Article 50 also covers systems that may appear on websites, apps, kiosks, recruitment platforms, customer-experience tools, or other digital services.

Deployers of AI-based emotion recognition or biometric categorisation systems must inform natural persons who are exposed to those systems.

This obligation exists whether the system operates in real time or analyzes people afterward.

These systems can also raise separate privacy and data-protection issues, including under the GDPR.

If your website uses camera, voice, facial, behavioral, or biometric analysis to infer emotions or categorize people, this is not a normal analytics feature that should be treated casually.

It deserves specific legal and privacy review.

What does not automatically need an AI label?

For an ordinary commercial website, Article 50 does not mean that you must automatically label:

  • every paragraph drafted with an AI assistant;
  • every product description written with AI support;
  • every spelling correction suggested by AI;
  • every obvious illustration created with an image generator;
  • every background graphic;
  • every internal document;
  • every AI-assisted translation;
  • every page where an AI tool helped with brainstorming.

Whether disclosure is required depends on the specific Article 50 trigger.

The law is designed around transparency risks, not a universal badge for AI involvement.

Standard editing is treated differently

Article 50(2)'s machine-readable marking obligation does not apply to the extent an AI system performs an assistive function for standard editing or does not substantially alter the input data or its meaning.

The Commission guidelines provide examples to help providers distinguish standard editing from substantive generation or manipulation.

That matters for features such as:

  • grammar correction;
  • conventional editing assistance;
  • some formatting or technical processing;
  • minor changes that do not substantially alter the substance.

Not every AI-powered editing feature turns a document into synthetic content requiring the same provider-side marking treatment.

A simple compliance table for website owners

Website useLikely Article 50 action
Third-party AI chatbot talking directly with visitorsEnsure visitors are informed they are interacting with AI. The design obligation sits primarily with the provider, but the website owner should verify the notice appears clearly
AI-generated product description, reviewed by staffNormally no visible Article 50 label solely because AI assisted, assuming it is not public-interest text requiring disclosure
AI-generated article about elections, published without human reviewClear AI disclosure is likely required
AI-assisted public-interest article with substantive human editorial review and editorial responsibilityArticle 50 text-labelling exception may apply
Photorealistic AI image presented as a genuine real eventDeepfake disclosure likely required
Clearly fantastical illustrationUsually lower deepfake risk if a reasonable audience would not regard it as authentic
AI video altering a real person's speech or actionsDeepfake disclosure likely required
AI image generator itselfProvider must address machine-readable marking obligations
Website using emotion recognitionDeployer must inform exposed individuals
Content generated before 2 August 2026No retroactive Article 50 labelling requirement, although voluntary transparency is encouraged

This table is a practical starting point, not a substitute for assessing the actual facts.

The December 2026 deadline: who still has work to do?

As of October 2026, most Article 50 obligations are already live.

The remaining date that many technology vendors should watch is:

2 December 2026

Providers of AI systems placed on the market before 2 August 2026 have until that date to comply with the Article 50(2) machine-readable marking and detectability requirement.

This limited extension does not postpone the whole AI labelling regime.

A company operating a website should not conclude:

"We have until December to label our chatbot."

That is not what the grace period says.

The Code of Practice: voluntary, but useful

The European Commission facilitated a Code of Practice on Transparency of AI-Generated Content.

The Code is voluntary.

It is designed to help providers and deployers demonstrate compliance with Article 50's marking and labelling obligations.

The Commission explains that organizations adhering to an approved Code can gain greater legal certainty and predictability.

Organizations that do not follow the Code can still comply, but they need to demonstrate compliance through other adequate means.

For a small website operator using ordinary third-party tools, reading the entire Code may be excessive.

For AI vendors, media platforms, agencies creating synthetic content at scale, and businesses with substantial generative-AI operations, it deserves serious attention.

What are the penalties?

The potential consequences are significant.

Article 99 provides that breaches of Article 50 transparency obligations can be subject to administrative fines of up to:

EUR 15 million

or, for an undertaking:

up to 3% of total worldwide annual turnover for the preceding financial year

with the higher maximum applying to undertakings, subject to the specific rules in the Regulation.

For SMEs, including startups, the AI Act provides that the fine is capped at the lower of the percentage or fixed amount specified for the relevant infringement. The consolidated Article 99(6a) also applies the lower maximum to small mid-cap companies for infringements under paragraphs 4 and 5.

That does not mean every missing chatbot notice will produce a multi-million-euro fine.

Authorities must consider the circumstances of the individual case, including factors such as:

  • nature of the infringement;
  • seriousness;
  • duration;
  • consequences;
  • number of affected persons;
  • damage;
  • intent or negligence;
  • mitigation and cooperation.

Member States can also use other enforcement measures, including warnings and non-monetary measures.

The headline number should be taken seriously, but not sensationalized.

Compliance is risk-based and enforcement is intended to be proportionate.

Who enforces the rules?

Article 50 is mainly enforced by national competent market-surveillance authorities in EU Member States.

The EU AI Office has a more limited enforcement role in specific cases, including certain systems linked to general-purpose AI models under its supervision and systems integrated into designated very large online platforms or search engines.

The European Data Protection Supervisor handles relevant AI systems used by EU institutions, bodies, and agencies.

For an ordinary commercial website, the practical expectation is that national authorities will be central to enforcement.

What should a website owner do now?

Because Article 50 is already applicable, this is no longer a future-planning exercise.

A practical review can be completed in a few steps.

Step 1: inventory where AI reaches visitors

List every public-facing AI use.

Examples:

  • chatbot;
  • AI search assistant;
  • AI support agent;
  • synthetic voice;
  • AI-generated video;
  • AI-generated photography;
  • AI-generated articles;
  • automated summaries;
  • recommendation or personalization systems;
  • emotion or biometric tools.

Do not limit the inventory to the marketing department.

Support, HR, ecommerce, product, and external agencies may all use AI.

Step 2: identify who is provider and who is deployer

For every system, ask:

  • Who developed it?
  • Under whose name is it offered?
  • Who controls the system?
  • Are we only using a third-party system?
  • Have we substantially customized or white-labelled it?
  • Is an agency using the system on our behalf?

Document the conclusion.

Step 3: review chatbot interfaces

If AI talks directly to visitors, make the disclosure clear from the beginning.

Do not hide it in Terms of Service.

Do not rely on visitors to infer that an avatar or chat bubble must be AI.

A short, friendly sentence is usually better.

Step 4: identify realistic synthetic media

Review photorealistic AI imagery, voice, and video.

Ask whether a reasonable visitor could mistake the content for a genuine recording, person, place, object, or event.

Add visible or audible disclosure where required.

Step 5: review public-interest text

Identify AI-generated text dealing with public-interest topics.

For each item, ask:

  • Was there substantive human review?
  • Did the reviewer have appropriate knowledge?
  • Were sources checked?
  • Could the reviewer reject or rewrite the text?
  • Who carries editorial responsibility?

If no meaningful review exists, consider the Article 50 disclosure requirement.

Step 6: document the process

Keep a simple internal record:

  • system name;
  • vendor;
  • business owner;
  • provider/deployer role;
  • content types;
  • disclosure method;
  • editorial review process;
  • review date.

This does not need to become a 200-page compliance manual.

A short record is far better than relying on memory.

Step 7: review contracts with AI vendors

Ask vendors:

  • Does the system comply with Article 50(1)?
  • Are generative outputs machine-marked where required?
  • How is the marking implemented?
  • Can the marking survive normal export or transformation?
  • Does the vendor follow the EU Code of Practice?
  • What documentation is available?
  • Which party handles user-facing disclosure?
  • What changes apply to older versions before 2 December 2026?

Good vendor answers can reduce your operational uncertainty.

Recommended website wording

The AI Act does not require every business to use identical wording.

Simple language is usually better.

Chatbot

AI assistant: You're chatting with an AI system. You can request human support when needed.

AI-generated image

AI-generated image

AI-altered video

Transparency notice: This video contains content generated or altered using artificial intelligence.

Public-interest article requiring disclosure

AI transparency notice: This publication contains text generated or materially manipulated using artificial intelligence.

Use wording appropriate to the context and ensure it is clear, distinguishable, and accessible.

Should you create a "How We Use AI" page?

It can be a good idea.

A voluntary AI-transparency page can explain:

  • which AI tools your company uses;
  • what they are used for;
  • where humans review outputs;
  • how customers can reach a human;
  • how your organization approaches synthetic content.

This can improve trust.

But it does not replace a required disclosure at the point where the visitor encounters the relevant AI system or deepfake.

A transparency page is supplementary.

It is not a legal invisibility cloak.

Avoid shortcuts when deciding whether a label is needed

The EU AI Act does not require an "AI-generated" badge on every AI-assisted webpage.

That is consistent with Article 50's narrower structure.

For a business website, the useful starting points are direct AI interaction, realistic synthetic media, and meaningful human review of public-interest text.

However, businesses should avoid reducing the rule to an overly simple formula such as:

"Marketing text never needs a label."

The legal question is not whether a page is called "marketing."

The real questions include:

  • Is the text published to inform the public?
  • Does it concern a matter of public interest?
  • Was it generated or manipulated by AI?
  • Was there meaningful human review or editorial control?
  • Does a person or legal entity hold editorial responsibility?

Likewise, realistic synthetic images need a context-based deepfake assessment. The Commission's guidance looks at resemblance, plausibility, message, deployment context, audience expectations, and whether the content could falsely appear authentic or truthful.

Simple rules are useful for orientation.

They should not replace the actual criteria.

The practical bottom line

For most ordinary websites, compliance is manageable.

You do not need to cover every AI-assisted paragraph with warning labels.

You do need to understand where AI directly affects what visitors believe.

Focus on the situations with the clearest transparency risk:

  1. Tell people when they are directly interacting with AI.
  2. Ensure deepfakes are clearly disclosed when required.
  3. Label relevant AI-generated public-interest text unless genuine human review and editorial responsibility bring the exception into play.
  4. If you provide generative AI systems, address machine-readable marking requirements.
  5. Inform people exposed to emotion-recognition or biometric-categorisation systems.
  6. Document who reviews AI content and who is responsible for publication.
  7. Remember that Article 50 has been applicable since 2 August 2026.
  8. Providers relying on the limited pre-existing-system grace period for Article 50(2) should be ready by 2 December 2026.

The core idea is simple:

AI transparency is not about putting a warning on everything. It is about making sure people are not misled about who they are interacting with or whether important content is authentic.

For website owners, that is a much more practical standard than the headlines suggest.

Put transparency into your website workflow

At SoxDomains, we can help you prepare the website infrastructure behind that customer experience. Compare our hosting and VPS options, protect browser connections with an appropriate SSL certificate, and use our website security guide to plan the operational layers. Our guide to building a website with an LLM also explains the practical development workflow. These services do not certify AI Act compliance or replace the legal assessment of your AI use.

Frequently asked questions

Do I need to label every page that was written with ChatGPT or another AI tool?

No. Article 50 does not create a universal label for all AI-assisted text. The specific text-disclosure rule concerns published AI-generated or manipulated text used to inform the public on matters of public interest, subject to exceptions such as meaningful human review, editorial control, and editorial responsibility.

Do product descriptions need an AI label?

Ordinary product descriptions are not automatically subject to the Article 50(4) public-interest text rule. The subject and purpose of the publication matter. Claims involving areas such as public health, consumer safety, finance, or major public debate may require a more careful assessment.

Does an AI chatbot need to tell visitors it is AI?

Providers of directly interactive AI systems must design them so users are informed from the beginning of the first interaction, unless the AI nature is obvious. Website operators using third-party chatbots should verify that the disclosure is actually visible.

Who must label a deepfake?

The professional deployer publishing or using the deepfake is responsible for the human-facing disclosure under Article 50(4).

Is invisible metadata enough for a deepfake?

No. The Commission says deployers cannot rely only on machine-readable marking. The disclosure to people must be clear and perceivable, such as a visible or audible label.

Who handles machine-readable AI marking?

Article 50(2) places this obligation primarily on providers of AI systems that generate synthetic audio, image, video, or text.

Do old AI-generated images need to be relabelled?

The Commission says content generated before 2 August 2026 does not need to be labelled retroactively under Article 50, although voluntary transparency is encouraged.

What happens on 2 December 2026?

The limited grace period ends for Article 50(2) machine-readable marking obligations for AI systems that were already placed on the market before 2 August 2026.

Can a company outside Europe be affected?

Yes. The AI Act can apply to providers outside the EU placing systems on the EU market and to providers or deployers outside the EU where AI output is used in the Union.

What is the maximum fine for violating Article 50?

Article 99 provides administrative fines of up to EUR 15 million or, for an undertaking, up to 3% of worldwide annual turnover for the preceding financial year, whichever maximum is higher, subject to the rules in the Act. SMEs and qualifying small mid-cap companies benefit from lower maximum-cap mechanics for the relevant infringements, and authorities consider proportionality and the circumstances of the case.

Is the EU Code of Practice mandatory?

No. It is voluntary. Organizations may use it to help demonstrate compliance, while non-signatories can demonstrate compliance through other adequate means.