The phrase “AI-generated content must be labelled” sounds like one task. Since August 2, 2026, it is better understood as a chain assigned to different actors.

That date matters. Article 50 of the European Union’s AI Act began to apply, and the European Commission published guidance on how its transparency rules work for providers and deployers. The Commission’s current materials distinguish a provider’s machine-readable marking of synthetic output from a deployer’s clear disclosure to people who encounter a deepfake or certain AI-generated public-interest text. They also distinguish a real substantive review from a procedural check. The Commission’s Article 50 FAQ

The useful thesis is not that every generated object needs the same warning. It is that every disclosure needs an accountable owner, a defined trigger, and a readback at the point where a person first encounters the content. A technical signal is part of that chain. It is not the whole chain.

One asset, two disclosure jobs

The current consolidated AI Act assigns the provider a technical job. Providers of AI systems that generate synthetic audio, images, video, or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the law’s limits around technical feasibility and standard editing. The current consolidated text on EUR-Lex

The deployer has a different public-facing job. When a deployer uses an AI system to generate or manipulate image, audio, or video content that qualifies as a deepfake, the content must be disclosed as artificially generated or manipulated. The Commission’s FAQ says that disclosure must be clear, distinguishable, understandable, and perceivable at the latest on first exposure. A deployer cannot satisfy that obligation simply by pointing to a machine-readable mark embedded by the provider. The Commission’s guidance and FAQ

That distinction is easy to lose in a production handoff. A generator may export a file with a valid signal, then an editor may upload a cut that strips metadata. A platform may display a different label, or no visible label at first exposure. The first state can be technically compliant while the last fails to tell a person what they are seeing. This is an editorial inference, not a claim that every platform strips every signal.

The rule creates two questions:

  1. Can a system or downstream tool detect that the content was generated or manipulated?
  2. Can the person encountering the content understand that fact without a technical tool or a special action?

The first belongs mainly to the provider’s implementation. The second belongs to the deployer’s publication. “The file has credentials” answers the first, not the second.

The deployer follows authority, not the person who clicked Generate

The Commission’s FAQ defines a deployer as a natural or legal person using an AI system under its authority, excluding personal, non-professional activity. It also says that when a legal person controls the use, its employees are not separate deployers, and the organization remains the deployer when contractors or freelancers operate the system on its behalf and under its responsibility and control. The Commission’s explanation of provider and deployer roles

This corrects a common production story: “The freelancer made it, so the freelancer owns the disclosure.” The click is evidence of an action, not necessarily the role. A campaign team, publisher, studio, or other organization may need to identify who had authority over the system’s use, who decided to publish, and who could stop the release. Contracts can allocate tasks, but a handoff should not substitute a contract label for actual authority.

Consider a hypothetical product campaign. An agency uses a generator to create a photorealistic clip that appears to show a real athlete endorsing a product. The provider’s system should carry its machine-readable mark where Article 50(2) applies. The organization using the system to publish the clip must separately ask whether the result would falsely appear authentic or truthful in its intended context and, if it is a deepfake, place a clear disclosure where viewers first encounter it. The agency also still has separate questions about permission, likeness, the product claim, and the commercial relationship. Article 50 transparency does not answer those questions.

“Human review” is not a checkbox

The text rule contains a narrower exception. Deployers must clearly label AI-generated or manipulated text published to inform the public about matters of public interest, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

The Commission’s FAQ gives that exception more substance. Human review means deliberate examination of the content’s substance by people with relevant knowledge and professional judgment. Editorial control means a responsible editorial entity has authority to approve, alter, or reject the substance on substantive grounds, including fact-checking and checking the trustworthiness of sources. Spell-checking, grammar correction, or another formal check is not enough. The Commission’s Article 50 FAQ, human-review section

This matters beyond legal classification. A person “in the loop” can still be absent from the decision that gives a text its meaning. If someone only checks formatting, the process has not shown substantive review. If a reviewer can identify a false claim but cannot stop publication, the process has not shown editorial control. If no person or legal entity holds responsibility, the exception’s accountability condition is missing.

The public value of review is not the presence of a human hand. It is judgment with authority. A polished article can be less trustworthy than a labelled one: fluency can conceal that no one was empowered to question its claims.

The transition date is narrower than the myth

Article 50 applies from August 2. The Commission describes a limited transition only for the provider’s marking and detection obligation under Article 50(2), and only for certain AI systems placed on the market before that date. The stated deadline for those systems is December 2, 2026. The same FAQ says content generated before August 2 does not need to be labelled retroactively, while encouraging deployers to do so where possible. The Commission’s current implementation explanation

That is not a general permission to publish an unmarked deepfake until December. It is a timing rule for a specific provider obligation. Treating it as a universal grace period confuses an old system’s technical adaptation window with the deployer’s responsibility at public exposure.

Build a disclosure handoff card

The simplest operational response is a short card attached to the final asset or text, not a generic “AI used” field.

Card fieldRecord before releaseStop condition
AuthorityProvider, deployer, and organization controlling the useThe team cannot identify who can approve or stop publication
Content triggerInteractive system, synthetic output, deepfake, or public-interest textThe team cannot explain which Article 50 trigger it is evaluating
Technical stateWhether the provider mark is present, machine-readable, and preserved in the delivery fileThe mark is unknown, missing, or lost after export
Public disclosureExact words, placement, language, accessibility, and first-exposure surfaceThe label appears only behind a menu, in metadata, or after a viewer acts
Review recordWhat substantive claims were examined, by whom, and under what authorityReview is only spell-checking, formatting, or an unverifiable sign-off
Final readbackVersion, destination, date, and what a person actually sees or hearsThe posted or previewed version differs from the checked version

The card is not a legal conclusion and cannot settle consent, copyright, truth, or platform policy. It prevents those questions from being assigned to an unnamed “AI label.” If a field is unknown, the correct status is hold, not inference.

The EU framework makes transparency more precise by separating the technical origin signal from the public act of disclosure. That separation may feel like extra work, but it reflects how synthetic media actually moves: from system to file, from file to edit, from edit to platform, and from platform to a person’s first impression.

A label earns trust when someone can say who supplied it, what it covers, where it appears, and who remains responsible when the asset changes. The badge is not the accountability. The handoff is.

Sources and limitations

  1. EUR-Lex, “Regulation (EU) 2024/1689, consolidated text dated July 27, 2026” — checked September 10, 2026; supports the in-force consolidated AI Act text, including Article 50’s provider marking, deployer disclosure, first-exposure, and human-review provisions. Limitation: the consolidated EUR-Lex text is a documentation tool; the authentic legal versions are those published in the Official Journal, and the current page may require browser verification.
  2. European Commission, “Guidelines on transparency obligations for providers and deployers of AI systems” — checked September 10, 2026; supports the Commission’s July 20, 2026 publication of Article 50 implementation guidance and its application from August 2, 2026. Limitation: Commission guidelines explain and operationalize the rules; they are not a substitute for the regulation or jurisdiction-specific legal advice.
  3. European Commission, “Transparency obligations under Article 50 of the AI Act” — checked September 10, 2026; supports the provider/deployer definitions, the separation between machine-readable marks and visible disclosures, the deepfake and public-interest text rules, the human-review and editorial-control criteria, the limited December 2 transition, and the enforcement summary. Limitation: Commission FAQ material is explanatory guidance; application still depends on the system, actor, content, audience, and other applicable law.
  4. European Commission, “Code of Practice on Transparency of AI-Generated Content” — checked September 10, 2026; supports the voluntary status of the code, its separate provider and deployer sections, and its practical guidance on marking, detection, labels, placement, and human review. Limitation: the code is a voluntary compliance tool and does not replace Article 50 or the Commission’s guidelines.