Since Sunday, Article 50 of the EU AI Act has been in force. Since then, I've been seeing a cautious "Made with AI" notice under every other blog image. Most of these notices are unnecessary. Two cases, however, get overlooked by many operators, and those are exactly the ones that can cost you money.
Why the deadline held
Back in spring, word was that the Commission would push everything back. That's only half true. The Digital Omnibus, passed by Parliament and Council in June 2026, moves the obligations for high-risk systems from August 2, 2026 to December 2, 2027. So anyone using AI in hiring or credit decisions gets 16 more months. The transparency rules in Article 50, though, were left untouched by lawmakers. They've applied since August 2, 2026, with no transition period.
There is exactly one grace period. For generative systems that were already on the market before August 2, 2026, the machine-readable marking required under Article 50(2) doesn't kick in until December 2, 2026. This deadline applies to the makers of the tools, not to you as a user. If you launch a system after the cutoff date, you have to label from day one.
Provider or deployer: everything hinges on this
The regulation splits obligations by role. Mix up your role, and you'll end up labeling the wrong thing while missing the right one.
Providers
Providers develop an AI system and put it on the market. Think OpenAI, Adobe, Midjourney, Google. They have to mark their outputs in a machine-readable way and build chatbots so users can tell they're talking to AI. This obligation doesn't fall on you as long as you're using someone else's tools.
Deployers
Deployers use AI professionally. That's you, if you generate images or have text written for your company website. Your list is shorter than most people think: label deepfakes, and label AI-generated text on matters of public interest. That's it.
Private individuals are excluded entirely. If you make a deepfake for fun and share it in a family chat, Article 50 doesn't apply. The moment that same content ends up on your company website, things look different.
The trap of putting your own brand on it
If you offer someone else's AI system under your own name, you slide into the provider role and inherit its obligations. This affects more websites than it sounds like. A white-label chatbot that you run on your homepage as "Your Assistant" makes you the provider of that system. The same applies if you self-host an open-source model and build a service on top of it.
Images: three questions and you'll know where you stand
An image only needs a label if all three conditions apply. The Commission lists them in its FAQ on Article 50: resemblance to a real person, object, or place; plausible existence, meaning what's shown could actually exist; and the impression that the image depicts something real.
If even one of these three is missing, you don't need a label. That's why the cartoonish robot in your blog header is exempt, while a deceptively realistic product photo is not.
Four everyday cases
- Label required: You furnish an empty apartment photo using AI for a listing. Viewers assume the furnishings are real, and then show up to an empty room at the viewing.
- No label needed: Your smartphone's night mode removes noise. Standard processing doesn't change what the image conveys.
- Borderline case: You retouch wrinkles out of a portrait. Once the meaning of the image shifts, say in a before-and-after comparison for a cosmetic treatment, the case tips into labeling territory.
- No label needed: You generate a dragon flying over Cologne Cathedral. Obviously fantastical, nobody mistakes it for a photograph.
The trade magazine docma worked through this distinction using several examples and offers a rule of thumb that holds up in practice:
Does the image still show what was actually in front of the lens?
If you answer yes, the image needs no label. If no, it's worth taking a second look at the three criteria (docma).
Text: the filter is "public interest"
This is where most blogs get it wrong, and in both directions. Some slap a notice under every AI-assisted text, others under none at all.
An AI-written text needs a label if you publish it to inform the public and it concerns a matter of public interest. In its guidelines, the Commission lists: politics and democratic processes, public administration, the judiciary, fundamental rights, public safety, health, environmental protection, consumer protection, as well as economic, financial, scientific, and cultural developments that are subject to public debate.
Your recipe for pasta alla Norma doesn't fall under this. Your article about a new tax rule, a medication, a product recall, or the local election does. A guide to retirement savings plans and a write-up interpreting a new study also belong in this group.
What counts as editorial review
The exemption saves most editorial teams. Texts that a qualified person has substantively reviewed, and for which someone bears editorial responsibility, don't need a label. The Commission requires a substantial review for this to apply. Spell-checking, a quick skim, and a checkbox in the workflow aren't enough.
In practice, this means: if you read the raw AI draft, verify figures, check sources, and rewrite passages, you meet the exemption. If you run the text through a tool and publish it, you don't. Keep a record of who reviewed what and when, even if it's just a field in your editorial system. If a dispute arises, you'll need to show this, and three years from now nobody will remember.
What's not covered at all
A lot of everyday work falls outside the scope. Internal notes, quotes, minutes, and emails aren't published, so Article 50 doesn't apply. Product descriptions in your shop don't inform the public about a matter of public debate, even if AI wrote them. The same goes for travel tips, recipes, craft instructions, and the vast majority of service content.
Also exempt is text where AI helped you write without supplying the substance. Organizing an outline, smoothing out phrasing, shortening sentences: these assistive functions count as standard editing. The Commission's test is whether the tool changed the substantive content. If you're the one thinking through the text and using AI as an editor, you remain the author.
What the notice has to look like
A person must be able to perceive it without technical aids, at the latest upon first contact with the content, and it must be clear and distinguishable. Metadata alone isn't enough to satisfy deployer obligations. A visible label on the image, a notice line above or below the text, or for audio, a spoken announcement.
Since June, the Commission has provided an EU icon you can use instead of your own wording. It comes from the Code of Practice on Transparency of AI-generated Content, which the Commission finalized on June 10, 2026. Signing on is voluntary, but it helps as evidence toward regulators.
For artistic, satirical, or fictional work, a discreet notice is enough, say in the credits or accompanying text. Nobody expects a watermark plastered across an illustration.
Two things that go wrong quickly
The chatbot on your homepage
The obligation under Article 50(1) falls on the provider, who has to design the system so users can recognize the AI. But the moment you present the bot under your own name, you're the one on the hook. One sentence in the first message is enough: An AI assistant is answering here. Where the AI is obviously apparent, the notice can be skipped, though I wouldn't push that exception too far with a support widget.
Destroyed provenance data
C2PA data and watermarks often get stripped out during conversion, cropping, and compression. That's why the Code of Practice requires providers to use at least two layers of marking, since no single technique is robust enough on its own. Check your image workflow before your CDN optimizes the evidence away. One test is enough: upload a generated image, download it again, and see if the signature survived the trip.
Who enforces this, and what a violation costs
In Germany, the Bundesnetzagentur handles market surveillance. The Bundestag set this up in June 2026 with the AI Market Surveillance and Innovation Promotion Act, known as KI-MIG for short. The agency serves as both the central contact point and the complaints office, so tips from competitors land there too.
The penalty range for violations of Article 50 goes up to 15 million euros or 3 percent of global annual revenue, whichever is higher. For small and medium-sized companies, the lower amount applies. The often-cited figure of 35 million relates to the prohibited practices under Article 5, not to labeling.
Whether the Bundesnetzagentur will send warnings or offer guidance in its first year, nobody knows yet. There are no publicly documented proceedings so far. Still, I'd expect letters from competitors, since competition law offers a second lever alongside regulatory oversight.
Your to-do list for this week
- List every place on your site where AI contributes to writing or imagery: images, text, chatbot, translations, product descriptions.
- Sort your images using the three questions. Only the remainder needs a label.
- Go through your articles on health, law, money, politics, and consumer topics. Either add a label or document editorial review.
- Add a disclosure sentence to your chatbot.
- Check whether your image pipeline preserves the metadata.
- Record who bears editorial responsibility. Without a name attached, the exemption for texts doesn't apply.
Where I'm not certain
The Commission's guidelines from July 20, 2026 don't have the force of law. They show how the Commission reads the rule, but the final say rests with the European Court of Justice. On borderline cases, like wrinkle retouching or when exactly a guide article touches on a matter of public interest, law firms' assessments diverge.
I also got the date of the Bundestag's decision on the KI-MIG from a law firm source, not from the official gazette. If a lot of money or a lot of reach is riding on this for you, get it checked by a lawyer instead of relying on a blog post. Including this one.
Sources
- European Commission: FAQ on the transparency obligations under Article 50
- European Commission: Guidelines on transparency obligations, July 20, 2026
- European Commission: Code of Practice on Transparency of AI-generated Content
- AI Act Service Desk: Full text of Article 50
- Jones Day: Final Code of Practice on Marking and Labelling AI-Generated Content
- DLA Piper: The Digital Omnibus and the deferral of high-risk obligations
- Usercentrics: Digital Omnibus in force, Article 50 unchanged
- docma: Labeling requirements for AI-generated images
- Attorney Ferner: KI-MIG and the Bundesnetzagentur as regulator
- digital-chiefs: Roles and fines under Article 50