AI policy

AI-disclosure rules are now live in the EU: what marketers actually have to do

Article 50 of the EU AI Act is now applicable. The obligations are real but narrower than the panic suggests, and the main exemption is something you should want anyway.

The short version

From 2 August 2026, Article 50 of the EU AI Act applies (no, not that Article 50), and with it the EU's AI-disclosure rules. If you run marketing for a brand with an EU audience, here's the honest summary. You must disclose deepfakes: AI-generated image, audio or video that could pass as real people, places, objects or events. You must disclose AI-generated text published to inform the public on matters of public interest, unless a human reviewed it and a named person or company holds editorial responsibility for it. And your chatbot has to be identifiable as AI unless that's already obvious. That's the list.

Most of what marketing teams are currently being told, that every AI-touched asset needs a badge, that AI ad copy must be declared, that you need watermarking software by Monday, is not in the regulation.

One caveat before the detail: I'm a GEO consultant, not a lawyer, and this isn't legal advice. It's a practitioner's reading of the regulation itself and the Commission's guidance, with links so you can check me.

Article 50 for marketers, on one card Two lists. You must disclose: deepfakes, public-interest AI text with no human review, and chatbots that could pass as human. No badge needed: AI-assisted ad copy and product pages, stylised imagery nobody mistakes for real, and anything a named human signs off. Footer: the editorial-responsibility exemption is the same accountability trail that gets content cited by AI. Article 50, minus the panic what marketing teams must disclose in the EU, from 2 August 2026 dogonthetable.com You must disclose Deepfakes photoreal AI of real people, places or events Public-interest AI text, unreviewed no human check, no named editorial owner Chatbots that could pass as human must be identifiable as AI unless it's obvious No badge needed AI-assisted ad copy and product pages the everyday stack; watermarking is your vendor's job Stylised imagery nobody mistakes for real the artistic get-out is written into the Act Anything a named human signs off the editorial-responsibility exemption The exemption that's going to be heavily leant on: a named human who stands behind the content. That accountability trail is also what gets you cited. Compliance and GEO going hand in hand.
Article 50's two deployer duties, and the everyday marketing work that sits outside them. Not legal advice; check the linked sources.

What Article 50 actually requires

The article splits the world into providers (the companies building generative AI systems) and deployers (everyone using those systems under their own authority, which includes your marketing team).

Providers carry the heavy engineering duty: outputs must be marked in a machine-readable format and detectable as artificially generated, as far as technically feasible. That's OpenAI's job, Google's job, Anthropic's job. Not yours.

Deployers, meaning you, have 2 disclosure duties:

  • Deepfakes. If you generate or manipulate image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic, you must disclose that it's artificially generated. For evidently artistic, creative or satirical work the duty shrinks to disclosing existence in a way that doesn't hamper the work.
  • Public-interest text. If you publish AI-generated text "with the purpose of informing the public on matters of public interest", you must disclose it, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it.

Disclosure has to be clear, distinguishable and there by the moment of first exposure. The Commission published a free set of EU labelling icons in June: a basic AI mark, a "fully AI-generated" variant and a "partially AI-modified" variant. Using them is optional; the disclosure itself is not.

What you almost certainly don't have to do

The Commission's own icons page states it flat: not all AI-generated or manipulated content needs to be labelled. So, some myths, in descending order of how often I've seen them this month:

  • You don't have to label every AI-assisted asset. Product descriptions, ad copy, social posts, email campaigns and stylised AI imagery that no reasonable person would mistake for an authentic photo of something real sit outside both deployer triggers.
  • You don't have to watermark anything yourself. Machine-readable marking is the provider's obligation. Your only real exposure is stripping those marks out in your pipeline, which some CMS and social platforms do on re-upload. Worth checking, not worth panicking about.
  • You're not exempt because you're in the UK or US. The Act covers deployers established outside the EU where the system's output is used in the EU. Publishing to an EU audience puts you in scope.

The honest caveat: "matters of public interest" isn't a tidy category. A fintech's AI-written explainer on pension rules looks a lot more like public-interest text than a mattress brand's product page. If your content marketing dresses itself as journalism, assume the text rule can reach you. Which brings us to the exemption that does all the quiet work.

What changed this summer while nobody was looking

The compliance scaffolding around Article 50 finished landing in July, and most commentary hasn't caught up. The final Code of Practice on Transparency of AI-generated Content was assessed as adequate by the Commission on 8 July and by the AI Board the day after. By the end of July about 190 organisations had signed it, roughly half of them small companies. On the provider side: OpenAI, Google, Meta, Microsoft, Anthropic and Mistral. On the deployer side: Bulgari, Getty Images, Lufthansa and Lenovo, among some 150 others.

The Commission also published guidelines on the scope of the transparency obligations on 20 July, with definitions and worked examples of what's in and out.

Signing the code is voluntary. It buys signatories a recognised, EU-wide way to demonstrate compliance; non-signatories must show their own measures are adequate, assessed authority by authority. For a small marketing operation I wouldn't rush to sign, but I would steal its homework: the icon placement rules in Section 2 are a ready-made disclosure spec someone else paid the lawyers for.

The bit nobody says: the exemption is a GEO strategy

Read the text rule again. The disclosure duty disappears when a human reviewed the content and a named person or organisation holds editorial responsibility. The law doesn't actually care whether AI wrote your article. It cares whether anyone stands behind it.

That's the same question I bang on about in generative engine optimisation. Named authors, a real review step, an entity that answers for its claims: that's what makes content citable to answer engines, and it's what E-E-A-T has rewarded for years. A German court already decided Google owns the words its AI generates; accountability for machine output is the direction of travel everywhere, not just in Brussels.

So the compliance work and the visibility work are the same work. If your content operation has a named editor who genuinely reviews and signs off what goes out, you were exempt from the text rule before it existed, and you're more likely to be the source an AI answer quotes.

What to do this month

  • List every place generative AI touches published output: images, video, audio, text, your website chatbot.
  • For each, ask the 2 trigger questions: could this pass as authentic imagery of real people, places or events? Is it text informing the public on a matter of public interest?
  • Write the editorial step down. Named reviewer, actual sign-off, kept records. This is the exemption, and it only protects you if it really happens.
  • Label anything photoreal-synthetic now. The EU icons are free and user-tested.
  • Check your chatbot introduces itself as AI.
  • Ask your AI vendors what they do for Article 50 marking, and check your publishing stack doesn't strip it.
  • While you're at it, find out what AI systems currently say about your brand. The free audit shows you in a few minutes, and the fix list it produces is the same editorial-accountability work as above.

Penalties, honestly

The ceiling for Article 50 breaches is EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The scare posts stop there. The regulation doesn't: for SMEs the cap flips to whichever is lower, and enforcement runs through national market surveillance authorities, member state by member state. Nobody is fining your blog on Monday morning.

The realistic near-term risk isn't the fine. It's publishing a photoreal AI image of something that never happened, unlabelled, and having it noticed. That was a bad idea before 2 August too. Now it's a bad idea with a legal citation attached.

Common questions

Do I have to label all AI-generated content in the EU?

No. The deployer disclosure duty in Article 50 covers deepfakes and AI-generated text published to inform the public on matters of public interest. AI-assisted ad copy, product imagery and blog posts with human editorial responsibility mostly trigger nothing. The Commission's own guidance says plainly that not all AI-generated content needs labelling.

Does Article 50 apply to UK or US companies?

Yes, when it counts. The AI Act applies to providers and deployers established outside the EU where the AI system's output is used in the EU. A UK team publishing AI-generated content to an EU audience is in scope; Brexit isn't an exemption.

What counts as a deep fake under the AI Act?

AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. That's the Article 3 definition. An obviously stylised AI illustration isn't one; a photoreal composite of a real place or person is.

Is your content built to be stood behind?

The same accountability trail that exempts you from Article 50's text rule is what gets you cited by AI in the first place. I audit both. Tell me what's broken.