This content has been automatically translated and may include minor variations.
Somewhere in the last few years, “is this real?” became a fair question to ask about almost anything you come across online — a photo, a voice, a product shot, a conversation. That shift happened fast, and mostly without anyone deciding it should.
Article 50 of the EU AI Act is a response to that shift, and the intention behind it is a good one: if knowing something was AI-made would change how a person reads it, they’re entitled to know. Not that AI shouldn’t be used to generate or shape content — it says nothing about that. It says the audience gets to have accurate footing when they look at the result.
That’s a reasonable thing to ask for, and it’s one most brands would probably want to meet even without a regulator asking. Where the frustration lives is in the doing — tracing which assets involved AI and how much, deciding what counts as disclosure-worthy, and getting that answer to actually travel with the asset all the way to publication. That’s real operational weight, and it’s fair to feel that weight even while agreeing with the reason for it.
The EU AI Act’s transparency obligations became applicable on August 2, 2026. They are the broadest section of the entire regulation, because they reach any organization that uses a generative AI system – not only the companies that build one.
For anyone responsible for brand governance across markets, a narrower question is more useful: which of these duties falls on a brand, which falls on the AI vendors it uses, and what has to change in the workflow producing campaign content. Those are the questions customers have put to me for months.
What the EU AI Act actually requires?
Article 50 is not a single labeling rule. It sets out 4 distinct duties, aimed at different actors and carrying different exceptions, and collapsing them into one is the most common source of both over-compliance and under-compliance.
The duties are:
- People interacting with an AI system must be told they are, unless it is obvious from the context.
- Providers of systems generating synthetic audio, image, video, or text must mark those outputs in a machine-readable format, detectable as artificially generated or manipulated, to the extent technically feasible.
- People exposed to emotion recognition or biometric categorization systems must be notified.
- Deployers publishing deep fakes must disclose them visibly, as must those publishing AI-generated text to inform the public on matters of public interest.
Enforcement arrived on the same date as the obligations themselves. Breaches of Article 50 sit in the tier carrying administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Source: EU AI Act Article 99, 2024). Enforcement sits with national market surveillance authorities rather than with Brussels.
That ceiling is not the highest tier – prohibited practices carry up to €35 million or 7% – but it is high enough that “we assumed it had been delayed” is an expensive position to hold.
Why the disclosure duty lands differently on brands than on AI vendors
The distinction that matters most here is between a provider and a deployer. A provider builds or places an AI system on the market; a deployer uses one. A marketing organization generating campaign copy or imagery with a commercial AI tool is, in the ordinary case, a deployer.
That matters because the machine-readable marking duty falls on providers. The obligation to embed detectable markers in generated output sits with the vendors of the generative tools, not with the brand that used them.
What reaches a deployer is considerably narrower. Visible disclosure is required for deep fakes – content resembling real people, places, or events – and for AI-generated text published to inform the public on matters of public interest.
There is a further carve-out worth knowing about. The marking duty does not apply where AI performs only an assistive function for standard editing, or where it does not substantially alter the input data or its semantics. The European Commission adopted guidelines on the scope of these duties on July 20, 2026, ahead of the application date (Source: European Commission, 2026).
For most brand campaign work, the deciding questions are whether an asset resembles a real person, place, or event closely enough to count as a deep fake, whether text is being published to inform the public on a matter of public interest, and whether AI substantially altered the content or merely assisted with standard editing.
Answering those is a legal judgment, and it belongs with counsel rather than with a marketing team. The operational problem is a different thing entirely – and that one does belong to marketing.
What the Digital Omnibus delayed, and what it did not
The confusion is understandable, because something genuinely was postponed. It just was not this.
The amending regulation was published in the Official Journal on July 24, 2026 and entered into force three days later, days before the transparency duties became applicable (Source: Regulation (EU) 2026/1744, 2026). Obligations for stand-alone high-risk systems moved from August 2, 2026 to December 2, 2027, and high-risk AI embedded in regulated products moved to August 2, 2028.
Neither of those touches the transparency layer, because Article 50 applies regardless of risk classification. A marketing team generating social copy is not running a high-risk system, and never was – which is precisely why the high-risk delay does not reach it.
One transition does reach Article 50, and it is narrow enough to misread easily. Providers of generative systems already placed on the market before August 2, 2026 have until December 2, 2026 to implement machine-readable marking, while systems launched from August 2 onward must comply immediately.
Read that as a short engineering grace period for a specific set of AI vendors, not as a general reprieve. Every other duty in Article 50 has been live since August 2.
The gap between a legal minimum and an operational answer
Even where no disclosure is legally required, the question arrives anyway. Retailers, platforms, agencies, and enterprise customers are already asking brands to state whether AI was involved in a given asset, on timelines no regulation sets.
Most organizations cannot answer that question about their own libraries. Provenance information, where it exists at all, is scattered across file metadata that survives some tools and not others – and a large share of AI editing writes no provenance record whatsoever.
The regulation does at least draw a line under the back catalogue. Content generated before August 2, 2026 does not need to be labeled retroactively, though the Commission encourages it where possible (Source: European Commission, 2026).
The harder structural point is where disclosure falls due. The obligation attaches at publication, to the artifact an audience sees – not to the file sitting in a storage system. An asset can carry flawless provenance metadata all the way through a library and still be published in an advertisement that discloses nothing at all.
That is the gap most brand governance setups have not closed. Knowing which assets involved AI is a metadata problem; making sure the resulting advertisement, menu, or social post carries the right label is a production problem, and it usually sits with whoever built the template.

What we are doing about this at Papirfly
The questions reaching me from customers are rarely legal ones. They are operational: which of our assets involved AI, who recorded that, and whether the disclosure reaches the finished advertisement.
None of what follows is legal advice, and none of it decides anything on a customer’s behalf. Whether a specific asset needs a label is their own call, based on their own reading of the Act. What Papirfly provides is the mechanism.
Preservation comes first in how we have sequenced this. Where assets arrive carrying industry-standard content credentials, we keep that information intact as they move through the platform – because a system that discards provenance breaks the chain its customers depend on further downstream.
On top of that, teams can:
- Flag AI involvement on any asset – AI generated, AI modified, or neither – with a clear visual indicator in the platform.
- Filter the library to locate AI-involved assets for review or audit.
- Map existing metadata across so assets are flagged automatically rather than by hand.
- Add an AI label or disclaimer to documents produced in the platform, either using the EU icon, or in their own wording, design, and placement.
- Identify every Papirfly feature that uses AI through an AI icon, so people always know when they are working with an AI tool.
Every organization interprets the Act slightly differently, so none of this is fixed. There are several ways to configure it depending on the workflow and how prominent labeling needs to be, and more of it becomes automatic over time.
Two commitments on our own content, neither of them required of us under Article 50. Any article on this blog produced with AI assistance carries a note saying so, and any image published here that has been materially altered with generative AI is identified as such.
Waiting for a legal floor to force that question is not a brand governance strategy.
Conclusion
Less landed on brand teams on August 2 than the headlines implied, and more will be asked of them than the law strictly requires. Both things are true at once, and planning for only one of them is the mistake.
The legal question – which specific assets trigger a disclosure duty – belongs with counsel. The operational question is whether the systems storing and producing brand content can reliably answer “was AI involved here,” and carry that answer through to whatever gets published.
The principle worth holding onto is that provenance is only useful if it survives into the output. Teams able to trace AI involvement from asset to published artifact will find every version of this question easier – the regulatory one and the commercial one alike.
See how compliance works inside your asset library
Consent status, automatic flagging, and audit trails.
See how compliance works inside your asset library
Consent status, automatic flagging, and audit trails.
Consent status, automatic flagging, and audit trails.

FAQs
What exactly changed on August 2, 2026 under the EU AI Act?
The transparency obligations in Article 50 became applicable, covering AI system disclosure, machine-readable marking of AI-generated content, notification for emotion recognition and biometric categorization, and visible disclosure of deep fakes. The penalty provisions became operative on the same date, with fines for Article 50 breaches reaching up to €15 million or 3% of worldwide annual turnover.
Does the EU AI Act require all AI-generated marketing content to be labeled?
The visible disclosure duty on deployers applies to deep fakes and to AI-generated text published to inform the public on matters of public interest, not to all AI-assisted marketing content. Machine-readable marking is a separate duty that falls on providers of generative AI systems rather than on the brands using them.
Was the AI Act’s transparency deadline delayed by the Digital Omnibus?
Almost entirely no. The Digital Omnibus moved high-risk obligations to December 2027 and August 2028, but left the Article 50 transparency duties applicable from August 2, 2026. The single exception is a short transition allowing providers of generative systems already on the market to implement machine-readable marking by December 2, 2026.
Who is responsible for labeling AI content, the brand or the AI vendor?
It depends on which duty is in question. Machine-readable marking of generated output is a provider obligation, so it sits with the AI tool vendor, while visible disclosure of deep fakes and certain public-interest text sits with the deployer publishing the content.
Does content created before August 2, 2026 need an AI label?
Content generated before that date does not need to be labeled retroactively. The European Commission encourages organizations to do so where possible, but it is not a requirement.












