The EU AI Act just made "AI-generated" a required, machine-readable label. Here is who has to use it.
Framework spark: Samyak Jain's governance-lens read of the AI Act on LinkedIn, and Gianna Brachetti's Article 50(4) decision tree. Primary sources: Regulation (EU) 2024/1689 and the European Commission.
The short version
- The EU AI Act's Article 50 turns "is this AI-generated?" into a required, machine-readable field starting August 2, 2026; the web is getting a provenance layer, and marketers are the deployers on the hook for the human-facing half of it.
- The deadline holds. The Digital Omnibus postponed the high-risk rules to 2027 and 2028 but left Article 50 on August 2, 2026; only the marking of AI tools already on the market before that date gets a grace period, to December 2, 2026.
- The AI tool you use marks its own output because that is the provider's job, but you as the deployer still owe a separate, human-facing disclosure for deepfakes and for text that informs the public on matters of public interest. Ordinary product marketing text sits outside that obligation; an AI image of a real person may not.
- Breaches carry fines up to 15 million euros or 3% of worldwide annual turnover. Labeling AI content is a transparency requirement, not a confirmed search-ranking penalty, but the provenance mark is about to become a signal the same engines you optimize for can read.
On August 2, 2026, roughly two and a half weeks from this writing, the transparency rules in Article 50 of the EU AI Act become enforceable. Most of the coverage treats this as a compliance story for legal teams. Read it from where I sit, and it is something else: the European Union is about to require that AI-generated content carry a machine-readable mark of its origin. The web is getting a provenance field, and the people who publish and optimize content are the ones who have to fill it in.
Article 50’s transparency obligations apply from August 2, 2026. Breaches carry fines up to 15 million euros or 3% of worldwide annual turnover.
What actually changes on August 2, 2026?
Article 50 forces two kinds of disclosure: a machine-readable one and a human-facing one. It is not a single rule but a set of transparency obligations split across the providers who build generative AI systems and the deployers who use them, and the paragraphs that carry the weight divide into two provider duties and two deployer duties.2
Here is where each obligation lands.
- 50(1). Providers of systems that interact directly with people must build in a notice that the person is dealing with an AI, unless that is obvious to a reasonably well-informed person.2 This is the “you are chatting with a bot” rule.
- 50(2). Providers of generative systems must ensure their synthetic audio, image, video, and text output is “marked in a machine-readable format and detectable as artificially generated or manipulated.”2 This is the machine disclosure, and it is the one that quietly changes the web.
- 50(3). Deployers of emotion-recognition or biometric-categorization systems must tell the people exposed to them.2 Rare in marketing; I will set it aside.
- 50(4). Deployers must disclose deepfakes and must disclose AI-generated or AI-manipulated text “published with the purpose of informing the public on matters of public interest.”2 This is the human disclosure, and it is the one most likely to reach you.
Two of those four are provider duties and two are deployer duties. That provider/deployer split is the whole game, so hold onto it.
Wait, didn’t the Digital Omnibus delay all of this?
No. The Digital Omnibus delayed the expensive high-risk regime and deliberately left the Article 50 transparency rules alone. When the Commission proposed the Digital Omnibus to relieve timeline pressure, the relief went to the standalone high-risk systems in Annex III, whose obligations moved to 2027 and 2028 while the supporting standards and guidance get built.5 Article 50 was not in that package. Its August 2, 2026 application date stands.4
There is exactly one softening, and it is narrow. The 50(2) marking obligation for generative systems that were already placed on the market before August 2 does not bite until December 2, 2026.3 Systems that ship on or after August 2 get no such runway. So the model behind whatever tool you adopt next is on the immediate timeline; the one you have been using since last year has four extra months. Either way, enforcement authority is live on August 2, and an Article 50 breach sits in the AI Act’s second-highest penalty tier: fines up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher.1
What is the “provenance layer,” and why should an SEO care?
Article 50(2) requires a machine-readable mark, not a visible label, and machine-readable content is precisely the layer SEO and GEO practitioners already work in. When a regulator says synthetic output must be “detectable as artificially generated,” it is describing metadata: a watermark, a cryptographic manifest, a signed provenance record that travels with the file. The leading implementation is C2PA, the content-provenance standard already adopted across major camera makers, editing software, and model providers.9 The AI Act does not mandate C2PA by name; 50(7) tasks the AI Office with facilitating a Code of Practice on detecting and labeling AI content,6 with the Commission’s draft Article 50 guidelines fleshing out how the obligations apply in practice,7 and the market is converging on provenance manifests to satisfy it.
To confirm this is already real and not a 2027 problem, I ran a quick test: I generated an image with OpenAI’s current image model, gpt-image-1, the one behind ChatGPT’s image feature, and inspected the raw file. It carried a full C2PA manifest, a signed provenance record naming “OpenAI Media Service API” as the generator and tagging the file, in IPTC’s vocabulary, as trainedAlgorithmicMedia, meaning AI-generated. No special access and no detection model, just metadata sitting in the file that any parser can read. Anyone can check a suspected image the same way by dropping it into the Content Credentials verify tool.9 The provenance mark is not coming; for images from the major generators, it is already there.
Call this the provenance layer: a new stratum of the web where every synthetic asset carries a detectable mark of its AI origin, readable by the same crawlers and answer engines that read your structured data. That framing is my own, and I label it as such, but the mechanism under it is not speculative. The moment a law requires machine-readable AI marks at the scale of every EU-facing generative tool, “was this made by AI?” stops being a guess a detector has to make and becomes a field that is often already filled in.
For anyone who thinks about how machines read the web, that is the interesting part. We spend our time making content legible to systems through schema, clean HTML, and feeds. Article 50 adds a new attribute to that same legibility layer, and unlike schema it is not optional and not authored by you. It is stamped by the tool.
Are you a provider or a deployer? (Almost certainly a deployer.)
If you use ChatGPT, Claude, Gemini, or Midjourney to make content, you are a deployer, and your live obligations are the human ones in 50(4), not the machine one in 50(2). The provider is whoever built and placed the model on the market; the deployer is whoever uses it under their own authority.2 That distinction decides who owes what.
- The provider owes the 50(2) machine-readable marking of the output and, for a conversational product, the 50(1) “you are talking to AI” notice.
- The deployer, which is you, owes the 50(4) disclosures: deepfakes, and text published to inform the public on matters of public interest.
Here is the trap, and it is the thing I most want you to leave with. The provider marking the file does not discharge your disclosure. I will call it the provider-deployer disclosure gap: the model stamps a machine-readable mark in the metadata, but if you publish a deepfake or public-interest text, you still owe a separate, human-facing disclosure that a reader can actually see. The split itself is well-documented in the compliance literature; marketers rarely hear it named, and naming it for that audience is the point. The two obligations live at different layers and neither substitutes for the other.
One caveat that promotes some deployers into providers. If you fine-tune, substantially modify, or put your own name on a general-purpose system and market it, the Act can treat you as a provider, with the marking duty attached.1 Most marketers will not cross that line; teams shipping their own branded AI features should assume they might.
Do you actually have to label your AI content?
For ordinary product marketing text, almost certainly not; for text you publish about public-interest topics, walk the four questions below. The public-interest text obligation in 50(4) is narrower than the panic suggests, and Gianna Brachetti’s decision tree is the cleanest walk-through of it.8
- Scope. Does the content inform the public on a matter of public interest, meaning current affairs, health, environment, politics, consumer protection, economic or scientific matters? If no, 50(4)’s text rule does not apply. Ordinary product marketing lands here: outside the obligation.
- Expertise. If it is public-interest content, is there a reviewer with genuine domain expertise? If not, disclose.
- Substantive review. Does that reviewer actually verify the claims rather than proofread? If not, disclose.
- Editorial responsibility. Is a named person or organization ready to own full publisher liability for an error? If yes, 50(4) provides an editorial-responsibility exemption and no label is required. If no, disclose.2
Consider a concrete case, since the abstraction hides the work. A direct-to-consumer skincare brand publishes an AI-drafted explainer titled “is retinol safe during pregnancy” and illustrates the page with an AI-generated image of its founder. Walk each asset separately. The explainer is text on a health matter, so it clears question one into the obligation; if a qualified reviewer substantively verifies the claims and the brand owns editorial responsibility, it can take the exemption, and otherwise it discloses. The founder image is a different branch entirely: it is a synthetic depiction of a real person, so it is a deepfake under 50(4) and carries its own disclosure duty regardless of how the copy around it is classified. Two assets, one page, two different answers. That is why “is our marketing exempt” is the wrong question. The unit of analysis under Article 50 is the asset, not the page.
That four-question structure tells you what the EU is actually regulating. It is not trying to tag every AI sentence; it is trying to make sure AI-written text on things that affect people is either owned by a human editor or labeled as machine-made. That is a governance mechanism wearing a disclosure costume, which is the deeper point in Samyak Jain’s read of the Act.10
Does labeling content “AI-generated” hurt your search or AI-citation visibility?
There is no evidence today that an AI-provenance mark is a ranking penalty, and Google’s stated position cuts against the fear. Google has said for years that it rewards helpful, high-quality content regardless of how it is produced, and that using AI is not against its guidelines;11 the target is low-value content, not AI as a method. A machine-readable provenance mark is a transparency signal, not a documented ranking factor, and treating it as radioactive is not supported by anything on the record.
There is a distinction the ranking question obscures, and it is where the real GEO story sits. The 50(2) machine mark rides in metadata, invisible to a reader, and no search or answer engine has said it reads that mark as a ranking or citation input. The 50(4) human disclosure is the visible one, the text a model can quote and a reader can see, and it is the one you author. My read, labeled as inference: the visible disclosure is where the risk and the opportunity both live, because specificity is a trust signal and vagueness is a warning label. A line that reads “drafted with AI, reviewed and verified by a named editor” reads as accountability; a bare “AI-generated” stamp slapped across a whole page reads as a health warning. If provenance ever does become a weighted signal, the specific and accountable version is the one you want to be caught holding.
So the forward read, and I label it plainly as inference: as answer engines lean harder on trust and source signals, a machine-readable “AI-generated” mark is exactly the kind of input a system could start weighting, especially for the public-interest and health-adjacent topics where these engines are most cautious about what they cite. That is not the state of play in July 2026; it is the direction the provenance layer points. The defensible position is neither to hide AI involvement nor to slap a blanket banner on everything, but to make disclosures truthful, specific, and scoped to what the law actually requires. Over-labeling is its own trust problem.
What to actually do before August 2
Map, then disclose only where the law bites. The work is smaller than the headlines imply if you sort it by the provider-deployer split.
- Inventory your generative touchpoints. List where AI produces public-facing output: on-site chat and support bots, AI-written articles and guides, synthetic product or lifestyle imagery, generated video.
- Confirm your vendors mark their output. For every generative tool you deploy, the 50(2) machine-readable marking is the provider’s job; verify in their documentation or contract that they do it, since you are relying on it.
- Find your 50(4) exposure. Flag two things: any deepfake, meaning AI-generated or AI-manipulated media depicting a real person, and any AI-written text that informs the public on a public-interest matter. Those need a human-facing disclosure unless an exemption applies.
- Decide editorial responsibility for public-interest text. If you publish in that category, either run substantive human review under a named owner and claim the editorial exemption, or disclose. Document which path you chose.
- Add the “talking to AI” notice to bots. If you run a customer-facing chatbot, make sure it says so at first interaction.
None of this requires labeling your catalog. It requires knowing which of your content is a deepfake, which informs the public, and which is neither, and then disclosing on the first two. The provenance layer will handle the machine half whether you think about it or not. Article 50 is really about making sure a human is accountable for the rest.
Terms defined here
- Provenance layer. The emerging machine-readable stratum of the web in which every piece of synthetic media carries a detectable mark of its AI origin. Under EU AI Act Article 50(2), providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable format that is detectable as artificially generated; combined with content-provenance standards such as C2PA, this makes AI origin a structured signal that crawlers and answer engines can read the same way they read schema.
- Provider-deployer disclosure gap. The gap between what an AI tool marks automatically and what the human publishing the output must still disclose. Under Article 50, the provider of a generative model owes the machine-readable marking of its output (50(2)); the deployer who publishes that output still owes a separate, human-facing disclosure for deepfakes and public-interest text (50(4)). The tool marking your content does not discharge your disclosure duty.
Sources
- Regulation (EU) 2024/1689 (the EU AI Act), including Article 50 and the Article 99 penalty tiers, via EUR-Lex
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems (readable text and paragraph structure)
- Sidley / Data Matters - EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026 (application date and the December 2, 2026 marking grace period)
- AI Act Blog - Article 50 transparency obligations: the 2 August 2026 deadline that has not been postponed
- Gibson Dunn - EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (high-risk deadlines moved to 2027 and 2028)
- European Commission - Code of Practice on Transparency of AI-Generated Content (Article 50(7) detection and labeling)
- European Commission - Draft guidelines on the implementation of the Article 50 transparency obligations
- Gianna Brachetti - EU AI Act Article 50(4) disclosure decision tree
- C2PA - Coalition for Content Provenance and Authenticity (the leading machine-readable content-provenance standard)
- Samyak Jain - The EU AI Act Isn't Really About AI. It's About Governance (LinkedIn, the governance-lens read that prompted this piece)
- Google Search Central - Google Search's guidance about AI-generated content (rewarding high-quality content however it is produced)
Recent developments
Related reading
This piece elsewhere