Updated on 18 July 2026

AI Labeling Checklist 2026: 7 Steps to AI Act Compliance

Last updated: July 21, 2026

On August 2, 2026 (European Commission, implementation timeline), the transparency and labeling obligations under Article 50 of the AI Act take effect. Anyone who publishes AI-generated images, videos, audio, or texts, or operates a chatbot, must disclose this from then on. This AI labeling checklist guides you to compliance in seven clear, checkable steps, from clarifying your role through visible and machine-readable labeling to audit-proof evidence. Every line gives you concrete, actionable guidance, with verified deadlines and a tool that handles the four technical steps for you in minutes.

Key Takeaways

  • The deadline is August 2, 2026 (not the 8th). From this date, Article 50 of the AI Act applies EU-wide, including in Germany, with no transition period for new content.
  • Two roles, two obligations: providers (paragraph 2) mark outputs in a machine-readable way, deployers (paragraph 4) visibly disclose deepfakes and certain AI texts. E-commerce, D2C, and marketing are almost always deployers.
  • Visible AND machine-readable: a label on the content is enough for deployers; anyone playing it safe also embeds metadata (IPTC/XMP, C2PA).
  • One deadline shifts: the provisional Digital Omnibus pushes the machine-readable marking (paragraph 2) for legacy systems to December 2, 2026. The visible deployer obligation (paragraph 4) stays at August 2, 2026.
  • Fines: up to 15 million euros or 3% of global annual turnover.
  • Don't forget evidence: a register with a hash and timestamp protects you in case of a dispute or cease-and-desist notice.

Contents

  1. Checklist at a glance (overview table)
  2. Step 1: clarify your role
  3. Step 2: inventory your AI content
  4. Step 3: label visibly
  5. Step 4: label in a machine-readable way
  6. Step 5: verify
  7. Step 6: keep evidence
  8. Step 7: embed the process
  9. Get it all done automatically
  10. FAQ

This page belongs to our overview AI labeling obligations under the EU AI Act. If you want to understand the sanctions and deadlines in detail first, read AI Act deadlines and fines. You can look up unclear terms in the AI labeling glossary.

The AI Labeling Checklist at a Glance

Print out this overview or pin it next to your monitor, it is your quick-reference template for the entire process.

# Step Concrete Outcome Who Deadline
1 Clarify your role Documented: provider (paragraph 2), deployer (paragraph 4), or both everyone before 8/2/2026
2 Inventory AI content Complete asset list including date & "before/after 8/2" everyone before 8/2/2026
3 Label visibly Label directly on the image, video, text, chatbot Deployer from 8/2/2026
4 Label in a machine-readable way IPTC/XMP, C2PA, watermark if applicable, in the file Provider (mandatory), deployer (best practice) from 8/2/2026 (legacy systems: 12/2/2026)
5 Verify "Check file": label visible, metadata retained everyone ongoing
6 Evidence / register SHA-256 hash + timestamp + CSV export everyone ongoing
7 Process & documentation Labeling embedded in the approval workflow everyone permanent

Download idea: this table is available as a free checkable PDF checklist, including checkboxes and a deadline column. You get it directly in the tool at ki-kennzeichnen.de, along with an editable AI labeling template for your internal policy.

Below, each step in detail, with examples, edge cases, and a checkbox.

Step 1: Clarify Your Role, Provider or Deployer?

Article 50 of the AI Act is titled "Transparency Obligations for Providers and Deployers." Before you label anything, your role determines which paragraph applies to you:

  • Provider (paragraph 2): you develop or train an AI system that generates synthetic image, audio, video, or text outputs, and you place it on the market. Your obligation: mark outputs so that they are identifiable as artificially generated in a machine-readable way, "effective, interoperable, robust, and reliable, to the extent technically feasible."
  • Deployer (paragraph 4): you use a third-party AI system (such as ChatGPT, Midjourney, Sora) for your own published content. Your obligation: visibly disclose deepfakes (realistic but artificial image, audio, or video content) as well as AI texts on topics of public interest.

Example for distinction: an online shop that creates product visuals with Midjourney is a deployer. The startup that builds the image generation engine behind Midjourney is a provider. If you use a tool and offer its output to others as your own AI feature, both roles can apply.

For most companies in e-commerce, marketing, and communications, the rule is: you are generally a deployer (paragraph 4). You don't build models, you use third-party tools. We explain in detail which role specifically applies to your case and which obligations follow from it under Provider or deployer, obligations under Article 50.

Check off: ☐ Role documented (provider / deployer / both), including a one-sentence justification.

Step 2: Inventory All AI Content

You can only label what you know about. Create a complete inventory of all content that was fully or partially generated with AI. Systematically check these channels:

  • AI-generated product and advertising images (shop, landing pages, Amazon/eBay listings, social ads)
  • AI videos and animated clips (Reels, YouTube, product animations)
  • AI texts (blog, product descriptions, guides, chatbot responses)
  • Deepfakes, realistic-looking but artificial people, voices, or scenes (e.g., an AI testimonial)
  • generative image edits (background replacement, outpainting, generated-in objects, not plain retouching)
  • AI audio (synthetic voiceovers, music)

Note four pieces of information per asset: storage location, creation date, tool used, and whether it was placed on the market before or after 8/2/2026. The last item determines the deadline in step 4.

Field Example Entry
Asset hero-summer-2026.jpg
Location /shop/landingpage
Date 07/15/2026
Tool Midjourney v7
Before/after 8/2/2026 before → machine-readable by 12/2/2026

We address practical special cases separately for product images on Amazon & eBay and for AI labeling in e-commerce & marketing.

Check off: ☐ Inventory list of all AI assets complete and dated.

Step 3: Label Visibly

Visible labeling must happen on the content itself, not hidden in the legal notice or footer. Here is how you implement it per format:

  • Images: a visible label or icon, e.g. the note "AI generated." The European Commission provides an official, optional icon set for this (European Commission overview), with the variants basic, fully AI-generated, and partially AI-modified, each as SVG and PNG. Place the icon in a corner or in the caption. Details under EU icons for AI content and in practice under Labeling AI images.
  • Videos: a notice in a clearly visible spot, ideally displayed permanently or right at the start, see Labeling AI video.
  • Texts on topics of public interest: a clear notice about the AI generation (e.g., "This text was created with AI"). A lighter standard applies to artistic, fictional, or satirical formats; the disclosure must not disrupt the work. More on this under Labeling ChatGPT texts.
  • Chatbots: users must recognize at the start of the interaction that they are talking to an AI; an introductory sentence is enough.
  • Deepfakes: always visibly disclose as artificial, regardless of the channel. Deeper on the topic: Deepfake labeling.

Edge case, social ads: the platform label from Instagram, Meta, or TikTok does not automatically suffice legally; the platform's terms of service do not replace the statutory obligation under Article 50. Label independently. More on this under AI in advertising on Meta, Instagram & Google Ads.

Acceptable vs. insufficient: a clear notice such as "AI generated" or "Created with AI" is sufficient. Vague terms such as "stock image," "digital art," or "edited" are not sufficient.

Check off: ☐ Visible label on every affected asset, recognizable to humans.

Step 4: Label in a Machine-Readable Way

As a provider, machine-readable AI labeling is mandatory; as a deployer, it is a strongly recommended best practice, because platforms and search engines increasingly rely on these signals. The marking is embedded directly in the file and must be "effective, interoperable, robust, and reliable," to the extent technically feasible. In practice, that means:

  • IPTC/XMP metadata with the "Digital Source Type" field (e.g., the value trainedAlgorithmicMedia for purely AI-generated content)
  • C2PA / Content Credentials as a cryptographically signed proof of origin that also logs editing steps
  • optionally an invisible watermark that persists even after re-encoding

How these three standards work together and complement each other is explained in C2PA, IPTC & watermarks.

Important deadline, the Digital Omnibus: under the provisional Digital Omnibus (as of May 2026, Gibson Dunn), the machine-readable marking (paragraph 2) for systems placed on the market before 8/2/2026 has been postponed to December 2, 2026. The core deadline of August 2, 2026 remains fixed; the visible deployer labeling (paragraph 4) and the chatbot disclosure are not postponed.

Obligation Who From When
Visible disclosure (deepfake, text) Deployer, paragraph 4 August 2, 2026
Chatbot notice Deployer, paragraph 4 August 2, 2026
Machine-readable marking, new systems Provider, paragraph 2 August 2, 2026
Machine-readable marking, legacy systems Provider, paragraph 2 December 2, 2026

Check off: ☐ Metadata / C2PA written into every file.

Step 5: Verify, Does the Labeling Survive Export?

Trust is good, verification is mandatory. The most common mistake: the metadata is embedded but gets removed again during upload. Spot-check whether:

  • the visible label is actually visible and legible (including on mobile devices),
  • the metadata has survived the export through a CMS, image compression, or a social platform, many platforms strip IPTC/XMP during upload,
  • the C2PA signature can be validated with a viewer.

Example: you correctly label an image with IPTC metadata but upload it to Instagram, and the platform removes the metadata. Result: only the visible label still carries the labeling. This is exactly why the visible layer is the more reliable one for deployers. A "check file" check reliably shows you what is really in the file, before and after upload.

Check off: ☐ Labeling technically verified (spot check per channel).

Step 6: Keep Evidence, the Labeling Register

In the event of a dispute, for example a cease-and-desist notice or a regulatory inquiry, you must be able to prove that and when you labeled the content. So set up a labeling register that documents, per asset:

  • the SHA-256 hash of the labeled file (a unique fingerprint)
  • the timestamp of the labeling
  • the labeling method used (label / metadata / C2PA)
  • export as CSV for audit-proof archiving

This evidence is your safeguard in the event of a complaint. You can read about which sanctions loom in a worst case, up to 15 million euros or 3% of global annual turnover, under AI Act deadlines and fines.

Check off: ☐ Evidence register with hash & timestamp set up.

Step 7: Embed the Process & Documentation

Labeling is not a one-time task but part of every piece of content production. To make it run permanently alongside your workflow:

  • define a responsible role (who checks before publication?),
  • integrate labeling firmly into your content and approval workflow (e.g., as a mandatory step before go-live),
  • record an internal policy in writing as an AI labeling template: which wording, which icon, which metadata, who countersigns.

Example of a mini policy: "Every AI image receives the EU icon fully AI-generated in the bottom right before publication, the IPTC field Digital Source Type = trainedAlgorithmicMedia, and an entry in the register. Approved by the marketing lead."

Check off: ☐ Labeling documented in the standard workflow and assigned to a role.

Getting Four Steps Done Automatically

Steps 3 through 6 are technical, and those are exactly the ones we take off your hands. The free web tool at ki-kennzeichnen.de combines everything in one flow:

  • a visible EU label via drag and drop onto images and videos (official icon variants),
  • machine-readable embedding (IPTC/XMP, optionally C2PA + an invisible watermark),
  • "check file" to verify what is really in the file,
  • an evidence register with SHA-256, timestamp, and CSV export,
  • batch processing (up to 50 files as a ZIP), custom icon sets, templates, and a REST API for automation.

This lets you check off four of the seven steps in a few minutes, including the evidence that purely client-side labeling tools don't offer. Label AI content for free now →

Frequently Asked Questions (FAQ)

Do I even need to label?

If you publish AI-generated images, videos, audio, or deepfakes, or operate a chatbot, generally yes. Purely internal, unpublished use is not affected. When in doubt, use the self-check in the tool.

From when does the AI labeling obligation apply in Germany?

The obligations under Article 50 of the AI Act apply EU-wide, and thus also in Germany, from August 2, 2026 (not August 8). The machine-readable marking for legacy systems has been provisionally postponed to December 2, 2026.

Who has to label, me or the AI tool?

Both, but differently: the provider (the tool maker) marks outputs in a machine-readable way (paragraph 2). The deployer (you as the user) visibly discloses deepfakes and certain texts (paragraph 4). As a company in marketing, you are almost always a deployer.

No. Labeling must happen on the content itself, on the image, in the video, or directly in the chatbot. A blanket note in the legal notice is not sufficient.

Which wording is acceptable?

A clear notice such as "AI generated" or "Created with AI." Vague terms such as "stock image," "digital art," or "edited" are not sufficient.

Do I need to label images retouched with AI?

Plain retouching (color correction, minor fixes) generally does not trigger an obligation. But as soon as the content is generatively created or substantially altered (added objects, swapped background, deepfake), the labeling obligation applies.

Is the AI label from Instagram or TikTok enough for Article 50?

Not necessarily. Platform labels are based on the platform's terms of service and don't automatically replace the statutory obligation under the AI Act. Label independently, and check whether your metadata survives the upload.

Are the EU icons mandatory?

No. The official EU icon set is optional, but recommended, because it creates recognizability and interoperability. You may also use a clear text notice.

What happens if I violate the labeling obligation?

Fines of up to 15 million euros or 3% of global annual turnover, whichever amount is higher. There is also the possibility of cease-and-desist notices from competitors. Details under Penalties & cease-and-desist notices.

How do I prove, in case of a dispute, that I labeled correctly?

Through a labeling register with a SHA-256 hash and timestamp per file (step 6). The tool at ki-kennzeichnen.de generates this register automatically and exports it as CSV.

Sources

This article does not replace legal advice. It reflects the status as of July 21, 2026; the Digital Omnibus is provisional at this time. For your specific case, please consult qualified legal advice.

Read more