Updated on 20 July 2026
AI Labeling Glossary: All Terms on the EU AI Act Explained
The AI labeling glossary defines all the key terms around the AI labeling obligation under the EU AI Act in a clear, searchable form. Anyone dealing with Art. 50 quickly runs into a thicket of technical terms: provider, deployer, C2PA, IPTC DigitalSourceType, synthetic content, watermark. Every entry in this glossary provides a precise definition and links to an in depth article, so you get from the keyword straight to a practical guide. The relevant deadline for the transparency obligations under Art. 50 of the EU AI Act is August 2, 2026.
This glossary is aimed at D2C brands, e-commerce retailers, and marketing teams that use AI generated images, videos, or texts and want to label them correctly. Last updated: July 21, 2026.
Key takeaways
- Art. 50 EU AI Act governs the transparency obligations for AI content and applies from August 2, 2026.
- Providers must mark synthetic outputs in a machine readable way (paragraph 2), deployers must disclose deepfakes visibly (paragraph 4).
- As a D2C brand, shop, or marketing team, you are usually the deployer.
- Machine readable techniques: IPTC DigitalSourceType/XMP, C2PA (Content Credentials), and watermarks.
- The official EU icons are optional, not mandatory.
- Violations can be sanctioned with up to 15 million euros or 3 percent of worldwide annual turnover.
- The Digital Omnibus only postpones the machine readable marking for legacy systems to December 2, 2026, the core deadline remains.
Table of contents
- Basic legal terms
- Roles: provider and deployer
- Content types and techniques
- Sanctions and enforcement
- Use cases by content and channel
- Terms at a glance (table)
- Labeling in 5 steps
- Frequently asked questions (FAQ)
Terms at a glance
| Term | Short definition | Who is affected? |
|---|---|---|
| Art. 50 EU AI Act | Transparency obligations for AI content, valid from August 2, 2026 | Providers and deployers |
| Provider | Must mark AI outputs in a machine readable way (paragraph 2) | Providers of AI systems |
| Deployer | Must disclose deepfakes visibly (paragraph 4) | Shops, D2C, marketing |
| Synthetic content | AI generated or substantially altered media | Everyone who uses AI |
| Deepfake | Deceptively realistic AI content | Deployer (paragraph 4) |
| Machine readable | Marking via IPTC/XMP, C2PA, or watermark | Provider (paragraph 2) |
| IPTC DigitalSourceType | Metadata field for digital provenance | Provider |
| C2PA / Content Credentials | Cryptographically signed proof of provenance | Provider |
| Watermark | Usually invisible signature in the media data | Provider |
| EU icons | Optional official labeling icons | Everyone (voluntary) |
| Digital Omnibus | Amendment package, postpones paragraph 2 for legacy systems | Providers of legacy systems |
| Sanctions | Up to 15 million euros or 3 percent of annual turnover | For violations |
Basic legal terms
AI Act Regulation (EU) 2024/1689, officially the "EU AI Act," has been in force since August 1, 2024. It governs the use of artificial intelligence in the EU using a risk based approach, ranging from prohibited practices through high risk systems to transparency obligations for the standard case. For AI labeling, Article 50 is the most relevant. → Pillar: the AI labeling obligation under the EU AI Act
Art. 50 EU AI Act Art. 50 of the EU AI Act is the central article on transparency obligations for AI content. It obliges both providers (paragraph 2) and deployers (paragraph 4) of AI systems to make AI generated or AI manipulated content transparent. The obligations apply from August 2, 2026, 24 months after the regulation entered into force. Legal text: artificialintelligenceact.eu/article/50
Transparency obligation The transparency obligation is the overarching requirement of Art. 50: users should be able to recognize that they are interacting with an AI system or looking at AI generated content. It comprises two levels, the technical, machine readable marking by providers, and the disclosure visible to humans by deployers. Both levels complement each other and do not replace one another. → The AI labeling obligation at a glance
Labeling obligation The labeling obligation is the practical core of the transparency obligation: the concrete requirement to mark synthetic content and, in the case of deepfakes, to disclose it visibly to viewers. It covers images, audio, video, and certain texts. What exactly needs to be done depends on your role (provider or deployer) and the type of content. → The AI labeling obligation: who, what, from when
Deadline: August 2, 2026 August 2, 2026 is the relevant deadline from which the transparency obligations under Art. 50 apply. It results from the regulation entering into force on August 1, 2024, plus a 24 month transition period. By this date, labeling workflows should be established in image, video, and text production. → AI Act deadlines and fines
Digital Omnibus The Digital Omnibus is an amendment package from the EU Commission (preliminary, as of May 2026). It postpones the machine readable marking (Art. 50(2)) to December 2, 2026 for systems placed on the market before August 2, 2026. The core deadline of August 2, 2026 remains in place, and the visible deployer labeling (paragraph 4) is not postponed. → AI Act deadlines and fines
Roles: provider and deployer
Provider A provider is whoever develops an AI system or offers it under their own name or brand, for example the maker of an image generator. Under Art. 50(2), providers must mark synthetic image, audio, video, and text outputs in a machine readable way, for example via IPTC/XMP metadata, C2PA, or watermarks. The standard: the marking must be "effective, interoperable, robust, and reliable, as far as technically feasible." → Provider and deployer obligations in detail
Deployer A deployer is whoever uses an AI system in their own professional context, for example a shop that uses AI product images, or an agency that creates AI advertising. Under Art. 50(4), deployers must disclose deepfakes visibly and label AI generated text on matters of public interest. D2C, e-commerce, and marketing teams are almost always deployers. → Provider and deployer obligations
Dual role Many companies are simultaneously deployers and, in effect, publishers of the content. Whoever only uses an AI tool is a deployer and owes the visible disclosure. Whoever redistributes or modifies their own AI outputs under their own name and places them on the market can additionally fall into obligations close to those of a provider. When in doubt, label visibly and preserve the metadata. → Provider and deployer obligations
Art and satire exception A lighter standard applies to obviously artistic, creative, fictional, or satirical works (Art. 50(4)). A restrained disclosure that does not impair the enjoyment of the work is sufficient here, for example a subtle notice instead of an intrusive label placed in the middle of the image. The exception does not fully exempt you from transparency, but it does lower the requirements for how the disclosure is displayed. → Deepfake labeling
Content types and techniques
Synthetic content Synthetic content is images, audio, video, or text generated or substantially altered by an AI system. It is the core term that the labeling obligation attaches to. Not every small AI retouch turns a photo into synthetic content, what matters is whether the content is, in substance, AI generated or significantly manipulated. Example: a fully AI generated product image is synthetic, a simple exposure correction generally is not.
Deepfake A deepfake is AI generated or AI manipulated image, audio, or video content that deceptively resembles real people, objects, places, or events and could falsely appear authentic. Deployers must disclose deepfakes visibly under Art. 50(4). Typical examples: an AI testimonial with an invented face, a realistic looking product video, or a cloned voice in a commercial. → Deepfake labeling
Machine readable Machine readable means that a marking can be automatically detected by software, as opposed to a label visible to a human. It is implemented via metadata (IPTC/XMP), C2PA signatures, or embedded watermarks. This level is mandatory for providers (paragraph 2) and is the basis on which platforms can automatically detect and label AI content. → Machine readable labeling: C2PA, IPTC, and watermarks
IPTC DigitalSourceType
IPTC DigitalSourceType is a standardized metadata field from the IPTC standard that describes the digital provenance of an image, for example trainedAlgorithmicMedia for fully AI generated content or compositeWithTrainedAlgorithmicMedia for partially AI altered images. The value is written directly into the image file and is machine readable. It counts as one of the most practical techniques for marking AI images. → C2PA, IPTC, and watermarks
XMP metadata XMP ("Extensible Metadata Platform") is a format developed by Adobe for embedding structured metadata in files such as JPEG, PNG, TIFF, or PDF. XMP carries, among other things, the IPTC DigitalSourceType value and anchors the AI provenance permanently in the file format. Because many programs and platforms read XMP, it is well suited as an interoperable carrier of machine readable labeling. → C2PA, IPTC, and watermarks
C2PA / Content Credentials The "Coalition for Content Provenance and Authenticity" (C2PA) defines an open standard for cryptographically signed proof of provenance. "Content Credentials" is the common brand name for it. C2PA attaches a tamper evident history to the file: who created it, with which tool, and whether and how AI was involved. Manipulating the file breaks the signature, which makes the tampering detectable. → C2PA, IPTC, and watermarks
Watermark A watermark is a, usually invisible, signature embedded directly into the pixel or audio data, meant to survive conversion, compression, or a screenshot. Unlike metadata, a robust watermark survives the removal of file information. It is one of several permitted techniques for machine readable marking and is often combined with metadata. → C2PA, IPTC, and watermarks
EU icons EU icons are official image marks provided by the EU Commission for labeling AI generated content, in three variants (basic, fully AI generated, partially AI modified), available as SVG and PNG. Their use is optional: what is mandatory is labeling as such, not the use of these exact icons. They do, however, offer a recognizable, EU wide, consistent visual standard. → Using EU icons for AI content correctly
Visible label A visible label is the disclosure recognizable to humans that a piece of content is AI generated, for example an icon, a text overlay, or a note in the caption. It is the core of the deployer obligation for deepfakes (paragraph 4). Important: the visible label does not replace the machine readable marking, it complements it for the human viewer. → EU icons for AI content
Sanctions and enforcement
Fine / sanctions Violations of the transparency obligations under Art. 50 can be sanctioned with fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever amount is higher. The specific amount depends on the severity, duration, and intent of the violation, the risk is significant even for smaller companies. → AI Act deadlines and fines
Cease-and-desist letter Alongside regulatory sanctions, Germany also carries the risk of a cease-and-desist letter under competition law from competitors or associations, for example for unlabeled AI product photos that could be considered misleading. Unlike a regulatory procedure, a cease-and-desist letter can happen quickly and without an authority involved, and it causes costs directly. For shops and marketing, this is often the more immediate risk. → AI labeling: penalties and cease-and-desist letters
Compliance register / proof A compliance register documents which content was labeled when and how, for example with an SHA-256 checksum per file, the labeling type, and a timestamp. It serves as proof of diligence toward authorities and in the event of a cease-and-desist letter. An auditable register turns "we labeled it" into verifiable, exportable evidence. → AI labeling checklist
Use cases by content and channel
Labeling AI images AI generated photos and graphics ideally carry the marking twice: machine readable in the metadata (IPTC/XMP, C2PA), and, where deepfake relevant, visible via a label. That way you are transparent both toward platforms and toward end customers. → Labeling AI images
AI product images on Amazon / eBay AI generated product photos in marketplace listings are a common use case. Labeling creates transparency for customers and at the same time satisfies both platform and legal requirements, important to avoid listing suspensions and cease-and-desist letters. → Labeling AI product images on Amazon and eBay
AI advertising on Meta / Instagram Platforms such as Meta partly recognize metadata automatically and label content themselves. If you mark it correctly in a machine readable way, you keep control over how it is displayed instead of leaving it to the platform's automatic system. → AI advertising on Meta and Instagram ads
Labeling AI video The same principles apply to generated or manipulated videos as to images, metadata plus a visible label for deepfakes. For videos, you also need to pay attention to a permanently visible overlay that survives further editing. → Labeling AI video
Labeling AI texts (ChatGPT) Deployers must disclose AI generated texts on matters of public interest. Relief applies for purely internal, artistic, or clearly editorially reviewed content. A transparent notice at the start or end of the text satisfies the obligation in most cases. → Labeling AI texts from ChatGPT
E-commerce and marketing overall Whoever uses AI in a shop, content, and campaigns should establish a consistent labeling workflow instead of handling individual cases. That reduces errors and makes compliance scalable. → AI labeling in e-commerce and marketing
The AI labeling glossary in practice, the free tool
You do not have to implement labeling manually. The free AI labeling tool from Scalemaker covers all the techniques named in this glossary in a single workflow:
- Visible EU label by drag and drop onto images and videos (official EU icons)
- Machine readable marking via IPTC/XMP metadata, C2PA, and watermarks
- Check file: test existing files for labeling that is already present
- Compliance register with SHA-256 proof and CSV export
- Batch processing (up to 50 files as a ZIP) and a REST API
Unlike purely client side tools, the backend offers an auditable register, proof export, batch processing, and an API. → Get started for free now
Labeling in 5 steps
- Determine your role. Clarify whether you are a provider (paragraph 2) or, as is usual, a deployer (paragraph 4). That determines which obligation primarily applies to you.
- Classify the content type. Check per file: fully AI generated, partially AI altered, or a deepfake? That decides the right IPTC value and the visible label.
- Mark in a machine readable way. Write IPTC/XMP metadata into the file and, where sensible, C2PA and a watermark.
- Label visibly. For deepfakes and content subject to the deployer obligation, add a visible EU icon or a notice.
- Secure proof. Record every labeling event with an SHA-256 checksum in the register and export the evidence.
→ To the complete AI labeling checklist
Frequently asked questions (FAQ)
From when does the AI labeling obligation apply? The transparency obligations under Art. 50 of the EU AI Act apply from August 2, 2026, 24 months after the regulation entered into force on August 1, 2024.
Do I as a shop or marketing team even have to label content? Yes. Whoever publishes AI content in a professional context is usually a deployer and must disclose deepfakes visibly and label AI text on matters of public interest. → Provider and deployer obligations
What is the difference between provider and deployer? The provider develops or distributes the AI system and must mark outputs in a machine readable way (paragraph 2). The deployer uses the system and must disclose deepfakes visibly (paragraph 4). Shops and marketing teams are usually deployers.
Who has to label a deepfake? The deployer who publishes or distributes the deepfake. The disclosure must be visible to viewers, for art and satire a restrained notice is sufficient. → Deepfake labeling
Are the EU icons mandatory? No. The official EU icons are an optional offering from the EU Commission in three variants (basic, fully AI generated, partially AI modified). What is mandatory is labeling as such, not the use of these exact icons.
What does "machine readable" mean in concrete terms? A marking automatically recognizable by software, implemented via IPTC/XMP metadata, C2PA signatures (Content Credentials), or embedded watermarks, as opposed to a label visible to humans. → C2PA, IPTC, and watermarks
Does the Digital Omnibus move the deadline? Only partially. Under the preliminary Digital Omnibus (as of May 2026), the machine readable marking is postponed to December 2, 2026 for systems placed on the market before August 2, 2026. The core deadline of August 2, 2026 and the visible deployer labeling remain unchanged.
What happens in the event of violations? Up to 15 million euros or 3 percent of worldwide annual turnover (whichever amount is higher). In Germany, the risk of cease-and-desist letters under competition law comes on top of that. → AI labeling: penalties and cease-and-desist letters
How do I prove that I labeled correctly? Through a compliance register with an SHA-256 checksum, timestamp, and labeling type per file, which can be exported as CSV. → AI labeling checklist
Is a visible label alone enough? For deployers dealing with deepfakes, the visible label is central, but it does not replace machine readable marking where that is required. The combination of both is safest. → Labeling AI images
Sources
- EU AI Act, implementation timeline (EU Commission)
- Guidelines on the transparency obligations (Art. 50), EU Commission
- EU icons for labeling AI generated content (EU Commission)
- Art. 50 EU AI Act, full text
- EU AI Act Transparency Obligations, compliance by August 2, 2026 (Sidley)
- EU AI Act Omnibus Agreement (Gibson Dunn)
Last updated: July 21, 2026. This article does not constitute legal advice. Please consult qualified legal counsel for your specific situation.