Updated on 26 July 2026

AI Labeling Under the EU AI Act: The Complete Guide

From 2 August 2026, companies across the EU must transparently disclose AI-generated content as such under certain conditions. This obligation stems from Article 50 of the EU AI Act. This guide brings together everything marketing teams, e-commerce retailers, D2C brands and agencies in Germany need to know: what the law requires, who it affects, which deadlines and fines apply, and how to label images, videos and text correctly in practice. For every detailed question, the relevant section links to an in-depth article.

Table of Contents

What the EU AI Act Requires (Art. 50)

The AI labeling obligation stems from Article 50 of Regulation (EU) 2024/1689, the EU AI Act. In the original text, the article is titled "Transparency Obligations for Providers and Deployers of Certain AI Systems." The goal is simple: people should be able to recognize when they are dealing with AI-generated or AI-manipulated content, and when they are interacting with a machine rather than a human.

The EU AI Act entered into force on 1 August 2024. Its obligations, however, take effect in stages. The transparency obligations under Art. 50 become applicable 24 months after entry into force, that is, on 2 August 2026. Until then, companies have time to adapt their processes.

Important for understanding this: it is not a ban on AI content. Anyone who publishes AI content may continue to do so without restriction, just with disclosure. Nor does the law require a specific wording or a specific logo. What matters is that the disclosure is clear, recognizable and timely.

Art. 50 requires two technically quite different layers. The visible disclosure to humans (para. 4) primarily affects deployers. The machine-readable marking in the file (para. 2) affects the providers of the AI systems. On top of that comes a separate obligation for chatbots (para. 1): users must learn at the start of the interaction that they are communicating with an AI, unless this is already obvious from the context. Which of these layers affects you depends on your role. A compact explanation of the technical terms, from "synthetic" to "Content Credentials," is provided in the AI Labeling Glossary.

Who Is Affected: Providers and Deployers

Art. 50 consistently distinguishes between two roles. This distinction is the most important lever for determining your specific obligations.

  • A provider is anyone who develops an AI system and places it on the market under its own name. Examples: OpenAI, Midjourney, Google, Black Forest Labs. Providers are subject to Art. 50 para. 2 and must mark their outputs in a machine-readable format.
  • A deployer is anyone who uses an AI system in the course of their professional or commercial activity to create or publish content. Examples: the online shop, the agency, the freelancer, the public authority. Deployers are subject to Art. 50 para. 4 and must visibly disclose deepfakes and certain texts.
Criterion Provider (Art. 50 para. 2) Deployer (Art. 50 para. 4)
Who is this? Develops and places an AI system on the market Uses an AI system professionally or commercially
Examples OpenAI, Midjourney, Google, Flux Online shop, agency, broker, editorial team
Core obligation Mark outputs as AI in a machine-readable way Visibly disclose deepfakes and certain AI texts
Recognizable to whom? Machines, platforms, verification tools Humans
Deadline 2 August 2026 (legacy systems: 2 December 2026) 2 August 2026 (not postponed)

For most companies in marketing, e-commerce and the small and medium-sized business sector, the rule is: you are typically a deployer. If you generate a product photo with Midjourney, write a text with ChatGPT, or create an advertising video with a video tool, you are using someone else's AI system, not building one. The machine-readable marking at the source is owed by the respective tool provider, your deployer obligation concerns the visible disclosure to your audience.

The roles are not mutually exclusive, however. Anyone who substantially modifies a purchased model, renames it, or offers it as a product under their own name can themselves become a provider and then additionally bears the obligations under para. 2. For the vast majority of users, though, it remains the deployer role. You can find the full decision check at Provider or Deployer: Who Must Label AI Content.

Deadlines: What Applies When

The decisive date is 2 August 2026. From this day, the transparency and labeling obligations under Art. 50 apply directly. It results from the regulation entering into force on 1 August 2024 plus a 24-month transition period. The frequently cited date "8 August" is incorrect, it has no legal basis.

There is one important but narrowly limited nuance. Under the so-called Digital Omnibus (as of May 2026, provisional), the obligation to apply machine-readable marking under para. 2 for systems placed on the market before 2 August 2026 was postponed to 2 December 2026. This applies exclusively to legacy systems at the provider level.

Everything related to visible labeling has not been postponed:

  • The core deadline of 2 August 2026 remains fixed.
  • The visible deployer labeling of deepfakes (para. 4) applies from 2 August 2026.
  • The chatbot disclosure (para. 1) applies from 2 August 2026.
Date What applies? Who is affected?
1 August 2024 EU AI Act enters into force Starting point of the deadlines
2 August 2026 Art. 50: visible labeling, chatbots, machine-readable marking of new systems Deployers and providers
2 December 2026 Machine-readable marking for systems placed on the market before 2 August 2026 (Digital Omnibus, provisional) Providers only (legacy systems)

For the vast majority of companies that are deployers, the postponement changes nothing. Your visible obligations take effect on 2 August 2026. Moreover, the postponement is provisional and may change in the further legislative process. The safe strategy is: treat 2 August 2026 as your real deadline and regard the December buffer only as a technical grace period for legacy content. The complete timeline with all the details is compiled in the article AI Act: Deadlines and Fines at a Glance.

Fines, Sanctions and Cease-and-Desist Letters

Violations of the transparency obligations under Art. 50 carry fines of up to 15 million euros or 3 % of worldwide annual turnover, whichever amount is higher. This is the verified range you should remember. Supervisory authorities assess the amount on a case-by-case basis according to severity, duration and intent. A one-time oversight is weighed differently than systematic concealment.

Here is a common misconception to correct: many articles circulate the significantly higher figure of 35 million euros or 7 %. For the transparency and labeling obligation under Art. 50, this figure is simply wrong. The higher range applies to the most serious violations of prohibited AI practices (Art. 5), not to labeling. Anyone who cites 35 million euros for missing AI labeling has fallen for a widespread myth.

In addition to the regulatory fine, there is a second, often underestimated risk in Germany: the cease-and-desist letter (Abmahnung) under the UWG, the German Act Against Unfair Competition. Missing or misleading AI labeling, for example in advertising or product photos, can be classified as an unfair business practice and lead to a cease-and-desist letter from competitors or entitled associations. Unlike a fine proceeding, which an authority must first initiate, a cease-and-desist letter can land on your desk within days and trigger legal costs, a penalty-backed cease-and-desist declaration, and a contractual penalty. Especially in online retail, this risk is practically more relevant than the maximum regulatory penalty.

A third level appears in no piece of legislation but often weighs heaviest for brands: reputational damage. If it becomes known that a company is concealing AI content, loss of trust follows immediately. On top of that come platform sanctions: Meta, Instagram, TikTok, Amazon and eBay are expanding their own labeling rules, violations of which can lead to reduced reach, rejected ads or listing suspensions, independent of the law. You can read what to do in the event of a cease-and-desist letter and how to protect yourself at AI Labeling: Penalties, Fines and Cease-and-Desist Letters.

How to Label AI Content Correctly

Depending on your role, the EU AI Act requires up to four interlocking building blocks. For correct practice, you combine them so that the labeling is preserved even if one layer is lost during sharing or uploading.

The visible EU icon (deployer, para. 4) is the disclosure recognizable to humans, placed directly on the content. It belongs in the image or the video frame, ideally supplemented with the text "AI-generated." A hidden notice in the legal notice or footer explicitly does not suffice. For deployers in marketing and e-commerce, this is the central, legally required building block.

The machine-readable XMP/IPTC metadata (provider, para. 2) sits invisibly in the file and is read by platforms and verification tools. The relevant field is called "DigitalSourceType" and is stored in the XMP block. For fully AI-generated content, the correct value is trainedAlgorithmicMedia. If a real image was only partially altered by AI, for example by replacing the background, compositeWithTrainedAlgorithmicMedia is correct. This layer is mandatory for providers. For deployers, it is voluntary, but a strongly recommended best practice, because platforms and search engines increasingly rely on these signals.

An invisible watermark serves as redundancy. It is embedded directly in the pixels and survives re-compression, scaling and moderate editing significantly better than a metadata block. Where IPTC/XMP is stripped on upload, the watermark often continues to carry the machine-readable information.

C2PA / Content Credentials is the optional signature layer. C2PA attaches a cryptographically signed manifest to the file that verifiably documents what and when a piece of content was created with. If the file is manipulated, the signature breaks. C2PA best fulfills the "robust" and "reliable" criteria from Art. 50 para. 2, but it too can be lost if a platform strips all metadata.

None of these techniques alone fulfills the regulation's four requirements: "effective, interoperable, robust and reliable, as far as technically feasible." Only working together do they cover each other's weaknesses. In practice, many companies therefore combine the visible label for the audience with machine-readable metadata for platforms and verification tools. The article Machine-Readable AI Labeling: C2PA, IPTC and Watermarks shows how to technically write C2PA, XMP and IPTC metadata and where the limits lie. You can set up all four building blocks in a single pass with our free tool.

Labeling by Medium: Images, Videos, Text

The scope of the obligation differs depending on the content type. The central risk case across all media is the deepfake, a term defined by the regulation itself: AI-generated or AI-manipulated image, audio or video material that deceptively resembles real people, objects, places or events. Not every AI image is automatically a deepfake. An obviously artificial fantasy motif or a stylized illustration does not fall under this definition.

Images. Artificially generated or manipulated images that look real must be disclosed as AI-generated. Purely minor retouching (exposure, color cast, dust removal on a genuine photo) generally does not turn a real photo into a deepfake requiring labeling. The more strongly the intervention changes the depicted reality, or the more deceptively real the result appears, the more likely the obligation applies. When in doubt, and with photorealistic results, labeling is the safer path.

Videos. The same deepfake rules apply to synthetic or manipulated videos as to images. The difference lies in the technology: platforms such as YouTube, Instagram or TikTok practically always re-transcode uploads (re-encoding) and in doing so frequently strip the metadata. That is why, for video, a visible overlay rendered into the frame and an invisible watermark are mandatory, not optional. The label belongs in a corner of the frame, visible for the entire duration or at least the first few seconds, with sufficient contrast and outside the platform's UI zones.

Text. Text is the special case. Under para. 4, published AI text only needs to be disclosed if it informs the public on matters of public interest, such as reporting on politics, health or current events. Product descriptions, marketing and service texts are generally not affected. And even for topics of public interest, an explicit exception applies if the content underwent genuine human editorial control and a person bears editorial responsibility. Simply using ChatGPT therefore does not trigger a text labeling obligation.

Audio. Synthetic voices, cloned speakers and AI music also fall under Art. 50 as soon as real people are imitated. Here, an audible or displayed notice plus machine-readable metadata is recommended. An audio deepfake, for example a cloned voice over genuine footage, must also be disclosed.

The medium-specific guides in detail:

Channel-specific special cases are covered in the articles on AI Product Images on Amazon and eBay, on AI Advertising on Meta and Instagram, and on AI Labeling in E-Commerce and Marketing. The difficult question of when content counts as a deepfake is resolved in the article on Deepfake Labeling.

The Official EU Icons

The European Commission provides an official, free icon set for the uniform labeling of AI content. It comprises three basic variants, each available in light and dark versions as well as SVG and PNG formats:

Variant Meaning Typical use
basic Neutral AI notice without specifying the degree General marking where no differentiation is needed
fully AI-generated Fully AI-generated Image or video created entirely with Midjourney, DALL·E or Sora
partially AI-modified Partially AI-edited Real photo or video that was altered using generative AI

Important: using these icons is optional, not mandatory. The law does not prescribe a specific graphic mark, it only requires clear, recognizable labeling. The EU icons are, however, strongly recommended because they send a uniform, immediately understandable signal across Europe, increase recognizability, and demonstrably meet the "clearly recognizable" requirement better than a self-made mark.

Three basic rules apply to placement. Size: the label must be readable without having to zoom in, and must remain recognizable on a smartphone too. Contrast: choose the light or dark variant so that it stands out from the background, with a semi-transparent backing if necessary. Position: the bottom right or bottom left corner has become established, directly on the content, not in the footer. Download the icons exclusively from the Commission's official source to avoid counterfeits or outdated versions. The article EU Icons for AI Content: Templates and Usage explains which icon fits which case and where to get the templates.

Verifying Your Labeling

Trust is good, verification is mandatory. The most common mistake in practice: the metadata is correctly embedded but gets removed again on upload. Many platforms re-compress files and in doing so strip EXIF, XMP and sometimes even C2PA data. Your carefully applied labeling can be gone afterward, while the burned-in icon remains.

The general tendency by channel: on your own website or in your shop, metadata is usually preserved on the original upload. On Instagram, Facebook, TikTok, and on marketplaces such as Amazon and eBay, it is frequently removed. The visible EU icon burned into the pixel image, by contrast, survives compression and is the layer that no platform can compress away. This is precisely why the visible label and the machine-readable marking belong together.

So verify after uploading, not before: publish a labeled test asset on the target channel, download the published version, and check with a C2PA viewer or the "check file" function whether the icon and metadata are preserved. If the icon is obscured by cropping, adjust the placement and test again. A verification function shows whether a marking is present. It does not verify whether content was genuinely created with AI. And a platform label such as "Made with AI" from Instagram or TikTok is based on the platform's terms of service, not on Art. 50, and does not replace the statutory deployer obligation.

7-Step Checklist

Practical implementation is very manageable if you proceed in a structured way.

  1. Clarify your role. Determine whether you are a provider, a deployer, or both. For most companies, the answer is: deployer. Document the classification with a brief justification.
  2. Inventory your AI content. Record all AI images, videos, audio and text that you publish, on your website, in your shop, in advertising and on social media. For each asset, note the storage location, creation date, tool used, and whether it was placed on the market before or after 2 August 2026.
  3. Label visibly. Add a visible label to content requiring labeling, ideally the EU icon plus the text "AI-generated," directly on the content. Vague terms such as "stock image" or "digital art" are not sufficient.
  4. Add machine-readable marking. Also write IPTC/XMP metadata (DigitalSourceType) and, where sensible, C2PA Content Credentials as well as an invisible watermark into your files.
  5. Verify. Spot-check per channel whether the visible label is readable and whether the metadata has survived the export.
  6. Keep records. Set up a labeling register that documents a SHA-256 hash, a timestamp and the labeling method used for each asset, exportable as CSV. This record protects you in the event of a dispute or a cease-and-desist letter.
  7. Anchor the process. Make labeling a fixed, mandatory step in your content and approval workflow, and assign it to a responsible role.

Steps 3 through 6 are technical, and that is exactly what our free web tool takes off your hands. It places the official EU icons on images and videos by drag and drop, writes IPTC/XMP metadata (optionally C2PA and an invisible watermark), offers a "check file" function, processes up to 50 files in a batch (exported as a ZIP), provides a REST API, and logs every operation in the labeling register with a SHA-256 hash, timestamp and CSV export. You can find a detailed, cross-format version of this list with examples in the AI Labeling Checklist. You can get started right away with our free tool.

Frequently Asked Questions

From when does the AI labeling obligation apply in Germany?

From 2 August 2026. The transparency obligations under Art. 50 become binding EU-wide, and thus also in Germany, on this day, 24 months after the EU AI Act entered into force on 1 August 2024. The frequently cited date "8 August" is incorrect.

Who must label AI content, providers or deployers?

Both, but differently. Providers (the makers of the AI systems) mark their outputs in a machine-readable way (para. 2). Deployers (companies that use AI professionally) visibly disclose deepfakes and certain AI texts (para. 4). Most marketing and e-commerce users are deployers.

How high is the fine for missing AI labeling?

Violations of Art. 50 carry fines of up to 15 million euros or 3 % of worldwide annual turnover, whichever amount is higher. The figure of 35 million euros that circulates concerns the most serious violations of prohibited practices (Art. 5), not the labeling obligation. In Germany, there is also the risk of a cease-and-desist letter under the UWG.

No. The labeling must occur on the content itself and be clearly recognizable, for example as an overlay on the image, as the text "AI-generated," or with the EU icon. A blanket notice in the legal notice or footer does not meet the requirement.

Are the EU icons for AI labeling mandatory?

No, the official EU icons are optional but recommended. The EU AI Act does not prescribe a specific graphic mark, only a clear, understandable disclosure. The uniform EU icons, however, make correct and Europe-wide understandable labeling easier.

Do I have to label text created with ChatGPT?

In most cases, no. The text obligation under para. 4 only applies to content that informs the public on matters of public interest, and even there an exception applies where genuine editorial control exists. Product, marketing and service texts generally do not fall under this obligation.

Do I have to label a chatbot as AI?

Yes. Users must be able to recognize at the start of the interaction that they are communicating with an AI system and not with a human, unless this is obvious from the context. This obligation also applies from 2 August 2026 and has not been postponed.


Not legal advice. This content is for general information purposes and does not replace individual legal advice. The Digital Omnibus is provisional as of the time of writing and may change. For your specific case, please consult legal counsel.

Go deeper on individual topics

See all articles on the blog