top of page

EU AI Act Transparency Rules: New Labelling Tools and Key Compliance Steps for AI-Generated Content

  • Elena Niki Karletidi
  • Jul 12
  • 5 min read



Introduction


The European Union is moving from the legislative design of the AI Act to its practical implementation. Recent developments concerning the identification, marking and labelling of AI-generated content provide businesses with greater clarity on how the EU’s transparency requirements are expected to operate in practice.


In June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content, together with EU labelling icons and supporting frequently asked questions. These tools are intended to assist providers and deployers of generative AI systems in preparing for the transparency obligations under Article 50 of the EU AI Act.


The developments are particularly relevant to organisations using generative AI to produce or modify text, images, audio and video, including financial institutions, professional-services firms, media organisations, marketing agencies, online platforms and other businesses publishing content directed at the public.


What does Article 50 of the AI Act require?

Article 50 establishes transparency requirements for certain AI systems and AI-generated or manipulated content.


The obligations differ depending on whether an organisation acts as a provider of the relevant AI system or as a deployer using the system in its activities.


Obligations for providers

Providers of AI systems that generate synthetic audio, image, video or text content must ensure that their outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated.


The marking solution must be effective, interoperable, robust and reliable, taking account of the type of content, technical limitations and generally recognised standards.


This requirement is primarily directed at the developers and providers of generative AI systems rather than ordinary business users.


Obligations for deployers

Organisations using AI systems must disclose that content has been artificially generated or manipulated where they:

  • generate or manipulate image, audio or video content constituting a deep fake; or

  • generate or manipulate text published for the purpose of informing the public about matters of public interest.


The disclosure must be clear and distinguishable and must be made no later than the first exposure of the content to the public.


Certain exceptions apply, including circumstances involving authorised law-enforcement uses and, subject to specific conditions, artistic, creative, satirical or fictional works. For public-interest text, the disclosure requirement may also not apply where the AI-generated content has undergone human review or editorial control and a person or organisation holds editorial responsibility for its publication.


The new EU icons for AI-generated content

The Commission has introduced a set of standardised icons that deployers may use when labelling AI-generated or manipulated content.


The purpose of the icons is to provide a recognisable and consistent visual indication that content was created or modified using AI. Their use may help individuals distinguish authentic content from synthetic or manipulated material and may contribute to reducing deception, impersonation and misinformation risks.


The icons are freely available and form part of the practical framework accompanying the Transparency Code of Practice. However, an important distinction must be maintained:

Use of the EU icons is voluntary, but compliance with the applicable transparency obligations is mandatory.


Simply displaying an icon will not automatically establish compliance. An organisation must still assess whether the disclosure is sufficiently clear, appropriately placed and provided at the correct point in time. It must also consider whether additional wording or technical marking is required, depending on the content and the organisation’s role.


The Transparency Code of Practice

The Code of Practice is divided into two principal sections:

  1. Measures for providers, addressing the marking and detection of AI-generated or manipulated content.

  2. Measures for deployers, addressing the visible labelling of deep fakes and certain AI-generated or manipulated text.


Adherence to the Code is voluntary. Nevertheless, the European Commission and the European AI Board have assessed it as an appropriate tool through which signatories may demonstrate compliance with the relevant AI Act transparency obligations.


Signing the Code may therefore provide participating organisations with a more predictable and harmonised compliance framework across the EU. It may also reduce uncertainty regarding the technical and organisational measures expected by supervisory authorities.


The Code does not replace the AI Act and does not provide an unconditional safe harbour. A signatory remains responsible for assessing its own systems, use cases and disclosures and for ensuring that the measures it implements satisfy the legal requirements in practice.


Revised AI Act implementation timetable

The wider AI Act implementation timetable has also been amended through the EU’s Digital Omnibus on AI.


The European Parliament approved the amendments on 16 June 2026 by 423 votes to 57, with 174 abstentions. The Council gave its final approval on 29 June 2026. Under the revised timetable, the requirements for high-risk AI systems will generally apply:

  • from 2 December 2027 for stand-alone high-risk AI systems; and

  • from 2 August 2028 for high-risk AI systems embedded as safety components in products governed by specified EU sectoral legislation.


The amendments also introduce a prohibition relating to AI systems designed to generate child sexual abuse material or non-consensual intimate content involving identifiable persons.


These postponements concern the high-risk AI framework and should not be interpreted as a general suspension of all AI Act obligations. In particular, the Article 50 transparency obligations concerning AI-generated and manipulated content are scheduled to become applicable from 2 August 2026, subject to any specific transitional provisions introduced for systems already placed on the market.


What businesses should do now

Organisations should not limit their preparations to identifying whether they develop AI systems. Businesses that use publicly available generative AI applications may themselves qualify as deployers and become responsible for the way AI-generated content is reviewed, approved, labelled and published.

A practical compliance exercise should include the following steps.

1. Identify AI-generated content

2. Determine the organisation’s role

3. Distinguish assistance from generation

4. Establish an approval and labelling procedure

5. Introduce human editorial controls

6. Review contracts with technology and content providers

7. Train employees


AI transparency is broader than the AI Act

Compliance must also be considered alongside other areas of EU and national law.

Where AI-generated content involves identifiable individuals, personal data or automated decisions, the GDPR may apply. Relevant issues may include transparency, lawful processing, data accuracy, the use of biometric data, automated decision-making and the rights of affected individuals.


Intellectual-property rights, personality rights, consumer-protection rules, advertising standards, defamation law and sector-specific regulatory obligations may also apply.

Accordingly, an AI label does not make otherwise unlawful content permissible. A properly labelled deep fake, for example, may still infringe privacy, data-protection, copyright or personality rights.


Conclusion

The publication of the Transparency Code of Practice, the supporting FAQs and the EU labelling icons represents an important step towards the operational application of the AI Act.

For businesses, the central message is that AI transparency is no longer merely a matter of voluntary ethics or good practice. In the circumstances covered by Article 50, it is becoming a formal compliance obligation.


Organisations should therefore establish a structured approach for identifying AI-generated content, determining their regulatory role, applying appropriate labels, documenting human review and retaining evidence of compliance.


The postponement of certain high-risk AI requirements should not delay this work. The transparency rules for AI-generated and manipulated content follow a separate timetable and require immediate operational preparation.



 
 

The material reflected in our website, including Blog material, is for informational purposes only and does not constitute legal advice, consulting, or any other professional advice. Please seek independent professional guidance for your specific needs.

All rights reserved. No part of this work may be reproduced, stored in a retrieval system of any nature, or transmitted, in any form or by any means including photocopying and recording, without the prior written permission of the ENAH Services Ltd. The reproduction or transmission of all or part of the work, whether by photocopying or storing in any medium by electronic means or otherwise without the written permission of the owner is strictly prohibited and the commission of any unauthorised act in relation to the work will result in civil and/or criminal actions. 

bottom of page