Gabriel Espinheira
No, the EU AI Act does not make your marketing team stamp an AI label on every asset from 2 August 2026. It makes you answer a harder question: who generated it, who reviewed it, who accepts responsibility, and what must the audience see?
Picture the Monday publish queue. One tab holds an article drafted with AI and rewritten by the founder. Another holds a real product photo that an image model changed. A third holds the website chatbot. The team has one blanket question: "Do we label all of this?"
That question is too blunt. EU AI Act labelling depends on the organisation's role, the type of output, how substantially AI changed it, and whether a person exercised editorial control. This article turns those branches into an operating check. It is practical guidance, not legal advice for a borderline use case.
TL;DR: EU AI Act labelling is not one badge for every AI-assisted asset. Providers generally own machine-readable marking. Marketing teams may need visible disclosures for chatbots, deepfakes, and some public-interest text. Record the system, asset type, reviewer, editorial owner, and disclosure decision before anything ships.
Does the EU AI Act require a label on every AI marketing asset?
The blanket-label rule is wrong. The European Commission's own guidance says: "Not all AI-generated or manipulated content needs to be labelled."
Article 50 splits transparency into different jobs. A provider of a generative AI system may need to make synthetic text, images, audio, or video machine-readable and detectable as AI-generated. A deployer may need to show a visible disclosure when publishing a deepfake or certain AI-generated text about matters of public interest. A provider of a system that interacts directly with people may need to tell users they are talking to AI.
Those duties are related, but one does not satisfy another.
A visible "made with AI" note does not add missing provenance metadata to a file. Metadata does not tell a visitor that the support agent answering them is a machine. Neither one proves that an editor checked the claims in an article before it went live.
The Act also treats assistive editing differently. Under Article 50(2), the provider marking duty does not apply where AI performs a standard editing function or does not substantially alter the input or its meaning. Grammar correction is the obvious example. Rebuilding a product image until a real shop looks like a different place is a different decision.
Over-labelling everything can feel cautious. It can also become a substitute for judgement. If every asset gets the same badge, the badge tells you nothing about what happened, who checked it, or why the team believed that disclosure was sufficient.
Who marks the output and who tells the audience?
Most confusion starts by putting the software vendor, the agency, and the publisher into one bucket. Article 50 separates providers from deployers because they control different parts of the chain.
| Role | What that role controls | Article 50 question | Evidence to keep |
|---|---|---|---|
| Provider of a generative AI system | How the system produces and marks output | Is synthetic output machine-readable and detectable where required? | Vendor documentation, output metadata, model or system version |
| Provider of direct-interaction AI | How a chatbot, voice agent, or assistant presents itself | Is the person told they are interacting with AI at first contact, unless that is obvious? | Interface copy, screenshots, accessibility check |
| Deployer or publisher | How AI output reaches the audience | Is the asset a deepfake or public-interest text that needs visible disclosure? | Asset classification, disclosure text, placement, publish record |
| Editorial owner | What the organisation is willing to stand behind | Was the text meaningfully reviewed, and who accepts responsibility for it? | Named reviewer, source check, approval record, final version |
The role changes with the setup. A company that configures and offers its own customer-facing AI service may carry a different role from a company that uses an off-the-shelf writing assistant internally. An agency may generate the asset while the client publishes it. Contracts and actual control matter more than the job title in the email signature.
An agency creates a synthetic spokesperson video and sends the export to the client's marketing manager. The AI tool has no provenance mark, the agency assumes the client will add a disclosure, and the client assumes the exported file is already compliant. Three organisations touched the asset. Nobody owns the decision.
The fix starts before the export. Record who is acting as provider or deployer, which party adds the visible disclosure, which party checks the technical mark, and who keeps the evidence. If that classification is unclear, ask the vendor and get legal advice before publishing. A tool can carry provenance. It cannot accept editorial responsibility for your business.
What should a marketing team audit before 2 August 2026?
Start with four artefacts already sitting in the queue. They expose the most common branches without forcing a small team to build a legal department around every prompt.
| Marketing artefact | First question | Likely control point | What to retain |
|---|---|---|---|
| Website chatbot or voice assistant | Will a reasonable visitor know they are interacting with AI at first contact? | Opening interface and conversation design | First-screen capture, disclosure copy, accessibility check |
| Synthetic or manipulated image, audio, or video | Does it resemble a real person, object, place, entity, or event and falsely appear authentic? | Creative brief and pre-publish review | Original, generated version, tool, editor, disclosure decision |
| AI-generated public-interest text | Is the purpose to inform the public on a matter of public interest, and did a responsible editor review it? | Editorial approval | Sources, material edits, reviewer, responsible publisher |
| Assistive editing | Did AI only correct or lightly edit without substantially changing the input or meaning? | Authoring history | Original input, final output, short change note |
A website chatbot is the cleanest place to start. Article 50(1) requires direct-interaction AI to inform people that they are interacting with a machine unless that is obvious to a reasonably informed person in context. Do not hide the sentence in the privacy page. Put it where the conversation starts and check that assistive technology can read it.
Images and video need a more careful classification than "AI was involved". Article 50(4) focuses visible disclosure on deepfakes: generated or manipulated media that resembles real people, objects, places, entities, or events and could falsely appear authentic. A clearly impossible illustration and a fabricated video of a real founder do not carry the same risk. The EU labelling icons can help with disclosure, but the team still owns the classification and placement.
Text has its own branch. The visible disclosure rule covers AI-generated or manipulated text published to inform the public on matters of public interest. Ordinary promotional copy will not always fit that description. Some content will sit near the line. A health claim, public-policy explainer, financial update, or safety notice deserves a more conservative review than a button label. When purpose or subject makes the boundary unclear, stop and ask counsel.
Finally, separate generation from assistance. A spell-check pass and a machine-written article are not the same event. Your record should say what changed, not merely tick "AI used". That single distinction cuts a large pile of false alarms out of the audit.
When does human review change the answer for AI-generated text?
"Reviewed" is one of the most abused words in a content queue. It can mean a founder checked every source and rewrote the argument. It can also mean someone skimmed the first paragraph on a phone while walking into a call.
Article 50(4) includes an exception for public-interest text when the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility. Both parts matter. A human has to do real editorial work, and someone has to accept responsibility for the publication.
The exception is not a universal safe harbour for every AI use. It addresses the visible disclosure rule for a specific class of text. Provider marking duties and other rules may still apply. Copyright, advertising standards, sector rules, GDPR, and ordinary accuracy obligations do not disappear because an editor clicked approve.
For an operator, a useful review test looks like this:
- Open the load-bearing sources instead of trusting linked summaries.
- Challenge the central claim and remove anything the evidence cannot carry.
- Rewrite material passages where the model changed meaning, tone, or certainty.
- Check names, dates, numbers, and quoted language against the source.
- Record the final approver, who knows the organisation is publishing under its own name.
That takes longer than tapping a green approval chip, which is the trade. The team gains a defensible decision and gives up anonymous, frictionless publishing. If nobody is willing to own the sentence, the sentence should not ship.
A cautious legal adviser may still recommend disclosure in a sensitive context even after strong review. The workflow should allow that judgement. The goal is not to manufacture an exemption. The goal is to show the facts that informed the decision.
How do you build EU AI Act labelling into the publish queue?
Put the decision beside the asset before approval. Do not leave it in a policy document nobody opens or in the memory of the person who happens to know which tool made the image.
The Future of Life Institute reported that transparency obligations were the second most common trigger in its compliance checker in 2026, affecting around 33% of respondents. That is first-party tool data, not a population study. It still shows why a generic AI policy is too broad to be useful. A meaningful share of teams will hit a transparency question, and each question needs an asset-level answer.
Use a five-field publish record:
- Name the tool or system that created or changed the asset, including its version where available. Keep the relevant vendor documentation.
- Record whether the business is acting as provider, deployer, publisher, or more than one role for this use.
- State whether the output is text, image, audio, video, or an interactive system, then describe how substantially AI changed it.
- Name the person who checked the output and the person or organisation that accepts responsibility for publishing it.
- Record whether a visible disclosure is used, where it appears, what technical marking exists, and why that route was chosen.
The record can live in a Board beside the article, ad, or Studio asset. That is the useful role for a shared workspace such as SharpOS: the work trail stays beside the work. SharpOS is not legal-compliance software, and a tidy card cannot guarantee compliance. It can stop the decision from disappearing into a private spreadsheet when the agency, employee, or vendor changes.
A badge cannot rescue a publish queue nobody owns.
Check the audience experience too. Article 50 says the information should be clear and distinguishable by the first interaction or exposure, with applicable accessibility requirements met. Test the actual route. Does the disclosure remain visible when the image is downloaded? Does it survive a social reshare? Can a screen reader identify it? Does the chatbot announce itself before collecting a message?
The best workflow catches those questions while the asset can still change. Adding a tiny label five minutes before publish is not a system. It is a patch.
Frequently asked questions
Does every AI-generated marketing asset need a label?
No. Article 50 separates machine-readable marking by providers from visible disclosures by deployers. Visible labels focus on deepfakes, some public-interest text, and direct AI interactions. The exact role and context matter, so a borderline use should be classified before publication rather than pushed through a universal checkbox.
Does a website chatbot need an AI disclosure?
Usually, the system should inform visitors that they are interacting with AI at or before the first exchange, unless that fact is obvious to a reasonably informed person in context. Put the notice in the opening interface, make it accessible, and keep a screenshot of the experience your visitors actually receive.
Does human review exempt an AI-written article?
Human review can remove the Article 50(4) visible-disclosure duty for public-interest text when the review is substantive and a person or organisation holds editorial responsibility. It does not erase other duties or turn a cursory approval into a safe harbour. Keep the sources, material edits, reviewer, and final owner on record.
Are the EU AI icons mandatory?
No. The European Commission says the icons are optional, while the underlying Article 50 labelling requirements are legal obligations. Using an icon alone does not establish compliance. If your team uses one, follow the placement and accessibility guidance and make sure the disclosure remains clear at first exposure and after redistribution.
What should a small marketing team record before publishing?
Record the AI system and version, the organisation's role, the asset class and degree of alteration, the human reviewer and editorial owner, plus the disclosure decision and supporting evidence. Keep that record beside the final asset so it survives handoffs, staff changes, vendor exits, downloads, and later questions.
Run the audit before the label
Take ten AI-touched assets from the last month and run the five-field record. You will find two kinds of failure quickly: content that needs a clearer disclosure, and content nobody can explain well enough to approve. Fix both before 2 August.
If the workflow crosses your website, AI tools, content queue, and asset library, it needs one owner and one visible work trail. See how SharpHaw approaches AI Automations, review the Plans, or book a 30-min call: bring the AI-assisted workflow your team cannot explain and leave with a fix list.
Plan. Build. Iterate.

