The Week in One Line
The EU has published an official set of icons for labelling AI-generated content — and the more useful finding is how little of what your organisation publishes actually needs one.
What the Act Actually Says
The deployer duty covers two things, and only two. Article 50(4) requires deployers to disclose deepfakes — AI-generated or manipulated image, audio or video resembling real persons, objects, places, entities or events that would falsely appear authentic — and AI-generated or manipulated text published to inform the public on matters of public interest.
The second one has an exemption most people miss. The text duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. An AI-drafted article that a named editor checked and signed off is outside the obligation.
There are now official icons. Three of them: a basic AI icon, one for fully AI-generated content, and one for partially AI-modified content. Each comes in four variations — black, white, and both at 50% transparency — in SVG and PNG. They are free, and the Commission asks for no attribution.
The placement rules are stricter than the icon itself. The icon must be perceivable at the latest on first exposure, placed where no intervening overlay sits on top of it, and embedded directly into the content unless an equivalent alternative such as a user interface overlay exists. And it must remain visible when the content is reshared or downloaded.
The Commission also notes something from its own user testing: the icon performed better across all measures when it was accompanied by a text label than when it stood alone.
Two sentences worth quoting exactly. Using the icons is optional. The labelling obligation under Article 50 is not. And in the Commission's own words, use of the icons does not establish legal compliance by itself.
The Code of Practice is where the real decision sits. The Code on Transparency of AI-generated Content was finalised on 10 June 2026 and has two sections: one for providers, covering marking and detection, and one for deployers, covering labelling. The Commission and the AI Board have confirmed it is an adequate voluntary tool for demonstrating compliance. By the end of July, around 190 companies and organisations had signed.
Here is the asymmetry. Signatories can rely on the Code's measures to demonstrate compliance across all Member States. Those who comply by other means must demonstrate that their measures are adequate — and that will be assessed individually by different national market surveillance authorities.
Regular readers will recognise the problem in that sentence. In Edition 13 we looked at the Commission's own list of those national authorities. Most Member States still had no published Single Point of Contact.
Sources: European Commission, EU Icons for labelling AI-generated content and Code of Practice on Transparency of AI-generated Content; AI Act Article 50.
What This Means for Your Business
Most of your published AI content is out of scope. The blog posts, the product copy, the newsletter drafts — if a person reviewed them and someone holds editorial responsibility, the labelling duty does not reach them. The panic in most marketing teams is aimed at the wrong material.
The material that is in scope is the material nobody logged. A face swapped into a photograph. A voiceover that sounds like a named person. An empty room furnished with AI in a property listing — that last example is the Commission's own. These get made quickly, by whoever needed them, and they rarely appear on any content inventory.
The reshare requirement is an engineering change, not a copy change. A caption in your CMS does not survive a screenshot, a download, or a repost on another platform. Meeting that requirement means the mark goes into the asset itself, which touches whatever produces and exports your media.
Signing the Code is a predictability decision. It is not about virtue. Signing buys one EU-wide recognised route. Not signing means defending your own approach to each national authority that asks — in a landscape where many of those authorities are not yet publicly identified.
This Week's Action Point
Take the last ten things your organisation published that involved AI, and ask three questions of each.
- Is it a deepfake — does it resemble a real person, place, entity or event in a way that could pass as authentic?
- If it is text on a matter of public interest, did a named person review it and take editorial responsibility?
- If it needs a label, does that label survive a screenshot, a download and a repost?
My expectation, and I would like to know if I am wrong: most items will clear questions one and two, and the handful that do not will fail question three.
I have turned this into a one-page decision sheet — Does This Need a Label? — with the flow, the exemptions, the placement rules and a short inventory table. It is linked in the comments of today's post. Free, no sign-up.
Further Reading
- EU Icons for labelling AI-generated content — the icons and placement rules
- Article 50 — full text
One question I would like your answer to: has anyone in your organisation actually tested whether an AI label survives a screenshot? It is a two-minute check and I suspect very few people have run it. Reply or leave it in the comments. I read every one.
Next Tuesday
The provider side of the same rule: what machine-readable marking actually means in a generation pipeline, and why 2 December matters for anything that was already live before August.
Matúš Paško — I design enterprise AI systems that have to run in production under real compliance and reliability constraints. If you are working out which of your AI outputs are in scope and what it would take to mark them properly, my calendar link is in my profile.
#EUAIAct #Article50 #AICompliance #AIGovernance #EnterpriseAI