On August 2, 2026, a section of the EU AI Act that had been sitting quietly since 2024 turned into something a regulator can fine you for. Article 50 is now live, which means AI-generated images must carry marks that software can read, and deepfakes must carry disclosures that people can see. If you generate images, publish them, or simply look at them online, the AI image labeling rules in 2026 reach you in some way. Most of what has been written about this was aimed at compliance teams. This is written for everyone else, including the part nobody in a law firm has much reason to tell you.
What Actually Changed on August 2, 2026
Two things switched on at once. Article 50 became applicable across all 27 member states, and the Commission's AI Office, alongside national market surveillance authorities, gained the power to enforce it. Before that date, the transparency rules were a plan. Now they are a duty with a penalty attached.
The supporting paperwork arrived just in time. The Commission adopted final guidelines on Article 50 on July 20, 2026, and a voluntary Code of Practice on Transparency of AI-generated Content, published on June 10, was assessed as adequate by the Commission and the AI Board. The code is where the technical detail lives: what a mark should look like, how durable it needs to be, and what a disclosure has to do for a reader.
Worth knowing what did not change. The Act's toughest requirements for high-risk systems were pushed back in the EU's simplification package, with some sensitive use cases now due in December 2027 and high-risk AI inside regulated products not until August 2028. So when you read that "the AI Act took effect," that is shorthand. Transparency took effect. Much of the rest is still coming.
What the AI Image Labeling Rules in 2026 Require, in Four Duties
Article 50 is shorter than its reputation suggests. It sets out four duties, and they land on two different groups: providers, who build and supply AI systems, and deployers, who use those systems in their own products, services and publishing.
First, systems that interact with people directly have to say they are AI. A chatbot cannot let you assume you are talking to a person. Second, providers of generative systems must mark synthetic image, video, audio and text output so it can be detected as artificial by machine. Third, deployers running emotion recognition or biometric categorisation must tell the people exposed to it. Fourth, deployers who publish a deepfake must disclose it, and AI-written text published to inform the public on matters of public interest must be labeled unless a human reviewed it and someone takes editorial responsibility.
| Article 50 duty | Falls on | What it requires in practice | Example |
|---|---|---|---|
| 50(1) Interaction disclosure | Providers, as a design duty | Build the system so people are told they are dealing with AI at or before the first interaction. Not required where it would be obvious to a reasonably observant person. | A retail support chatbot that opens with "You are chatting with an AI assistant." |
| 50(2) Machine-readable marking | Providers of generative AI systems | Mark synthetic image, video, audio and text so software can detect it: signed, tamper-evident metadata plus an imperceptible watermark. Assistive edits that do not substantially alter the content are exempt. Systems already on the market get until 2 December 2026. | An image generator embedding Content Credentials and an invisible watermark in every file it outputs. |
| 50(3) Emotion recognition and biometric categorisation | Deployers | Tell the people exposed to the system that it is running, and handle their data under GDPR. Exempt where legally authorised for detecting or prosecuting crime. | A retailer running in-store software that infers shopper mood must notify people at the entrance. |
| 50(4) Deepfake and public-interest text disclosure | Deployers | Disclose deepfakes visibly at first exposure, in a place no overlay covers and that survives resharing. Label AI-written text on matters of public interest unless a human reviewed it and someone takes editorial responsibility. Artistic, satirical and fictional works only need disclosure that does not spoil the work. | An agency publishing an AI-generated photo of a real high street adds a visible "AI-generated" label. |
One detail that saves a lot of worry: the Act's definition of a deployer carves out personal, non-professional activity. Posting an AI-generated picture on your own account for fun does not make you a deployer with legal duties. Doing it for a client, a brand or a publication does.
Marking and Labeling Are Two Different Jobs
This is where most summaries blur things, and the distinction matters more than any other point in this post. Marking is invisible and meant for machines. Labeling is visible and meant for humans. Different obligation, different party, different failure mode.
For marking, the Code of Practice asks for two layers. Layer one is signed, time-stamped metadata recording that the content was AI-generated or manipulated, embedded so tampering shows. In practice that means C2PA-style Content Credentials, since that is the deployed standard matching the description. Layer two is an imperceptible watermark woven into the pixels themselves, durable enough to survive compression, cropping, scaling and format conversion. Fingerprinting against a registry is allowed as an extra, but never on its own.
One layer is built for machines and one is built for people. Only one of them survives a screenshot.
Providers signing the code also commit to giving the public a free way to check content, whether through an open specification, a downloadable tool or an API. They agree to preserve marks that are already present rather than wiping them during processing, and to ban circumvention tools in their terms. That last commitment is the one I would watch, because it decides whether "strip the watermark" stays a search result or becomes a product.
For labeling, the EU released three free icons: a basic AI mark, a "fully AI-generated" mark and a "partially AI-modified" mark, each in four colour variants. Using them is optional. Disclosing is not. The placement rules are specific: the disclosure has to be visible at first exposure, sit where no overlay covers it, and stay attached when the content is downloaded or reshared. User testing found icons performed better when paired with a short text label, so "voice generated with AI" beats a bare symbol.
Which AI Images Need a Visible Disclosure, and Which Ones Do Not
The visible disclosure duty attaches to deepfakes. The Act defines those as AI-generated or manipulated image, audio or video resembling real people, objects, places, entities or events, in a way that would falsely appear authentic to someone looking at it. The test is not "did AI touch this." The test is whether it could pass as real.
Several carve-outs matter. Content that is evidently artistic, creative, satirical or fictional only needs disclosure in a way that does not spoil the work, so a label in the credits can be enough rather than a badge burned across the frame. Uses authorised by law to detect or prosecute crime are exempt. On the marking side, an AI feature that only assists standard editing without substantially changing the content, like straightening a horizon or fixing red-eye, does not trigger the provider marking duty.
The Deadlines That Are Not August 2
August 2 is the headline date, but three other dates decide what you actually owe right now. Generative systems already on the market before August 2, 2026 have until December 2, 2026 to bring their machine-readable marking into line, a grace period added through the EU's simplification package. The visible disclosure duties had no such extension.
Old content gets a partial pass. Images generated and published before August 2 do not need retroactive labels, though the Commission encourages it. The catch that trips people up: something generated in March but published today is new publication, and the disclosure duty applies. If you have a backlog of AI visuals waiting in a content calendar, that backlog is now in scope.
If You Are in the US, UK, Australia, New Zealand or Canada
Article 50 follows the audience, not the head office. A provider or deployer established anywhere in the world is covered when its system is placed on the EU market or its output reaches people in the EU. A marketing agency in Auckland publishing an AI-generated campaign image that Europeans can see is inside the rules, which surprises a lot of teams outside Europe.
California picked the same day on purpose. Its AI Transparency Act, originally SB 942 and amended by AB 853, became operative on August 2, 2026, timed to match Brussels. Covered providers, meaning publicly available generative AI systems with more than a million monthly users in the state, must offer a free detection tool, provide an option for a visible disclosure and embed a hidden one carrying provider, system version and creation date. Stripping provenance data is prohibited, as is distributing tools built to strip it. Platform obligations follow on January 1, 2027.
Elsewhere the picture is thinner. The UK has no statute requiring AI content to be labeled and leans on existing regulators instead. Australia works through online safety codes and standards that push certain generative services and search providers toward differentiating AI output, rather than a general labeling law. New Zealand and Canada have no comprehensive AI statute in force, and Canada's proposed AI and Data Act lapsed when Parliament was prorogued in January 2025. Between them, the EU and California rules now set the working default for anyone shipping to both.
If you want a sense of what all this looks like from the receiving end, take an image you were sent this week and run it through our free checker. It reads the metadata that Article 50 is trying to standardise and shows you what survived the trip.
The Fines, and Who Actually Hands Them Out
Transparency breaches sit in the middle penalty tier. National market surveillance authorities do most of the enforcing, with the AI Office handling systems under its supervision and the European Data Protection Supervisor covering EU institutions. Penalties are set nationally, so the practical severity varies by member state.
What I would not expect is a wave of day-one penalties. Regulator readiness across member states is uneven, the guidelines only landed in final form in late July, and the first cases will almost certainly involve large providers or obvious deception rather than a small business that forgot an icon. That is a reason to move deliberately, not a reason to ignore it.
Why a Missing Label Proves Nothing
Here is the part the compliance coverage skips. Article 50 is a duty on people who follow rules. It asks honest tools and honest publishers to sign their work. It has no effect whatsoever on the person building a fake profile photo for a romance scam, or a fabricated invoice image, or a synthetic screenshot of a news headline. That person was never going to add a label.
A label tells you an image is AI. The absence of one tells you nothing at all.
Even honest marks leak. Signed metadata is fragile by design: re-encode a file, screenshot it, or push it through a pipeline that rewrites the image, and the credential can vanish while the pixels stay identical. Watermarks are harder to shake, but not every generator embeds one, and nothing embedded before the tool adopted the standard will be there at all.
There are also whole categories the rules simply do not reach. Content published before August 2. Output from small models run locally with no compliance program. Images from tools with no European exposure at all. In my own testing, the share of AI images that still carry usable provenance after a single social platform round trip is far lower than the policy discussion implies.
I tested this myself with one JPEG sent through five common platforms. Four of the five returned a different file. Gmail was the only one that preserved the original byte for byte. X kept all 35 metadata fields but changed the underlying file; WhatsApp retained 22 of 35 while rewriting some of their values; Facebook left just 6 of the original 35; and YouTube returned a WebP with none of the 35 original metadata fields surviving. One round trip was enough to turn the same source image into five very different forensic records.
How to Check an Image Yourself in About a Minute
Treat a label as a weak positive signal and verify anyway. The sequence I use takes about a minute and needs nothing but a browser.
Start with metadata, the fastest answer when it is there. Look for Content Credentials, a software field naming a generator, or missing camera data on something presented as a photo. Then run error level analysis, which highlights regions compressed differently from their surroundings and often exposes pasted or regenerated areas. Then check the picture itself: lighting that disagrees between subject and background, text that dissolves under zoom, jewellery and teeth that repeat oddly, edges too clean against a busy background.
Finish with context, which catches more fakes than any pixel test. Who posted it first, when, and does any independent account of the same event exist? A real photograph of a real event almost never arrives alone.
What Is Still Being Argued Over
Two open fights could change what you owe. The first is the definition of a deepfake. Industry groups argued the Commission's July guidelines stretched the term wider than the 2024 text intended, which matters for anyone making photorealistic images of things that never existed rather than manipulations of real people. Meta signed the code in late July while warning that stacking overlapping labels on everything ends up meaning nothing to readers, and that criticism is fair.
The second is durability. Text watermarking is acknowledged to be less reliable below a couple of hundred tokens, and image watermarks vary in how well they survive aggressive editing. The two task forces the AI Office plans to launch in September 2026 exist partly to push that state of the art forward. Anyone promising you a settled technical answer today is selling something.
Frequently Asked Questions
Do I have to label AI images I post on my personal social account?
My business is in the US, UK or Australia. Does Article 50 apply to me?
What about images I generated last year?
Can I remove a watermark or provenance data from an image I own?
What to Do This Week
If you publish professionally, spend an hour on an inventory. List where AI-generated images appear across your site, ads, social accounts and client work, pick one disclosure pattern and apply it consistently, then check whether your AI vendors mark their output and offer a detection route. The EU icons are free, so the visible half of compliance costs a design decision rather than a budget.
If you are on the receiving end instead, the practical takeaway is smaller and more useful: labels are about to become common enough that their absence will feel like reassurance, and that instinct is exactly backwards. Verify the images that matter, especially the ones asking you for money, a login or a decision. Upload the next suspicious JPG to our free error level analysis and metadata checker and see what the file admits before you act on it.