AI image labelling under Article 50 of the EU AI Act: What decision-makers need to know now
- 20 hours ago
- 7 min read
The countdown is on: On August 2, 2026, the transparency obligations under Article 50 of the EU AI Act will come into force. For companies, marketing departments, and compliance officers, this deadline marks the end of the gray area surrounding synthetic media. Anyone who commercially uses or publishes AI-generated or manipulated content will have to adhere to clear rules; otherwise, they face fines of up to €15 million or 3% of their global annual turnover.
The core requirements of Article 50 EU AI Act
Article 50 regulates the transparency obligations for developers and commercial users of AI systems. The legislator's aim is not to prohibit generative AI, but to ensure the traceability and detectability of synthetic media.
The EU AI Act strictly distinguishes between two roles:
Providers: Manufacturers of AI systems (e.g., Midjourney, OpenAI, Adobe) must ensure that AI outputs are technically marked with machine-readable, invisible tags.
Operators (Deployers): Companies, agencies and media houses that use AI tools in everyday life are obliged to clearly label deceptively realistic synthetic media (deepfakes) for the human viewer.
The “why”: The meaning and purpose of regulation
Since generative image generators have reached a visual quality where the human eye can hardly distinguish between reality and fiction, the European Union is pursuing a first, multi-layered protection mandate with Article 50.
The primary goal is to protect consumers from deception , ensuring they are not manipulated by misleading representations in the digital sphere. Furthermore, the regulation safeguards information integrity by protecting public discourse from automated forgeries and targeted disinformation. Finally, the regulatory framework fosters trust in the market , as uniform standards provide companies with a legally secure framework for the commercial use of generative tools.
Scope: Which content must be labelled?
The labeling requirement primarily concerns so-called deepfakes and photorealistic AI visuals . The regulation applies as soon as media create or alter content that depicts real people, places, objects, or real events and could be mistakenly considered authentic photographs by the viewer.
In a business context, this applies not only to manipulated photographs of people, but also to commercial AI graphics such as synthetic stock photos, photorealistic AI product renderings, or virtually designed real estate brochures, if they convey the visual impression of a real photograph.
The concrete implementation of the labelling
European legislation requires a dual safeguard consisting of visual perceptibility for humans and technical anchoring in the file code.
Visual implementation for operators/deployers
For companies in the role of operator , visual identification is crucial. A reference hidden solely in the code is insufficient for publication purposes.
The visual marking must meet the following criteria:
Clarity and readability: The notice must be written in clear language (e.g., "AI-generated image" , "Artificially generated" or "AI-generated" ).
Prominent placement: The marking must be placed directly on or attached to the medium, e.g. as a visible overlay badge in the corner of the image, as a permanent line of text at the edge of the image, or as an immediately adjacent caption in the running text.
Accessibility & Visibility: The label must stand out sufficiently from the background in terms of color (high contrast) and must not be obscured by UI elements, hover effects or responsive cropping.
EU standard icons: The EU Commission supports the use of standardized transparency icons (e.g. stylized AI or Sparkle symbols with accompanying text) to ensure cross-linguistic recognizability in the internal market.
Technical implementation for providers
In parallel to the visual level, the guideline prescribes a technical depth marker, primarily from AI system providers:
Machine-readable metadata: Embedding of standardized manifests (preferably according to the C2PA standard from the Coalition for Content Provenance and Authenticity ).
Steganographic watermarks: Robust, invisible markings at the pixel level that remain readable in the image code even after compression, conversion, or cropping.

What is exempt from the labelling requirement?
Not every use of AI tools in everyday work automatically leads to a transparency obligation. The legislator explicitly allows for everyday workflows and specific use cases.
Simple AI assistance and digital retouching remain exempt from the visible labeling requirement. Typical image optimizations such as automatic cropping, color grading, sharpening, noise reduction, or the removal of small background objects do not distort the essential content of the image and therefore do not require a label.
Furthermore, exemptions apply to art, entertainment, satire, and fiction . For obviously fictional or artistic works, the labeling may be placed in such a way that the overall artistic impression is not unreasonably impaired, for example, by mentioning it in the imprint or end credits instead of a prominent watermark on the image itself. Law enforcement agencies are also exempt from these requirements during investigative work.
The debate about mandatory AI labeling
The introduction of mandatory labeling is sparking intense debate among experts. While proponents celebrate the move as a long-overdue safeguard for democracy, critics warn of immense operational hurdles and a false sense of security.
Protection from disinformation vs. false sense of security
At first glance, mandatory AI labeling offers significant advantages for society. In the age of synthetic media, reliable labeling could, in part, protect against targeted disinformation, digital fraud, and identity theft . Consumers regain their ability to orient themselves and make informed judgments online. The transparency provided by the label creates awareness and orientation, thus counteracting the gradual erosion of trust in digital media and reporting.
However, appearances are deceiving. Criminal actors and state-sponsored disinformation campaigns, by definition, do not adhere to EU laws. This creates a real danger of a false sense of security (known in the field as the liar's dividend ): consumers might mistakenly assume that any image without an AI label is automatically genuine and unaltered. Furthermore, there is a risk of "label fatigue," a habituation effect in which online warnings are simply ignored.
Competitive advantage through transparency vs. operational overkill
While some proponents of the AI label also emphasize that the labeling creates technical standardization and transparency, which can also be used as a competitive advantage to communicate honestly as a brand and build customer trust, many companies also see the massive administrative effort and gaps in implementation:
High operational integration effort: Marketing pipelines, CMS and approval processes must be completely restructured.
Aesthetic impairment: Visual overlay badges or mandatory lines of text disrupt the design of high-quality advertising campaigns. For premium brands, this creates a real conflict between aesthetic aspirations and compliance requirements.
The demarcation dilemma: The legal gray area is large. Compliance officers face the difficult question of where AI assistance ends and a deepfake requiring labeling begins.
The "Canva effect" and internal information loss: Even with exemplary visual labeling, a massive liability risk quickly arises in everyday practice. A typical scenario: An employee generates an AI-generated image, edits it in a graphics program like Canva (where the machine-readable metadata is technically lost during export), and publishes it legally with a visual text note in a social media post. If the team then saves this image "naked" (without the crucial metadata in the code and separate from the original accompanying text) back into the internal asset management system, a time bomb is ticking. Another colleague, who uses the image months later for a new campaign, has no way of recognizing that it is AI-generated. They publish it unlabeled, and the company unknowingly commits a violation.
The hidden trap in the archive: Risks with legacy holdings
This risk is compounded when considering a company's own archive. While the EU AI Act does not require retroactive labeling for images that lie unused in databases , Article 50 applies in full as soon as an existing image from the DAM or CMS is republished for a new campaign, a social media post, or a website relaunch.
The insidious thing is that proof of origin, such as C2PA metadata, is extremely prone to errors in everyday digital business, as the Canva example illustrates, and is often lost through previous conversions, edits, or CMS migrations. Anyone who then unknowingly republishes an unmarked, AI-generated image as a genuine photograph immediately commits a compliance violation.
The solution: The fully automated VAARHAFT audit in 48 hours
To eliminate these blind spots in the data around the cut-off date, VAARHAFT offers an audit with the Fraud Scanner, in which the entire data set of a company is analyzed fully automatically within 48 hours and all AI-generated or AI-processed images are marked.
VAARHAFT is a TrustTech provider in Europe and has, among other things, built its own forensic image trust layer that can reliably detect deepfakes.
For IT security, the principle of zero data retention applies: Assets are analyzed on servers within the EU, solely in RAM, and are not stored. Since VAARHAFT's forensic models operate directly at the pixel level, they are completely independent of metadata . Even if provenance information has been deleted by graphics programs or years ago, pixel forensics reliably detects AI-generated or manipulated content.
After 48 hours, the company has three concrete analysis results available:
Executive Summary: A concise management report with the exact percentage of AI-generated, manipulated, and authentic assets to serve as a basis for management decision-making.
Operational hit list: A targeted overview of all marked assets including a forensic PDF report and a heatmap that precisely locates manipulations in the image visually.
Structured system dataset: A CSV or JSON file with classification and confidence value for each image, ready for automatic bulk import into the internal DAM or CMS.
This audit serves to radically prioritize risks. For example, if the analysis shows that only 4% of 250,000 archived images are of synthetic origin, the manual review requirement for the legal department is immediately reduced from 250,000 to 10,000 assets. This saves valuable legal resources and creates immediate legal certainty.
Continuous monitoring and certificates of authenticity
An audit establishes a reliable baseline, but legally sound compliance requires continuous processes. VAARHAFT offers two complementary building blocks for this purpose.
The fraud scanner integrates directly into existing DAM, CMS, or shop systems via an API and automatically checks each asset before publication. The system performs metadata analysis, creates heatmaps, and generates a timestamped dataset. This serves as comprehensive compliance documentation for regulatory authorities, something most companies currently lack.
For in-house media production, VAARHAFT's SafeCam ensures the authenticity of images at the moment of creation. Since proving manipulation after the fact is complex and costly, VAARHAFT seals its own content with a cryptographically verified origin from the outset. This allows VAARHAFT to mark authentic images in a tamper-proof manner, similar to an anti-AI label or certificate of authenticity.
Compliance with Article 50 is about safeguarding your publications, while forensic authenticity is about protecting your company's credibility. These obligations come into effect on August 2nd. Don't leave your compliance to incomplete metadata. Start your automated VAARHAFT 48-hour audit now and make your data legally compliant for the AI age.
Schedule your compliance audit appointment now!
Sources:
Regulation (EU) 2024/1689 (EU AI Act): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
C2PA (Coalition for Content Provenance and Authenticity): https://c2pa.org/
Video on the AI Act labeling requirement: https://www.youtube.com/watch?v=jMDL3cW2sUA
.png)





Comments