Published on 14 April 2026. Updated on 2 August 2026.
Regulations checked on 1 August 2026.
Do you have to label AI-generated content?
From 2 August 2026, certain images, videos, audio and text generated or manipulated with AI must include clear notices and, where applicable, machine-readable marking. You must also inform people when they interact with an AI system. Consult the guide that fits your activity to find out what to label, where to display the notice and what evidence to keep.
Today, 2 August 2026, the transparency obligations of the European Artificial Intelligence Regulation come into application. This is the part of the regulation that affects the most companies, and probably the part that has been explained the least.
If you have read in recent months that today was the deadline for high-risk systems, that timetable is no longer valid. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and has been in force since the 27th. It postpones high-risk obligations until December 2027 and August 2028. It does not postpone transparency.
In other words: what many companies were rushing to prepare now has sixteen more months. And what almost nobody was preparing starts today.
This article is about the second point. What you are required to do from today, what you are not required to do despite what you may have read, and what you can get resolved this week.
What starts applying today and what has been postponed
| What happens | What happens | Status |
|---|---|---|
| 1 August 2024 | The regulation enters into force | Done |
| 2 February 2025 | Prohibited practices and the obligation to develop AI literacy | In force |
| 2 August 2025 | Obligations for general-purpose AI models and governance rules | In force |
| 2 August 2026 | Transparency obligations under Article 50 | Applicable from today |
| 2 December 2026 | Final deadline for generative systems already on the market to include machine-readable marking | Transitional |
| 2 December 2026 | Two new prohibitions: non-consensual intimate material and AI-generated child sexual abuse material | Pending |
| 2 December 2027 | Obligations for high-risk systems under Annex III: employment, education, credit and essential services | Postponed |
| 2 August 2028 | Obligations for high-risk systems integrated into regulated products: healthcare, machinery and vehicles | Postponed |
The two nuances almost nobody is mentioning
First: the postponement is not a general truce. The Omnibus moves Chapter III, Sections 1 to 3. Everything else remains exactly where it was. The transparency obligation under Article 50 applies today, and prohibited practices and AI literacy have been mandatory since February 2025.
Second: Spain’s own law has not yet been approved, and that does not exempt you from anything. The Draft Organic Law on the proper use and governance of artificial intelligence was published in the Official Gazette of the Spanish Parliament on 12 June 2026 and is still under consideration. It designates AESIA as the central authority and sets out the penalty regime. But the European regulation applies directly: it is binding with or without a Spanish law. The national law says who can sanction you and how, not whether you have to comply.
Step 1. Find out what role your company plays
The regulation assigns different obligations depending on the role you play, and that allocation determines what applies to you. Before looking at any obligation, locate yourself.
Provider
The person or organisation that develops the AI system or places it on the market under its name or brand. This also includes anyone who makes substantial changes to an existing system.
If you buy a solution and significantly modify it for your business (change the model, add your own training data or alter its intended purpose), you may move from deployer to provider. There is also a less obvious case that makes you a provider: putting your brand on top of a third-party system and presenting it as your own. This is what happens with many customised web assistants.
Deployer
This is where most SMEs fall. You integrate, configure and operate a system developed by someone else within your organisation. You use a third-party tool for chat, your ecommerce platform’s recommendation engine or a generative model for content.
Your main obligations:
- Correctly classify the risk of each AI system in your company.
- Complete an impact assessment for data protection if the system processes personal data.
- Appoint a person with the competence, authority and judgement required for human oversight.
- Enable and maintain the system logs.
- Do not operate with the provider’s default thresholds without validating them in your context.
- Comply with the Article 50 disclosure obligations that apply to you, which is what we cover in step 2.
Common mistake. Operating with the provider’s minimum package: unvalidated default thresholds, insufficient logs and assuming that an impact assessment is unnecessary. Compliance is not proclaimed; it is demonstrated through verifiable processes.
Importer and distributor
If you place systems from providers outside the EU on the European market, you are an importer. If you resell them without modifying them, you are a distributor. Both roles have verification obligations: ensuring that the provider has completed the conformity assessment, that the documentation is in the language of the destination country and that the system arrives with the required marking and safe-use conditions.
Step 2. Keep only the obligation that applies to you
The most expensive mistake is treating transparency as a single obligation. There are four, and each falls on a different actor. Almost all the useless work being done these weeks comes from confusing them.
| Obligation | Who it applies to | What it means for you |
|---|---|---|
| Ensuring that people know they are interacting with an AI system, unless this is obvious from the context | The system manufacturer | You choose and configure the tool, and you are responsible for the welcome message |
| Marking outputs in a machine-readable format | The manufacturer of the generative tool | Creating it is not your obligation. It is still wise not to destroy it: exporting or recompressing content can remove the source metadata |
| Informing people when emotion-recognition or biometric-categorisation systems are used | The deployer, that is, you | Tone or facial-expression analysis. Inferring emotions from employees or students has been directly prohibited since February 2025 |
| Disclosing deepfakes and publicly interesting text published without review | The deployer, that is, you | This is the one that affects you directly |
The information must be provided clearly and distinctly, no later than when the person is first exposed to it, and it must be accessible.
What exactly is a deepfake?
The regulation defines it as image, audio or video content generated or manipulated with AI that resembles existing people, objects, places, entities or events and would appear authentic to the person viewing it.
It is worth reading this twice, because almost everyone reads it incorrectly: it does not refer only to famous people. It refers to objects, places and events too. A recreation of your product, premises or a real situation falls within this definition. A dragon, an impossible landscape or a clearly stylised illustration does not.
Three exceptions that save you half the work
- Standard editing. Correcting colour, removing noise, increasing resolution, cropping or removing a background without changing the meaning does not trigger any obligation.
- Human review, and only for text. If the text goes through review or editorial control and a person or company takes responsibility for publishing it, no notice is required. This covers the normal workflow of almost any company.
- Content from before 2 August 2026. You do not need to relabel content that has already been published. For text, the publication date is what counts: if it was generated in July and published in August, it counts as August.
Step 3. Put every use of AI through three questions
You do not need a colour-coded traffic light. Simply follow the path set out by the regulation itself, which is also the path you can defend in the event of a complaint.
Question 1. Does the piece represent something or someone that exists, in a way that could appear authentic?
Question 2. Does a notice solve the problem, or is the problem that the piece makes a false claim?
Question 3. Is there an identifiable person who has genuinely reviewed the piece and takes responsibility for what was published?
Four possible outcomes:
| Outcome | What it means |
|---|---|
| No notice | Instrumental use of AI. Publish as normal |
| Notice required | The regulation requires it. Do not publish without it |
| Recommended notice | The regulation does not require it, but commercial or reputational risk makes it advisable |
| Redo | No label can fix the problem, because the problem is deception or lack of rights |
Question 2 is the one that saves the most money. Labelling a product as “AI-generated” when it is not what it appears to be does not legalise anything: it is still misleading advertising. If the image promises an attribute that the product does not have, no label will fix it.
Step 4. Write the notice and place it where it can be seen
The regulation requires the information to be clear, distinguishable, accessible and available before the person interprets what they see. That rules out most of the notices circulating today.
Not compliant: a line in the footer, a mention in the privacy policy or terms, text that appears for half a second in a video, a watermark hidden by the interface, or a notice that disappears when the piece is downloaded or shared.
Compliant: a notice on the piece itself, visible on first exposure, placed where nothing obscures it, embedded in the content whenever possible, written in plain language and accompanied by a text alternative for screen readers.
Channel-specific formulas ready to copy
| Situation | Formula |
|---|---|
| Product or service image | “AI-generated image. Non-photographic recreation.” |
| Space, premises or facility | “AI-generated recreation. This is not a photograph of the premises.” |
| Video with a synthetic spokesperson | Caption in the opening seconds and persistent overlay: “Virtual spokesperson generated with AI.” |
| Cloned audio or voice | Spoken notice at the beginning: “Voice generated with AI with the person’s authorisation.” |
| Chat or assistant | First message: “I am [brand]’s virtual assistant. I respond using artificial intelligence. You can ask to speak to a person at any time. You can also find out how to create an assistant that gives notice and hands the conversation to a person.” |
| Unreviewed informational text | Heading, not footer: “Text generated with AI. Published without editorial review.” |
| Social media | The platform’s native label and, in addition, a notice within the creative, because the native label is lost when the content is reshared |
The EU’s official icons
The European Commission has published a set of free icons, available for use without attribution, in SVG and PNG. There are three variants: basic, entirely AI-generated and partially AI-modified. They are optional and work best when accompanied by text rather than used alone. Using them does not, by itself, demonstrate compliance.
What you do NOT have to label
This list is just as important as the previous one, because excessive caution also costs money and erodes trust in the notice when it is genuinely needed.
- Product descriptions, technical specifications and bullets written with AI. They do not require a notice. They do require the data to be accurate.
- Metadata, titles, alt text and descriptions generated at scale. Auxiliary function.
- Reviewed automatic translations.
- Welcome emails, abandoned-cart or after-sales emails written with AI and reviewed.
- Blog articles written with AI and reviewed before publication, with someone taking editorial responsibility.
- Illustrations, patterns and abstract backgrounds that do not resemble anything existing.
- Photos adjusted with standard editing: colour, noise, resolution, cropping and background removal.
- Internal use: reports, proposals, minutes and analyses. They are not published for the public, so they do not trigger Article 50. They do trigger data-protection and confidentiality requirements.
- Content published before 2 August 2026. You do not need to go back and label it.
If you have read that everything touched by AI must be labelled, that is not the case. The obligation concerns deepfakes and publicly interesting text published without review.
If you use AI in recruitment, credit or essential services
You are still in the high-risk category. The only thing that has changed is when the requirements will be enforced.
High-risk AI systems include those used in:
- Employment and people management: recruitment, performance assessment and dismissal decisions. If you screen CVs or prioritise candidates with AI in recruitment, this is where you fall.
- Education: admissions, academic assessment and accreditation.
- Essential services: access to insurance, loans, housing, healthcare, public assistance and energy.
- Financial services: creditworthiness assessment and fraud prevention.
- Justice and law enforcement: migration, border control and judicial proceedings.
And AI systems integrated as a safety component in regulated products: medical devices, industrial machinery and vehicles.
The obligations (documented risk management, data governance, technical documentation, human oversight, traceability logs, conformity assessment, fundamental-rights impact assessment and post-market monitoring) are enforceable from 2 December 2027 for those under Annex III and from 2 August 2028 for those integrated into regulated products.
And one thing that has not been postponed: inferring emotions from employees or students has been prohibited since February 2025. This is not high risk with requirements. It is prohibited. A notice is not enough.
What applies in Spain in addition to the European regulation
Customer service: you cannot leave everything to the bot
Law 10/2025 of 26 December, regulating customer-service services, has been in force since 28 December 2025, with an adaptation deadline of 28 December 2026. Among other things, it prohibits customer service from being based exclusively on automated systems: if a person asks, they must be able to speak to someone.
It affects companies providing basic services of general interest and large companies. For personal data, also review how to comply with the GDPR when using AI. Depending on your activity, it is also worth reviewing the DMA, DSA and NIS2. It is not mandatory for everyone else, but the recommendation is the same: always offer a route to a person. That is what customers expect and what prevents half of all complaints.
AI literacy: it is already an obligation, not a best practice
Since 2 February 2025, organisations have had to ensure a sufficient level of AI knowledge among the staff who use it. There is no prescribed format, but it is worth being able to prove it: a short documented session, with an attendance list and saved materials, is worth more than good intentions.
The cost of non-compliance
| Infringement | Cap |
|---|---|
| Using prohibited systems | Up to €35 million or 7% of total annual worldwide turnover |
| Failing to comply with provider, deployer or Article 50 transparency obligations | Up to €15 million or 3% of total worldwide turnover |
| Providing incorrect information to the authorities | Up to €7.5 million or 1% of total worldwide turnover |
For SMEs the calculation is different and works in their favour: the lower figure between the fixed amount and the percentage applies, not the higher one.
An example. An SME with annual turnover of €2 million breaches the rules. Three per cent of €2 million is €60,000, well below the €15 million cap. As it is an SME, the lower figure applies: €60,000. It is still a serious blow for a company of that size.
And penalties are not the only consequence. An open investigation damages your reputation, consumes legal resources and can bring operations to a halt.
Your plan for the next seven days
| Step | What you do | How long it takes |
|---|---|---|
| 1. Inventory | List where AI is used today in each channel: website, product pages, chat, email, creatives, automations and third-party tools. Also include the AI your team is already using without your knowledge | Half a day |
| 2. Classification | Run each use through the three questions in step 3 and keep only what results in “notice” or “redo” | Two hours |
| 3. Quick fixes | Chat welcome message, guaranteed route to a person and notices on the live pieces with the highest risk | One day |
| 4. Templates | Notice formulas by channel and a reusable block in your CMS or theme | Half a day |
| 5. Register | One row for each published piece: which tool was used, what the AI did, what notice it carries and who approved it | Ten minutes per piece |
| 6. Contracts | Ask your AI providers for their technical documentation and check the data-processing agreement | Depends on them |
| 7. Training | A short, documented AI-literacy session for the team | One hour |
Frequently asked questions
Do I have to label product descriptions written with AI? No. The obligation to disclose AI-generated text only applies to text published to inform the public about matters of public interest, and even then it falls away if there is human review with editorial responsibility. A product description is not a matter of public interest.
What about AI-generated product photos? It depends on whether they faithfully represent the real item. If the product looks as it really is, no notice is required. If the image enhances it until it looks like something else, labelling does not solve the problem: the image must be changed.
Do I have to add watermarks or metadata to the content I generate? It is not your obligation. Machine-readable marking is the responsibility of the manufacturer of the generative tool. What is advisable is not to destroy it: image optimisers and some exports remove source metadata.
Do I have to relabel everything I published before? No. Content published before 2 August 2026 does not need to be relabelled. For text, the publication date is what counts.
Is a notice in the footer or privacy policy enough? No. The regulation requires the information to be clear, distinguishable and available on first exposure. A footer does not comply.
Has the AI Act been delayed? Only the high-risk obligations, which move to December 2027 and August 2028. Transparency obligations apply from 2 August 2026 and prohibited practices from February 2025.
Can I serve my customers using only a bot? If your company falls within the scope of Law 10/2025, no: customer service cannot be based exclusively on automated systems, and people must be able to speak to someone if they ask. It is not mandatory for everyone else, but it is recommended.
What I3OS is teaching us about complying with AI requirements
At Impulsa3 we are seeing that governance is not something to write at the end of a project. I3OS builds owners, authorised sources, access limits, human review and documentation of capabilities in from the design stage. This is our way of preparing for cross-functional adoption without losing control when the system consults data, proposes work or takes part in customer processes. This does not replace the specific analysis required by the AI Act for each case, but it offers practical experience of how to make compliance part of the operating model.
Sources
Regulations and official documentation checked on 1 August 2026.
- Regulation (EU) 2024/1689 (European AI Regulation), Article 50. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI). Official Journal of the European Union of 24 July 2026, in force since 27 July 2026. https://www.boe.es/buscar/doc.php?id=DOUE-L-2026-81147
- European Commission. Code of Practice on transparency of AI-generated content, 10 June 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- European Commission. Guidelines on the transparency obligations under Article 50. https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
- Official EU icons for labelling AI-generated content. https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content
- Draft Organic Law on the proper use and governance of artificial intelligence. BOCG, Congress, Series A, no. 97-1, 12 June 2026. https://www.congreso.es/public_oficiales/L15/CONG/BOCG/A/BOCG-15-A-97-1.PDF
- Law 10/2025 of 26 December, regulating customer-service services. BOE no. 312 of 27 December 2025. https://www.boe.es/buscar/act.php?id=BOE-A-2025-26698
Closing remarks
This article is not legal advice. For decisions involving regulatory exposure, validate them with your legal adviser.
If you want to go deeper into integrating all this into a governance model with decisions, metrics and owners, read how to set up an AI committee without dying in the attempt.
If you want to follow the full journey, also read about the three phases of AI transformation. And if you would rather have us support you with the inventory, classification and notice templates, Impulsa3 can do it with a practical approach and no unnecessary jargon. Tell us about your case.