← All guides Compliance

The EU AI Act and image labelling

Transparency obligations for synthetic imagery, who they fall on, and what a business outside the EU should do about them. A plain summary, not legal advice.

· 10 min read · Best AI Image Detector

The obligations split in two. Providers of generative systems must mark their output in a machine-readable way, and deployers who publish synthetic content must disclose it to people. Both can apply to an organisation outside the EU.

Why transparency rules arrived here first

Regulating whether synthetic media may exist is intractable. Regulating whether people are told about it is not, which is why disclosure has become the common approach across several jurisdictions rather than a European peculiarity.

The reasoning is that most of the harm in this field is a misunderstanding rather than an image. Somebody believing a picture records something that happened, when it does not, is the injury, and a label addresses it directly without anybody deciding what may be produced.

That framing explains the shape of the rules. They attach to the moment of publication and to the moment of production, and they say very little about the content itself, which is left to existing law on fraud, defamation and the rest.

Who each duty falls on

The two obligations, roughly
PartyDutyWhat it looks like in practice
Generator providerMark output machine-readablyEmbedded metadata, watermarking, credentials
Publisher of synthetic mediaDisclose to peopleA visible label or caption
Publisher, artistic useLighter disclosureAcknowledgement that does not spoil the work
Deepfake of a real personDisclose clearlyThe strictest case, few exemptions
Text on matters of public interestDisclose unless reviewedHuman editorial review can displace it

The first row is the one most businesses assume covers them and does not. Unless you build and supply a generative system, you are the second row: somebody publishing output, with a duty to tell your audience.

The fourth row carries the sharpest teeth, because a synthetic depiction of an identifiable real person is where the harm is most concrete. Exemptions there are narrow, and other law is likely to apply as well.

Whether it reaches you outside the EU

Probably, if you have EU users. These rules generally follow the market rather than the establishment, in the same way data protection rules do, which means publishing to an EU audience can bring you within scope regardless of where you are.

The practical consequence for most organisations is that a single global policy is cheaper than a geofenced one. Labelling synthetic imagery everywhere costs a caption; maintaining two versions of every asset and a rule about who sees which costs considerably more.

It also ages better. Similar disclosure requirements are appearing in several other jurisdictions, and an organisation that already labels has nothing to do when the next one arrives.

  1. 2024
    Act enters into force Obligations phased in rather than switched on.
  2. 2025
    Prohibitions and literacy duties The first tranche, covering banned practices.
  3. 2026
    Transparency duties apply Marking of generated output, and disclosure by publishers.
  4. Ongoing
    Codes of practice and guidance How the duties are met in practice is still settling.
  5. Elsewhere
    Similar rules appear Comparable disclosure requirements in other jurisdictions.
Roughly when each obligation bites. Dates are indicative and national implementation differs.

What compliance actually looks like

  1. Find out what you publish

    Audit your own site, campaigns and social output. Most organisations discover generated imagery arriving through agencies and stock subscriptions they never asked about.

  2. Write down where it is permitted

    Decoration and illustration yes, anything asserting a fact no. That line does more work than any technology-specific rule.

  3. Label in the caption, not the policy

    A disclosure buried in a terms page is not a disclosure to the person looking at the image.

  4. Stop stripping metadata

    Where a generator marks its output, keeping that marking intact through your pipeline is part of the point of the rule.

  5. Put it in supplier contracts

    Agencies and freelancers need to declare generated content in deliverables. Most will not volunteer it because nobody has asked.

The fifth step is where the effort pays back most. An organisation cannot audit its way out of a supply chain that keeps adding undeclared imagery, and a clause in a brief costs nothing compared with a retrospective review.

Why detection is not the compliance mechanism

It is worth being clear that these rules are built on declaration rather than on detection, and deliberately so. A duty to mark output at the point of generation is enforceable; a duty to correctly identify synthetic content after the fact would be a duty to be right about something nobody can be reliably right about.

That has a practical implication. Meeting your obligations means knowing what you published and saying so, not running a detector over everything and hoping it agrees. Detection is how you find out what your suppliers gave you; it is not the compliance artefact.

It also means that a high score on somebody else content is not evidence of a breach. The obligation is on the publisher to disclose what they know, and an error rate is not a finding about what they knew.

What a small business should actually do

Most of this lands on organisations with no compliance function, and the proportionate response is short. Three actions cover the realistic exposure and take an afternoon rather than a project.

Write one line into your supplier brief requiring generated content to be declared. That single sentence moves the problem to the people who actually know the answer, and it is the cheapest control available.

Label generated imagery in captions wherever a reader might take it for a photograph. Not in a policy page, not in a footer, in the caption beside the picture where somebody looking at it will see it.

Check your image pipeline is not stripping metadata during optimisation. Most do by default, and where a generator has marked its output, discarding that marking works directly against the purpose of the rule.

Where this is heading

The direction across jurisdictions is consistent enough to plan around, even where the detail differs. Disclosure duties are expanding, provenance metadata is becoming infrastructure rather than a niche standard, and platform labelling is being built on markers rather than on detection.

That has a useful implication for anybody publishing original photography. Preserving provenance is shifting from a technical nicety to a commercial asset, because an image that can assert what it is will increasingly be treated differently from one that cannot.

Questions people ask

Do I have to label AI images on my website?
Where you publish synthetic content to people who might reasonably take it for a record of something real, disclosure obligations are increasingly likely to apply, and EU rules reach organisations outside the EU with EU audiences. A caption is cheap; ask your own lawyer about your specific situation.
Does this apply to a business outside the EU?
It can. These rules generally follow the market rather than the place of establishment, much as data protection rules do, so publishing to an EU audience can bring you within scope. A single global labelling policy is usually cheaper than maintaining a geofenced one.
What about purely decorative images?
The obligations are aimed at content that could be mistaken for a record of reality. An abstract header nobody would take for a photograph is a different case from an image implying a real customer or a real event, and lighter treatment applies to clearly artistic work.
Who has to add the machine-readable marking?
The provider of the generative system, not you. Your part is to avoid stripping it. Most image pipelines remove metadata during optimisation by default, which quietly discards exactly the marking the rule exists to create.
Can I use a detector to prove compliance?
No, and it is not designed for that. These rules are built on declaration at the point of generation and disclosure at the point of publication. Detection is how you audit what your suppliers actually delivered, which is a useful internal control rather than a compliance artefact.
What should go in an agency contract?
A requirement to declare generated content in every deliverable, a prohibition on generated imagery in anything asserting a fact, and a requirement to preserve provenance metadata. Most agencies will not volunteer any of this, because until recently nobody asked.