Policy & Regulation

After 2 August 2026: What AI Images and Videos Must Disclose

Uncutly Editorial · August 26, 2026 · 7 min read

Start creating free on Uncutly

If the creator does not load, you can open it directly.

Start creating free on Uncutly
A camera image passing through four transparent layers representing disclosure, watermarking, metadata, and signed provenance
Illustration by Uncutly Editorial

For years, AI media transparency was discussed as a voluntary product feature: a label here, an invisible watermark there, perhaps a Content Credential if the tool supported it. On 2 August 2026, the European Union moved part of that debate into an enforceable operating requirement.

Article 50 of the EU AI Act does not say that every AI-assisted pixel needs the same badge. It creates role- and context-dependent transparency obligations, including technical marking for certain generated or manipulated outputs and visible disclosure for deepfakes within scope. The practical challenge is that teams often use “label,” “watermark,” and “provenance” as if they were interchangeable. They are not.

This article is an operational explainer, not legal advice. Teams should apply the final law and Commission guidance to their own role, market, content, and exceptions.

The deadline has passed

The European Commission’s 31 July enforcement release says the AI Office and national authorities began enforcing the AI Act from 2 August 2026, when new transparency rules also started to apply. The release states that deepfakes must be labelled and AI-generated or altered content must carry machine-readable marks within the rules’ scope.

The Commission’s Article 50 guidelines are essential because the nouns matter. A provider placing a generative system on the EU market has different responsibilities from a deployer using a system professionally. Disclosure duties also depend on the kind of output and use; exceptions and adapted forms of disclosure exist.

The safest editorial summary is not “Europe requires one AI watermark.” It is that relevant systems and professional uses now need a transparency design that combines technical identifiability with human-facing disclosure where required.

Four technologies people keep confusing

Four layers of AI media transparency: visible disclosure, machine-readable marking, watermark or detection, and signed provenance
Four complementary layers answer different questions. None alone proves that the depicted event is true.
LayerPrimary audienceWhat it doesWhat it does not prove
Visible disclosurePeopleStates that media was generated or manipulatedThe exact tool, edits, or truth of the scene
Machine-readable markPlatforms and toolsProvides a detectable structured signalThat every downstream copy retains the signal
Watermark/detectionVerification systemsTests for a model-specific or embedded signalComplete editing history or universal origin
Signed provenancePeople and systemsRecords signed assertions about origin and editsThat the depicted claim is factually true

A visible notice can survive a screenshot because it is rendered into the presentation, but it may be cropped. Embedded metadata can carry richer information, but a platform may strip it during transcoding. An invisible watermark may survive some transformations and fail others. Signed provenance can show tampering with recorded assertions, but it cannot record events that were never asserted.

Provider and deployer are different roles

The provider builds or places the AI system on the market. For generated image, audio, video, or text outputs within Article 50’s technical-marking scope, the provider’s problem is to make outputs identifiable in a machine-readable and sufficiently robust way, following the law and guidance.

The deployer uses the system under its authority. A publisher, agency, studio, political campaign, marketplace, or other professional operator may therefore face a separate visible-disclosure question when publishing deepfake content or covered public-interest text. The person uploading media is not automatically the provider, and buying access to a compliant system does not automatically satisfy every downstream duty.

Responsibility chain from AI provider to professional deployer, platform or publisher, and audience
Technical marking starts with a provider; professional use, presentation, preservation, and audience context continue downstream. Exact legal duties remain scope-dependent.

The platform or publisher is operationally important even when its legal classification differs by service. It can preserve or strip metadata, display or hide credentials, attach labels, and give audiences a verification path. A technically marked output can become opaque if downstream processing discards every usable signal.

What visible disclosure means

Visible disclosure is designed for a person encountering the media, not for a forensic tool. It should be timely, prominent enough to notice, and connected to the relevant content. A label buried in a general terms page cannot perform the same function as context attached to the media.

Creative and editorial teams need a reusable presentation rule: label placement, wording, localization, treatment in thumbnails, treatment after sharing, and handling for artistic, satirical, or other exceptional contexts described by the law. They also need evidence that the label was present at publication time.

The visible layer should not make broader claims than the evidence supports. “AI-generated” can be misleading for a camera photograph with a small generative edit; “AI-altered” may be more accurate. Conversely, a vague “enhanced” label may not communicate a synthetic person or event.

What machine-readable means

Machine-readable marking lets automated systems recognize relevant generated or manipulated output. That can involve metadata, provenance manifests, embedded watermarks, or compatible signals. The Commission’s framework focuses on the outcome—identifiability under the applicable requirements—rather than declaring that one commercial technology solves every case.

Google offers a useful scale example, with an important caveat: these are vendor-reported figures. In May 2026, Google said SynthID had been applied to more than 100 billion images and videos and 60,000 years of audio. It also said SynthID verification in Gemini had been used 50 million times globally and announced Content Credentials for native video on Pixel 8, 9, and 10.

Official demonstration of checking generated-media signals in Gemini: a user uploads media and asks whether it was AI-generated, and the interface reports available verification information. Source: Google.

SynthID and C2PA solve different problems. SynthID is an imperceptible watermark and verification system associated with model output. C2PA Content Credentials carry signed provenance assertions that compatible tools can inspect across a media workflow. A product can use both.

The limits of provenance

The C2PA explainer is explicit about a subtle point: provenance validates the structure and integrity of recorded assertions; it does not make a value judgment that the content is true. A genuinely captured photo can be staged. A signed editing record can be incomplete. An asset without credentials is not automatically fake.

Provenance is most valuable when the chain begins at capture and persists through editing and publication. It can show that a camera signed an original, that a compatible editor recorded a transformation, and that the current file matches the signed manifest. Its weakness is ecosystem continuity: unsupported tools, screenshots, exports, and social transcoding can break or detach the chain.

That is why the transparency stack needs redundancy. A visible notice serves the viewer now. A machine-readable mark helps platforms. A watermark may survive where metadata does not. Provenance can preserve richer history for compatible systems.

A practical media-team checklist

  1. Map roles. Identify provider, deployer, platform/publisher, and any downstream distributor for each workflow.
  2. Classify uses. Separate generation, manipulation, deepfake content, public-interest text, internal drafts, and covered exceptions.
  3. Inventory signals. Record visible labels, watermarking, metadata, Content Credentials, and what survives export.
  4. Test the distribution path. Upload, transcode, download, screenshot, and share; check which signals remain.
  5. Localize disclosure. Make wording understandable in every market where the media appears.
  6. Keep evidence. Store the original output, model/version, generation time, prompts or job IDs where appropriate, approval, label treatment, and publication record.
  7. Design failure behavior. If credentials disappear, decide whether the system blocks publication, adds a visible label, or routes the asset for review.
  8. Review exceptions with counsel. Do not turn an editorial summary into a universal compliance rule.

The 2 August deadline changes the default conversation. Transparency is no longer a feature that can be added to the end of a generation pipeline. It is a chain across model, deployer, media tooling, platform, and presentation. A visible badge without technical evidence is incomplete; technical evidence nobody can see or preserve is incomplete too.

Sources