AI labelling: what the AI Act now requires

Post · 5 min read

As of yesterday, what the AI Act has been announcing for two years became real: the transparency obligations under Article 50 now apply. Unlike the demanding obligations for high-risk systems, whose application the “Digital Omnibus on AI” has postponed to the end of 2027, these rules take effect as planned. And in many cases compliance can be checked with the naked eye. Anyone who sees an AI video without a label already has an indication of a breach. Enforcement is therefore likely to start quickly, not least because in Germany the Federal Network Agency is set to receive the enforcement mandate.

For energy suppliers, municipal utilities and grid operators, this is not a niche topic. Anyone running a chatbot in a customer portal, using AI-generated images in communications or producing texts semi-automatically may fall under these obligations. Here we give a first overview of the legal requirements that now apply to using AI in communications and customer contact.

What this is about: four situations

Article 50 of the AI Act attaches to four situations. First, it must be disclosed when people interact directly with an AI, for example a chatbot or a voice assistant. Second, providers of generative AI must mark their outputs (image, audio, video, text) in machine-readable form and make them detectable as artificial. Third, information duties apply to emotion recognition and biometric categorisation. Fourth, and most visible in practice, so-called deepfakes and AI-generated texts on matters of public interest must be labelled.

Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake shall disclose that the content has been artificially generated or manipulated. This obligation does not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosing the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.

The allocation of roles matters. Providers develop an AI system and place it on the market; deployers use it under their own responsibility. Most companies are deployers, for instance when they use an off-the-shelf model for marketing or customer service. And it is precisely deployers whom the immediately visible labelling obligation addresses.

The European Commission has provided official logos for labelling content under the AI Act. Other forms of labelling are also possible.

No need to fear getting it wrong: anyone who has thought through a coherent approach to labelling under the AI Act has no penalties to fear. Documentation, however, is everything.

What exactly has to be labelled under the AI Act

Deployers must clearly and perceptibly flag deepfakes — AI-generated or AI-altered image, audio or video content that resembles real people, places or events and could appear genuine. The Commission's accompanying code of practice provides dedicated marks for this: an “AI” label with the addition “GENERATED” for fully generated content and “MODIFIED” for subsequently altered content. What matters is that the label is embedded directly in the content, for example in the top right corner of an image. A note in the caption alone is explicitly not sufficient. For videos, the label must be shown at the start and repeated after interruptions; for audio-only content, an audible notice takes its place.

Not every use of AI triggers the obligation. Pure editing aids without substantial change — spell checking, minor cropping or noise reduction — are exempt. An AI translation, inserting objects or altering a person, by contrast, must be disclosed. For evidently artistic or satirical works, a softened obligation applies that is not meant to disturb enjoyment of the work.

For chatbots and assistants the rule is: users must learn at the start of the interaction that they are talking to an AI, unless that is obvious anyway. For AI texts on matters of public interest, the obligation falls away if the text has undergone editorial review and a responsible person stands behind it.

Practical examples: label or not?

Does every image made with AI have to be labelled?

No. It depends on how strongly the experience of the product is distorted — and context matters too. Even before AI there was advertising in which customers knew what they were getting into. If a model in an ad promotes a bottle of cola in front of an AI-generated beach scene, that is as irrelevant as retouching the image to remove a freckle or a drop of sweat on the person's skin. If, however, the product itself is altered, or that beach is used to advertise a dream holiday at a place that does not exist, it has to be labelled. In case of doubt, it always comes down to the individual case.

Do I have to label existing images on my website?

No, the publication date applies. Anything published from 2 August 2026 onwards must be labelled. Anything already visible before that does not.

Do I have to label content in a private context?

No, private individuals are exempt from the AI Act.

Do I have to document every change?

There is no legal obligation, but it is advisable to mark AI-generated images or videos at least internally, or to keep them in a separate folder, so that you yourself know what was changed and what was not.

Deadlines and penalties

The disclosure obligation for deployers applies from 2 August 2026. For machine-readable marking by providers there is a short grace period until 2 December 2026, provided the generative system was already on the market before August. Legacy content does not have to be labelled retroactively.

The penalties are substantial: Article 99 of the AI Act provides for fines of up to 15 million euros or 3 per cent of worldwide annual turnover. But the fine is not the only risk. Missing or misleading labelling can at the same time count as an unfair commercial practice. That brings competition law (in Germany, the UWG) into play alongside the AI Act, and breaches can be pursued independently by competitors and associations. On top of that, any affected person can file a complaint with the market surveillance authority.

What to do now

Labelling is only one building block. Since 2 February 2025, the AI literacy obligation under Article 4 of the AI Act has applied: companies must ensure that staff who use AI, or who are responsible for its outputs, have a sufficient understanding of the technology and its limits. Knowing when content becomes subject to labelling makes both requirements easier to meet.

The Commission's guidelines and code of practice are not legally binding; ultimately only the European Court of Justice can interpret Article 50 authoritatively. In practice, however, both become the benchmark: those who follow them can demonstrate their conformity to the authorities.

For companies this means less about hastily handing out labels and more about knowing where AI content is created in-house, and about building labelling cleanly into existing processes. It is about creating awareness for the topic. Being able to show the supervisory authorities that there is a process and a strategy for lawful use is already half the battle.

As a rule of thumb, these five steps apply:

  1. Review and assess assets
  1. Document
  1. Clarify responsibilities
  1. Set binding standards, discuss edge cases as a team
  1. When in doubt, label once too often rather than once too rarely

This is where the real core lies. In the end, the labelling obligation is a question of data transparency and process discipline: a dependable overview of where AI is used in customer communications, portals and content production, and workflows that carry the labelling along reliably.

That is the perspective from which we at control-f look at the topic when we talk to energy suppliers about their data and digital infrastructure.

This article provides an overview and does not replace legal advice in individual cases.

Kategorie / Category: Blogposts

All posts