When and how to declare generative origin in documents?
EU AI Act Compliance: Operational Guidelines for Content Transparency and Article 50
Regulation (EU) 2024/1689, known as the European Union Artificial Intelligence Act (EU AI Act), establishes the first comprehensive legal framework for regulating artificial intelligence technologies in the European market. Among its most broadly applicable provisions are the transparency rules set out in Article 50, which become fully binding as of August 2, 2026. These rules aim to mitigate the risks of manipulation, deception, and the spread of unverified information, ensuring that citizens are aware when interacting with automated systems or consuming artificially generated content.
The implementation timeline was partially adjusted through the Digital Omnibus Act on AI, which stipulates that for systems placed on the market prior to August 2, 2026, the content marking obligation under Article 50 will apply starting December 2, 2026. This four-month extension provides stakeholders with time to align their development workflows without facing immediate penalties.
Determining whether an artificial origin disclaimer is required in company documents, reports, or presentations requires a precise distinction among the type of content produced, the role of the entity, and the final distribution channel.
Distinguishing Between Providers and Deployers
The European regulation divides legal responsibilities between two primary roles in the value chain:
- Providers
- Professional Deployers
Providers are natural or legal persons that develop an AI system (or have an AI system developed) to place it on the market or put it into service under their own name or trademark. They are obligated to design systems so that generated files (text, images, audio, or video) contain an invisible technical watermark that is machine-readable and capable of revealing the file’s artificial origin.
Professional Deployers are public or private entities that use such AI systems under their own authority in the course of a professional activity. They are the primary addressees of the rules requiring a visible, overt disclosure of the synthetic nature of content when it is distributed or published externally.
Operational Criteria for Disclosure
The necessity of including an explicit disclosure (e.g., a visual notice such as “AI-Generated”) within a report or presentation depends on the level of process automation and the media types embedded in the document.
Standard operational practice identifies three primary use cases:
| Content in Report or Slides | ||
| Disclosure Required? (Visual Disclaimer) | Legal and Operational Rationale | |
| Drafted text, edited and reviewed by an operator | NO | The human operator assumes full editorial and legal responsibility for the content, waiving the transparency disclosure requirement for the text. |
| Photorealistic images, audio, or video created via AI | YES | There is a legal obligation to indicate artificial origin directly on the media itself or within footnotes/captions to prevent visual or auditory deception. |
| Reports or presentations created and sent 100% automatically | YES | The workflow excludes a human-in-the-loop; specifying that the output is machine-generated is mandatory. |
The underlying logic rests on the principle of personal and professional liability: a human editor’s sign-off waives the visual transparency label requirement, whereas automated distribution by a software system makes it mandatory.
Internal-Use Reports and Documentation
Technical reports, predictive analyses, and informational dashboards generated with AI assistance that remain strictly within the company perimeter are exempt from these obligations. As internal documents that are not published for external informational purposes, they are categorized as minimal- or zero-risk systems.
However, organizations must verify that using these internal systems complies with personal data protection regulations (GDPR), preventing the transmission of confidential information or sensitive data to external large language models (LLMs) that lack adequate data security guarantees.
Text Intended to Inform the Public on Matters of Public Interest
The Article establishes that professional deployers who publish text generated or modified by AI systems to inform the public on matters of public interest must explicitly declare its artificial origin.
Interpretive guidelines adopted by the European Commission on July 20, 2026, assign a broad definition to “matters of public interest.” This includes not only journalistic publications, but also sustainability reports (ESG), online corporate financial statements, legal/medical/financial client documentation, and institutional communications directed at consumers.
Exemptions for Human Review and Editorial Responsibility
The regulation includes a critical exemption for commercial and scientific documents. The obligation to include a visual transparency notice is waived if two structural requirements are met simultaneously:
- The AI-generated text has undergone substantial human review and effective editorial control prior to publication.
- A natural or legal person formally assumes editorial responsibility for publishing the content.
The European Commission clarifies that human review cannot be a mere formal rubber-stamp or superficial glance. It must be a thorough examination of the merit and substance of the text, conducted by professionals with appropriate subject-matter expertise capable of correcting logical errors or factual inaccuracies generated by the automated system.
In practical terms, a corporate report initially drafted using a language model—but subsequently edited, fact-checked, and signed off by an analyst or manager—is legally considered a work of human authorship. Consequently, such a document requires no surface labeling or AI-generation disclaimers.
Technical Traceability and C2PA Metadata
While human editorial review determines the need for user-facing visual disclaimers, technical file compliance operates under automated systems logic.
Providers of generative AI models are required to mark digital outputs by embedding structured, tamper-evident metadata compliant with the international C2PA (Coalition for Content Provenance and Authenticity) standard.
This metadata travels inside the file itself and contains certified information regarding:
- The application or software service that generated the content (e.g., OpenAI Media Service API).
- The legal entity issuing the file’s cryptographic signature (e.g., OpenAI OpCo, LLC).
- The precise timestamp of the file’s generation.
Distribution platforms and professional social networks (such as LinkedIn) integrate automated readers for this metadata. When a user uploads an image or media file to their profile, the platform analyzes the file in real time and automatically displays a visual transparency badge (identified by the Content Credentials “cr” icon), without requiring authorization or consent from the user who uploaded it.
By clicking this icon, any viewer can access the complete provenance history of the file and verify the application used to create it.
This automated technical oversight introduces strategic considerations for organizations:
- Infrastructure-Enforced Transparency: Omitting a manual disclosure does not prevent third-party platforms from informing the public about the synthetic origin of photorealistic images or videos embedded in reports.
- Reputational and Trust Risks: If an organization publishes a report or presentation without declaring AI usage, the automatic appearance of the “cr” badge on embedded media could create a perception of a lack of transparency or deliberate concealment.
- Proactive Communication Strategy: Voluntarily declaring the use of generative tools within document footnotes or descriptions is preferable to having it automatically flagged by external platforms.
Guidelines for Organizational Compliance
Organizations should map the use of technology tools across their workforce, categorizing activities into purely internal processing, AI-assisted text editing, and external content production.
To utilize the visual disclosure exemption for text, companies must implement workflows that document actual review and sign-off by a qualified human operator. Software platforms equipped with audit trail functionality can record the reviewer’s identity, modifications made, and formal approval, providing solid documentation during potential compliance audits.
Finally, for media content lacking editorial review, or where synthetic elements remain photorealistic, planning for clear, visible disclosures at the time of publication is the safest path to protecting brand reputation and adhering to the spirit of the EU AI Act.
References
- EU AI Act Official Text / Information Portal
- European Commission Regulatory Framework for AI
- EDPB Data Protection Impact Assessment Guidelines
Make sure to consult official EU regulatory portals for exact compliance requirements. As a reference and source of information, always!
www.artificialintelligenceact.eu
Credits to Denis Dal Molin

