Since August 2, 2026, Article 50 of the EU AI Act has been in force. If your company generates or publishes AI images, video, or audio, you're required to label it in a machine-readable format and, for deepfakes, disclose visibly that the content is artificial. Non-compliance carries fines of up to €15 million or 3% of global annual turnover, whichever is higher (Article 99, AI Act).
Almost none of the mistakes we're seeing are technical. The problem is interpretation: who's on the hook, when it applies, and what counts as "sufficient labeling."
The AI Act defines a "deepfake" in Article 3(60) as image, audio, or video content generated or manipulated by AI that resembles real people, objects, places, entities, or events, and that a person could reasonably mistake for authentic content. In practice, that covers everything from a video that puts words in a real person's mouth to a product image that places someone in a location they never visited, an audio clip that clones a voice, or an image that simulates an event that never happened.
We're covering the seven most common compliance mistakes we're seeing among companies and creators working with AI image and video generation, with a source for every claim so you can verify it yourself.
What actually changed on August 2, 2026
Article 50 of the AI Act has been in the regulation's text since 2024, but it entered into application and enforcement on August 2, 2026. That day, the European Commission, through the EU AI Office, gained the power to investigate and sanction providers of general-purpose AI (GPAI) models, and the transparency obligations went from paper to enforceable law.
You don't need to operate a high-risk system under Annex III, or have trained your own model. Using generative AI to produce image, video, audio, or text that reaches a third party is enough, marketing content, corporate videos with avatars, press releases, thumbnails, social campaigns. That already puts you inside the scope of Article 50.
With that framework in place, here are the mistakes most likely to catch companies out.
1. Thinking the obligation belongs only to the model provider
The most common mistake: assuming that if you use an AI image-generation platform, compliance is that company's problem, not yours. The AI Act explicitly distinguishes between the provider (who builds the system) and the deployer (who uses it to produce and publish content), and assigns them separate, cumulative obligations. Article 50(4) puts the responsibility directly on the deployer who publishes a deepfake to make clear the content is artificial, regardless of what the tool itself does.
If your company publishes the content, you carry the disclosure obligation even if you never wrote a line of the model's code.
2. Believing the Code of Practice is optional, so there's nothing to comply with
The European Commission and the AI Board have endorsed the Code of Practice on Transparency of AI-generated content as a voluntary way to demonstrate compliance (digital-strategy.ec.europa.eu). Voluntary code doesn't mean voluntary obligation: the code is a tool for meeting the law, not the law itself. Article 50 has been enforceable since August 2, 2026, whether or not your company signs onto the code.
3. Assuming "it's obviously AI" excuses you from labeling
A common argument among marketing teams is that if an image or video is clearly synthetic, disclosure is redundant. Article 50 doesn't recognize that exception based on subjective perception: it requires that information about AI use be contextual, understandable, and provided at the right moment, regardless of how "obvious" the content seems to the team that made it. What's obvious to your team isn't necessarily obvious to the audience the content reaches.
4. Assuming the art or satire exception always protects you
Article 50(4) provides an exception for works that are "manifestly artistic, creative, satirical, fictional, or analogous," which in that case only require disclosure that is "appropriate and does not hamper the display or enjoyment of the work." Treating this exception as a catch-all is the most common error here. The line between a satirical deepfake and a misleading one depends on the context of publication, not the creator's original intent: a piece made as an internal joke can lose that character the moment it's taken out of context on social media, and the exception stops applying.
5. Not training your team on what each tool actually does
A recurring problem is that content teams don't distinguish between AI that generates from scratch, AI that transforms real input (editing, upscaling, style changes), and AI that only assists (correction, suggestions). Each level carries different labeling implications. As the sources we consulted put it: if a team doesn't understand when a tool generates, when it transforms, when it only assists, and when the output needs substantial review before publishing, the company doesn't have a compliance problem, it has a workflow culture problem.
Generating an image from scratch, or substantially transforming one in a way that changes the content, needs to be labeled; a minimal edit doesn't. For example, placing a product in a setting it's never been in needs a label; adjusting the lighting doesn't.
6. Thinking this only affects "big tech" or foundation models
Article 50 isn't aimed at any particular company size. It applies to anyone using generative AI to produce content that reaches third parties: agencies, ecommerce, media, startups, freelancers. Company size doesn't decide anything here; what determines the obligation is the role (provider or deployer) and the type of content produced. There is a timing nuance for GPAI model providers: models released before August 2, 2025 have until August 2, 2027 to fully adapt, a year longer than models released after that date. But that extra time is for model providers, not for those who simply use those models to publish content.
7. Underestimating the size of the fine
Failing to meet Article 50's transparency obligations is sanctioned, under Article 99 of the AI Act, with fines of up to €15,000,000 or 3% of the company's global annual turnover, whichever is higher. For context on the regulation's penalty scale: prohibited practices under Article 5 go up to €35 million or 7% of turnover; failing to meet operator obligations (where Article 50 sits) goes up to €15 million or 3%; and providing incorrect or misleading information to authorities goes up to €7.5 million or 1%. This isn't a symbolic fine, and several industry sources are already warning that the lack of common technical standards will produce widespread non-compliance in the first few months.
Quick checklist before publishing AI-generated content
- Identify whether your company is acting as a provider, a deployer, or both, for each piece of content.
- Combine metadata with a watermark that survives social media compression.
- If the content could be mistaken for a real person, place, or event, treat it as a deepfake and add a visible disclosure, not just metadata.
- Don't apply the satire/art exception by default: review the publication context case by case.
- Train your content team on the difference between generating, transforming, and assisting.
How we handle this at Picgenio
Every image you generate in Picgenio carries metadata labeling by default. On top of that, the image settings panel lets you choose which visible label to apply before exporting, depending on the channel you're publishing to. That's the combination Article 50 itself asks for, and the one we outlined in the checklist: metadata plus visible disclosure, not just one or the other.
Frequently asked questions
Since when is it mandatory to label AI-generated content in the EU? Since August 2, 2026, when Article 50's transparency obligations of the AI Act entered into application and enforcement (digital-strategy.ec.europa.eu).
Who does Article 50 of the AI Act apply to? Providers and deployers of AI systems that generate or manipulate audio, image, video, or text reaching third parties, with no requirement to operate a high-risk system.
What's the maximum fine for not labeling AI content? Up to €15 million or 3% of the company's global annual turnover, whichever is higher, under Article 99 of the AI Act.
Is a visible watermark enough to comply? Not necessarily. The law requires labeling that's machine-readable and detectable as AI; a visible watermark that gets lost when content is cropped or compressed doesn't cover the requirement on its own. It's recommended to combine a C2PA credential, a resilient watermark, and a record of the generation event.
Is there an exception for artistic or satirical content? Yes, Article 50(4) allows for lighter disclosure for works that are manifestly artistic, creative, or satirical, but the criterion is subjective and depends on the publication context, it isn't an automatic exemption.
This article is for informational purposes only and does not constitute legal advice. For compliance decisions specific to your company, consult a lawyer specialized in AI regulation.

