Skip to content

AI

Do You Have to Label AI Images on Social Media? What the AI Act Requires

SteadybeatAugust 6, 2026Lue suomeksi
A magnifying glass revealing a glowing watermark hidden inside a landscape picture

On 2 August 2026 the part of the EU AI Act that touches ordinary businesses most directly started to apply. Coverage has been patchy, and at least one wrong claim is still circulating. Here is what is known, what is not, and which parts apply to you if your business publishes AI-made content on social media.

This is not legal advice

Written on 6 August 2026, based on the text of the Regulation and the guidance the Commission has published. Where I am reading between the lines, I say so. Individual cases are settled by legal assessment, not by a blog post.

What changed on 2 August

The AI Act — Regulation (EU) 2024/1689 — entered into force back in August 2024, but its obligations have been switching on in stages. The stage that arrived on 2 August 2026 is Article 50, which covers transparency.

Article 50 does not require everything made with AI to be labelled. It splits duties between two different parties and gives each of them a different job. Most businesses publishing on social media land on the side with less to do.

One claim is worth killing straight away. The amendment package proposed in November 2025, the Digital Omnibus, has now been adopted as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. It pushed back deadlines for high-risk systems, but it did not postpone Article 50. If you see a claim that transparency obligations moved to 2027, it is wrong.

Breaches carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. Read that as a ceiling rather than a starting point.

Two roles, and which one you are in

The Act separates the provider from the deployer. The definitions sit in Article 3, and they are worth reading closely, because the whole split of duties hangs on them.

A provider is a party that "develops an AI system … or that has an AI system … developed and places it on the market or puts the AI system into service under its own name or trademark".

A deployer is a party "using an AI system under its authority", unless the use is personal and non-professional.

If you write an Instagram caption with ChatGPT or generate an image inside a social media tool, you are using a system somebody else built, in the course of your business. That makes you a deployer. It stays true no matter how many AI tools you use or how central they are to your marketing.

Who is responsible for what
ObligationProviderDeployer
Disclose that a system is AI (chatbots), 50(1)YesNo
Machine-readable marking of output, 50(2)YesNo
Inform about emotion recognition or biometric categorisation, 50(3)NoYes
Disclose deepfakes and public-interest text, 50(4)NoYes

So a deployer's duties come from 50(3) and 50(4). Emotion recognition and biometric categorisation have nothing to do with social media marketing, which leaves one paragraph.

When you actually have to disclose

Article 50(4) contains two separate things that often get mixed together.

Deepfakes

The first covers image, audio and video. A deployer has to disclose that the content is artificially generated or manipulated when it is a deepfake. Article 3 defines that as:

AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful

Two conditions, and both have to hold. The content has to resemble something that exists, and it has to be something that would pass as authentic.

The first condition is broader than it sounds. "Existing objects" covers a great deal, since an AI image of a pastry does resemble a pastry that exists. The answer is not in that half of the test.

My reading: the weight sits on the second condition. An illustrative image that does not claim to show any particular real thing does not appear authentic in the sense the definition is reaching for. Ordinary AI illustration in a marketing post falls outside.

The line shows up where an image is presented as a record of reality. An AI-made "photo" of your product, your premises or your staff is a different proposition from a generic illustration, because a viewer reads it as documentary. That is where the definition starts to bite, and it is the case most people skip past.

There is an exception for work that is evidently artistic, creative, satirical or fictional. There, disclosure is limited to a manner that does not spoil the experience of the work.

Text on matters of public interest

The second branch covers text, and it is narrower than a first glance suggests. It applies to AI-generated text published for the purpose of informing the public on matters of public interest.

A company's marketing post is not that. This is about journalism and public-interest communication, not about announcing your new product.

The duty also falls away where the text has been through human review or editorial control and a person or organisation carries editorial responsibility for it. In practice: reading the draft, deciding it is right and publishing it under your own name is exactly the situation the exception describes.

What is not your job

Paragraph 50(2) puts a duty on the provider to make sure system outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated".

This is not a visible "made with AI" caption in the corner of an image. It means metadata and watermarking, invisible to a person and readable by a machine. It is handled by the services that generate the content, and the large models already do it. It is not something a small business adds by hand.

On 10 June 2026 the Commission published a voluntary Code of Practice on Transparency of AI-generated Content describing how the duty is met in practice. The Commission and the AI Board found it adequate for demonstrating compliance on 8–9 July 2026, and by the end of July around 190 organisations had signed it. Signing is voluntary. The underlying obligation is not.

The EU also published a set of icons for deployers to label AI content. If a label is needed, that set beats inventing your own.

What is still unknown

One question is open. It is not about you but about the people who make the tools you use, and it is worth knowing it is open, because it explains why the answers you find on this topic disagree with each other.

The boundary between provider and deployer is unclear when a software company builds a feature on somebody else's model and sells it under its own brand. That is exactly how social media tools are put together: the image comes out of OpenAI's model or a comparable one, but the button lives in the tool's own interface. The phrase "under its own name or trademark" in the definition supports treating that company as a provider. The competing reading is that it merely uses the original provider's system.

I went through the Commission's FAQ on the topic, the final guidelines published on 20 July 2026, and the Code of Practice. None of them settles it directly. The guidelines do refer to "downstream system providers" and encourage model providers to mark content so that later parties in the chain can meet their own obligation. That points towards the duty sitting downstream, but a pointer is not an answer.

Neither reading changes what you have to do. The question decides only which of the two applies the machine-readable mark: the company that made the tool, or the one that made the model. A deployer's duties are the same either way.

One more point deserves attention. The guidelines encourage keeping marks intact as content travels through a distribution chain. Image processing and compression strip metadata easily, and this area is moving quickly. If the marking matters to you, check how your tools treat it.

Dates

Checklist

2 August 2026 — Article 50 started to apply. Deployer duties are live now.

2 December 2026 — Transitional deadline for machine-readable marking under 50(2). It covers only systems already on the market before 2 August 2026, and it is the provider's problem. Anything launched after that date had to comply immediately.

Content generated before 2 August 2026 does not have to be labelled retroactively.

The short version

If your business publishes AI-made illustrations and marketing copy on social media, Article 50 probably does not require a visible label. The duty targets deepfakes and public-interest communication, and neither describes ordinary social media marketing.

Two situations are still worth recognising. An AI image presented as a photograph of something real sits closer to the deepfake definition than an illustration does. And publishing public-interest communication without human review can bring the text branch into play.

Labelling anyway is rarely a bad idea. What the law requires and what your audience appreciates are two different questions.

Sources

Publish to every channel at once

Try Steadybeat