EU AI Act · use case
EU AI Act for Generative AI Content, Deepfakes and Marketing Copy
Text, image, audio and video generators have triggered Article 50 labelling duties since 2 August 2026. Machine-readable marking, deepfake disclosure, and what GPAI providers owe.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
Limited risk
Limited risk (Article 50(2) and 50(4) transparency); GPAI model duties for model providers
When it applies
GPAI model obligations apply since 2 August 2025. Article 50 obligations have applied since 2 August 2026.
Regulation (EU) 2024/1689, Art. 50(2), 50(4); Arts. 53-55 general-purpose AI models; Art. 5(1)(a)
Companies that generate content with AI, from marketing copy and product images to synthetic voices and video avatars, have two sets of duties under the EU AI Act. Providers of the generating system must mark outputs as artificially generated in a machine-readable way. Deployers who publish deepfakes, or AI-written text on matters of public interest, must disclose it to the audience.
If you build or fine-tune the underlying general-purpose model itself, a separate chapter applies: technical documentation, a copyright policy, a public summary of training content, and, for models with systemic risk, evaluation and incident-reporting duties. Most companies use a third-party model through an API and are not model providers.
Classification
Why this classification applies
Article 50(2) requires providers of AI systems, including general-purpose systems, that generate synthetic audio, image, video or text to ensure outputs are marked in a machine-readable format and detectable as artificially generated, where technically feasible, effective, interoperable and robust. Watermarking, content credentials and metadata standards are the intended tools.
Article 50(4) requires deployers to disclose deepfakes, meaning AI-generated or manipulated image, audio or video that appreciably resembles existing persons, objects, places or events and would falsely appear authentic. AI-generated text published to inform the public on matters of public interest must also be disclosed, unless a natural person exercises editorial control and responsibility.
Generation is not on the Annex III list, so a content generator is limited-risk unless its purpose is a listed one. It also cannot use manipulative or deceptive techniques to distort behaviour (Art. 5(1)(a)); synthetic reviews or fake testimonials presented as genuine sit close to that line and breach consumer-protection law regardless.
Obligations
What you have to do
- System providers: implement machine-readable marking of outputs (metadata such as C2PA or IPTC fields, provider watermarks) and document the method and its limits (Art. 50(2)).
- Deployers: label deepfakes visibly and label AI-written public-interest text unless a person has editorial responsibility (Art. 50(4)).
- Keep a labelling procedure per channel (website, social, email, video) and evidence of labels as displayed.
- Model providers: technical documentation, information for downstream providers, copyright compliance policy, public training-content summary, and additional duties for systemic-risk models (Arts. 53-55).
- Consumer-law hygiene: do not present AI-generated reviews or endorsements as genuine (Unfair Commercial Practices Directive).
- AI literacy for content and marketing teams (Art. 4).
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Stripping metadata in the publishing pipeline. Social schedulers and image optimisers often remove the very marks the provider added.
- AI-generated “customer” photos or testimonials. Beyond Art. 50, this is a deceptive commercial practice.
- Cloned voices of real presenters without disclosure. A synthetic voice that resembles a real person is a deepfake under Art. 50(4).
- Assuming an API user is never a provider. Fine-tuning and rebranding a model, or substantially modifying a system, can make you the provider.
FAQ
Frequently asked questions
Do we have to label every AI-written blog post?
Article 50(4) covers text published to inform the public on matters of public interest and exempts content under human editorial control. Ordinary marketing copy reviewed by your team is not caught, but the machine-readable marking duty on the provider side still applies where feasible.
Are AI-generated product images deepfakes?
Only if they appreciably resemble real persons, objects, places or events and would falsely appear authentic. A synthetic lifestyle scene with a fictional model is closer to that line than an illustrative render; label it to be safe and never depict real people without disclosure.
We fine-tune an open model for our product. Are we a GPAI provider?
Fine-tuning can make you the provider of a new general-purpose model for the modifications you made, with proportionate documentation duties. If the result is a narrow-purpose system, you are a system provider instead. The Commission’s GPAI guidelines set thresholds; document your analysis.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-22. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.