When you have to label AI content, and when you only should
Work out which AI labelling duties actually reach a one-person business, which ones are aimed at the model vendors, and what to write when a label is genuinely required.
on this page · 0 / 0 checked
You drafted the post with Claude, made the header image in ChatGPT, cleaned up the audio in something else, and now you are looking at the publish button wondering whether anything is supposed to say so. Somewhere behind you is a newsletter about a European law that started applying on 2 August 2026 [1], a client contract with a clause about AI you skimmed once, and a vague sense that the rules landed and nobody sent you the part that applies to you.
Most of what has been written about AI labelling was written for the companies that build the models. The law splits the duty in two, and the half pointed at your side of the table is narrow and specific. What is not narrow is the platform rules, which are enforced against your account rather than through a regulator, and the metadata your tools are already writing into your files without asking. This guide is for solo operators, freelancers and small teams publishing their own work and their clients’ work. If you run a product that generates content for a million people a month, or you use AI in hiring, credit or medical decisions, you are in a different regime and you want a lawyer, not a guide.
The law puts the marking on the vendor and the labelling on you
The EU AI Act’s transparency rules apply from 2 August 2026 [1]. They divide everyone into two roles. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark [3]. A deployer is anyone “using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity” [3]. Making a birthday card with Gemini is personal. Making a client’s launch video with it is not. If you use these tools for work, you are a deployer, and that is the only role you need to read about.
The provider side is where the heavy engineering sits. Providers must ensure that outputs “are marked in a machine-readable format and detectable as artificially generated or manipulated” [1][2], with the solutions required to be “effective, interoperable, robust and reliable as far as this is technically feasible” [2]. They must also design systems that interact directly with people so those people are told they are talking to an AI, unless that is obvious to a “reasonably well-informed, observant and circumspect” person [2]. That is the vendors’ problem, and they are solving it in their own products, which matters to you for a reason covered further down.
The deployer side is two duties, both about telling a person what they are looking at, delivered “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure” [2]. Enforcement runs through national market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are the provider or deployer [1]. Fines run up to €15M or 3% of total worldwide annual turnover for companies, with proportionality for small and medium businesses [1]. Two transitional details are worth knowing: the marking obligation has a grace period until December 2026 for generative systems placed on the market before 2 August 2026, and deepfakes generated before that date carry no mandatory retroactive labelling, though it is encouraged [1].
Two deployer duties can reach a one-person business
The first is deepfakes. The Act defines one as “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful” [3]. That is broader than a fake celebrity video. A product photograph of a room that does not exist, a testimonial voice that sounds like a real customer, a generated street scene passed off as your shopfront: all of it resembles real things and would read as authentic. Deployers of a system producing that content “shall disclose that the content has been artificially generated or manipulated” [2]. Where the content is part of an “evidently artistic, creative, satirical, fictional or analogous work”, the duty shrinks to disclosing the existence of generated content in a manner “that does not hamper the display or enjoyment of the work” [2].
The second is text, and it is narrower than the panic suggests. It covers deployers publishing AI-generated or manipulated text “with the purpose of informing the public on matters of public interest” [2]. Your pricing page is not that. A newsletter about an election, a public health claim or a local planning decision might be. And the duty falls away entirely where the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility” for the publication [2].
Read that exception twice, because it is the whole answer for most writing. The rule is not counting how many words a model produced. It is asking whether a human stands behind the publication. If you edited the draft, checked the claims and put your name on it, you are the person holding editorial responsibility, and the disclosure duty does not apply. If you scheduled forty posts generated overnight and nobody read them, you have no editorial responsibility to point at, and the rule now describes you exactly.
Most of what you make does not need a label at all
The marking obligation itself carves out systems that “perform an assistive function for standard editing or do not substantially alter the input data” or its semantics [2]. That is the legal shape of an intuition you already have. Fixing grammar is not authorship. Neither is transcribing an interview, upscaling a photo you took, or turning your own notes into cleaner sentences.
YouTube draws the same line more concretely, and its list is the most useful plain-English version anyone has published. Disclosure is not required for beauty filters, colour and lighting adjustments, special effects filters such as background blur, generative help with a video outline, script, thumbnail, title or infographic, caption creation, video sharpening, upscaling or repair, voice or audio repair, cloning your own voice for voiceovers or dubs, or generating a backdrop to simulate a moving car [8]. The platform notes that the list is not exhaustive [8].
What survives that filter is a small, recognisable category: content that makes a viewer believe something happened which did not. That is the thing every one of these rulebooks is actually chasing, and once you see it that way the compliance question stops being “did I use AI” and becomes “would a reasonable person think this was real”.
California’s law is aimed over your head and lands on your posts anyway
California’s AI Transparency Act became operative on 2 August 2026, the same day as the EU rules, after AB 853 moved the date [5]. It binds covered providers, meaning anyone whose generative system “has over 1,000,000 monthly visitors or users and is publicly accessible” [5]. You are not that. The vendors you use are.
What those vendors owe is worth knowing, because it explains what shows up in your files. AI-generated image, video and audio content has to carry a latent disclosure, latent meaning “present but not manifest” [4], conveying the name of the covered provider, “the name and version number of the GenAI system that created or altered the content”, the time and date of creation or alteration, and a unique identifier [4]. Users must also be offered the option of a manifest disclosure, one that identifies the content as AI-generated and is “clear, conspicuous, appropriate for the medium of the content, and understandable to a reasonable person” [4]. Each provider has to make available “an AI detection tool at no cost to the user” so anyone can check whether content came from its system [4]. Penalties are “five thousand dollars ($5,000) per violation”, and each day in violation is “deemed a discrete violation” [5].
Two later dates matter more to you than the first one. From 1 January 2027, the duties extend to large online platforms, defined as public-facing social media, file-sharing, mass messaging or stand-alone search services distributing content that exceeded 2,000,000 unique monthly users in the preceding 12 months [5]. Those platforms must detect provenance data embedded in or attached to content, give users an interface disclosing that such data is available, let them inspect it, and must not “knowingly strip any system provenance data or digital signature” from what gets uploaded [5]. From 1 January 2028, capture devices first produced for sale in the state on or after that date, including cameras, phones with built-in cameras or microphones and voice recorders, must “embed latent disclosures in content captured by the device by default” [5]. Your work gets labelled by infrastructure, whether or not you ticked a box.
The platform rules are the ones that will actually be enforced against you
No market surveillance authority is coming for a freelancer’s Instagram post. A platform classifier absolutely is. YouTube requires disclosure when AI “makes a real person appear to say or do something they didn’t do”, “alters footage of a real event or place”, or “generates a realistic scene that didn’t actually occur” [8]. The label appears in the expanded description for content that is non-photorealistic or animated, and “for AI content that is photorealistic, a label in the video player may also appear” [8]. Creators who consistently choose not to disclose “may be subject to manual application of a label, or penalties from YouTube, including removal of content or suspension from the YouTube Partner Program” [8]. YouTube also states plainly that “disclosing AI content won’t limit a video’s audience or impact its eligibility to earn money” [8], which removes the only real argument for hiding it.
The asymmetry here is the useful part. The legal duty is narrow, slow, and pointed mostly at companies far larger than yours. The platform duty is broad, automatic, and applied by a system that will guess wrong occasionally. Labelling your own work is how you keep the guess from mattering.
Your files are already carrying marks you did not add
Supported images generated with ChatGPT, Codex and the OpenAI API carry both C2PA Content Credentials and a SynthID watermark, and supported OpenAI-generated audio carries “an inaudible watermark embedded in the audio itself” [6]. Coverage “can vary by product, model, export path, file type, and when the content was created” [6]. Google has watermarked over 20 billion pieces of content with SynthID since 2023, and since November 2025 its Nano Banana Pro images in the Gemini app, Vertex AI and Google Ads carry embedded C2PA metadata as well [7]. You can upload an image into the Gemini app and ask whether it was created with Google AI; it checks for the SynthID watermark and answers [7].
Two things follow. First, if you generate an image and post the original file, a disclosure of sorts is already travelling with it, and from January 2027 the larger platforms have to detect that data and show users it is there [5]. Second, that disclosure is fragile. OpenAI’s own documentation says metadata “can sometimes be removed by platforms, editing tools, or file conversions”, and that a missing signal may simply mean it “was stripped during upload, download, editing, conversion, or sharing” [6]. Post a re-exported copy rather than the file the model gave you and the credential may not survive the trip.
Text is the gap. The provenance signals OpenAI documents cover images and audio, with a stated goal of expanding them to all modalities including text [6]. Until that arrives, the only label on the blog post Claude helped you draft is the one you decide to write.
Write the disclosure once and put it where the reader is
A usable disclosure is one sentence, in plain words, placed where someone meets the content rather than buried in a policy page. The legal standard is the same instinct: clear, distinguishable, and no later than first exposure [2]. “The images in this post were generated with ChatGPT” is a disclosure. “This site may contain AI-assisted content” is a hedge that covers everything and tells nobody anything, and it will not satisfy the deepfake duty for the one video that needed it.
Use the platform’s own control when there is one, because that is what feeds the label a viewer sees and the signal the classifier checks. Then keep the original generated file rather than a re-exported copy, so the credentials survive. If you strip metadata deliberately for file size, you have removed the machine-readable half of your disclosure and the human-readable half is now the only one left.
What still goes wrong
The machine-readable layer is weaker than it sounds. Credentials get stripped by ordinary handling, and OpenAI says so in its own help page [6]. That cuts both ways: the absence of a Content Credential is not evidence that something is real, and you should not treat a detection tool’s silence as a verdict. A watermark check tells you when a signal is present, not why it is absent.
The legal edges are genuinely unsettled. “Matters of public interest” is not a bright line, and the Commission points to its own guidelines on Article 50 rather than the Act itself for scope, exceptions and use cases [1]. Enforcement against very small operators is untested, and proportionality for smaller businesses is a stated principle [1] rather than a formula anyone can apply in advance. If your work sits near politics, health or money, the cautious reading of the text duty is the correct one.
The part nobody regulates is the part that costs you most. A client who finds out after the fact that their case study was written by a model does not file with a market surveillance authority; they stop hiring you. None of this guide replaces reading your client contracts, several of which now say something about AI in the deliverables clause, and some of which say more than their signer realised.
- 01European Commission — Quick facts: transparency rules for AI systemsdigital-strategy.ec.europa.eu
- 02EU AI Act — Article 50, transparency obligations for providers and deployersartificialintelligenceact.eu
- 03EU AI Act — Article 3, definitionsartificialintelligenceact.eu
- 04California SB 942 — California AI Transparency Act, chaptered textlegiscan.com
- 05California AB 853 — AI Transparency Act amendments, chaptered textlegiscan.com
- 06OpenAI — Provenance signals (Content Credentials, SynthID) in OpenAI-generated contenthelp.openai.com
- 07Google — How we're bringing AI image verification to the Gemini appblog.google
- 08YouTube Help — Disclosing use of altered or synthetic contentsupport.google.com