The transparency obligations under Article 50 of the AI Act have applied since 2 August 2026. We outlined the four areas covered by those provisions in an earlier article. In practice, however, the question of disclosure rarely arises in the abstract; it usually concerns a specific use case. A company may have used AI to create a campaign visual, draft a text or integrate a chat assistant, only to find that it is unclear whether, and in what form, the use of AI must be disclosed.
The wording of the legislation alone is often of limited assistance in carrying out this assessment. A more practical approach is to start with the finished content and work through the relevant questions step by step.
Preliminary question: Is my company subject to the obligations at all?
The first question is to whom the use of AI is legally attributable. The AI Act distinguishes in particular between providers and deployers:
A person who develops an AI system, or has one developed, and places it on the market under its own name is generally regarded as a provider. The focus for providers is primarily on the system’s technical design. This includes, in particular, whether machine-generated content is marked as such and whether those markings can be technically detected and verified.
A person who uses an AI system in the course of its business is, by contrast, a deployer. Its obligations primarily concern transparent use vis-à-vis the persons who interact with the system or its outputs. Where a company develops its own tool and also uses it for its own communications, it may simultaneously perform both roles.
For companies, the distinction is particularly relevant in collaborative projects and outsourcing arrangements. Employees, such as members of an in-house marketing team or employed graphic designers, generally act on behalf of the company and do not assume a separate role as deployer. The same may apply to a service provider acting under close instructions.
The position may be different where an agency independently decides whether and how to use AI in a client project and thereby assumes responsibility of its own. A person who integrates a third-party AI model into its own product and offers that product under its own name may also itself become a provider.
The designations or allocation of responsibilities chosen in the contract are not conclusive. What matters are the actual circumstances and, in particular, who determines how the AI is used.
Images, Video and Audio: When Does Content Constitute a Deep Fake?
For visual and audio content, two levels must be distinguished: the technical marking obligations imposed on the provider of the AI system and the disclosure obligations imposed on the company using the generated content. At provider level, a system that generates synthetic image, video or audio content must generally mark its outputs in such a way that they can subsequently be technically detected and verified as artificially generated or manipulated. Not every form of digital editing falls within this category. Cropping, sharpening or reducing image noise does not, in itself, create synthetic content. The position may be different where new visual elements are added, several scenes are combined or voices are artificially generated.
At the second level, the issue is disclosure to the public. For companies using such content, the principal question is whether the content constitutes a deep fake. The concept is broader than its everyday usage might suggest. It is not necessary for a well-known person to be impersonated or for an actual event to be falsified. It may be sufficient for AI-generated content to depict a person, place or situation in a realistic manner such that it could be mistaken for an authentic recording. An intention to deceive is not required. Accordingly, even a wholly fictional but photorealistic advertising visual may qualify as a deep fake, for example an image of a family seated at a breakfast table even though neither the persons nor the scene ever existed.
The overall impression is decisive. Relevant factors include, in particular, the degree of realism, the intended audience, the context in which the content is published and the likelihood that it will be perceived as an authentic recording. Where such an impression of reality is clearly absent, the content will generally not constitute a deep fake. Examples include clearly drawn illustrations, manifestly impossible scenes, or obvious exaggerations and parodies. The AI Act also provides for a lighter-touch approach in relation to artistic, satirical and comparable works. In such cases, the disclosure may be presented in a manner that does not unduly impair the display or enjoyment of the work.
Where disclosure is required, it must be made where the content is perceived. For images and videos, the notice should be immediately visible; for audio content, it should generally be audible at the beginning. A marking contained solely in the metadata is not sufficient to inform the public.
Text: A Narrow but Practically Relevant Disclosure Obligation
The threshold for disclosure is higher for text than for image, video or audio content. Visible disclosure is generally required only where three conditions are met: the text has been generated or manipulated in whole or in part by AI, it is published, and it is intended to inform the public on a matter of public interest. This may include content relating to health, the environment, the administration of justice, consumer protection, and political or economic affairs. Product descriptions, conventional advertising copy and purely entertainment content will generally fall outside the provision. The position may be different, for example, in the case of an AI-generated advisory article addressing a public-health policy debate.
An important exception applies where the text has undergone sufficient human review and a natural or legal person assumes editorial responsibility for its publication. A merely formal approval is not sufficient. A party wishing to rely on the exception should be able to document that the content was reviewed by a suitably qualified person, checked against its factual basis and, where necessary, substantively revised. If the text is materially altered using AI after that review, it must be reassessed whether the conditions for the exception remain satisfied or whether the disclosure obligation applies again.
What Disclosure Does Not Achieve
Three points help to avoid common misunderstandings. First, the provider’s technical marking obligations may apply even where synthetic content is used solely within the organisation. Visible disclosure of AI-generated text, by contrast, generally presupposes publication and will normally not apply to purely internal content. Second, the means of distribution is irrelevant. Whether content is distributed by newsletter, landing page, social network or press release does not, in itself, make a difference. The decisive factors are the content, its purpose and the role of the company concerned.
Third, proper disclosure does not automatically render the use of AI lawful. It merely satisfies the transparency requirements. A separate assessment remains necessary to determine whether data protection requirements are met, copyright and personality rights are respected, the communication complies with unfair competition law, or further requirements apply, including prohibitions or specific obligations for high-risk systems. Conversely, Article 50 of the AI Act applies irrespective of whether a system is commercial or open source and is by no means limited to high-risk applications. Even the use of an ordinary image generator in marketing may trigger the transparency obligations. Infringements may be subject to administrative fines of up to EUR 15 million or, in the case of undertakings, up to 3% of total worldwide annual turnover. Potential consequences also include claims under unfair competition law and reputational harm, particularly because the absence of a required disclosure may be immediately apparent to the public.
Practical recommendation:
Whether AI-generated content must be disclosed should not be reassessed from first principles in every individual case. A standardised decision-making process based on four key questions is more effective:
- Who is responsible for the output?
For each use case, determine whether your company provides the AI system, merely deploys it or performs both roles. This allocation should be documented. Particular care is required for third-party solutions offered or distributed under the company’s own name. In those circumstances, the company may itself qualify as a provider. - Does the image appear to be an authentic recording?
Include the impression of reality as a standard item in the approval process for campaign materials. The issue is not confined to manipulated footage of well-known individuals. Fully fictional but photorealistic everyday scenes are more frequently overlooked. - Is the editorial review sufficient?
For AI-generated texts concerning matters of public interest, define the requirements that must be met for a genuine substantive review. The review process should also be documented in a traceable manner. A purely formal approval will generally not be sufficient. - Have the service providers been properly involved?
Require providers of AI systems and commissioned agencies, by contract, to apply any required markings and to ensure that those markings remain technically verifiable. The marking should survive any further processing or integration of the content. Service providers should also be required to notify you of relevant changes to the systems or procedures used.
The key point remains that disclosure addresses transparency only. Data protection, copyright and unfair competition requirements must continue to be assessed separately.
We would be pleased to assist you in identifying the relevant roles, designing internal review and approval processes, and putting in place appropriate contractual safeguards vis-à-vis service providers.
Contact:
Jens Borchardt
