The EU's AI disclosure rules, explained for people who run websites
What the EU AI Act's Article 50 disclosure rules mean for ordinary websites, who they reach, and what to do about them, in plain language.
This guide is not legal advice. It is a plain-language explanation of a law, written by people who build compliance tools, for people who run websites. If your situation is complicated, talk to a lawyer.
The thirty-second version
Since 2 August 2026, the EU's AI Act has included a disclosure duty for AI-generated content. If your website publishes AI-assisted text or AI-generated images to people in the EU, some of that content now needs labelling. Not all of it. The rules distinguish between text and images, between assisted and generated, and between content that informs the public and content that sells your services. The rest of this guide is what "some of it" means, and it is shorter than you fear.
How we got here, briefly
The AI Act was agreed in 2024 after the sort of negotiation that produces a document nobody reads end to end. It applies in stages. The headline-grabbing parts, the rules for high-risk AI systems, come later. The transparency rules landed earlier, in August 2026, because labelling content is something regulators reasonably expect everyone to manage without a two-year runway.
Here is the part nobody says out loud: the people this touches most are not AI companies. They are ordinary businesses whose websites quietly filled up with AI-assisted content over the last few years, written by their marketing agency, their intern, or themselves at eleven at night. Almost none of them were told. If you are reading this in mild alarm, you are not behind. Everyone found out late.
Who this actually applies to
The honest answer: more people than you expect, fewer than fear it.
The duty attaches to content published to people in the EU. Where your business is registered matters less than where your readers are. A UK studio with German clients, an American shop that ships to France, a Dutch agency running sites for anyone at all: if EU visitors are part of your audience, the transparency rules are part of your life. This is the same long reach GDPR taught everyone about, and the logic is identical.
In the language of the Act, the duty falls on the "deployer" of the AI system, which for a website means the business that used AI to make the content and published it. Not the AI company. Not your hosting provider. You.
Which raises the question every agency owner just asked: whose duty is it when an agency built the site, wrote the copy with AI, and runs the whole thing for a client who thinks "generative" is a type of yoga? The short answer is that the client publishes, the agency created the exposure, and in practice the agency ends up owning the fix. The long answer has its own guide: The agency problem: client sites and whose duty it is.
What has to be disclosed, and what doesn't
This is the heart of the law, and it turns on two distinctions worth learning properly.
Text is different from images. For AI-generated text, the duty applies where the text is published "to inform the public on matters of public interest", and, crucially, the duty is lifted where the content "has undergone a process of human review or editorial control" and a real person "holds editorial responsibility". That quoted language comes straight from Article 50(4), and it is the single most practical sentence in the whole Act. It means AI-drafted text that a real person has genuinely reviewed, with someone named taking responsibility for it, does not need a label. The catch, and it is the catch our entire product exists for, is that when anyone asks, you need to be able to show that the review actually happened. An unrecorded review is a story. A recorded one is a defence.
Images get no such lift. There is no editorial-review exception for imagery. The sharpest duty applies to what the Act calls deep fakes: AI-generated or manipulated images, audio or video that resemble real people, places, objects or events and would falsely appear authentic. Those must be visibly disclosed. Not in the metadata, not in the alt text, not in a footer nobody scrolls to. More on this in the next section, because it is where most websites are quietly exposed.
Assisted is different from generated. Text you wrote yourself and asked a model to tighten sits differently from text a model produced, and you skimmed. The honest test is authorship: who actually made this? If the substance came from the machine, treat it as AI-generated and either label it or put it through real human review with a name attached.
The edge cases people actually have: product descriptions generated at scale are squarely in scope and squarely eligible for the review lift if someone genuinely reviews them. Machine-translated versions of your own human-written pages are at the gentle end, though pure machine translation published unreviewed is braver than we would be. Stock imagery is the library's problem to mark at source, but the deep-fake duty can still reach what you publish. A chatbot on your page carries its own separate duty, the oldest one in the Act: people must know they are talking to a machine.
For the full walk-through of what counts, there is a dedicated guide: Does my website need AI disclosure?
Images are the ones that bite
If you take one section of this guide seriously, make it this one.
The text duty comes with a built-in escape route: human review, editorial responsibility, no label needed. The image duty does not. An AI-generated image that looks like a real photograph of a real-seeming person, place or event needs a disclosure that a visitor can actually see, "at the latest at the time of the first interaction or exposure", to quote Article 50(5). That means on the page, near the image, in words a human reads. A C2PA credential buried in the file's metadata is good practice and genuinely useful, but it is not, by itself, a visible disclosure.
Think about what actually lives on business websites. The hero image of a team that does not exist. The "our office" photograph rendered by a model because the real office is a spare bedroom. The suspiciously photogenic tradesman on a trades site. Every one of those is a realistic AI image presenting as authentic, which is precisely the territory the deep-fake rule was written for.
There is a softer rule for content that is "evidently artistic, creative, satirical, fictional": it still needs disclosure of its generated nature, but in an "appropriate manner" that does not spoil the work. An obviously stylised illustration is a lighter problem than a fake photograph. The trouble is that "evidently" is doing a lot of work in that sentence, and the safe, honest practice is simple: if the image came out of a model, say so where people can see it.
The full treatment, including what a compliant image label looks like: AI images and the label rule.
What a compliant disclosure looks like
The Act's standard is that disclosures are provided "in a clear and distinguishable manner" no later than first exposure. In practice, for text, that means a line a reader will actually encounter, in the language of the page, near the content it describes.
A good disclosure sounds like a person: "Parts of this article were drafted with AI assistance and reviewed before publication by a named member of our team." It says what happened, who stood behind it, and it reads like the rest of your site.
A lazy disclosure is the cookie-banner school of compliance: a site-wide line in the footer saying "some content may be AI-generated". It discloses nothing about anything in particular, which is another way of saying it discloses nothing.
And there is non-disclosure dressed as disclosure: a hidden page at /ai-policy that no reader will ever find, doing the legal equivalent of mumbling. If a disclosure needs a sitemap to locate, it is not clear, and it is certainly not distinguishable.
Where does it go? For an article, at the top or foot of the piece. For an image, adjacent to the image or in its caption. For a page that is substantially AI-generated, before the reader has invested ten minutes in it. The test is not cleverness; it is whether an ordinary visitor would actually encounter it. There is a full guide with examples: How to write a disclosure that satisfies the rules.
What happens if you ignore it
Here are the real numbers, and then the honest framing.
Non-compliance with the transparency obligations carries administrative fines of up to €15m or 3% of total worldwide annual turnover, whichever is higher, under Article 99(4). For small and medium-sized businesses, the Act applies the lower of those figures rather than the higher, and regulators are directed to weigh proportionality, cooperation and whether the breach was negligent or deliberate.
Now the framing. Enforcement is young. Member states have been standing up their regulators, and regulators move at regulator speed. Nobody is kicking down doors over an unlabelled blog post this quarter. But the duty exists now, the fines are on the statute book now, and the practical risk arrives before any regulator does: a competitor's complaint, a journalist's question, a procurement questionnaire asking how you comply with Article 50, a client asking their agency the same. Retrofitting disclosure across a few hundred pages under pressure, with the record showing you did it after being asked, is strictly worse than doing it calmly, this month, because you chose to.
Who would actually come asking, country by country: Regulators, country by country. What the fine print actually says: What Article 50 actually says.
Questions people actually ask
Does a blog post written with ChatGPT need a disclosure? If it was published for EU readers to inform them about something that matters to the public, yes, unless a real person reviewed it and takes editorial responsibility. If it was reviewed, keep evidence of the review. The lift is real, but it is not a vibe; it is a process.
Do old posts count, or only new ones? Less than you might fear. The Commission's guidance on these rules says content published before 2 August 2026 needs no retroactive labelling, and pre-existing AI imagery generated before that date is likewise exempt. The exemption only protects what you leave alone, though: update, republish or repurpose old content after that date and it comes into scope as a fresh publication. A calm audit still beats a panicked purge, not least because it tells you which pages are genuinely dormant and which you have quietly been editing all along.
Does an AI-edited photograph count? Editing sits on a spectrum. Cleaning up lighting is not the concern. Generating or reworking an image so it depicts something that did not happen, while looking like it did, is deep-fake territory and needs a visible disclosure.
We are a UK business. Does this apply to us? If people in the EU are part of your audience, yes. The Act reaches content published to EU visitors regardless of where the publisher sits, which is the same extraterritorial logic as GDPR.
Does internal content count? Our intranet is half AI these days. The duties here concern content published to the public. Your internal wiki is between you and your colleagues.
Does human review really remove the labelling duty for text? For text, yes, that is what Article 50(4) says: AI-generated content that has undergone human review or editorial control, with a natural or legal person holding editorial responsibility, is excepted. The operative words are "has undergone a process". A process leaves a record. That is the entire reason our product exists, so treat this answer as coming from an interested party and check the Article yourself.
Is there an exception like that for images? No. That is the asymmetry this whole guide keeps returning to. Text can be reviewed out of the duty. Images cannot.
Do we have to label content our agency made for us? The publisher carries the duty, and "our agency did it" has never impressed a regulator in any adjacent field. Ask your agency what was AI-generated, and if they cannot answer, that is itself the answer.
What about AI translations of our own pages? Translating your own human-written content is the gentle end of the spectrum. The cautious practice, and the one we follow ourselves, is a short note that the translation was AI-assisted and reviewed. It costs one sentence.
Is a line in our site footer enough? No. Disclosure has to be clear, distinguishable, and encountered by the time the content is, which a generic footer line is not.
Doing something about it
A sensible process has four steps, and none of them requires panic. Know what is actually on your site, which for most businesses means a scan rather than an afternoon of clicking. Decide what needs a label and what a named person will review instead. Have that person actually review it and sign their name to it. And keep a record that would satisfy someone who asked to see it, because a review nobody can evidence is a review that never happened.
That process is what we built Swornmark to do: the scan, the suggested disclosures, the named sign-off, and a tamper-evident certificate anyone can verify. There is one in the footer of this very page, covering this very article, which felt like the least we could do given the subject matter.
If you are staring at a website full of maybe-AI content and would rather compare horror stories than buy anything, we would genuinely love a chat. And if you just want to know where you stand, the scan is free and takes about a minute: swornmark.com.
This guide is not legal advice. It was drafted with AI assistance and reviewed before publication. Swornmark holds editorial responsibility for it, which, as you have just read, is rather the point.
More guides
Does my website need AI disclosure?
A decision-tree guide to whether the EU's AI disclosure rules reach your website, with the questions people actually ask.
AI images and the label rule: images are the ones that bite
Why AI-generated images are the strictest corner of the EU's disclosure rules, and what a label a visitor can see actually means.
What Article 50 actually says
A clause-by-clause walk through Article 50 of the EU AI Act, quoting the text and translating it for people who run websites.
The agency problem: client sites and whose duty it is
When an agency builds and runs a client's website, whose AI disclosure duty is it? The practical answer for agency owners.
How to write a disclosure that satisfies the rules
How to write an AI disclosure that satisfies the EU rules: worked examples, placement, tone, and the review that beats any wording.
Regulators, country by country: who would actually come asking
Which national authorities enforce the EU's AI disclosure rules, country by country, and how enforcement actually reaches a business.
The state of AI disclosure in Europe, August 2026
We scanned 494 ordinary business websites in 17 EU countries, 26 days after Article 50 took effect. Under 1% label their AI content. The numbers, by country and sector, with the method.