Does my website need AI disclosure?
A decision-tree guide to whether the EU's AI disclosure rules reach your website, with the questions people actually ask.
Part of our guide to the EU AI disclosure rules.
This guide is not legal advice. It is a plain-language explanation of who the EU's AI disclosure rules actually reach. For the full picture, start with our main guide to the disclosure duty.
The short answer
Probably some of it, and probably less than you fear. If your website publishes AI-assisted text or AI-generated images to people in the EU, the AI Act's transparency rules apply to you since 2 August 2026. Whether any given page needs a label depends on what the content is, who made it, and whether a human genuinely reviewed it. That is the whole law in three sentences. The rest of this article is working out which of your pages fall where.
Work through it like this
Start with your audience, not your address. The rules attach to content published to people in the EU, wherever your business is registered. A Manchester agency with Dutch clients is in. A Boston shop that ships to Ireland is in. A site that genuinely serves nobody in Europe is out, and "we have never checked" is not the same as "nobody in Europe".
Then ask who made the content. Text you wrote yourself, with your own hands and your own typos, carries no duty at all. The rules are about content an AI system generated or manipulated. If a model drafted it, translated it at scale, or rewrote it beyond recognition, keep going. If a model fixed your grammar, relax.
For AI text, ask what the content does. The duty in Article 50 applies to AI-generated text published "to inform the public on matters of public interest". Your blog advising landlords on tax changes: squarely in. Your guide to choosing a boiler, your explainer on tenants' rights, your health-adjacent listicle: in. Your own about page describing your own company: at the gentle end, though a disclosure still costs one sentence and buys quiet.
Then ask whether a human really reviewed it. This is the part of the law most worth knowing. The text duty is lifted entirely where the content "has undergone a process of human review or editorial control" and a named person "holds editorial responsibility" for it. Reviewed, by someone, on the record. If your process is real and you can show it, your reviewed AI text needs no label at all. If your process is "Dave skimmed it once, probably", you have a story rather than a defence, and stories do not survive being asked twice.
Images are their own question, and a harder one. There is no review-and-lift for imagery. AI-generated images that depict real-seeming people, places or events need a visible disclosure on the page, near the image, where a person actually looks. If your site carries a generated team photo or a rendered "our premises" shot, that is the page to fix first. The full treatment is in our images guide, and it earns its dramatic title.
Old content is more forgiving than you might expect, with a catch. The Commission's guidance on these rules says content published before 2 August 2026 does not need labelling retroactively, and for imagery the date that matters is when it was generated. So the untouched 2023 blog post is off the hook. The catch is the word untouched: republish it, update it, or fold it into a new page after that date and it walks back into scope, and most sites edit more than they remember. An audit is still how you find out which pages are genuinely dormant and which just feel dormant.
Questions people actually ask
We only used AI to edit and polish. Does that count? Light editing of human-written text is the safe end of the spectrum; the rules aim at generated content, not assisted typing. The honest test is authorship. If the substance came from you, it is yours. If the substance came from the model and you tidied it, treat it as AI-generated.
Our blog is AI-drafted but a person edits every post before it goes out. Do we need labels? If the review is real and someone takes editorial responsibility, no, that is exactly the exception Article 50 provides for text. The practical requirement hiding in that sentence is evidence. A review that leaves no record is very hard to distinguish, later, from no review.
We are outside the EU. Surely this is not our problem? If EU visitors are part of your audience, it is. The Act reaches content published to people in the EU regardless of where the publisher sits, the same way GDPR does. Familiar logic, new subject matter.
Our agency wrote the site. Whose problem is it? You publish it, so the duty lands with you, and "the agency did it" is not a sentence regulators find moving. The fair follow-up question, what agencies owe their clients here, has its own guide.
Does our chatbot need anything? Yes, and it is the oldest rule in this part of the Act: people must be told they are interacting with a machine, unless it is obvious. Most chat widgets handle this with a line in the greeting. Check yours actually says it.
Do product descriptions count? Generated at scale, yes, they are AI-generated text published to the public. They are also perfect candidates for the review lift: a person reviews the batch, takes responsibility, keeps the record. This is the least dramatic fix on the list.
What about machine-translated versions of our own pages? Translating your own human-written content sits at the gentle end. Our own practice, and the cautious one, is a short note that the translation was AI-assisted and reviewed. One sentence per language.
What happens if we just do nothing? The fines for breaching the transparency rules run to €15m or 3% of worldwide turnover, with smaller companies fined at the lower of those rather than the higher. Enforcement is young and nobody is being raided over a blog post. But the duty exists now, and the cheap moment to comply is before anyone asks. The expensive moment is after.
So what do we actually do on Monday? Find out what is on your site, honestly, which for most people means a scan rather than a fortnight of clicking. Sort it into three piles: human-made, AI-made-and-worth-reviewing, AI-made-and-needs-a-label. Then make the piles true: review and sign the second, label the third, and keep a record of all of it.
Where we come in
That Monday process is what Swornmark does end to end: a scan that finds the content in question, suggested disclosures for what needs them, a named sign-off for what a review can lift, and a tamper-evident certificate that proves the whole thing happened. The scan is free and takes about a minute, and if it finds nothing, it will say so and you can close the tab with a clear conscience.
This guide is not legal advice. It was drafted with AI assistance and reviewed before publication. Swornmark holds editorial responsibility for it.
More guides
AI images and the label rule: images are the ones that bite
Why AI-generated images are the strictest corner of the EU's disclosure rules, and what a label a visitor can see actually means.
What Article 50 actually says
A clause-by-clause walk through Article 50 of the EU AI Act, quoting the text and translating it for people who run websites.
The agency problem: client sites and whose duty it is
When an agency builds and runs a client's website, whose AI disclosure duty is it? The practical answer for agency owners.
How to write a disclosure that satisfies the rules
How to write an AI disclosure that satisfies the EU rules: worked examples, placement, tone, and the review that beats any wording.
Regulators, country by country: who would actually come asking
Which national authorities enforce the EU's AI disclosure rules, country by country, and how enforcement actually reaches a business.
The state of AI disclosure in Europe, August 2026
We scanned 494 ordinary business websites in 17 EU countries, 26 days after Article 50 took effect. Under 1% label their AI content. The numbers, by country and sector, with the method.
The EU's AI disclosure rules, explained for people who run websites