KI-Kennzeichnungspflicht

AI labeling requirement 2026: This is what now applies in the EU

An overview of the new transparency obligations of the AI Regulation

Since August 2, 2026, new transparency obligations regarding the use of artificial intelligence have been in effect in the European Union. Anyone operating a chatbot, publishing synthetic images, or distributing deepfakes must disclose the use of AI under certain conditions. In the public debate, this quickly leads to the conclusion that all AI-generated content must be labeled in the future. This is not the case. This article explains what obligations actually exist, who they apply to, what sanctions are threatened, and what rights those affected by deepfakes have.

AI labelling obligation according to Article 50 of the AI Regulation: What applies since August 2, 2026

The legal basis for the new labelling requirement is Article 50 of the AI Regulation, Regulation (EU) 2024/1689 on artificial intelligence. The regulation entered into force on August 1, 2024, but its effect is phased in. First, from February 2025, the prohibitions on certain AI practices and the requirement for AI competence applied. In August 2025, the rules for general-purpose models and the establishment of supervisory structures followed. Since August 2, 2026, the core of the regulation has been applicable, including the transparency obligations of Chapter IV.

The purpose of these regulations is narrowly defined. The regulation aims to prevent people from being deceived about the origin or authenticity of content. It does not, however, introduce a general obligation to label every text, image, and analysis created with AI. Article 50 contains four clearly defined categories of offenses with different addressees and several exceptions. Understanding these distinctions helps avoid unnecessary warnings and simultaneously identifies where action is actually required. Our topic page provides an overview of all company obligations. AI regulation for companies.

The European Commission specified the requirements in guidelines in July 2026. These guidelines address the personal and material scope of application as well as the practical implementation of the labeling. For companies, this means that while the obligations are generally determinable, the assessment of individual cases remains challenging because it depends on the technical design of the system and the company's own role in the market.

If you use generative AI in customer contact or communication, you should have the applications in question legally classified now, before complaints or official inquiries arise. Also, the Mandatory training according to the AI Regulation This already applies.

Chatbots, deepfakes and synthetic content: the four categories of cases in Article 50

Article 50 differentiates according to the type of system and the role of the obliged entity. A provider is someone who develops or commissions the development of an AI system and markets it under their own name. An operator is someone who uses an AI system under their own responsibility, for example, a company that uses a third-party image model for its advertising. The same company can assume different roles in different projects, and the corresponding obligations depend on these roles.

Interaction with AI must be recognizable

Systems that interact directly with people must be designed in such a way that the person concerned recognizes that they are communicating with a machine. This applies to chatbots on websites, AI avatars, and voice assistants in telephone customer service. The obligation lies with the provider. It does not apply if the fact is obvious to a reasonably observant person.

Synthetic content requires a machine-readable tag.

Providers of generative systems must mark their systems' output in a machine-readable format so that synthetic audio, image, video, and text content can be technically identified as artificially generated or manipulated. This includes watermarks, metadata, or similar methods. This obligation applies to the manufacturers of the systems, not to individual users.

Emotion recognition and biometric categorization

Anyone using emotion recognition or biometric categorization systems must inform the individuals concerned about their use. This obligation rests with the system operator. It is in addition to the data protection requirements that already apply to the processing of biometric data.

Deepfakes and texts of public interest

Operators who create or manipulate deepfakes must disclose that the content was artificially created or altered. For texts, this disclosure obligation applies if they are published to inform the public about matters of public interest. The disclosure must be clear, recognizable, and provided no later than the moment of first interaction or perception. The regulation also clarifies that other transparency obligations under Union or national law remain unaffected.

For each AI application, clearly define whether your company is a provider or operator. A legal review of this role allocation prevents obligations from being overlooked or unnecessarily assumed. Companies without their own compliance structure can outsource this task to a [relevant party/person]. external AI officer transmitted.

Exceptions and transitional periods for the AI labelling requirement

Article 50 contains several limitations that are often overlooked in media coverage. For artistic, creative, satirical, or fictional works, disclosure is only required in a manner that does not impair the performance of the work. A distracting notice in the middle of the image is therefore not required. Separate exceptions exist for law enforcement purposes. The copyright issues arising from the use of generative systems, which we will discuss under [reference to relevant section], must be distinguished from this labeling requirement. AI and intellectual property represent.

The limitation is particularly important in practice when it comes to texts. The disclosure requirement only applies if the text is intended to inform the public about matters of public interest. Furthermore, if the text is subject to human editorial control and a natural or legal person bears editorial responsibility, the requirement does not apply. Therefore, a product description, a newsletter, or a specialist article that was created with AI support and subsequently editorially reviewed generally does not need to be labeled as AI content.

A transitional period applies to existing content. Synthetic content created or distributed before the deadline only needs to comply with the requirements by December 2, 2026. For images, audio, and video, the date of creation is decisive; for texts of public interest, the date of publication is the determining factor. A text drafted before the deadline but published afterward may therefore be subject to the obligation.

Review your inventory before the end of the transition period. Those who only react after a complaint lose the flexibility that an early legal assessment offers.

Fines of up to 15 million euros: Sanctions for violations of transparency obligations

Violations of Article 50 fall under the second level of sanctions in the AI Regulation. According to Article 99(4), fines of up to €15 million are possible, or, in the case of companies, up to three percent of their total worldwide annual turnover of the preceding financial year. Whichever is higher applies. By comparison, violations of the prohibited AI practices under Article 5 can be punished with fines of up to €35 million or seven percent of turnover, and false statements to authorities with fines of up to €7.5 million or one percent.

These amounts are upper limits, not fixed amounts. Factors considered in determining the amount include the type, severity, and duration of the violation, the size and annual turnover of the company, cooperation with the authorities, and whether the violation was intentional or negligent. Small and medium-sized enterprises and start-ups are subject to special proportionality rules and lower upper limits.

The regulations are enforced on two levels. For general-purpose models, the European Commission's AI office is responsible, while for the application level, national market surveillance authorities are responsible. In addition, there is a risk that many companies underestimate: Failure to provide proper or misleading labeling can also have implications under competition law. Warnings for violations of the AI regulation by competitors or associations. The official procedure is therefore not the only point of attack.

If you receive an official inquiry or a warning letter regarding a missing AI label, you should seek legal advice before making any statement. Statements made during legal proceedings are difficult to correct later.

Deepfakes and AI content: What rights do those affected have?

The labeling requirement protects the public from deception. However, it does not replace the individual rights of those who are themselves harmed by a deepfake. If a person's face or voice is incorporated into a synthetic video or audio recording without their consent, several legal bases for claims may apply simultaneously.

The central element is the general right of personality enshrined in Article 2 Paragraph 1 in conjunction with Article 1 Paragraph 1 of the Basic Law. This gives rise to claims for injunctive relief and removal of infringing material in accordance with Section 1004 Paragraph 1 of the German Civil Code (BGB) in conjunction with Section 823 Paragraph 1 of the BGB. In the case of images, Sections 22 and 23 of the German Copyright Act (KUG) also apply, which generally permit distribution only with consent. In cases of serious violations, monetary compensation may be considered. If personal data is processed, claims for erasure under Article 17 of the GDPR and for damages under Article 82 of the GDPR also arise. You can find more information in our section. Data protection for private individuals.

Depending on the content, criminal offenses such as insult (§§ 185 ff. StGB), violation of the most personal sphere of life through image recordings (§ 201a StGB), or fraud may be committed. If synthetic voices or fake advertising images are used for property crimes, the situation overlaps with the classic [crime]. Online fraud. In cases of sexualized deepfakes, the burden on victims is particularly high because the content spreads rapidly. Two things are crucial here: securing evidence through screenshots with the date and URL, and promptly contacting the platforms that are obligated to process reports under the Digital Services Act.

If you have been affected by a deepfake, first secure the evidence and then have it checked what claims you have against the creator and the platform. What scenarios Compensation for damages in the case of AI use We will present the triggers separately. The sooner the spread is stopped, the less damage.

When is legal advice regarding AI labeling requirements worthwhile?

For companies, an audit is always worthwhile when AI systems are used in external communications. This includes chatbots, synthetic voices in telephone calls, generated product images, avatars in advertising, and automatically created content on political or social issues. It is advisable to take stock of all use cases, define the company's role as provider or operator, establish standardized disclaimers, and document the decisions made. Contracts with AI service providers are equally important, as they stipulate who is technically responsible for ensuring machine-readable tagging. Since AI systems regularly process personal data, the audit should be conducted in conjunction with the [relevant data protection authority/company]. Data protection law for companies be interlocked.

For private individuals, the trigger is usually a specific incident: a manipulated video, a cloned voice in a phone call, or a fake advertisement featuring their own face. In these cases, the focus is on injunctions, deletion, and compensation, and often on speed.

Rogert & Ulbrich advises companies and private individuals in the areas of data protection, IT law, and online fraud. The law firm is led by Dr. Marco Rogert and Tobias Ulbrich has taken on over 40,000 mandates and filed more than 25,000 lawsuits and has extensive experience in conducting complex proceedings against internationally operating companies.

The consultation includes the legal assessment of your AI applications, the design of notice and labeling concepts, support in official proceedings, and the extrajudicial and judicial enforcement of claims in cases of personal rights violations through synthetic content.

Whether it's a compliance issue within the company or a violation of your personal rights through a deepfake: Get in touch and secure your claims.

Conclusion: AI labeling requirements demand classification instead of blanket statements.

Since August 2, 2026, the transparency obligations of Article 50 of the AI Regulation have been in effect. They do not require blanket labeling of all AI content, but rather focus on four specific scenarios: interaction with AI systems, machine-readable labeling of synthetic output, the use of emotion recognition and biometric categorization, as well as deepfakes and texts of public interest. The decisive factor is the role as a provider or operator.

The potential fine of up to €15 million or three percent of global annual revenue demonstrates the seriousness of these obligations. At the same time, there remains room for appropriate solutions, as exceptions exist for art, satire, and editorially responsible texts, and a deadline of December 2, 2026, applies to existing content. Establishing an internal transparency strategy now will prevent the need for costly revisions under time pressure.

For those affected by deepfakes: The new labeling requirement improves the recognizability of manipulated content, but does not replace individual legal claims. Injunctions, deletion, and damages continue to be governed by personality rights, copyright law, and the General Data Protection Regulation (GDPR).

Have your specific situation legally assessed early on, especially if deadlines are approaching or content is already circulating.

FAQs – Frequently asked questions about the AI labeling requirement