Skip to content

Build1 publisher3 min readPublished

The Aug 2 AI labelling rules are a provider problem. Your list is three disclosures.

Article 50 and California's transparency act both switched on 2 August 2026. The watermarking work belongs to model vendors; a shipping team owes chatbot, deepfake and public-interest text notices.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Two AI labelling laws took effect together on 2 August 2026: Article 50 of the EU AI Act and California's AI Transparency Act.
  • The EU AI Act splits obligations between the provider, whoever puts the generative AI system on the market, and the deployer, whoever uses it; nearly all the engineering-heavy requirements sit with the provider.
  • Under Article 50(2), providers must design their systems so that synthetic image, audio, video and text output carries a machine-readable mark identifying it as AI-generated; this covers watermarking, C2PA-style content credentials and cryptographic signing, and is the tool's job when a user generates an image in a mainstream tool.
  • Deployer duty one: if you deploy an AI system that interacts with people, those people must be told they are dealing with AI, unless it is obvious from context.
  • Deployer duty two: if you publish AI-generated or manipulated image, audio or video that resembles real people, places or events, you must disclose it.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Two AI labelling regimes switched on together on 2 August 2026: Article 50 of the EU AI Act and California's AI Transparency Act, SB 942 as amended by AB 853 [1][15]. For anyone shipping a product rather than running a model, the practical consequence is that the expensive part of compliance is a ticket on someone else's board.

The EU AI Act splits duties between the provider, meaning whoever puts a generative system on the market, and the deployer, meaning whoever uses it, and nearly all the engineering-heavy requirements sit with the provider [2]. Article 50(2) requires providers to design systems so that synthetic image, audio, video and text output carries a machine-readable mark identifying it as AI-generated: watermarking, C2PA-style content credentials, cryptographic signing [3]. If you generate an image in a mainstream tool, marking it is the tool's job [3].

What attaches to a deployer is three things [3]. If you deploy an AI system that interacts with people, they must be told they are dealing with AI unless that is obvious from context [4]. If you publish AI-generated or manipulated image, audio or video resembling real people, places or events, you must disclose it [5]. If you publish AI-authored text intended to inform the public on matters of public interest, you must disclose that as well [6].

The third duty has an exception written into it: it does not apply where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication [7]. The dev.to explainer reads that plainly as the difference between a site that pipes model output straight to publication and one where a named human edits and stands behind the piece [7]. There is no equivalent escape for image, audio or video; a deepfake stays a deepfake after you edit it [8].

Note who the timeline favours. Article 50 kept its 2 August 2026 date while the Digital Omnibus, in force from 27 July 2026, pushed the standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk to 2 August 2028 [9][10] - a gap of sixteen months and twenty-four months respectively behind the transparency rules [2]. The single concession granted to Article 50 is a four-month conformity window, to 2 December 2026, for generative systems already on the EU market before 2 August; anything launched on or after that date gets nothing [11][1]. That window is a provider window. Deployer disclosures were due on 2 August [12].

Exposure is real but not top-tier. Article 50 breaches sit at up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher, against the 35 million euro or 7 percent reserved for prohibited practices, a cap 20 million euro lower [13][4]. The Act also reaches non-EU businesses whose AI output is used in the EU, so a US freelancer serving European clients is in scope [14].

California is narrower still. CAITA regulates covered providers only, defined as publicly accessible generative AI systems with more than one million monthly visitors or users in California [16]. Below that threshold it does not apply to you [16].

What to watch: whether the machine-readable marks actually show up in vendor output by the 2 December 2026 conformity deadline [11], because deployers relying on tool-side marking inherit the gap when it is missing. Watch, too, how the editorial-responsibility carve-out is treated where review is nominal rather than substantive; the text sets the test at responsibility, not effort [7].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories