Skip to content
skill-guide · 2026.08.06

Do You Need to Label AI Content? EU Rules for UK Businesses

by paul thomas·7 min·1,598 wordsSKILL-GUIDE
// in this post

Between a 5,500-person subscriber base at thehumanco.org, 500+ LinkedIn newsletter readers, and client work teaching AI capability, nearly everything I publish is built alongside AI. I run my business with AI agents, compete in hackathons, and processed 3 billion tokens across Claude Code and Cowork in the first quarter of this year alone.

So when the EU AI Act's transparency rules took effect on 2 August 2026, my first priority was figuring out where the legal line sits. Do I need to label my content?

Finding a straight answer took far too long because most coverage has been misleading or overly theoretical.

Here's my breakdown of what the transparency rules actually mean for UK-based operators.

Note: This is an operator's breakdown, not legal advice. If you have material exposure in the EU market, consult a qualified solicitor.

The EU AI Act delay you read about covered different rules

If you saw news headlines in May 2026 claiming the EU delayed its AI Act, those reports were true, but widely misunderstood.

The EU did delay the rules, but only for heavy-duty, high-risk applications, like medical devices, critical infrastructure, and recruitment algorithms, pushing those out to late 2027 and 2028.

What didn't move were the content transparency rules. The legal obligation to declare when AI generates text or media took effect right on schedule on 2 August 2026. A four-month grace period does run to 2 December 2026, but it covers only the machine-readable marking requirement, and only for systems already on the EU market before August.

In short: the rules for high-risk industrial AI were paused, but the rules for published content arrived on time. If you saw the "delay" headlines and filed your compliance under 2027, you filed the wrong deadline.

Do the EU AI Act rules apply to UK businesses?

The European Commission's position is that providers of AI systems established or located outside the EU are subject to the AI Act if the output of their AI system is used in the EU. Where your company is registered doesn't settle it. Where your output lands does.

If you sell into Europe, run a website Europeans read, operate a chatbot Europeans can reach, or send AI-assisted communications to customers in EU member states, you are potentially in scope. A lot of UK businesses that think of themselves as domestic are not, once you look at who actually receives their output.

The four things Article 50 covers

Article 50 covers four distinct situations, and they don't all fall on the same party. Two land on providers, the people who build and supply AI systems. Two land on deployers, the people who use them. Most businesses reading this are deployers rather than providers, which makes the second pair the ones to look at first.

Telling people they're dealing with an AI. Systems that interact directly with people have to make clear the person is talking to a machine, unless that's obvious to a reasonably well-informed person. This falls on providers, and it covers chatbots, voice agents and avatars. Background systems and machine-to-machine traffic are out of scope.

Marking synthetic content so it can be detected. Providers of systems that generate audio, image, video or text have to mark the output as AI-generated in a machine-readable format. There are real exemptions, including short sequences, source code, machine-to-machine output, and assistive functions that support standard editing without substantially altering the input or its meaning.

Emotion recognition and biometric categorisation. Deployers of these systems have to inform the people exposed to them that the system is operating.

Deepfakes and public-interest text. Deployers have to label AI-generated or manipulated image, audio or video content that falsely appears authentic, clearly and distinguishably. Artistic, creative, satirical and fictional work is exempt, provided the labelling doesn't spoil the work. The same obligation covers AI-generated text published to inform the public on matters of public interest.

AI-generated text: where most businesses will trip up

That final rule, labelling AI-generated text published on "public interest" topics, is the trap most operators will fall into. The trigger threshold is broader than it looks, and the exemption is surprisingly narrow.

To skip the label, the text must undergo genuine human review or editorial control, where an individual or organisation assumes full accountability for the content. Substantive fact-checking and professional validation qualify. However, the EU guidance explicitly notes that running basic spell-checks or fixing typos does not cut it.

That distinction is everything. Generating a draft with Claude, skim-reading it once, and hitting publish isn't editorial control, it's just light proofreading. True editorial control means a named human actively verifies the claims, corrects the errors, and owns the output.

This solves my own dilemma. Because every article I publish is fact-checked against primary sources, signed with my name, and backed by my personal reputation, it meets the bar for editorial control, meaning the mandatory label doesn't apply. While I'm confident in that legal standing, I'd still rather maintain a clear, documented audit trail of that review process than debate it with a regulator later.

Penalties for getting it wrong

Up to €15 million or 3% of total worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities.

That number is not aimed at a mid-sized business publishing a blog. It is aimed at large providers, and enforcement attention will follow the same logic. The ceiling is not your likely exposure, though it does tell you there is real enforcement budget behind this.

What I'd actually do about it

Find out where AI touches anything that leaves your business. Most leaders cannot produce that list, which is the actual problem underneath the compliance question. Marketing copy, customer emails, chatbots on the website, reports that go to clients, anything a supplier generates on your behalf.

Check what your vendors are doing, because their tool can create your obligation. If a supplier runs a chatbot for you or generates content in your name, you may be the deployer, and two of the four obligations sit with deployers rather than the people who built the system.

Decide who reviews what, and write it down. The exemption for public-interest text depends on a named human taking responsibility. Make that a person and a step, not an assumption.

Say it's a bot when it's a bot. The cheapest obligation to meet, and the one where getting caught out looks worst.

Use the Commission's own icons where you do need to label something. The EU has published a free set of icons for marking AI-generated content, covering fully generated and partially modified material, and you can use them without attribution or sign-up. The Commission's own wording is worth keeping in mind: the icons are optional, the labelling requirements they exist to serve are not.

Keep the record. Who approved what, and when. Nobody wants to reconstruct that under pressure.

Why compliance depends on how you adopted AI

Meeting any of these obligations requires knowing exactly where AI is being used across your business. That turns out to be the hard part, and how difficult it is depends on a choice you made much earlier.

If you bought licences for everyone and told them to experiment, AI is now embedded in your emails, proposals, and client reports in ways no one recorded and no one can track. You have an invisible compliance shadow. But if you built a few targeted projects, each with a clear owner, you can answer the legal question in an afternoon. Someone actually knows what each system touches and what happens to its output.

Governance isn't a separate workstream from adoption. The way you adopted AI determines whether you can answer for it. That is the strongest argument for running a few owned projects over a general rollout, and I certainly didn't expect it to come from a legal framework.

FAQ

Do the EU AI Act labelling rules apply to UK businesses?

They can. The European Commission is explicit that providers established or located outside the EU fall under the AI Act if the output of their AI system is used in the EU. Being outside the EU is not the deciding factor. Whether your AI output reaches people inside it is.

When did the EU AI Act transparency obligations take effect?

2 August 2026. A four-month grace period runs to 2 December 2026, but only for the machine-readable marking requirement under Article 50(2), and only for generative AI systems already placed on the EU market before 2 August 2026. Content published before 2 August 2026 does not need labelling retrospectively.

Wasn't the EU AI Act delayed?

Parts of it were. The Digital Omnibus postponed high-risk obligations, moving stand-alone Annex III systems to 2 December 2027 and AI embedded in regulated products to 2 August 2028. The Article 50 transparency obligations were not postponed and took effect as scheduled. If you read that the AI Act had been delayed and concluded nothing applied yet, that headline was about different rules.

Does AI-assisted writing have to be labelled?

Only in specific circumstances. The obligation covers AI-generated or manipulated text published to inform the public on matters of public interest, and it does not apply where the text has undergone human review or editorial control with someone taking responsibility for it. The guidance is clear that spell-checking or grammatical correction alone does not count as review.

What are the penalties for breaching the AI Act transparency rules?

Up to €15 million or 3% of total worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities.

// read next
// subscribe
Get the next one in your inbox
One practical AI note a week, from the actual work. Free, unsubscribe in a click.