The EU AI Act and DAM: labeling AI and proving authenticity
Starting August 2, 2026, the transparency requirements of the EU AI Act (Article 50) will apply to anyone who manages, distributes, or publishes digital assets.
AI-generated or AI-edited content must be labeled: visible to humans for content that simulates reality, and machine-readable so that search engines, platforms, and feeds such as LinkedIn, TikTok, or Instagram can understand its origin. This applies to product images, photorealistic campaign visuals, AI-generated text without editorial review, and chatbots.
A Digital Asset Management (DAM) system has long since stopped being a passive repository. It becomes a central control point where it is decided whether content meets labeling requirements or not: during export, format conversion, and distribution to channels and partners.
Those who set the right course now will be prepared by August. And they gain something beyond compliance in the future: a way to demonstrate that content is authentic.
DAM as gatekeeper
What role does AI already play in your DAM? Tagging? Agentic workflows? Generating focal points and format variants?
As soon as images or text (including accessibility descriptions) are generated with AI, they will soon need to be labeled in a machine-readable way. And as soon as they
-
communicate real-world information, and
-
have not been reviewed by a human editor (changing the format is not a review),
they will also need a human-readable label.
This applies regardless of whether AI is used directly inside the DAM. The system should understand the logic behind both machine- and human-readable labeling, detect signals, and, critically, ensure they are preserved.
That is exactly why the DAM is the right place for this. What matters now is implementing these changes across the organization behind the DAM.
Two EU documents regulate how Article 50 of the EU AI Act should be applied:
- The Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026 explains how AI-generated and AI-manipulated content can be marked and labeled.
- The Commission’s Guidelines on the transparency obligations under Article 50, formally adopted on 20 July 2026, clarify which providers, deployers, systems and content types fall within scope.
There is a key difference: the Code is a voluntary compliance tool, while the Guidelines explain how the legal obligations should be interpreted and applied.
Because both documents are now available, the main challenge is no longer what the rules say, but how quickly organizations can put them into practice before 2 August.
An important step right now is an AI inventory. Which software in my company uses AI? Which content has already been created or edited using AI?
Machine-readable: how does it work?
This is the question Adobe, Arm, BBC, Intel, Microsoft, Truepic, and others asked themselves five years ago when they founded C2PA, a consortium that developed a certificate to track origin (which camera, which AI generator), editing steps (masking in Photoshop is faster with AI), and publishing. This information is stored as a small string alongside IPTC and EXIF metadata.
The first cameras already write these certificates. ChatGPT does as well. Google integrates them into its AI systems and smartphones. Midjourney and Flux are still holding back. Photoshop and Lightroom write certificates when images or videos are edited using AI.
It’s a robust and relatively simple system within the creation–DAM–CMS process. But as soon as, for example, a JPG is converted into a PNG, the certificate can be lost along with all other metadata if workflows are not designed to preserve it.
Invisible watermarking marks the second layer of security. Under the final Code of Practice, this is no longer just a recommendation: it becomes part of the expected technical setup for generative AI providers that sign the Code.
In practice, that means combining digitally signed metadata, such as C2PA information, with an imperceptible watermark to make AI-generated or AI-manipulated content easier to detect over time. The reason is simple: no single marking technique currently meets all the four requirements of effectiveness, interoperability, robustness, and reliability on its own. Metadata can show where an asset came from and how it has changed, while watermarking carries additional evidence of AI involvement. Watermarks can be configured freely and, in addition to C2PA information, can include additional data.
For example, every retailer downloading images for their online store could be marked in the watermark on the fly. This opens up traceability: Who is using outdated images? Where have images been misused? Watermarks can even be detected in printed materials.
Images from Adobe Stock already contain Content Credentials. Agencies such as DPA are rolling out C2PA combined with watermarking. Providers like IMATAG and others offer services to embed certificates and watermarks.
In addition, the IPTC field DigitalSourceType, a standardized metadata field, can be populated. It uses a controlled vocabulary to indicate how an asset was created, for example AI-generated or AI-edited.
Read more: Content Authenticity: How to protect trust in the digital age
How DAM users should prepare now
-
AI inventory: which asset, which tool, which date
-
Metadata policy: consistently populate IPTC DigitalSourceType
-
Map export paths: test today where origin data is lost during conversion, rendition, and distribution
-
Approval step: check labeling before publication, not only in the distribution channel
-
Define output channels: decide per channel which type of labeling is required, whether visible disclosure, machine-readable provenance, or additional watermarking via service providers
Labels are now available off the shelf
Organizations publishing AI-generated or AI-manipulated content do not have to create a disclosure mark from scratch. The Code of Practice includes a set of EU icons that deployers of generative AI systems can use to label content covered by Article 50 of the EU AI Act.
The EU icon set help people recognise, clearly and distinctly, that content has been artificially generated or manipulated:
- A basic icon: when AI was involved in the creation of deep fake content or published text, or when a custom text label or interactive second layer is implemented.
- One icon indicates fully AI-generated content: content created entirely by AI, with no human involvement.
- One icon indicates partially AI-modified content: pre-existing content that has been partially modified using AI, generating deep fakes or AI-generated text that lacks human review.
All three icons are available in four variations for light and dark backgrounds, and they are free to use. Their use is optional: an equivalent icon or label is equally acceptable, as long as it carries the capitalised acronym "AI" as its main visual element, and it remains clear and distinguishable.
Signing the Code of practice is voluntary. What is not optional is the labeling obligation under Article 50, and using the icons is not a proof of compliance by itself. The organization publishing the content remains responsible for ensuring that its disclosure meets the applicable requirements of Article 50 AI Act.
For DAM users, this is a practical gain. A defined set of marks can be built into approval workflows and rendition templates, making disclosure more consistent across channels. This is more reliable than deciding how to label each asset case by case at the point of publication.
What is clear and what is not
One thing is clear: if an image is meant to depict reality (product images, people in photorealistic visuals, etc.) but is generated by AI, then human-readable labeling must appear even in places where image attribution has never been shown before. That includes website key visuals, brochures, posters, trade show walls, and more.
The question that matters most in everyday practice has been answered by the Commission’s Guidelines: not every edit or AI-assisted edit needs a label. What matters is whether the change could affect how authentic the content appears to the viewer. Routine adjustments such as lighting correction, colour correction, noise reduction, file compression, accessibility improvements, and small cosmetic adjustments are generally outside of scope when they do not change how authentic the content appears.
The line is drawn where AI changes the substance of what the viewer sees. Inserting, removing, or replacing objects or people, face swapping, or generating realistic scenes that never took place may affect a person’s perception of authenticity.
Context also matters. For example, substantial AI editing of background details in a journalistic image can affect the authenticity of the content and how it is perceived. A background extension or replacements applied to a product image in advertising or packaging are considered to have a minor impact. For product images, the practical test is straightforward: if the image still represents the product accurately, it is generally not a deep fake. If it makes the product appear more appealing, higher quality, or materially different from what it actually is, it may need to be treated differently.
Read more: EU AI Act Article 50 explained
From obligation to opportunity
You can, of course, simply label AI content as such. But that is not always well received by audiences.
The more interesting direction is the opposite. You can prove that a photo is real. That a text was written by a human. That images truly belong to the sender. In that sense, a labeling requirement becomes a proof of authenticity.
That makes the effort worthwhile. Similar to data protection, imprint requirements, and other mechanisms, it is the serious players who invest time in standing out from unreliable sources.
LinkedIn has already started filtering AI-generated content from feeds. They use detection tools that reportedly achieve around 94% accuracy. But authenticity certificates change the system entirely. They eliminate false positives and help communication reach the intended audience.
Recent examples, from major media outlets to political figures, show how unmarked AI content can quickly damage credibility. Using AI without disclosure may become the next trigger for public backlash.
About the author
This article is a guest contribution by Alexander Karst.
Alexander has been working in the advertising and imaging industry since 1994. After roles at PhotoDisc and Getty Images as a web and PR manager, he founded Die Bildbeschaffer GmbH in 2008. His agency supports companies and agencies with image sourcing, research, rights clearance, and image management. In addition, he provides training and consulting on image rights and the broader challenges of managing images, content, and media.
GenAI and Content Authenticity
Read more about the crisis of trust in digital content
Frequently asked questions
-
The Article 50 transparency requirements apply from 2 August 2026. They introduce obligations for providers and deployers of certain AI systems, including requirements to mark AI-generated or AI-manipulated content in machine-readable form and to disclose specified content clearly to people.
-
No. Routine adjustments such as colour correction, noise reduction, compression, accessibility improvements, and minor cosmetic edits generally do not require a label when they do not alter how authentic the content appears. Labeling becomes more relevant when AI materially changes what viewers perceive, for example by inserting or replacing people or objects, swapping faces, or creating a realistic event that never occurred.
-
A DAM can act as a control point for AI-related metadata, approvals, renditions, and distribution. It can record how an asset was created or edited, preserve provenance information during format conversion, apply the appropriate visible disclosure, and prevent publication when required information is missing.
-
C2PA is a technical standard for attaching verifiable provenance information to digital content. Content Credentials can record an asset’s origin and editing history, helping people and systems assess how it was created or changed. DAM workflows should preserve this information across conversion, rendition, and distribution.
-
Organizations should inventory the AI tools and assets they use, define a metadata policy, identify where provenance data may be lost, add an approval check before publication, and specify the visible and machine-readable labeling required for each output channel. These steps turn compliance into a repeatable workflow rather than a last-minute publishing decision.
On this page
