Does AI have to be labeled? Who carries the duty for AI images
Lennart WolfWhoever uses AI images professionally has to label them: your own company, not the vendor of the AI tool. Since 2 August 2026, the AI Act, the EU's AI regulation, requires that convincingly real AI content is visibly disclosed when published. We show who is responsible between your agency and your own team, and which images are affected at all.

Who has to label AI images: the tool vendor or you?
The duty falls on whoever is responsible for the use of AI and puts the images to professional use. The AI Act calls this role the deployer. In the normal case, the deployer is your company.
Many marketing teams assume the image generator takes care of it, since it marks its own output internally anyway. That assumption is the single most common mistake around AI labeling. The law separates two roles. The provider develops the AI system or puts it on the market under its own name. Those are, in everyday terms, the makers of the image generators. The deployer uses the system professionally, in the words of the law "under its own authority". That is almost always you. A way to remember it: the provider builds the tool, the deployer works with it. Only purely private use falls outside the duty.
This is set out in Article 3 and Article 50 of the AI Act. The disclosure duty for convincingly real image, audio and video content is addressed explicitly to deployers there. It has applied since 2 August 2026.
Typical deployers, even if they would never call themselves that:
- the marketing department publishing AI product shots or campaign visuals
- the online shop showing real clothing on AI-generated models
- the property marketer turning a photo into an AI-animated walkthrough video
- the publisher using an AI-generated cover
In short: whoever is responsible for the use of AI and puts the content to professional use does the labeling. The tool does not take that job off your hands.
Still unsure whether this applies to you?
Start the self-testAgency, freelancer, your own staff: who labels in which setup?
Labeling falls to whoever decides whether and how AI is used. In case of doubt the duty falls on the company as a whole, and almost never on the individual person at the keyboard.
The European Commission addressed exactly this question in its guidelines on the transparency obligations from July 2026. Guidelines are official aids to interpretation: not legally binding, but the yardstick supervisory authorities go by. They state that employees working on instruction and under the control of their employer are not deployers in their own right. The same holds for freelancers producing on behalf of and under the responsibility of the company. It gets interesting in the triangle between agency and client.
| Your setup | Who is the deployer and has to disclose |
|---|---|
| An employee creates AI images on the job | The company. The individual employee is not a deployer in their own right. |
| A freelancer works to your brief and under your control | Your company. |
| An agency creates AI images under its own responsibility, the client merely publishes them | The agency. It also has to make sure its disclosure actually reaches the audience, for instance through a contractual arrangement with the client. |
| The client dictates whether and how AI is used | The client is then a deployer itself, possibly alongside the agency. |
For clients that means: whoever gives their agency a free hand and neither orders nor steers the use of AI is not a deployer under the guidelines. But the moment you specify that and how AI is used, the duty moves to you. Because that line blurs in everyday work, labeling belongs in the contract.
So the question of roles is settled by control over the use of AI. The name on the invoice is secondary.
Visible and machine-readable: why your AI tool's marking is not enough
The AI Act asks for two separate things: a machine-readable marking by the tool vendor, and a visible disclosure by you as the deployer. Neither layer replaces the other.
The provider has to ensure that the outputs of its system are detectable as artificially generated, as far as that is technically feasible. This marking sits in the metadata, for example, in invisible extra information stored alongside the image file. People see nothing of it, checking software can read it out. Your disclosure as a deployer, by contrast, addresses people: the audience has to be able to recognise at first exposure that a piece of content was artificially generated or altered.
| Provider (tool maker) | Deployer (your company) | |
|---|---|---|
| Duty | Machine-readable marking of the outputs | Visible disclosure when publishing |
| Addressed to | Software that checks content automatically | People who see the content |
| Legal basis | Article 50(2) AI Act | Article 50(4) AI Act |
| In force since | 2 August 2026; systems already on the market have until 2 December 2026 | 2 August 2026, with no transition period |
An example: your image generator delivers a campaign visual with a clean machine-readable marking. You post it without a visible notice. The provider's duty is met, yours as a deployer is not.
On top of that comes an EU transition rule: providers of AI systems that were already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking. That changes nothing about your duty as a deployer, which already applies. If anything it sharpens the situation: until December there is no guarantee that legacy tools mark their output at all. Anyone relying on their tool today may well end up with no labeling on either level. And even an existing marking can be lost along the way, because many platforms strip metadata on upload or editing.
Remember the division of labour like this: the provider marks for machines, you disclose for people.
When you become a provider yourself
Whoever offers or puts into service an AI system under their own name or brand becomes a provider in legal terms. You do not need an AI model of your own for that.
The AI Act ties the provider role to the system running under your name. Even having an AI system developed for you and then using it under your own brand, or making it available to customers, brings the provider duties with it, including the machine-readable marking. What counts is the system under your brand. Whoever merely uses someone else's tool and publishes or sells its images remains a deployer.
If a company has an image generator built and offers it as its own "studio" to the whole corporate group or to external customers, it is the provider of that system. That holds even if the studio only wires in a third-party AI model through an interface (API), making it what is known as an AI wrapper; what counts is your own name, not the depth of the engineering. If the company also uses the system for its own communications, the deployer role comes on top.
Which images are affected and which are not
Labeling is required for anything that looks real but was artificially generated or altered. An edited real photo can fall under it too.
The law calls such content deepfakes: image, audio or video content generated or altered by AI that resembles real persons, objects, places, entities or events and falsely appears authentic. A completely invented but realistic-looking person falls under it as well. As a rule of thumb from practice: what is covered are convincingly real depictions of anything you might encounter in daily life, from people and rooms to products and food.
| Example | Labeling required? |
|---|---|
| AI-generated product shot or campaign visual, convincingly real | Yes, visible disclosure |
| Real photo, furnished by AI or animated into a video | Yes, visible disclosure |
| Colour correction, noise reduction, standard retouching | No. No substantial alteration, no convincingly real result |
| Recognisably unrealistic style, such as comic or illustration | No. It does not appear real, so it is not a deepfake |
| Artistic, satirical or fictional works, recognisable as such | Relaxed: disclosure in a form that does not spoil the work is enough |
| Purely private, non-professional use | No. Without professional use there is no deployer duty |
The reason for the retouching exemption: a plain colour correction does not produce a convincingly real result and misleads no one. The duty hinges on exactly that, on the potential to deceive. Labeling AI content therefore does not mean labeling every edited image.
Label what could deceive, and only that.
Conclusion: labeling AI images is your job, and it is doable
The problem is rarely the technology, it is responsibility. Whoever uses an AI system under their own authority and puts the content to professional use carries the duty as a deployer, since 2 August 2026 and with no transition period. The division of labour in the law stands alongside that: tool vendors mark for machines, you disclose visibly for people. So there are two things to do: settle who owns labeling at your company and at your service providers, and set up a process that labels every affected image visibly and durably.
On the cost side: the AI Act provides for fines of up to 15 million euros for breaches of the labeling duty or, for companies, up to 3 percent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises the lower of the two applies. In Germany the Bundesnetzagentur, the Federal Network Agency known to many from its oversight of telecoms and energy networks, acts as the central authority for the AI Act; the Wettbewerbszentrale, a self-regulatory body of German industry for fair competition, has been taking complaints about missing AI labeling since the end of July 2026. Competitors can also issue a warning letter over missing labeling, meaning they demand an out-of-court cease-and-desist and reimbursement of costs. For purely online labeling breaches, reimbursement of those costs to competitors is excluded (Section 13(4) UWG, the German Unfair Competition Act), to the extent AI labeling falls under it.
Three approaches compared: what holds up when it counts?
| Visible label only | AI tool's marking only | mintys by on:mint | |
|---|---|---|---|
| Visible disclosure, your duty as a deployer (Article 50(4) AI Act) | Met | Missing | Met |
| Machine-readable marking in the file (Article 50(2) AI Act, per C2PA) | Missing | MetBy the provider, as long as the metadata survives. | Met |
| Labeling survives upload, screenshot and editing | PartlyThe label can be cropped out or removed. | MissingMetadata is usually lost in the process. | MetInvisible watermark in the pixels. |
| Evidence of when and by whom labeling happened | Missing | PartlyOnly while the metadata is intact. | Met |
| Approach documented along the EU Code of Practice | Missing | Missing | Met |
| Risk of warning letters and fines | RemainsAs soon as the label is removed and no evidence exists. | HighYour disclosure duty stays unmet. | MinimisedDuty met and documented. |
That leaves the evidence. If it comes to a dispute, what counts is what you can prove: that an image carried a label, even after it was shared or re-uploaded. That is what we built mintys for, the AI labeling solution by on:mint. mintys places the visible label directly on your image: in your corporate design if you want, and at the right size for every visual. When the format changes, from portrait to landscape for instance, the label stays consistently in its place.
mintys also writes that same label into the image's metadata in machine-readable form, following C2PA, an open standard for provenance information stored directly in the file. An invisible watermark backs up both. It sits in the pixels themselves rather than in the metadata, and therefore survives cropping, compression and re-uploading. So if someone removes the visible label or a platform strips the metadata, it remains provable when and by whom this image was labeled. The result is a digital passport for your image, secured against unnoticed changes and documenting that the labeling was applied.
There is a commitment behind the tool: on:mint has signed the Code of Practice on Transparency of AI-Generated Content, the code of conduct developed at EU level for implementing these transparency obligations. According to the Commission's guidelines, following such a code is a simple and predictable way to demonstrate compliance. Those who do without it have to expect supervisory authorities to request more information. With mintys you label along the practices of that code. mintys also supports you in judging whether an image needs a label at all. So you label only what has to be labeled.
Only the combination of visible label, machine-readable marking and invisible watermark meets your disclosure duty under the AI Act in a way that survives upload and editing and can be proven in a dispute. That is exactly what mintys does. Visible labeling under Article 50 AI Act, evidence included.
Rather check first what applies to you?
To the self-test