Reading progress0 %

    INSIGHT

    Does AI have to be labeled? Who carries the duty for AI images

    Lennart WolfLennart Wolf

    Whoever uses AI images professionally has to label them: your own company, not the vendor of the AI tool. Since 2 August 2026, the AI Act, the EU's AI regulation, requires that convincingly real AI content is visibly disclosed when published. We show who is responsible between your agency and your own team, and which images are affected at all.

    Does AI have to be labeled? Who carries the duty for AI images

    Who has to label AI images: the tool vendor or you?

    The duty falls on whoever is responsible for the use of AI and puts the images to professional use. The AI Act calls this role the deployer. In the normal case, the deployer is your company.

    Many marketing teams assume the image generator takes care of it, since it marks its own output internally anyway. That assumption is the single most common mistake around AI labeling. The law separates two roles. The provider develops the AI system or puts it on the market under its own name. Those are, in everyday terms, the makers of the image generators. The deployer uses the system professionally, in the words of the law "under its own authority". That is almost always you. A way to remember it: the provider builds the tool, the deployer works with it. Only purely private use falls outside the duty.

    This is set out in Article 3 and Article 50 of the AI Act. The disclosure duty for convincingly real image, audio and video content is addressed explicitly to deployers there. It has applied since 2 August 2026.

    Typical deployers, even if they would never call themselves that:

    • the marketing department publishing AI product shots or campaign visuals
    • the online shop showing real clothing on AI-generated models
    • the property marketer turning a photo into an AI-animated walkthrough video
    • the publisher using an AI-generated cover

    In short: whoever is responsible for the use of AI and puts the content to professional use does the labeling. The tool does not take that job off your hands.

    Still unsure whether this applies to you?

    Start the self-test

    Agency, freelancer, your own staff: who labels in which setup?

    Labeling falls to whoever decides whether and how AI is used. In case of doubt the duty falls on the company as a whole, and almost never on the individual person at the keyboard.

    The European Commission addressed exactly this question in its guidelines on the transparency obligations from July 2026. Guidelines are official aids to interpretation: not legally binding, but the yardstick supervisory authorities go by. They state that employees working on instruction and under the control of their employer are not deployers in their own right. The same holds for freelancers producing on behalf of and under the responsibility of the company. It gets interesting in the triangle between agency and client.

    Your setupWho is the deployer and has to disclose
    An employee creates AI images on the jobThe company. The individual employee is not a deployer in their own right.
    A freelancer works to your brief and under your controlYour company.
    An agency creates AI images under its own responsibility, the client merely publishes themThe agency. It also has to make sure its disclosure actually reaches the audience, for instance through a contractual arrangement with the client.
    The client dictates whether and how AI is usedThe client is then a deployer itself, possibly alongside the agency.

    For clients that means: whoever gives their agency a free hand and neither orders nor steers the use of AI is not a deployer under the guidelines. But the moment you specify that and how AI is used, the duty moves to you. Because that line blurs in everyday work, labeling belongs in the contract.

    So the question of roles is settled by control over the use of AI. The name on the invoice is secondary.

    Visible and machine-readable: why your AI tool's marking is not enough

    The AI Act asks for two separate things: a machine-readable marking by the tool vendor, and a visible disclosure by you as the deployer. Neither layer replaces the other.

    The provider has to ensure that the outputs of its system are detectable as artificially generated, as far as that is technically feasible. This marking sits in the metadata, for example, in invisible extra information stored alongside the image file. People see nothing of it, checking software can read it out. Your disclosure as a deployer, by contrast, addresses people: the audience has to be able to recognise at first exposure that a piece of content was artificially generated or altered.

    Provider (tool maker)Deployer (your company)
    DutyMachine-readable marking of the outputsVisible disclosure when publishing
    Addressed toSoftware that checks content automaticallyPeople who see the content
    Legal basisArticle 50(2) AI ActArticle 50(4) AI Act
    In force since2 August 2026; systems already on the market have until 2 December 20262 August 2026, with no transition period

    An example: your image generator delivers a campaign visual with a clean machine-readable marking. You post it without a visible notice. The provider's duty is met, yours as a deployer is not.

    On top of that comes an EU transition rule: providers of AI systems that were already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking. That changes nothing about your duty as a deployer, which already applies. If anything it sharpens the situation: until December there is no guarantee that legacy tools mark their output at all. Anyone relying on their tool today may well end up with no labeling on either level. And even an existing marking can be lost along the way, because many platforms strip metadata on upload or editing.

    Remember the division of labour like this: the provider marks for machines, you disclose for people.

    When you become a provider yourself

    Whoever offers or puts into service an AI system under their own name or brand becomes a provider in legal terms. You do not need an AI model of your own for that.

    The AI Act ties the provider role to the system running under your name. Even having an AI system developed for you and then using it under your own brand, or making it available to customers, brings the provider duties with it, including the machine-readable marking. What counts is the system under your brand. Whoever merely uses someone else's tool and publishes or sells its images remains a deployer.

    If a company has an image generator built and offers it as its own "studio" to the whole corporate group or to external customers, it is the provider of that system. That holds even if the studio only wires in a third-party AI model through an interface (API), making it what is known as an AI wrapper; what counts is your own name, not the depth of the engineering. If the company also uses the system for its own communications, the deployer role comes on top.

    Which images are affected and which are not

    Labeling is required for anything that looks real but was artificially generated or altered. An edited real photo can fall under it too.

    The law calls such content deepfakes: image, audio or video content generated or altered by AI that resembles real persons, objects, places, entities or events and falsely appears authentic. A completely invented but realistic-looking person falls under it as well. As a rule of thumb from practice: what is covered are convincingly real depictions of anything you might encounter in daily life, from people and rooms to products and food.

    ExampleLabeling required?
    AI-generated product shot or campaign visual, convincingly realYes, visible disclosure
    Real photo, furnished by AI or animated into a videoYes, visible disclosure
    Colour correction, noise reduction, standard retouchingNo. No substantial alteration, no convincingly real result
    Recognisably unrealistic style, such as comic or illustrationNo. It does not appear real, so it is not a deepfake
    Artistic, satirical or fictional works, recognisable as suchRelaxed: disclosure in a form that does not spoil the work is enough
    Purely private, non-professional useNo. Without professional use there is no deployer duty

    The reason for the retouching exemption: a plain colour correction does not produce a convincingly real result and misleads no one. The duty hinges on exactly that, on the potential to deceive. Labeling AI content therefore does not mean labeling every edited image.

    Label what could deceive, and only that.

    Conclusion: labeling AI images is your job, and it is doable

    The problem is rarely the technology, it is responsibility. Whoever uses an AI system under their own authority and puts the content to professional use carries the duty as a deployer, since 2 August 2026 and with no transition period. The division of labour in the law stands alongside that: tool vendors mark for machines, you disclose visibly for people. So there are two things to do: settle who owns labeling at your company and at your service providers, and set up a process that labels every affected image visibly and durably.

    On the cost side: the AI Act provides for fines of up to 15 million euros for breaches of the labeling duty or, for companies, up to 3 percent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises the lower of the two applies. In Germany the Bundesnetzagentur, the Federal Network Agency known to many from its oversight of telecoms and energy networks, acts as the central authority for the AI Act; the Wettbewerbszentrale, a self-regulatory body of German industry for fair competition, has been taking complaints about missing AI labeling since the end of July 2026. Competitors can also issue a warning letter over missing labeling, meaning they demand an out-of-court cease-and-desist and reimbursement of costs. For purely online labeling breaches, reimbursement of those costs to competitors is excluded (Section 13(4) UWG, the German Unfair Competition Act), to the extent AI labeling falls under it.

    Three approaches compared: what holds up when it counts?

    Visible label onlyAI tool's marking onlymintys by on:mint
    Visible disclosure, your duty as a deployer (Article 50(4) AI Act)MetMissingMet
    Machine-readable marking in the file (Article 50(2) AI Act, per C2PA)MissingMetBy the provider, as long as the metadata survives.Met
    Labeling survives upload, screenshot and editingPartlyThe label can be cropped out or removed.MissingMetadata is usually lost in the process.MetInvisible watermark in the pixels.
    Evidence of when and by whom labeling happenedMissingPartlyOnly while the metadata is intact.Met
    Approach documented along the EU Code of PracticeMissingMissingMet
    Risk of warning letters and finesRemainsAs soon as the label is removed and no evidence exists.HighYour disclosure duty stays unmet.MinimisedDuty met and documented.

    That leaves the evidence. If it comes to a dispute, what counts is what you can prove: that an image carried a label, even after it was shared or re-uploaded. That is what we built mintys for, the AI labeling solution by on:mint. mintys places the visible label directly on your image: in your corporate design if you want, and at the right size for every visual. When the format changes, from portrait to landscape for instance, the label stays consistently in its place.

    mintys also writes that same label into the image's metadata in machine-readable form, following C2PA, an open standard for provenance information stored directly in the file. An invisible watermark backs up both. It sits in the pixels themselves rather than in the metadata, and therefore survives cropping, compression and re-uploading. So if someone removes the visible label or a platform strips the metadata, it remains provable when and by whom this image was labeled. The result is a digital passport for your image, secured against unnoticed changes and documenting that the labeling was applied.

    There is a commitment behind the tool: on:mint has signed the Code of Practice on Transparency of AI-Generated Content, the code of conduct developed at EU level for implementing these transparency obligations. According to the Commission's guidelines, following such a code is a simple and predictable way to demonstrate compliance. Those who do without it have to expect supervisory authorities to request more information. With mintys you label along the practices of that code. mintys also supports you in judging whether an image needs a label at all. So you label only what has to be labeled.

    Only the combination of visible label, machine-readable marking and invisible watermark meets your disclosure duty under the AI Act in a way that survives upload and editing and can be proven in a dispute. That is exactly what mintys does. Visible labeling under Article 50 AI Act, evidence included.

    Rather check first what applies to you?

    To the self-test

    No. The machine-readable marking is the tool vendor's duty. Your visible disclosure as a deployer stands alongside it. So review your publishing process instead of relying on the tool.

    No. The duty sits with you as the deployer and cannot be outsourced to platforms. Platforms that merely distribute third-party content are not deployers under the Commission's guidelines. Their labels are voluntary and only kick in when the platform detects AI signals in the file or users declare the use themselves. Meta's "AI info" notice, for example, stays absent when metadata was lost during editing. You are still the responsible party. So check and label every image and every video yourself before you publish it.

    Text has a rule of its own: disclosure is required from whoever publishes AI-generated text in order to inform the public on matters of public interest. The duty falls away when a person has reviewed the text or exercised editorial control and a person or company bears editorial responsibility. That exemption applies to text only, not to images.

    No. Images generated or altered before 2 August 2026 do not have to be labeled retroactively. For images, what matters is the point of generation or editing. The European Commission does recommend labeling such back catalogues where the effort stays proportionate.

    The central supervisory authority for the AI Act in Germany is the Bundesnetzagentur, the Federal Network Agency. Alongside it, the Wettbewerbszentrale takes complaints about missing AI labeling.

    Yes. A deployer is any natural or legal person using an AI system professionally under their own authority. Only purely private use is exempt.

    With documentation that ties the visible label firmly to the file. That is exactly what is usually missing: the visible label and the metadata are two separate layers, and nobody records whether a label was applied. mintys closes that gap. It writes the labeling into the file's C2PA metadata, for entire image and video series at once as well, and secures that documentation against unnoticed changes. So everything sits in one place: the image, the label, the file information and the timestamp. If a request from a supervisory authority or a warning letter arrives, you present the evidence in a few clicks.