[ Provenance and law · Guide ]

What are you legally required to do when you publish AI-generated content?

Short answer

There is no single global rule, but the three regimes that matter converge on the same two mechanics: a machine-readable mark embedded in the file, and a human-visible disclosure where a person could be misled. The EU AI Act's Article 50 transparency obligations apply from 2 August 2026 and cover synthetic audio, image, video and text plus a specific deepfake disclosure duty. China's labelling Measures, in force since 1 September 2025, have required both explicit visible labels and implicit metadata labels for longer and in more prescriptive detail. The United States has no comprehensive federal statute; California's AI Transparency Act, operative 2 August 2026, imposes detection-tool, visible-disclosure and latent-provenance duties on large generative-AI providers, and the FTC polices deceptive practice under existing authority. For a publisher shipping worldwide, the workable policy is to mark everything and disclose wherever a reasonable viewer might be deceived.

Published 19 August 2026 · Lifewood Data Technology · 3,012 words · 8 sources

Key points

  • EU AI Act Article 50 applies from 2 August 2026. Providers must mark synthetic audio, image, video and text in a machine-readable, detectable format; deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest.
  • The Commission has signalled a transition for the marking duty for generative systems already on the market before that date, and an AI Office code of practice on marking and labelling as a compliance route.
  • China moved first and is more prescriptive. The CAC Measures and mandatory national standard GB 45438-2025 took effect 1 September 2025, requiring both explicit labels visible to users and implicit labels written into file metadata.
  • The US has no comprehensive federal labelling law. California's SB 942, as amended by AB 853, becomes operative 2 August 2026 for covered providers above one million monthly users, with hosting-platform duties following on 1 January 2027.
  • The obligations split into provider duties (mark at generation) and deployer duties (disclose at publication). A brand publishing content made with someone else's model is usually a deployer, and cannot assume the provider's marking discharges its own disclosure duty.
  • Because obligations attach to the file and the file travels, per-market labelling policies are more expensive and more fragile than one global policy. Mark everything at the point of export.

Disclosure. Published by Lifewood Data Technology, which produces AI-generated content commercially and therefore operates under these rules itself. This guide is a practitioner's summary, written from the primary instruments and reputable legal commentary, and it is not legal advice. Obligations turn on facts specific to each deployment; confirm your position with counsel before relying on it.

The shape all three regimes share

Read side by side, the EU, Chinese and Californian instruments are less different than their drafting suggests. Each separates a technical duty from a communicative one. The technical duty is to embed something in the file that a machine can read — metadata, a watermark, a cryptographic manifest — so that the artificial origin travels with the content. The communicative duty is to tell a human being, in a form they will actually notice, when they are looking at something synthetic that they might otherwise take as real.

The second structural feature they share is a split of responsibility along the supply chain. The party that builds and operates the generative system carries the marking duty. The party that publishes the output carries the disclosure duty. Most brands are in the second category, which is the source of the most common compliance error in this area: assuming that because a model vendor watermarks its outputs, the publisher has nothing to do.

The three regimes at a glance
RegimeIn forceCore duties
EU AI Act, Article 502 August 2026Providers: machine-readable marking of synthetic audio, image, video, text. Deployers: disclose deepfakes at first exposure; disclose AI-generated text published to inform the public on matters of public interest. Chatbots must reveal they are machines
China — CAC Labelling Measures + GB 45438-20251 September 2025Explicit labels — visible text, audio or graphic markers telling users the content is AI-generated. Implicit labels — technical markers written into file metadata. Duties fall on information service providers and content distribution platforms
California AI Transparency Act (SB 942, amended by AB 853)2 August 2026 (hosting platforms from 1 January 2027)Covered providers above one million monthly users: free public AI-detection tool, optional visible disclosure for users, and latent machine-readable provenance in generated image, video and audio. Later phases add duties for large online platforms and capture-device makers

Dates and thresholds here are the operative headlines, not the full scope of any instrument. Each contains exemptions, definitions and carve-outs that decide real cases — the assistive-editing exemption in Article 50 and the covered-provider threshold in SB 942 both do a great deal of work.

The EU: Article 50, and what a deepfake means in it

Article 50 of the AI Act sets transparency obligations for particular categories of system rather than for AI generally. Four duties matter to a content producer. Systems that interact directly with people must make clear that the person is dealing with an AI system. Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Deployers who generate or manipulate deepfake content must disclose that the content is artificially generated or manipulated. And deployers publishing AI-generated text to inform the public on matters of public interest must disclose that too, unless the content underwent human review with editorial responsibility retained by a person or organization.

The definition of deepfake is broader than the popular usage. It covers AI-generated or manipulated image, audio or video content resembling existing persons, objects, places, entities or events, which would falsely appear to a person to be authentic or truthful. That reaches a synthetic voice of a real spokesperson, an AI-generated shot of a real building, and a manipulated recording of a real event — not only face-swapped video of a public figure. The disclosure has to reach the viewer at first exposure at the latest, in a clear and distinguishable manner.

Timing has two components worth separating. The obligations themselves apply from 2 August 2026. The European Commission has indicated a grace period for the marking obligation in respect of generative systems placed on the market before that date, and the AI Office has been finalising a code of practice on the marking and labelling of AI-generated content, adherence to which is intended to offer a route to demonstrating compliance with the relevant paragraphs of Article 50.

China: explicit and implicit labels, and a mandatory standard behind them

China's regime is older and more specific. In March 2025 the Cyberspace Administration of China, with the Ministry of Industry and Information Technology, the Ministry of Public Security and the National Radio and Television Administration, released the Measures for Labeling AI-Generated Synthetic Content together with the mandatory national standard GB 45438-2025. Both took effect on 1 September 2025.

The Measures require two kinds of label. Explicit labels are perceivable by users — text, audio cues or graphics that tell a person the content is AI-generated, for example an "AI-generated" marker at the start or end of a piece of text or a corner label on an image. Implicit labels are technical markers added to the file's metadata, not readily perceivable by users, which record the synthetic origin and the provider. The obligations run to internet information service providers and to platforms distributing online content, which means a distribution platform has its own detection and labelling responsibilities rather than merely relying on the uploader.

For a company producing content for Chinese platforms, the operational consequence is that labelling cannot be a publishing afterthought handled by the social team. The implicit label has to be written when the file is produced, survives handoff, and is what a platform's automated check looks for. Legal commentary comparing the Chinese and EU approaches consistently notes this prescriptiveness as the main difference: the EU states an outcome, China specifies the mechanism.

The United States: no federal statute, a state patchwork, and the FTC

There is no comprehensive federal AI content labelling law in the United States as of mid-2026. What exists is three overlapping sources of obligation, and treating any one of them as the whole picture is a mistake.

  • State legislation. California's AI Transparency Act (SB 942), as amended by AB 853, is the most consequential for content producers. It becomes operative on 2 August 2026. Covered providers — generative AI systems with more than one million monthly visitors or users that are publicly accessible in California — must offer a free, public AI-detection tool for their own outputs, offer users the option of a visible disclosure, and embed latent, machine-readable provenance data in generated image, video and audio. AB 853 extends the framework in later phases to large online platforms, which from 1 January 2027 must surface provenance data and must not knowingly strip it, and eventually to capture-device manufacturers.
  • Sector and conduct rules. The Federal Trade Commission has long-standing authority over unfair or deceptive acts or practices, which reaches undisclosed synthetic endorsements, fabricated testimonials and AI-generated claims that mislead consumers, without any AI-specific statute being needed.
  • Right of publicity and performer agreements. Using a real person's voice or likeness is governed by state right-of-publicity law and, in unionized production, by collective agreements. These are covered in the companion guide on rights and consent.

The practical reading for a US publisher is that the compliance question is rarely "is there a labelling law here" and usually "would a reasonable consumer be misled if we did not say this". That standard is older than generative AI, it is enforced, and it does not wait for a labelling statute.

A publishing policy that satisfies all three

The cheapest defensible position for an organization publishing across markets is a single global policy that meets the strictest applicable requirement, rather than per-market variants of the same asset. These steps produce that policy.

Building a labelling policy for AI-generated content

  1. Classify every asset by how synthetic it is

    Three buckets: AI-assisted editing of real material (colour, noise, upscaling), AI-generated material that does not depict real people or events, and AI-generated or manipulated material that resembles real persons, places or events. Only the third is a deepfake in the Article 50 sense, and it carries the heaviest disclosure duty.

  2. Mark at export, not at publication

    Write machine-readable provenance into the file at the point it leaves production — C2PA manifest where supported, plus whatever watermark the generating model applies. Marking at publication means every downstream distribution path has to be trusted to do it, and one of them will not.

  3. Decide the visible disclosure by audience risk, then apply it globally

    If any market requires a visible label for that asset class, apply it everywhere rather than maintaining a labelled and an unlabelled cut. Two versions of the same file is how the unlabelled one ends up in the wrong market.

  4. Write the deepfake rule down and make it a hard gate

    Any asset depicting a recognizable real person, place or event that was generated or materially manipulated requires disclosure at first exposure and documented consent from any real person depicted. Make this a production gate, not a review comment.

  5. Preserve provenance through the pipeline

    Audit each step — editing, transcoding, platform upload — for whether it strips metadata. Most do. Where it cannot be preserved, record the chain of custody yourself so the claim can still be substantiated.

  6. Keep the record, per asset

    Which model produced it, when, under which licence, what human review it received, what labels were applied, and where it was published. This is what answers a regulator, and it is also what answers a client asking whether they can reuse an asset in a market you did not originally clear.

What this actually changes in production

For most content operations the answer is: less than the volume of commentary suggests, provided the work is done at the right stage. Marking is a one-time pipeline change at export. Visible disclosure is a design decision made once per asset class. Consent for depicted real people is a paperwork discipline that responsible productions already had. The expensive version of compliance is the retrofit — discovering after publication that ten thousand localized variants need a label, or that nobody recorded which of them used a synthetic voice.

The genuinely awkward area is content produced before a policy existed. Back-marking is often impossible because the generation context is gone, and the honest options are to re-export from source where the source survives, to add visible disclosure without a machine-readable mark where it does not, or to retire the asset. Deciding that policy deliberately, and recording the decision, is a materially better position than discovering the gap during an audit.

Lifewood Data Technology operates under these rules as a producer and applies marking and disclosure metadata at the delivery stage of every AIGC programme, because delivery is the last point at which one process touches every language variant. For how the underlying provenance technology works and where it fails, see the companion guide on C2PA and watermarking.

Related questions

Do we have to label AI-generated content everywhere, or only in regulated markets?

Legally, only where an applicable rule bites. Practically, a single global policy is cheaper and safer than per-market variants, because files travel and the labelled and unlabelled versions of the same asset are indistinguishable at a glance. Most publishers operating in the EU or China conclude that marking everything and disclosing by asset class is less work than maintaining exceptions.

Does using AI to edit real footage trigger the EU marking obligation?

Article 50 provides that the marking duty does not apply where the AI system performs an assistive function for standard editing and does not substantially alter the input data or its semantics. Routine colour correction, denoising and upscaling sit inside that carve-out. Replacing a background, altering what a person appears to say, or generating imagery that was never captured do not.

Who is responsible — the model vendor or the company publishing the content?

Both, for different things. The provider of the generative system carries the marking obligation; the deployer publishing the output carries the disclosure obligation. A brand using a third-party model is normally a deployer and must make its own disclosure decisions. Vendor watermarking does not discharge the publisher's duty.

What counts as a deepfake under the EU AI Act?

AI-generated or manipulated image, audio or video content resembling existing persons, objects, places, entities or events, which would falsely appear to a person to be authentic or truthful. It is broader than face-swapped video of a public figure — a synthetic voice of a real spokesperson and an AI-generated depiction of a real location both fall inside the definition.

Is there a US federal law requiring AI content labels?

Not a comprehensive one as of mid-2026. The operative sources are state legislation — most significantly California's AI Transparency Act, operative 2 August 2026 — sector-specific rules, and the FTC's general authority over deceptive practices, which reaches undisclosed synthetic endorsements and misleading AI-generated claims without any AI-specific statute.

What happens if a platform strips our provenance metadata?

Most re-encoding pipelines do strip it, which is the central practical weakness of metadata-based provenance. Mitigations are to combine metadata with a watermark that survives re-encoding, to apply a visible disclosure that is part of the picture rather than the file, and to keep your own records so the claim is substantiable independently. California's AB 853 additionally introduces duties on large online platforms not to knowingly strip compliant provenance data, from 1 January 2027.

Sources

Every figure, date and legal requirement above traces to one of these. Where a source is a market-research summary, a vendor pricing page or a preprint rather than a primary document, the text says so at the point of use.

  1. Article 50 — Transparency Obligations for Providers and Deployers of Certain AI Systems EU Artificial Intelligence Act (consolidated text)
  2. Transparency obligations under Article 50 of the AI Act — FAQ European Commission, Shaping Europe's digital future
  3. Quick Facts: Transparency rules for AI systems European Commission, Shaping Europe's digital future
  4. Measures for Labeling of AI-Generated Synthetic Content (English translation) China Law Translate · March 2025
  5. China's AI-Labeling Measures and Mandatory National Standards Take Effect September 1 Loeb & Loeb LLP · March 2025
  6. New AI Content Labelling Rules in China — and how they compare to the EU AI Act Bird & Bird · 2025
  7. SB 942 — California AI Transparency Act (bill text and history) California Legislative Information · 2024
  8. AB 853 — California AI Transparency Act amendments CalMatters Digital Democracy · 2025

Talk to the Lifewood AIGC team

Lifewood delivers AIGC programmes with provenance metadata and disclosure applied at export, across every language variant in the batch. If you are retrofitting a policy onto an existing library, the useful first step is an inventory of which assets can still be re-exported from source — that determines what is fixable and what has to be retired.