The headlines this summer made it sound like a crisis: “sweeping new AI rules,” “massive fines,” “drastic measures.” The reality, as Smashing Magazine’s Vitaly Friedman reports, is considerably more targeted. Starting August 2, 2026, EU AI Act labeling requirements are live — and they apply to any company worldwide that serves EU citizens, not just European businesses. The same global-reach logic that made GDPR everyone’s problem makes this everyone’s problem too.

For brand managers and business owners, the question isn’t whether to care. It’s what, specifically, you need to do — and where the actual risk sits.

Faceted globe overlapping a document with a highlighted AI disclosure label badge

Four Categories Trigger Mandatory Disclosure — Most Brands Touch at Least One

As Friedman summarizes from the Act, Article 50(4) of the EU AI Act mandates disclosure for four categories:

Deepfakes. Any image, audio, or video that realistically depicts a real person, place, or event in a way that could be mistaken for authentic. Content that is obviously stylized or non-realistic generally falls outside this requirement.

Chatbots and AI agents. If users might reasonably believe they’re talking to a human, they must be told they aren’t. If your website runs a conversational AI assistant, it needs to identify itself.

Fully AI-written text on public interest topics. Health, safety, finance, politics, science, environment, culture — if your AI-generated copy touches these areas and no human has meaningfully reviewed it, it requires disclosure.

Emotion recognition and biometric categorization tools. Less common in standard brand contexts, but worth knowing if you run any kind of behavioral analysis on users.

The critical exemption: if a human has substantively reviewed and edited AI-generated content, and a named person or entity takes editorial responsibility for it, the disclosure obligation does not apply. As Friedman notes, “a human skimmed it before publishing” doesn’t qualify. The Commission is explicit that the review must be substantive — not a rubber stamp.

The “Edited” Exemption Has a Precise Definition

This is where most brands will have real questions. The line the EU draws is between intentional human intervention and automated generation.

Spellcheck, grammar correction, formatting, color correction, and AI translation? Not considered AI generation. AI-generated summaries, composite imagery, substantive rewrites, or photo manipulation that adds or removes elements? Considered AI generation, and disclosure applies.

In practical terms: if your marketing team uses AI to draft a product description and a copywriter rewrites it substantially before publishing under their name, you’re likely fine. If the AI writes the product description and someone approves it with minimal changes, you’re in disclosure territory — especially if that description touches health claims, environmental benefits, or financial outcomes.

For product photography, the rule is similarly concrete. AI-generated illustrations or photos that resemble real people, places, or objects need a label — even in advertising and commercial contexts. Some law firms are already recommending precautionary labeling for any realistic AI-generated commercial imagery, regardless of whether it strictly meets the threshold.

Smartphone screen showing ambiguous sparkle icon versus explicit AI label badge, connected by a directional arrow

A Sparkle Icon Is Probably Not Sufficient

Here’s where design decisions become compliance decisions. Many products currently signal AI involvement with a ✨ sparkle icon. The EU’s guidance suggests this probably isn’t enough.

The European Commission has published an official EU AI icon set — a specific “AI” mark, not a generic sparkle. The requirement is that the signal be “clear and distinguishable.” The sparkle is too ambiguous: it often means “AI-powered feature” rather than “this specific content was generated by AI.” Those are different things, and the law cares about the latter.

This matters for web and app design in a concrete way. If your interface uses sparkles to indicate AI-assisted features throughout, you may need a more explicit label specifically at the point where AI-generated content is surfaced to users. The Carbon Design System’s approach — inline labels, icon-only variants, and explainability panels depending on context — is a reasonable model for how to handle this at scale.

Over-Labeling Carries Its Own Risk

Compliance runs in both directions. While the EU rules address under-disclosure, there’s an equally serious problem on the other side: overclaiming AI involvement to seem cutting-edge when the capability doesn’t match the claim.

The Nielsen Norman Group’s AI glossary defines “AI washing” as making false, misleading, or exaggerated claims about whether a product uses AI or what it can do — and notes explicitly that it erodes user trust when capability doesn’t match the claim. Here’s the connection that matters: the same Article 50 framework that creates mandatory disclosure obligations for under-labeling creates a mirror risk for over-labeling. Slapping “AI-powered” on a rules-based filter or a basic recommendation engine isn’t just a reputational problem — it’s a potential misrepresentation to users in a regulatory environment that is actively scrutinizing AI claims. The trust-erosion NNGroup describes is now also a compliance argument.

The honest move is also the smart one. Label what’s actually AI-generated. Don’t label what isn’t. Don’t claim AI capabilities you don’t have.

Both Providers and Deployers Are on the Hook

One detail that catches companies off guard: the obligation applies to both the company that builds the AI system and the company that deploys it. If you license an AI chatbot from a third-party vendor and embed it in your website, you don’t inherit the vendor’s compliance — you have your own obligation. The same logic applies to AI-generated content tools, image generators, and any other AI capability you’re using in customer-facing contexts.

This is structurally similar to how GDPR works: the fact that a tool came from outside your organization doesn’t transfer your responsibility to that vendor. If your website or app is the surface where EU users encounter the AI output, you’re a deployer with obligations.

Five Steps That Cover Most Brand Exposure

The practical checklist is shorter than the panic implies:

Audit your AI touchpoints. Where does AI-generated content appear in customer-facing contexts? Chatbots, product descriptions, imagery, summaries, recommendations — map them.

Establish editorial accountability. For AI-assisted text, define what “substantive review” means in your workflow and who is named as responsible. Vague approval processes won’t satisfy the standard.

Replace sparkles with explicit labels where required. Use the EU’s published AI mark or a clear text label at the point of AI-generated content, not just as a global feature indicator.

Audit your vendor agreements. Understand what AI your third-party tools use and confirm who carries the disclosure obligation in your contracts.

Don’t overclaim. If your “AI” feature is a rules-based filter or a basic recommendation engine, call it what it is. The trust cost of AI washing compounds over time.

For brands that communicate through their website — which is most brands — these questions land squarely in how your site is designed and what it says. If you’re rethinking how AI features are presented or need to update interface copy to meet disclosure standards, that’s a web design and development problem as much as a legal one.

Two angular faceted figures flanking a shield with a checkmark, representing brand transparency and consumer trust

Regulators Are Consistently Moving in One Direction

Meta’s $16.7 billion settlement with 47 U.S. states — reached after allegations that the company deliberately designed addictive features while obscuring them from users — is a data point in the same direction as EU AI labeling rules, even though the legal mechanisms differ. Fast Company describes the settlement as a bellwether moment for how regulators are using design requirements to put power back in users’ hands.

The pattern is consistent across jurisdictions: more disclosure, more user control, more accountability for how digital products work. Brands that treat transparency as a genuine practice — not a legal checkbox — will be better positioned as these rules spread. The companies that will struggle are treating compliance as something to minimize. The ones that will benefit are recognizing that honest communication about what AI does and doesn’t do in their products is something customers notice, remember, and reward — and building their workflows accordingly now.