AI Content 10 min read

EU AI Act content disclosure rules: what changed on Sunday

EU AI Act content disclosure rules took effect 2 August 2026. Here's what the rule requires, who it actually falls on, and what exempts a reviewed draft.

A printed page resting on a desk with a visible label line, soft morning daylight, calm and unhurried

EU AI Act content disclosure rules took effect on Sunday, 2 August 2026. I run VibeMyWay alone, I publish on the same platforms this rule governs, and I use AI to draft a lot of what I publish. So over the past few days I read Article 50 itself, the Commission's own guidance on it, and the parts of the Digital Omnibus that actually touch this date, instead of the compliance posts about it.

Here's the short version. The obligation lands on whoever hits publish, not on the tool that helped draft the post. There's a real exemption for text that's genuinely reviewed before it ships, and there's a hard line that exemption doesn't cross. Both matter more than the date itself.

This isn't legal advice, and I'm not claiming VibeMyWay makes anyone compliant. It's a plain reading of what the rule says, what it doesn't say, and what I changed in my own publishing process because of it.


What the EU AI Act content disclosure rules actually cover

Article 50 of the EU AI Act is the provision that governs this, and Sunday's the day the Commission's AI Office and national market surveillance authorities gained direct power to enforce it. More than 180 organisations had already signed the Commission's voluntary Code of Practice ahead of that date. This isn't a soft rollout waiting for someone to notice it.

Here's the part that gets flattened into "AI content needs a label" and loses precision on the way. Article 50(4)'s text-disclosure duty only reaches AI-generated or manipulated text published to inform the public on matters of public interest. It's not a blanket rule covering every sentence a business publishes with AI help. That's the scope.

Who the EU AI Act content disclosure rules fall on

The duty sits with the deployer, the person or organisation that publishes the content, not the provider that built the AI system used to draft it. A generative tool can't carry legal responsibility for what gets published with it. The publisher can, and does.

That's also where the exemption lives. Text that's undergone genuine human review, with a named person holding editorial responsibility for it, falls outside the disclosure duty. Not because a tool is "compliant." Because someone read the draft, took responsibility for it, and decided it was fit to publish. That's the actual mechanism, not a phrase layered on top of it.

What "reviewed" actually has to mean

Commission guidance sets a real bar here, not a formality. A spell-check or a quick skim-and-approve doesn't qualify. Genuine review means fact-checking, verifying names and dates, and amending anything that's wrong, plus a named, contactable person who actually holds editorial authority over what gets published. That person's identity has to be publicly findable, not just logged somewhere internal. An audit trail nobody outside the company can see doesn't meet the standard.

Which is also where autopilot posting runs into a wall it can't design around. If nobody reads a post before it publishes, there's no reviewer, no editorial responsibility, and no exemption to claim. I've written before about what posting on autopilot does to brand voice once speed takes over: Marketing on autopilot posts off-brand. That's the problem.. The same design choice now doubles as a legal exposure point, not just a voice one.

A laptop showing a document mid-review, cursor resting in the margin, soft morning light

The line I won't blur

Two things get conflated constantly, and getting either one wrong turns a plain reading into a false claim.

First: the human-review exemption is text-only. Image, audio, and video deepfakes carry no equivalent exemption. Reviewed or not, they still need disclosure.

Second: the 7 May 2026 Digital Omnibus agreement postponed the AI Act's high-risk obligations. Annex III systems move to December 2027, Annex I systems to August 2028. It left Articles 50 through 55 alone. The one real date change inside Article 50 itself is narrower still, a four-month extension to 2 December 2026 on the provider-side watermarking duty for generative systems already on the market. That's not the deployer's disclosure duty. That one didn't move.

Why this lands on the feed you're already scrolling

An independent scan of just over a million posts across LinkedIn, X, Reddit, Substack, and Medium flagged more than 40% of longform LinkedIn posts as fully AI-generated, and nearly two-thirds of everything the scan flagged came from LinkedIn alone, despite the platform making up only about a third of what was scanned. That's the backdrop this rule lands on. Not an abstract regulatory topic. The feed you've been scrolling all week, past what feels like the sixth panic post about this exact date. I've made the same argument before, that unreviewed AI content was already a trust problem before any regulation touched it: How to avoid AI slop.

Meanwhile, enterprise compliance vendors have already started pricing certainty on rules with real interpretive gaps still in them. One builder's account describes a related AI Act provision drawing quotes of $30,000 to $100,000 for a single SMB audit. That's a different provision than the one this article covers, but it's the same market instinct: sell confidence a law's own guidance doesn't fully offer yet.

A calendar page showing a single date at rest on a desk, muted blue and slate palette

What labelling can't do, and what I'm not claiming

A University of Bayreuth and Aalto University study found that a week after exposure, people correctly identified whether content came from AI only 37.7% of the time, once the AI-generated material had been reworded by a human. Disclosure requirements assume a label changes how a reader evaluates content. The research says that effect fades fast, worth naming honestly rather than treating a label as a fix for reader trust.

The Code of Practice itself is voluntary, and independent policy analysis has already flagged real ambiguity in it, including where ordinary edited content stops and a "deepfake" starts. Even people close to enforcement expect friction rather than a clean rollout. Ashley Casovan of the IAPP, reacting to the rule taking effect, said implementation would be difficult: "But I think we often hear this with compliance requirements. And yet, the world turns and we figure these things out".

So here's what I'm not claiming. VibeMyWay doesn't make anyone compliant. It isn't certified, and I'm not a lawyer. What it does is produce a package you read before it ships, with your name on the decision to publish it, which happens to be the same posture Article 50(4)'s exemption describes. That's not a marketing angle. It's what I changed in my own process once I read the text.


Sources

Frequently asked questions

Was the EU AI Act delayed?

Partly, and precisely. The Digital Omnibus agreement from May 2026 postponed the AI Act's high-risk obligations under Annex III to December 2027 and Annex I to August 2028. Articles 50 through 55, the transparency and disclosure rules, weren't touched and took effect on schedule. The one real change inside Article 50 is a four-month extension on the provider-side watermarking duty for systems already on the market, to 2 December 2026. The deployer disclosure duty this article covers wasn't part of that extension.

Does reviewing AI-generated content before publishing exempt me from disclosure?

For text published to inform the public on matters of public interest, yes, when the review is genuine and a named person holds editorial responsibility for the piece. It doesn't work as a rubber stamp. Commission guidance excludes a spell-check or a quick approval. And it doesn't extend to image, audio, or video. Deepfakes require disclosure regardless of review.

Does this apply to my small business?

Being small doesn't exempt a business from the duty itself, once the duty applies. What's genuinely unsettled, per independent re-verification of Article 50(4)'s own text and its recitals, is whether the broader "any business activity" framing you'll see referenced online has any textual basis beyond the actual test the law sets: whether the content informs the public on a matter of public interest [S13]. I'm treating that broader framing as an open question, not a settled yes.

Does the disclosure rule apply to social media posts specifically?

That's genuinely unsettled at the primary-source level, and I'd rather say so than guess. Article 50(4)'s own text and its accompanying recitals don't define "informing the public on matters of public interest," and neither addresses social platforms or routine business content as a category [S13]. The duty turns on the purpose of what's published, not the platform it's published on, but the law itself doesn't draw a bright line for where an ordinary social post falls. I'm not asserting either answer here until there's clearer guidance or precedent.


The bottom line

The rule that took effect this week doesn't reward panic, and it doesn't reward whoever sells the most certainty about it either. It rewards the workflow I was already running: read the draft, decide who's responsible for it, say so plainly.

I'm not going to tell you this makes you compliant, because no article can, and no tool should claim to. What I can tell you is what changed in my own process. Every post gets read by me before it ships, and I know exactly who's accountable for it, because it's me.

If you want to see what a reviewed, brand-consistent content package actually looks like before it publishes, read how I built VibeMyWay's own workflow: Why I built VibeMyWay (and what broke first).