What Does the EU AI Labelling Obligation Mean for Companies?
The AI labelling obligation in Article 50 of the EU AI Act (Regulation (EU) 2024/1689) has applied since 2 August 2026 — and because you can only label what you can see, compliance starts with visibility: that is what an official, GDPR-compliant AI channel like amaiko running inside Microsoft Teams gives you. Chatbots have to identify themselves as AI, and AI-generated content has to carry a machine-readable marking — but who owes which duty depends on your role: providers mark their own outputs, deployers disclose deepfakes and certain AI texts.
What you get out of this article:
- Since 2 August 2026, chatbots have had to identify themselves as AI — with no transition period.
- The 2 December 2026 deadline covers only machine-readable marking for systems that were already on the market.
- Germany’s Federal Network Agency (Bundesnetzagentur) is the authority — complaints office included, and anyone can report a breach.
- Fines run up to €15 million or 3 % of worldwide annual turnover; for SMEs the lower figure applies.
- 78 % of people using AI at work bring their own tools — this shadow AI appears in no inventory, which makes it the biggest labelling risk you have.
Which AI Content Do Companies Have to Label Since August 2026?
Article 50 bundles four transparency duties. Who each one hits — and by when:
| Duty (Art. 50) | Who it applies to | Deadline | What to do |
|---|---|---|---|
| Disclose chatbots as AI (para. 1) | Providers of interactive AI systems | since 2 Aug 2026 | Notice at the first interaction, at the latest |
| Mark synthetic content machine-readably (para. 2) | Providers of generative AI | since 2 Aug 2026; existing systems by 2 Dec 2026 | Watermark or metadata, e.g. C2PA |
| Disclose deepfakes (para. 4) | Deployers | since 2 Aug 2026 | Visible labelling |
| AI text on matters of public interest (para. 4) | Deployers | since 2 Aug 2026 | Label — unless there is editorial control |
What matters in practice: not every AI-drafted email has to be labelled. A text that a human reviews and takes responsibility for falls outside the duty — editorial control is the most important exemption for everyday business. Images, audio and video get no such exemption: they have to be machine-readably identifiable as AI-generated.
Does the Transition Period Until December 2026 Apply to Every AI System?
No — and plenty of summaries miss the detail. The transition period in Art. 111(4) covers only the machine-readable marking under para. 2, and only for systems placed on the market before 2 August 2026. Chatbot disclosure and every deployer duty have applied since 2 August with no transition period at all.
The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) changes nothing here either. What it postponed were the high-risk obligations — Annex III to December 2027, Annex I to August 2028. Article 50 was left untouched. If you were counting on a reprieve, plan against the real dates instead.
Who Enforces the Labelling Obligation in Germany?
Since the KI-MIG — Germany’s AI Act implementation and market surveillance law — took effect on 29 July 2026, the Bundesnetzagentur is the market surveillance authority, single point of contact and complaints office for the EU AI Act, with a free AI service desk for companies.
That word “complaints office” deserves a second look: it is not only authorities that can report a breach, but competitors, customers or former employees. Fines run up to €15 million or 3 percent of worldwide annual turnover; for small and medium-sized companies, whichever figure is lower applies. So the risk is not theoretical — it has an address and a form.
How Do You Mark AI-Generated Content in Machine-Readable Form?
The state of the art is signed provenance metadata following the C2PA standard, backed up by watermarking. The major model providers already embed these manifests at generation time — the problem starts afterwards: screenshot an image, re-compress it, or push it through a tool that drops metadata, and you have destroyed exactly that embedded marking again.
That marking is what amaiko preserves end to end: the pipeline never re-encodes an image, so it never strips the C2PA manifest the provider embedded, and it checks for that manifest before the image is even stored — without your team lifting a finger. With images from private AI accounts, nobody can tell you whether the marking survived the trip into marketing.
What an official AI channel costs — and what it saves you against a sprawl of private tools — takes two minutes with the ROI calculator.
Why Is Shadow AI the Real Compliance Risk?
You can only label AI you know about. That is precisely where it breaks down: 78 % of people using AI at work bring their own tools, and 4.2 % of employees have already pasted company data into ChatGPT. None of that usage appears in an AI inventory or surfaces in a compliance review — and it still produces content that gets published in your company’s name.
A ban does not fix this, it just pushes the usage further into the dark — our analysis of shadow AI in companies explains why. And the more uncoordinated tools pile up, the more expensive AI agent sprawl gets, well beyond compliance.
The better answer is an official channel more attractive than the private account: amaiko runs directly in Microsoft Teams — no separate app, no new interface, no training effort — and it is GDPR-compliant with EU data residency. More than 200 people work with it every day — visible, governable, labellable. That turns the obligation into an inventory, and the inventory into a productivity gain.
Frequently Asked Questions (FAQ)
What does the EU AI labelling obligation mean for companies?
Since 2 August 2026, Article 50 of the EU AI Act has required transparency about the use of AI. The duties are split by role: providers have to disclose chatbots and mark their outputs in machine-readable form, while deployers have to label deepfakes and AI text on matters of public interest. Breaches are enforced by the Bundesnetzagentur.
By when do existing AI systems have to be labelled?
Systems that were on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking under Art. 50(2). Every other duty — chatbot disclosure above all — has applied since 2 August 2026 with no transition period.
How high are the fines for breaching the labelling obligation?
Up to €15 million or 3 percent of worldwide annual turnover. For small and medium-sized companies, Art. 99(6) of the EU AI Act applies whichever of the two figures is lower.
Do we have to label content when employees use private AI accounts?
The deployer duties — disclosing deepfakes and AI text on matters of public interest — land on your company regardless of which account the content came out of. The real problem: shadow AI appears in no inventory, so nobody knows which content is AI-generated in the first place. An official AI channel like amaiko makes the usage visible and governable.
Does every AI-generated text have to be labelled?
No. The labelling duty for text only bites on matters of public interest — and it falls away when a human reviews the text editorially and takes responsibility for it. Internal documents and reviewed business texts are generally out of scope.
How does amaiko help with the AI labelling obligation?
amaiko gives you an official, visible AI channel that lets you see where AI is used in your company — and assess it against the labelling obligation: GDPR-compliant with EU data residency, directly in Microsoft Teams. When the model provider delivers AI images with a signed C2PA provenance marking, amaiko preserves it end to end — nothing in the pipeline strips it, and the image is checked for the manifest before it is even stored.
What does a GDPR-compliant AI assistant cost a company?
amaiko costs €29.91 per user/month, billed annually. For that your team gets an assistant with persistent corporate memory and a growing marketplace of specialists — directly in Microsoft Teams, with no separate app. What that means for your team size is what the ROI calculator works out for you.
Continue Reading
What Is AI Agent Sprawl — and How Do You Control It?
AI agent sprawl is the ungoverned spread of AI agents across a company. Here's what causes it, why it's a security risk, and how to govern it with one layer.
microsoft-copilotIs Microsoft Copilot GDPR-Compliant in 2026?
Copilot is not GDPR-compliant out of the box in 2026 — Flex Routing, CLOUD Act and FISA 702 remain risks. amaiko is the German-hosted alternative from day one.
shadow-aiShadow AI Is Already in Your Company — You Just Don't Know It Yet
78% of employees using AI at work bring their own tools. That's not an adoption win — it's a compliance crisis hiding in plain sight.