Disclosure Obligations for Generated Content
What the emerging transparency rules actually require, why machine-readable marking and human-visible disclosure are separate obligations, and the design decisions a deployer has to make.
Transparency requirements around synthetic content have moved from principle to law, and they impose obligations on two different parties for two different reasons. Reading them as one requirement is the most common source of a compliance gap.
The two obligations
The EU AI Act's transparency provisions, which apply from August 2026, separate them clearly.
Providers of generative systems must mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated. This is a technical obligation on whoever builds the system, and it is what watermarking and content credentials are for. The requirement is explicitly for interoperable, robust and reliable marking to the extent technically feasible, which acknowledges that the state of the art is imperfect.
Deployers have separate obligations. A system that interacts with people must disclose that they are interacting with an AI system, unless it is obvious. A deepfake, meaning image, audio or video content that appreciably resembles real people or events, must be disclosed as artificially generated when published. Text published to inform the public on matters of public interest must be disclosed unless it underwent human review with editorial responsibility.
Machine-readable marking serves platforms and downstream tooling. Human-visible disclosure serves the person looking at the content. Doing the first does not satisfy the second, and the exemptions differ.
Design decisions this forces
Where disclosure appears. A label in metadata is not disclosure to a viewer. A caption, an overlay, an interstitial or a persistent badge each have different visibility and different survival characteristics when content is shared or screenshotted.
When it is exempt. The "obvious" exemption and the editorial-responsibility exemption both require a judgement that should be recorded rather than assumed, since the exemption is what a regulator will ask about.
Assistive-use carve-outs. Rules generally distinguish content generated by a system from content a human authored with assistance, and where the boundary sits for a given workflow is a decision the deployer makes and should document.
Preservation across the pipeline. Marking applied at generation is stripped by re-encoding, cropping and screenshotting. Whether the obligation is satisfied at the point of generation or at the point of publication changes who has to preserve what, and a pipeline that discards credentials between the two leaves both parties exposed.
When it breaks
Disclosure fatigue is real. Labelling everything trains people to ignore labels, and a badge on content nobody doubts dilutes the badge on content that matters. This tension between comprehensive marking and effective communication is not resolved by the rules and is left to design.
Marking obligations outrun the technology. The requirement is for robust and reliable marking to the extent technically feasible, and for text, robust marking is not currently achievable against a paraphrase. Documenting what was done and why is what a good-faith position looks like when the technical state of the art does not meet the aspiration.
Jurisdictions diverge. Requirements differ by region and are still forming, so a global product faces several regimes at once. Building the strictest applicable behaviour once is usually cheaper than maintaining regional variants, and it is a decision better made early than after a launch.
Disclosure does not transfer trust. Labelling content as generated tells a viewer how it was made and nothing about whether it is accurate. Treating a disclosure requirement as discharging responsibility for the content's substance confuses provenance with quality, and the two obligations are separate.
10 flashcards for this concept
Click a card to reveal the answer.