If you publish with AI-generated images, the rule that takes effect on August 2 probably asks less of you than the coverage suggests.

Your diagrams aren't covered. Your abstract header art isn't covered. The machine-readable watermark everyone is worried about belongs to the company that built the tool, not to you. What does land on you is narrow, and I'll show you where the line sits in the statute text.

I went to the text because most of what I read pointed the obligation at the wrong person. One article told bloggers to "make sure your AI images are watermarked." That instruction is aimed at OpenAI and Google, not at anyone reading it.

Two other things happened this week that make the timing worth paying attention to, and I'll get to both. The more useful one is that Google shipped a feature carrying exactly the watermark the EU is about to require, and pulled it in 24 hours anyway.

First: Article 50 was not delayed

The Digital Omnibus package pushed back various high-risk obligations, and that compressed in coverage into "the AI Act is postponed." It wasn't. The transparency duties arrive on schedule. That means chatbot disclosure, marking of AI-generated content, and deepfake labeling.

What most coverage flattens is that Article 50 contains two different obligations pointed at two different people.

The watermark isn't your obligation

"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."

The subject is providers. OpenAI, Google, Midjourney, the people who build the tool. Recital 133 reinforces it, requiring providers to embed technical solutions.

If you generate an image with a tool that doesn't watermark its output, that is the tool's compliance gap. You are not expected to reverse-engineer a marker into someone else's file.

There's a transition detail worth knowing: systems already on the market before August 2 get until December 2, 2026 for the machine-readable marking requirement specifically. The official journal citation for that extension is one I never chased down, so treat the date as reported rather than confirmed.

Article 50 split into its two obligations. Left: 50(2), machine-readable marking, subject of the sentence is Providers — whoever built the tool, OpenAI, Google, Midjourney — marked "Not your obligation." Right: 50(4), visible disclosure, subject is Deployers — whoever publishes it, including individuals — marked "This one can be yours."

What might be yours

"Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated."

Deployer is defined in Article 3(4) as "a natural or legal person… using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity."

Natural person. Individuals are in scope by default. The exit is Article 2(10):

"This Regulation does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity."

So the question for anyone publishing is whether what they do counts as "purely personal non-professional," and here the statute doesn't give an answer. The text sets no revenue threshold and no follower count, and nothing in it says that running ads makes you professional.

The Commission adopted guidelines on these obligations on July 20, 2026. Several law firm summaries report that the guidelines read the personal-use exemption narrowly, citing an example where an individual posting a deepfake of a local mayor for political criticism couldn't hide behind it. That direction matches how the exemption is worded. But I never opened the guidelines myself. The official page wouldn't load for me. So I'm passing on what secondary sources say the primary source says, and labeling it as such.

What the text supports on its own: publishing to the public, on matters that shape public discussion, is not the fact pattern "purely personal" was written to protect.

What actually counts as a deepfake

This is where most of the anxiety is misplaced. Article 3(60):

"AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful"

Two conditions, both required. It has to resemble something real, and it has to plausibly pass as authentic.

An abstract header illustration doesn't meet either condition. Neither does a diagram, or a stylized drawing that nobody would take for a photograph.

A photorealistic image of a real place, or of a person who reads as a real person, is a different matter. The guidance reportedly treats photorealistic portraits of people who don't actually exist as still inside the definition, because such a person could exist and viewers can't tell the difference. That's the whole point of the "falsely appear to be authentic" test.

The two-condition test from Article 3(60) applied to five image types. Abstract header art, diagrams, and stylized illustrations fail both conditions and need no label. A photorealistic portrait of a person who doesn't exist, and a photorealistic image of a real place, satisfy both and require a label.

Text is a much narrower rule

The second sentence of 50(4) covers text, and it asks for far less than the image rule:

"Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply… where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."

Read the structure carefully, because it's easy to misread. The obligation only attaches to text about matters of public interest. And even then, human editorial review with someone holding editorial responsibility removes it.

If you edited the draft and published it under your own name, you exercised editorial control and you hold editorial responsibility. The exemption is written for exactly that case.

How to disclose

Article 50(5) sets a standard rather than a format:

"The information… shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure."

The article prescribes no wording, no font size, and no placement. The test is clear, distinguishable, and present by the time someone first sees the content.

What that rules out is obvious enough: six-point grey text in a footer, a label washed out against the image, a line buried in your terms of service. A visible caption under the image clears it.

Two mockups side by side. Left, labelled "Doesn't clear it": an image with a tiny near-invisible caption reading "ai-generated." Right, labelled "Clears it": the same image with a legible caption reading "AI-generated image" directly beneath it. Below, a list marking three failures — buried in terms of service, six-point footer text, washed-out overlay — against one that works: a visible caption under the image.

Does it reach outside the EU

Article 2(1)(c) extends the regulation to providers and deployers in a third country "where the output produced by the AI system is used in the Union."

Whether a blog in Seoul or Ohio that happens to be readable in Europe satisfies "output used in the Union"? Or does it take something closer to targeting an EU audience? Nothing I read settled it. The one relevant example I found, secondhand, involves a third-country advertiser running a celebrity deepfake in ads shown in the EU. That's active targeting, a long way from mere accessibility.

I can't tell you the rule reaches you. A caption is cheap enough that I'd add it anyway if you publish photorealistic imagery of real people or places and have meaningful European readership.

The penalty number, in context

Article 99(4)(g) puts Article 50 violations at up to €15,000,000, or 3% of worldwide annual turnover "if the offender is an undertaking," whichever is higher.

The 3% branch only engages for undertakings, which is why the headline figure for an individual is the €15M ceiling. That number is going to get used to frighten people, so two things are worth knowing.

The AI Act doesn't levy fines directly. Article 99(1) leaves actual penalties to member states, requiring them to be "effective, proportionate and dissuasive" while taking into account "the interests of SMEs, including start-ups, and their economic viability." Enforcement runs through national market surveillance authorities under Article 70(1).

And there are no enforcement cases to point at, for a reason that should be obvious: the obligation starts tomorrow. Anyone citing a track record either way is inventing it. Whether these authorities will spend capacity on individual bloggers is a question nobody can answer yet, and I found no published enforcement priorities.

I ran my own site through this

Rules read differently once you apply them to something you own, so I went through every image on this blog.

Twenty-eight images across ten published posts. Sorted against the two-condition test:

The three kinds of image on this blog, each tested. A screenshot of Gamma's editor: fails all three, not in scope. The abstract social banner: fails all three, not in scope. A hand-built reconstruction of a Claude session: satisfies "resembles real" and "passes as authentic" but not "AI-generated," so the article doesn't reach it. Tally at the bottom: zero AI-generated images, zero requiring a label, one relabelled anyway in July.

AI-generated images: zero. Every one is a screen capture of something that actually happened on my machine. Gamma's editor, Kimi's model picker, Anthropic's comparison table, a browser running a game two models wrote. The default social-share banner is abstract circuitry and type, which resembles nothing real.

So on the face of it, nothing here needs a label. But one image gave me pause, and it's the interesting case.

cadence-ai-chat.png shows a Claude conversation: my prompt on one side, Claude's reply and a code block on the other. It is not a screenshot. I rebuilt that exchange as an image because the original session was gone.

Run it against the definition. Does it resemble something that exists? Yes, the Claude interface is real and the image is built to look like it. Would it falsely appear authentic? Yes, that's the whole reason it works. Two out of two.

The third element is what saves it. No AI generated or manipulated that image, so Article 50(4) doesn't reach it. The rule is about synthetic media, and this is a hand-built reconstruction.

The image in question: a mocked-up chat window showing my prompt asking for a Cadence landing page, and a reply from Claude with the opening of an HTML file. It reads as a screenshot. It is a reconstruction I assembled after the original session was gone.

Which is a technicality, and I knew it before August 2 was on my calendar. I audited my own posts in July and flagged this one, because the alt text described it as though it were a real capture. It now says "a reconstruction of the exchange." I changed it because it was misleading, not because a regulation told me to.

Compliance would have let this image through untouched.

The company: the watermark was already there

On July 30, Google added a "Create image" feature to Google Earth on the web, running on its Nano Banana 2 model. You could pick a spot on the real satellite map and prompt a photorealistic alteration on top of it.

404 Media spent very little time finding the failure mode. High-rises dropped onto rural land. A homeless encampment inserted into a real Los Angeles block. An explosion and bomb crater in another. Protesters assembled outside Google's own headquarters.

Google pulled the feature on July 31, about 24 hours after launch. From its statement:

"We know that people uniquely trust Google Earth for a reliable view of the world. We've seen geospatial professionals using this feature for a range of useful purposes, however we've also seen people sharing screenshots of generated imagery that appear to violate our policies. So we're rolling back this feature in Google Earth while we work on implementing stronger guardrails."

One detail connects this to August 2, and I didn't see it made in the coverage I read.

Those generated images carried SynthID. That's Google's invisible watermark, embedded in the output itself. The feature already satisfied the exact technical requirement the EU is about to impose on generative systems.

It complied. And Google still had to pull it in a day.

A watermark answers a question nobody was asking. It's a signal for detectors that check. It does nothing for a person scrolling past a screenshot of a crater where their neighborhood used to be, and the screenshot is what travels. Screenshots don't carry metadata.

Article 50 splits its obligations along the same line. The machine-readable half belongs to the tool vendor, and the visible half belongs to whoever publishes.

And a court, in the same week

On July 31 the Regional Court of Munich I ruled for GEMA, the German music rights body, against Suno (case 42 O 763/25). The court found infringement at three separate stages: training on the protected works, storing them inside the model, and generating outputs substantially similar to the originals from ordinary prompts.

This one is about inputs rather than disclosure, so it doesn't change what you label. It matters because the three-stage finding removes the usual defense of arguing about which stage you're on.

Three caveats that carry weight. It is a first-instance decision and not final; Suno disagrees, says its technology is built to generate new music rather than reproduce existing songs, and is weighing an appeal. It's a German regional court, binding no other member state. And the case turned on something specific to music, since GEMA could demonstrate outputs closely resembling the originals. That evidentiary path doesn't transfer cleanly to text or images.

GEMA's framing is that operating a system in Europe is enough to be sued in Europe. Whether the court applied German law directly to US training, or grounded jurisdiction in the storage and output happening inside Europe, is a meaningful distinction. I never got to the court's own press release to settle it, so I'll put it no stronger than this: European operation, storage, and output were the connecting thread.

Timeline of three days. July 30: Google ships AI image generation into Google Earth, outputs carrying SynthID watermarks. July 31: the Munich court rules for GEMA against Suno, finding infringement at training, storage, and output. July 31, roughly 24 hours after launch: Google pulls the feature after 404 Media produces fake craters and protests on real coordinates. August 2: Article 50 applies, machine-readable marking for providers and visible disclosure for publishers.

So what do you actually do

On the text as it stands:

Photorealistic images of real people, real places, or real events. Label them, visibly, near the image. This is the case the rule was written for.

Abstract illustrations, diagrams, obviously stylized art. Outside the deepfake definition, no obligation.

If you edited the draft and published it under your own name, the editorial control exemption in 50(4) covers you as written.

Machine-readable watermarking isn't your job at all. 50(2) points that at whoever made the tool.

And if you can't work out whether you count as "professional," you probably don't need to resolve it. A caption costs nothing and settles the question either way.

One thing that isn't in any statute. The Google Earth rollback wasn't a compliance failure, since the watermark was there. It was a trust failure, and it took a day. Google Earth spent twenty years becoming the thing journalists and war-crimes investigators point at when they need to establish that something is real. The feature put that at risk faster than any regulator could have.


What I couldn't verify

Four things in this piece rest on secondary reporting, and I've flagged each where it appears:

  • The Commission's July 20 guidelines. The official page wouldn't load for me. Everything I say about how narrowly the personal-use exemption is read comes from law firm summaries of it.
  • The December 2, 2026 marking extension. Reported consistently, but I didn't confirm the citation in the official journal.
  • Extraterritorial reach. Whether being readable in the EU satisfies "output used in the Union" is not something I could settle from the sources I reached.
  • The Munich court's reasoning on jurisdiction. GEMA's release describes the outcome; the court's own release I never got to.

Verified August 1, 2026 against the AI Act text (Articles 2, 3, 50, 70, 99), GEMA's official release, and Google's public statement. The Munich decision is first-instance and not final.

This is a reading of what the statute says. It isn't legal advice, and if the answer genuinely matters to your situation, the €15M number is a good reason to ask someone qualified.