Compliance
The EU AI Act disclosure rules are live. What creators actually have to do.
The transparency obligations applied from 2 August 2026. Most of the coverage was written for enterprises. Here is the part that touches individuals.
The EU AI Act's transparency provisions for AI-generated content took effect on 2 August 2026. Coverage has focused on model providers and large deployers, which has left a lot of independent creators unsure whether any of it applies to them.
The idea in one sentence
Synthetic content should be marked as synthetic in a machine-readable way, so platforms and downstream systems can tell what they are handling — not only human viewers.
"Machine-readable" is the operative phrase. A caption saying "made with AI" helps a reader, but is not a machine-readable marking.
Who it reaches
- Providers of generative systems carry the marking obligation. If you use someone else's tool, this is largely their problem.
- Deployers — people who publish the output — have narrower duties, chiefly around disclosing deepfakes and certain synthetic material.
- Territorial reach is broad. It is not limited to businesses established in the EU; what matters is whether output reaches people there. For anything published on the open internet, assume it does.
Why this is arriving from several directions
The EU is the strictest, not the only source. California's SB 942 addresses AI content transparency, New York has legislated on synthetic performers, and the NO FAKES Act addresses digital replicas. Platforms have moved independently: several now label AI content and some adjust monetisation for it. The direction is consistent even where the detail differs.
What to do now
- Check what your tools emit. Some attach Content Credentials; many attach nothing. Know which yours does.
- Keep your own records. Whatever a regulator eventually asks for, being able to show what you made and when is the foundation. Reconstructing it later is much harder.
- Disclose plainly where it matters — realistic depictions of real people above all. This is the area with the least tolerance and the most attention.
- Do not rely on metadata alone. Platforms strip it on upload. If your compliance story depends on embedded metadata surviving distribution, it will fail at the first re-upload.
Where GenieMade fits
Every creation is hashed, signed and entered into a public registry, so the record is anchored to the content rather than the file's metadata — it survives stripping, re-upload and screenshotting. Anyone can check it without an account.
That is a records capability, not a compliance certification. It gives you a durable, independent answer to "what is this and when did it exist", which is the question underneath most of these rules. It does not make you compliant on its own, and no tool can.
See what a record looks like →Check any file against the public registry.Summarises publicly available information about the EU AI Act and related legislation as of publication. Not legal advice. Obligations and dates change — verify against primary sources or qualified counsel before relying on any of it.