Practical guide · last reviewed July 2026
The short version
01
Disclose, from 2 August 2026
From 2 August 2026, if you publish AI-generated or AI-manipulated images (deep fakes), you must disclose that they're AI: a duty on you as the deployer (Article 50(4)).
02
Mark it so machines can read it
AI outputs are also meant to carry a machine-readable mark (Article 50(2)), primarily a duty on the AI provider. The Digital Omnibus amendment, formally adopted in June 2026, gives systems already on the market until 2 December 2026 for that specific marking.
03
The cost of ignoring it
Non-compliance can mean fines up to €15 million or 3% of global annual turnover.
04
The WordPress fix
On WordPress, the practical fix is three layers: a visible badge, embedded IPTC/XMP metadata, and schema.org JSON-LD, which the free AIM Transparency plugin does automatically.
This is a practical guide, not legal advice. The EU AI Act's detailed technical marking standards are still being finalised through the Commission's Code of Practice and standardisation work ahead of August 2026. Whether a specific image is in scope, and what your organisation must do, depends on your circumstances; consult a qualified advisor for your case.
What is Article 50?
The EU AI Act (Regulation 2024/1689) entered into force in August 2024, with obligations phasing in over several years. Article 50 is the part about transparency: making sure people know when they're dealing with AI, and that AI-generated content can be recognised as such. Its transparency obligations become applicable on 2 August 2026.
Article 50 splits into duties on two kinds of party: providers (who build/supply the AI system) and deployers (who use it, that's most WordPress site owners).
Does it apply to my WordPress site?
If you use an AI tool (Midjourney, DALL·E, Firefly, Stable Diffusion, and so on) to generate or edit images that you then publish (on a blog, a news site, a shop, a portfolio), you're acting as a deployer, and Article 50(4)'s disclosure duty is aimed at you. The obligation is strongest for "deep fakes": image, audio or video content that's been artificially generated or manipulated to resemble real people, objects, places or events.
Article 50(4) has a second half, and it's about text. If you publish AI-generated or AI-manipulated writing in order to inform the public on matters of public interest — news, journalism, public affairs, health or safety guidance — that has to be disclosed as well. This half is deliberately narrower than the image half: a shop, a portfolio or a personal blog isn't publishing to inform the public in that sense, and the text duty doesn't reach it at all.
It also carries an exemption the image half does not. Text that has had human review or editorial control, and where a named person or organisation holds editorial responsibility for publishing it, needs no disclosure. Those are two conditions rather than one, so a review with nobody named does not qualify. And the two halves are judged separately: reviewing an article does not exempt an AI-generated image sitting inside it.
It's an EU regulation, but its reach is broad: it applies where the AI system's output is used within the EU, so non-EU sites with EU audiences are generally caught too. Purely artistic, satirical or fictional work has lighter, context-appropriate disclosure, but "we're a small blog" is not, by itself, an exemption.
The dates
-
2 February 2025
In force
Article 4, AI literacy. Anyone who deploys AI has to understand what it does. The plugin’s Readiness view keeps that record for you.
-
2 August 2026
In force
Article 50, transparency. The duty to disclose AI content on your own site started here, with no transition period and nothing to opt into.
-
2 December 2026
Not your deadline
A transition for AI providers. Under the Digital Omnibus, tools already on the market get until this date to add machine-readable marking under Article 50(2). It buys your site no extra time.
The four duties, and how to meet each on WordPress
50(1)
Tell people when they're talking to an AI
If your site runs a chatbot or AI assistant, visitors must be told they're interacting with AI, not a human. On WordPress: a small persistent disclosure notice near the chat widget (AIM Transparency ships a notice + an [aicl_ai_notice] shortcode for this).
50(2)
Mark AI outputs so machines can detect them
AI-generated audio, image, video and text should be marked in a machine-readable way (e.g. embedded metadata / provenance) so detection tools can recognise it. Primarily a provider duty, but embedding the mark in the files you host is good practice and future-proofs you. On WordPress: write the IPTC/XMP DigitalSourceType tag into the image file, plus schema.org JSON-LD on the page.
50(4)
Disclose AI-generated / manipulated images to people
As a deployer publishing AI-generated or manipulated visual content (especially deep fakes), you must clearly disclose that it's artificial. On WordPress: a visible badge on the image ("AI Generated" / "AI Modified") that a human can plainly see.
Art 4
AI literacy for your team
Already in force: organisations must take steps so staff dealing with AI have a sufficient level of AI literacy. On WordPress: keep a simple record: which AI tools you use, who's responsible, a review cadence. (AIM Transparency includes an Article 4 checklist and a readiness score.)
Penalties
The AI Act carries real teeth. Failure to meet the transparency obligations can lead to administrative fines of up to €15 million, or 3% of total worldwide annual turnover, whichever is higher (figures vary with the specific infringement and are set by national authorities). The point isn't the maximum. It's that "we didn't know" won't be a defence after 2 August 2026.
or 3% of total worldwide annual turnover, whichever is higher.
Transparency breaches sit under the AI Act's administrative fines, applied by national authorities from 2 August 2026.
What you actually need to do
Identify which published images are AI-generated or AI-edited.
Add a clear, human-visible disclosure to each (a badge).
Embed a machine-readable mark in the files and the page.
Disclose any AI chatbot/assistant.
05
Keep a short AI-literacy / tooling record for Article 4.
How AIM Transparency handles it
AIM Transparency is a free WordPress plugin built for exactly this.
You flag an image as AI, and it applies all three disclosure layers at once (the visible badge, the embedded IPTC/XMP metadata, and the schema.org JSON-LD) across your galleries, featured images and content, on any standard theme.
Text and chatbots, not just images. Article 50(1) is a separate duty from 50(2), and it needs a disclosure in your copy rather than on a file. Two shortcodes cover it: [aicl_disclosure] places an AI notice anywhere shortcodes run, with a type (generated, edited, assisted or chatbot) and a style (inline, badge or banner), and [aicl_ai_notice] is the chatbot case on its own. There is a step-by-step guide to the chatbot duty.
It finds what you have not disclosed yet. The free Detection card checks two things without sending anything off your server: your unflagged library, for images whose files already read as AI-generated, and your site itself, against a registry of 672 AI systems. It separates chatbots and assistants (50(1)) from image and content generators (50(2)), so you can see which duty applies to what. An Article 4 readiness checklist sits alongside it.
The core is free forever; Pro adds automatic flagging on upload, more image formats, a library scanner and compliance reports.
Frequently asked questions
Do I really have to label AI images on my WordPress site?
Does it apply to non-EU websites?
Isn't a visible label enough? Why embedded metadata too?
What happens if I do nothing?
Official sources & further reading
This guide summarises primary EU sources in plain English; always verify against the official text for your own situation (it is not legal advice):
