Two AI labelling laws switched on together on August 2, 2026 — Article 50 of the EU AI Act and California's AI Transparency Act — and almost every explainer written about them is aimed at compliance officers at model companies. If you are a freelancer, a marketer, a small publisher or anyone who just puts AI-made images and text on the internet, the useful question is narrower: which of these duties is actually yours, and which belong to OpenAI, Google and Adobe whether you think about them or not? The honest answer is that most of the machinery lands on the model providers, and your own obligations are few, specific, and easy to satisfy — if you know which three they are.
The EU AI Act splits obligations between the provider — whoever puts the generative AI system on the market — and the deployer, meaning whoever uses it. Nearly all the engineering-heavy requirements sit with the provider.
Under Article 50(2), providers must design their systems so that synthetic image, audio, video and text output carries a machine-readable mark that identifies it as AI-generated. That is watermarking, C2PA-style content credentials, cryptographic signing — provider work, not yours. If you generate an image in a mainstream tool, that marking is the tool's job.
The deployer duties in Article 50 are the ones that can attach to an individual, and there are three:
Everything else in the transparency article is provider machinery.
The text obligation has an exception written into it: the disclosure duty does not apply where the AI-generated text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication.
Read plainly, that is the difference between a site that pipes model output straight to publication and a site where a named human reads, edits and stands behind the piece. The second case is outside the labelling duty for text — not because the AI involvement is hidden, but because a person has taken responsibility for the claims. It is worth noting how neatly this rewards the editorial workflow that helpful-content ranking already rewards.
The image, audio and video duty has no equivalent human-review escape. A deepfake stays a deepfake after you edit it.
Article 50 applied from 2 August 2026. It kept its date when everything around it moved.
The Digital Omnibus — the EU's amending package, which entered into force on 27 July 2026 — postponed the high-risk obligations that were supposed to arrive on the same day: Annex III standalone high-risk systems (recruitment, credit scoring, education, law enforcement, border control) now bite on 2 December 2027, and high-risk AI embedded in regulated products under Annex I on 2 August 2028.
The one concession Article 50 received is narrow: generative systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to bring their machine-readable marking into conformity under Article 50(2). Systems launched on or after 2 August 2026 get no grace period at all. Note again who that helps — it is a provider grace period. Your deepfake and chatbot disclosures were due on 2 August.
Penalties for breaching Article 50 fall in the AI Act's middle tier: up to €15 million or 3% of worldwide annual turnover, whichever is higher, rather than the headline €35 million / 7% reserved for prohibited-practice violations. And the Act reaches non-EU businesses whose AI output is used in the EU, so a US freelancer serving European clients is in scope.
California's AI Transparency Act (SB 942, amended by AB 853) became operative on 2 August 2026 — a date deliberately aligned with the EU. Its structure, though, is nothing like Article 50's.
CAITA regulates covered providers only: generative AI systems with more than one million monthly visitors or users that are publicly accessible in California. If you are reading this wondering whether it applies to you, it does not. There is no CAITA duty on ordinary users, and — a detail that surprises people — it does not cover AI-generated text at all. Images, video and audio only.
What covered providers owe as of 2 August:
Two later phases matter for planning: from 1 January 2027, large online platforms must detect and surface embedded provenance data, and AI hosting platforms may not knowingly offer non-compliant systems; from 1 January 2028, capture-device manufacturers must support the disclosures by default. Enforcement is $5,000 per violation, per day, by state authorities, with no private right of action.
Put the two regimes side by side and the practical picture for an individual is short.
You must, if you publish into the EU: label deepfake-style synthetic media, tell people when they are talking to your chatbot, and either disclose AI-written public-interest text or take genuine editorial responsibility for it.
You do not have to: watermark every AI-assisted image you post, add a badge to AI-assisted copywriting, or run detection tooling. Those are provider duties, and in California they are provider duties that only bind services above a million monthly users.
Worth doing anyway: keep the provenance metadata intact. Latent marks travel in file metadata, and re-exporting, screenshotting or stripping EXIF removes them. Nothing in either law obliges you to preserve a mark someone else embedded — but a 2027 platform rule that surfaces provenance is coming, and content that arrives with credentials intact will read as more trustworthy than content that arrives bare. That is a reputational argument, not a legal one, and it is the right way to think about most of this: the legal minimum for an individual is genuinely small, and the disclosure habit is worth more than the compliance box.
Originally published on www.nihardaily.com. For more articles like this one, visit www.nihardaily.com.