Most of what you have read about EU AI Act compliance was written for lawyers. This one is written for the person who actually opens the composer, picks the caption, and hits schedule.
If you run social or marketing for a mid-market brand or agency and your audience or clients reach the EU, August 2, 2026 is the date to know. That is when Article 50 of the EU AI Act, the law’s core AI transparency rule, becomes enforceable. Getting this right does not require a legal team. It requires knowing exactly which of your posts need a label, which do not, and what to do about the two questions even the regulators have not fully answered yet.
One quick note before we start. This article reflects the law as it stood in late July 2026. It is not legal advice for your specific situation. Where something is genuinely unsettled, we say so instead of guessing, and we tell you when it is worth a five-minute call with counsel.
Who Has to Comply for EU AI Act, and With What
The European Union Artificial Intelligence Act (EU AI Act) is the world’s first comprehensive legal framework for regulating artificial intelligence. It classifies AI systems based on their potential risk to safety and human rights, applying stricter rules to higher-risk technologies.
This regulation exists to “improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence,” while protecting people from AI’s real risks.
This means that before you touch a single caption, you need two questions answered. Does this law reach your account at all, and once it does, which parts of it actually land on your desk versus someone else’s.
The three sections below walk through both, starting with the scope question everyone asks first.
Here is the one-line answer. Your audience’s location decides this, not where your company is headquartered.
Article 2 of the AI Act gives it a reach beyond the EU’s borders. If the output of an AI system, a caption, an image, a video, a chatbot reply, is used by people in the EU, the rules can apply to you even if your business has never set foot in Europe. A B2B marketing newsletter covering this exact question put it simply:
“It’s not about where YOU are based, it’s about where your audience is.”
That principle is clear. What is not clear yet is where the line sits for an ordinary global post.
Nobody, not even the European Commission’s own AI Act Service Desk, has published a test for this specific scenario:
- A campaign built for EU audiences and shared on an EU business account
- An ordinary global post that happens to reach some EU followers because your account is public
The first is clearly in scope. The second is the genuinely gray area. If a meaningful share of your audience sits in the EU, or if you run paid campaigns that target EU countries, treat yourself as in scope and move on to the next section. If your reach into the EU is incidental, this is exactly the kind of edge case worth a short conversation with counsel rather than a guess from a blog post, including this one.
The Four Things Article 50 Actually Asks For
Article 50 is not one rule. It is four separate duties, and only some of them land on your desk.
| Sub-article | What it requires | Whose job is it |
| 50(1) | Tell people when they are talking to an AI system, like a chatbot | Mostly the tool provider (who builds AI), partly you as a deployer (who uses AI). |
| 50(2) | Machine-readable AI watermarking on synthetic content | The AI tool provider |
| 50(3) | Disclose when emotion recognition or biometric categorization is in use | Deployer, rarely relevant to ordinary social content |
| 50(4) | Disclose deepfakes and certain AI-generated public interest text | Deployer, this is the one that matters most for social teams |
Two of these barely touch a normal social media calendar. Article 50(3) is aimed at things like workplace emotion-detection software, not your Instagram grid. Article 50(2), the actual AI watermarking mechanism, is a job for whoever built the AI tool you are using, not for you.
That leaves 50(1) and 50(4) as the two duties a social team really owns: telling people when a chatbot is a bot, and disclosing certain AI-generated content. The rest of this article is built around those two.
Provider or Deployer, Which One is Your Team?
Under the AI Act, a “provider” builds or trains an AI system. A “deployer” uses one that someone else built. If your team uses an AI writing assistant, an image generator, or a chatbot platform someone else developed, you are a deployer.
This distinction changes what you actually owe. A named marketing practitioner covering the EU AI Act for B2B teams draws the comparison to GDPR’s controller and processor roles, and notes that
“Deployer duties are deliberately lighter. You’re not expected to prove how the model was trained.”
In practice, that means your job is disclosure, not engineering. You do not need to audit an AI vendor’s training data or rebuild their labeling technology. You need to tell your audience, clearly, when specific content falls under Article 50(1) or 50(4).
What to Disclose, When, and on Which Platform
This is the part you actually act on. Once you know the law applies to you, the next question is practical: which deadline matters, which content types need a label, and what that label actually looks like on the platforms you post to every day.
Is the Deadline Delayed? August 2 vs. December 2
You may have seen a headline saying the EU AI Act got delayed. That is true for one part of it, and not true for the part that matters most to you.
On May 7, 2026, the Council of the EU and the European Parliament reached a provisional agreement on a package known as the Digital Omnibus. It pushed back the deadline for high-risk AI system obligations, things like formal risk assessments for high-stakes AI, to December 2, 2027. That delay has nothing to do with disclosure.
| What it covers | Deadline | |
| Disclosure duty | Telling your audience about chatbots and AI-generated content (Article 50) | Live August 2, 2026, not delayed |
| AI watermarking | Machine-readable marking baked into the AI tool itself (Article 50(2)) | December 2, 2026, for tools already on the market before August 2 |
The watermarking piece is a technical grace period for AI vendors, not a delay for your disclosure duty.
Which AI Content Needs a Label, and Which Doesn’t
This is where most of the anxiety lives, and most of it is unnecessary.
Content that needs a disclosure:
- Deepfakes: A category of synthetic media, meaning images, audio, or video generated or edited by AI to realistically resemble a real, identifiable person, place, or event
- AI-generated or AI-edited text published specifically to inform the public on a matter of public interest, think news-style commentary, not a product description
Content that is exempt or gets lighter treatment:
- Content that is evidently artistic, satirical, or fictional
- AI-assisted text that has gone through genuine human review, with a real person taking editorial responsibility for it before it publishes
Ordinary marketing copy, an AI-drafted caption your team edits and approves, a product description, a scheduled promotional post, generally does not trigger the strict public-interest text rule.
An opinion piece from an agency co-founder covering this exact gray area is honest about the fuzziness here: “The public interest threshold is still being clarified in practice,” and in places, “what counts as a deepfake versus an obviously stylized AI image is a judgement call.” His advice, which is worth following: “where it’s genuinely unclear, disclose anyway.”
How to Disclose on Instagram, TikTok, LinkedIn, and YouTube
Every major platform already has its own AI label. None of them were built with Article 50 in mind, which is exactly why marketers keep asking whether the native tag is enough on its own.
| Platform | Native AI label | How you apply it | What Article 50 adds |
| Instagram / Facebook | Meta’s “AI info” label, applied automatically when it detects AI provenance metadata, or manually via the composer | Self-disclose in the post composer if Meta doesn’t auto-detect it | You still need to disclose deepfakes yourself if Meta’s detection misses the content |
| TikTok | AIGC label, self-applied or auto-applied if the creator skips it | Toggle the AI-generated content label before posting | Same underlying duty applies if the video would count as a deepfake or public-interest text |
| Partners with the C2PA standard, showing a content credentials icon when AI tools attach that metadata | Depends on whether your creation tool writes C2PA metadata | The disclosure duty exists independent of whether the icon shows up | |
| YouTube | Self-disclosure checkbox in Creator Studio for realistic altered or synthetic content, with visible labels on sensitive topics | Check the box during upload for realistic AI content | Same, plus the Article 50(1) chatbot-disclosure duty if you run an AI-powered channel bot |
Here is the honest answer nobody has confirmed yet. Does a platform’s own AI tag satisfy your Article 50 obligation on its own? No source we found, including the Commission’s own guidance, states this clearly either way. Treat the platform label as a helpful first layer, not a substitute for your own disclosure judgment.
If you want a lower-risk path while that question stays open, look at the EU’s own labeling icons, a standardized set marking content as Fully AI-Generated, Partially AI-Modified, or carrying a Basic marker.

These icons come out of a voluntary Code of Practice on Transparency of AI-Generated Content, which functions like a set of industry AI ethics guidelines rather than binding law. Following it will not guarantee compliance, but it is the closest thing to an agreed standard right now, and it is a stronger content authenticity signal than relying on a single platform’s auto-label.
Chatbots need the same honesty. If you run an AI-powered customer service bot or an AI sales assistant on your page, Article 50(1) requires you to make that obvious. A B2B marketing newsletter written by Louise Read puts the failure mode bluntly: Do not “give the bot a fake human name and a stock headshot” and let people believe they are messaging a colleague. A visible label like “AI Assistant” and an easy way to reach a human solves this.
How to Make Compliance Part of Your Routine
Understanding the rule once is not the same as following it every week. This section turns disclosure into a habit built into the workflow you already run, the policy documents your team already has, and an honest look at what else is out there beyond the EU.

Bake Disclosure into Your Publishing Workflow
The teams handling this well are not treating disclosures as one more step in the process they already run for every post.
The fragmentation problem is real. A company covering AI disclosure fragmentation across commerce platforms describes it as “a genuine compliance headache,” since the same product photo can travel under three separate platform disclosure regimes before the EU AI Act adds a fourth layer on top. The fix is not a new tool. It is one new checkpoint in the tool you already use.
Add a single question to whatever approval step already sits between drafting and publishing: does this piece need an AI disclosure, and did we add it? If your team uses a set social media workflow for every post that goes live, this is one checkbox that must be added to a process that already exists.
Naming an owner matters here too. Spreading the disclosure check across everyone who touches a post is how it gets skipped. Assign it to whoever already reviews content last, and be careful this does not become a single point of failure.
The same single approver bottleneck at agencies that slow down a normal publishing calendar will slow down your disclosure check too if one person becomes the only gate.
Write Your Disclosure Rules into Policy
A checklist that only lives in someone’s head disappears the day that person is on vacation, so write it down.
Add a short section to your existing brand documentation covering:
- Which content types on your calendar typically need a label, based on the rules above.
- Who signs off on the disclosure question before a post goes live.
- Two or three ready-made caption lines your team can copy and adjust.
Here are three you can start with:
- “This video includes AI-generated visuals.” (short, general-purpose)
- “Some elements of this image were created using AI.” (for partially AI-modified content)
- “You’re chatting with our AI assistant. Want a real person? Just ask.” (for a customer-facing bot)
These disclosures belong in your brand style guide next to your other tone and formatting rules, not in a separate compliance document nobody opens. A short, written AI policy like this is what responsible AI actually looks like for a social team, not a thick legal binder, just a clear internal answer to “what do we do here.”
Don’t Forget the US, a Growing State-Law Patchwork
The EU AI Act is not the only piece of AI regulation on your radar if you post to a US audience too. A handful of states have passed their own AI disclosure laws, and they do not all cover the same ground.
| Jurisdiction | What it actually covers | Who’s affected | Penalty |
| EU, Article 50 | Deepfakes, AI chatbots, certain AI-generated public interest text | Anyone whose AI content reaches EU audiences | Up to EUR 15 million or 3% of global turnover |
| New York, GBL §396-b | AI-generated “synthetic performers” in advertisements | Advertisers running ads with fully AI-generated performers | $1,000 first violation, $5,000 per subsequent violation, per New York’s own announcement |
| California, SB 243 | AI companion chatbots designed for ongoing, human-like interaction | Any business running this kind of chatbot for California users | Greater of actual damages or $1,000 per violation, per the official bill text, and it allows individual lawsuits |
| New Jersey, N.J.S.A. 56:18-2 | Bots used in commercial sales, real estate ads, or election-related solicitation | Businesses running undisclosed bots in those specific contexts | $2,500 first violation, $5,000 for a second, $10,000 for each one after that, per the bill’s own penalty section. |
| Utah, HB 452 | Mental health chatbots specifically, not general customer service bots | Companies offering AI mental health or therapy-style chatbots | Enforced by the state, effective since May 7, 2025 |
Notice how narrow some of these are. Utah’s law is not a general chatbot rule, it is specific to mental health tools. New Jersey’s is specific to sales, real estate, and election communication, not customer service bots in general. Only California’s applies broadly to human-like chatbot interactions the way people often assume all of these laws do.
The practical move, if you post to both EU and US audiences, is to set one internal standard built around the strictest rule you are actually exposed to, rather than tracking four separate playbooks. Marketing compliance across two regions does not have to mean two separate processes, just one standard set to the stricter side.
State law moves fast in this space, so confirm current status before you rely on any of these figures for a specific campaign.
Penalties, Your Checklist, and the Bottom Line
Here is what happens if this slips through the cracks, the list you can actually run this week, and an honest summary of where things stand.
What are the Penalties for Getting it Wrong?
The EU AI Act has three separate penalty tiers, and the one that applies to most social media compliance failures is the middle one, not the headline-grabbing top figure people quote.
| Violation type | Maximum fine |
| Prohibited practices (Article 5), like social scoring or manipulative AI | EUR 35 million or 7% of global annual turnover |
| Most other breaches, including Article 50 transparency violations | EUR 15 million or 3% of global annual turnover |
| Supplying incorrect information to authorities | EUR 7.5 million or 1% of global annual turnover |
Source: Article 99: Penalties | AI Act Service Desk
This is the correction worth remembering. If you fail to disclose AI content under Article 50, you are looking at the EUR 15 million or 3% tier, confirmed directly through the Commission’s own guidance. The higher EUR 35 million or 7% figure applies only to Article 5’s prohibited practices, a much narrower and more severe category that has nothing to do with an undisclosed AI caption. Plenty of content online blends the two, so treat any source that quotes 35 million for a disclosure failure with suspicion.
SMEs and startups get a real, if limited, benefit here too. Under Article 99, smaller companies pay the lower of the fixed amount or the percentage, not the higher one that larger companies face. That caps the size of the fine. It does not exempt a small agency from the disclosure duty itself.
Your Pre-August 2 Compliance Checklist
This is the practical core of EU AI Act compliance for a social team. Run through it this week, not the week of August 2.
- List every place AI touches your outward-facing content: captions, images, video, product descriptions, and any chatbot on your page or site.
- Confirm whether your audience or clients include EU users, and flag any account where that answer is genuinely unclear.
- Mark which of those AI touchpoints fall under Article 50(1) or 50(4), using the content rules above.
- Add one disclosure checkpoint to your existing approval workflow, and name who owns it.
- Write two or three disclosure caption templates into your style guide.
- Check whether any customer-facing chatbot is clearly labeled as AI, with an easy path to a human.
- If you post to US states too, note which state laws actually apply to your specific use case, not all of them by default.
So, Where Does That Leave You?
Most of what makes EU AI Act compliance feel overwhelming is the fear that you are missing something everyone else already understands, and you are not. Two real, specific questions here are still unsettled, even for the people writing about this professionally: exactly where the line sits for an ordinary global post, and whether a platform’s own AI tag is enough on its own. Nobody has a confirmed answer to either yet, so do not let anyone, including this article, tell you otherwise.
What you do know is enough to act on. Disclose deepfakes and AI text on public interest matters. Label your chatbot. Build one checkpoint into the workflow you already run. The natural home for that checkpoint is wherever a post already goes for a client’s or manager’s approval and before anything goes live.
If you want to see what that looks like inside an actual approval flow, SocialPilot‘s plans include the kind of approval workflow built to hold exactly this sort of sign-off step, one clear gate where the disclosure question gets asked and answered before anything publishes.
Disclaimer: This article is not legal advice. For a specific answer about your company’s exposure, especially around the two open questions above, talk to counsel.


