AI content disclosure: what marketing teams must label before August 2026
New EU rules require labelling AI-generated content from August 2, 2026. Here's what disclosure means for marketing teams, how watermarks and Content Credentials work, and how to stay on-brand while staying compliant.

For most of the last two years, disclosing that a marketing asset was made with AI was optional: a judgment call buried in your content policy, if you had one at all. That window is closing. From August 2, 2026, the EU AI Act starts requiring clear labels on certain AI-generated content, the major platforms are rolling out their own "made with AI" tags, and the underlying file formats are quietly learning to carry their own history. For teams shipping AI images, video, and audio at volume, disclosure is becoming part of the job.
AI content disclosure is the practice of making it clear, to audiences, platforms, and regulators, when content was generated or meaningfully altered by AI. It spans three layers: visible labels people can read, invisible watermarks machines can detect, and provenance metadata that records how a file was made. This guide explains what's actually required, how the mechanics work, and how to handle disclosure without making your brand look defensive.
What does the EU AI Act require, and when?
The headline date is August 2, 2026. From then, the EU AI Act's transparency obligations apply, and the European Commission has published a Code of Practice on marking and labelling AI-generated content to help teams comply. Two requirements matter most for marketers.
First, deepfakes (and AI-generated or AI-manipulated text published on matters of public interest) must be clearly labelled so people aren't deceived. Second, users have to be told when they're interacting with an AI system such as a chatbot. Alongside the human-readable labels, providers of generative AI systems are expected to embed machine-readable marks so synthetic content can be detected automatically downstream.
A few things are worth keeping in proportion. The Code of Practice itself is voluntary; it's a practical route to meeting the binding obligations, not a new layer of law. The rules bite hardest on deepfakes and public-interest content, not on every product shot or social graphic. And the law is European, but if you sell into the EU, or publish on global platforms, it effectively sets the floor for everyone. The safe assumption for any team operating at scale is that disclosure is now the default expectation, not the exception.
How do AI watermarks and Content Credentials work?
The "machine-readable mark" part of the law sounds abstract until you see the two technologies doing the work. They solve different halves of the problem.
A watermark is a signal hidden inside the content itself. Google's SynthID, for example, embeds an imperceptible pattern directly into the pixels of an image or the waveform of audio at generation time, invisible to people but detectable by a model even after the file is cropped, compressed, or re-saved. Google reports that over 10 billion pieces of content have already been watermarked with SynthID across its Imagen, Veo, Lyria, and Gemini models. The strength of a watermark is durability: because it lives in the content, it's hard to remove by accident.
A Content Credential takes the opposite approach. Built on the open C2PA standard, it's a tamper-evident, cryptographically signed record that travels alongside the file, describing how the content was created and how it changed over time. As the C2PA explains, any edit that doesn't update the credential breaks its cryptographic signature, which is what makes tampering detectable. Think of it as a nutrition label for media. Its strength is richness: it can carry the whole history, including which AI tools and source "ingredients" were involved.
| Invisible watermark (e.g. SynthID) | Content Credential (C2PA) | |
|---|---|---|
| Where it lives | Inside the pixels/audio | Metadata attached to the file |
| Best at | Surviving edits and re-uploads | Recording detailed creation history |
| Main weakness | Limited information carried | Can be stripped from the file |
| Who reads it | Detection models and platforms | Anyone with a verifier (e.g. Content Credentials) |
The two are complementary. C2PA even supports "durable" credentials that use invisible watermarking as a soft binding, so provenance can be recovered if the metadata is stripped. For a marketing team, the practical takeaway is that you usually don't build either of these yourself; you inherit them from the AI tools you generate with, which is exactly why your choice of tools matters.
Visible labels vs. invisible signals: which do you owe whom?
Disclosure isn't one thing; it's an answer to three different audiences, and they don't all need the same thing.
Your audience needs honesty they can read. That's a visible label or a line of copy: "Concept imagery generated with AI," a caption note, a footer disclosure. The goal is that a reasonable person isn't misled about what they're looking at, especially for anything resembling a real person, place, or event.
Platforms need a signal they can detect. Social networks and search engines increasingly scan for watermarks and Content Credentials and apply their own labels automatically. You don't control that labelling, but you do control whether your files carry the signals cleanly. Strip the metadata in a careless export and you can end up looking like you're hiding something you weren't.
Regulators need a defensible record. If an asset ever falls under the AI Act's deepfake or public-interest provisions, "we labelled it and the file carried machine-readable marks" is the position you want to be in. This is where having provenance baked into your workflow, rather than bolted on after the fact, pays off.
Why disclosure is a brand problem, not just a legal one
It's tempting to file all of this under compliance and hand it to legal. That undersells it. Disclosure is really a trust decision, and trust is brand territory.
The brands that get burned aren't the ones that use AI (almost everyone does now); they're the ones whose AI use feels concealed. When undisclosed synthetic content gets discovered, the story isn't "they used AI," it's "they hid it." A confident, well-designed disclosure does the opposite: it signals that you're in control of your process. That only works, though, if the content underneath is actually good and actually yours. This connects directly to why so much AI content looks off-brand in the first place: generic, obviously-synthetic output is both easier to spot and less worth standing behind.
The deeper point is consistency. Disclosure that's improvised per post (a label here, none there, metadata sometimes) reads as chaos. Disclosure that's wired into how every asset is produced reads as policy. The same discipline that keeps your AI images and video on-brand is what makes disclosure reliable: when generation runs through a repeatable process, the labels and provenance come out the same way every time.
How this looks with Orisu
Orisu doesn't write your disclosure policy; that's your call about what to label and how. What a node-based canvas does is make the policy executable instead of aspirational.
Because every asset is produced by running a workflow rather than improvised in a dozen tabs, the disclosure step becomes part of the workflow itself. Wire your brand kit and your standard caption or watermark treatment into the canvas once, and every run produces content that's both on-brand and labelled the way you decided, not dependent on whoever happened to export the file remembering to add a note. The same models that carry watermarks like SynthID into their output keep doing so when you run them through Orisu; the credentials and signals ride along.
That's the quiet advantage of treating content as a process you can fold and reuse: when disclosure is a step on the canvas instead of an afterthought, staying compliant and staying consistent turn out to be the same task. As the on-brand AI content guide argues, the teams that win the next phase of AI content aren't the ones generating the most; they're the ones whose output is trustworthy, recognizable, and honest about how it was made.
Your brand kit is one URL away.
Paste your site and Orisu builds the kit — colors, fonts, voice, logo — then holds every generation to it.
Common questions.
Do marketing teams have to label AI-generated content?
It depends on where and what you publish. The EU AI Act requires clear labelling of deepfakes and AI-generated or AI-manipulated text on matters of public interest from August 2, 2026, and platforms increasingly surface AI labels on their own. Even where it isn't legally required, disclosing AI use is becoming a trust expectation rather than a nice-to-have.
What is the difference between a watermark and a Content Credential?
A watermark like Google's SynthID is an invisible signal embedded in the pixels or audio of a file that survives editing and proves a specific AI tool made it. A Content Credential (C2PA) is signed metadata that travels with the file recording how it was created and edited. Watermarks are hard to strip; credentials carry richer history. The two are complementary, not rival, approaches.
Does adding AI disclosure or a watermark change how my content looks?
No. Both SynthID watermarks and C2PA Content Credentials are designed to be invisible to viewers: the image, video, or audio looks identical. A Content Credential adds only a few kilobytes of metadata, and a watermark lives below the threshold of human perception. Any visible 'made with AI' label is a separate editorial choice you control.
Will labelling AI content hurt engagement or trust?
In our experience the bigger risk is being caught not disclosing. Audiences increasingly assume AI involvement anyway, and platforms add their own labels regardless. A clear, confident disclosure, paired with content that's genuinely good and on-brand, reads as honesty, not apology. The brands that get hurt are the ones whose AI use feels hidden.


