On August 2, 2026, something took effect on the same day in both Brussels and Sacramento. In the EU, Article 50 of the AI Act became applicable; in California, the California AI Transparency Act did. Both regulate how it must be disclosed that a machine generated a piece of content. They do it in opposite ways, and that difference decides who ends up doing the work.
Brussels buried its reasoning in the fine print
Why the EU is regulating this at all is something the legislator spelled out itself, in Recital 133 of the Act. It states that AI systems generate large volumes of synthetic content that are becoming increasingly difficult for people to distinguish from genuine content. It continues:
The wide availability and increasing capabilities of those systems have a significant impact on the integrity and trust in the information ecosystem, raising new risks of misinformation and manipulation at scale, and other harms, including in relation to fraud, impersonation and consumer deception.
So labeling isn't an end in itself. It's meant to flip the burden of proof: instead of readers having to figure out what's real, senders are supposed to say so. EU law knows this same logic from food labeling and advertising disclosure. What's new here is the subject matter, not the principle.
Technically, the regulation stays open-ended. The recital mentions watermarks, metadata, cryptographic proofs of provenance, logging, and fingerprints, and it requires that whichever technique is chosen be reliable, interoperable, and robust, as far as the state of the art allows. That last caveat is really the heart of the problem, because none of these techniques survives a screenshot.
China got there first, but targets different actors
Anyone who thinks the EU is out there alone is mistaken. China put its labeling requirement into force back on September 1, 2025, nearly a year before Brussels. The measures require two layers: visible labels on content that could mislead the public, and implicit markers in the metadata containing the provider's name and a content ID.
The crucial difference lies in who is targeted. China's rules address internet service providers and the platforms that distribute content. Platforms have to review uploaded content and sort it into categories: confirmed AI-generated, possibly, suspected. The burden sits with the operators of the infrastructure, not with the person who publishes something.
The US has no federal law, but California does
At the federal level, there is still no labeling requirement for AI content in the US. In 2025 the Senate rejected a moratorium that would have barred states from regulating AI on their own. In December 2025 the President instead signed an executive order establishing a task force to review state laws in court and dangling federal broadband funding as leverage against states with strict AI laws. Even so, by July 1, 2026, 29 states had passed their own AI laws.
California is the most interesting case, because its law shares the same effective date as the EU rule. It obligates Covered Providers — providers of generative systems with more than one million monthly users. They must deliver three things: a free public tool anyone can use to check whether a piece of content came from their system, an option for visible labeling that users can turn on, and mandatory metadata in every generated image, video, and audio file, stating the system name, version, and date.
Starting January 1, 2027, the large platforms are added to the mix; they must detect and display provenance data. Camera manufacturers follow in 2028. The law provides for fines of $5,000 per day for violations, enforced by the state, with no private right of action.
If you run a blog in California and publish an AI-written text, you don't have to label anything yourself. The duty sits with the tool maker, and from 2027 onward, with the platform.
The UK is waiting it out
A briefing from the House of Commons Library dated January 20, 2026, sums up the situation in one sentence: there is no law requiring the labeling of AI content. In its copyright consultation, the government has acknowledged that clear labeling would benefit rights holders and the public, but points to technical difficulties. A draft bill has been postponed several times.
The difference that actually matters
Line the three models up side by side, and the pattern becomes clear.
- China: Providers mark the content, platforms check and label it. The individual just publishes.
- California: Providers mark content and offer verification tools; from 2027, platforms display the provenance. The individual just publishes.
- EU: Providers add machine-readable markers. And on top of that, the operator — meaning the person or company publishing the content professionally — must add a label that humans can actually see.
That makes the EU the only one of the three legal systems that places an obligation directly on the desk of the person publishing. Anyone in Germany who puts a deepfake into a piece of content, or publishes an AI-written text on a matter of public interest, has to act themselves and, when in doubt, document themselves that a human reviewed the text. The fines for violating Article 50 run up to €15 million or 3 percent of worldwide annual turnover, whichever is higher. For small and medium-sized companies, the lower amount applies.
Then there's the reach of the law. Under Article 2, the regulation also applies to providers and operators from third countries once the output of their AI system is used in the Union. A blog based in Texas with German readers falls under this, at least by the letter of the law. Who is actually supposed to enforce that is another matter entirely.
Why technology alone won't solve the problem
All three legal systems rely on the same technical foundation. The industry standard C2PA writes provenance data into the file itself: which model, which version, which date, plus a cryptographic signature. As long as the file stays unchanged, this works.
In everyday use, it rarely stays unchanged. A screenshot creates a brand-new file with no history at all. Many content management systems resize uploaded images into smaller variants and strip out metadata in the process, because that saves loading time. Messaging apps compress files, platforms convert them into their own formats. At the end of that chain sits an image that no longer reveals anything about its origin.
The Commission's Code of Practice draws the obvious conclusion and requires providers to use at least two layers of marking, for instance metadata plus a watermark embedded in the image signal itself. Even that isn't foolproof, since anyone determined to strip a watermark can find tools to do it. That's why visible labeling by the person publishing isn't just an add-on — it's the only layer that actually survives a screenshot. That explains why Brussels insists on it, and it doesn't make the burden on creators any lighter.
The underlying problem is real
The numbers speak against the suspicion that Brussels is inventing a problem. A study by Stanford University, Imperial College London, and the Internet Archive from April 2026 analyzed crawl data from mid-2025. The result: 35 percent of new websites were AI-generated or AI-assisted. 74.2 percent of new pages contained some AI-generated content.
The third figure is the interesting one. Only 2.5 percent of new pages were pure AI output. The vast majority are mixed texts, where humans and machines worked together. An analysis by the consulting firm Graphite arrives at a similar picture for articles: the share of texts classified by detectors as predominantly machine-written rose to roughly half by the end of 2024 and then held steady. The analysis covered more than 55,000 English-language pages, checked with three different detection systems.
The widely cited 2023 prediction that 90 percent of all online content would be machine-generated by 2026 didn't come true. The web hasn't been flooded — it's been blended.
And that's exactly where the rule's weakness lies. It grips most firmly on purely AI-generated content, which at 2.5 percent is the rarest category of all. For the mixed texts that make up three-quarters of the new web, everything hinges on two vague legal terms: whether the AI merely assisted, and whether a human substantively reviewed the result. Publishers have to make that judgment call themselves, and both terms will only really be defined once courts weigh in.
Assessment
My own take, clearly marked as such: the EU identified a real problem and then sent the bill to the wrong people. A provider with billions in revenue builds provenance data into the model once and is done with it. A solo creator has to classify every image edit, keep review logs, test her publishing pipeline for metadata loss, and weigh, for every how-to article she writes, whether the topic counts as a matter of public interest. The burden scales down, not up.
That the Commission recognizes this burden problem is evident from the Digital Omnibus. In June 2026 it pushed back the obligations for high-risk systems by 16 months, explicitly justifying the package in terms of simplification and competitiveness. It left Article 50 untouched, apart from a four-month delay for machine-readable marking of older systems.
The counterargument deserves space too: without an obligation on publishers, labeling stays toothless, because machine-readable markers vanish the moment someone takes a screenshot. Anyone who wants readers to actually recognize a deepfake as one has no way around a visible notice — and only the person publishing can add that. California doesn't solve this problem; it just pushes it onto the platforms, and onto 2027.
What happens in the coming months
On December 2, 2026, the grace period ends for generative systems that were already on the market before the cutoff date. From then on, every output must carry a machine-readable marker. On January 1, 2027, the platform-level rules kick in in California. Whether the Bundesnetzagentur, which has overseen this in Germany since the KI-MIG came into force, will open proceedings or simply offer guidance in its first year remains to be seen. So far, none have become public.
What I can't tell you is whether labeling will actually restore the trust that the recital invokes. With 74 percent of content being a mix, a label might, in the end, be the weakest of all possible answers. Then again, so far nobody has come up with a better one.
Sources
- EU AI Act, Recital 133
- AI Act Service Desk: Article 2, Scope
- European Commission: FAQ on the transparency obligations under Article 50
- Morgan Lewis: New California AI Disclosure Rules Become Operative
- Covington: China Releases New Labeling Requirements for AI-Generated Content
- Loeb & Loeb: China's AI-Labeling Measures Take Effect September 1
- House of Commons Library: AI content labelling, briefing dated January 20, 2026
- Tech Policy Press: Where State AI Legislation Stands Half Way Into 2026
- Paul Hastings: Executive Order Challenging State AI Laws
- Study by Stanford, Imperial College London, and the Internet Archive on the share of AI content on the web
- Graphite analysis on the share of AI-generated articles
- Deloitte: Changes to the EU AI Act under the Digital Omnibus on AI