EU now requires AI labeling for many AI-generated images, videos and audio. Missing the required AI labeling? Here are your possible defenses.
As of August 2, 2026, the EU AI Act requires deployers of AI systems in a lot of cases to disclose when image, audio or video content has been artificially generated or manipulated by AI ("deepfakes").
These rules do not apply only to European organizations. U.S. businesses and nonprofits may also be covered whenever they use AI-generated content in connection with activities that reach the EU. For example, a U.S. company that publishes an AI-generated recruiting video for positions in Europe, posts AI-generated marketing videos targeting EU customers, or uses AI-generated content on an EU-facing website may qualify as a deployer under the AI Act and become subject to these disclosure requirements.
My recent article explains why these new rules affect far more organizations than many businesses expect.
What happens if the required AI labeling is missing?
The AI Act authorizes administrative fines of up to €15 million or 3% of worldwide annual turnover, although these are maximum amounts and any penalty will depend on the circumstances, as well as on which national or EU authority initiates the enforcement proceeding.
For many organizations in the US, private enforcement is likely to present the more immediate risk. Competitors and trade associations may argue that the AI Act's transparency obligations constitute market conduct rules under national unfair competition laws and seek cease-and-desist orders or other remedies. At least during the initial phase of the AI Act, many businesses are more likely to receive such a claim than become the subject of a regulatory investigation.
If you receive such a claim, possible defenses will always depend on the facts. They may include:
- The content was created before the disclosure obligation became applicable on August 2, 2026.
- The organization was not the deployer of the AI system that generated or manipulated the content. Rather, the content originated from a third party without any indication that it had been AI-generated, provided the organization can credibly document its provenance and the circumstances under which it obtained the content.
In all cases, it helps that the organization maintained reasonable compliance procedures and records demonstrating when the content was created, where it originated, and why it reasonably concluded that the applicable disclosure requirements had been satisfied. The rules are complicated. Especially for texts, corporate communications departments using AI-drafted materials should assess whether their editorial review meets the substantive requirements of the AI Act. Also note Article 50(1) that concerns disclosures if chatbots and other AI systems interact with humans.
As with many new regulatory requirements, you should observe the actual enforcement practice.
For more on the surprisingly broad scope of these new EU rules, see my earlier article:
Disclaimer: the information contained in the Potomac Law Group website is provided for informational purposes only, and should not be construed as legal advice on any subject matter.
No recipient of content from this site, client or otherwise, should act or refrain from acting on the basis of any content included in the site without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from an attorney licensed in the recipient’s state.

