Skip to content

RESOURCES / BLOG

The EU AI Act Is Here: What Every Organization Operating in the EU Using AI-Generated Images Needs to Know

AI-generated and AI-edited images have gone from novelty to everyday production tool. Marketing teams generate product backgrounds in seconds; ecommerce teams remove and replace objects at scale. 

As AI becomes a central part of publishing workflows, organizations are facing a new challenge: how do you maintain trust and transparency when AI plays a role in creating what your audience sees?

As of August 2, 2026, the EU AI Act offers a first detailed regulatory attempt to address this. Its transparency provisions, Article 50, apply to many organizations publishing digital content into the EU market, regardless of where it’s headquartered. 

This isn’t about restricting AI use. It’s about disclosure — making sure people and software alike can tell when content was created or modified with AI.

Organizations evaluating how to implement AI transparency measures are increasingly looking at how to operationalize provenance and disclosure across existing media workflows. 

If your organization publishes AI-generated or AI-manipulated images, audio, video, or text that reaches people in the EU, Article 50 may apply under certain cases, even if you’re not building or deploying a high-risk AI system.

Article 50 contains different transparency provisions for different categories of AI systems and content. Organizations should assess which, if any, are relevant to their own activities. The EU Act doesn’t treat all AI-generated content the same way. Article 50 covers four distinct scenarios, each with its own obligation:

When This Happens…This is Required
An AI system interacts directly with a person (chatbot, voice assistant)Users must know they’re interacting with AI
An AI system generates or manipulates images, audio, video, or text, substantially altering contentOutputs must be machine-readable as AI-generated or AI-manipulated
An AI system performs emotion recognition or biometric categorizationThe people subject to it must be informed
AI content qualifies as a deepfake, or AI text on a public-interest matter is published without human reviewThe publisher must clearly disclose this

The AI Act focuses on transparency at a few different levels, which serve two audiences through two mechanisms.

Human TransparencyMachine Transparency
Lets viewers know content contains AILets software understand provenance
Visible labelsMetadata
Helps consumersHelps platforms, search engines, verification tools

Article 50 contains different transparency mechanisms, including machine-readable technical measures in some situations and human-facing disclosures in others. Which mechanism is relevant depends on the applicable provision and the particular use case. Visible, human-facing labels are reserved for content that could genuinely mislead viewers, like deepfakes resembling real people or events, and AI text on public-interest topics published without meaningful human review.

The AI Act also recognizes that certain AI-assisted editing may fall outside some transparency obligations where the semantic content of the original material is not substantially altered. That means an AI-assisted edit that doesn’t materially change what an image communicates — removing a stray object, adjusting a background, adding a drop shadow — may be treated as  a different category than fully synthetic or identity-altering content. Whether that applies depends on the specific circumstances.

“Machine-readable marking” is like a chain of custody that travels with the file. It’s meant to answer where an image came from, whether AI was involved, and what changes were made to the original.

The Act doesn’t require the use of a specific technology. Instead, it asks for marking that’s robust, interoperable, and detectable, leaving implementation open. However, the Code of Practice on Transparency of AI-Generated Content, published in June 2026 by the European Commission as guidance, encouraged technical approaches that support interoperability and machine-readable provenance.  

These guidelines provide more concrete implementation measures and have been confirmed by the European Commission as adequate for demonstrating Article 50 compliance.

One standard has emerged as the practical default for tracking this information is C2PA (Coalition for Content Provenance and Authenticity). It gives organizations a standardized way to attach trusted provenance data to media assets — and preserve that data as those assets move between tools, teams, and platforms.

That information is packaged as Content Credentials, a verifiable, portable record of an asset’s history. While C2PA isn’t named in the regulation, its broad adoption across the technology and media industries has made it one of the leading implementations of machine-readable provenance.

The EU AI Act is currently the most comprehensive law of its kind, but it’s not likely to be the last word on AI transparency. Other governments are exploring similar approaches, and major technology companies — like Google, Meta, and OpenAI — are voluntarily adopting provenance standards such as C2PA to help establish trust in digital content.

Google Photos, for example, now displays a “How this was made” section for supported images, showing details about an image’s origin, edit history, and whether AI tools were used. As more platforms expose this kind of information, and consumers become more aware of AI-generated media, transparency is becoming part of modern digital publishing — not just another regulatory requirement.

None of this requires rebuilding a pipeline overnight, but it does mean treating transparency as a standing part of asset management rather than a one-off task.

ActionWhy It Matters
Identify which assets are AI-generated or AI-edited.You can’t apply transparency workflows to content you haven’t tagged.
Preserve provenance metadata through your pipeline.Keeps a defensible record of an asset’s history intact.
Support machine-readable disclosure at the platform level.Lets downstream tools detect AI involvement automatically.
Add visible disclosures where actually required.Meets the narrower obligation tied to deepfakes and public-interest content.
Review where AI enters existing publishing workflows.Surfaces gaps before they become compliance or trust issues.

AI transparency is a technical question as much as it is a legal one. While organizations have to determine their own compliance obligations, Cloudinary provides the infrastructure to help operationalize transparency across their existing media workflows. These capabilities include:

Not every AI-generated or AI-edited asset requires the same treatment. When visible disclosures are appropriate, Cloudinary can apply AI disclosure badges or labels dynamically at delivery time rather than permanently modifying the original asset.

That approach offers several practical advantages:

  • The original asset remains unchanged.
  • Disclosures can be updated centrally as requirements evolve.
  • Different regions or use cases can receive different disclosure treatments.
  • There’s no need to generate and manage duplicate versions of the same media.
  • Automatically adjust the marking (size and location) to the asset version (size, aspect-ratio, etc.)

Cloudinary supports the C2PA standard for Content Credentials, enabling organizations to preserve and attach tamper-evident provenance information to supported assets. Depending on the workflow, Content Credentials can record information such as:

  • Whether AI was used during content creation or editing.
  • The sequence of transformations applied to an asset.
  • The organizations or tools that handled the asset throughout its lifecycle.
  • Cryptographically verifiable provenance information that compatible tools can inspect.

Rather than replacing visible disclosures, Content Credentials complement them by providing machine-readable provenance that helps software understand how digital content was created and modified.

Cloudinary manages AI-generated and traditional media within the same platform, allowing organizations to apply consistent governance, search, lifecycle management, and delivery workflows across their media libraries

Instead of introducing a separate process for AI-generated assets, teams can incorporate transparency into the workflows they already use to manage visual content at scale.

In Cloudinary, an AI disclosure becomes just another transformation applied at delivery. That means organizations can introduce, update, or regionalize disclosures without modifying the original asset or creating duplicate files. As transparency requirements evolve, existing media workflows can evolve with them.

The EU AI Act is only one step in a broader shift toward AI transparency. As organizations prepare for that future, Cloudinary can help incorporate transparency into existing media workflows — without fundamentally changing how assets are stored, transformed, or delivered.

See how Cloudinary supports AI transparency with Content Credentials, provenance, and dynamic media workflows. Schedule a personalized demo.

Start Using Cloudinary

Sign up for our free plan and start creating stunning visual experiences in minutes.

Sign Up for Free