Spotting and correctly labelling AI content
How to recognize AI-generated images, text and voices and when you have to label your own AI content from August 2026. Explained practically for solo founders with no legal department.
Two things are happening at the same time right now. AI content is getting so good that you can barely recognize it with the naked eye, and the legislator is tightening the transparency obligations. If you use AI yourself, say for images or texts on your site, both concern you. You want to know whether a piece of content is real, and you want to be on the safe side when you publish your own AI content. This playbook takes you through both, in ten steps and without legalese.
One thing up front, so it's clear what we're relying on. The dates and obligations named here come from the EU AI Act, the sources are at the end. This is not legal advice, but an orientation. In case of real doubt, you ask someone with a robe.
Step 1, why this is becoming important now
The EU AI Act brings transparency obligations for AI content in Article 50. The central paragraphs 50(2) and 50(4) apply from August 2, 2026. For systems that were already on the market before that, there's a transition period until December 2, 2026. Alongside, on June 10, 2026, the EU Commission published a Code of Practice on the transparency of AI content, that is, a practical guide for what marking and labelling should look like. Meaning for you: this is no longer a future topic, it kicks off in a few weeks.
Step 2, understanding the invisible watermark
The big providers build watermarks directly into the image. Google uses SynthID, which marks AI-generated images invisibly and also survives cropping or light editing. You don't see it with your eye, but suitable check tools recognize it. So if you want to know whether an image comes from a Google model, SynthID is your first port of call. Other providers have their own methods, a uniform standard across all tools is still missing.
Step 3, checking Content Credentials and metadata
Many AI images carry so-called Content Credentials following the C2PA standard, that's a kind of digital package insert that records what an image was created with and how it was edited. Upload a suspicious image to a Content Credentials checker and see whether an origin is stored. Alongside that, a look at the file's metadata is worthwhile. Careful, metadata often disappears as soon as an image runs through social media, the platforms strip it out. So a missing entry proves nothing, an existing one all the more.
Step 4, watching for the classic mistakes, but carefully
You used to recognize AI images by six fingers and melting text. That works worse and worse, the current models paint clean hands and readable text. Don't rely on it anymore. What still sometimes helps are impossible reflections, backgrounds that repeat on close inspection, or jewelry and buttons that don't match. Treat that as a weak indication, not as proof.
Step 5, using detector tools with skepticism
There are services that claim to reliably recognize AI texts or images. Take their result as a hint, never as a verdict. These tools are regularly wrong, both false positive and false negative. With texts in particular this is critical, even a few human changes flip the result. If a tool shows you a 70 percent AI probability, that doesn't mean it's 70 percent correct. Use several signals together, not a single tool.
Step 6, voices and videos are the trickiest case
Voice cloning and video deepfakes are by now so good that the ear and the eye no longer suffice. If someone asks you for money or access by voice message or video call, the AI question has become real. The simplest defense isn't technical but a second channel. Call back, ask something only the real person can know, agree on a code word in the team. Technical deepfake detection exists, but for you as a solo founder the second channel is the more practical protection.
Step 7, clarifying your own duty as a user
Now the other side. As soon as you publish AI content yourself, you can be subject to a labelling obligation under Article 50 in the role of the user, called deployer in the law. This concerns above all two cases, AI-generated or heavily altered image, audio and video content with a public reference, and deepfakes of real people. Purely internal use or obviously artistic editing are to be assessed differently. The exact delineation is part of what the Code of Practice and the guidelines clarify. For you that means: assume that public AI content should be labelled, until you know the opposite for certain.
Step 8, labelling cleanly in practice
Labelling doesn't have to be complicated. A clear note on the content is enough in most everyday cases, for example "Image created with AI" in the caption or a note in the imprint area for your site's image sources. Just leave the providers' machine-readable marking, meaning SynthID or Content Credentials, in there, don't delete it on purpose. That way you fulfill the technical part with no extra effort. The human-visible note you add where the content appears.
Step 9, setting a mini-process for your business
So you don't have to think anew every time, set three rules. First, every AI image that goes public gets a labelling note. Second, incoming images and voices from strangers you treat as possibly AI-generated, especially when it's about money or access. Third, you briefly document what you created with what, a simple list is enough. These three rules cost you a few minutes a week and spare you trouble later.
Step 10, staying on it, the topic is moving
The situation is changing monthly right now. The Code of Practice of June 10, 2026 is new, the guidelines are still being sharpened, and with the deadline of August 2, 2026 comes the first real test. Set yourself a reminder to look at the topic again in late summer. Whoever works cleanly early has nothing to correct later, and that's exactly the cheapest way through a new regulation.
What comes next
If you make AI images yourself, AI images for your brand is the matching practice playbook for it. For the full legal overview in the DACH region, go to EU AI Act and GDPR for the DACH region. And whoever wants to understand why AI models even invent things and how to recognize it, reads the lesson Hallucinations.
Sources
- EU AI Act, transparency rules Article 50: https://artificialintelligenceact.eu/transparency-rules-article-50
- Article 50 transparency guide, effective dates and Code of Practice: https://euaicompass.com/eu-ai-act-article-50-transparency-guide.html
- Google DeepMind, SynthID watermark in Nano Banana Pro: https://deepmind.google/models/gemini-image/pro