Labelling AI content: what is actually mandatory for a Swiss company

Since 2 August 2026, the EU AI Act requires AI-generated content to be flagged. Sorting out what is mandatory, what is exempt, and what is simply good practice for a Swiss company.
Partager cet article :
Illustration isométrique : une presse appose un badge aux douze étoiles européennes sur une série de documents, palette bleue PrismIA

Dans cet article

Podcast

🎧 Listen to this article · approx. 4 min

Since 2 August 2026, the EU AI Act requires AI-generated content to be flagged. This article stays practical: what does it actually mean for you?

Let’s clear the air straight away: the bulk of the marking burden sits with the tool providers (OpenAI, Microsoft, Google and the rest), not with the companies using them. And for a Swiss company, these rules only apply if its systems or its content reach the European market. What genuinely remains yours: deepfakes, and public-interest texts published without real editorial control. Your emails, reports and internal documents are not covered, even if a certain ethic still applies.

We keep it simple here, and there is a small plug & play kit for IT managers further down 👇

The essentials in 30 seconds
  • Since 2 August 2026, Article 50 of the AI Act applies: AI-generated content must be identifiable, chatbots must disclose that they are AI, deepfakes must be flagged.
  • Technical marking (an invisible, machine-readable signature inside the file) is the job of the AI tool providers. If you use ChatGPT, Copilot or Gemini, that part is on them, not on you.
  • Your company is concerned as a deployer in specific cases: deepfakes, public-interest texts published without genuine editorial control, and emotion recognition or biometric categorisation systems. For a chatbot, informing the user falls first on the system’s provider.
  • A Swiss company is only in scope if its systems or AI outputs are used in the European Union. With no link to the EU market there is no direct obligation, but the practice is becoming the standard.
  • Penalties can reach 15 million euros or 3 % of worldwide annual turnover.

What changed on 2 August 2026

The AI Act, the European regulation on artificial intelligence, has been phasing in since 2024. On 2 August 2026, an important milestone took effect: the transparency obligations of Article 50. In plain terms, the European Union wants people to know when they are dealing with an AI, or with content it produced.

Concretely, three families of obligations:

  1. Systems that talk to people (chatbots, voice assistants, avatars) must clearly indicate that they are AI, unless it is already obvious, for instance stated directly in the interface.
  2. Synthetic content (text, images, audio, video generated by AI) must be marked in a machine-readable format, so it remains detectable as artificial.
  3. Deepfakes and certain published texts must carry a disclosure visible to the reader.

What does that disclosure actually look like? A line reading “AI-generated content” under a video or at the top of an article, a discreet label in the corner of an image, a note in a post’s description. Nothing dramatic: a clear indication the reader sees on first viewing.

To support the shift, the European Commission published a voluntary code of practice, signed at the end of July by around 190 organisations, including the major model providers (OpenAI, Microsoft, Google, Anthropic, Mistral) and large deploying companies (Lufthansa, Getty Images, Lenovo). It also offers official icons (“AI-generated”, “AI-modified”…) that anyone may use.

There is a transition window: generative AI systems already on the market before 2 August have until 2 December 2026 to comply with the machine-readable marking obligation.

Provider or deployer: who does what

This is the distinction that changes everything, and the one headlines tend to skip. The AI Act separates two roles.

The provider is whoever develops and makes the AI system available: OpenAI for ChatGPT, Microsoft for Copilot, Google for Gemini. Setting up machine-readable marking of generated content is their responsibility. In other words, your company does not have to build that technology itself. Do not assume, however, that every tool and every output format is already compliant, especially during the transition period running to 2 December 2026.

The deployer is the company using the system in its activity. Its obligations are far more targeted, and come down to three cases:

Case Your obligation
You publish a deepfake (content resembling a real or plausible person, object, place or event closely enough to be taken as authentic) Disclose that the content was generated or manipulated by AI, discreetly if the work is evidently artistic or satirical
You publish an AI-generated text on a matter of public interest (politics, public health, consumer safety…) without genuine editorial control Disclose that the text is AI-generated
You expose people to an emotion recognition or biometric categorisation system Inform the people concerned that the system is in operation

And the chatbot? The duty to disclose that it is an AI falls first on its provider, who must design the system accordingly. It becomes yours if you develop or offer the bot under your own name. Either way, check that the one you deploy states it clearly.

And that is roughly it for your own obligations as a deployer. The rest, the vast majority of day-to-day AI use in a company, is not covered.

What about hybrid content, AI plus human control?

This is by far the most common case: a report structured with ChatGPT then substantially reworked, an article whose first draft came from AI, a summary generated then verified line by line. Good news: where a public-interest text has undergone genuine substantive review or editorial control, and a natural or legal person takes editorial responsibility for its publication, no disclosure is required. That exemption is written into the regulation itself. One caveat: a quick read-through, a spell-check or a stylistic tweak is not enough. The review must address the substance, meaning the facts, the sources, the reasoning and the conclusions.

Illustration: a reviewer checks AI-generated text on screen, stamp in hand, next to a stack of already badged documents

Good practice comes down to two habits: an identified reviewer who checks the substance of everything going out to the public, and the freedom to add, if you want transparency beyond the obligation, a note along the lines of “AI-assisted”. Optional, but readers appreciate it. It is, incidentally, what we do at the bottom of our own articles.

What about a Swiss company?

The AI Act is a European regulation, but it has extraterritorial reach: it also applies to companies in third countries, Switzerland included, as soon as their AI systems are placed on the European market or their outputs are used in the European Union.

Three profiles to place yourself:

  • A purely Swiss SME, Swiss clients, content aimed at the Swiss market: no direct obligation under the AI Act. Nothing legally urgent, though Switzerland is preparing its own framework, more on that below.
  • An SME with clients or subsidiaries in the EU, or whose AI outputs are intended to be used in the EU (a newsletter deliberately sent to European subscribers, a site explicitly targeting the European market): the transparency obligations apply to that content. Mere worldwide accessibility of a website is not, on its own, enough to bring you into scope.
  • A company placing an AI system on the EU market under its own name or trademark: it carries the provider’s obligations, including technical marking.
Outlook

Two reasons to care even without an EU link. First, marking AI content is becoming the de facto standard: tools build it in, platforms are starting to detect it, audiences are getting used to it. Second, Switzerland is preparing its own approach: it signed the Council of Europe Convention on AI on 27 March 2025 and has opted for mainly sector-specific regulation, complemented by cross-cutting rules (transparency, data protection), with a draft expected to go to consultation by the end of 2026. Companies that build good habits now will have nothing to catch up on.

Illustration: a stamp marks documents one by one with a badge of European stars on a conveyor line

In practice: your images, your emails, your reports, your website

The test to apply is simple: does it leave the company, and has someone reviewed and taken responsibility for it? Let’s run through the common cases.

Your content Disclosure required?
An email drafted with Copilot or ChatGPT No. Internal communications and correspondence are not covered.
A report or client proposal prepared with AI, then reviewed and approved by a colleague No. Genuine substantive review with editorial responsibility covers you.
A text published without genuine editorial control, to inform the public on a matter of public interest (politics, health, consumer safety…) Yes, if it is aimed at the EU. Substantive review under responsibility lifts the obligation.
A product page or commercial landing page written with AI No. It is not a public-interest text within the meaning of the regulation.
An AI illustration in an evidently artificial style (abstract, isometric visual) No visible disclosure required. Machine-readable marking is the tool provider’s job. A note remains good practice where confusion is possible.
An image, audio or video resembling a real (or plausible) person, place or event that could be taken as authentic Yes. That is a deepfake under the regulation: disclosure required, discreet if the work is evidently artistic or satirical.
A chatbot on your site, a voice agent on the phone Yes. It must present itself as an AI from the first interaction: its provider’s duty, yours if it is offered under your name.

The overall logic is sound: the legislator is not trying to find out whether your teams use AI to work, it is trying to prevent the public from being misled by artificial content passing itself off as authentic.

Where to start: the IT manager’s light plan

No compliance programme needed. Four steps, two of which fit into a single meeting.

  1. Inventory what goes out. List the places where AI produces content that leaves the company: website, social media, newsletters, marketing images, chatbot, videos. Internal use can wait, it is not covered.
  2. Settle the EU question. One question for management or legal: do our AI content or services reach the European market? The answer drives everything else, and it takes an hour, not a three-month audit.
  3. Add a transparency section to your AI policy. Three lines will do: who discloses what, with which wording, and who reviews what goes out to the public. If you do not have an AI policy yet, this is the moment: it is the same document that frames shadow AI, and we will devote a dedicated article to it in the coming weeks.
  4. Brief your teams, in one short session. The message fits into three reflexes: the cases where you disclose (deepfake, public-interest text without substantive review, a chatbot under your name), the habit of reviewing substance before publishing, and who to ask when in doubt. An informed team applies these rules without thinking about them.

Don’t overdo it

The risk with new regulation is tipping into excess zeal: stamping “AI-generated” on every document, keeping registers of every prompt, having people sign waivers. None of that is being asked.

The editorial control exemption is the central safeguard: content worked on with AI, then reviewed on substance and owned under editorial responsibility, is ordinary editorial content. That is exactly what you already do for anything carrying your company’s name. For an SME using off-the-shelf tools and publishing neither deepfakes nor public-interest texts without editorial control, compliance stays targeted and proportionate: documenting three simple decisions (which tools we use, which content we label, who reviews substance before publication) is essentially all of it.

The aim of the text is public trust, not paperwork for companies.

FAQ

Do I have to label emails written with ChatGPT or Copilot?
No. Internal communications and business correspondence are not covered by the transparency obligation. It applies to certain content distributed to the public (deepfakes, public-interest texts).
Is a Swiss company with no European clients concerned?
Not directly. The AI Act applies to Swiss companies only if their AI systems are placed on the EU market or their outputs are used there. Adopting good practice is still advisable: Swiss regulation is on its way, and marking is becoming the standard.
Do we need “AI-generated” on all our marketing images?
No. The visible disclosure requirement targets deepfakes: content resembling real people, places or events that could be taken as authentic. An evidently artificial illustration needs no visible disclosure; its machine-readable marking is handled by the tool that produced it.
Does a report written with AI and then reviewed need a disclosure?
No, provided there is genuine substantive review (facts, sources, reasoning) and editorial responsibility is taken. A simple spell-check is not enough. This is the most common hybrid case in companies.
What is the code of practice signed by 190 organisations?
A voluntary framework published by the European Commission to help AI providers and deployers apply Article 50 consistently. Signing is not mandatory; it serves as a recognised reference for demonstrating compliance.
What is the risk of non-compliance?
The regulation provides for fines of up to 15 million euros or 3 % of worldwide annual turnover. In practice, the first risk for an SME is reputational: artificial content left unflagged that misleads its audience.
Take action

PrismIA helps organisations in French-speaking Switzerland use AI with confidence: mapping actual usage, AI policies and team training. Discover our AI training · Audit and consulting.

Sources

D'autres articles à explorer