Since 2 August 2026, the EU AI Act requires AI-generated content to be flagged. This article stays practical: what does it actually mean for you?
Let’s clear the air straight away: the bulk of the marking burden sits with the tool providers (OpenAI, Microsoft, Google and the rest), not with the companies using them. And for a Swiss company, these rules only apply if its systems or its content reach the European market. What genuinely remains yours: deepfakes, and public-interest texts published without real editorial control. Your emails, reports and internal documents are not covered, even if a certain ethic still applies.
We keep it simple here, and there is a small plug & play kit for IT managers further down 👇
- Since 2 August 2026, Article 50 of the AI Act applies: AI-generated content must be identifiable, chatbots must disclose that they are AI, deepfakes must be flagged.
- Technical marking (an invisible, machine-readable signature inside the file) is the job of the AI tool providers. If you use ChatGPT, Copilot or Gemini, that part is on them, not on you.
- Your company is concerned as a deployer in specific cases: deepfakes, public-interest texts published without genuine editorial control, and emotion recognition or biometric categorisation systems. For a chatbot, informing the user falls first on the system’s provider.
- A Swiss company is only in scope if its systems or AI outputs are used in the European Union. With no link to the EU market there is no direct obligation, but the practice is becoming the standard.
- Penalties can reach 15 million euros or 3 % of worldwide annual turnover.
What changed on 2 August 2026
The AI Act, the European regulation on artificial intelligence, has been phasing in since 2024. On 2 August 2026, an important milestone took effect: the transparency obligations of Article 50. In plain terms, the European Union wants people to know when they are dealing with an AI, or with content it produced.
Concretely, three families of obligations:
- Systems that talk to people (chatbots, voice assistants, avatars) must clearly indicate that they are AI, unless it is already obvious, for instance stated directly in the interface.
- Synthetic content (text, images, audio, video generated by AI) must be marked in a machine-readable format, so it remains detectable as artificial.
- Deepfakes and certain published texts must carry a disclosure visible to the reader.
What does that disclosure actually look like? A line reading “AI-generated content” under a video or at the top of an article, a discreet label in the corner of an image, a note in a post’s description. Nothing dramatic: a clear indication the reader sees on first viewing.
To support the shift, the European Commission published a voluntary code of practice, signed at the end of July by around 190 organisations, including the major model providers (OpenAI, Microsoft, Google, Anthropic, Mistral) and large deploying companies (Lufthansa, Getty Images, Lenovo). It also offers official icons (“AI-generated”, “AI-modified”…) that anyone may use.
There is a transition window: generative AI systems already on the market before 2 August have until 2 December 2026 to comply with the machine-readable marking obligation.
Provider or deployer: who does what
This is the distinction that changes everything, and the one headlines tend to skip. The AI Act separates two roles.
The provider is whoever develops and makes the AI system available: OpenAI for ChatGPT, Microsoft for Copilot, Google for Gemini. Setting up machine-readable marking of generated content is their responsibility. In other words, your company does not have to build that technology itself. Do not assume, however, that every tool and every output format is already compliant, especially during the transition period running to 2 December 2026.
The deployer is the company using the system in its activity. Its obligations are far more targeted, and come down to three cases:
| Case | Your obligation |
|---|---|
| You publish a deepfake (content resembling a real or plausible person, object, place or event closely enough to be taken as authentic) | Disclose that the content was generated or manipulated by AI, discreetly if the work is evidently artistic or satirical |
| You publish an AI-generated text on a matter of public interest (politics, public health, consumer safety…) without genuine editorial control | Disclose that the text is AI-generated |
| You expose people to an emotion recognition or biometric categorisation system | Inform the people concerned that the system is in operation |
And the chatbot? The duty to disclose that it is an AI falls first on its provider, who must design the system accordingly. It becomes yours if you develop or offer the bot under your own name. Either way, check that the one you deploy states it clearly.
And that is roughly it for your own obligations as a deployer. The rest, the vast majority of day-to-day AI use in a company, is not covered.
What about hybrid content, AI plus human control?
This is by far the most common case: a report structured with ChatGPT then substantially reworked, an article whose first draft came from AI, a summary generated then verified line by line. Good news: where a public-interest text has undergone genuine substantive review or editorial control, and a natural or legal person takes editorial responsibility for its publication, no disclosure is required. That exemption is written into the regulation itself. One caveat: a quick read-through, a spell-check or a stylistic tweak is not enough. The review must address the substance, meaning the facts, the sources, the reasoning and the conclusions.

Good practice comes down to two habits: an identified reviewer who checks the substance of everything going out to the public, and the freedom to add, if you want transparency beyond the obligation, a note along the lines of “AI-assisted”. Optional, but readers appreciate it. It is, incidentally, what we do at the bottom of our own articles.
What about a Swiss company?
The AI Act is a European regulation, but it has extraterritorial reach: it also applies to companies in third countries, Switzerland included, as soon as their AI systems are placed on the European market or their outputs are used in the European Union.
Three profiles to place yourself:
- A purely Swiss SME, Swiss clients, content aimed at the Swiss market: no direct obligation under the AI Act. Nothing legally urgent, though Switzerland is preparing its own framework, more on that below.
- An SME with clients or subsidiaries in the EU, or whose AI outputs are intended to be used in the EU (a newsletter deliberately sent to European subscribers, a site explicitly targeting the European market): the transparency obligations apply to that content. Mere worldwide accessibility of a website is not, on its own, enough to bring you into scope.
- A company placing an AI system on the EU market under its own name or trademark: it carries the provider’s obligations, including technical marking.
Two reasons to care even without an EU link. First, marking AI content is becoming the de facto standard: tools build it in, platforms are starting to detect it, audiences are getting used to it. Second, Switzerland is preparing its own approach: it signed the Council of Europe Convention on AI on 27 March 2025 and has opted for mainly sector-specific regulation, complemented by cross-cutting rules (transparency, data protection), with a draft expected to go to consultation by the end of 2026. Companies that build good habits now will have nothing to catch up on.

In practice: your images, your emails, your reports, your website
The test to apply is simple: does it leave the company, and has someone reviewed and taken responsibility for it? Let’s run through the common cases.
| Your content | Disclosure required? |
|---|---|
| An email drafted with Copilot or ChatGPT | No. Internal communications and correspondence are not covered. |
| A report or client proposal prepared with AI, then reviewed and approved by a colleague | No. Genuine substantive review with editorial responsibility covers you. |
| A text published without genuine editorial control, to inform the public on a matter of public interest (politics, health, consumer safety…) | Yes, if it is aimed at the EU. Substantive review under responsibility lifts the obligation. |
| A product page or commercial landing page written with AI | No. It is not a public-interest text within the meaning of the regulation. |
| An AI illustration in an evidently artificial style (abstract, isometric visual) | No visible disclosure required. Machine-readable marking is the tool provider’s job. A note remains good practice where confusion is possible. |
| An image, audio or video resembling a real (or plausible) person, place or event that could be taken as authentic | Yes. That is a deepfake under the regulation: disclosure required, discreet if the work is evidently artistic or satirical. |
| A chatbot on your site, a voice agent on the phone | Yes. It must present itself as an AI from the first interaction: its provider’s duty, yours if it is offered under your name. |
The overall logic is sound: the legislator is not trying to find out whether your teams use AI to work, it is trying to prevent the public from being misled by artificial content passing itself off as authentic.
Where to start: the IT manager’s light plan
No compliance programme needed. Four steps, two of which fit into a single meeting.
- Inventory what goes out. List the places where AI produces content that leaves the company: website, social media, newsletters, marketing images, chatbot, videos. Internal use can wait, it is not covered.
- Settle the EU question. One question for management or legal: do our AI content or services reach the European market? The answer drives everything else, and it takes an hour, not a three-month audit.
- Add a transparency section to your AI policy. Three lines will do: who discloses what, with which wording, and who reviews what goes out to the public. If you do not have an AI policy yet, this is the moment: it is the same document that frames shadow AI, and we will devote a dedicated article to it in the coming weeks.
- Brief your teams, in one short session. The message fits into three reflexes: the cases where you disclose (deepfake, public-interest text without substantive review, a chatbot under your name), the habit of reviewing substance before publishing, and who to ask when in doubt. An informed team applies these rules without thinking about them.
Don’t overdo it
The risk with new regulation is tipping into excess zeal: stamping “AI-generated” on every document, keeping registers of every prompt, having people sign waivers. None of that is being asked.
The editorial control exemption is the central safeguard: content worked on with AI, then reviewed on substance and owned under editorial responsibility, is ordinary editorial content. That is exactly what you already do for anything carrying your company’s name. For an SME using off-the-shelf tools and publishing neither deepfakes nor public-interest texts without editorial control, compliance stays targeted and proportionate: documenting three simple decisions (which tools we use, which content we label, who reviews substance before publication) is essentially all of it.
The aim of the text is public trust, not paperwork for companies.
FAQ
Do I have to label emails written with ChatGPT or Copilot?
Is a Swiss company with no European clients concerned?
Do we need “AI-generated” on all our marketing images?
Does a report written with AI and then reviewed need a disclosure?
What is the code of practice signed by 190 organisations?
What is the risk of non-compliance?
PrismIA helps organisations in French-speaking Switzerland use AI with confidence: mapping actual usage, AI policies and team training. Discover our AI training · Audit and consulting.
Sources
- European Commission, guidelines on transparency obligations (Article 50)
- European Commission, code of practice on the transparency of AI-generated content (31 July 2026)
- Regulation (EU) 2024/1689 (AI Act), official text on EUR-Lex, as amended by Regulation (EU) 2026/1744 (which does not change the transparency obligations applying from 2 August 2026)
- CDBF, application of the AI Act to Swiss companies
- Swiss Federal Council, AI regulation and the Council of Europe Convention