.png)
How to Handle AI-Generated Content

On 2 August 2026 the EU AI Act's transparency rules start applying. Here's what changes for you, and the guideline our teams at DieProduktMacher (DPM) now work from.
Say a campaign goes live next week. Half the visuals came out of a generative model. One of them is a photorealistic shot of a doctor in a clinic, and it runs across your homepage and your paid social.
Three questions you need answered before that ships. Who owns the image? Who's liable if it turns out to resemble a real person or someone else's brand? And does it need a label?
From Sunday the third question has a legal answer attached to it. The first two have had answers for a while. Here's how we work through all three, in case it helps with your own setup.
What Changes on 2 August
Article 50 of the EU AI Act starts applying. It sets transparency obligations for two roles: providers, meaning the companies behind the models like Google or Midjourney, and deployers, meaning whoever uses the output and puts it in front of people. That second role is us, and maybe also you.
The Digital Omnibus package pushed several high-risk AI deadlines out to 2027 and 2028. Article 50 wasn't one of them. It applies on schedule.
Breaching it carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs, whichever is lower. In Germany you should also expect the faster, cheaper enforcement route: warning letters from competitors and consumer associations.
Enforcement sits with the Bundesnetzagentur. The Bundestag passed the national implementing act on 11 June 2026, and the agency runs a free service desk for compliance questions aimed particularly at smaller companies. Worth using before you need a lawyer.
The Question Is Whether It's a Deep Fake
Not everything is affected. The disclosure duty for deployers covers two things:
Deep fakes. AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events, and would falsely appear to someone to be authentic. Intent is irrelevant. If you weren't trying to deceive anyone, the label is still required. So it’s about the detail. Could it be perceived as a real person?
AI-generated text published to inform the public on matters of public interest, where nobody reviewed it and no person or company took editorial responsibility. If a human editor checks it and stands behind it, the duty falls away. For most commercial copy that's the normal case. For a formal corporate announcement, check twice.
Our internal review boiled the visual side down to three questions. For us, three yeses means it's a deep fake and gets labelled:
- Does the content show a person, product, place or event that a viewer could perceive as real?
- Was it generated or modified with an AI tool?
- If it was modified, does that editing go beyond a minor technical change?
What counts as a deep fake: a mood image with photorealistic people who don't exist. A real product shot dropped into an AI-generated environment. A genuine photograph of a real place edited with AI in a way that changes what a viewer would believe about it.
What doesn't: purely graphic content with no people, objects or places in it. Anything that breaks physics or biology, so humans flying unaided, dragons, elephants driving cars. And minor technical edits to existing material: colour correction, lighting adjustments, noise reduction, background details, audio parameters, accessibility improvements, file compression.
There's also a carve-out for evidently artistic, creative, satirical or fictional work. There the disclosure has to happen in a way that doesn't wreck the experience of the piece.
Sidenote: None of that changes ownership. A dragon still has no copyright holder. And you're still responsible if it infringes someone.
The Labels We Use
We standardised the vocabulary across files, client comms and the labels themselves into three categories:
For the public-facing label we use the EU icon set. The Commission published it in June 2026: a basic AI icon plus icons for fully AI-generated and partially AI-modified content, free, in four colour variants, and user-tested. They perform noticeably better with a short text label beside them.
We recommend starting with the basic icon and moving to the specific ones where that's clearer for the recipient. When the classification is genuinely borderline, we label it "AI-Generated", because that's the safer position to defend.
Worth being explicit: the icons are optional, the labelling duty isn't. Using the icon doesn't establish compliance on its own.

How We Run It Day to Day
Source lives in the filename. An image generated with Gemini already carries that in its name, so we keep it. Figma AI doesn't, so anything generated there gets renamed to XXX_FigmaAI immediately after creation. The AI category goes into the filename too.
No track record, no use. An image nobody can trace either doesn't go in, or gets flagged in the layout as "not approved for use". Without that rule, everything else on this list becomes guesswork.
Documentation scales with client sensitivity. The more regulated the client, the more we document and the earlier. Digital health sits at one end of that scale.
Handover is explicit. Clients receive labelled assets plus a note on what was generated, what was edited. That's how liability stays clear on both sides.
The training goes wider than the design team. One session for everyone, a deeper one for the people generating images daily. Both recorded, because whoever joins in six months needs the same grounding.
The guideline has a review cadence. The Act is still rolling out, the Commission published further guidance in July, and industry practice is moving. A document written once and filed is worse than none, because people trust it.
What to Do This Week
Pull an inventory of the AI-generated visuals currently live on your properties. Most organisations underestimate this number.
Run the three-question test over them. You'll probably find the number needing a label is smaller than feared, and the number with no traceable source is larger.
Decide who signs off on photorealistic AI imagery, and write the name down.
Ask every agency and freelancer for their AI guideline in writing. If they don't have one three days out, that tells you something.
And if you've had a logo or key visual generated: check what's actually protected. The trademark route is probably open. The copyright almost certainly isn't.
This is the approach we work to across client projects. If you want to compare notes on how you're handling it, we're happy to talk.
*This article describes how we handle AI-generated content at DPM. It's knowledge sharing based on our own processes and our internal review, not legal advice. We're a product and design consultancy, not a law firm. For binding guidance on your specific situation, talk to a qualified lawyer.
Further Reading
- EU icons for labelling AI-generated content, European Commission
- Code of Practice on marking and labelling of AI-generated content, European Commission
- Leitfaden zur Kennzeichnung von KI-generierten Texten und Bildern, Mittelstand-Digital Zentrum Berlin
- Was müssen Unternehmer rechtlich beachten, wenn sie KI im Marketing einsetzen?, e-recht24
- Künstliche Intelligenz, Regelungen der KI-Verordnung, IHK Köln
- KI-Inhalte ab 2026: Diese Kennzeichnungspflichten gelten künftig, offizium/next

.avif)