The EU AI Act and your images: what actually changed on August 2, 2026
New transparency rules now require AI-generated images to carry machine-readable markings. Here's who the rules bind, the real deadlines, and what it means for the files on your drive.
- EU AI Act
- C2PA
- regulation
- AI
On August 2, 2026, the EU AI Act's transparency rules — Article 50 — became applicable. On the same day, across the Atlantic, California's AI Transparency Act (SB 942) became operative. Two major jurisdictions started requiring AI-generated content to be labeled, on the same day, and most of the coverage has been written for compliance lawyers.
Here's the version for people who actually make, share, and manage images.
What Article 50 requires
The core obligation is short: providers of AI systems that generate synthetic images (or audio, video, or text) must ensure the outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated."
"Machine-readable" is the key phrase. A visible "AI-generated" caption doesn't satisfy it on its own — the marking has to live in the file in a way software can detect. In practice, that means the two technologies we write about constantly on this blog:
- C2PA Content Credentials — a cryptographically signed metadata manifest embedded in the file (our explainer)
- Invisible watermarks like Google's SynthID — signals baked into the pixels themselves
The law doesn't mandate either technology by name. The European Commission's guidelines (published July 20, 2026) require solutions that are "effective, interoperable, robust and reliable as far as technically feasible" — and C2PA plus watermarking is the de facto implementation stack the industry has converged on. A voluntary Code of Practice, formally deemed an adequate compliance route in July 2026, adds a standardized EU icon set for labeling.
The deadlines are staggered — and that matters
"The rules took effect August 2" is true but incomplete. The rollout has three dates worth knowing:
| Date | What applies |
|---|---|
| August 2, 2026 | Article 50 becomes generally applicable. Deployer obligations start — notably, disclosing deepfakes and AI-generated text published on matters of public interest. |
| December 2, 2026 | Extended deadline for machine-readable marking in generative AI systems that were already on the market before August 2026. |
| February 2, 2027 | Deadline for the interoperability solution — the common technical layer that lets one provider's marks be detected by another's tools. |
There's no retroactive obligation: images generated before these rules applied don't need to be labeled after the fact.
Non-compliance carries fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. California's SB 942 has its own penalty regime, and press coverage on day one singled out Midjourney — which still ships no watermark or C2PA manifest — as the notable non-compliant holdout.
Who the rules bind (probably not you)
This is the part almost nobody spells out: the marking obligations fall on the providers of AI systems, not on the people who use them.
If you generate an image with ChatGPT, the legal duty to embed a machine-readable mark belongs to OpenAI. You, as the user, are not required by Article 50(2) to keep that mark in the file. The main user-side obligation is Article 50(4): if you deploy a deepfake — realistic synthetic content depicting real people, places, or events — you have to disclose that it's artificial. Artistic and satirical works get lighter-touch treatment.
So is it legal to remove AI metadata from your own images? In most everyday cases, nothing in Article 50 prohibits an end user from stripping metadata from a file they're entitled to modify. But context matters a great deal: passing off a deepfake as real, or removing provenance to deceive in a commercial or political context, can put you on the wrong side of this law and others. We're a metadata tool, not a law firm — if your use case is anywhere near the deepfake line, get actual legal advice.
What this means in practice
Expect three things over the next year.
More of your files will carry provenance metadata. With the December 2026 deadline approaching, every major generator that hasn't fully implemented C2PA will. OpenAI already dual-marks images from ChatGPT with both a C2PA manifest and a SynthID watermark. Google does the same for Gemini images. Adobe Firefly has signed everything since launch. The unmarked AI image is becoming the exception.
Platforms will read those marks more aggressively. Instagram, TikTok, LinkedIn, and YouTube already use embedded metadata to trigger AI labels. Regulatory pressure makes that reading stricter, and mislabeling disputes (real photos flagged as AI because of a Photoshop edit) will keep growing — we cover that in our Instagram "AI info" post.
The gap between metadata and watermarks will start to matter. Stripping metadata removes the C2PA manifest. It does not remove a pixel-level watermark like SynthID. If you're cleaning files for privacy, you should know exactly which layer you're removing and which layer survives — that's the subject of C2PA vs. SynthID.
Where CleanImages fits
Our position hasn't changed with the law, because the law regulates AI providers, not people cleaning their own files.
When you drop an image into the metadata viewer, we show you what's embedded — including C2PA manifests and AI-generation tags — before you remove anything. If the file carries a Content Credentials manifest, we flag that you're about to remove an authenticity signature, because that's a real tradeoff: provenance marks are genuinely useful for journalism and verification, and sometimes the right call is to keep them.
What we won't do is pretend metadata removal makes an AI image undetectable. It doesn't — watermarks survive, and pixel-level classifiers don't care about metadata at all. What it does is remove the readable data layer from files you're about to share, which is exactly what a privacy tool should do.
TL;DR
Since August 2, 2026, EU law requires AI providers to embed machine-readable marks in generated images, with full enforcement for existing systems from December 2, 2026 and an interoperability deadline in February 2027. California's equivalent went live the same day. The duty sits with the AI companies, not with users — but the practical effect for everyone is that AI images increasingly carry two layers of marking: metadata you can remove, and watermarks you can't. Knowing the difference is the new baseline for sharing files intentionally.