
The First AI Break-In Was an Accident

Make It Find What It Missed

The EU Just Made AI Honesty the Law. Here’s What Actually Applies to You.
On August 2, new European Union rules took effect for AI-generated content, and they reach further than Europe. The law applies to anyone whose AI content gets used or seen inside the EU, which, if you publish on the open internet, can include you. Penalties top out at 15 million euros or 3 percent of worldwide revenue.
Before you panic: most of what a typical business does with AI is either exempt or easily covered. But there’s one requirement that touches something I’ve actively taught on this blog, so let’s get you the plain-English version. The usual disclaimer applies double today: I’m a marketer who reads regulations so you don’t have to, not a lawyer, and if EU customers are a real slice of your audience, spend an hour with actual counsel.
Who does what
The rules (Article 50 of the EU AI Act, with official guidelines published in July) split responsibility in a way that’s genuinely sensible.
The companies that make AI, like Google, OpenAI, and Anthropic, must embed invisible, machine-readable markers in generated content so software can detect what’s synthetic. That’s their job, and it’s already happening under the hood of the tools you use.
You, the business using AI, own the visible honesty. Two duties matter for content publishers:
First, if AI content depicts real people, places, or events in a way that appears authentic, what the law calls a deepfake, you must disclose that it’s AI-generated. Second, if you publish AI-generated text meant to inform the public on matters of public interest, you must label it, unless a human reviewed it and someone takes editorial responsibility for it. That last clause is the exemption most legitimate businesses will live in.
The part that touches you: “appears authentic”
Here’s where this gets practical, because I taught a version of this on this very blog. If you’ve used AI to put your headshot in a nicer office, dress up a casual photo, or unify your team’s pictures against one background, that content depicts a real person in a way that looks like a real photo. Under the new rules, when EU audiences can see it, that wants a disclosure. Nothing dramatic: a simple “photo enhanced with AI” line in appropriate placement satisfies the requirement, and for creative work the law explicitly says the label shouldn’t ruin the experience.
Meanwhile, the illustrated graphics all over this site need no label at all. A cartoon robot on a navy background doesn’t appear authentic, and content that’s obviously artistic or stylized was never the target. The law is aimed at deception, not at art.
Text works the same way. Every post on this blog gets drafted with AI assistance (reading my audio transcripts from AI Roundtable calls and turning them into written form), then reviewed, edited, and published under my name with my editorial responsibility. That workflow is exactly the exemption the law describes. What the law won’t excuse is fully automated publishing where nobody reviews and nobody’s accountable, which, separate from any regulation, was always a bad idea.
What you probably don’t need to worry about
Content published before August 2 doesn’t need retroactive labels, though the EU encourages it where easy. AI used as a grammar checker or for minor edits doesn’t trigger anything. And enforcement runs through national market surveillance authorities whose realistic priorities are large-scale deception, election interference, and fraud, not a Massachusetts contractor’s website. The reason to act anyway is that this standard will flow downhill fast: platforms, ad networks, and enterprise clients will start requiring these disclosures contractually, and the businesses with clean habits will sail through.
What I’m doing at Tableland, and recommend
Four moves, none expensive. I’m adding a standing transparency note to published content, like the one at the bottom of this post, stating that illustrations are AI-generated and text is human-reviewed with named editorial responsibility. I’m labeling any photorealistic AI edits of real people or places going forward. I keep our visual brand deliberately stylized, which was an aesthetic choice that just became a compliance perk. And I’ve confirmed the image tools I use embed the machine-readable marks on their side, which is worth one email to any vendor you rely on.
The deeper point is the one I keep coming back to on this blog: the practices that keep you compliant are the same ones that keep you trusted. Nobody has ever lost a customer by being clear about how they work.
- Inventory where AI creates or edits your public content: text, images, audio, video.
- Photorealistic AI depictions of real people, places, or events get a simple disclosure line.
- Obviously stylized illustrations and graphics: no label required.
- AI-assisted text: keep human review, and put a real name behind editorial responsibility.
- Add a standing transparency note to your site; it covers the gray areas gracefully.
- Ask your AI vendors to confirm their outputs carry machine-readable marking.
- Selling into the EU meaningfully? One hour with a lawyer beats guessing.
Transparency note: Illustrations on this site are AI-generated in a deliberately stylized format. Illustrations are created with tools that apply machine-readable content credentials at generation; site image optimization may not preserve those marks in every delivered copy. Article text is drafted with AI assistance, then human-reviewed and edited. Editorial responsibility for everything published here is held by Jeff Daniels, Tableland Partners LLC.
This post came out of a real conversation at the AI Essentials Roundtable, the small group I run for business owners who want to actually use AI instead of just reading about it. We meet every other week, screen-share real builds, and steal each other’s wins. If that sounds useful, details are here: tablelandpartners.com/ai_essentials_roundtable


