The Label Is the Last Mile

Analysis·Giovanni Leonardi·July 2026·11 min read

Researched by an agentic pipeline · reviewed and gated by the author

A label is an output; compliance is the chain that makes that output correct.

A disclosure that survives the journey

A European customer sees a product video in a social feed. The clip began with a generative tool, moved through an agency, was reframed in an asset-management system, subtitled by another service, transcoded by the platform and finally displayed on a phone. Somewhere near the start, the file carried machine-readable information about its origin. At the end, the viewer sees no disclosure.

That sequence is illustrative, but the control failure is real. Article 50 of the EU AI Act applies from 2 August 2026 and separates several duties across providers and deployers: disclosure in direct AI interactions, machine-readable marking of synthetic outputs, and visible or audible disclosure for specified uses such as deepfakes and certain public-interest text. The obligation is not one universal label, and the limited transition to 2 December 2026 applies only to a defined marking duty for qualifying systems already on the market. [S1] [S2] [S4]

The useful enterprise distinction is simple. A label is an output; compliance is the chain that makes that output correct. The chain begins before generation, when the organisation decides what system, actor, content and audience it is dealing with. It continues through provenance, editorial review and distribution. It ends only when the organisation can show what the user encountered at first exposure.

That turns transparency from a design embellishment into an operating control.

Four questions, not one label

Many programmes start in the wrong place: “What label should we add?” Article 50 makes that question premature.

The first question is who is acting. A provider designing a directly interactive AI system has a different duty from an enterprise deploying a tool to publish content. In a supply chain, one organisation may provide a system, another deploy it, and several others transform or distribute its output. A generic AI inventory rarely captures those role changes.

The second is what was produced. Machine-readable marking, visible disclosure, a direct-interaction notice and evidence of substantive human review are different controls. They serve different audiences. A provenance credential may help software inspect origin and editing history. A visible notice helps a person understand the encounter. Neither proves that the content is true.

The third is where and to whom the output appears. The Commission’s guidance frames disclosure around first interaction or exposure, not around a notice hidden in a policy page. [S2] A control that works in the originating product can fail after export, agency processing or platform publication.

The fourth is whether an exception genuinely applies. Standard editing that does not substantially alter meaning is not the same as synthetic generation. Human involvement in public-interest text is not automatically an exemption: review must be substantive and editorial responsibility real. [S4] The presence of a named approver matters only if that person has the competence and authority to change or stop publication.

The resulting classification is necessarily more granular than “uses AI”. It must connect system, organisational role, content type, audience, channel, exception rationale and accountable owner. In simple products where one provider controls the whole path, this may remain a modest control. In a multinational enterprise with decentralised creation and multiple agencies and platforms, it becomes an evidence architecture.

Where the chain breaks

The technical part is often described as a provenance problem. That is correct, but incomplete.

C2PA Content Credentials can cryptographically bind assertions about an asset’s origin and editing history. The standard is valuable precisely because it treats provenance as a lifecycle rather than a badge. It also states its boundary: credentials can be removed, and provenance is not a judgement about truth. [S5]

This distinction matters in ordinary enterprise work. A model can attach a valid mark. A designer can crop the image. A content-management system can optimise it. A social platform can transcode it. Each transformation may preserve, alter or strip information. The Washington Post tested an AI-generated video carrying Content Credentials across eight major social platforms in 2025 and reported that none preserved the credentials in the uploaded result; only one displayed a warning, and it was not prominent. [S6] That is one test, not a market-wide benchmark. It is nevertheless enough to disprove the assumption that marking at generation guarantees disclosure at exposure.

The organisational breaks are less visible.

Procurement may record that a supplier supports provenance without testing the enterprise’s actual export and publication path. Legal may classify the use while marketing changes the format or audience. An editorial team may approve the words while nobody owns the machine-readable mark. A platform team may show a notice in the interface while records management cannot preserve evidence of what appeared on a particular date.

None of these failures is solved by appointing a single “AI compliance owner”. The responsibilities must remain distinct: legal classification, technical implementation, editorial judgement, channel execution and evidence retention. The operating model joins their outputs without pretending they are the same job.

An illustrative release decision

Consider a composite public-affairs workflow. A company uses a generative system to draft a statement about an infrastructure project. An agency adds synthetic imagery and turns the material into a short video. The text is substantively rewritten by an experienced editor, while the video is published through three platforms.

A defensible control sequence would look like this:

  1. The product or AI-governance owner records the systems and suppliers involved.
  1. Legal determines the organisation’s role for each system and output, tests whether the text concerns a matter of public interest, and records the basis for any exception.
  1. The editor performs substantive review, changes unsupported passages, and has authority to withhold publication. The record shows what changed and who accepted editorial responsibility.
  1. The media workflow attaches or preserves machine-readable provenance where required and records the original asset securely.
  1. Channel owners test the actual exports on the publishing platforms and place human-readable disclosure where the audience first encounters the content.
  1. Evidence links the classification, version, review, provenance test and publication proof. If a platform strips a mark, the release process treats that as a control exception requiring an alternative response rather than assuming the original file was enough.

This is not a statutory template. It is the operating mechanism implied by duties that change with actor, content and context, and by technologies whose durability cannot be assumed. The purpose is not to maximise paperwork. It is to make the critical decisions reproducible.

The strongest case for a lighter response

There is a serious sceptical argument. Article 50 may prove to be a bounded compliance wave rather than a lasting enterprise transformation.

Vendors can embed marking and interaction disclosure into products. Platforms can standardise the preservation and display of provenance. The voluntary Code of Practice promotes layered techniques and documented compliance, but enterprises need not all build the same control apparatus. [S3] The Regulation recognises technical feasibility, context and exceptions. Many low-complexity deployments may be handled through existing publishing approval, procurement and release controls. Over-engineering can create cost, slow legitimate use and flood audiences with low-value notices.

This argument should change the response. The goal is not a new central bureaucracy or a universal “label everything” rule. It is a control scaled to the number of role changes, transformations, channels and judgement calls in the flow.

If vendors and platforms deliver durable interoperability by default, part of today’s technical burden will become commodity infrastructure. But even then, the enterprise must decide whether the duty applies, whether an exception is sound, who holds editorial responsibility and what evidence demonstrates first exposure. Tooling can automate preservation; it cannot settle the organisation’s role or manufacture substantive accountability.

The right test is therefore not whether the organisation has an Article 50 programme. It is whether its existing operating model can answer the four questions and preserve the answer through release.

Compliance is not trust

Transparency policy is often justified in the language of trust. The evidence supports a narrower conclusion.

In a CHI 2025 study involving 911 participants, warning labels affected whether users believed social-media content was AI-generated, but the tested labels did not significantly change liking, commenting or sharing. [S7] A broader MIT policy review warns that process labels can reduce trust in accurate synthetic content, create an implied authenticity advantage for unlabelled material and lose salience through banner blindness. [S8]

Those findings do not make disclosure pointless. They separate three outcomes that organisations routinely collapse:

  • Regulatory evidence: can the enterprise demonstrate that the correct duty was identified and executed?
  • Recognition: did the user notice and understand that AI was involved?
  • Behaviour or trust: did the information change reliance, sharing or judgement?

A compliant label can succeed at the first outcome and partly at the second without producing the third. Provenance can establish where an asset came from without establishing that it is accurate. Visible disclosure can inform a person without preventing deception. Measuring label counts therefore says little about the quality of either compliance or user protection.

Enterprises should test the outcomes separately. Audit samples should trace an asset from generation to exposure. User testing should assess noticeability and comprehension on real devices and accessibility modes. Risk teams should avoid claiming behavioural benefits that have not been demonstrated.

The minimum viable control plane

The phrase “control plane” can invite unnecessary architecture. Its practical meaning here is a connected set of decisions and evidence.

Control object Decision Evidence
Role and scope Provider, deployer, content, audience, exception Classification record and owner
Provenance Required mark and preservation path Original asset, transformation log and verification test
Editorial authority Review depth and responsibility Version history, decision and named accountable person
Exposure Correct disclosure in the actual channel Device or publication proof
Change New system, format, guidance or platform behaviour Reassessment trigger and remediation record

The enterprise need not centralise every decision. It does need common definitions, escalation points and a record that survives organisational hand-offs. Lost or conflicting provenance should be treated as an incident to investigate, not as proof that content is human-made or false. Supplier claims should be tested through the real workflow. Exceptions should expire or be reassessed when the system, audience or editing process changes.

The principal uncertainty is empirical. At the first days of Article 50 applicability, comparative evidence does not show whether enterprises with this connected operating model achieve better compliance or user outcomes than those using narrower release controls. Enforcement and case law are immature; the Commission guidance is influential but non-binding. A mature market may make some controls much simpler.

That uncertainty argues for instrumentation rather than theatre. Select representative content flows, including mixed human-and-AI work. Test transformations and platforms. Record exceptions. Measure first-exposure execution. Review failures after actual releases. The aim is to learn where the chain breaks before an authority, customer or public controversy discovers it first.

The question that survives the label

Article 50 does not require every enterprise to become a provenance laboratory. It does require affected organisations to stop treating transparency as a final creative decision.

The durable management question is no longer, “Did we add the label?” It is: Can we reconstruct why this disclosure was required, who accepted responsibility, whether its provenance survived, and what the audience actually saw?

When the answer is available from one connected evidence chain, the label becomes credible. When it is scattered across legal advice, supplier promises, editing tools and platform screenshots, the last mile is already broken.

Sources

  1. European Parliament and Council — Regulation (EU) 2024/1689 (Artificial Intelligence Act) — 13 June 2024, published 12 July 2024 — https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  1. European Commission — Guidelines on transparency obligations for providers and deployers of certain AI systems — 20 July 2026 — https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
  1. European Commission — Code of Practice on Transparency of AI-generated Content — 10 June 2026 — https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
  1. European Commission — Transparency obligations under Article 50 of the AI Act: Questions and Answers — 24 July 2026 — https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
  1. Coalition for Content Provenance and Authenticity — C2PA and Content Credentials Explainer, Specification 2.4 — accessed 15 August 2026 — https://spec.c2pa.org/specifications/specifications/2.4/explainer/Explainer.html
  1. The Washington Post — Tests show top social platforms don’t disclose markers on AI videos — 22 October 2025 — https://www.washingtonpost.com/technology/2025/10/22/ai-deepfake-sora-platforms-c2pa/
  1. Gamage, Sewwandi, Zhang and Bandara — Labeling Synthetic Content: User Perceptions of Warning Label Designs for AI-generated Content on Social Media — CHI 2025 — https://arxiv.org/html/2503.05711v1
  1. MIT — Labeling AI-Generated Content: Promises, Perils, and Future Directions — November 2023 — https://computing.mit.edu/wp-content/uploads/2023/11/AI-Policy_Labeling.pdf

More from Transformation