Yesterday the European Union switched on the part of its AI rulebook that touches every person who writes, shoots or films for a living. From 2 August 2026, Article 50 of Regulation (EU) 2024/1689 requires chatbots to admit they are machines, generative systems to mark their outputs so software can detect them, deployers to label deepfakes, and certain AI-written publications on public-interest matters to carry a disclosure. Penalties run to €15 million or 3% of worldwide turnover.
Table of Contents
None of that pays a photographer. None of it obliges an AI company to license a novel, a news archive or a stock library. The distinction between transparency duties and remuneration rights is the whole story of what the AI Act does and does not do for original work, and it is the distinction most of the commentary around yesterday’s deadline missed.
The date that mattered was 2 August 2026
The AI Act entered into force on 1 August 2024 and has been arriving in instalments ever since. Bans on a short list of prohibited practices and the AI literacy duty landed in February 2025. Obligations for providers of general-purpose AI models, along with the governance architecture, arrived on 2 August 2025. The next stop was 2 August 2026, and for anyone working in text, image or moving image it was the stop that counted.
Two things happened on that date. Article 50, the transparency chapter, became applicable to providers and deployers of AI systems across the Union. And the European AI Office gained the power to actually enforce the general-purpose AI rules that had technically applied for a year already, including the copyright policy duty and the training-data disclosure duty in Article 53. Until yesterday, a model provider that ignored those duties faced no fine. From yesterday, the AI Office can request information, evaluate models, order corrective measures and impose penalties.
The gap between an obligation existing and an obligation being enforceable is the single most useful thing to understand about the last twelve months of AI policy in Europe. Rightsholder organisations spent that period pointing at Article 53 and being told, in effect, that the machinery was not yet switched on. Researchers who went looking for the mandatory public summaries of training content found a handful. There was no central register, no filing portal, no deadline with teeth. That has changed, at least on paper.
What did not change on 2 August is the underlying copyright question. The AI Act does not create a new right for authors. It does not create a levy. It does not create a licence. It points at existing EU copyright law, principally Directive (EU) 2019/790 on copyright in the Digital Single Market, and tells model providers to have a policy for complying with it. Whether training a large language model on a photographer’s archive is lawful in the first place is a question the AI Act deliberately declined to answer. That question sits with national courts and, since March, with the Court of Justice in Luxembourg.
So the honest answer to whether the AI Act helps original creation is layered. It gives creators three things they did not have before: a disclosure regime that makes synthetic content nominally identifiable, a transparency duty that produces documents rightsholders can inspect and build cases on, and a hook that lets EU law reach model providers who trained abroad. It withholds the one thing most creators actually asked for, which is payment.
There is a second layer. Even the things the Act gives are conditional on enforcement capacity that does not yet exist in most of the Union, on technical standards for marking that are still being worked out, and on a political appetite for policing AI companies that visibly cooled during the Digital Omnibus negotiations. A right that no authority has staff to supervise is a right in name.
And there is a third layer, which is the one that shows up in bank accounts. The economic damage to creative work over the past three years has come less from unlicensed training than from substitution. Search engines that answer the question instead of sending the click. Image generators that fill a brief in fifteen seconds for the price of a subscription. Voice cloning that removes the dubbing session. Nothing in Article 50 or Article 53 slows substitution down. Labelling a synthetic image does not make a commissioning editor buy a real one.
That is why the framing of yesterday’s deadline as a win for creators, which several trade bodies reached for, deserves scepticism. It is a procedural win. Procedural wins matter, because evidence gathered under a transparency duty is what litigation and licensing negotiations are built from. But a procedural win in August 2026 sits alongside a Commission consultation that closed in June, a Parliament resolution from March asking for remuneration, and a legislative proposal that is not expected before 2027. The instrument that might actually pay creators is at least eighteen months away from a first draft, and further from application.
Marking and labelling are two different duties
Almost every summary of Article 50 published in the past six weeks collapsed two obligations into one. They are separate, they fall on different parties, and confusing them produces the wrong compliance plan.
The first is marking. Under Article 50(2), the provider of an AI system that generates synthetic audio, image, video or text must ensure the output carries a machine-readable mark and is detectable as artificially generated or manipulated. This is a technical duty on the company that builds and offers the system. It is invisible to the reader or viewer. Its purpose is provenance infrastructure, so that detection tools, platforms and forensic services have something to read.
The second is labelling. Under Article 50(4), the deployer of a generative system must clearly label AI-generated or manipulated text published to inform the public on matters of public interest. Under a parallel duty, deployers must disclose content that constitutes a deepfake. These are human-facing duties on the party that puts the content in front of an audience. A marketing agency, a broadcaster, a news publisher, a freelancer who earns regularly from the work.
The Commission’s guidance is explicit that a deployer cannot discharge the disclosure duty by pointing at the provider’s embedded mark. Machine-readable provenance is not disclosure to a person. A deployer must produce something a viewer can perceive without special tools or extra steps, which means a visible or audible label, at or before first exposure. The EU has published an icon set that deployers may use for this purpose.
The definitional question of who counts as a deployer matters for freelancers in particular. The Commission’s FAQ draws the line at economic benefit on a regular basis. A private individual generating a deepfake and posting it is outside the AI Act entirely, treated as a personal activity. A person doing the same work as part of a trade, occupation or freelance practice is a deployer with obligations. Employees acting under the instructions and control of a company are not separate deployers, and a company remains the deployer even when contractors and freelancers operate the system on its behalf.
For a small studio, that allocation is worth mapping before an authority asks. If a Slovak agency generates a synthetic presenter for a client’s campaign, the agency is the deployer and carries the disclosure duty, not the individual animator on staff. If the agency subcontracts the generation to a freelancer, the agency still carries it. The contract needs to say who produces the label and who keeps the record.
There are two further transparency duties in the article that get less attention. Article 50(1) requires providers of systems that interact directly with people to design them so users know they are talking to an AI, unless that is obvious. The Commission reads the obviousness exception narrowly, because relying on it removes information from the user. Article 50(3) requires deployers of emotion recognition and biometric categorisation systems to inform the people exposed to them, whether the analysis runs live or after the fact.
Article 50 is also not tied to the Act’s risk tiers. It applies whether a system is high-risk, limited-risk or unclassified. Open-source licensing does not exempt a system from it either, which is a point several developers assumed the other way round.
Machine-readable marks and the limits of provenance
The marking duty in Article 50(2) sounds like a technical formality. It is the most consequential and the least settled part of the regime, because the state of the underlying technology does not match the ambition of the text.
The Act requires marking solutions that work reliably and interoperably, as far as is technically feasible, taking into account the properties of different content types, the cost of implementation and the recognised technical baseline. That qualifier does an enormous amount of work. Marking an image is comparatively tractable. Marking short text is close to impossible.
Three approaches are in play. Cryptographic provenance metadata, of which the C2PA specification and its Content Credentials implementation are the dominant expression, attaches a signed manifest describing how a file was made and edited. Statistical watermarking embeds a detectable pattern in the output itself, as Google’s SynthID does for images, audio and video. Fingerprinting and hashing keep a reference copy so a candidate file can be matched against a registry.
Each fails differently. Metadata is fragile. Social platforms strip it during upload and transcoding, format conversion drops it, and a screenshot destroys it entirely. A platform can support Content Credentials in its interface and still remove them in practice further down the pipeline. Anyone who has watched an image lose its IPTC fields between a CMS and a Facebook post knows the failure mode already.
Watermarks survive more transformations but degrade under heavy editing, and for text they remain weak. A three-sentence caption carries almost no capacity for a statistical signal, and paraphrasing removes what capacity there is. The practical consequence is that the marking duty will produce reasonable provenance for AI images and video, patchy provenance for audio, and close to nothing usable for the short text that dominates commercial writing.
The Commission built exemptions around these limits. Outputs falling outside the marking duty include short sequences of numbers, symbols or letters, source code, machine-to-machine outputs never exposed to a person, and material used inside closed production loops such as film pipelines, unless it becomes the final output. Systems performing an assistive function for standard editing are excluded, with guidance offering examples of where ordinary editing ends. A narrow exemption exists for business-to-business and industrial contexts under conditions set out in the guidelines.
The exemption for standard editing is the one photographers should read closely. Generative fill, sky replacement, denoise and upscale sit on a spectrum, and where a given tool falls determines whether an image carries a mark. A retoucher who removes a lamp post is doing something categorically different from a retoucher who generates a background that never existed, and the guidelines attempt to draw that line with examples rather than a bright rule.
The compliance route the Commission prefers is the Code of Practice on Transparency of AI-generated Content, published in final form on 10 June 2026 after a drafting process that ran from November 2025 through three rounds of working groups. Section 1 covers providers and marking. Section 2 covers deployers and labelling. Adherence is voluntary, but the Commission and the AI Board have confirmed the code as an adequate tool for demonstrating compliance, which converts it into a practical safe harbour. By the end of July 2026, roughly 190 companies and organisations had signed. Providers and deployers who go their own way must demonstrate that their measures are adequate, assessed individually by national market surveillance authorities, and can expect more requests for information.
For a creator, the useful reading of all this is inverted. The marking duty is not primarily a shield for your work. It is a labelling regime for the competition. Its benefit to you, if it arrives, is that synthetic material becomes distinguishable in the market, which restores some value to the claim that a photograph is a photograph. Its benefit is only as strong as the weakest link in the distribution chain, and the weakest link is currently the platform layer.
Deepfake disclosure rests on a three-part test
The deepfake duty is the part of Article 50 most likely to touch commercial video and photography work in the next year, and its scope is narrower than the word suggests.
The Act defines a deepfake in Article 3(60) as AI-generated or manipulated image, audio or video content resembling existing persons, objects, places, entities or events, which would falsely appear to a person to be authentic or truthful. The Commission’s guidance breaks that into three cumulative criteria, and all three must be met.
Resemblance requires a high level of similarity between the synthetic content and the subject it simulates. Existence requires that the person, object, place, entity or event resembles something that exists, could plausibly exist, or could plausibly have existed. The third criterion, false appearance of authenticity, is where the analysis actually happens. Assessment takes account of the degree of resemblance, the substantive message of the content, the intended and foreseeable deployment contexts, and the composition and expectations of the likely audience.
That audience-expectation test is the practical escape hatch for most advertising and entertainment work. If the intended audience in a specific context does not expect the content to be authentic, the material may not falsely appear authentic, and the deepfake duty may not attach. The guidance gives the example of background scenes, special effects and technical pre- and post-processing in standard film production, which are unlikely to mislead an audience about authenticity.
Where a deepfake forms part of an evidently artistic, creative, satirical or fictional work, the transparency duty is limited. Disclosure must happen in a manner appropriate to the work and must not hamper its display or enjoyment. A film does not need a watermark burned across the frame. An end-credit disclosure or an accompanying notice can satisfy it.
Timing is fixed. Disclosure must reach the viewer at first exposure at the latest, in a clear and distinguishable way, understandable and perceivable without technical tools. Scrolling to a footer three screens down is unlikely to qualify for a video that autoplays.
The category that will generate the most enforcement interest is synthetic depiction of real people in commercial contexts. A cloned presenter, a resurrected celebrity endorsement, a fabricated customer testimonial, a synthetic doctor in a health advertisement. All of those meet the resemblance and existence criteria comfortably, and audience expectation in an advertising context runs toward believing what is shown. For anyone producing that kind of material for clients in the EU, the deployer duty is live now, with no grace period, because the December extension applies only to the provider-side marking duty for legacy systems.
One further point matters for photographers and camera operators specifically. The deepfake duty is content-based, not tool-based. A composite built from real photographs using AI-assisted tools can meet the definition. A fully synthetic image of a real place can meet it. The question is not which software was open, it is what the finished frame claims to show.
Public-interest text and the editorial responsibility carve-out
For writers, the single most important provision in Article 50 is the exemption written into the text-labelling duty, because it draws a legal line between edited publishing and unedited output.
The duty in Article 50(4) requires deployers to clearly label AI-generated or manipulated text published to inform the public on matters of public interest. Three criteria must be satisfied. The text must be published. It must be informative to the public. It must concern a matter of public interest, a category the Commission’s guidance fills out with politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, and economic, financial, political, scientific or cultural developments that may be a relevant subject of public debate.
That list is broad. A commercial blog post about a change in Slovak VAT treatment is about a financial development relevant to public debate. An explainer on a new medicine is public health. A piece on an election is obviously in scope. The idea that Article 50(4) applies only to journalism does not survive reading the enumerated categories.
Then comes the exemption. Published text that has undergone human review or editorial control does not need to be labelled. The Commission defines those terms with more precision than most compliance summaries acknowledge, and the definitions set a real bar.
Human review means deliberate examination of the substance of the content by one or more natural persons with relevant knowledge and professional judgement about the subject matter. Academic peer review and professional validation chains are the examples given. Editorial control means control exercised in practice by a responsible editorial entity, such as an editor-in-chief, with authority to approve, alter or reject the substance of the text on substantive grounds, including fact-checking and assessing the trustworthiness of sources. Editorial responsibility means a person holds ultimate legal responsibility for publication, including for that review.
And the negative definition is the part that will catch people. Superficial, purely formal or procedural checks do not count. Spell-checking does not count. Grammatical correction does not count. Running a draft through a style tool and clicking publish does not count.
This creates a genuine advantage for outfits that maintain an editorial process, and it does so in a way that is legible to clients. A publisher who can name the editor responsible for a piece, show a substantive review step and demonstrate fact-checking sits outside the labelling duty. A content farm publishing unreviewed model output on public-health topics sits inside it and is exposed to fines up to €15 million or 3% of turnover, enforced by national market surveillance authorities.
Whether that advantage translates into money is a separate question. The exemption removes a compliance burden. It does not require anyone to prefer edited content, price it higher, or rank it above unedited content. The AI Act rewards editorial responsibility with paperwork relief, not with market preference. A commissioning client who does not care about labels will not pay more because your process qualifies for an exemption.
There is, though, a defensible commercial argument to build from it. Agencies that document review chains, name responsible editors and retain evidence of substantive checks are producing something a regulated client can publish without a disclosure obligation. In pharmaceutical, financial services, energy and public-sector work, where the client’s own compliance function reads every deliverable, that is a procurement differentiator worth naming in a pitch. It is narrow, it is unglamorous, and it is the most concrete thing the AI Act hands a working writer.
The enforcement reality tempers this. Detecting unlabelled AI text at scale is not a solved problem. Detection tools carry false-positive rates that make them unsuitable as evidence, a point acknowledged in the studies measuring AI content share on the web. A market surveillance authority acting on a complaint can demand documentation from a named deployer. It cannot sweep the web. Expect enforcement to concentrate on visible, complainable cases involving identifiable companies rather than on the long tail.
The grace period that pushed marking to December
One date shifted, and only one. The provisional agreement reached between the Council and Parliament in May 2026 introduced a limited transitional measure for the marking duty in Article 50(2).
Providers of generative AI systems already on the market or in service before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking and detection requirement. Systems placed on the market from 2 August 2026 onward have no such extension. Content generated before 2 August 2026 does not need to be labelled retroactively, though the Commission encourages deployers holding or distributing such material to apply marking voluntarily where they can.
Everything else in Article 50 applied from yesterday without extension. The duty to disclose that a user is interacting with an AI system. The duty to inform people exposed to emotion recognition and biometric categorisation. The deepfake disclosure duty on deployers. The public-interest text labelling duty on deployers. Those are live.
The asymmetry is deliberate and it has an awkward consequence. Between now and December, deployers are obliged to label deepfakes and unedited public-interest text while the providers of the tools they use may not yet have implemented the machine-readable marking that would help them identify synthetic material in the first place. The human-facing duty arrived four months before the technical infrastructure it logically depends on. For a deployer that generates its own content, this is manageable, since it knows what it made. For a deployer handling third-party material, such as a newsroom verifying user-submitted footage or an agency working with supplied assets, the sequencing is unhelpful.
The practical response is documentation. From now until the technical layer matures, the defensible position for any studio or agency is a written record of what was generated with which tool, who reviewed it, what was disclosed and where. That record is cheap to maintain and it is the only thing that answers a regulator’s question about a specific piece of content.
Copyright duties live in Article 53, not Article 50
The provisions that matter for whether your work can be used to train a model sit in a different chapter of the AI Act, apply to a different set of companies, and became enforceable yesterday rather than newly applicable.
Article 53 imposes four duties on providers of general-purpose AI models placed on the EU market. They must draw up and maintain technical documentation in line with Annex XI. They must give downstream providers the information needed to understand capabilities and limits and to meet their own obligations. They must put in place a policy to comply with Union copyright law, including identifying and respecting reservations of rights expressed under Article 4(3) of the Copyright Directive. And they must publish a sufficiently detailed summary of the content used for training, following the template issued by the AI Office.
The first two duties do not apply to providers of free and open-source models unless the model presents systemic risk. The copyright policy and the training-content summary apply to everyone, open source included. That is a point worth repeating because the open-source exemption is frequently overstated.
Territorial reach is the design feature that makes Article 53 interesting for European creators. The Act’s approach, articulated in its recitals, is that copyright-related obligations attach to models offered on the EU market regardless of where the training took place. A model trained entirely in California and offered to European users falls within scope. This is the mechanism by which EU copyright standards reach conduct outside the Union, and it is the reason American and Asian providers have had to build EU-specific compliance documentation rather than treating the fair use analysis as sufficient everywhere.
What Article 53 does not do is create a right. It requires a policy for complying with existing law. The substantive question of whether training on protected works infringes reproduction rights is governed by the Copyright Directive and the InfoSoc Directive as transposed into national law, and it is adjudicated by national courts. The AI Office supervises whether a provider has a policy and has published a summary. It does not decide whether the training was lawful.
This division confuses almost everyone the first time they encounter it, including some rightsholder organisations that have addressed complaints to the AI Office about infringement. Compliance with the general-purpose AI Code of Practice, published on 10 July 2025 and endorsed by the Commission and the AI Board on 1 August 2025, does not equal copyright compliance. They are parallel tracks. A provider can be a model citizen under the Code and still lose a copyright case in Munich, which is roughly what happened.
The Code of Practice does, however, contain commitments with real content. Its copyright chapter requires signatories to maintain a copyright policy, to rely only on lawfully accessed sources, and to respect machine-readable reservations of rights. The final version made exclusion of piracy sites mandatory, which earlier drafts had softened. It requires proportionate safeguards against copyright-infringing outputs and reflection of prohibitions on infringing use in terms of service. And it requires a designated point of contact plus a mechanism through which rightsholders can lodge substantiated complaints about non-compliance.
That complaint mechanism is the most usable feature of the whole framework for an individual creator. It gives a named channel at each signatory, and a documented refusal to engage becomes evidence. It is not a court and it awards nothing. It creates a paper trail.
An earlier draft duty requiring providers to audit third-party datasets that were not web-crawled was removed from the final Code. That deletion matters more than it looks. A large share of training material reaches models through intermediary datasets and licensing brokers rather than through the provider’s own crawler. Removing the audit duty leaves a route by which content that a creator reserved against crawling can still arrive inside a model, laundered through a dataset the provider did not compile and is not obliged to interrogate.
The training-data summary and its thin first year
The disclosure duty in Article 53(1)(d) was supposed to be the instrument that let rightsholders see what had been ingested. Its first year suggests the instrument needs redesigning.
The AI Office published its mandatory template on 24 July 2025, days before the general-purpose AI obligations applied. The template asks for general model information including data modalities and approximate dataset size, a list of data sources identifying large datasets individually, the top 10% of domain names for web-scraped content, and an account of data processing, including how copyright reservations were respected and what content moderation removed illegal material. The design principle the Commission articulated is that a summary should be sufficient to understand and insufficient to replicate, protecting trade secrets while giving third parties something to work with.
The requirement took effect on 2 August 2025 for new models. Models already on the market before that date have until 2 August 2027 to publish, subject to a narrow exception. Supervision and corrective powers began yesterday. The Commission has said it will not conduct content-level audits, but can act on complaints or on qualified alerts from the scientific panel of independent experts constituted under the Act.
Then the empirical record. Researchers who set out to assess the quality of published summaries had to run an exhaustive search to locate them, and found five to assess as of 12 January 2026. Their work was picked up by Euractiv and Tech Policy Press under headlines about developers skirting the mandate. Their finding was not that companies had published bad summaries. It was that most had published nothing findable, that no unified place existed to file or discover the documents, and that the template produced inconsistent submissions that were hard to compare.
A transparency duty with no register, no filing address and no penalty produced approximately five usable documents in its first five months. That is the fact that should anchor any assessment of what the AI Act has so far delivered to creators.
Three days before yesterday’s enforcement date, OpenAI published a compliance statement covering safety frameworks, provenance watermarking partnerships and cybersecurity cooperation with European agencies. Reporting on it noted that the copyright chapter of the Code of Practice, the area where the company’s compliance had already been publicly questioned, was absent from the document. Whether that omission draws an AI Office request for information is now a live question rather than a theoretical one.
The template’s ambiguities compound the problem. It is not clear whether the size of scraped content should be measured in file size, token count or some other unit, which means two providers can comply while producing figures nobody can compare. The top-10%-of-domains disclosure sounds precise until you consider that the long tail is where individual photographers, small publishers and specialist blogs live. A photographer whose site was crawled will not find it named in a summary that lists the largest 10% of domains by volume. The disclosure is calibrated to reveal the presence of Wikipedia and Common Crawl, not the presence of your portfolio.
For a creator deciding where to spend effort, the summary is worth monitoring rather than relying on. It is useful for establishing that a category of content was used, which supports collective action by a trade body or a collecting society. It is close to useless for establishing that your specific work was used, which is what an individual claim requires.
Rights reservations only bite if machines can read them
The legal architecture that decides whether your work can be mined rests on a single conditional clause, and the condition is technical.
Article 4 of the Copyright Directive permits text and data mining of lawfully accessible works for any purpose, including commercial purposes, unless the rightsholder has reserved the right in an appropriate manner. For content made publicly available online, Article 4(3) specifies that the reservation must be expressed in machine-readable form. If a valid reservation exists, the exception does not apply and a licence becomes necessary. If it does not, the mining is permitted.
Everything therefore turns on what counts as machine-readable. That question was left open in 2019 and has stayed open. In practice, the market settled on robots.txt, a convention designed in 1994 for search crawlers, extended informally with user-agent directives for AI bots. Emerging alternatives include the TDM Reservation Protocol, ai.txt, headers, embedded metadata in IPTC and XMP fields, and the publisher-backed Really Simple Licensing standard, which expresses licensing terms and pricing rather than a bare refusal.
The Commission has been trying to close the definitional gap. It launched a consultation on 1 December 2025, supported by the EU Intellectual Property Office, on protocols for reserving rights against text and data mining, drawing on an EUIPO study of generative AI from a copyright perspective. Stakeholders were asked about the technical feasibility and uptake of the available options, and invited to join follow-up workshops. The deadline was extended to 23 January 2026. The intended output is a published list of generally agreed machine-readable opt-out solutions, reviewed at least every two years alongside updates to the general-purpose AI Code of Practice. Signatories to the Code committed to respecting appropriate machine-readable protocols beyond robots.txt and its successors.
Until that list exists, a creator reserving rights faces a guessing problem. Implement robots.txt and you have covered the convention the Code names explicitly, and nothing else. Implement four protocols and you have hedged, at the cost of maintaining four sets of files with no confirmation that any of them is legally sufficient.
The deeper problem is structural, and it is one the Parliament’s own report on copyright and generative AI acknowledged. An opt-out regime places the administrative burden on the party with the least capacity to carry it. A photographer with 40,000 images across a portfolio site, three stock agencies, two social accounts and a decade of client galleries cannot practically reserve rights everywhere the work sits. The agencies control their own terms. The social platforms grant themselves broad licences. Client sites are outside the photographer’s control entirely. Meanwhile the default, in the absence of a reservation, is permission.
Compliance data suggests the signals get ignored anyway. Analysis of crawler behaviour through 2026 indicates that robots.txt functions as a request rather than a control, honoured by some named crawlers and disregarded by others, which is why enforcement has migrated to the network and firewall layer where a request can be refused rather than declined politely. Around 19% of sites reportedly block GPTBot, and millions of sites now disallow AI training, but blocking a declared user-agent does nothing against an undeclared one.
There is one bright line the German courts have drawn. In the GEMA proceedings, the collecting society had declared an opt-out on behalf of its members, and the Munich court treated that reservation as operative. Collective declaration by an organisation with a mandate is a workable route where individual declaration is not. For photographers, that points at CEPIC members and national bodies. For writers, at authors’ societies. For musicians, at the collecting societies that have been most active in litigation.
The compliance calendar creators should track
Dates in the AI Act have moved repeatedly, and several of the moves changed which obligations bind whom. The table below consolidates the position after the Digital Omnibus on AI received final Council approval on 29 June 2026.
AI Act and adjacent milestones relevant to creative work
| Date | What applies | Who it binds |
|---|---|---|
| 2 Aug 2025 | Article 53 duties begin, including copyright policy and training-content summary | Providers of general-purpose AI models |
| 24 Jul 2025 | Mandatory template for training-content summaries published | Providers of general-purpose AI models |
| 10 Jun 2026 | Final Code of Practice on Transparency of AI-generated Content published | Voluntary, providers and deployers |
| 20 Jul 2026 | Commission guidelines on Article 50 adopted | Providers and deployers |
| 2 Aug 2026 | Article 50 transparency duties apply, AI Office enforcement powers over general-purpose AI activate | Providers, deployers, and model providers |
| 2 Dec 2026 | Machine-readable marking duty applies to generative systems already on the market before 2 Aug 2026 | Providers of legacy generative systems |
| 2 Aug 2027 | Training-content summaries due for models placed on the market before 2 Aug 2025 | Providers of legacy models |
| 2 Dec 2027 | High-risk duties for stand-alone Annex III systems | Providers and deployers of high-risk systems |
| 2 Aug 2028 | High-risk duties for AI embedded in Annex I regulated products | Providers of regulated products |
The pattern is unmistakable once laid out. Transparency duties arrived roughly on schedule. Substantive compliance machinery slipped by sixteen months to two years. Copyright disclosure for the models trained during the period that most concerns rightsholders, meaning everything built before August 2025, does not have to be documented until August 2027.
Enforcement depends on authorities that barely exist
A regulation is worth what its supervisors can do, and on this measure the AI Act entered its most demanding phase with an incomplete institutional base.
Member States were required to designate national competent authorities, including at least one notifying authority and at least one market surveillance authority acting as single point of contact, by 2 August 2025. As of March 2026, according to a European Parliamentary Research Service briefing, the Commission’s list of single points of contact contained eight entries out of twenty-seven. Tracking by independent monitors in June 2026 counted nine Member States that had designated both market surveillance and notifying authorities, with around twelve carrying pending legislative proposals or announcements. Conformity assessment bodies for high-risk systems remain concentrated in a small number of Member States.
That matters directly for Article 50, because the Commission’s own guidance places enforcement mainly with national market surveillance authorities. The AI Office has only a limited role over Article 50, confined to systems built on general-purpose AI models where the same entity provides both, or systems integrated into a very large online platform or search engine designated under the Digital Services Act. The European Data Protection Supervisor handles EU institutions. Everything else, including the agency down the road that generated an unlabelled synthetic testimonial, falls to a national authority that in most of the Union has not been formally designated, staffed or funded.
For a creator considering whether to complain about a competitor’s unlabelled output, or about a platform distributing synthetic material passed off as photography, the practical route in most Member States today is unclear. Where an authority exists, it is typically a repurposed telecoms, consumer protection or data protection regulator absorbing a new mandate with existing staff.
Enforcement over model providers is better resourced but narrow in scope. The AI Office can request technical documentation, evaluate models, require corrective measures and impose fines up to €15 million or 3% of worldwide turnover for the preceding financial year. The Commission has stated it will not conduct content-level audits of training data, relying instead on complaints and on qualified alerts from the scientific panel. It has also announced a call to expand EU model evaluation capacity, expected to be operational in 2027, which is an admission that the capacity is not there now.
The Commission adopted an action plan on cybersecurity and AI in July 2026 as part of building out the supervisory function. Harmonised standards under the standardisation request to CEN-CENELEC’s joint technical committee remain in draft, which was one of the stated reasons for deferring the high-risk timeline in the first place.
None of this means the Act is toothless. It means the first eighteen months of enforcement will be selective, complaint-driven and concentrated on large, visible providers where a single case produces deterrence. Small deployers face low probability of inspection and high exposure if inspected, which is the worst combination for planning purposes and argues for cheap documentation rather than expensive systems.
The Digital Omnibus reset expectations about deadlines
The political story of the past nine months changed what creators can reasonably expect from EU AI regulation, and it did so in a direction rightsholder organisations did not welcome.
By late 2025, implementation of the AI Act was visibly behind schedule. Harmonised standards were unfinished, guidance was late, conformity assessment infrastructure was thin, and industry plus several Member States argued the August 2026 timeline was unworkable. On 19 November 2025 the Commission tabled the Digital Omnibus, a package of amendments across the EU’s digital rulebook, including a dedicated AI component proposing a conditional delay mechanism for high-risk obligations.
Negotiations were not smooth. The first political trilogue on 28 April 2026 ended without agreement, breaking down over conformity assessment for Annex I systems. Negotiators returned and reached a provisional agreement in the early hours of 7 May 2026. Member State representatives confirmed it in the Council on 13 May. The European Parliament formally endorsed it on 16 June. The Council gave final approval on 29 June, with publication in the Official Journal and entry into force following, ahead of the 2 August date that would otherwise have triggered the original Annex III timeline.
The substantive outcome was a clean split. High-risk obligations, meaning risk management, data governance, technical documentation, human oversight and conformity assessment, were deferred to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. Transparency obligations under Article 50 were not deferred, apart from the four-month marking grace period for legacy generative systems. Registration duties for exempt high-risk systems were reinstated. Regulatory sandboxes were pushed to 2 August 2027. A new prohibition was added to Article 5 covering AI systems generating child sexual abuse material and non-consensual intimate imagery.
Two readings of this are available and both are defensible. The Commission’s reading is that the Act’s risk-based structure survived intact and the amendments were targeted simplification responding to genuine readiness problems. The creative sector’s reading is that the first serious test of political will produced a delay, and that the copyright review now under way will face the same pressure from the same quarters.
What the Omnibus demonstrated is that AI Act deadlines are negotiable when industry argues that compliance is impractical, and that transparency duties are politically cheaper to keep than substantive ones. That is the pattern to carry into any assessment of what the Commission’s copyright initiative will produce in 2027.
There is also a competitiveness argument running through EU AI policy since the Draghi report that cuts against remuneration mandates. Submissions from technology policy institutes to the copyright consultation in June 2026 argued for defending a broad, permissive text and data mining framework and cautioned against measures that would restrict AI development without commensurate benefit to creators. Those arguments have institutional traction in a Commission that has made simplification a headline theme.
German courts moved faster than Brussels
While Brussels negotiated timelines, a single chamber of a regional court in Munich did more to establish that training on protected works can be unlawful in Europe than the entire AI Act.
On 11 November 2025, the 42nd Civil Chamber of the Munich I Regional Court ruled in favour of GEMA, the German music collecting society, against OpenAI in case 42 O 14139/24. GEMA had sued over the lyrics of nine well-known German songs, including works by Kristina Bach, Herbert Grönemeyer and Reinhard Mey, arguing they were memorised in the model parameters and reproducible almost verbatim.
The court agreed on the central technical question. It found the lyrics were reproducibly contained in the models, meaning the model did not merely extract statistical parameters but retained the protected content itself. It inferred memorisation by comparing training material against model output. It held that memorisation in model parameters constitutes reproduction under section 16 of the German Copyright Act, and that reproduction in chatbot output constitutes a further infringement. Hallucinated deviations in the output did not defeat recognisability of the originals.
Critically, the court held that the text and data mining exception in section 44b, transposing Article 4 of the Copyright Directive, did not cover durable encoding of works in model weights, even where the sources were lawfully accessible. GEMA had also declared an opt-out on behalf of its members, which independently removed the exception. The court granted injunctive relief, disclosure and damages, dismissing a secondary personality-rights claim. OpenAI appealed to the Munich Higher Regional Court.
Then, on 31 July 2026, three days ago, the same chamber ruled largely for GEMA against Suno in case 42 O 763/25, the first European decision on AI music generation. Judge Elke Schwager found two separate violations. Storing the protected songs inside the model infringed the reproduction right. Serving outputs built on them to users infringed the making-available right. The court prohibited Suno from reproducing six works, including widely known titles, or using them for training without a licence, and ordered disclosure of revenues plus damages to be quantified. The chamber confirmed its November reading of the text and data mining exception, which means Europe now has two consistent first-instance judgments treating model weights as a place where reproduction happens. The judgment is not final and Suno may appeal.
For creators, the significance is not the specific outcome, which binds nobody outside Germany and remains subject to appeal. It is the reasoning. If durable memorisation in weights is reproduction, then the training exception protects far less than model providers assumed, and the licence becomes necessary rather than optional. If the appellate courts uphold it, the economics of European deployment change. If they reverse it, the AI Act’s transparency duties are left carrying weight they were never designed to bear.
The Hamburg Regional Court reached the question from another direction in 2024, dealing with dataset creation rather than model contents, and in a decision of 27 September 2025 confirmed that text and data mining for analytical purposes remains permissible within the limits of the German transposition. Read together, the German case law draws a line between analysis and retention rather than between AI and not-AI, which is a more workable distinction than most of the policy debate has managed.
Litigation is spreading. The association of Danish press publishers announced proceedings against OpenAI in July 2025. Munich, with experienced intellectual property chambers and a demonstrated willingness to rule for rightsholders, has become a forum of choice for European claimants. Other collecting societies, including counterparts in France, Italy and the United Kingdom, have been watching the GEMA strategy closely, and the Suno judgment gives them a second precedent to work from.
The Getty judgment exposed how hard proof is
For photographers specifically, the most instructive case of the past year is one the rightsholder largely lost, and the reasons it was lost are more useful than a win would have been.
On 4 November 2025, Mrs Justice Joanna Smith handed down judgment in the English High Court in Getty Images (US) Inc & Ors v Stability AI Limited. Getty had sued over the use of millions of its images to train Stable Diffusion, pleading primary and secondary copyright infringement, database right infringement, trade mark infringement and passing off.
Getty abandoned its primary copyright and database claims during trial. The reason was evidential and territorial. Getty’s case that Stability had downloaded images in the United Kingdom was inferential, built on factors such as Stability being a UK-registered company employing UK-based developers. When the evidence had to be produced, it was not there. Training had happened on infrastructure outside the jurisdiction, and English copyright law reaches acts done in England.
On the surviving secondary infringement claim, the court held that Stable Diffusion models do not contain or store reproductions of the works they were trained on, and therefore are not infringing copies. There are, in the court’s words, no copies in the model. That conclusion sits in direct tension with the Munich chamber’s finding on memorisation, and the divergence is now the central unresolved question in European AI copyright.
Getty won narrowly on trade marks. Early versions of Stable Diffusion generated synthetic images bearing the Getty watermark, which the court held infringed in limited circumstances where confusion as to origin was possible. Responsibility fell on Stability rather than on the user who typed the prompt, because Stability controlled the datasets and the model behaviour that produced the watermark, while the user controlled neither.
Three lessons transfer directly to any photographer contemplating action.
Territoriality defeats claims before the merits are reached. If training occurred outside the jurisdiction where you can sue, the claim may not survive to the substantive question. This is precisely the gap the AI Act’s market-based reach was designed to close for its own obligations, and it is why the extraterritorial argument became the headline topic at the Court of Justice hearing in March.
Evidence of ingestion is extremely difficult to obtain. Getty is a large company with substantial resources and a strong inference to draw, and it still could not carry the burden. An individual photographer has no realistic prospect of proving that a specific image entered a specific training set without disclosure from the provider. This is the connection back to Article 53. The training-content summary is the only lawful route to that evidence, which is why its thin implementation matters so much.
Outputs are easier to prove than inputs. Getty’s only success came from something visible in the generated image. Where a model reproduces a recognisable element, a watermark, a signature, a distinctive composition, the claim becomes tractable. The commentary that the judgment might have gone differently on copyright with strong evidence of real-world infringing outputs is the practical guidance buried in the case.
The judgment also created a doctrinal oddity worth noting. The court held that an article for the purposes of UK secondary infringement can be intangible, a position that appears to depart from EU distribution-right principles, without addressing the departure. That is a UK problem rather than an EU one, but it illustrates how unsettled the underlying concepts are.
The UK Government was due to publish its full report on the use of copyright works in AI development by March 2026, which will shape the divergence between the UK and EU positions further.
Luxembourg holds the question that decides everything
Every national judgment discussed above is provisional until the Court of Justice of the European Union rules, and the case that will decide the framework is pending.
Case C-250/25, Like Company v Google Ireland Limited, was referred by the Budapest court on 3 April 2025 and is the first preliminary reference on generative AI and copyright to reach Luxembourg. Like Company, a Hungarian news publisher, alleges that Google’s Gemini reproduced and made available portions of its protected press content, including a summary of an article about a plan to introduce dolphins to Lake Balaton.
Four questions were referred. Whether the display in a chatbot response of text partially identical to a press publication, beyond individual words or very short extracts, constitutes communication to the public under the press publishers’ right and the InfoSoc Directive. Whether it matters that the output is produced through probabilistic next-token prediction. Whether training a large language model, by learning and modelling linguistic patterns from protected works, constitutes reproduction. And if it does, whether those acts fall within the text and data mining exception in Article 4 of the Copyright Directive.
The Court sat as a Grand Chamber and held its first oral hearing on generative AI and copyright on 10 March 2026, running six hours. Extraterritoriality became the hearing’s dominant theme, with Member States divided on whether EU copyright law can reach training conducted outside the Union. The Advocate General showed interest in what has been described as the unitary-process theory, asking whether infringement should be assessed by looking at the AI system as a whole, spanning training, grounding, inputs, outputs and communication, rather than isolating individual acts.
That framing, if adopted, would be the most consequential development for creators in the entire European AI copyright debate. Assessing the system as a unified process would make it far harder for a provider to argue that the training happened lawfully elsewhere while only the harmless output reached Europe.
The Advocate General’s opinion is expected on 3 September 2026, a month from now. Judgment will follow, with estimates pointing to late 2026 or into 2027.
Independent scholarly opinion urges caution. The European Copyright Society, whose members include leading copyright academics across Europe, published an opinion in March 2026 arguing that the reference is factually murky, conflating chatbot, large language model and search engine, and inconsistent about which right is actually at issue, since the relevant right is the press publishers’ related right rather than authors’ copyright. The Society also noted that if the system relies on retrieval-augmented generation, the use of the publisher’s content does not form part of the learning process at all, which makes its characterisation as training doubtful.
That critique carries a warning for creators hoping for a decisive win. A reference built on unclear facts can produce a narrow ruling, or an inadmissibility finding, or a judgment about press publishers’ rights that says little about photographs, films or literary works. The Court may also decline the extraterritoriality question entirely as unnecessary to resolve the dispute.
For planning purposes, the sensible position is that the framework question will not be settled before 2027, that national divergence will continue in the meantime, and that any commercial arrangement made now should be drafted to survive either outcome.
Parliament asked for remuneration and the Commission opened a file
The instrument that might actually pay creators is not the AI Act. It is a copyright reform that does not exist yet, and its progress through 2026 is the most direct answer to the question of whether anything will change.
The European Parliament’s Committee on Legal Affairs adopted an own-initiative report on copyright and generative artificial intelligence on 25 February 2026, with Axel Voss as rapporteur. The full Parliament adopted the resulting resolution on 10 March 2026 by 460 votes to 71, with 88 abstentions. The margin matters. That is not a narrow ideological win, it is a broad institutional position.
The resolution’s substance is what creators asked for. It states that EU copyright law should apply to all generative AI systems placed on the EU market regardless of where they were trained. It calls for a coherent and functioning licensing framework enabling fair remuneration of creators for exploitation of their protected content by generative AI models. It encourages providers to seek licences and states that comprehensive transparency about the works used in training is a prerequisite for such a market to develop. It recommends strengthening enforcement and transparency obligations for developers using protected content.
It goes further on mechanism. It asks the Commission to facilitate voluntary collective licensing agreements by sector, in consultation with collecting societies, as a route to a working market that gives rightsholders fair remuneration while giving providers access to training data, and it asks that such agreements be accessible to individual creators and small enterprises, not only to large catalogues. It recalls that a refusal to permit training must be respected. It asks the Commission to examine solutions for immediate, fair and proportionate remuneration for past uses where a licensing market could not yet form. And it asks the Commission to introduce a remuneration obligation on generative AI providers that aggregate and disseminate press publishers’ content in search results and other services, on the basis that those services compete directly with the rightsholders’ own. Earlier drafts floated a role for the EUIPO in mediating licensing and maintaining a machine-readable register of licence offers.
A remuneration obligation for past uses and a mandated collective licensing route are precisely the instruments the AI Act omitted. The Parliament asked for them explicitly, which removes any ambiguity about whether the existing framework was understood to be sufficient. It was not, and the co-legislator said so.
The Commission’s response was procedural. On 13 May 2026 it launched a call for evidence on a targeted legislative initiative under the working title of a directive enhancing the copyright environment for European creativity and innovation, running to 25 June 2026. The same exercise covers a review of the 2019 Copyright Directive, which Article 30(1) of that directive required no earlier than June 2026. The consultation asks about the challenges generative AI poses for rightsholders regarding control of content, licensing models and remuneration, including the rise of AI-generated imitations of personal characteristics. It also covers online piracy of live events, remuneration of performers and producers for recorded music, and access to works for research.
The Commission’s own framing points at licensing and enforcement rather than at prohibition, with stated aims of improving licensing and enforcement of copyright in the AI context and improving conditions for creators’ remuneration. A legislative proposal is expected during 2027.
Run the timeline forward. Proposal in 2027, ordinary legislative procedure through Parliament and Council taking eighteen to thirty months on a contested file, a transposition period of two years for a directive, and national implementation after that. A remuneration mechanism arriving from this process would realistically start paying creators somewhere between 2030 and 2032. Anyone making business decisions on the assumption that EU law will restore licensing income before then is planning on a schedule the legislative process cannot meet.
The lobbying arithmetic is also visible in the consultation record. Submissions from technology policy institutes argued for a broad permissive mining framework and against mandatory remuneration, expanded opt-out rights or new rules on AI-generated works, drawing on parallel arguments made in the United Kingdom. Those submissions land in a Commission that spent the first half of 2026 delaying its own AI rules on competitiveness grounds.
Writers face substitution before they face infringement
For anyone earning from text, the AI Act addresses the wrong problem. The money did not leave because models were trained on articles. It left because answers stopped requiring visits.
The measurement is now extensive and consistent in direction across methodologies that disagree on magnitude. SparkToro and Datos found that fewer than one third of Google searches in 2026 still send a click to the open web, with only around 360 clicks to the open web per 1,000 US searches. Their panel of tens of thousands of domains, all with professional marketers actively working on traffic, showed the share of traffic Google sends declining by eight percentage points between June 2025 and May 2026, a relative drop of roughly 22%.
Pew Research Center’s behavioural tracking of 68,879 real searches found a 47% relative decline in click-through when an AI summary appeared, and that only 1% of users clicked a link inside the summary itself. Seer Interactive’s longitudinal analysis across 25.1 million organic impressions found organic click-through on informational queries falling from roughly 1.76% to 0.61%. Ahrefs measured the reduction in clicks to the first result rising from 34.5% in April 2025 to 58% by December 2025. Press Gazette reported US publisher traffic from Google down 38% year on year. Amsive, working across 700,000 keywords, measured a milder 15% decline. DMG Media reported drops as steep as 89% on specific query types.
The studies measure different things and the low and high figures are not contradictory, they are answers to different questions. What none of them shows is stability.
The vertical distribution matters for anyone choosing what to write. BrightEdge tracking through February 2026 put AI Overview coverage at 88% in healthcare, 83% in education and 82% in business technology. Those are the categories where explainer content used to earn reliably. Gartner’s forecast of a 25% decline in traditional search engine volume by 2026 now looks conservative rather than alarmist.
A labelling duty on synthetic text does nothing about any of this. The economic pressure on writers comes from an interface change at the point of distribution, and the AI Act does not regulate interfaces.
The supply side compounded it. Graphite’s analysis of 55,400 English-language articles sampled from Common Crawl, classified by Pangram, GPTZero and Copyleaks with results averaged, found that articles classified as primarily AI-generated accounted for an estimated 49.9% of sampled content in the first quarter of 2026. The share rose sharply after ChatGPT’s release, from around 36% within twelve months of launch, to roughly 48% by late 2024, then plateaued near half from the start of 2025. A separate Graphite analysis found 86% of articles appearing in Google Search were human-written against 14% AI, which suggests the ranking systems filter a good deal of it. NewsGuard’s tracking had identified 3,749 AI content farm news and information websites across sixteen languages, including Czech, by 23 June 2026.
Graphite was careful about limits, and so should anyone citing it be. Detection tools carry false positives, mixed human and AI workflows defeat article-level classification, and counting new articles is not a census of the web. A 2026 preprint examining archived websites estimated roughly 35% of newly published sites by mid-2025 were AI-generated or AI-assisted, found lower semantic diversity where AI involvement was higher, and did not find reliable evidence of reduced factual accuracy in the sampled material.
The competitive picture for a professional writer is therefore not that the market is flooded with lies. It is that the market is flooded with adequate, fluent, low-differentiation material, priced at close to zero, while the distribution channel that used to reward differentiation has narrowed. That is a harder problem than infringement, and it is the one the AI Act leaves entirely alone.
Photographers lost their licensing floor before the law arrived
Photography sits in the worst position of the three disciplines the question asks about, because it suffered structural damage on both sides simultaneously and the AI Act reaches neither.
The demand side moved first. Generative image tools produce a usable frame inside the same workflow the buyer is already in, in seconds, without a search, a filter, a licence comparison, a download and a crop. That convenience argument, made bluntly on photography industry forums through 2026, is more damaging than any price argument. Stock licensing at subscription rates was already cheap. The competition is not undercutting on price, it is removing a workflow interruption.
The supply side then filled with synthetic material. Platform policies split into distinct camps through 2026. Adobe Stock and Freepik accept AI-generated submissions. Shutterstock permits them but routes them to a separate lower-payout collection. Getty Images bars externally generated AI entirely. iStock sells only AI from its own licensed in-house generator. Adobe pays 33% of net sale on stock with a floor in the region of a third of a dollar per licence, which means an AI contributor earns from volume rather than from any individual image, and that volume competes for the same buyer attention as a professional’s catalogue.
The corporate story reinforced the picture. Getty Images and Shutterstock announced a merger of equals on 7 January 2025, positioned as strengthening the financial foundation of both. Shutterstock stockholders approved it on 10 June 2025. The US Department of Justice concluded its review without conditions on 23 February 2026. The UK Competition and Markets Authority took longer, referring the deal to a Phase 2 review on 3 November 2025 after remedies were offered, issuing an interim report on 19 February 2026 that found no substantial competition concern in the global creative stock market but identified a lessening of competition in the UK editorial market, and conditioning clearance on a sale of Shutterstock’s editorial business. Getty’s board resolved on 30 June 2026 not to proceed with that divestiture, and Getty terminated the merger agreement on 7 July 2026, notifying the CMA the same week. The senior secured notes issued to finance the transaction fell due for special mandatory redemption, and the board moved to retain a financial adviser on financing alternatives.
Two consolidating stock agencies spent eighteen months and substantial financing costs on a transaction that collapsed over a UK editorial business generating around $10.6 million in 2025 revenue. That is a picture of an industry under enough pressure to attempt consolidation and constrained enough that a small divestiture killed it.
Be careful with the numbers circulating about this sector. Several sites publishing in 2026 claim revenue collapses of 68% to 98% for named agencies, Getty bankruptcy, and photographer income falling from $1.47 billion to $31 million. Those figures do not appear in the companies’ filings and the sites carrying them show the hallmarks of automated content production. Getty’s actual position, from its own disclosures, is a company that pursued a merger, cleared US antitrust, walked away from a UK remedy and is evaluating financing alternatives. That is pressure, not collapse, and the difference matters when a photographer is deciding whether to keep a stock portfolio active.
Against that, what does the AI Act deliver to a photographer?
It delivers marking of synthetic images, which is the discipline where marking works best. An image can carry a signed manifest and a statistical watermark, and both survive more handling than a text signal. If the marking duty is implemented properly and platforms preserve provenance, buyers gain the ability to distinguish photography from generation, which is the precondition for pricing the difference.
It delivers a deepfake disclosure duty that catches synthetic depiction of real people and real places in commercial contexts, which is where the most direct substitution for editorial and location photography occurs.
It delivers a transparency hook, through Article 53, that in principle lets a photographer establish whether an image corpus was used. In practice the top-10%-of-domains disclosure will not name an individual portfolio.
It delivers nothing on the opt-out problem, which for photographers is acute because the work is scattered across agencies, platforms and client sites the photographer does not control.
And it delivers nothing on substitution, which is what actually took the income.
The realistic strategic conclusion for professional photography is that regulation is not the lever. The segments holding value are those where the deliverable cannot be generated because it must be true. Editorial and documentary work, where provenance is the product. Events and weddings, where the subject is specific and unrepeatable. Product and location work where the client needs the actual object in the actual place. Portraiture where the person must be that person. The segments losing value are conceptual, illustrative and generic commercial imagery, where the buyer never needed a real referent in the first place.
Video sits where labelling meets money
Moving image is the discipline where the AI Act’s transparency duties align most closely with a commercial interest, and where the substitution threat is newest.
Video generation crossed a usability threshold during 2025 and 2026 for the shot lengths that dominate advertising, social content and stock footage. Simultaneously, the deepfake duty attaches most naturally to video, because the resemblance and false-authenticity criteria are easiest to satisfy in moving image with synchronised audio.
For production companies, the guidance contains two provisions that materially reduce the compliance burden and are worth knowing before a client raises the topic.
First, outputs used only inside closed-loop production environments fall outside the marking duty unless they become the final output. A studio using generative tools for previsualisation, concept frames, rotoscoping assistance or temporary elements is not marking every intermediate asset. Only what ships is in scope.
Second, the audience-expectation test in the deepfake analysis exempts a great deal of standard production. Generated background scenes, special effects and technical pre- and post-processing as part of normal film production are unlikely to make content falsely appear authentic to an audience, because the audience is not being told it is watching unmediated reality. The deepfake duty targets deception about authenticity, not the use of synthetic technique. A science fiction film built substantially from generated imagery does not require a disclosure at first frame. A corporate video featuring a synthetic customer giving a testimonial does.
For artistic, creative, satirical and fictional works containing deepfakes, disclosure is limited to an appropriate manner that does not hamper display or enjoyment, which in practice means credits, accompanying notices or platform-level metadata rather than on-screen overlays.
The provenance side is further advanced in video than the marking discussion usually acknowledges. The C2PA specification reached version 2.3 in December 2025, extending provenance to live streaming through segment signing in CMAF, which matters for broadcast and event work. Verification tooling in professional editing suites can preserve signed edit histories rather than discarding them.
Where video faces its distinct problem is likeness. A performer’s face and voice can be reproduced convincingly enough that the commercial value of the original engagement drops. The AI Act addresses this through disclosure only. It requires a label on the deepfake. It does not require consent, and it does not create a right to be paid for the resemblance. That gap is what Denmark tried to close through copyright, and what the Commission’s copyright review has been asked to consider under the heading of AI-generated imitations of personal characteristics.
For a production company operating in the EU right now, the concrete change is contractual rather than technical. Every engagement involving a recognisable person should specify whether synthetic generation of that person’s likeness or voice is permitted, for what uses, for how long, and at what additional fee. Every deliverable containing synthetic elements should be accompanied by a disclosure recommendation the client can implement, with a record that the recommendation was made. That record is what protects the production company when the client publishes without the label and the authority asks who was responsible.
Provenance is a workflow, not a checkbox
If any part of the current framework produces durable benefit for original creation, it is provenance, and it will only do so if creators treat it as a production discipline rather than an export setting.
The C2PA specification, implemented commercially as Content Credentials, attaches a cryptographically signed manifest recording how an asset was captured and edited. A conformance programme launched in mid-2025 introduced a public registry of products that have passed testing, which separated verified conformance from marketing claims. Adoption through 2026 spans consumer smartphones, professional cameras, editing software, and some platforms. LinkedIn displays an indicator on images carrying credentials that users can click for a provenance summary. TikTok adopted Content Credentials for AI content labelling at consumer scale in partnership with the Content Authenticity Initiative.
The gaps are equally documented and worth stating plainly.
Platforms strip metadata during upload and transcoding. A platform can support Content Credentials in its interface and remove them in its pipeline. Until the major distribution channels preserve manifests end to end, a large share of content loses provenance at the moment of publication.
Absence proves nothing. A file without credentials may be old, produced on an unsupported device, processed through a non-conforming tool, or simply transformed. A credential is positive evidence of authenticity, while its absence is evidence of nothing at all, and that asymmetry will persist for years.
Coverage is partial even where support exists. Lightroom Classic applies Content Credentials on JPEG export but not on TIFF, PSD or raw files. Consumer smartphone cameras outside specific partnership programmes do not sign natively, which leaves most user-generated content unsigned. Nikon added support to the Z6 III by firmware in August 2025, then suspended it after a signing vulnerability, revoking certificates, with the service not restored as of early 2026.
Signing carries a privacy cost that matters for journalism. A signed photograph can expose the photographer’s identity, precise GPS coordinates and device serial. Version 2.1 of the specification added redactable assertions and zero-knowledge identity proofs, but adoption of anonymous-but-verified workflows remains early, and until it matures, press photographers working in hostile environments face a real conflict between provenance and source protection.
And provenance proves origin, not truth. A credential establishes that a file was signed by a particular device or application. It says nothing about whether the camera was pointed at what the caption claims, whether the framing is honest, or whether the context is accurate.
Despite all of that, the direction of travel favours creators who adopt it. Camera Bits confirmed in February 2026 that Photo Mechanic, the first stop in most press photographers’ workflows for ingest, culling and metadata, is gaining C2PA support, with the goal of preserving signatures from camera through to publication. That is the missing link in photojournalism, and its arrival changes what an editor can verify. Competition organisers have begun adopting credential models to deal with AI entries. The US cybersecurity agency recommended content credentials in a January 2025 advisory on multimedia integrity.
The commercial argument for a working professional is narrower than the enthusiasm suggests, and stronger where it applies. Provenance is worth most in business-to-business contexts where the buyer’s own compliance or editorial function has to verify what it publishes. Newsrooms, agencies handling regulated clients, insurers, legal evidence work, real estate media, academic publishing. It is worth least in consumer-facing distribution where a badge is ignored or where the platform strips it before anyone sees it.
The practical implementation for a studio is three steps. Sign at capture where the hardware supports it. Preserve through editing by working in credential-aware modes rather than exporting through tools that discard manifests. Audit the delivery path, meaning the content management system, the CDN and the publishing integrations, to find where manifests are being dropped. Most studios discover the loss happens in a step nobody thought about.
A licensing market is forming outside the statute
The most interesting development for creator income in the past year happened commercially rather than legislatively, and it did so without waiting for the copyright review.
Microsoft launched the Publisher Content Marketplace on 3 February 2026, after a pilot co-designed through late 2025. The structure is a marketplace where publishers set licensing terms and AI companies license content for grounding responses, with usage-based reporting and payment tied to delivered value. Copilot was the first buyer. Named early partners included the Associated Press, Vox Media, Condé Nast, People Inc., USA Today, Business Insider and Hearst titles, with Yahoo joining as a demand partner. Microsoft stated the marketplace would support publishers of all sizes, including independents, and opened a registration form for interested publishers. Commission rates and payout formulas were not disclosed. Amazon was reported in February 2026 to be preparing a comparable marketplace as part of AWS’s AI offerings.
Alongside the platform marketplaces, a standards-based route emerged. Really Simple Licensing, a publisher-backed open standard, expresses licensing terms and pricing directly on a website in a form crawlers can read, which converts the binary opt-out into a priced offer. Its relationship to the platform marketplaces is unresolved, and Microsoft’s announcement did not address integration.
The structural difference between these mechanisms and the AI Act is that they pay for use rather than disclosing it. That is the mechanism the Parliament asked the Commission to build in law, arriving first from companies that concluded a functioning market served them better than continued litigation.
The obvious objection is concentration. If a small number of marketplaces intermediate payments between AI companies and publishers, bargaining power moves to the intermediary, and undisclosed commission structures are not a promising start. Attribution is also technically hard when a single AI response draws on several sources, and payout formulas that nobody can audit invite the same complaints publishers made about programmatic advertising.
The second objection matters more for the readers of this article. These marketplaces are built for publishers with catalogues, editorial infrastructure and legal teams. A photographer with 40,000 images, a documentary maker with a back catalogue, or a freelance writer with a portfolio across twenty client sites cannot participate directly. The Parliament’s resolution anticipated this, which is why it asked that collective licensing arrangements be accessible to individual creators and small enterprises rather than only to large catalogues. Whether that access materialises will determine whether the emerging market pays creators or pays the companies that publish them.
There is a rough parallel with music. Collective management developed because individual negotiation between millions of authors and thousands of users was impossible, and the institutions that resulted, whatever their flaws, do route money to individuals. Nothing equivalent exists for photography, freelance journalism or independent video, and building it is an organisational problem rather than a legal one. CEPIC on the image side and national authors’ societies on the text side are the plausible starting points, and the Commission’s stated openness to sector-by-sector voluntary collective licensing is an invitation those bodies should be taking up now rather than after a 2027 proposal.
Crawl economics became the real point of pressure
While Brussels debated opt-out protocols, the infrastructure layer built something closer to an enforcement mechanism, and the numbers it published reframed the argument.
Cloudflare, which handles traffic for roughly a fifth of the web, has been publishing crawl-to-referral ratios to show that the historic exchange of access for traffic has broken down for AI crawlers. Its 2025 figures put Google at around 14 crawls per referral, OpenAI in the region of 1,700, and Anthropic in the tens of thousands. Later figures cited in coverage of the company’s July 2026 announcement put Anthropic’s ratio around 38,000 pages crawled per referral visit and OpenAI’s around 1,091. The ratios differ between reports and periods, and the metric counts referral visits rather than impressions, which is exactly the point. A mention inside an AI answer may build a brand. Only a referral visit can be monetised by an ad stack.
The composition of bot traffic changed alongside it. On 3 June 2026, Cloudflare’s chief executive shared Radar data showing automated requests generating 57.5% of HTML traffic, the first time machines held the majority. By June 2026, training crawlers made up around half of AI bot traffic on the network, while search bots, the ones that historically paid for access with clicks, had fallen to roughly a tenth. More than half of AI crawl traffic was re-fetching pages that had not changed.
Cloudflare’s response ran in two directions. It opened a private beta of Pay Per Crawl, returning HTTP 402 Payment Required to AI crawlers unless they authenticate with a signed request and declare willingness to pay, with a floor of one cent per successful retrieval and per-crawler policies allowing publishers to permit, charge or block each crawler independently. It then announced on 1 July 2026 that from 15 September 2026 its defaults would block mixed-use crawlers, meaning those blending search indexing with AI training and agent use, on any page carrying ads. The new defaults apply to new customers, new sites of existing customers and all free-tier accounts, with existing customers able to adjust settings. Pay Per Crawl is evolving into a Pay Per Use model that pays when content is used in an answer rather than when a page is fetched, supported by an attribution dashboard, and Cloudflare acquired Human Native, which built tooling to convert unstructured web content into structured datasets for AI licensing.
The permission model at the infrastructure layer is being unbundled, which is the change the Copyright Directive’s opt-out was supposed to deliver and did not. A publisher can now allow search indexing while refusing training, which is what publishers actually wanted rather than the all-or-nothing choice robots.txt offered.
Two caveats keep this from being a solution. Adoption by the major labs is not there. Named partners in the Pay Per Use variant have been smaller AI companies, and the largest providers have not announced support for the authentication scheme the payment model depends on. Without that, enabling the feature results in content being blocked rather than monetised, which protects the work without paying for it.
And the interaction with visibility cuts against many creators’ interests. If blocking becomes the default on ad-supported pages, the pages a brand relies on for citation in AI answers may disappear from those answers. For an agency selling generative engine optimisation, that tension is the central strategic question of the next year. Blocking protects the asset and reduces the reach. Permitting builds the citation and funds the substitute.
Early testing on a large public dataset reportedly cut unauthorised bot traffic by roughly a third and lifted data-licensing revenue by around a quarter, which suggests the model works where the counterparty is willing to pay. The willingness is the constraint, not the technology.
Newsrooms and the editorial exemption they now depend on
Journalism carries the sharpest version of every tension in this article, and it is the sector where the AI Act’s provisions come closest to mattering commercially.
The exemption in Article 50(4) for text under human review or editorial control was written with journalism in mind, and it gives newsrooms something structurally useful. A publication with a named editor-in-chief exercising substantive control, a fact-checking process and clear editorial responsibility publishes AI-assisted text on public-interest matters without a disclosure obligation, while an unreviewed content operation publishing the same material must label it.
That distinction is enforceable against identifiable publishers, which is where market surveillance authorities can realistically act. NewsGuard’s count of 3,749 AI content farm sites across sixteen languages describes the population most exposed, and while many operate outside the EU or behind anonymous registrations, those distributing into the Union and monetising there are within reach.
Against that, the revenue picture is severe and unaddressed. Press Gazette reported US publisher Google traffic down 38% year on year. Named publishers have reported organic traffic losses in the range of 30% to 55%, with staffing reductions following. The press publishers’ right created in 2019 has not produced the negotiating power it promised, which is part of why the Parliament asked the Commission to introduce a remuneration obligation on generative AI providers that aggregate press content in search results and other services.
Litigation and licensing are running in parallel, sometimes at the same publisher. Danish press publishers announced proceedings against OpenAI in July 2025. Several publishers that had sued Microsoft joined the co-design process for its content marketplace. That combination is not incoherent, it is the standard posture of a party negotiating with a credible threat behind it.
For newsrooms, the AI Act’s practical contribution is that the transparency documents it produces are the evidentiary base for both tracks. A training-content summary establishes what categories of content were ingested. A complaint mechanism under the Code of Practice creates a record. A qualified alert from the scientific panel can trigger AI Office action. None of that is a licence, and all of it is material a lawyer or a negotiator can use.
The provenance question also lands hardest here. A newsroom verifying user-submitted footage during a breaking story needs provenance more than any other buyer, and it faces the platform-stripping problem more acutely because the material arrives through consumer channels. The arrival of C2PA support in Photo Mechanic addresses the outbound chain from staff photographers. The inbound chain, where a video reaches the desk through a messaging app, remains largely unsigned.
Agencies, freelancers and the disclosure paperwork
For a digital agency, the AI Act arrived yesterday as an operational obligation rather than a strategic opportunity, and the exposure is asymmetric.
An agency is a deployer for every generative system it uses on a client’s behalf, and it remains the deployer even when contractors and freelancers operate those systems under its direction. Individual employees are not separate deployers. A freelancer earning regularly from the work is a deployer in their own right when acting on their own account.
Two duties bite immediately. Deepfakes produced for client campaigns require clear disclosure to the viewer at first exposure. Unreviewed AI-generated text published on public-interest matters requires clear labelling, unless the agency can demonstrate substantive human review or editorial control by someone with relevant subject knowledge and ultimate legal responsibility for publication.
The second of those is where most agencies are exposed, because the volume of published content on health, finance, energy, consumer safety and public administration topics produced with generative assistance is enormous, and the review step is frequently the sort of formal check the guidance explicitly excludes. Spell-checking and grammar correction do not qualify. The question a regulator asks is not whether a human touched the draft, it is whether a named person with relevant knowledge examined the substance and holds legal responsibility for publishing it.
The defensible operating model is documentation that costs almost nothing to maintain. For each deliverable, record which generative tools were used and for what. Record the reviewer, their relevant expertise and what they checked. Record whether the client was advised that a disclosure was required, and what was recommended. Record what the client published. Four fields in a project management system, retained for the limitation period, answers every question an authority is likely to ask about a specific piece of content.
Client contracts need three additions. An allocation of who carries the deployer duty for published output, since the agency’s client is often the actual publisher. A warranty structure that does not have the agency guaranteeing the legality of a client’s publication decisions. And an express statement of whether generative tools may be used in production, because a growing number of procurement documents now ask, and answering inconsistently across pitches is a credibility problem.
There is a modest commercial upside. An agency that can evidence editorial responsibility is selling something a regulated client can publish without a disclosure obligation, and the compliance function on the client side understands that immediately. It is not a premium proposition on its own. It is a reason to be shortlisted where the alternative supplier cannot answer the question.
Film, television and advertising production
Production companies face the AI Act as a set of workflow questions with clear answers, and a set of talent questions with none.
The workflow answers are mostly favourable. Intermediate assets generated inside a closed production pipeline fall outside the marking duty unless they become the final output, which covers previsualisation, concept art, temporary elements, clean-up passes and technical processing. Generated backgrounds, effects and standard pre- and post-processing are unlikely to trigger deepfake disclosure, because a cinema audience does not expect unmediated reality. Where a deepfake does appear in an evidently creative or fictional work, disclosure must be appropriate to the work and must not interfere with its display, which credits and accompanying notices satisfy.
Advertising is where the analysis tightens. An audience watching an advertisement does expect the customer to be a customer, the doctor to be a doctor and the location to be the location. Synthetic depiction of any of those meets the resemblance and existence criteria, and the audience-expectation limb of the false-authenticity test runs against the advertiser. A synthetic presenter, a cloned voice, a fabricated testimonial and a generated product-in-use shot all sit inside the deepfake duty, with disclosure required at first exposure in a form the viewer can perceive without tools.
The talent question is unresolved and it is the one that determines income for performers, voice artists and, indirectly, the crews that support them. The AI Act requires disclosure of a synthetic likeness. It does not require consent from the person depicted, and it does not create a right to remuneration for the resemblance. A performer’s protection therefore rests on contract, on national personality rights, on data protection where biometric data is processed, and in Denmark on a new neighbouring right.
Voice work is furthest along in the substitution. Dubbing, subtitling and adaptation were identified in the CISAC study conducted by PMP Strategy as the audiovisual roles facing the sharpest exposure, with 56% of translators’ and adaptors’ revenue assessed as at risk by 2028, against 15% to 20% cannibalisation for screenwriters and directors. That study, published in December 2024, projected 21% of audiovisual creators’ revenues at risk by 2028, amounting to a cumulative €12 billion loss over five years, alongside 24% and €10 billion for music creators, on the express assumption of an unchanged regulatory framework.
The regulatory framework did change, and it changed in a way the study’s assumptions did not contemplate, because what arrived was disclosure rather than remuneration. A labelled synthetic voice-over displaces a session as thoroughly as an unlabelled one.
The practical response in production contracts is now standard among the better-advised companies. Separate the engagement fee from any licence to generate synthetic versions of the performer. Specify the permitted uses, territories and duration of any such licence, and price it independently. Require the client to obtain written consent for any synthetic likeness of a real person appearing in a deliverable. Provide the client with a disclosure recommendation in writing and keep the record. Where the production supplies assets rather than a finished publication, make explicit that the publishing party carries the deployer duty.
For crews on the technical side, the honest assessment is that generative tools reduce hours on specific tasks rather than removing roles wholesale. Background replacement, clean-up, upscaling, colour work and simple compositing absorbed a large share of billable time on commercial productions, and those hours compress. The work that holds up is what requires physical presence, direction of real performers, and responsibility for a shoot that has to happen once.
Music, voice and the collecting societies
Music is not one of the three disciplines the question names, and it deserves a section anyway, because it is where the legal strategy that might eventually protect writers and photographers is being tested.
The collecting societies had three structural advantages nobody else has. They hold mandates from large memberships, which let GEMA declare a text and data mining reservation on behalf of members rather than requiring each songwriter to configure a website. They have decades of experience litigating and licensing at scale against reluctant counterparties. And their repertoire is highly identifiable, meaning a court can compare a known lyric or melody against a model output and see the match.
That combination produced results. The Munich I Regional Court found for GEMA against OpenAI on 11 November 2025, holding that memorisation of lyrics in model parameters is reproduction and that the mining exception does not cover durable encoding in weights. The same chamber found for GEMA against Suno on 31 July 2026, extending the reasoning to compositions and to the making-available right, ordering disclosure of revenues and damages. In the March hearing, originals and Suno outputs were played back to back in the courtroom and the melodies matched. The court noted it was undisputed that the works had been used in training and obtained from the internet through stream-ripping.
Neither judgment is final. OpenAI has appealed and Suno may. But the strategy is now proven, and it is transferable to any sector that can organise collective mandates and produce identifiable works.
Photography has the identifiability. A distinctive image reproduced closely enough is as recognisable as a melody. What photography lacks is the collective mandate infrastructure, and building it is the single most consequential organisational project available to the image sector.
Text is harder on both counts. Prose is more diffuse, memorisation of a specific paragraph is less likely for most published writing than for a famous lyric, and authors’ societies vary widely in the breadth of their mandates. The GEMA route works best for works that are short, famous and repeatedly requested, which describes lyrics and describes very little journalism.
The voice question connects music to the video sector. Voice cloning affects session musicians, narrators, dubbing artists and presenters, and the AI Act’s response is a disclosure duty on the deployer rather than a consent requirement or a payment. Collecting societies with performer members are the natural vehicle for collective negotiation over voice, and the Commission’s stated willingness to facilitate sector-by-sector voluntary collective licensing is an opening.
The Parliament’s request for a solution covering past uses, where a licensing market could not yet form, matters most in music because the scale of unlicensed historical training is largest and best documented there. If a mechanism for historical remuneration is built for music, the template exists for images and text.
Stock libraries, archives and education publishing
Three adjacent markets absorb much of the commercial impact and none of the regulatory attention.
Stock libraries occupy the position described earlier, with contributor policies now split between accepting synthetic submissions, segregating them into lower-paying collections, barring external AI entirely, or selling only in-house licensed generation. The collapse of the Getty and Shutterstock merger on 7 July 2026, after the UK regulator conditioned clearance on divesting Shutterstock’s editorial business and Getty declined, leaves two separately listed companies facing the same demand-side pressure without the cost synergies they had planned for. Contributors should read that as continued downward pressure on rates rather than as a crisis with a defined end.
Archives sit in a more interesting position. An archive’s value increases when synthetic material floods the market, because an archive holds material that provably existed at a particular time and place. Provenance infrastructure raises that value further, since a signed chain of custody from an archival record is exactly what a verification process needs. The US Library of Congress launched a community of practice in July 2025 to examine content credentials in archival and preservation workflows, which is a signal of where institutional attention is going. For a photographer with a substantial back catalogue of documentary material, the archive framing is a better commercial story than the stock framing.
Education publishing faces the substitution problem in its purest form. Explainer content, worked examples, revision material and reference summaries are precisely what generative systems produce adequately, and AI Overview coverage in the education vertical ran at around 83% by February 2026. The publishers holding value are those selling assessment, accreditation, curriculum alignment and institutional trust rather than explanation.
In all three markets the pattern repeats. Value migrates from the artefact to the guarantee. What survives is not the image, the paragraph or the diagram, it is the assurance that it is what it claims to be, produced by someone accountable for the claim.
Academic and scientific publishing deserves a footnote here because the Article 50(4) exemption names peer review explicitly as an example of qualifying human review. A journal running substantive peer review publishes AI-assisted text on public-interest scientific matters without a labelling obligation. That is a rare instance of an EU compliance rule aligning neatly with an existing professional practice rather than requiring a new one.
Scientific research also enjoys a separate and broader mining exception under Article 3 of the Copyright Directive, which cannot be overridden by contract and which the Commission’s copyright review is examining alongside access and reuse of works for research. Any tightening of the commercial mining exception in a 2027 proposal will need to preserve that research pathway, and the two exceptions are frequently conflated in public debate about whether AI training is legal in Europe.
Denmark tried to put copyright on faces
The most inventive national response to synthetic media came from Copenhagen, and the Commission’s reaction to it tells you a great deal about the limits of what Member States can do alone.
Denmark published a draft bill on 7 July 2025 amending its Copyright Act to introduce two personality rights. The first would give a natural person the ability to prohibit online dissemination of realistic digital imitations of their personal characteristics, including voice, appearance and movements. The second, in a proposed section 65a, would protect artists and performers against realistic digital imitations of their performances, limited to making such content available to the public rather than to reproduction. The right was framed as a neighbouring right to copyright, civil in nature, with exceptions for news reporting, satire and artistic expression, and it was drafted to extend to any natural person whose likeness is disseminated within Danish jurisdiction rather than to Danish nationals alone.
Consultation closed on 21 August 2025. The amended draft was notified to the Commission under the technical regulation procedure on 31 October 2025. Cross-party support was reported. Expected entry into force moved through several dates during 2026, with 31 March and 1 July both cited before a snap general election intervened, and as of the spring the bill had not received final parliamentary adoption. The culture minister was explicit that he hoped to export the model to the rest of the Union, and pressed European counterparts to adopt similar measures during Denmark’s Council presidency.
The Commission pushed back on substance. Its objections, echoed in academic commentary and in a European Parliament briefing, run roughly as follows. Copyright protects original works reflecting the author’s own intellectual creation. Voice, appearance and likeness considered in isolation are not works. International instruments and Court of Justice case law confirm that copyright does not extend to ideas and does not apply where expression is dictated by function. Copyright vests in the creator, not in the person depicted, which is exactly why the rights in a photograph belong to the photographer rather than the subject, and the Danish proposal inverts that logic. Several Member States, responding to the Danish presidency’s own policy questionnaire, argued that deepfake harms extend beyond the remit of copyright law. Academic commentators questioned whether a standalone personality-rights statute would be the better vehicle.
There is a second objection with more force than the doctrinal one. The Danish rules would operate against illegal content on Danish territory through geo-blocking by very large online platforms and search engines. If no other Member State adopts equivalent rules, deepfakes imitating a person’s characteristics remain available everywhere else. A national right against a borderless harm produces a national remedy and a continuing problem.
For photographers and performers, the episode carries a mixed lesson. The initiative demonstrated that a Member State can move faster than the Union on a specific harm, that political support for protecting likeness is available, and that the copyright framework is a plausible if contested vehicle. It also demonstrated that harmonisation constrains national creativity, that the Commission will invoke it, and that a right transferable and commercially exploitable by design raises a question the proposal’s supporters did not settle. If likeness becomes property, it can be sold, and the parties best placed to buy it are the ones a performer most needs protection from.
France took a different route, using criminal law in its digital spaces legislation to prohibit sharing AI-created images or audio of a person without consent, requiring platforms to indicate such content clearly as AI-generated, and banning pornographic deepfakes whether labelled or not. The Digital Omnibus added a prohibition to Article 5 of the AI Act covering AI systems that generate child sexual abuse material and non-consensual intimate imagery, which addresses the most severe category at Union level without touching commercial likeness use.
Where the law helps and where it does not
Set against the question directly, the framework divides into three columns rather than two. Some things improved, some things did not change, and some things got worse during the period the law was being built.
Assessment by discipline of what the current EU framework delivers
| Area | What the framework provides | What it leaves unaddressed |
|---|---|---|
| Text and journalism | Labelling duty on unreviewed public-interest AI text, exemption for genuine editorial control, training-content disclosure | Referral traffic collapse, substitution by adequate synthetic copy, no remuneration mechanism |
| Photography | Marking duty where provenance technology works best, deepfake disclosure for synthetic people and places | Opt-out burden across uncontrolled platforms, licensing rate erosion, individual works invisible in disclosures |
| Video and film | Closed-loop and standard-editing exemptions, audience-expectation test, disclosure for synthetic likeness | No consent or payment right for likeness, voice substitution, unresolved performer economics |
| Training and licensing | Copyright policy duty on model providers, market-based territorial reach, complaint channel under the Code | No licence requirement, no levy, no collective mechanism, dataset intermediaries not audited |
| Enforcement | AI Office powers over model providers from 2 August 2026, fines to €15m or 3% | Eight of twenty-seven single points of contact as of March 2026, no content-level audits, complaint-driven only |
Read across the right-hand column and the answer to the original question becomes clear. The AI Act supports original creation procedurally and does not support it economically. Where economic support might come from, it comes from courts, from infrastructure providers and from commercial marketplaces, none of which is the AI Act.
Practical moves for a working creator this quarter
Regulation that arrived yesterday produces a short list of things worth doing in the next ninety days, and a longer list of things that can wait.
Start with the disclosure duties, because they are live and they attach to you as a deployer rather than to a distant model provider. Identify every output you publish or supply that contains AI-generated or manipulated image, audio or video resembling a real person, place, object or event. For each, decide whether the intended audience in that context expects authenticity. Where the answer is yes, add a disclosure the viewer perceives at first exposure without tools. The EU’s published icon set is available for this and using it removes an argument about adequacy.
Next, audit published text against the public-interest categories. Politics, public administration, justice, fundamental rights, public security, public health, environmental protection, consumer safety and economic, financial, scientific or cultural developments relevant to public debate. That covers more commercial content than most people assume. For anything in scope produced with generative assistance, either establish a documented substantive review by a named person with relevant expertise and legal responsibility for publication, or label it.
Build the record while you build the process. One row per deliverable, with tools used, reviewer, what was checked, what disclosure was recommended and what the client published. This is the cheapest insurance available and it is the only thing that answers a specific question from a specific authority about a specific piece of content.
Reserve rights where you control the surface. Implement machine-readable reservations on your own domain now, using robots.txt at minimum since the Code of Practice names it, and add the protocols the Commission’s forthcoming list is likely to endorse as that list emerges. Accept that you cannot reserve rights on surfaces you do not control, and treat that as an argument for consolidating your best work onto a domain you own.
Join or press a collective. The single mechanism proven to work against a model provider in a European court was a reservation declared by an organisation holding a mandate from its members. Individual reservation is administratively impossible at portfolio scale. If your sector body does not have a mandate structure, that is the thing to ask for at the next general meeting.
Start signing at capture where the hardware allows, preserve credentials through editing, and audit the delivery chain for the step that strips them. Do this for work where the buyer verifies what they publish, which means editorial, regulated-sector, legal and institutional clients. Do not expect it to pay in consumer social distribution.
Decide your crawler posture deliberately rather than by default. From 15 September 2026, Cloudflare’s defaults will block mixed-use crawlers on ad-supported pages for new and free-tier sites. If you rely on citation in AI answers for lead generation, that default may work against you. If you rely on licensing or on protecting a catalogue, it works for you. The decision is a business decision about whether you sell attention or sell access, and it should be made once, deliberately, and reviewed rather than inherited from a hosting provider’s settings.
Rewrite two clauses in your standard contract. One allocating the deployer duty for published output between you and the client. One on synthetic reproduction of any real person appearing in your work, separating the engagement fee from a priced, time-limited and use-limited licence for synthetic versions.
What can wait is anything connected to high-risk obligations, conformity assessment or the harmonised standards, which now sit in December 2027 and August 2028 and which almost certainly do not apply to creative production work in any case.
Contract clauses and pricing worth changing now
Regulation shifts risk between parties, and risk that has shifted is a pricing question before it is a legal one. Four changes are worth making to standard terms this year.
The first is the allocation of the deployer duty. In most agency and production relationships, the party that publishes is the client, which makes the client the deployer for the disclosure duties in Article 50(4) and for deepfake disclosure. The supplier’s contract should say so, should record that the supplier advised on the required disclosure, and should stop short of warranting the legality of the client’s publication decisions. A supplier that accepts an unqualified compliance warranty for a publication it does not control has priced a risk it cannot manage.
The second is separation of the creation fee from the synthetic reproduction licence. This applies to any engagement involving a recognisable person, a distinctive voice or a body of work that could be used as training material. Historically a photographer’s licence covered usage of the images. It now needs to address, separately, whether the client or anyone downstream may use the delivered material to train, fine-tune or condition a generative system, and whether they may generate synthetic variants. Silence on that point defaults to the client’s interpretation, and clients’ standard terms have been quietly expanding to include it.
The third is the training-use provision itself, and it needs to work in both directions. As a supplier, decide whether you permit training on your delivered work, at what price, and with what carve-outs. As a buyer of freelance work, decide the same. A photographer who grants unrestricted rights on a shoot has licensed the raw material for their own replacement, and the fee that made sense for publication use does not make sense for that. Agencies commissioning freelance photography and writing should expect this clause to appear in incoming contracts and should have a position on it.
The fourth is disclosure and record-keeping obligations flowing both ways. The supplier should undertake to disclose which generative tools were used in production, because clients in regulated sectors increasingly need that for their own compliance files. The client should undertake to implement recommended disclosures and to notify the supplier if it publishes without them.
On pricing, three adjustments follow from the analysis above.
Work that cannot be generated because it must be true should be priced away from work that can. That means separating a documentary, editorial, event or product rate from a conceptual or illustrative rate, rather than maintaining a single day rate that gets benchmarked against generation cost. The buyer of a real photograph of a real thing is buying evidence, and evidence has never been priced against illustration.
Verification and provenance work should be a line item. Signing at capture, preserving credentials through the edit and delivering a verifiable chain of custody costs time and adds value for a specific class of buyer. Bundling it into the base rate makes it invisible and unpaid.
Review and editorial responsibility should be a line item for text work. If a client needs published output that does not require an AI disclosure under Article 50(4), someone with relevant expertise has to examine the substance and accept legal responsibility. That is a service with a defined regulatory function and it should be quoted as one, not absorbed into a per-word rate.
None of this changes the demand curve. It changes what you are selling on the parts of the curve that still hold, and it stops the erosion of terms that has been happening by default in the absence of anyone raising the question.
Failure modes inside the transparency regime
Assume for a moment that everything in Article 50 is implemented as designed. The regime still contains four failure modes that will shape how much good it does.
The first is the absence-proves-nothing asymmetry, which is structural rather than a defect of implementation. In a market where a minority of content carries provenance, a credential is evidence of authenticity and its absence is evidence of nothing. That means labelling cannot be used to identify synthetic content, only to identify some of it. A bad actor’s simplest strategy is to strip metadata, which is neither technically difficult nor easily detected, and the resulting file is indistinguishable from an unsigned genuine photograph taken on an older camera.
The second is label fatigue. If disclosure appears on a large fraction of content, it stops carrying information. Photography commentators have raised the possibility that a public already conditioned to assume anything might be fake will treat provenance indicators as noise regardless of what the metadata says, which would make public apathy a larger obstacle to adoption than any technical problem. The value of a label is inversely related to how many things carry it, and the value of the exemption for edited content depends on audiences noticing which things do not.
The third is the compliance-theatre risk visible already in the training-content disclosures. A duty satisfied by publishing a document that meets a template while revealing nothing actionable produces the appearance of transparency and none of the effect. Five findable summaries in five months, with inconsistent units and a disclosure threshold that names only the largest domains, is what a formally satisfied duty looks like. Enforcement powers activating yesterday may change that, or may produce more documents of the same kind.
The fourth is displacement of the harm rather than reduction. If EU rules make marked, labelled, documented deployment more expensive, the incentive is to serve the EU market from a posture that minimises exposure while continuing everything else elsewhere. The Act’s market-based reach is designed to prevent that, and the extraterritoriality argument at the Court of Justice hearing in March is exactly the fight over whether it works. If the Court declines to extend EU copyright reach to training conducted abroad, the AI Act’s transparency duties become a labelling regime for outputs sold into Europe, with the training economics untouched.
A fifth risk sits outside the regime and affects everyone in it. Research on model collapse, including work published in Nature in 2024, examined what happens when models are trained recursively on generated data, and subsequent work argued that accumulating real alongside synthetic data breaks the recursion problem. If roughly half of newly published articles are classified as primarily AI-generated, and if the share of synthetic imagery keeps rising, the value of verifiably human-made material as training input rises with it. That is an argument for licensing markets that pay for provenance-verified human work, and it is the most plausible commercial mechanism by which original creation gets paid, because it aligns the buyer’s technical interest with the creator’s economic one rather than relying on regulation to override it.
Definitions that decide outcomes
Several arguments about whether the AI Act protects creative work are actually disagreements about definitions, and getting them right changes the answer.
A provider, under Article 3(3), is a person or body that develops an AI system, or has one developed, and places it on the EU market or puts it into service under their own name or trademark, irrespective of whether they are established inside or outside the Union. Providers outside the EU fall within the Act where the output of their system is used in the EU. A deployer is a person or body using an AI system under their authority, excluding personal, non-professional use. The same person can be both, and an agency that builds a client-facing tool on top of a third-party model becomes a provider of that system while remaining a deployer of others.
A general-purpose AI model is the object of Article 53’s copyright duties. A general-purpose AI system built on such a model is the object of Article 50’s transparency duties. The distinction is why the AI Office supervises copyright policy at the model layer while national authorities supervise labelling at the system layer, and why the AI Office’s competence over Article 50 is limited to cases where the same entity provides both, or where the system is integrated into a designated very large online platform or search engine.
Text and data mining, in the sense of Article 4 of the Copyright Directive, is the automated analysis of digital material to generate information such as patterns and correlations. Whether model training is text and data mining is not settled, and it is the third question referred in Case C-250/25. The German judgments answered it by distinguishing analysis, which is covered, from durable retention of protected content in model parameters, which they held is not.
A reservation of rights under Article 4(3) is the mechanism by which a rightsholder removes the mining exception for their work. For content publicly available online it must be machine-readable. What qualifies is the subject of the Commission’s consultation process and the list it will publish.
A deepfake, under Article 3(60), requires resemblance, existence of the simulated subject and false appearance of authenticity, all three cumulatively. Synthetic content that fails any of the three is not a deepfake for the purposes of the disclosure duty, however synthetic it is.
The word marking means machine-readable provenance for detection tools, while labelling means human-perceivable disclosure, and the two duties fall on different parties. Every practical compliance error in this area starts by treating them as one thing.
Human review, for the purposes of the Article 50(4) exemption, is deliberate examination of the substance by a person with relevant knowledge and professional judgement about the subject matter. Editorial control is control exercised in practice by a responsible editorial entity with authority to approve, alter or reject substance on substantive grounds. Editorial responsibility means ultimate legal responsibility for publication. Formal checks are excluded by name.
The United Kingdom and United States positions diverge
European creators operate in a market where the same work is treated differently in three of the largest jurisdictions, and the divergence is widening rather than converging.
The United Kingdom retains a narrower mining exception than the EU, limited to non-commercial research, and has spent two years consulting on whether to broaden it. A proposal for a commercial exception with a rights reservation, modelled loosely on the EU approach, met organised opposition from the creative sector during 2025. The Government was required to publish a full report on the use of copyright works in AI development by March 2026. The Getty judgment then demonstrated that even under existing UK law, the practical obstacles to a claim are territorial and evidential rather than doctrinal, and the court’s finding that Stable Diffusion contains no copies of its training works removed the most direct route to liability. The court also held that an article for secondary infringement purposes can be intangible, a position that appears to depart from EU distribution-right principles and that a higher court may revisit.
The United States operates on fair use, which is a case-by-case defence rather than a rule, and which produces outcomes European creators find hard to predict. Settlements have been substantial in specific circumstances, particularly where sourcing from pirated material was in evidence, while transformative-use arguments have succeeded in others. What matters for a European creator is that a US provider training under fair use assumptions and then serving European users cannot rely on that defence for the EU-facing part of its operation, at least on the Commission’s reading of the Act’s territorial reach.
That reading is precisely what the Court of Justice is being asked to test. If the Court adopts something like the unitary-process approach the Advocate General probed at the March hearing, assessing the system as a whole rather than isolating training from output, the practical consequence is that a model offered in Europe is assessed against European standards regardless of where the compute sat. If it declines, the gap between the jurisdictions becomes an arbitrage opportunity rather than a compliance question.
The strategic implication for a European creator is that jurisdiction of use, not jurisdiction of training, is where the bargaining power lies. A claim against a provider’s European offering is more tractable than a claim about training conducted on another continent, and licensing negotiations conducted on the basis of EU market access are stronger than negotiations conducted on the basis of where a dataset was assembled.
There is a competitiveness counter-argument running in parallel that European creators should understand rather than dismiss. Submissions to the Commission’s copyright consultation argued that restricting the mining framework would restrict AI development in Europe without commensurate benefit to creators, pointing at the same debate in the United Kingdom, and noting that EU regulatory choices carry global weight. That argument has real institutional purchase in a Commission that spent the first half of 2026 delaying its own AI rules on readiness and competitiveness grounds, and it is the argument the copyright proposal will have to survive.
Central Europe and the smaller language markets
Most analysis of the AI Act is written from Brussels, Berlin or London, and the position in the smaller Member States differs in ways that matter for anyone working in Slovak, Czech, Hungarian or comparable markets.
Institutional capacity is the first difference. With eight of twenty-seven single points of contact designated as of March 2026 and around nine Member States having designated both market surveillance and notifying authorities by June, the smaller administrations are disproportionately represented among those still working through national implementing legislation. Conformity assessment infrastructure is concentrated in Germany, France and the Netherlands. For a creator in a smaller Member State, the practical effect is that the complaint route contemplated by the Act may not have a functioning address, and that supervision of local deployers will be thinner and later than in the larger markets.
Language market economics is the second. Smaller language markets had thinner commercial content economies to begin with, which means both that the absolute revenue at risk is smaller and that the remaining margin is more fragile. A drop in referral traffic that a large German publisher absorbs by cutting a desk can remove the viability of a Slovak or Czech title entirely. NewsGuard’s tracking of AI content farms across sixteen languages includes Czech, which indicates that automated content operations have found the smaller markets worth targeting, and the reason is straightforward. Competition for the search real estate is weaker and the cost of producing adequate copy in any language collapsed at the same time it collapsed in English.
Enforcement of the labelling duty in a small market is where the gap between the text and reality will show fastest. The duty applies to a deployer publishing unreviewed public-interest text in Slovak exactly as it does in German. The probability of an authority acting on it in the near term is materially lower.
There is one asymmetric advantage. In markets where professional editorial infrastructure is scarce, being the supplier who can evidence substantive review and named editorial responsibility is a stronger differentiator than in markets where every competitor can. The Article 50(4) exemption is a compliance credential, and credentials are worth most where they are rare.
Provenance adoption is the area where smaller markets will lag hardest, because it depends on hardware, software and platform decisions made elsewhere. A photographer in Bratislava can sign at capture only if their camera supports it, and can preserve credentials only through tools that implement the specification. The infrastructure will arrive, later, and the practical advice is to be ready for it rather than to wait for it.
Realistic scenarios for 2027 and 2028
Three outcomes are plausible from here, and the branch point is the Court of Justice rather than the Commission.
In the first scenario, the Court of Justice follows something close to the German reasoning. Training that results in durable retention of protected content in model weights is reproduction, the mining exception does not cover it, and the system is assessed as a whole so that offering the model in Europe brings the training within reach. Model providers face a licensing requirement for European deployment. The Commission’s 2027 copyright proposal then becomes a mechanism for organising a market that already has to exist, most likely through sector-by-sector collective licensing with the EUIPO in some registry or mediation role, as the Parliament suggested. Creators with collective representation get paid. Creators without it get paid through whatever collective structures their sectors manage to build by then, which is why the organisational work matters now rather than after the judgment.
In the second scenario, the Court follows the reasoning in the English High Court on model contents, or resolves the reference narrowly on press publishers’ rights, or declines the extraterritoriality question. Training remains outside the reproduction right in most configurations. The AI Act’s transparency duties become the whole of the European framework, the copyright proposal arrives weakened by the same competitiveness arguments that reshaped the Digital Omnibus, and the licensing market develops only where commercial parties choose it, which means for large publishers through marketplaces and infrastructure deals and not for individuals.
In the third scenario, and this is the one the evidence currently supports most, the answer is mixed and slow. A judgment that resolves some questions and refers others back to national courts. Divergent national case law continuing through 2027 and 2028 as appellate courts in Germany and elsewhere work through the memorisation question. A copyright directive proposed in 2027, negotiated into 2029, transposed into 2031. Meanwhile the commercial layer, marketplaces, crawl controls and provenance-verified licensing, becomes the operative system because it is the only one that pays anything before the end of the decade.
In all three scenarios, the labelling regime that arrived yesterday stays in place and the substitution pressure on creative work continues, because nothing in any of the three addresses the interface change at the point of distribution. That is the part of the assessment that does not branch.
Two further developments are worth watching because they could change the picture independently of the courts. The first is whether the Commission’s list of agreed machine-readable reservation protocols, when it appears, converts opt-out from a guessing game into something a small creator can actually implement. A single endorsed protocol with clear legal effect would be a modest, cheap and genuinely useful change. The second is whether the major AI providers adopt the authentication schemes that paid-access models depend on. Without that adoption, the infrastructure layer can block but cannot charge, and blocking protects work without funding it.
The pessimistic reading of the past twelve months is that the EU had the opportunity to attach remuneration to the transparency duties and chose not to, then delayed the parts of its own regulation that industry found inconvenient, then opened a consultation about doing something in 2027. The optimistic reading is that transparency duties are the precondition for everything else, that the documents they generate are what litigation and licensing run on, and that the Parliament’s 460-vote resolution shows the political base for remuneration exists. Both readings describe the same facts.
Questions the evidence cannot yet settle
Several questions central to this topic remain genuinely open, and it is worth marking them as open rather than resolving them rhetorically.
Whether protected works are meaningfully present in model weights is a technical question that two courts answered in opposite directions within twelve months. The Munich chamber found memorisation by comparing training material against output and concluded the works were reproducibly contained in the model. The English High Court concluded there are no copies in the model. Both had expert evidence. The disagreement may reflect different models, different works, different evidential records, or a genuine unresolved question about what retention means in a distributed representation. Nobody should claim certainty here.
Whether marking will function at scale is unknown. The technology works for images under controlled conditions and fails for short text. The platform layer strips metadata today. Whether the Code of Practice’s measures plus standardisation work produce a durable chain by 2028 is a forecast, not a fact.
Whether transparency documents will ever be actionable for individual creators is doubtful on current evidence and not impossible. A disclosure threshold set at the top 10% of domains does not reveal an individual portfolio. A future template revision, or a court-ordered disclosure in litigation, could change that.
Whether substitution or infringement is the larger economic harm is contested, and the answer differs by discipline. For photographers the substitution case is strong. For collecting societies with identifiable repertoire the infringement case has produced actual judgments. For writers the two are entangled, because the substituting product was built from the substituted work.
Whether labelling changes buyer behaviour has not been tested at scale. The commercial theory of provenance assumes that a verifiable claim of human authorship commands a premium once synthetic content is distinguishable. That assumption is plausible in business-to-business verification contexts and unproven in consumer markets, where the competing hypothesis is that audiences already discount everything.
And whether the political will exists to enforce what has been enacted is the question the next eighteen months answer. The AI Office gained real powers yesterday. The Member States that have not designated authorities were required to do so a year ago. A regulation is not a fact about the world until someone acts on it, and the first enforcement decision under Article 50 will tell European creators more about their position than any amount of further legislation.
Answers to the questions creators keep asking about the AI Act
No. The AI Act creates transparency duties, not remuneration rights. Article 53 requires providers of general-purpose AI models to have a policy for complying with EU copyright law and to publish a summary of training content. It does not require a licence, a fee or a levy. The European Parliament asked the Commission in March 2026 to build a remuneration mechanism, and a legislative proposal is expected during 2027.
Article 50’s transparency duties became applicable to providers and deployers of AI systems across the EU, and the AI Office gained enforcement powers over general-purpose AI model obligations that had technically applied since August 2025 without any penalty attached.
No. Deployer labelling duties cover two categories. Deepfakes, meaning synthetic image, audio or video resembling real people, places, objects or events that would falsely appear authentic. And AI-generated text published to inform the public on matters of public interest, unless it underwent substantive human review or editorial control.
Deliberate examination of the substance by a person with relevant subject knowledge and professional judgement, or control by a responsible editorial entity with authority to approve, alter or reject substance, plus ultimate legal responsibility for publication. Spell-checking and grammar correction are excluded by name.
Yes, where the activity is professional. A person using an AI system in a personal capacity is outside the Act. A person who earns from the activity regularly, or who is otherwise in a trade, occupation or freelance practice, is a deployer with obligations.
The publishing party is generally the deployer for published output, but a company remains a deployer even where freelancers operate systems on its behalf and under its control. The allocation should be written into the contract, along with a record that the required disclosure was recommended.
Marking is machine-readable provenance embedded by the provider of the generative system so detection tools can identify synthetic content. Labelling is human-perceivable disclosure by the deployer. A deployer cannot satisfy its disclosure duty by relying on the provider’s embedded mark.
It applied from 2 August 2026 for systems placed on the market from that date. Generative systems already on the market before 2 August 2026 have until 2 December 2026. Content generated before 2 August 2026 does not need retroactive labelling.
No. Free and open-source licensing does not exempt a system from Article 50. For general-purpose AI models, the open-source exception in Article 53 covers technical documentation and downstream information duties, but the copyright policy and training-content summary still apply.
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, with proportionality available for small and medium-sized enterprises and small mid-cap companies. EU institutions face up to €750,000.
Mainly national market surveillance authorities. The AI Office has a limited role, confined to systems built on general-purpose AI models where the same entity provides both, and to systems integrated into designated very large online platforms and search engines. As of March 2026, eight of twenty-seven Member States had designated a single point of contact.
Legally, a valid machine-readable reservation under Article 4(3) of the Copyright Directive removes the mining exception, which makes a licence necessary. Practically, robots.txt functions as a request that some crawlers honour and others ignore, and the Commission has not yet published its agreed list of machine-readable protocols. Collective declaration by an organisation holding a member mandate has been treated as operative by a German court.
The Munich I Regional Court found for GEMA against OpenAI in November 2025 and against Suno in July 2026, holding that memorisation of protected works in model parameters is reproduction and that the text and data mining exception does not cover it. Both judgments are first instance and under or open to appeal. The English High Court reached the opposite conclusion on whether models contain copies.
Case C-250/25 is the first preliminary reference to the Court of Justice on generative AI and copyright, brought by a Hungarian publisher against Google over Gemini outputs. It asks whether chatbot output can be communication to the public, whether training is reproduction, and whether the mining exception covers it. The Advocate General’s opinion is expected on 3 September 2026.
No. It requires synthetic images to be marked and, where they depict real people or places deceptively, disclosed. It does nothing about substitution, pricing or buyer preference. The commercial value of marking depends on whether platforms preserve provenance rather than strip it.
It is worth most where the buyer verifies what they publish, meaning editorial, regulated-sector, legal and institutional work. Metadata is stripped by many platforms during upload and transcoding, absence of a credential proves nothing, and signing can expose location and device data. Treat it as a workflow discipline for specific client types rather than a universal fix.
Some routes exist and most are built for publishers rather than individuals. Microsoft’s Publisher Content Marketplace launched in February 2026 with usage-based payment. Really Simple Licensing lets a site publish priced terms machine-readably. Cloudflare’s paid-access model depends on AI providers adopting an authentication scheme that the largest have not announced support for.
Cloudflare’s default settings begin blocking mixed-use crawlers, meaning those combining search indexing with AI training and agent use, on pages carrying ads. The default applies to new customers, new sites of existing customers and free-tier accounts, and can be changed in the dashboard.
Add viewer-facing disclosure to any deepfake output. Audit published text against the public-interest categories and either document substantive review or label it. Keep a four-field record per deliverable covering tools, reviewer, disclosure recommended and what was published. Reserve rights on domains you control. Split creation fees from any licence permitting synthetic reproduction or training use. Decide your crawler posture deliberately before the September default change.
Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

This article is an original analysis supported by the sources cited below
Transparency obligations under Article 50 of the AI Act European Commission question-and-answer page setting out the scope of provider and deployer duties, the deepfake test, the editorial review exemption and the enforcement split, last updated 24 July 2026.
Code of Practice on Transparency of AI-generated Content Commission page documenting the final code published on 10 June 2026, its provider and deployer sections, its status as an adequate compliance tool and the number of signatories by end of July 2026.
Guidelines on transparency obligations for providers and deployers of certain AI systems Commission guidance clarifying the scope of Article 50, adopted following public consultation and Member State input.
EU icons for labelling AI-generated content Commission icon set that deployers may use to satisfy the human-perceivable disclosure requirement.
AI Act regulatory framework Commission overview confirming that from 2 August 2026 the AI Office and Member State authorities are responsible for supervision and enforcement, including AI Office powers over general-purpose AI models.
Commission consultation on protocols for reserving rights from text and data mining Primary record of the December 2025 consultation supporting Article 53 opt-out compliance and the planned list of agreed machine-readable reservation solutions.
Article 70 of the AI Act on national competent authorities Statutory text requiring Member States to designate notifying and market surveillance authorities and to resource them adequately.
Report on copyright and generative artificial intelligence European Parliament own-initiative report calling for a licensing framework, fair remuneration, sector-by-sector voluntary collective licensing and examination of remuneration for past uses.
Enforcement of the AI Act European Parliamentary Research Service briefing recording that eight of twenty-seven single points of contact had been designated as of March 2026.
The Danish approach to copyright and deepfakes Parliament briefing analysing why likeness does not fit copyright doctrine and why a national geo-blocking remedy leaves the underlying harm in place.
Like Company v Google, CJEU holds first hearing on generative AI and copyright Report on the six-hour Grand Chamber hearing of 10 March 2026, the extraterritoriality debate among Member States and the expected date of the Advocate General’s opinion.
Comment of the European Copyright Society on Case C-250/25 Independent academic opinion urging caution, noting the reference conflates chatbot, model and search engine, and questioning whether retrieval-augmented generation constitutes training at all.
Like Company v Google Ireland Ltd (C-250/25) case summary Procedural account of the four referred questions and the interaction between the press publishers’ right and the mining exception.
Digital Omnibus on AI, provisional agreement reached at the May trilogue Analysis of the 7 May 2026 agreement, the deferral of high-risk duties to December 2027 and August 2028 and the new Article 5 prohibition.
EU AI Act Omnibus agreement, postponed high-risk deadlines and other key changes Account of the failed 28 April trilogue, the political agreement that followed and the amendment package’s scope.
The Digital AI Omnibus, proposed deferral of high-risk AI obligations Running timeline of Parliament endorsement on 16 June 2026 and final Council approval on 29 June 2026.
EU AI Act transparency obligations, preparing for compliance by 2 August 2026 Practitioner analysis confirming that Article 50 duties survived the Omnibus apart from the marking grace period to 2 December 2026.
The AI Act’s transparency obligations, rules, scope and timeline Overview of the four transparency categories, the adoption of Commission guidelines on 20 July 2026 and the position of open-source systems.
Copyright compliance under the EU AI Act for GPAI model providers Analysis of Articles 53(1)(c) and (d), the voluntary Code of Practice and the mandatory training-content template.
European Commission releases mandatory template for public disclosure of AI training data Detail on the template published 24 July 2025, the top-10%-of-domains disclosure, the 2027 deadline for legacy models and the absence of content-level audits.
Decoding the GPAI Code of Practice and the training data summary template Analysis of the copyright chapter’s commitments, the mandatory exclusion of piracy sites, the rightsholder complaint mechanism and the removal of the third-party dataset audit duty.
GPAI training transparency research Academic assessment finding only a handful of training-content summaries published and locatable, with inconsistent formats and no unified filing system.
Landmark ruling of the Munich Regional Court in GEMA v OpenAI Report on case 42 O 14139/24, the memorisation finding, the rejection of the mining exception defence and the works at issue.
GEMA vs OpenAI, Munich Regional Court I issues landmark copyright decision Doctrinal analysis of why storage in model parameters and reproduction in output were both held impermissible, and how the ruling relates to the earlier Hamburg decision.
Getty Images v Stability AI, English High Court rejects secondary copyright claim Analysis of the 4 November 2025 judgment, the finding that there are no copies in the model and the apparent departure from EU distribution-right principles.
Stability AI defeats Getty Images copyright claims before the High Court Account of the abandoned primary claims, the territorial and evidential problems and the limited trade mark findings on watermarks.
CISAC and PMP Strategy study on the economic impact of generative AI Source for the projections that 24% of music creators’ and 21% of audiovisual creators’ revenues are at risk by 2028 under an unchanged regulatory framework.
Market for generative AI outputs and the projected impact on creators’ revenues Breakdown of the study’s cannibalisation rates by revenue stream, including the exposure of translators and adaptors.
In 2026, less than one third of Google searches still send a click Clickstream analysis showing the share of traffic Google sends to a large panel of domains falling eight percentage points between June 2025 and May 2026.
Nearly half of online articles are now AI-generated Detailed account of Graphite’s methodology across 55,400 Common Crawl URLs, three detectors, the 49.9% figure for the first quarter of 2026 and the study’s stated limits.
How much of the web is written by AI Independent reporting on the same analysis with explicit caution about mixed human and AI workflows defeating article-level classification.
AI tracking center NewsGuard’s running count of AI content farm news and information sites, reaching 3,749 across sixteen languages including Czech by 23 June 2026.
Cloudflare’s new policy pushes AI companies to pay for publishers’ content Report on the 15 September 2026 default change blocking mixed-use crawlers on ad-supported pages and which customer categories it applies to.
Microsoft launches Publisher Content Marketplace for AI licensing Coverage of the February 2026 launch, the usage-based payment model and the publisher partners involved in the pilot.
Getty Images and Shutterstock receive unconditional antitrust clearance from the US Department of Justice Primary company statement of 23 February 2026 confirming the expiry of the US waiting period without conditions.
Getty Images quarterly disclosure on the Shutterstock merger process Filed record of the UK Competition and Markets Authority Phase 2 review, the February 2026 interim report and the provisional remedy decision of 16 April 2026.
Competition and Markets Authority record of the Getty and Shutterstock merger inquiry Timeline confirming conditional clearance in May 2026, the consultation on final undertakings and Getty’s termination of the merger agreement on 7 July 2026.
Personal identity meets copyright, Denmark moves to regulate deepfakes Account of the Danish draft bill, its two proposed personality rights, the consultation and notification timeline and the minister’s intention to export the model.
Copyrighting voice and image, how Denmark’s deepfake law challenges personality rights Academic analysis of reconceptualising voice and appearance as transferable intellectual property rather than personality rights.
Comments to the European Commission regarding the copyright environment in Europe Industry-side submission to the June 2026 consultation arguing against mandatory remuneration and expanded opt-out rights, included to represent the opposing position accurately.
European Commission launches copyright consultation focused on AI Summary of the 13 May 2026 call for evidence, its scope covering licensing, enforcement, piracy, performer remuneration and research access, and the 25 June closing date.
Overview of AI Act national implementation plans Tracker recording how many Member States had designated market surveillance and notifying authorities and how many still had legislation pending as of mid-2026.
C2PA adoption in 2026, hardware platforms and verification reality Technical assessment of the conformance programme, version 2.3 live-stream signing, the Nikon certificate suspension and the metadata-stripping problem in platform pipelines.
Content Credentials and proving photographs are real Practitioner account of C2PA support arriving in Photo Mechanic, the limits of Lightroom Classic export support and competition-level adoption.
| Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy. |
This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.















