NewsLabs
Log in
Book a demo
← All stories
LEGAL

When do publishers have to disclose AI use? (EU AI Act Series, Part 1)

When do publishers have to disclose AI use? (EU AI Act Series, Part 1)

Written by

Marko Đuričić
Marko ĐuričićConsultant @ Summit Lex

I'm a business and regulatory consultant with a legal background, working on commercial, technology and regulatory matters. I help companies understand which regulatory requirements apply to them, where the risks sit, and how to build compliance into their processes and products.

LinkedIn
When do publishers have to disclose AI use? (EU AI Act Series, Part 1)

Welcome to a new series on AI-generated news and the EU AI Act.

I'm Marko, a business and regulatory consultant with a legal background. I work on commercial, technology and regulatory matters. Over the next few posts, I will walk through what the AI Act actually requires from newsrooms that use AI, in plain language and with practical examples.

This first post answers the question every editor is asking right now: when does an AI-assisted article have to carry a label, and when does a genuine editorial process remove that obligation?

The answer is found in the EU AI Act and in the Commission’s guidelines on Article 50. This post covers one question only: when a news publisher has to disclose that an article was generated or manipulated by AI, and when a genuine editorial process removes that obligation.

The EU AI Act's AI-Content Rules Are Now in Force

Regulation (EU) 2024/1689, commonly known as the EU AI Act, entered into force on 1 August 2024. Its transparency obligations under Article 50 became applicable on 2 August 2026. At the time of writing, organisations involved in generating, handling or publishing generative AI content are therefore already operating within the applicable transparency framework.

To understand how that framework works, it is useful to begin with two provisions that allocate different obligations to different actors.

Who Is the Publisher Under the AI Act?

The AI Act does not use “developer” as a defined legal role. Instead, it uses the term provider. In broad terms, a provider is a person or organisation that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (AI Act, Art. 3(3)). A company may therefore qualify as the provider of its own AI system even where the underlying model is supplied by another company such as OpenAI, Anthropic or Google.

Article 3(4) refers to that actor as the deployer and defines it as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in the course of a personal, non-professional activity. In a typical AI-journalism setup, if a company supplies an article-generation tool that is then used by a news publisher to publish content, that publisher is the deployer.

The technical marking obligation sits with the provider of the tool rather than with the publisher, and will be covered in a later post in this series.

The provider builds the system; the deployer publishes with it. Each carries a different obligation.
AI Act, Art. 3(3) and Art. 3(4). The marking duty sits in Art. 50(2), the disclosure duty in Art. 50(4).

When Does the Deployer’s Disclosure Obligation Apply?

Article 50(4) does not require disclosure merely because a news publisher has used AI somewhere in its editorial workflow. The Commission Guidelines identify three cumulative elements that must be satisfied before the disclosure obligation is triggered.

First, the text must be published, meaning that it is made accessible to an indeterminate and sufficiently large number of readers rather than remaining within a closed or private group (Commission Guidelines, para. (131)(i)). Second, it must be published for the purpose of informing the public, which means that it is intended to communicate knowledge, opinions or facts; short pieces of text that do not materially serve that purpose fall outside the criterion (Commission Guidelines, para. (131)(ii)). Third, the text must concern a matter of public interest, a concept that includes areas such as politics, public administration, justice, fundamental rights, public health, environmental protection, consumer safety, and economic, financial, political, scientific or cultural developments capable of public debate (Commission Guidelines, para. (131)(iii)).

The Guidelines make the distinction concrete. They identify, for example, an AI-generated summary of a human-authored newspaper article discussing a recent town-council decision as text falling within the provision. By contrast, a news summary generated by a chatbot only for the individual user who prompted it does not meet the publication criterion in the same way (Commission Guidelines, examples following para. (131)).

The practical consequence is straightforward: if any one of these three elements is missing, Article 50(4) is not triggered in the first place. The deployer therefore does not need to rely on an exemption, because no disclosure obligation arises at all.

All three elements must be present before Article 50(4) is triggered at all.
Commission Guidelines, para. (131)(i) to (iii). All three conditions must be met before Art. 50(4) applies.

When Can the Deployer Avoid the Disclosure?

Where Article 50(4) does apply, the Regulation creates an exception from the disclosure requirement if two cumulative elements are met: the content must have undergone human review or editorial control, and a natural or legal person must hold editorial responsibility for its publication (AI Act, Art. 50(4), second subparagraph).

The first element concerns what actually happened to the content before publication. Paragraph 134 of the Commission Guidelines explains that human review means a deliberate examination of the substance of the content by one or more natural persons with relevant knowledge and professional judgment. Fact-checking is expressly identified as a minimum part of that review, so a simple glance over the text is not sufficient. Editorial control, by contrast, refers to control exercised in practice by a responsible editorial entity, such as an editor-in-chief, with genuine authority to approve, alter or reject the substance of the text on substantive grounds, including by checking factual accuracy and the trustworthiness of sources (Commission Guidelines, para. (134)).

The emphasis is therefore not on whether human review appears to exist on paper, but on what the reviewer actually does with the article. A person who meaningfully checks facts, evaluates sources, assesses the substance and has the authority to change or reject the text is performing the kind of review contemplated by the Guidelines. A person who merely sees the output, checks that it looks plausible or clicks an approval button is not necessarily doing so.

The second element is editorial responsibility. The Commission explains that the relevant natural or legal person must hold ultimate legal responsibility for publication, including responsibility for the human-review or editorial-control process. The Guidelines further state that the identity and contact details of the responsible legal person, natural person or editorial function should be made publicly available in an easily findable location, for example through a website's terms and conditions or other user-facing legal information (Commission Guidelines, para. (138)).

These two requirements are intended to operate together. Genuine review alone is not enough if no natural or legal person ultimately assumes responsibility for publication; equally, assigning formal responsibility to an editor or publisher cannot cure a review process that is merely superficial. If either element is missing, the exception does not apply and the disclosure obligation remains.

The exception needs both elements. Either one alone is not enough.
Commission Guidelines, paras. (134), (135) and (138).

What Counts as Genuine Human Review?

The Commission Guidelines deliberately avoid a mechanical threshold for sufficient review. There is no minimum number of minutes an editor must spend on an article, no percentage of the text that must be rewritten and no fixed quantity of human intervention that automatically converts AI-generated content into sufficiently reviewed content. The assessment is substantive and case-specific: the real question is whether genuine professional judgment was exercised over the content.

Paragraph 135 makes clear what does not qualify. Superficial, purely formal or procedural checks, such as spelling or grammar correction, are insufficient. The same applies to the mere existence of an editorial policy, automated review processes or cursory editorial approval that does not involve substantive engagement by the human reviewer or editorial entity (Commission Guidelines, para. (135)).

This makes the dividing line easier to understand in practice. Correcting spelling, grammar or formatting does not amount to substantive review. Nor is it enough to insert a nominal human-approval step into the workflow if the person performing that step does not actually engage with what the article says. A process can therefore contain a human actor and still fail the legal test if that person's involvement is little more than a formality.

Timing Matters

The Commission states that where an AI system is used to modify, supplement or reformulate content after editorial sign-off, the resulting content must again be treated as AI-generated or manipulated for Article 50(4) purposes. Any substantive AI intervention after the human-review or editorial-control stage therefore causes the exception to become void (Commission Guidelines, para. (136)).

In practice, this means that the review must relate to the version of the content that is ultimately published. A news publisher cannot complete a substantive human review, obtain editorial sign-off and then send the article back through AI for a further material rewrite while continuing to rely on the earlier review. The human-review or editorial-control stage therefore needs to sit at the end of the substantive content-generation process. If AI materially changes the article afterwards, the earlier sign-off no longer applies to the version that is ultimately published.

A substantive AI change after sign-off puts the article outside the earlier review.
Commission Guidelines, para. (136).

The Commission's Own Examples

The Commission's own examples are particularly useful because they show that AI involvement itself is not the decisive issue. What matters is whether the resulting content has entered a genuine and accountable editorial process. The Guidelines identify an AI-manipulated newspaper article or an AI-generated summary as capable of satisfying the exception where it has been subject to the editorial control of the relevant editor-in-chief and editorial responsibility is held by the legal person publishing the newspaper. They likewise identify an AI-supported translation of a human-written article as capable of satisfying the exception where the translation has undergone human review (Commission Guidelines, examples following para. (138)).

By contrast, the Guidelines give examples of AI-generated articles published without any deliberate human review or editorial control, articles reviewed and edited by another AI system while a human performs only a superficial grammatical check, and AI-generated self-published content without review by a competent natural or legal person. In those examples, the exception is not satisfied (Commission Guidelines, examples following para. (138)).

Taken together, these examples show that the Act is not asking whether a human appeared somewhere in the workflow. It is asking whether the content was subjected to real human or editorial judgment before publication and whether an identifiable person or entity ultimately assumes responsibility for that publication.

Ultimately, responsibility lies with the news publisher as the deployer. It is therefore for the publisher to establish an appropriate editorial process, define the responsibilities of journalists and editors, and determine whether the disclosure obligation applies to particular content.

A Useful Analogy: SCHUFA and Meaningful Human Involvement

Although it did not concern the AI Act, the CJEU's judgment in Case C-634/21, SCHUFA Holding, provides a useful analogy when considering whether human involvement is genuine or merely formal. The Court held that the automated creation of a credit score could itself constitute automated individual decision-making where a third party “draws strongly” on that score when deciding whether to establish, implement or terminate a contractual relationship. The Court's concern was that accountability for automated processing should not be circumvented simply by pointing to a later decision taken by another actor.

The analogy should not be overstated, and its relevance to any particular case should ultimately be assessed with qualified legal counsel. SCHUFA did not decide that downstream human sign-off is automatically insufficient, nor did it interpret the Article 50 AI Act concept of human review. The more direct proposition under Article 50 comes from the Commission Guidelines themselves: superficial, formal or cursory human checks do not amount to the substantive human review or editorial control required for the exception (Commission Guidelines, paras. (134)–(135)).

Nevertheless, SCHUFA is useful in illustrating a broader regulatory point: placing a human somewhere at the end of an automated process does not necessarily transform that process into meaningful human decision-making. For a news publisher, the safer approach is therefore to ensure that the journalist or editor has the knowledge, authority and practical ability to question, change or reject the AI-generated substance before publication.

A Practical AI-Journalism Decision Tree

The legal test becomes easier to understand when applied to real workflows. The four scenarios below work through the most common newsroom cases in turn.

The full Article 50(4) test, applied in order.
AI Act, Art. 50(4); Commission Guidelines, paras. (131) to (138).

Scenario A: Fully Automated Publication. An AI system monitors information sources, writes an article and automatically publishes it without substantive human review. If that article informs the public on a matter of public interest, the Article 50(4) disclosure obligation should apply. This is the clearest case for an explicit AI-generated label.

Scenario B: AI Draft + Substantive Journalistic Review. An AI system generates a first draft, and a journalist then checks the facts and sources, reviews the substance, changes or rewrites sections where appropriate and approves the final article. The publisher or responsible editor assumes editorial responsibility. This is the strongest case for relying on the Article 50(4) exception. The text has undergone the type of substantive human review contemplated by the AI Act and Commission Guidelines, while the publisher or responsible editor holds editorial responsibility for the final publication (Commission Guidelines, examples following para. (138)).

Scenario C: AI Draft + Superficial Proofreading. An AI system generates the article and a person corrects typos, grammar and formatting before publishing it. The Commission expressly distinguishes superficial or formal review from genuine substantive human review. Where the underlying AI-generated content remains effectively untouched from an editorial perspective, the disclosure obligation remains applicable (Commission Guidelines, para. (135); examples following para. (138)).

Scenario D: Journalist-Written Article with AI Assistance. A journalist researches and writes the article but uses AI for brainstorming, headline suggestions, grammar correction, formatting or other limited assistance. This should not automatically be treated as an AI-generated article. Where the published text itself was not generated or substantively manipulated by the AI system, Article 50(4) may not be engaged in the first place.

The same four workflows, with the outcome each one produces.
Commission Guidelines, para. (135) and the examples following para. (138).

Conclusion: The Real Dividing Line Is Editorial Responsibility, Not AI Usage

To conclude, the key takeaway is that the EU AI Act does not prohibit AI-generated journalism, nor does it impose a blanket requirement to label every article produced with any degree of AI assistance. For publishers, the central distinction is between AI replacing editorial judgment and AI operating within a genuine human editorial process.

Where an AI system effectively produces public-interest journalism without meaningful human control, Article 50 requires disclosure of the AI-generated or manipulated nature of the content. Where the content undergoes genuine substantive human review or substantive editorial control, and a natural or legal person holds editorial responsibility for the final publication, the Regulation expressly provides an exception to the disclosure obligation.

Two further topics follow in this series. The first is how the disclosure has to be presented to readers and what the penalties are for getting it wrong. The second is the separate technical marking obligation that falls on the company supplying the AI system rather than on the publisher.

Stay tuned!

Disclaimer

This article is provided for general informational purposes only and does not constitute legal advice. The application of the EU AI Act and other relevant laws depends on the specific facts, technical setup, contractual arrangements and roles of the parties involved.

Individual cases should therefore be assessed on their own circumstances, and organisations should obtain advice from appropriately qualified legal counsel before relying on the positions or recommendations described above.

Written by

Marko Đuričić
Marko ĐuričićConsultant @ Summit Lex

I'm a business and regulatory consultant with a legal background, working on commercial, technology and regulatory matters. I help companies understand which regulatory requirements apply to them, where the risks sit, and how to build compliance into their processes and products.

LinkedIn