Was this image created by AI? This article has been edited with AI.
Artificial intelligence has quickly become a normal part of communications and marketing work. It is used to create images, edit photographs, produce text, create videos, generate subtitles and search for content. At the same time, a new question arises:
How can an organisation later know which assets have been created or processed using AI – and how can that information be preserved with the asset all the way through to publication?
The EU AI Act makes this question even more relevant. The transparency obligations under Article 50 apply from 2 August 2026.
However, not all content processed with AI needs to be visibly labelled. Therefore, the first task is not to add an AI label to every image, but to understand what has been done to the asset and in which situations this needs to be disclosed.
Not all AI use is the same
Consider three images. In the first image, AI removes a small distracting detail. In the second image, AI adds a person who was not present in the original image. The third image is entirely AI-generated and looks like a real photograph. AI has been used in all three cases, but their significance from a transparency perspective is not the same.
The EU AI Act requires providers of AI systems to use machine-readable markings for certain AI-generated or substantially manipulated synthetic content. Ordinary assistive editing is subject to an exception.
For an organisation publishing content, an especially important case is a deepfake. This refers to AI-generated or manipulated image, audio or video content that resembles an existing person, object, place, organisation or event and may appear authentic to a person. The artificial origin of such content must be clearly disclosed.
There is also a transparency obligation concerning AI-generated or AI-manipulated text published to inform the public on matters of public interest. However, if the text has undergone appropriate human review or editorial control and a natural or legal person bears editorial responsibility for its publication, a visible AI disclosure is not required under this rule.
Put simply: the AI Act does not mean that every file touched by AI must be labelled in the same way.
The real problem begins before publication
Imagine a typical marketing organisation. An advertising agency creates a campaign image. The background of the image is modified using generative AI. The finished image is delivered to the marketing team, which stores it in a shared folder.
Three months later, another employee finds the image and wants to use it on the website. How do they know what has been done to the image?
The filename may not tell them. The email has already been forgotten. The person who created the image may work for another organisation. From the perspective of the AI Act, this may be an even more important practical problem than adding an AI icon to the final publication.
Information about the use of AI should travel with the asset throughout its lifecycle.
DAM can act as the organisation’s memory
A media bank, or DAM (Digital Asset Management), can help solve this problem. When an asset is stored in DAM, information such as the following can be stored with it:
Use of AI: No / Yes
AI processing: AI-assisted / Partially AI-modified / Fully AI-generated
AI tool: for example, the application or service used
Reviewed: Yes / No
Publishing restriction: Must be reviewed before publication
AI disclosure required: Yes / No / To be assessed
This means that the information is not stored only in an employee’s memory or an email, but becomes part of the asset’s management information. DAM can also be used to maintain the organisation’s approved AI guidelines, labelling practices and, for example, the AI icons recommended by the EU in the same place as the assets to be published. See one official AI-image logo here.
The content creator does not need to know the entire AI Act. They need to know what information about the asset must be recorded. The publisher, in turn, can see before publication what has been done to the asset and whether anything related to its use needs to be checked.
But DAM metadata alone does not solve the problem
There is an important distinction here. DAM metadata can tell people inside the organisation, for example:
“The background of this image has been modified with AI.”
But what happens when the image is downloaded from DAM, sent to an advertising agency, edited in another application and published on social media? DAM may no longer control the entire journey of the file. C2PA has been developed to address this problem.
What is C2PA?
C2PA (Coalition for Content Provenance and Authenticity) is a technical standard for describing the origin and modification history of digital content. The concept of Content Credentials is also based on it.
Read more: digital-strategy.ec.europa.eu
The idea is to provide a kind of digital product label for an asset. It can be used to communicate information such as how the asset was created and how it was subsequently processed. The information can be cryptographically bound to the asset so that its connection to that specific content and the integrity of the information can be verified.
C2PA does not itself determine whether an image is true or false. It helps answer a different question:
Where did this asset come from, and what can be reliably verified about its history?
C2PA and DAM solve different parts of the same problem
They should not be seen as competing solutions. DAM manages the organisation’s assets and the information associated with them. C2PA aims to preserve and verify the origin and modification history of the asset even as the file moves between systems.
A good future workflow could look like this:
Creation → AI processing information → DAM → review → publication → preservation of provenance information
In DAM, the organisation can manage asset usage rights, approvals, metadata, AI status, publication status and instructions. C2PA can complement this by carrying verifiable provenance information with the asset.
C2PA is not a magic solution
This is important to understand. Digital assets often travel through a long chain:
Camera → image editing → AI service → DAM → website → social media → user-downloaded copy
Every part of the chain should handle provenance information correctly for the complete history to be preserved. If one system removes metadata from the file or creates a new version without the previous provenance information, the chain can break. Therefore, an organisation should not assume that C2PA alone will solve the requirements of the AI Act. Both technology and an operating model are needed.
What about personal data and facial recognition?
The AI Act is not the same thing as the GDPR. If the AI in a media bank, for example, analyses images of people, recognises faces or creates technical identifiers based on facial features for the purpose of uniquely identifying individuals, this also involves the processing of personal data and potentially GDPR requirements concerning biometric data.
In such cases, the organisation needs to know, among other things:
- what personal data the AI processes
- where the processing takes place
- what data the AI generates
- how long the data is retained
- whether the assets are used to train AI models
- which subprocessors are used
- how the data is deleted
- how data subject rights are implemented.
This is a different question from whether a finished image must be labelled as AI-generated content. However, in an organisation’s AI governance, these two issues need to work together.
What should a communications organisation do now?
There is no need to make this complicated. A good starting point is five practical steps:
- Agree what information about AI use should be recorded.
Define common metadata for AI-generated and AI-modified assets. - Store the information with the asset.
Do not leave it in emails, filenames or people’s memory. - Define the publishing process.
The publisher must be able to see whether an asset requires an AI disclosure or another review. - Follow the development of C2PA and Content Credentials solutions.
They offer a way to carry provenance information beyond the organisation’s own DAM. - Document the AI functions used by the DAM itself.
If the media bank itself uses AI, for example for image search, facial recognition, OCR or speech recognition in videos, the privacy, location, retention and deletion practices of that processing must also be understood.
A good DAM does more than store files
In the age of AI, digital asset management gains a new dimension. It is no longer enough to know:
What file is this? Where may it be used? Who may use it?
Increasingly, organisations also need to know:
How was this content created? Has it been modified with AI? Who reviewed it? What needs to be disclosed when it is published? And does that information remain with the asset?
This is where the role of the media bank becomes particularly interesting. DAM can act as the organisation’s shared memory: assets, usage rights, provenance information, AI use, approvals and publishing instructions can all be combined into one controlled process.
C2PA, in turn, can help carry some of this trust information with the asset itself from one system to another.
The European Commission’s guidance also makes a useful distinction between the machine-readable marking provided by the AI system provider and the human-visible disclosure made by the organisation using or publishing the content. In the case of deepfakes, a machine-readable marking embedded only in the file is not sufficient.
Read more: digital-strategy.ec.europa.eu
The AI Act is therefore not only about placing an AI label in the corner of an image. Above all, it is about whether an organisation can know and demonstrate how the content it publishes was created.
![]() |
Author Rolf Koppatz Rolf is the CEO and consultant at Communication Pro with long experience in DAMs, Managing Visual Files, Marketing Portals, Content Hubs and Computer Vision. Contact me at LinkedIn. |

