SecurityTechInsider AI security & governance
EN/ NL
Policy

Marking AI content from 2 August 2026: what the AP expects from your workflow

From 2 August 2026 the Dutch Data Protection Authority supervises AI transparency. What must you label, watermark and demonstrably record in your workflows?

4 September 2026 4 min
Illustration for this article: Marking AI content from 2 August 2026. A shaft of hard daylight crossing a raw concrete soffit, dust suspended in the beam.
From 2 August 2026 you must mark AI-generated content and prove your marking workflow to Dutch supervisors. Image: SecurityTechInsider — original editorial illustration

From 2 August 2026, you must mark all AI-generated image, audio, video and certain text content in your workflows both so machines can read it and so users can see it. You must also be able to demonstrate, per workflow, which content is AI-generated and which is not. This is now a testable obligation, not a design choice.

The prompt is an analysis of 4 September 2026 of marking AI-generated content under EU supervision, which argues that the Dutch Data Protection Authority will supervise transparency obligations for generative AI systems from that August date onwards. The core requirement is that citizens must know when they are communicating with an AI system and when content has been artificially generated or manipulated. In our assessment, the practical message is that the AP forms a concrete trigger: from that date Dutch organisations will be held to account not only on principles, but on demonstrable implementation of marking and recording across their workflows.

Which content types must you mark?

The transparency obligations apply to artificial content across several categories. Image, audio and video content that is AI-generated or AI-modified falls under the requirement. Certain text content also triggers the obligation, though not all AI-generated text needs to be labelled. The key distinction is whether the text addresses matters of general interest and whether it has been subject to demonstrable editorial control with clear responsibility. If editorial control is present and documented, the labelling requirement may not apply. If AI is the primary publication channel with no such oversight, you must label systematically.

The intention to mislead is not a precondition for marking. Content without a misleading purpose can also fall under the definition of synthetic content that requires marking. This means well-intentioned AI applications must also be recognisable as AI content to the end user.

What are the failure modes you must guard against?

  • Unmarked synthetic content — AI-generated or AI-modified material published without visible or machine-readable marking.
  • Undocumented workflows — processes where AI is used but no record exists of which content is AI-generated and which is not.
  • Absent editorial oversight — AI systems used as primary publication channels without demonstrable human supervision or responsibility.
  • Retroactive marking gaps — attempting to mark synthetic content generated before 2 August 2026, which is excluded from the obligation.
  • Unmarked deepfakes — content that meets the deepfake definition but lacks marking, regardless of intent.

Which concrete controls must you be able to demonstrate?

  1. Record the model and its purpose — document which AI system each workflow uses and the lawful basis for the data it processes.
  2. Maintain an audit trail per workflow — log which content was generated by AI, when, and under what conditions.
  3. Apply visible and machine-readable marking — use standardised icons or labels that both humans and systems can recognise.
  4. Document editorial control where it exists — record where human supervision occurs and who bears responsibility for the final output.
  5. Establish a reconstructable chain — ensure that marking, registration and evidence are linked so that supervisors can verify compliance.

How should you structure your marking workflow?

Marking is not a single label but a chain of technical traceability and visible distinction. The European Commission's guidelines distinguish two layers that exist alongside each other. First, content must be marked at the point of generation or modification so that the record is contemporaneous. Second, that marking must remain visible or machine-readable to the end user. A workable approach involves recording which model was used, documenting the lawful basis for any personal data involved, applying standardised icons or labels, and maintaining an audit trail that shows what evidence supports each marking decision.

There is a short transition period until December 2026 for marking generative systems that were already on the market before 2 August 2026. This does not exempt you from marking; it gives you time to implement the technical infrastructure. Retroactive marking of synthetic content generated before 2 August 2026 is excluded from the obligation.

What happens if you do not comply?

Breaches of the transparency obligations are punishable with fines of up to 15 million euros or 3 per cent of worldwide annual turnover. The Dutch Data Protection Authority, working in cooperation with the European AI Office, will supervise these obligations from 2 August 2026 onwards. This means your organisation will be held to account not only on whether you have a policy, but on whether you can demonstrate that the policy is actually implemented in each workflow where AI content is generated or modified.

For professionals in law, healthcare, supervision, finance and government, this is above all a documentation question. The obligation to demonstrably separate AI content from real content lies with your organisation. Tooling can support this by making visible which verification steps have been taken and what evidence is available per workflow. The choice of which content is marked as AI content and the final judgement on compliance remain with the professional and the organisation.

Sources: This article draws on reporting and guidance from Autoriteit Persoonsgegevens, Governance Web, Greenberg Traurig, Europese Commissie and Bird & Bird.

Elena Kovač

Written by

Elena Kovač

Follows EU policy as it turns from consultation into enforceable requirement.