On 10 June 2026, the European Commission published its long-awaited Code of Practice for marking and labelling AI-generated content, a voluntary playbook designed to help businesses meet transparency rules that become law across the bloc on 2 August. The Code itself is optional. The obligations it points to are not. They sit under Article 50 of the EU AI Act, and from August they apply whether or not a company signs the Commission's guidance.

For any organisation putting generative AI to work, the message is unambiguous: you will soon need to prove, not just assert, that AI-made or AI-altered content is properly disclosed. That is far easier when the AI generating your content lives inside your own walls, where every output can be logged, tagged and audited against your own rules.

This is where private deployment changes the calculation. Aphelion AI is a private enterprise AI platform built to keep intelligence, data and deployment inside infrastructure you own and control, so that transparency, provenance and disclosure become auditable by design rather than features you hope a third party has switched on. As the labelling deadline approaches, that control stops being a nice-to-have and becomes the cleanest route to compliance.

What the New Rules Actually Require

From 2 August, two things must be clearly flagged whenever AI is involved. The Commission frames the whole exercise as protecting a public right to know whether what people see, hear or read has been produced or altered by a machine, especially where that content can shape public debate.

In practice, the obligations break down into a small set of duties that every deployer should understand:

  • Deepfakes must be labelled. AI-generated or AI-manipulated images, audio and video have to be marked so audiences can recognise them for what they are.
  • Public-interest AI text must be disclosed. AI-produced text published on matters of public interest carries a label when it has gone out without human review or editorial control.
  • Chatbots must identify themselves. Anyone interacting with a conversational AI system, such as a customer-service bot, has to be told they are dealing with a machine rather than a person.

The Code splits the work across the AI supply chain. The companies that build generative models are asked to mark their output in a machine-readable format so it can be detected downstream, while the companies that deploy those models handle the visible labelling. To keep it workable, the Code leans on open technical standards and a common EU icon, sparing businesses from inventing their own scheme.

The timeline

The final Code was released on 10 June 2026 and is now open for signatures. The Article 50 transparency obligations become law on 2 August 2026. Drawn up by six independent experts with input from more than 180 stakeholders, it is the first instrument to tackle AI content labelling under the Act, and the window to prepare is short.

The Real Challenge: Proving Compliance, Not Claiming It

Signing a Code of Practice is the easy part. The hard part arrives when a regulator, a journalist or a customer asks you to demonstrate that a specific piece of content was generated by AI, was disclosed correctly, and can be traced back through your systems. With public, hosted tools, much of that evidence simply does not exist on your side of the line.

The exposure falls into three areas that every enterprise should weigh honestly:

  • Provenance risk: if content is generated on an external platform, you may have no reliable record of what was AI-made, when, or by which model version.
  • Disclosure risk: visible labelling that depends on staff remembering to apply it manually will be applied inconsistently, which is precisely the gap regulators look for.
  • Audit risk: you cannot evidence a process whose logs, prompts and outputs live on infrastructure you cannot see or export.

A private, governed approach closes all three at once, because generation, marking and logging happen inside an environment you fully control. The label is not an afterthought applied by a human; it is part of the pipeline.

"Transparency rules do not reward good intentions. They reward organisations that can show their work. Private AI turns disclosure from a promise into a record."

How Private AI Makes Labelling Auditable by Design

Compliance with Article 50 is not a slogan, it is an operational requirement. Aphelion is built around the architectural commitments that make that requirement straightforward to meet.

Generation and logging inside infrastructure you control

Aphelion runs your private AI within an environment you own or exclusively control, whether on-premises, in a private cloud, or in a secure containerised stack. Because every generation happens inside that boundary, machine-readable provenance can be attached at the moment of creation and the full record retained for audit. There is no external black box between your content and your evidence.

Your data and outputs stay inside your walls

Nothing your team submits is routed to a shared external platform. Sensitive commercial information, client records and draft content remain within your governed environment, which removes both the data-leakage risk and the compliance exposure that come with public tools. Aphelion's data enrichment capabilities feed your own context into every interaction, so outputs are accurate, relevant and fully accounted for.

Disclosure built into the workflow, not bolted on

A label only works if it is applied every time. Aphelion's system integration connects private AI to the CRMs, content systems, support desks and document stores you already run, so disclosure and provenance travel with the content through every pipeline. The rule is enforced by the system rather than left to a person to remember.

A governable AI agent your policies define

Rather than a generic assistant detached from your obligations, a private deployment answers to your policies alone. You decide what gets labelled, how it is marked, what is logged and how long it is retained, which is exactly the kind of control the EU AI Act expects deployers to exercise over the systems they put to work.

Why Acting Now Beats Waiting for August

The instinct is to treat 2 August as a distant problem and assume existing tools will be patched in time. That is an increasingly poor bet. The Code still needs the Commission and the AI Board to judge it adequate, separate guidelines are due to clarify what it leaves out, and the obligations bind regardless. The timing leaves little slack.

The practical consequences for buyers are already taking shape:

  • Deployers, not just model builders, carry the visible labelling duty, so the responsibility lands squarely on the businesses putting AI into products.
  • Manual disclosure processes will not survive an audit at scale, which pushes labelling toward something enforced by infrastructure.
  • Procurement teams now have a defensible case for private deployment, because demonstrable transparency has become a board-level question rather than a technical footnote.

Aphelion exists so that a regulatory deadline issued in Brussels is a date you prepare for calmly, not a scramble to retrofit governance onto tools that were never built to provide it. You can learn more about the team building that platform on our About page.

The Aphelion difference

Aphelion is purpose-built for private, governable enterprise AI. We do not resell access to a model whose internals you cannot see. We build AI that runs entirely within your environment, trained on your data, governed by your policies, and instrumented so that transparency obligations like the EU AI Act's labelling rules are met by design.

Frequently Asked Questions

What is the EU AI Act content labelling requirement?

From 2 August 2026, Article 50 of the EU AI Act requires that AI-generated or AI-manipulated content be clearly disclosed. Deepfakes and AI-produced text published on matters of public interest must carry a label, and anyone interacting with a conversational AI system such as a customer-service bot must be told they are dealing with a machine. The European Commission's Code of Practice is a voluntary playbook that gives businesses a recognised way to show they meet these obligations, but the underlying legal duties apply whether or not a company signs it.

How does Aphelion AI help with AI content labelling compliance?

Aphelion AI runs private models inside infrastructure you own or exclusively control, which means every generation, prompt and output can be logged, tagged and audited against your own policies. Because the model sits within your governed environment, machine-readable provenance marking and visible disclosure can be applied consistently at the point of generation rather than bolted on afterwards. That gives compliance and legal teams a defensible, end-to-end record of what the AI produced and how it was labelled. You can read more about the platform on the AI Agent page.

Does private AI improve data security and regulatory compliance?

Yes. A private deployment keeps every prompt, document and output inside your environment, which directly supports obligations under the EU AI Act, GDPR and sector-specific rules. Because nothing is routed to a shared external platform, you avoid the data leakage and audit gaps that come with public tools, and every interaction can be retained, reviewed and evidenced for a regulator. Transparency duties are far easier to satisfy when you control the full record.

Can private AI integrate labelling into our existing business systems?

It can. Aphelion connects private AI to the CRMs, ERPs, content systems and document stores you already run, so disclosure and provenance can be enforced wherever AI output enters a workflow. Data enrichment and system integration are core to the platform, which means labelling logic travels with the content through publishing, support and document pipelines rather than depending on staff to remember to apply it manually.

Public AI vs private AI: which is better for meeting transparency rules?

Public AI tools give you little visibility into how content is generated, marked or retained, which leaves gaps when a regulator asks you to prove compliance. Private AI keeps generation, logging and labelling under your control, making transparency duties auditable by design rather than dependent on a third party's settings. For enterprises facing the EU AI Act, that control is the difference between assuming you comply and being able to demonstrate it.

The Window to Prepare Is Now

The businesses that treat the August deadline as a formality will be the ones scrambling to evidence compliance after the fact, when the gaps in their public tooling become a liability. The businesses that treat it as a signal will move now to bring AI generation inside their own walls, where it is governed, logged and theirs to account for.

Private, governable AI is no longer just a security preference. It is the foundational infrastructure decision that lets an organisation meet rising transparency obligations with confidence rather than hope. Aphelion exists to make that decision straightforward, fast and right for your business.