header-mobile-bg

How to comply with the EU AI Act: a guide for enterprise content teams

Enterprises are scaling AI-generated content to accelerate time-to-market. However, speed without governance creates legal liability. With the EU AI Act broadly applicable as of August 2, 2026, content teams face mandatory rules around transparency, synthetic media labeling, and human oversight. 

A composable platform like CoreMedia DXP builds these controls in at the infrastructure layer, keeping human approval, AI-edit flagging, and content versioning in the workflow rather than leaving them to each content producer.

EU AI ACT

TL;DR, Key takeaways 

  • The EU AI Act's transparency rules for AI-assisted content are live now, since August 2, 2026. The high-risk obligations follow in December 2027.
  • Most marketing and CX content sit in the limited-risk tier. Key duties include disclosing bot interactions, labeling deepfakes, and preserving machine-readable metadata. You do not have to label every AI-assisted edit. The duty targets AI that talks to people or generates synthetic media, not routine drafting or tagging.
  • Compliance is manageable with the right architecture: a composable platform with human approval, provenance marking, and a record of AI involvement handles it; a fragmented stack cannot.  

What the EU AI Act is 

The EU AI Act is the European Union's law regulating artificial intelligence. It has been in force since August 1, 2024 and broadly applicable since August 2, 2026. It enforces risk-tiered rules on how AI systems are built, deployed, and managed in the EU. 

The Act reaches beyond Europe. It applies to any AI system used in the EU market, regardless of where the company is headquartered. A US- or Asia-based brand publishing content for EU consumers must comply under the exact same terms as an EU enterprise. 

How the EU AI Act impacts global enterprise content management 

The Act categorizes AI into four risk categories, and the riskier the use, the stricter the rules. For content teams, two of the four matter most: 

  • Limited risk covers AI that talks to people or creates media, like chatbots or AI-generated images. Its transparency rules apply now.
  • High risk covers more sensitive uses, such as hiring or credit decisions. Its tougher obligations arrive later. 

The other two, unacceptable risk (banned outright) and minimal risk (no real obligations), matter less for everyday content work. 

Risk categories and what they mean for content teams 

Most everyday content lands in the limited-risk tier, where the duty is disclosure or labeling rather than the full high-risk regime. Here is what each category covers and where it lands for content teams. 

Risk tierWhat it coversApplies to content teams?Your actions
Unacceptable risk Banned uses: social scoring, manipulative techniques, untargeted facial-image scraping, and, from December 2, 2026, AI-generated CSAM and non-consensual intimate imageryAlmost neverDo not use
High RiskSensitive-area high-risk AI systems (under Annex III: hiring, credit scoring, healthcare, education, biometric ID, essential services, law enforcement, and critical infrastructure) and AI embedded in regulated products (Annex I, with remote biometric identification subject to stricter controls) RarelyAssess, oversee, document (by Dec 2027) 
Limited RiskAI that interacts with people or generates content: chatbots, generative AI, deepfakes Almost alwaysDisclose and label (now) 
Minimal RiskEverything else, such as spam filters and AI-enabled video games Often, but unregulated No mandatory obligations

 

EU AI ACT Risk criteria

Where common content types fall 

Content typeRisk categoriesRequired action
Chatbot and voicebotLimited riskTell users they are interacting with an AI
AI-generated product descriptionsLimited riskMachine-readable marking on the generative system; no public "made by AI" label needed for routine text
Personalized banners and content blocksMinimal to limitedUsually no public label; if the creative is synthetic, the marking duty sits with the generative system
Deepfakes and synthetic spokesperson video or audioLimited risk (transparency)Label clearly as artificially generated
Emotion recognition or biometric categorization in a journeyLimited to high, sometimes bannedDisclosure at minimum; emotion recognition systems can trigger added obligations, and some uses are prohibited except for medical or safety reasons
Personalization that gates access to a service, or eligibility scoringPotentially high riskSome systems are considered high risk when they affect access, eligibility, or sensitive decisions, triggering risk assessment, human oversight, and documentation from December 2027

 

Classification follows the use, not just the format. The same AI-generated block is limited-risk as a marketing banner, but can move up a tier the moment it feeds a decision about someone's access, eligibility, or rights. 

The AI Act compliance timeline 

The EU AI Act entered into force on August 1, 2024 and became broadly applicable on August 2, 2026, with obligations phasing in on different dates. The most-watched date, the high-risk deadline, was pushed back by the Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on July 24, 2026 and in force since July 27, 2026. 

  • Aug 1, 2024 - Act entered into force.
  • Feb 2, 2025 - Prohibited practices and AI literacy obligations.
  • Aug 2, 2025 - Governance rules and general purpose AI (GPAI) model obligations.
  • Aug 2, 2026 - General applicability, including Article 50 transparency obligations.
  • Dec 2, 2026 - New Article 5 prohibitions on AI-generated CSAM and non-consensual intimate imagery take effect; marking and detection deadline for generative AI systems already on the market before Aug 2, 2026.
  • Dec 2, 2027 - High-risk systems in sensitive areas (Annex III).
  • Aug 2, 2028 - High-risk AI embedded in regulated products (Annex I). 

What is already live: transparency and labeling for AI-assisted content 

As of August 2, 2026, the AI Act transparency rules mainly affect limited-risk AI systems that interact with people or generate media. For content and CX teams, that means three duties are in force now: 

  • Disclose AI interactions. Users must be told when they are dealing with an AI system, such as a chatbot or voicebot, unless it is obvious.
  • Label synthetic and manipulated media. Deepfakes and other AI-generated or altered images, audio, and video must be marked as artificially produced, and similar disclosure can also apply to emotion recognition systems in user-facing contexts.
  • Mark AI output as machine-readable. Providers of generative AI must mark output in a format detectable by other systems, not only visible to a human reader. 

These map directly onto everyday content types.  

  • Chatbots and voicebots: need a disclosure that users are talking to an AI.
  • AI-generated product images or synthetic spokesperson video: need a clear label as artificially generated.
  • Generated banners or personalized blocks: usually no public "made by AI" stamp, but the underlying AI system carries the machine-readable marking duty, and providers and deployers have to keep that marking intact through publication. 

One carve-out gives teams a little room: generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to meet the marking and detection requirement. 

Copyright, IP, and provenance for AI-generated assets 

AI-generated assets raise two asset-level duties for content teams under the EU AI Act: 

  • Copyright. General purpose AI (GPAI) model providers must comply with EU copyright law and document their training data, in force since August 2, 2025. That duty sits with the provider, but it does not clear the enterprise publishing the output: if a generated image or passage reproduces protected material, the brand carries its own IP exposure under general copyright law. Provenance, knowing what a model was trained on and what an output derives from, is what lets a team manage that exposure.
  • Provenance marking. The transparency rules require AI output to carry machine-readable marking that identifies it as AI-generated. For a global content operation this is a metadata problem: the marking has to stay attached to an asset as it moves across sites, languages, and channels. Lose it during reformatting or localization and the disclosure duty is missed, even when the original file was marked correctly. 

Both are the same governance question. IP-infringing output and unmarked output are the same failure: content that published without the right check. 

Penalties for non-compliance, in tiers 

Non-compliance with the EU AI Act carries administrative fines in three tiers under Article 99, based on a percentage of the previous year's global turnover or a fixed sum, whichever is higher.  

Violation categoryMaximum fine (whichever is higher)
Breaches of prohibited AI practices€35 million or 7% of worldwide annual turnover
Breaches of other obligations, including many high-risk, GPAI, and transparency obligations€15 million or 3% of worldwide annual turnover
Supplying incorrect, incomplete, or misleading information to authorities€7.5 million or 1% of worldwide annual turnover

 

The current figures come from Article 99 of the EU AI Act. Check the official text for any updates. 

SMEs and start-ups face proportional fines. For content teams, the practical point is that a transparency failure, an unlabeled deepfake or an undisclosed chatbot, sits in the €15 million or 3% tier, not the top one, but it is still enterprise-scale exposure for a missed label and may trigger requests for information or compliance review by market surveillance authorities. 

How to comply: a checklist for content teams 

  1. Map where AI touches your content. List every point where AI drafts, translates, tags, or personalizes, from your CMS copilot to chatbots to image tools. You cannot disclose or govern what you have not mapped.
  2. Disclose AI interactions. Any chatbot or voicebot talking to customers needs a clear notice that the user is dealing with an AI. This is live now.
  3. Label synthetic media. Mark AI-generated or manipulated images, audio, and video as artificially generated, and keep the machine-readable marking intact through publishing and localization.
  4. Keep a human approval step before publishing. No AI-assisted content should reach a live channel without a person reviewing and clearing it.
  5. Record what was AI-assisted. Keep a trace of which content AI touched and who approved it, so you can show it if a regulator or auditor asks. 

Revisit this as deadlines shift. High-risk obligations arrive in December 2027, and the rules keep evolving, so treat compliance as a standing process, not a one-time project. 

Why legacy CMS architectures make AI Act compliance harder 

Most discussion of the EU AI Act treats it as a legal problem, something for legal to interpret and a risk function to track. For content teams it is also an operational one. When AI drafts, translates, tags, or personalizes content, some of the Act's obligations land on the content production process itself, not just on a policy document. That is why the CMS a team already uses either makes compliance routine or quietly works against it. 

Disconnected content stacks make compliance harder because no single system knows where AI touched content, who approved it, or whether it was labeled. When AI tools, the CMS, translation, and the contact center run separately, the gaps compound: 

  • No consistent record of what is AI-generated, so labeling and disclosure get missed across channels and regions.
  • Ungoverned AI use, where editors reach for external tools that sit outside any approval workflow, and fragmented stacks fail to support the kind of risk management system needed to record controls and reviews.
  • Metadata that does not travel, so AI-provenance and labeling markers get stripped when content is reformatted or localized, and the disclosure that was correct at creation is gone by publication.
  • No shared audit trail to show an authority, on request, that a human reviewed and signed off. 

The AI Act asks for human oversight and documentation. A stack stitched together from point tools struggles to produce either on demand, especially when AI controls are not integrated with existing risk management frameworks. 

What to look for in a CMS for easier compliance 

A CMS makes EU AI Act compliance manageable when it does a few things automatically, rather than relying on every content producer to remember a policy. Four capabilities matter most: 

  • Tracks AI involvement as metadata. Whether content was AI-drafted, AI-translated, or AI-tagged should be recorded on the content itself, not left to memory or a spreadsheet.
  • Enforces human approval before publication. An AI copilot can draft, suggest, and optimize, but publishing should stay a step a person clears every time, not one that gets skipped under deadline pressure.
  • Applies rules consistently across markets. Disclosure and review requirements should travel with the content model, so a rule met on one regional site applies the same way on every other, without each market team building it separately.
  • Keeps an audit trail automatically. Who approved what, when, and whether AI was involved should be a byproduct of normal use, so the team can show after the fact which pages were AI-assisted and who signed off. 

These are the criteria the rest of this guide measures against. The next section shows how a composable DXP meets them in practice. 

How CoreMedia's composable DXP operationalizes EU AI Act compliance 

A composable DXP answers the compliance problems above by holding content, data, and commerce in one governed system, a single source of truth for every digital asset and a foundation for AI governance. Rather than running AI through disconnected external tools (“shadow AI”), it integrates best-of-breed AI through governed APIs, so models operate inside the platform's permissions and approval rules instead of as unvetted third-party apps, supporting the AI Act expectation of high-quality data governance to reduce bias. Global teams manage disclosure, labeling, and oversight from one interface instead of reconciling a dozen. 

The CoreMedia Digital Experience Platform connects the CoreMedia CMS, personalization, the CoreMedia Customer Engagement Platform, and CoreMedia KIO as the embedded AI copilot across all of them. Because AI runs inside the platform, every AI-assisted action has an owner, an approval step, and a record. Structured metadata travels with the content by default, so AI-provenance and labeling markers stay attached across sites, languages, and formats, instead of being reapplied channel by channel. 

In practice, that architecture works through three building blocks: 

  • Hybrid Headless architecture for visual governance: editors see and approve AI-generated content in a visual editor before it publishes. This matters because the AI Act transparency and labeling duties depend on a human checkpoint that a purely headless setup often lacks.
  • Human oversight across all customer touchpoints: the CMS and the CoreMedia Customer Engagement Platform connect published content to live agents. This matters because oversight has to cover chatbots and customer conversations, not just web pages.
  • AI-assisted production (CoreMedia KIO): the embedded AI copilot speeds up content work while requiring editor approval on every action. This matters because it delivers the time-to-market gain without removing the human-centric AI principle behind the disclosure, labeling, and approval controls the EU AI Act requires. 

Hybrid headless CMS for regulated workflows 

Hybrid headless keeps a human review step before anything goes live, which is what makes AI-assisted content auditable. Purely headless systems give developers API-first flexibility but often leave content teams with no way to see and approve what publishes, so AI drafts can reach production without a check. 

CoreMedia's hybrid headless approach pairs that API flexibility with a visual editor, so editors preview AI-generated text, images, and layouts in context and approve or reject them before delivery. For the AI Act transparency and oversight rules, that visual checkpoint is where disclosure, labeling, and a human decision get recorded. 

Human in the lead: oversight from digital content to live agents 

The EU AI Act expects a person, not just a system, to stay responsible for what AI produces, with the ability to review, override, or stop it. This is human in the lead, not human in the loop: a person keeps control and final publishing authority even as AI handles more of the volume. Accountability for what gets published cannot be outsourced to an autonomous system, least of all for legally sensitive or brand-defining claims.  

Human oversight has to reach past the website into live customer conversations, and that is where CoreMedia Content Management System and the CoreMedia Customer Engagement Platform connect. The transparency rules cover chatbots and voicebots as much as published pages, so a customer must know when they are talking to an AI. 

CoreMedia handles the move from an AI chatbot to a live human agent inside one journey, so a hesitating customer on a financial services page can shift from bot to live chat, click-to-call, or a video call with a person. Approval workflows keep a named human accountable before AI-assisted content reaches a regulated channel. 

Bridging the digital-to-human

CoreMedia KIO: AI-assisted production with human control 

CoreMedia KIO speeds up content production while keeping a human in control of every action. It is the AI copilot built into CoreMedia Studio, with access to live brand guidelines, performance data, and customer data. It drafts metadata, summaries, variants, and translations, and handles tagging, SEO optimization, and image processing across large content sets. It works in natural language, and every operation runs in the name of the logged-in editor, within that editor's existing CMS permissions. 

How CoreMedia KIO keeps a human in the lead 

CoreMedia KIO cannot publish or delete content, so nothing it produces reaches an audience without a human publishing step. Every suggestion waits for an editor to review and approve it before it executes, an optional confirmation step can be enforced, and in-flight requests can be cancelled. 

Every change CoreMedia KIO makes is versioned, reviewable as a diff, and reversible, and content it creates or edits is flagged as edited by AI, which supports the disclosure decision the deployer has to make. CoreMedia KIO also makes no automated decisions and no decisions about people. For the Act's human-oversight expectation, that combination, no autonomous publishing, full traceability, and a required human approval, is the checkpoint in practice. 

Administrators can set organization-wide rules and guardrails through playbooks, so the same limits apply across teams and markets. 

Why CoreMedia KIO counts as limited-risk AI 

CoreMedia assesses CoreMedia KIO as a limited-risk AI system, in the transparency-obligation tier rather than the high-risk regime. It performs content operations initiated and reviewed by professional editors, and it does no biometric identification, no emotion recognition, and no profiling or scoring of people, so it serves none of the Annex III high-risk uses like hiring, credit, or access to essential services. 

In role terms, CoreMedia is the provider of the AI system and the customer is the deployer, so the duty to disclose AI use to a published audience sits with the customer, which CoreMedia KIO supports by flagging AI-edited content. CoreMedia is not a general purpose AI model provider either, so the GPAI obligations, including the copyright duties above, rest with the LLM provider the customer configures. One caveat carries over from the risk section: classification follows actual use, so a deployer that puts CoreMedia KIO output into a regulated decision should reassess it against the high-risk rules. 

Model choice and data control 

CoreMedia KIO runs on a configurable, validated set of LLM providers, including OpenAI, Azure OpenAI, Anthropic Claude, Mistral, DeutschlandGPT, or a custom model, so teams are not locked to one vendor. It can run in a private cloud or on-premise, which keeps control of where AI processes content and data. 

Content processed through CoreMedia KIO is not used to train any model, and because CoreMedia does not build or fine-tune models, training data and methods are governed by the chosen provider. CoreMedia KIO is covered by CoreMedia's ISO 27001 certification. 

CoreMedia KIO AI Agent

Security and data governance for multi-region content under the AI Act and GDPR 

CoreMedia meets the security and data-governance expectations that sit alongside the AI Act, with ISO 27001 certification and GDPR compliance as the baseline. For multi-region content, the platform runs on-premise, in a single-tenant managed cloud, a private cloud, or an EU region, so teams control where content and customer data sit. That control matters when AI personalization touches sensitive customer data and when post-deployment controls must support monitoring for serious incidents involving high-risk AI systems. 

Because CoreMedia is headquartered in Hamburg, jurisdiction follows the vendor's domicile in Germany, a point regulated and public-sector buyers weigh heavily. 

The demands these environments place on a platform are high. The German Bundestag runs citizen-facing content on CoreMedia, serving 18 million annual visitors and more than 250,000 live documents. On peak days it has absorbed up to 20 times its average daily traffic, and it came through multiple attempted cyberattacks without disruption. The Deutsche Bundesbank uses CoreMedia's headless CMS to manage monetary policy publications and economic research. 

The platform is also maintained to keep pace with changing regulation, so security and compliance updates are part of ongoing platform maintenance rather than one-off projects. Regulated organizations also need processes to report incidents and retain evidence for audits. 

Talk to our experts. Learn more about the EU AI Act and book a demo to understand what our DXP can do for regulated enterprises. 

The takeaway 

EU AI Act compliance for enterprise content is decided by your content operation, not by a legal memo. The rules in force today reward teams that can disclose AI use, label synthetic media, and show a human approved what went live, and the high-risk rules arriving in 2027 will reward the same discipline. Building that into the platform now costs far less than retrofitting it against a deadline. 

For a broader view of governing AI across published content and live customer conversations, see our Enterprise AI content governance article. To see disclosure, labeling, and human approval working inside one platform, explore how enterprises run on CoreMedia. 

This article provides an overview of the current regulatory landscape and does not constitute legal advice. A legal review is recommended for the assessment of specific cases. 

FAQs 

When does the EU AI Act take effect for content creators? 

For content creators, the EU AI Act's transparency obligations took effect on August 2, 2026, covering AI chatbots, generative AI, and synthetic media such as deepfakes. Earlier phases already apply: prohibited practices and AI literacy since February 2, 2025, and general purpose AI model obligations since August 2, 2025. The high-risk obligations that reach some content-adjacent systems were extended to December 2, 2027, and to August 2, 2028 for AI embedded in regulated products. 

Does every piece of AI-assisted content have to be labeled? 

No. The EU AI Act does not require a label on every piece of AI-assisted content. Users must be told when they interact with an AI system such as a chatbot, and synthetic or manipulated media such as deepfakes must be marked as artificially generated. Routine assistance like drafting or tagging does not carry the same public labeling duty. Generative AI systems already on the market before August 2, 2026 have until December 2, 2026 to meet the marking and detection requirement, and keeping an internal record of AI involvement supports the Act's oversight expectations. 

What to look for in an enterprise content stack for EU AI Act compliance? 

For EU AI Act compliance, an enterprise content stack should do four things automatically rather than relying on people to remember a policy: track AI involvement as metadata on the content itself, enforce human approval before anything publishes, apply disclosure and review rules consistently across every market and language, and keep an audit trail of who approved what and whether AI was involved. A composable platform that builds these into the workflow makes compliance routine, while a fragmented stack of disconnected tools leaves gaps a regulator can act on. 

How does a headless CMS help with AI compliance? 

A headless CMS helps with EU AI Act compliance by storing content as structured, reusable components with API control and workflow governance, which makes it possible to track and label AI-generated content consistently across every channel. A hybrid headless approach adds a visual editing layer, so content teams review and approve AI output in context before it publishes. That human approval step, and the record it leaves behind, are what the Act's human-oversight and transparency rules call for. 

What happens to AI metadata when content is reformatted or translated? 

Legacy, fragmented content stacks often strip metadata during reformatting or localization, causing compliant assets to lose their required machine-readable markings. A composable, component-based DXP like CoreMedia attaches AI provenance metadata directly to the structured content model, ensuring tags travel intact across languages, channels, and frontends.