The EU Just Made "A Human Looked At It" a Legal Category

EU AI Act Article 50 took effect on 2 August. Its human-review carve-out quietly turns accountability into a legal category, not just good practice.

6 min readBy Matthew Stublefield
A store front at night

"Published text that has undergone human review or editorial control – does not need to be labelled."

That sentence is from the European Commission's own FAQ, and it draws a distinction I didn't expect a regulator to draw this early.

This is analysis, not legal advice. Fieldway is not a law firm, and if you need to know whether any of this applies to your organization, that's a question for counsel.

Article 50 of the EU AI Act took effect on 2 August 2026, with the Commission's implementing guidelines adopted on 20 July. Among its requirements, one applies to deployers publishing AI-generated text intended to inform the public on matters of public interest: that text must be clearly labelled as AI-generated. The human-review carve-out is the exception to it.

The regulation isn't asking whether a machine was involved – it assumes one was. It's asking whether a person took responsibility for the output. And it treats those as different enough that one requires a public disclosure and the other doesn't.

That is accountability written into law as a category, and I think it's more interesting than the fine attached to it.

The scope, which most coverage gets wrong

The standard failure mode of AI Act commentary is to imply everything is covered, and then everyone panics about the wrong things.

The labelling duty above is narrow. It applies to AI-generated or manipulated text, that is published, with the purpose of informing the public, on matters of public interest. Your marketing blog is very probably not in scope. Your internal strategy memo is not in scope. This is aimed at things like news content and public-interest reporting, not at every sentence a model helped you write.

There are three other situations Article 50 covers, which Stibbe's analysis lays out cleanly: systems that interact directly with people must disclose they're AI from the first interaction; providers of generative systems must apply machine-readable marking to synthetic output; and emotion recognition, biometric categorisation and deepfakes carry their own disclosure duties.

Two dates worth holding. Article 50 applies to in-scope systems from 2 August regardless of when they came to market. But there's a limited transitional period for the marking obligation only – providers of generative systems already on the market before 2 August have until 2 December 2026 to comply with that piece. Content generated and published before 2 August needs no retroactive labelling; content generated before but published after does.

Penalties reach EUR 15 million or 3% of total worldwide turnover for the preceding financial year, whichever is higher, with proportionality considered for smaller companies.

The distinction that matters, and the trap in it

Now the precision hazard, because two different exceptions in this regulation both involve spell-checking and they point in opposite directions. I've seen these conflated in nearly every summary I've read, and getting it backwards would be genuinely misleading.

Under Article 50(2) – the provider's marking obligation – there's an exception for standard editing. The Commission's guidelines list grammar correction and spellchecking, minor stylistic polishing that doesn't change substance or meaning, translations, and formatting as exempt from marking. Light-touch editing there means you're outside the obligation.

Under Article 50(4) – the deployer's labelling obligation for public-interest text – the exception is human review or editorial control. And there, as read by one analysis of the guidelines, superficial spell-checking does not suffice; what qualifies is substantive review with documented editorial responsibility.

So spell-checking exempts you from one obligation and fails to rescue you from the other. Writing "the EU says spell-checking doesn't count" without naming which article is wrong in a way that could cost somebody real money.

What 50(4) does is look at two identical documents – same words, same model, same publication – and treat them differently based on whether a human genuinely engaged with the content and can be identified as responsible for it. Not whether the output is accurate. Not whether AI was used. Whether somebody stood behind it.

Why this lands where it does

I hold a belief that predates any of this and that I'd defend on its own terms: capability creates obligation. Any power or privilege or capability you hold generates a duty toward people with less of it, because of how thoroughly our systems are interconnected. That's not a productivity argument – it's the root of why I think leadership is obligation rather than authority.

Applied here: the capability to generate unlimited plausible text at zero marginal cost is real power, and it arrived without any corresponding obligation attached. A model can produce something that reads authoritative on any subject in seconds, and nothing in the technology requires anyone to answer for what it says. That gap is new, and it's not obviously self-correcting, because the incentives run entirely toward producing more.

What Article 50(4) does – narrowly, in one domain, with a compliance mechanism rather than a moral one – is attach an obligation to the capability. If you want to publish this to the public without a label, someone has to have actually read it and be accountable for it.

I'd rather that norm had emerged from professional practice than from Brussels. It didn't, and it wasn't going to, because the whole economic pressure of the last two years ran the other way.

The part that will reach you first

This won't reach most organizations as enforcement.

The Thomson Reuters Foundation analysed data from nearly 3,000 global companies and found the AI Act's influence already spreading through commercial channels: EU-based customers are writing AI Act provisions into requests for proposal, due diligence and contracts, including expectations around conformity, assessments and timelines.

That's how this arrives. Not a regulator knocking – a procurement questionnaire. A client's legal team adding a clause. A diligence checklist with a line about AI governance that didn't exist last year. Buyers ask because it's cheap for them to ask and expensive for them to discover later, and once one large customer standardizes the question, it propagates through everyone's sales process regardless of where anyone is headquartered.

Which means the practical exposure isn't a fine. It's being unable to answer a question in a deal you're trying to close.

What I'd actually do

Not "start a compliance program." For most organizations reading this, the labelling duty doesn't reach you, and the right response is proportionate.

Two things seem worth doing regardless.

First, know which of your outputs a person is genuinely accountable for. Not which ones went through a review step in a workflow tool – which ones a named human read closely enough to defend. If the answer is fewer than you assumed, that's useful information about your operation quite apart from any regulation.

Second, be able to say so. The next diligence questionnaire is going to ask about AI governance, and "we have a policy" is a weaker answer than being able to describe where a person engages with the work and what they're responsible for. That's not a compliance artifact, it's a description of how you operate, and if you can't produce it the problem isn't documentation.

A regulator just wrote into law that output somebody stood behind is a different thing than output nobody did. That's the correct instinct, arriving from an unexpected direction, and the sooner it stops needing a statute behind it the better.

Want help running a sharper practice?

The reading and synthesis behind your client work, handled – a living deliverable kept current, so more of your time goes where your name is actually on the line.

See how this works for advisors