AI is already finding its way into everyday content production. A marketing team creates a campaign visual with generative AI. An e-commerce team uses AI to place a product in a new setting. A designer removes a background or extends an image with generative fill. A manufacturer creates supporting visuals for a product launch.
And then someone asks: Can we actually use this?
Do we need to tell the audience that AI was involved? Does it matter whether AI created the whole asset or only changed part of it? What information should we keep? What happens if the file contains Content Credentials? And how do we make sure the next person using the asset knows what applies?
For many organizations, this is where AI governance starts. Not with a large compliance program, but with practical questions about content that is already moving through the business.
The good news is that you do not need to solve everything at once. A sensible first goal is much simpler: make sure you know enough about an asset to decide whether and how it can be used.
AI content governance is the combination of rules, metadata, provenance, review and distribution controls used to manage content that has been generated or changed with AI.
In practice, it helps you understand whether AI was involved, how it was involved, where that information came from, whether the asset needs additional review, whether disclosure is required and where the asset is approved for use.
That matters because AI can play very different roles in content creation. A marketing team might create a fully AI-generated lifestyle image for a campaign. A retailer might place a real product into an AI-generated environment. A manufacturer might use generative AI to create supporting launch material. A designer might simply use AI to remove the background from an existing photograph.
AI may be involved in all of these examples, but that does not automatically mean they should follow the same rules.
The practical starting point is therefore not simply “Was AI used?” but “How was AI used, and does that change what we need to do?”
The terminology can make a fairly practical content question feel much more complicated than it needs to be. Three concepts are useful to separate.
Article 50 of the EU AI Act introduces transparency obligations for certain AI systems and AI-generated or manipulated content. These rules apply from 2 August 2026, with different obligations depending on the role an organization has and the type of AI use.
For providers of generative AI systems, this includes requirements around machine-readable marking of certain AI-generated or manipulated outputs. Organizations using AI systems also have specific disclosure obligations in situations such as deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest.
Importantly, this does not mean that every asset touched by AI automatically needs a visible AI label. The requirements depend on the type of content, how AI was used, the organization's role and how the content is presented. The European Commission's guidance also makes distinctions around uses such as standard editing and assistive functions.
Read the European Commission’s guidance on Article 50 transparency obligations
For a content team, the practical consequence is simple: before you can decide what rules apply, you need enough context about the asset to understand what you are dealing with.
Disclosure is different from simply recording AI involvement internally.
Your organization may choose to require a visible label, note or watermark for certain content as part of its own policy, even where that goes beyond the legal minimum.
Where the AI Act specifically requires disclosure, however, that disclosure needs to be understandable and perceivable to the people exposed to the content. Embedded machine-readable provenance should not therefore be treated as a replacement for audience-facing disclosure where one is legally required.
That makes it useful to keep two questions separate: What do we know about this asset? and What do we need to communicate when we use it?
C2PA is an open technical standard for digital content provenance. It provides a way to associate cryptographically verifiable information with an asset about its origin and history. Content Credentials is a commonly used user-facing concept for C2PA-based provenance information.
This can be valuable because some of the information needed for governance may already travel with the asset.
But C2PA does not decide whether an asset is approved, compliant or suitable for a particular channel. And the AI Act does not require organizations to use C2PA specifically.
A useful way to think about it is that provenance can help answer “What do we know about this asset?” while your policy and governance process answer “What should we do with it?”
Learn more about the C2PA standard
You do not need to build a complete governance framework on day one. Start with the AI use cases you already have and gradually add enough structure to support better decisions.
Before writing rules or creating metadata fields, look at what your teams are actually doing.
Which AI tools are being used? What kind of content is being created? Is AI generating an entire asset or assisting with an edit? Are agencies and suppliers also creating AI content? And where does the finished content eventually get used?
For a retailer, that might mean AI-generated lifestyle environments around real product photography. For a manufacturer, it could be campaign illustrations or supporting launch material. A marketing team might generate complete concept images while also using generative fill for smaller edits to traditional photography.
These are different use cases and may need different rules.
You may also find older AI-created or AI-edited assets already sitting in your DAM without any information about the AI involvement. That does not mean you need to stop and classify your entire archive.
A practical approach is to establish a good process for new content first, then address older assets based on risk, relevance and likelihood of being reused.
In QBank, this first step can be as simple as identifying which types of assets may contain AI-generated or AI-assisted content, such as images, video, audio and documents. That gives you a clear scope before adding more rules or metadata.
Once you understand how AI is actually being used, decide how your organization wants to treat those use cases.
You do not need to start with a 30-page AI policy. A few real examples can often make the conversation much easier.
Take a product photograph where AI was used to remove the background and compare it with a realistic person generated entirely with AI for an external advertising campaign. Would you treat them in exactly the same way?
Probably not.
For each important use case, try to agree on four things: whether the content is allowed, whether it needs additional review, whether the audience needs to be informed and where the content may be used.
A useful first policy can therefore be quite focused. Agree on what you mean by different levels of AI involvement, what uses are allowed or restricted, who should review higher-attention content, when disclosure is needed and what information needs to stay connected to the asset.
Need help getting started? Our AI Content Policy Guide walks through the key decisions to make and gives you a practical structure for building your own policy.
→ Download the AI Content Policy Guide
In QBank, those decisions can then become controlled metadata, review criteria and distribution rules. Your policy defines the rule. QBank helps make it part of the everyday content process.
Once the basic rules are clear, start adding structure to the asset itself.
For some organizations, the easiest place to start is simply recording whether an asset was created or edited with AI. But over time, a simple yes or no is unlikely to be enough. You will also want to understand how AI was involved.
A practical classification could distinguish between human-created, AI-assisted, fully AI-generated, deepfake or synthetic content, and content that has not yet been assessed.
That last category is important. Missing information should not automatically be interpreted as confirmation that no AI was involved.
From there, you can gradually add context such as the AI tool used, where the information came from, whether disclosure is required, whether the asset has been approved and where it may be used.
You do not need to collect everything. A small set of metadata that people understand and consistently maintain is more valuable than a complex structure that becomes difficult to trust.
Provenance can also reduce the amount that needs to be entered manually. If an original file contains C2PA information or Content Credentials, QBank can preserve that information with the original. Relevant provenance information can also be mapped into QBank metadata and used alongside information added by your teams.
The principle is simple: preserve what the asset already knows, and add the organizational context it does not.
Recording information is only useful if someone can act on it.
If an asset is fully AI-generated and still waiting for review, it should not disappear among thousands of other assets. The right team should be able to find it quickly.
In QBank, metadata can be used to create live views of content that needs attention. For example, you could surface assets that have not yet been classified, AI content pending review, assets missing a disclosure decision or content created with a tool that is no longer approved.
As the metadata changes, those views change with it.
This means you do not necessarily need to create a completely separate AI workflow from day one. Your normal content process can remain familiar, while extra attention is added where it is actually needed.
Metadata rules can make that process more consistent too. For example, if an asset is classified as fully AI-generated, additional information such as its disclosure requirement can be required before it is considered ready for use.
The aim is not to make every upload slower. It is to make content that needs attention easy to identify and easy to handle correctly.
The last step is to make sure your governance does not stop inside the DAM.
Imagine an asset that is fully AI-generated, approved for website and social media, and requires a visible disclosure.
That tells the next user much more than a simple “AI-generated” tag. It tells them what they are actually allowed to do.
The same asset might be suitable for a campaign page but not for an e-commerce product listing. It could be approved for internal sales material but restricted from another external channel.
In QBank, metadata and channel filtering can help control which assets are available in different portals and publishing environments. Disclosure requirements can also stay connected to the asset rather than relying on someone remembering a separate policy document.
Labels and watermarks can already be supported through template-based outputs. Over time, the direction is towards more metadata-driven distribution, where the action taken during publishing can increasingly respond to what an asset requires.
There is one additional provenance consideration to keep in mind. A transformed or rendered version of an asset does not necessarily retain all provenance information carried by the original file. Where provenance is important, keep the original as your source of truth and be clear about which version carries that information.
There is a lot happening around AI-generated content right now: new regulation, Content Credentials, provenance standards, disclosure practices and new ways of creating and editing content.
It is easy to feel as if you need to understand all of it before you can start.
You don't.
Take one real piece of content your team is creating today and ask: Can we use this asset?
Then work backwards. Do we know how AI was involved? Do we know where that information came from? Does anyone need to review it? Where may it be used? Does the audience need to be informed?
If you can answer those questions consistently, you already have the foundation of practical AI content governance.
Start with the use cases you have today. Agree on a few rules. Capture enough information to support those rules. Then add more automation, provenance and distribution controls as your needs mature.
The goal is not to add more administration around AI. It is to make AI-assisted and AI-generated content easier to understand, easier to trust and safer to use.
No. The EU AI Act does not require every asset that has been touched by AI to carry the same visible label. What applies depends on the type of AI involvement, the content, the organization's role and how the content is used.
Your organization may still decide to use broader disclosure rules as part of its own AI content policy.
AI-generated content is created substantially or entirely using AI. AI-assisted content starts with human-created material that is then edited or enhanced with AI.
The exact boundary will not always be obvious. What matters operationally is that your organization agrees on definitions and uses them consistently so that the right rules can be applied.
No. The AI Act includes requirements around machine-readable marking in certain circumstances, but it does not prescribe C2PA as the required technical standard.
C2PA can instead support transparency and traceability as part of a broader content governance approach.
No. Content Credentials provide provenance information about an asset. Disclosure is about informing the audience when required.
They can complement each other, but they serve different purposes. Machine-readable provenance alone should not be treated as a replacement for audience-facing disclosure where one is legally required.
A practical starting point is to record how AI was involved, which AI tool was used, where the information came from and whether disclosure is required.
As your governance matures, you can add approval status, approved channels, approver information and connections to relevant source assets.
You do not need every possible scenario decided first. But you should agree on a few basic things: what different levels of AI involvement mean, what is allowed, what needs additional review, when disclosure is required and where different types of content may be used.
QBank can then help turn those decisions into everyday content governance.
Once you have agreed on the basic rules, the next challenge is making them part of the everyday content flow.
QBank can help you keep AI context and provenance connected to your assets, surface content that needs attention, support review and approval, and control how content is made available across channels.
Explore AI content governance in QBank
This article provides practical guidance for content governance and is not legal advice. Organizations should assess the requirements of the EU AI Act based on their own role, use cases and obligations.