TwinEthosRequest access

Control

GenAI content lacking explicit and implicit labels

AI-generated content must carry both a visible (explicit) label and metadata (implicit) label identifying it as AI-generated.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI-generated content is not labeled, marked, or traceable as artificial · control id cond.genai-content-no-explicit-and-implicit-label

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in China (CN).

The guard to add

Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.

A labeling step between the generator call and every save, return, or download path does two things: it adds an explicit label users can perceive (text drawn onto images or video frames, an audible notice in audio, a label beside generated text in the UI), and it writes implicit metadata into the file (a PNG text chunk, XMP block, or C2PA manifest) carrying the AI-generated attribute, the provider's name or code, and a unique content ID. Export and download routes go through the same step so files leave with both labels; a digital watermark can complement the metadata.

Where it goes: 9 AI output handling, 1 application source code.

What reviewers look for: in the module that writes generated media, both a visible label (ImageDraw text, ffmpeg drawtext=, a label component) and a metadata write (PngInfo with an AIGC field, XMP, c2pa) on every path to save or return, including export and download.

Example (OpenAI Images + Pillow), before:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64)))
img.save(path)

After:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64))).convert('RGB')
font = ImageFont.truetype('NotoSansCJK-Regular.ttc', 24)
ImageDraw.Draw(img).text((12, img.height - 36), 'AI生成 / AI-generated', fill=(255, 255, 255), font=font)
meta = PngInfo()
# implicit label: AI-generated attribute, provider name or code, content reference (Art. 5);
# take the exact metadata field names from the national standard GB 45438-2025 (not encoded here)
meta.add_text('ai_generated_label', json.dumps({'ai_generated': True, 'provider': PROVIDER_CODE,
                                                'content_id': str(uuid.uuid4())}))
img.save(path, format='PNG', pnginfo=meta)

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)