AI disclosure rules belong in your CMS, not a spreadsheet

Illustrated infographic summarizing: AI disclosure rules belong in the CMS, not a spreadsheet

By Greg Nowak. Last updated 2026-09-22.

When AI disclosure decisions live in a spreadsheet, the evidence starts drifting away from the content almost immediately. A page changes, an asset is replaced, or someone publishes through an import—and the row that once looked reassuring no longer describes what is live.

This has become a practical publishing concern. Article 50 of the EU AI Act has applied since 2 August 2026. It covers areas including deepfakes and AI-generated or manipulated text published to inform the public about matters of public interest. For that text, the disclosure obligation does not apply when the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

The rules do not create a blanket requirement to label every sentence touched by AI. They do make the quality of your review, the identity of the responsible publisher, and the connection between evidence and the approved version much more consequential. Your CMS is the sensible place to manage that connection.

Start with the publishing decision

“Was AI used?” is too crude to drive a useful workflow. An editor might use AI to suggest headings, translate approved copy, produce most of a first draft, or create a realistic image. Those activities do not carry the same editorial, legal, or reputational implications.

Define the decisions your team needs to make before adding fields or installing a plugin. Which uses must be recorded? What constitutes a substantive review? Who may accept editorial responsibility? Which cases require a public label or specialist advice? The answers should reflect your content, audience, role under the law, and legal guidance.

CMS record What it should answer Practical options
AI role How did AI contribute? Ideation, drafting, translation, transformation, generated media
Content risk Does the subject or format require escalation? Routine, public interest, sensitive claim, realistic synthetic media
Review Who checked the substance, and when? Reviewer, date, source notes, review outcome
Disclosure decision What must the audience be told? Not required, required and present, specialist review needed
Approved version Which revision does the decision cover? Revision ID, approval date, editorial owner
A compact content model that connects AI use, review evidence, disclosure, and the approved revision.

Collect evidence editors can realistically maintain

Use an AI role field with plain, limited choices instead of a free-text essay. Add a short review record that identifies the reviewer and covers factual accuracy, source reliability, misleading omissions, and fitness for the intended audience. Grammar correction alone is not a meaningful substantive review.

Store the disclosure decision separately from the AI role. AI use does not automatically determine the outcome. Centralise approved label wording where possible, while still allowing an explanation when an unusual case needs legal or editorial judgment.

For generated or manipulated images, audio, and video, keep the source asset, available provenance metadata, intended context, and approval together. Image optimisation and digital asset management can otherwise break the chain between the original file and the published derivative. This deserves its own process alongside any visible label.

Finally, name an editorial owner. “Human reviewed” is weak operational evidence when nobody can identify the person or organisation that accepted responsibility for publication.

Make the workflow enforce the policy

A practical sequence is Draft → Content review → Disclosure decision → Ready to publish → Published. The CMS should prevent the final transition when required evidence is missing or a case remains unresolved. A material edit after approval should return the page to review rather than silently inherit an old decision.

Apply the same checks to every publishing route. Scheduled posts, bulk updates, API imports, translations, migrations, and agency handovers can bypass controls that exist only as prompts in the browser. Validate critical requirements on the server and record the final revision that passed them.

How this fits WordPress

In WordPress, register structured governance fields as post metadata with appropriate data types, sanitisation, and capability checks. Enable revision support for metadata that must remain tied to the reviewed version. Show the essential fields in the editor, then add useful columns and filters to the Posts screen so an operations lead can find missing decisions and stalled reviews.

A small team may be able to retain the familiar Pending Review status and add validation around publication. Introduce custom statuses only when they improve routing or permissions. Whatever interface you choose, make sure programmatic publishing receives the same validation as a person clicking Publish.

How this fits Drupal

Drupal already supplies much of the foundation through fields, revisions, Workflows, and Content Moderation. Add governance fields to the relevant content types, create only the moderation states your team will use, and restrict sensitive transitions to appropriate roles. A View can become the working queue for content awaiting review or disclosure decisions.

Revisions are especially valuable here: the approval must identify the exact version that was reviewed. A moderation state alone cannot explain why a disclosure decision was made, so keep the evidence in structured fields attached to the content revision.

Put search quality through the same gate

Google’s current guidance does not treat generative AI assistance as an automatic search violation. It asks publishers to focus on accuracy, quality, relevance, and useful context. Generating many pages without adding value can fall under its scaled content abuse policy.

Add four editorial questions before approval: Does this page answer a distinct audience need? Does it contain useful knowledge or judgment beyond a generic summary? Is it substantially different from existing pages? Can its important claims be supported? For a proposed batch, review representative pages and overlap before producing the remainder. A disclosure label cannot make thin content useful.

Roll it out without creating form fatigue

Begin with one content type and a representative sample of real work. Include normal articles, edited AI drafts, translations, generated media, and at least one difficult edge case. Watch where editors hesitate, which fields they skip, and whether reviewers can reconstruct the final decision without opening another system.

Then extend the model to other publishing routes and backfill the live content where the risk justifies the effort. Owners get a visible control point, operations teams get an actionable queue, and agencies can hand over a decision trail that remains attached to the website.

If your AI-assisted publishing process has outgrown informal checks, Greg can help translate the policy into fields, roles, review states, queues, and publication safeguards. Start with a focused CMS workflow review.

Related on GrN.dk

Need help with this kind of work?

Plan your CMS workflow with Greg Get in touch with Greg.

Sources

Seneste artikler

Jeg lærte serverdrift ved at ødelægge mine egne servere. Jeg søger en, der vil stå ved siden af mig, mens jeg gør det, og så gøre det selv ugen efter.

Jeg er god til at bygge og dårlig til at ringe. Her er, hvem jeg vil have ved siden af mig, hvad der er lettest at sælge, og hvordan vi deler det.

AI kan samle onboardingopgaverne før første arbejdsdag. Se, hvordan lederen godkender konkret adgang, og hvordan åbne opgaver bliver fulgt til dørs.

En AI-assistent kan svare på spørgsmål og føre kunder til booking. Her er de konkrete grænser for pris, levering, personoplysninger og kontakt med en medarbejder.

Et sikkert AI-workflow kan omsætte Meet- og Teams-transskripter til godkendte beslutninger og opgaver i Jira eller Asana – uden at slippe kontrollen.

AI kan finde opsigelsesfrister og prisreguleringer i leverandørkontrakter, sende usikre fund til godkendelse og oprette de rette påmindelser.

Sådan automatiserer danske virksomheder Gmail og Microsoft 365 med hurtig sortering, begrænsede rettigheder og menneskelig godkendelse.

Samme kunde på flere kort i HubSpot? Se, hvordan CVR-match, AI-forslag og menneskelig godkendelse kan bruges til at rydde op med styr på felter, relationer og kundehistorik.

Få en ugentlig marketingrapport fra GA4 og Google Ads med kontrollerede beregninger, tydelige dataforbehold og et kort AI-udkast, der hjælper jer på mandagsmødet.

Brug AI til webshoppens alt-tekster med en overskuelig pilot: kortlæg billederne, få danske forslag, og kontrollér resultatet i WordPress og WooCommerce.