Declaring AI in a WordPress plugin: what actually changes
Par AIFORYA — 3 August 2026 — 11 min de lecture
On this page (10)
A date has been going round for a few weeks — 2 August 2026 — and it arrives with just about everything attached to it: that you now have to declare whether a site was built with AI, that a plugin should announce whether its code was written by a machine, that published images should carry a notice.
Those three statements are wrong, or true for reasons other than the one being given. They look alike enough to be confused, and they do not have the same consequences.
This article untangles what really changes for someone running a WordPress site. It is written for a site owner, not for a lawyer — and it says where our knowledge stops.
This text is not legal advice. It is a technical reading, made from our own compliance work. The points where a legal qualification is at stake are flagged as such: they are settled with a professional.
Contents
- What changes on 2 August, in one sentence
- The distinction that governs everything else
- What probably does not concern you
- What does concern you, and nobody talks about
- The three confusions to avoid
- The French rule everyone forgets
- What it is reasonable to do this week
- What we do not know
- How we go about it
What changes on 2 August, in one sentence
The European regulation on artificial intelligence does not apply all at once: it comes into force in stages, spread over several years. 2 August 2026 is the stage at which the transparency obligations become applicable.
Transparency here means two distinct things, and mixing them is where people go wrong:
- When someone interacts with an AI, they must know it. A visitor talking to a conversational assistant on your site must not believe they are talking to a person.
- When a piece of content is generated by an AI, it must be marked — and not only for the human eye: in a format readable by a machine, reliably and durably.
The first point is intuitive. The second is far less so, and it has the greater technical consequences — but, as we will see, it does not weigh on the person it is most often attributed to.
The distinction that governs everything else
The regulation does not talk about "sites" or "software". It splits obligations between two roles, and everything depends on which one you occupy:
| Role | Who that is | Example |
|---|---|---|
| Provider | whoever develops an AI system and puts it on the market under their own name — whether paid or free | the publisher of the plugin you installed |
| Deployer | whoever uses that system in the course of their activity | you, running the site |
Two immediate consequences.
Being free changes nothing. A plugin distributed free of charge still puts its publisher in the provider role. It is explicit in the text, and it is what surprises publishers themselves the most.
The role cannot be chosen by contract. A clause saying "we are merely a technical tool, the user alone is responsible" does not move a regulatory obligation. It only creates a gap between what is promised to the customer and what the text expects of the publisher. We know this because we had exactly that clause in our own terms and conditions, and it had to be rewritten.
What probably does not concern you
The heaviest obligation of 2 August — machine-readable marking of generated content — falls on the provider, that is, on the publisher of the plugin. Not on you.
Concretely: if you use a plugin that writes product descriptions, it is not for you to improvise a marking in your theme. It is for the tool to produce correctly marked content. If your tool does not do it, the question to ask is not "how do I get compliant?" — it is "what has my supplier planned?".
That is a good question to ask, incidentally. It quickly separates the publishers who have read the text from those who have not.
And no: the fact that a plugin was coded with the help of AI is not what is at stake here. The regulation is concerned with the content the software produces for your visitors, not with how its code was written. These are two different subjects, and confusing them leads you to look for compliance in the wrong place. What a plugin directory may ask you to declare about the origin of the code is another discussion, with another timetable.
What does concern you, and nobody talks about
Two things, and the second has gone completely unnoticed.
Your conversational assistant, if you have one. If your site offers an agent that answers visitors, they must know they are addressing a machine — clearly, and at the latest at the first exchange. A discreet mention at the foot of a widget is defensible; it is not obviously sufficient. If your agent has a first name and a face, prudence leans towards a plain notice.
Skills, which is an obligation, and is overdue. The regulation has required since February 2025 — so for more than a year — that people operating AI systems have a sufficient understanding of them. This obligation targets providers and deployers. It does not ask for a diploma: it asks that you know what the tool you installed does, what it sends outside, and what it can get wrong.
Nobody talks about it because it comes with no visible technical gesture. Yet it is the only one that directly targets a site owner, and it has been due for a long time.
The three confusions to avoid
"You have to put 'AI generated' everywhere." No — and over-marking has a real cost. The text provides an exception for ordinary editing assistance that does not substantially modify what you wrote. Compressing an image, renaming it, fixing a turn of phrase: you are probably within the exception. Generating a whole article or a complete product sheet: you are not. The exact boundary is discussed case by case, and it is a point of law.
"A notice for humans is enough." A line at the bottom of the page satisfies the eye, not the obligation. What is required for generated content is marking usable by a machine — so in the file metadata or in the markup, in a way that survives copying and republication. That is publisher work, not copywriting.
"It's a ban." It is an obligation to say, not a ban on doing. Nothing forbids publishing a text written by an AI. What is required is that it be identifiable. The difference is enormous for anyone building an activity on it: the text penalises concealed AI, not acknowledged AI.
The French rule everyone forgets
It has nothing to do with the European regulation, it has been in force since 2023, and its consequences are markedly more severe.
French law on commercial influence requires the notice "Images virtuelles" on any AI-produced image representing a face or a silhouette, and "Images retouchées" where a silhouette or a face has been modified. The notice must be clear, legible and identifiable on the image itself, in every format, for the whole time it is displayed.
It targets people engaged in commercial influence. If you publish generated visuals featuring people in a promotional setting, the question arises for you — and it has done since 2023, independently of 2 August.
What it is reasonable to do this week
Nothing urgent if you are only running your own site. Four steps, in this order, and none takes a day.
1. List what, on your site, produces content. Not the list of your plugins: the list of those that write, generate or compose something publishable. On most sites it fits in two or three lines — and many people discover, in making it, that they have none.
2. For each one, put the question to the publisher. "How do you mark the content your tool generates, and since when?" The answer, or its absence, will tell you a great deal. It is also the moment to check what the tool sends outside, and to whom.
3. Look at your conversational agent, if you have one. Does a visitor landing on it understand within a second that they are talking to a machine? If the answer needs defending, it is no.
4. Write down what you found, with the date. One page in an internal document is enough. The value is not in the form: it is in being able to say, later, what you knew and when. It is also the only way to see what has moved at the next review.
What you should not do: add notices everywhere as a precaution. A false marking, applied to content you wrote yourself, has no protective effect and damages the reading.
What we do not know
We are doing this work on our own plugins, and we have not finished. Three things remain open at our end, and it would be dishonest to leave them out of an article explaining the rule to others:
- The exact boundary of editing assistance — what "substantially modifies" a piece of content and what does not — is qualified case by case, and for some of our tools we have not settled it.
- Whether a first-interaction notice is sufficient for a conversational agent is open to discussion.
- Some categories of use tip a tool into a far heavier regime — assessing learners, screening job applications, emergency medical triage. It is not the advertised function that decides, it is the reasonably foreseeable use, and that assessment has to be written down.
If a publisher tells you everything is settled at their end and that it is simple, you have learned something about them.
How we go about it
Our plugins are AI-assisted, we say so, and we took the question from the other end: each one ships with its test suite, its quality gates and its official WordPress Plugin Check report. Disclosure here is not a checkbox — it is a document, and it exists before anyone asks for it.
That is also why this article says what we have not resolved. A page claiming everything is in order would be more pleasant to read and worth less.