A CMS Can Label AI Content. It Cannot Prove the Decision.
The AI-content labelling conversation has finally reached the content team. That is progress. A good CMS can give an editor a field for "AI generated", another for "AI modified", an approval step, a named reviewer and a visible label at publication.
All of that is useful. None of it is the hard part.
The hard part begins when someone asks why the label says what it says. What policy applied? Which model or tool was used? Was the AI only helping with standard editing, or did it generate a substantive first draft? What did the editor actually review? Who took editorial responsibility? Can the organisation still show the answer after the page became a PDF, an email, a social post, a partner feed or an answer from a retrieval system?
That is not a CMS-field problem. It is a portable evidence problem.
Note: This post describes regulatory frameworks in general terms only. Nothing here is legal advice. Requirements vary by jurisdiction, organisation type, and use case. Consult qualified legal specialists for guidance specific to your situation.
The rule is narrower than the panic
Article 50 of the EU AI Act has applied since 2 August 2026. It separates two jobs that are constantly blurred together.
First, providers of AI systems that generate synthetic audio, image, video or text have a duty to make output detectable as artificially generated or manipulated in a machine-readable format. Second, deployers have disclosure duties for deepfakes and for AI-generated or manipulated text published to inform the public on matters of public interest, subject to important exceptions including substantive human review or editorial control.^1
That does not mean every sentence touched by a writing assistant needs a warning label. It also does not mean a company can add a checkbox called "human reviewed" and call the question closed. The Commission's guidance is clear that the exemption turns on real review or editorial control, not superficial procedural checking.^2
A CMS can make that decision easier to capture. It cannot make the decision true.
A label is a claim, not its evidence
Imagine two organisations publishing an AI-assisted public-health article.
The first adds AI assisted: yes to a CMS entry. It does not record what assistance occurred, which policy governed it, whether a medically qualified editor reviewed the claims, or who authorised publication. It can render an icon on its own website, but it has no useful record once the content is copied elsewhere.
The second records the applicable policy version, permitted purpose, tool class, content version, editor's substantive review, accountable publisher, disclosure decision and the reason for that decision. The record travels with the content or is resolvable from it. A third party can tell whether the record was altered later.
Both organisations have a label. Only one has a defensible answer when a customer, regulator, platform or journalist asks what happened.
That distinction is the MX opportunity.
The CMS is part of the answer, not the boundary of it
CMS vendors are right to build AI-workflow controls. Content needs a place where people can declare assistance, route work to an editor and apply a publication label. The CMS is often the best user interface for this part.
But the content estate is larger than the CMS:
- A PDF is downloaded, emailed and printed.
- An image is cropped, compressed and uploaded again.
- A product description is syndicated to a retailer.
- A support article is copied into a knowledge base.
- A document is chunked into a retrieval index and returned through an agent.
- A partner receives a feed without the page that originally displayed the label.
A workflow field in one application does not automatically survive any of these moves. Nor does it provide a common language for policy, accountability and review across the DAM, the publishing platform, the customer-support system and the agent layer.
If governance only exists where one product can see it, it stops being governance when the content leaves that product.
What MX adds
MX should not replace a CMS and does not need to. It provides the machine-understanding layer that lets content systems express the governance decision in a shared, portable form.
For an AI-assisted artefact, that means making five things explicit and machine-readable:
- Policy - the versioned rules governing the permitted use of AI.
- Process - what the system or person actually did, including the boundary between assistance and generation.
- Review - the substantive human review or editorial control carried out, not merely a tick-box.
- Accountability - the person or organisation accepting responsibility for publication.
- Provenance - the evidence trail that connects the declaration to a specific content version and can still be checked later.
COGs, Community Owned Governance Standards, are where those rules become explicit. They do not grant a model authority. They say what is allowed, what is prohibited, what evidence is required and when the work must escalate to a human. That gives a content team something better than a general policy PDF: a versioned instruction that both people and machines can test against.
Where REGINALD fits, and where it does not
REGINALD-compatible provenance is the next layer. It can cryptographically sign and register a policy version, a content declaration or a decision-evidence reference so that a verifier can check its origin and integrity.
It does not put sensitive prompts, customer data, unpublished drafts or personal information into a public registry. It does not certify that an organisation complies with the EU AI Act. Compliance remains the organisation's legal and operational responsibility.
What it does offer is stronger evidence than "our CMS said so". A verifier can establish which record applied, whether it was changed and which content version it relates to, without needing to trust every intermediary in the chain.
The practical architecture
The right architecture is not a new label field in every tool. It is one policy and evidence model that every tool can use.
- The CMS captures editorial declarations, routes review and renders any required disclosure.
- The DAM carries media provenance using the relevant media standards, such as C2PA or Content Credentials where appropriate.
- MX expresses the shared policy, accountability and decision-evidence vocabulary across the carriers.
- COGs define the rules and escalation thresholds in a form agents and people can read.
- REGINALD-compatible provenance makes the references and declarations independently checkable.
This preserves the CMS's job. It makes content manageable. MX makes the governance around that content legible to machines wherever the content goes.
Start with the question behind the icon
Every organisation should absolutely improve its AI-content workflow. Add the fields. Define review. Train editors. Make disclosures clear where the law and the audience require them.
Then ask the question the icon cannot answer: can we show why this decision was made, under which rules, and whether that evidence still holds outside the system that made it?
If the answer is no, the next purchase is not another badge. It is an evidence architecture.
That is the work MX was built to make possible.