{"id":366341,"date":"2026-09-14T11:54:47","date_gmt":"2026-09-14T11:54:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ai-act-image-marking\/"},"modified":"2026-09-14T11:54:31","modified_gmt":"2026-09-14T11:54:31","slug":"ropemark-image-marking-for-eu-ai-act","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ropemark-image-marking-for-eu-ai-act\/","author":22023297,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.1","stable_tag":"1.0.1","tested":"7.1","requires":"6.1","requires_php":"7.4","requires_plugins":null,"header_name":"Ropemark Image Marking for the EU AI Act","header_author":"The Rope","header_description":"Mark, keep and disclose AI-generated images: writes the IPTC marking where it is missing, keeps it in every size WordPress generates, adds an AI badge with provenance popup and documents everything in the Media Library. EU AI Act, article 50.","assets_banners_color":"141c48","last_updated":"2026-09-14 11:54:31","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/wearetherope\/ai-act-image-disclosure","header_author_uri":"https:\/\/therope.it","rating":0,"author_block_rating":0,"active_installs":0,"downloads":49,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"therope","date":"2026-09-14 11:54:31","revision":3695140}},"upgrade_notice":{"1.0.1":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3695140,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3695140,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3695140,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3695140,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"ropemark\/disclosure":{"name":"ropemark\/disclosure","title":"AI disclosure notice"}},"tagged_versions":["1.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3695183,"resolution":"1","location":"assets","locale":"","width":1400,"height":800},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3695183,"resolution":"2","location":"assets","locale":"","width":1440,"height":470},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3695183,"resolution":"3","location":"assets","locale":"","width":1400,"height":380},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3695183,"resolution":"4","location":"assets","locale":"","width":700,"height":605},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3695183,"resolution":"5","location":"assets","locale":"","width":1400,"height":1105}},"screenshots":{"1":"Media Library list view with the AI marking column, filter and bulk actions.","2":"The marking panel in the attachment details: provenance, classification, per-image badge.","3":"Badges on grid tiles.","4":"The AI badge and the provenance popup on the front end.","5":"Settings: original file, generated sizes, badge, popup, label and site notice."}},"plugin_section":[262246],"plugin_tags":[216086,256950,4096,233,261422],"plugin_category":[],"plugin_contributors":[280651],"plugin_business_model":[],"class_list":["post-366341","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai-images","plugin_tags-image-metadata","plugin_tags-iptc","plugin_tags-media-library","plugin_tags-provenance","plugin_contributors-therope","plugin_committers-therope"],"banners":{"banner":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/banner-772x250.png?rev=3695140","banner_2x":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/banner-1544x500.png?rev=3695140","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/icon-128x128.png?rev=3695140","icon_2x":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/icon-256x256.png?rev=3695140","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/screenshot-1.png?rev=3695183","caption":"Media Library list view with the AI marking column, filter and bulk actions."},{"src":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/screenshot-2.png?rev=3695183","caption":"The marking panel in the attachment details: provenance, classification, per-image badge."},{"src":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/screenshot-3.png?rev=3695183","caption":"Badges on grid tiles."},{"src":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/screenshot-4.png?rev=3695183","caption":"The AI badge and the provenance popup on the front end."},{"src":"https:\/\/ps.w.org\/ropemark-image-marking-for-eu-ai-act\/assets\/screenshot-5.png?rev=3695183","caption":"Settings: original file, generated sizes, badge, popup, label and site notice."}],"raw_content":"<!--section=description-->\n<p><strong>Since 2 August 2026 the EU AI Act (article 50) requires AI-generated and AI-manipulated images to be marked in a machine-readable way and, when they show people or scenes that look real, to be disclosed visibly to the public.<\/strong> If you publish virtual models, AI product shots, campaign visuals or any image made with Midjourney, Nano Banana, DALL\u00b7E, Firefly, Stable Diffusion or similar tools, this concerns your WordPress site.<\/p>\n\n<p>Ropemark does four things: it <strong>marks<\/strong> files that lack the IPTC marking, <strong>keeps<\/strong> the marking in every size WordPress generates, <strong>discloses<\/strong> it on the page and <strong>documents<\/strong> it in the Media Library.<\/p>\n\n<h4>1. The visible disclosure<\/h4>\n\n<ul>\n<li><strong>AI badge<\/strong>: a round, semi-transparent \"AI\" mark overlaid on AI-generated images, in the corner you choose. Text or your own icon, diameter, colors, opacity, minimum image width and tooltip are settings; the markup carries CSS classes your theme can restyle.<\/li>\n<li><strong>Provenance popup<\/strong>: a click on the badge opens a small panel with type, disclosure text, creator, credit, generator and marking of that image. It is plain HTML kept hidden in the page, readable by assistive technology and search engines.<\/li>\n<li><strong>Per image<\/strong>: not every AI image needs the badge. Each attachment can follow the settings, always show it or never show it, one by one or in bulk.<\/li>\n<li><strong>Text label<\/strong> under AI images, <strong>site notice<\/strong> at the end of every page, and a <code>[ropemark_disclosure]<\/code> shortcode plus an \"AI disclosure notice\" block for your transparency page, with the count of AI images.<\/li>\n<li><strong>Data attributes<\/strong> (<code>data-ai-generated<\/code>, <code>data-digital-source-type<\/code>) and <strong>schema.org ImageObject<\/strong> with <code>digitalSourceType<\/code> for search engines and AI crawlers.<\/li>\n<\/ul>\n\n<h4>2. The machine-readable marking, written and kept<\/h4>\n\n<p>WordPress never touches the file you upload, but every size it generates (thumbnails, medium, large and the scaled copy it serves as \"full\") comes out of GD or Imagick <strong>without XMP and IPTC<\/strong>. The marking your generator or your DAM wrote into the original is gone from the images your pages actually show.<\/p>\n\n<ul>\n<li>The plugin <strong>reads<\/strong> the provenance of each upload: the IPTC <code>DigitalSourceType<\/code> term (<code>trainedAlgorithmicMedia<\/code>, <code>compositeWithTrainedAlgorithmicMedia<\/code>, and the rest of the vocabulary), the disclosure text, creator, credit and rights, and whether a <strong>C2PA \/ Content Credentials<\/strong> manifest is present, with the names of the tools that signed it (Google, Adobe Lightroom, Photoshop, and so on).<\/li>\n<li>It <strong>carries the marking into every generated size<\/strong>, byte for byte, without re-encoding pixels: JPEG, PNG and WebP.<\/li>\n<li>You decide <strong>what to carry<\/strong> (the whole XMP and IPTC blocks, or only the provenance fields), <strong>into which sizes<\/strong>, and whether the <strong>original<\/strong> is left untouched or cleaned of post-production traces (Camera Raw settings, document history) while keeping the marking.<\/li>\n<li><strong>Manual classification<\/strong> for files that carry no marking (most retouched images lose it): \"AI generated\", \"AI modified\" or \"not AI\", per image or in bulk. An AI classification <strong>writes the IPTC digital source type into the sizes and, unless the original carries a C2PA manifest, into the original<\/strong>. A manual choice becomes a machine-readable marking that travels with the file.<\/li>\n<li><strong>Generator traces<\/strong>: files without a formal marking but with signs of Midjourney, DALL\u00b7E, Firefly, Stable Diffusion, ComfyUI, Google, OpenAI and others (software fields, PNG parameters, XMP) are listed as \"Suspected AI, to confirm\", never marked automatically.<\/li>\n<\/ul>\n\n<h4>3. The audit trail in the Media Library<\/h4>\n\n<ul>\n<li>A column and a badge in the list view, a badge on grid tiles.<\/li>\n<li>A read-only <strong>provenance panel<\/strong> in the attachment details: digital source type, disclosure text, creator, credit, rights, C2PA signers, and which generated sizes carry the marking.<\/li>\n<li>A <strong>filter<\/strong>: AI generated or modified, suspected AI, with provenance marking, without.<\/li>\n<li><strong>Bulk actions<\/strong> to classify and to show or hide the badge, a <strong>library scan<\/strong> for everything uploaded before the plugin, a <strong>CSV export<\/strong> of the AI images for your audit file, and WP-CLI.<\/li>\n<li>The record is exposed on the <strong>REST API<\/strong> attachment endpoint for headless themes.<\/li>\n<\/ul>\n\n<h4>What the plugin does not do<\/h4>\n\n<ul>\n<li>It does not guess whether an image is AI-made by looking at pixels. It reads what the file declares in the standard vocabularies (IPTC Photo Metadata, C2PA). Files with no marking are shown as \"No marking\": write the marking in production, before upload (most generators do it; exiftool or any DAM can add <code>DigitalSourceType<\/code>).<\/li>\n<li>It does not copy C2PA manifests into resized copies. A C2PA signature covers the exact bytes of the original file, so a copy inside a derivative would validate as tampered. The original keeps its manifest; the plugin records the fact and the signers.<\/li>\n<li>It does not write AVIF yet. If your site converts sizes to AVIF, those sizes stay unmarked and the settings screen tells you.<\/li>\n<li>It is not legal advice. The AI Act distinguishes the machine-readable marking of the file (article 50(2)) from the visible disclosure to the person looking at the image (article 50(4)). The plugin gives you the tools for both; how you word the disclosure is your call, with your legal team.<\/li>\n<\/ul>\n\n<h4>Who it is for<\/h4>\n\n<p>Brands, e-commerce teams and agencies that publish AI-generated visuals (virtual models, product shots, campaign images, AI-retouched photos) and need the marking to survive publication, with proof in the Media Library. Works with WooCommerce galleries, the block editor, classic themes and headless setups.<\/p>\n\n<h4>Standards<\/h4>\n\n<ul>\n<li>IPTC Photo Metadata Standard: <code>Iptc4xmpExt:DigitalSourceType<\/code>.<\/li>\n<li>IPTC IIM (Caption, By-line, Credit, Copyright) in the Photoshop APP13 segment.<\/li>\n<li>C2PA (Coalition for Content Provenance and Authenticity) manifests: detected and reported, never altered.<\/li>\n<li>XMP in PNG (<code>iTXt XML:com.adobe.xmp<\/code>) and WebP (<code>XMP<\/code> chunk with the VP8X flag).<\/li>\n<\/ul>\n\n<h4>For developers<\/h4>\n\n<ul>\n<li><code>ropemark_get_provenance( $attachment_id )<\/code> returns the record; <code>ropemark_is_ai_generated( $attachment_id )<\/code> returns a boolean.<\/li>\n<li>Filters: <code>ropemark_should_preserve<\/code> (per attachment), <code>ropemark_decorate_image<\/code> (badge and label per image), <code>ropemark_badge_text<\/code>, <code>ropemark_label_text<\/code>, <code>ropemark_popup_rows<\/code>.<\/li>\n<li>Constant <code>ROPEMARK_CREDIT_DEFAULT<\/code> (wp-config.php) to start with the credit line in the popup enabled.<\/li>\n<li>Action: <code>ropemark_after_inject<\/code> with the per-size outcome.<\/li>\n<li>WP-CLI: <code>wp ropemark scan [--all] [--dry-run]<\/code>, <code>wp ropemark status &lt;id&gt;<\/code>.<\/li>\n<li>CSS classes for the front end: <code>.ropemark-wrap<\/code>, <code>.ropemark-ai-badge<\/code>, <code>.ropemark-pos-bottom-right<\/code> (and the other corners), <code>.ropemark-popup<\/code>, <code>.ropemark-label<\/code>, <code>.ropemark-site-notice<\/code>, <code>.ropemark-disclosure<\/code>, <code>img[data-ai-generated]<\/code>.<\/li>\n<\/ul>\n\n<p>Ropemark Image Marking for the EU AI Act is made by <a href=\"https:\/\/therope.it\">The Rope<\/a>, a digital agency in Milan.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install from the Plugins screen or upload the folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate.<\/li>\n<li>Go to <strong>Media \u2192 Ropemark<\/strong>, turn on the badge if you want it, and run <strong>Scan new images<\/strong> to process what was uploaded before activation.<\/li>\n<\/ol>\n\n<p>Every new upload is processed automatically.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20plugin%20detect%20ai%20images%3F\"><h3>Does the plugin detect AI images?<\/h3><\/dt>\n<dd><p>No. It reads the declaration inside the file (IPTC <code>DigitalSourceType<\/code>, C2PA manifest). Images without a declaration are listed as \"No marking\". Mark files in production, before upload: most generators embed C2PA, and exiftool or any DAM can write <code>DigitalSourceType<\/code>.<\/p><\/dd>\n<dt id=\"is%20the%20badge%20enough%20for%20the%20ai%20act%3F\"><h3>Is the badge enough for the AI Act?<\/h3><\/dt>\n<dd><p>The plugin cannot give legal advice. Article 50 asks for a visible, clearly distinguishable disclosure at first exposure for deepfakes, which the Commission guidelines of July 2026 read as including photorealistic portraits of people who do not exist. A badge on the image or a label next to it are the two forms seen on European e-commerce sites today. Metadata alone is not considered enough for the visible part.<\/p><\/dd>\n<dt id=\"why%20is%20the%20c2pa%20manifest%20not%20in%20the%20thumbnails%3F\"><h3>Why is the C2PA manifest not in the thumbnails?<\/h3><\/dt>\n<dd><p>Because it would be a lie. A C2PA signature binds the exact bytes of one file. Thumbnails are new files; the honest thing is to carry the XMP and IPTC declaration, keep the manifest on the original, and record the signing tools in the library.<\/p><\/dd>\n<dt id=\"my%20image%20optimizer%20strips%20metadata.\"><h3>My image optimizer strips metadata.<\/h3><\/dt>\n<dd><p>Smush, EWWW, ShortPixel, Imagify, TinyPNG, Optimole and LiteSpeed all have a \"strip metadata\" option. Turn it off for the marking to survive, then re-scan the library. The settings screen lists the optimizers it detects.<\/p><\/dd>\n<dt id=\"can%20i%20style%20the%20badge%3F\"><h3>Can I style the badge?<\/h3><\/dt>\n<dd><p>Yes: text or your own icon, corner, diameter, background color, opacity, text color, minimum image width and tooltip are settings. For anything else the badge, popup and label carry CSS classes (<code>.ropemark-ai-badge<\/code>, <code>.ropemark-popup<\/code>, <code>.ropemark-label<\/code>) that you can restyle from your theme stylesheet or the Customizer. You can also turn the badge off and use the <code>data-ai-generated<\/code> attribute in your theme.<\/p><\/dd>\n<dt id=\"can%20i%20keep%20the%20badge%20off%20some%20ai%20images%3F\"><h3>Can I keep the badge off some AI images?<\/h3><\/dt>\n<dd><p>Yes. Every attachment has a \"visible badge\" choice: follow the settings, always show, never show. Bulk actions set it on many images at once.<\/p><\/dd>\n<dt id=\"what%20if%20a%20file%20has%20no%20marking%20at%20all%3F\"><h3>What if a file has no marking at all?<\/h3><\/dt>\n<dd><p>Classify it by hand in the attachment details or with a bulk action. The plugin writes the IPTC digital source type into the generated sizes and, unless the original carries a C2PA manifest, into the original too. Files with generator traces are listed as \"Suspected AI, to confirm\" so you find them first.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20webp%20and%20png%20sizes%3F\"><h3>Does it work with WebP and PNG sizes?<\/h3><\/dt>\n<dd><p>Yes. XMP is written as an <code>iTXt<\/code> chunk in PNG and as an <code>XMP<\/code> chunk in WebP (creating the VP8X header when the encoder did not). IPTC IIM exists only in JPEG.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20down%20uploads%3F\"><h3>Does it slow down uploads?<\/h3><\/dt>\n<dd><p>Marginally: one read and one write per generated size, copying bytes. Nothing is re-encoded. On a large library use \"Scan in background\" (Action Scheduler when present, WP-Cron otherwise) or WP-CLI: <code>wp ropemark scan<\/code> processes tens of images per second in one process.<\/p><\/dd>\n<dt id=\"how%20does%20it%20behave%20on%20a%20large%20library%3F\"><h3>How does it behave on a large library?<\/h3><\/dt>\n<dd><p>Filters and counters use flat flags, not the serialized record, so the Media Library stays fast at tens of thousands of images. Scans run in time-bounded batches and release memory as they go. Each derivative is read once and written only when the marking is missing.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>First public release: IPTC\/XMP\/C2PA provenance reading, marking carried into JPEG, PNG and WebP sizes, manual classification per image and in bulk, generator traces as \"suspected AI\", AI badge with provenance popup, per-image badge choice, text label, site notice, shortcode and block, schema.org digitalSourceType, Media Library column, panel, filters and CSV export, foreground and background library scan, WP-CLI, REST.<\/li>\n<\/ul>","raw_excerpt":"Mark, keep and disclose AI-generated images: IPTC marking kept in every size, AI badge with provenance popup, Media Library audit. EU AI Act art. 50.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/366341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=366341"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/therope"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=366341"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=366341"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=366341"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=366341"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=366341"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=366341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}