BACK TO DIRECTORY

TransparAI: EU AI Act Compliance, AI Disclosure & AI Image Detection

by Patrick Schlesinger

0.0
(0 ratings)

TransparAI is the EU AI Act compliance plugin for WordPress that covers AI transparency and AI disclosure end to end: it detects AI-generated images in your media library, labels them with a visible AI badge, writes the machine-readable AI disclosure (the IPTC digital source type) into the image files, adds the note on AI-written text and the notice in front of a chatbot, and shows you where you stand with a readiness score, a self-assessment, an inventory of the AI systems on your site and a compliance report. Detection, labeling, structured data for SEO, audit trail, REST API and WP-CLI, all on your own server, without a single external request.

Who this plugin is for

Publishers and bloggers who use AI images or AI-assisted text. WooCommerce shops with AI product images or descriptions. Sites that run an AI chatbot. Agencies that maintain many client sites and need a documented, exportable and scriptable state per site. Anyone who has to answer “where do we use AI on this site” for management, a customer or a lawyer.

EU AI Act articles covered

Article 50, the transparency obligations, applies from 2 August 2026: visitors must be told when they talk to an AI system (50(1)), AI-generated content must carry a machine-readable marking (50(2)), and deepfakes as well as AI-written text on matters of public interest must be disclosed (50(4)). Which paragraph addresses you depends on whether you provide the AI system or deploy it; the plugin covers the technical side of all of them. Article 4, AI literacy, applies since 2 February 2025: providers and deployers take measures so that the people who work with AI systems have sufficient AI literacy, and the plugin’s checklist records what your organisation has done. The dashboard shows the whole timeline with the dates as adopted in Regulation (EU) 2024/1689.

Readiness score, self-assessment and compliance report

The TransparAI dashboard rates your compliance readiness from 0 to 100 with a traffic light: each check stands for a decision or an artefact the plugin can verify on its own, such as an AI level on your AI-written posts, a worked-through review queue, an answered chatbot question and an inventoried list of AI systems. A six-question self-assessment (chatbot, AI text, AI images, personalisation, translation, synthetic media) names the obligations likely to apply and the page that addresses each of them. The Article 4 checklist counts toward the score. Two widgets on the WordPress dashboard keep the score with its open checks and the key numbers in view. The score is a technical self-check of the plugin state and your own answers, not a legal assessment.

AI systems registry: which AI plugins run on your site

A list of known AI tools ships with the plugin and is matched against your installed plugins on your server, nothing is fetched. Chatbots an AI answers in are included, plugins the list does not know are suggested by their own description, and anything else (an external service, a script your theme calls) can be declared by hand. For every system you decide whether visitors are told about it; the notice appears as a line at the end of the page, a small badge or a dismissible banner and can be placed by block or shortcode too.

Automatic AI image detection

Most AI image generators leave traces in their files, and TransparAI reads all of the common ones: C2PA manifests (Content Credentials) from OpenAI (ChatGPT, DALL-E, GPT-Image), Adobe Firefly, Google Gemini including Nano Banana, and Bing Image Creator; the IPTC digital source type in XMP as written by Midjourney and a growing number of tools; generation parameters in PNG chunks from Stable Diffusion (AUTOMATIC1111), ComfyUI, NovelAI and InvokeAI; EXIF and XMP signatures of Flux, Leonardo.Ai, Ideogram, Recraft, Seedream and Photoshop Generative Fill; JPEG comment markers, C2PA in MP4 video and AI declarations in MP3 audio.

Detection parses the real file containers (JPEG segments, PNG chunks, RIFF, MP4 boxes, ID3 frames) and matches only inside metadata blocks, never with a blind text search over raw bytes, and never with guesses from image dimensions, file size or file names. Cameras from Leica, Sony and Nikon embed Content Credentials into real photos too, so a C2PA manifest alone never auto-labels anything here. Findings carry a confidence level: explicit AI declarations are labeled automatically, strong but informal signals land in a review queue where you confirm or dismiss them, single or in bulk, right in the media library. New uploads are checked on arrival, the existing library in a batched, pausable scan. Media generated by AI plugins on your own site (AI Engine, AI Power, Elementor AI, WordPress AI) is labeled at the source.

The visible AI label

A configurable AI badge marks labeled media in the front end: overlay or caption line, four positions, three sizes, dark, light, outline or icon-only, optional generator name, alt text note for screen readers and start date so older content is not badged retroactively. It renders server-side, so it survives page caching, and it works with the block editor, the classic editor, template images, widgets, Elementor free and Pro including Theme Builder, WPBakery Page Builder, Bricks Builder and WooCommerce, where the badge follows variation swaps and reappears inside the zoom and lightbox. A guard checks the real paint order and moves a badge that a theme overlay covers to a free corner or below the image. Per-image overrides and CSS utility classes give theme builders full control, markup a theme renders itself goes through the transparai_label_media filter, and an optional script also labels images printed without an attachment ID and CSS backgrounds. Page-cache plugins are told to refresh whenever a label changes.

Machine-readable AI labeling, structured data and SEO

For labeled files TransparAI writes the IPTC digital source type (trainedAlgorithmicMedia, or compositeWithTrainedAlgorithmicMedia for AI-edited media) as XMP into JPEG, PNG, WebP and AVIF, every size variant included. Google documents this field and can show an “AI-generated” label in Google Image Search, so the disclosure travels with the image wherever it is indexed. Each page additionally carries Schema.org JSON-LD structured data (ImageObject, VideoObject, AudioObject and an Article node for AI-written posts) with digitalSourceType both as the Schema.org enumeration and as the IPTC vocabulary URI, so search engines and AI crawlers get the declaration without opening a file. All of it is server-rendered with no extra request and no layout shift, so the SEO signals arrive without a Core Web Vitals cost. The same declarations serve GEO (generative engine optimization): AI search and answer engines such as Google AI Overviews, ChatGPT search and Perplexity weigh structured data and provenance signals when they decide what to cite. Existing metadata is merged, not replaced; unlabeling removes exactly what the plugin wrote; writes are atomic and validated. Because image optimizers and thumbnail regeneration strip metadata, every labeled file is fingerprinted and an hourly sweep restores missing declarations.

Camera photos and human work

Not every declaration says “AI”. Any media file can be declared as a camera photo (digitalCapture) or as human digital work (digitalCreation), from the attachment details, in bulk, or with WP-CLI. The declaration ends any AI label or pending detection, appears in the structured data, and is written into the file, but only where no other digital source type exists: a camera’s own declaration stays untouched. A “Human made” badge is optional and off by default.

AI-written text: disclosure levels per post

Every post, page and public custom post type carries an AI level for its text: no AI used, AI-assisted, AI-generated, or AI-generated and reviewed by a person. Set it in the block editor sidebar, the classic meta box, Quick Edit or Bulk Edit; the post list gets a sortable column and a filter, the AI Content screen sums it up per post type. AI levels show a configurable note ahead of the content, after it or on both sides, as a block, an inline note, a dismissible banner, a badge or a button that opens a dialog, plus an optional AI badge behind the post title. Five blocks (AI Notice, AI Image Label, AI Systems Notice, AI Systems List, Chatbot AI Notice) and the [transparai_notice] shortcode place every notice by hand; “only where a block or shortcode is placed” switches the automatic output off. Reviewed texts record the reviewer, the date and a fingerprint of the content, so a later edit shows as “changed since review”. The note can go into excerpts and RSS feed items, including a dc:description element and an optional [AI] prefix on feed titles.

Chatbot disclosure

Chatbot transparency is the Article 50 duty every visitor notices first: people must know when they talk to an AI system. TransparAI puts that notice into the first message of the bot for AI Engine, next to the chat launcher for every other widget, or as a line at the end of each page. Your answer decides whether it appears and who answers in the chat; the plugin recognizes more than 40 chat and chatbot vendors locally (plugins, theme snippets, registered scripts, your own browser as administrator) and tells you what it found, but never switches the notice on from a finding alone, because a live chat with a person behind it is not an AI system.

Audit trail, compliance report, REST API, WP-CLI

Every label, review decision, declaration and repair is recorded per file with time, previous state, trigger and the editor’s name, plus a site log of settings changes, scans, sweeps, bulk actions and declarations that the dashboard shows as recent activity. Export the whole library as a CSV audit list, or open the compliance report: a print view with the readiness score, the assessment answers, the Article 4 checklist, the AI systems in use, the state of every disclosure notice, the AI-written content, the media audit list and the recent activity, sealed with a document hash over the facts, the guidance basis and the stated limitations, ready for print-to-PDF. A REST API under transparai/v1 exposes rows, per-file detail, every action and the same report for headless setups and agency tooling; nothing in it is public. WP-CLI covers scanning, labeling, declaring, auditing, the score, the assessment, the AI systems inventory, the AI levels of posts and the report. Other plugins can label media through an action, detection rules and the AI systems list are extensible via filters, WPML and Polylang are configured, and uninstalling cleans up across a multisite network on request.

Privacy by design

The plugin runs entirely on your server: no accounts, no telemetry, no external requests, and the list of AI tools ships with the plugin instead of being fetched. The only HTTP request it can make is the optional delivery check, which asks your own site for one image to see whether your CDN strips the declaration. The interface is available in English, German, French, Spanish, Italian and Dutch. Please also read the Disclaimer section.

Contact: TransparAI@cms-admins.de

For developers

Everything below is stable API surface; hooks and options use the transparai_ prefix, meta keys _transparai_. Every shape and example lives in the GitHub README: https://github.com/cmsadmins/TransparAI

Meta: attachment keys _transparai_ai, _transparai_type, _transparai_source, _transparai_generator, _transparai_confidence, _transparai_detected, _transparai_human, _transparai_badge_pos, _transparai_history, _transparai_delivery (REST-exposed, upload_files); post keys _transparai_content_ai, _transparai_content_responsible, _transparai_content_review (edit_post). Options: transparai_settings, transparai_compliance, transparai_systems, transparai_log.

Hooks: do_action( 'transparai_mark_ai', $id, 'My Generator' ) labels media from your code, echo apply_filters( 'transparai_label_media', $html ) badges the AI images in markup your theme renders; filters transparai_signatures, transparai_detection_result, transparai_badge_html, transparai_badge_wrap_classes, transparai_notice_text, transparai_notice_html, transparai_chatbot_vendors, transparai_chatbot_notice, transparai_systems_registry, transparai_systems_notice.

Shortcode and blocks: [transparai_notice type="content|media|systems|chatbot" style="block|inline|banner|badge|modal" text="" id=""] and the five blocks (AI Notice, AI Image Label, AI Systems Notice, AI Systems List, Chatbot AI Notice) render only what is declared. REST (/wp-json/transparai/v1/, authenticated): GET /media, GET|POST /media/{id}, POST /media/{id}/scan, GET /report with document_hash, compliance and log. WP-CLI (wp transparai): scan, flag, unflag, human, status, score, content, assessment, systems, systems-declare, systems-undeclare, systems-visible, report, write-meta, verify-meta, verify-delivery. Theme control: container classes trai-badge-top-left to trai-badge-hidden and trai-badge-manual, stacking via --trai-badge-z.

External services

None. The plugin makes no request to any external service and never sends media or site data anywhere. The list of AI tools it matches installed plugins against is a file inside the plugin. The only HTTP request it can make is the optional delivery check, which fetches one image from your own site to see whether a CDN strips the declaration; it is off by default, runs only on click, and stops if the image is served from another host.

Privacy

TransparAI processes media files locally on your server and stores its results in the WordPress database (post meta and a few options). The per-file history records the user ID and display name of whoever labeled, confirmed, declared or dismissed a file (last fifty events), a site log keeps the last 200 administrative events, the self-assessment and the AI literacy checklist keep the name and date of the last save, and a post marked as reviewed stores the reviewer’s name and user ID, which is shown publicly only when you enable it. Everything is removed on uninstall with data removal enabled. The plugin collects, transmits and shares nothing and sets no cookies.

Disclaimer

TransparAI is a technical tool, not legal advice, and is provided “as is” without warranty of any kind, to the extent permitted by law (GNU GPL v2, sections 11 and 12). The author makes no representation that using it makes your site compliant with the EU AI Act, the Digital Services Act or any other law; legal obligations depend on your situation and remain your responsibility as the site operator. The readiness score and the self-assessment reflect your own answers and the checks this plugin can perform; they are not a legal assessment. Detection is based on metadata embedded by generators: stripped files carry no signals, and detected metadata is an indication, not proof. No function is guaranteed to run without error in every environment. You use this plugin at your own risk; to the extent permitted by law, the author accepts no liability for damages arising from its use.

Screenshots

Dashboard with the readiness score, the open check, the five steps in order and the counters

Dashboard with the readiness score, the open check, the five steps in order and the counters

Media library grid: AI badges, the badge for media declared as not AI and the AI status filter

Media library grid: AI badges, the badge for media declared as not AI and the AI status filter

Attachment details: label, detection evidence, the declaration in every file size and the raw XMP packet

Attachment details: label, detection evidence, the declaration in every file size and the raw XMP packet

Media list filtered to the review queue, with the AI column and the bulk actions

Media list filtered to the review queue, with the AI column and the bulk actions

Front end: title badge, the note above an AI-written text and the badge on a generated image

Front end: title badge, the note above an AI-written text and the badge on a generated image

Self-assessment: the six questions that decide which transparency duties apply

Self-assessment: the six questions that decide which transparency duties apply

The duties that follow from the answers, plus the Article 4 AI literacy checklist

The duties that follow from the answers, plus the Article 4 AI literacy checklist

AI systems in use: detected plugins, a suggestion to declare and the visibility for the visitor notice

AI systems in use: detected plugins, a suggestion to declare and the visibility for the visitor notice

Post list with the AI text column, the level filter and Quick Edit

Post list with the AI text column, the level filter and Quick Edit

Block editor: the TransparAI panel with level, responsible person and review stamp

Block editor: the TransparAI panel with level, responsible person and review stamp

Settings: badge look with a live preview, alt text, the not-AI badge and the page notice

Settings: badge look with a live preview, alt text, the not-AI badge and the page notice

Setup in three steps: scan the library, choose the badge, decide about the files

Setup in three steps: scan the library, choose the badge, decide about the files

Compliance report in print view with the document hash

Compliance report in print view with the document hash

The two dashboard widgets: readiness and numbers

The two dashboard widgets: readiness and numbers

AI images screen: library status, batched scan, audit export and the media lists

AI images screen: library status, batched scan, audit export and the media lists

EU AI Act timeline and the activity log that records every change

EU AI Act timeline and the activity log that records every change

Plugin Details

Active Installs
0
Total Downloads
331
Version
1.1.3
Requires WP
6.2
Requires PHP
7.4
Tested Up To
7.1
Added
2026-09-08
Last Updated
2026-09-17 5:48am GMT

Ratings

5
0
4
0
3
0
2
0
1
0