Magnolia and the EU AI Act
Last Modified: July 23, 2026
Magnolia AI Accelerator is a content management product that enables editorial teams to use AI assistance within their content workflows. Magnolia does not build, train, or operate its own AI models. Instead, it connects to third-party AI model providers, such as OpenAI, Anthropic, and AWS Bedrock models; through its AI Connector framework.
Magnolia does not rebrand these models as its own. When a user interacts with an AI capability inside Magnolia, the underlying model is provided by a third-party provider operating under its own regulatory obligations. Magnolia's role is to provide the integration layer: the tooling, controls, audit trail, and governance infrastructure that allows organisations to use these models responsibly within their content operations.
What Magnolia does
Magnolia takes responsibility for the following within its product:
Upcoming releases
Provenance and audit trail. Magnolia tracks AI-assisted content actions with a full audit log: what was changed, when, which model was invoked, and by which user. This record is retained and accessible to administrators for compliance review.
No use of customer data for model training. When customers use Magnolia on AWS infrastructure under a Pay-As-You-Go (PAYG) configuration, customer content is not shared with model providers for training purposes. Data does not leave the customer's selected AWS region.
With the upcoming major release, Magnolia aims to provide transparency measures that support and, where appropriate, exceed regulatory requirements. We want to bring transparency in the authoring interface. Wherever AI assistance is available or has been used to generate or modify content, Magnolia surfaces a clear indicator in the authoring UI. This includes field-level labelling of AI-assisted content changes, and the ability for administrators to require disclosure labels on published content.
Due diligence
Magnolia is an extensible platform. While Magnolia aims to provide built-in components and tooling to surface AI indicators in the authoring interface - such as field-level labels and icons marking AI-assisted or AI-powered content - the responsibility for implementing these correctly in a live environment rests with the implementation partner or customer.
Organisations deploying Magnolia are accountable for ensuring that AI use complies with applicable law and as clearly communicated to their editorial teams and end users, in line with their obligations under Article 50 of the EU AI Act.
What Magnolia does not do
Magnolia does not:
- Train or fine-tune AI models on customer content
- Present third-party AI models under Magnolia's own name or brand
Magnolia AI capabilities are not developed, marketed or intended for use as high-risk AI systems within the meaning of Article 6 of the EU AI Act, including the use cases listed in Annex III (e.g. employment and workers management, creditworthiness assessment, access to essential services) or as safety components of products covered by Annex I. Any assessment of whether a customer's deployment falls within a regulated use case remains the responsibility of the customer.
How Magnolia helps customers meet their obligations
Customers using Magnolia remain responsible for how they deploy AI-assisted content in their own products, services, public-facing web pages, materials, and other experiences. Magnolia provides the infrastructure to support that responsibility:
- Audit logs that can be exported and referenced in regulatory reporting
- Transparency controls that customers can configure to meet their own disclosure obligations
- Data sovereignty through AWS regional hosting, which supports GDPR and EU Data Residency requirements alongside AI Act obligations
Article 50 transparency obligations
Article 50 of the EU AI Act introduces transparency requirements for providers and deployers of certain AI systems, applicable from 2 August 2026. Magnolia supports compliance through:
- Machine-readable provenance metadata for AI-generated images and content, consistent with C2PA/IPTC standards (Article 50.2)
- Customer-configurable disclosure labels for AI-generated content on published pages (Article 50.4)
- Accessibility-compliant implementation of all disclosure mechanisms (Article 50.5)
This statement will be reviewed and updated as regulatory guidance develops. It is subject to legal review before publication.
Nothing in this statement should be interpreted as legal advice. Compliance with the EU AI Act and other applicable regulations depends on the customer's specific implementation, use case, and governance measures.