Skip to content

AI and GEO

AI-generated content: what Google allows and what the law requires

This guide is translated from the Spanish original. Quotations from Spanish laws are our own translation: the official text is the one published in the BOE or the DOGV.

You can publish AI-generated content on your company’s website. Google does not penalise it for how it was made; it does so when it adds nothing or is mass-produced to rank. And European law only requires you to label it in 2 cases, from 2 August 2026.

One of those cases disappears if a person reviews the text thoroughly and someone takes editorial responsibility. What does not change is who answers for what is published: you.

Below you will find what Google and the AI Act say, and the risks law firms and clinics run. At the end, a 9-step protocol and a table of uses with their verdict.

When something is our interpretation, we mark it as a cautious approach. When it is a working method of our own, as our approach. All sources were consulted on 2 October 2026.

Google does not penalise AI: it penalises content that adds nothing

Google said so in February 2023 and still says so: it rewards the quality of content, not how it is produced. Using AI gives no special advantage. And if you see it as “an inexpensive, easy way to game search engine rankings”, Google tells you not to use it.

The limit lies in its scaled content abuse policy. It is spam to generate lots of pages to manipulate rankings instead of helping, “no matter how it’s created”. Its examples include generating pages with AI without adding value and transforming other people’s content with synonyms or automatic translation.

Its guide on AI-generated content acknowledges that AI is useful for researching a topic and giving structure to original content. The English version, updated on 1 October 2026, adds a warning that the Spanish version does not yet include. Models do not retrieve facts: they predict a likely sequence of words, and that is why they can make up data.

That is why Google considers it essential to review everything generated by hand before publishing it. That includes titles, meta descriptions, structured data and image alt text.

The guidelines for its quality raters add nuance. Using AI does not, on its own, determine the effort or quality of a page. Paraphrasing can have value, for example when an expert explains a public policy in plain language (section 4.6.6).

But a page that is almost entirely copied or paraphrased, with no effort or contribution of its own, gets the lowest rating. Those raters do not decide rankings: Google uses their ratings to check whether its systems work.

The guide to generative AI features that Google published in May 2026 points the same way. What most influences your presence in AI Overviews and AI Mode is unique, useful content. Google asks you not to just repeat what is already on the internet “or could easily be produced by a generative AI model”.

We go into this in what GEO is and how it differs from SEO.

Who, how and why: Google’s 3 questions, applied to your website

Google suggests reviewing each piece of content with 3 questions in its helpful content guide. They help to make E-E-A-T concrete: experience, expertise, authoritativeness and trustworthiness. Of the 4, Google says trust is the most important.

Who created it. Google recommends accurate bylines where readers expect them, with information about the author.

The English version of that page, updated on 1 October 2026, goes further. Inventing author profiles with AI-generated photos, fake names or credentials that do not exist is deception, and a sign of a low-quality page.

How it was created. If automation generates a substantial part of the content, Google suggests disclosing it and explaining how and why it was used, when readers might wonder. According to Google’s 2023 blog post, giving AI an author byline is probably not the best way to explain it.

Why it exists. This is the most important question: content should be created mainly to help people. If you use AI with the main aim of manipulating rankings, you breach Google’s spam policies.

On topics that can affect people’s health, financial stability or safety, Google gives more weight to these signals. It calls them YMYL, and content from a law firm, a tax and accounting firm or a clinic usually falls into this group. Its English version specifies that, on these topics, raters look for highly accurate content consistent with expert consensus.

For those raters, generating lots of text with AI without human supervision or curation means little or no effort. In SEO for lawyers we apply E-E-A-T to a law firm’s pages.

The AI Act only requires you to label 2 types of content

Regulation (EU) 2024/1689, known as the AI Act, regulates transparency in its Article 50. It affects you as a “deployer”: anyone who uses an AI system under their authority in a professional activity (art. 3.4). An SME that drafts with ChatGPT or generates images for its website is one.

If you commission texts from an agency or a freelancer who works on your behalf and under your control, the deployer is still you. That is how the Commission sees it in its questions and answers.

Marking content in a machine-readable way is an obligation for providers, such as OpenAI or Google (art. 50.2). Article 50.4 is the one that applies to you, with 2 cases:

  1. Deepfakes. Image, audio or video content generated or manipulated with AI that resembles real people, objects, places or events and could pass for authentic. You must disclose that it is artificial (arts. 3.60 and 50.4).
  2. Texts of public interest. If you publish text generated or manipulated with AI to inform the public on matters of public interest, you must disclose it, unless it has undergone human review or editorial control and someone holds editorial responsibility for the publication.

The notice must be clear and distinguishable, at the latest at the time of first exposure, and accessible (art. 50.5). The Commission’s guidelines make clear that the technical mark added by the tool is not enough. You need a label that a person can see or hear without special tools.

It applies from 2 August 2026, and the digital omnibus did not change that

Article 50 applies from 2 August 2026, the general date of application of the Regulation (art. 113). The Commission makes clear in its questions and answers that content generated earlier does not need to be labelled retroactively, although it recommends doing so.

The AI “digital omnibus” is now law: Regulation (EU) 2026/1744, in force since 27 July 2026. As far as content is concerned, it changes 3 things, and none of them alters your obligation:

  • It gives providers until 2 December 2026 to mark content from systems placed on the market before 2 August (new art. 111.4). It is an extension for OpenAI or Google, not for whoever publishes the content.
  • It rewrites Article 50.7 on codes of practice. The Commission assesses whether following a code is enough to comply with paragraphs 2 and 4.
  • It softens AI literacy (art. 4). Companies must take measures to support it among their staff, without having to guarantee a specific level.

Article 50.4 and its date stay the same. What the omnibus does delay are the obligations for high-risk systems, until December 2027 and August 2028. They have nothing to do with writing website content.

Fines reach €15 million, and in Spain the law is still going through Parliament

Breaching Article 50 can cost up to €15 million or 3% of total worldwide annual turnover, whichever is higher (art. 99.4.g of the Regulation). For an SME, the lower of the 2 applies (art. 99.6). Each Member State sets its own penalty regime.

In Spain, the organic bill on AI designates the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) as the authority for Article 50 (art. 5.2.h). It also classifies failing to label a deepfake or a text of public interest as a serious infringement (art. 21.1.b). As of 2 October 2026 it is still in Congress, with the amendment period extended until 7 October.

A text is “of public interest” if it informs about justice, health or the economy

The Commission’s guidelines of 20 July 2026 set 3 conditions. The text must be published, aim to inform and deal with a matter of public interest. AESIA summarises them in Spanish.

Those matters include justice, public administration, public health and consumer safety. They also include any economic or financial development that may become the subject of public debate.

The examples in the guidelines help to show where a company website stands (point 131):

  • In: an article on a lifestyle website that compares the effect of several diets on a disease. So are a listed company’s investor reports.
  • Out: advertising copy and product descriptions, unless they make claims about, for example, health, consumer safety or sustainability. So is a consultant’s private advice to a client on how to comply with a regulation.

Cautious approach: treat your guides on regulations, tax deadlines, consumer rights or health as being of public interest. Let’s say a tax and accounting firm in Castellón explains a VAT change on its blog: that fits. Its service page for the self-employed is closer to advertising and would be out, as long as it makes no health, safety or sustainability claims. In a clinic, almost every treatment page talks about health: review it as if it were in.

The exception requires a thorough review and someone who answers for it

You do not have to label a text of public interest if you meet 2 conditions at the same time. The guidelines set them out in points 133 to 138:

  • Human review or editorial control. A person with knowledge and professional judgement on the subject examines the substance of the text. Checking the facts is the minimum.
  • Editorial responsibility. A natural or legal person takes ultimate legal responsibility for the publication. Their identity and contact details should be easy to find, for example in the website’s legal information.

Spell-checking, having a written editorial policy, an automated review or a superficial sign-off do not count as review. And if AI substantially changes the text after approval, the exception is lost.

Spain’s Information Society Services Law (LSSI) already requires those identity and contact details (art. 10). Check that your legal notice includes them in full.

If you prefer to label, there are 2 resources to help you: a voluntary Code of Practice, from June 2026, and free-to-use EU icons. The Commission deemed the code adequate on 8 July. Using the icons does not, on its own, prove that you comply.

Our approach: even if your review exempts you from the legal label, Google recommends explaining how the content was made when readers might wonder. A line at the bottom saying that you used AI, who reviewed it and when covers both.

Images: a realistic photo made with AI can be a deepfake

A generated image is a deepfake if it resembles something real and could pass for authentic. The guidelines give examples close to a company website (points 114 to 116):

  • Deepfake: a realistic avatar of the managing director congratulating the staff, or a product image that makes the product look different or better than it is.
  • Also a deepfake, according to the EU icons page: real photos of an empty flat with furniture added by AI.
  • Usually not a deepfake: correcting colour, removing a passer-by or changing a background for aesthetic purposes. It depends on whether it alters how the person perceives what is shown.

An obvious illustration or diagram fools nobody. An AI-generated “photo” of your team or your premises does.

Never use photos of clients or patients to generate content from them. The Spanish Data Protection Agency (AEPD) warns about this in its ten-point guide from January 2026: it may result in a data protection infringement or even a criminal offence.

Google recommends adding image metadata that indicates how the image was created. In e-commerce, Merchant Center requires the TrainedAlgorithmicMedia metadata on AI-generated images (Google’s guide).

In law firms and clinics, the risk starts with what you type into the tool

In a regulated sector, the risk does not start with what you publish. It starts with what you type into the tool.

Your clients’ data never needs to go in

To write a page for your website you do not need any real client data. The AEPD says so for anyone who uses AI at work: do not include confidential data about your organisation, your staff or your clients. If you want to set out a case, describe a fictitious one (ten-point guide “Be careful what you confide in AI” (Cuidado con lo que le confIAs)).

The General Data Protection Regulation (GDPR) points the same way. You can only process the data that is necessary (art. 5.1.c), and health data is a special category (art. 9.1). Anyone who processes data on your behalf must provide sufficient guarantees (art. 28.1).

The AEPD applies that discipline to itself. Its internal generative AI policy requires taking out enterprise plans, with clauses that prevent the data from being reused. And it requires results to be reviewed and validated by hand before they are used or published.

In the legal profession, professional secrecy also applies, and it covers all facts, data and documents learned in the course of practice (art. 22.1 of the General Statute of the Spanish Legal Profession (Estatuto General de la Abogacía)). The General Council of the Spanish Legal Profession and the Valencia Bar Association have published a White Paper on AI and the legal profession. It advises analysing the risks before using AI with personal data. And carrying out an impact assessment if the risk is high (art. 35 of the GDPR).

In a clinic, patients have the right to confidentiality of their health data (art. 7.1 of Law 41/2002 (Ley 41/2002)). The Code of Medical Ethics (Código de Deontología Médica) asks doctors to commit to the confidentiality of that data when they use AI (art. 82.3).

What you publish is signed by you, not by the tool

In 2026 the General Council of the Spanish Legal Profession approved Circular 3/2026 on generative AI. It considers it lawful to use AI for drafts, but only as an auxiliary function subject to human supervision.

Whoever signs takes responsibility for all the content, and a failure of the tool does not exempt them. Submitting a document with AI errors can be a serious infringement (art. 125.u of the General Statute).

The circular deals with legal documents and advice, not websites. Cautious approach: apply its 5 recommendations to your website and your articles. Know the tool, read the whole text, check it against external sources, use it only in areas you know well and record when and for what you used it.

If an agency publishes for you, the Code of Professional Conduct (Código Deontológico) makes you responsible for that advertising, unless proven otherwise (art. 7.3.c of the Code).

In medicine, publications on the internet must be rigorous and identify the author (art. 83.1 of the Code of Medical Ethics). And contributing to spreading false, unverified information that goes against scientific evidence is contrary to professional ethics (art. 81.5).

A figure or a promise made up by AI is also an advertising problem. You will find the limits for each profession in what a lawyer can advertise and what a clinic can say.

A page made with AI passes 9 checks before it is published

This is our approach to producing a page or a guide with AI without losing quality. Each step says what the tool does, what the person does and what is checked, with the law or guideline that justifies it.

Step What the AI does What the person does What is checked and where
1. Question and angle Groups real client questions and proposes an outline Chooses the question and decides what they can add that only they know: typical cases, data, judgement That you do not already have a page on the same thing and that it is not a city variant. Google: scaled content abuse
2. Sources Searches for and suggests candidate sources Opens each one and discards blogs and aggregators BOE, EUR-Lex, professional association or official documentation, in its current version and with the date consulted
3. Brief without data Nothing yet Writes the instructions with fictitious cases and no client data Tool on an enterprise plan and with data processor guarantees. GDPR, art. 28.1; AEPD
4. Draft Writes based on the chosen outline and sources Adds experience, examples and nuances Nothing: a draft is not published
5. Facts Lists the claims that need checking Checks each figure, article and date against its source That each link leads to the source and says the same as the text. Google: manual review
6. Substantive review Nothing Someone who knows the subject approves, changes or rejects the text Conditions for the art. 50.4 exception: guidelines, points 134 and 135
7. Sector rules Can flag promises, superlatives and testimonials Reviews the advertising and ethics rules of their profession Your code of professional conduct and your professional association (colegio)
8. Metadata and images Suggests title, meta description and alt text Corrects them and labels any deepfake Google asks for the same accuracy in metadata. AI Act, art. 50.4
9. Byline, date and log No changes after approval Signs with a real name, dates the review and records which tool was used and who reviewed it Person with editorial responsibility in the legal notice; guidelines, points 136 and 138; Circular 3/2026, recommendation 5

Steps 5 and 6 are what protect you with Google and under the law. If either one fails, the page is not published until it is corrected.

Let’s say a dental clinic in Valencia wants a guide on implants. The AI organises patients’ questions and writes a draft. The dentist corrects timeframes and risks, removes “guaranteed result” and signs with her membership number, without having pasted a medical record into any tool.

Yes, with care or no: 12 uses of AI on your website

This table sums up the verdict for each use. “With care” means it can be done if it goes through the protocol above.

Use Verdict Why Basis
Researching a topic and organising sources Yes Google considers AI useful for research and structure. You open each source Google, guide to AI content
Drafts of pages and articles Yes, with a substantive review Without human review, a text of public interest must carry a label AI Act, art. 50.4
Titles, meta descriptions and alt text Yes, reviewed Google asks for the same accuracy in them as in the text Google, English version
Translating into Valencian or English With care A translation reviewed by a person falls within the exception. Mass-translating other people’s content to generate pages that add nothing is spam Guidelines, examples in point 138; Google
Summaries of laws or court rulings With care Useful if an expert reviews them. AI can make up articles and dates Google’s raters, 4.6.6
Health, finance or legal content With care Google gives more weight to trust on YMYL topics, and your professional ethics apply all the same Google, helpful content
Obvious illustrations and diagrams Yes They do not pass for real, so they are not deepfakes AI Act, art. 3.60
Realistic photos of your team, your premises or your product No; if you use them, with a label They can be deepfakes and misleading advertising AI Act, art. 50.4; Unfair Competition Law (Ley de Competencia Desleal), art. 5
Images created from photos of clients or patients No They are personal data, and health data in a clinic AEPD; GDPR, art. 9
Generated or edited reviews No Adding or commissioning fake reviews, or distorting real ones, is a misleading practice Unfair Competition Law, art. 27.8; Google
Made-up testimonials No They are false endorsements. Google also treats invented author profiles as deception Unfair Competition Law, art. 27.8; Google, English version
Mass-generated FAQs or city pages No It is scaled content with no value. On top of that, Google stopped showing FAQs as a rich result on 7 May 2026 Google, spam policies; documentation changes

The reviews that do count are those from real clients. They must refer to services purchased or used in the previous 30 calendar days (art. 20.4 of the Consumer Protection Law (Ley de Consumidores)). Ask for them within that period, with the method in how to get Google reviews.

FAQs written for your clients are still useful. The problem is generating them by the hundred, or creating a page for each town with the same text.

What to do on Monday

  1. Take stock of the pages on your website made with AI and note who reviewed each one.
  2. Mark the ones that deal with health, law, tax or consumer matters. For those, document a substantive review and check that your legal notice identifies the person responsible.
  3. Review the authors: real names, verifiable credentials and no generated photos.
  4. Remove reviews and testimonials that are not from real clients. Label or replace realistic photos made with AI.
  5. Write a one-page policy: permitted tools, prohibited data and who reviews. The AEPD summary works as a model.
  6. Apply the 9-step protocol to the next piece you publish.
  7. If you are a lawyer, read Circular 3/2026; if you are a doctor, articles 81 to 83 of your code; if you are a dentist, the code of the General Council of Dentists (Consejo General de Dentistas). If you have a specific question, ask your professional association.

At NOR studio we use AI to research, organise and prepare drafts, and every text is worked on and reviewed by a person. We prepare the content with the relevant regulations to hand, and you (or your adviser) approve it before it is published. We explain this in SEO content and in how we write our guides.

Sources consulted (30)
  1. Google Search Central: Google Search’s guidance on using generative AI content (Spanish version, updated 31 December 2025)
  2. Google Search Central: Guidance on using generative AI content (English version, updated 1 October 2026)
  3. Google Search Central: Spam policies for Google web search, scaled content abuse
  4. Google Search Central: Creating helpful, reliable, people-first content (E-E-A-T and “who, how and why”)
  5. Google Search Central: Creating helpful, reliable, people-first content (English version, updated 1 October 2026)
  6. Google Search Central Blog: Google Search’s guidance about AI-generated content (8 February 2023)
  7. Google Search Central: Optimising your website for generative AI features in Google Search (updated 15 July 2026)
  8. Google: Search Quality Evaluator Guidelines (11 September 2025), sections 4.6.5 and 4.6.6
  9. Google Search Central: Latest documentation updates (end of FAQ rich results, 7 May 2026; AI content guidance, 1 October 2026)
  10. Google Search Central: Review snippet structured data (fake or undisclosed incentivised reviews)
  11. BOE (Official Journal of the EU): Regulation (EU) 2024/1689 on Artificial Intelligence (arts. 3, 4, 50, 99 and 113)
  12. EUR-Lex: Regulation (EU) 2026/1744, Digital Omnibus on AI (Official Journal of the EU, 24 July 2026)
  13. European Commission: Guidelines on the transparency obligations under Article 50 of the AI Act, C(2026) 5054, 20 July 2026 (PDF, in English)
  14. European Commission: Questions and answers on the transparency obligations under Article 50
  15. European Commission: Code of Practice on transparency of AI-generated content (10 June 2026)
  16. European Commission: EU icons for labelling AI-generated content (updated 24 September 2026)
  17. AESIA: Frequently asked questions on the Commission’s transparency guidelines (Article 50)
  18. BOCG, Congress of Deputies: Organic Bill on the proper use and governance of artificial intelligence (12 June 2026), arts. 5 and 21
  19. Congress of Deputies: progress of bill 121/000096 (amendment period until 7 October 2026)
  20. BOE (Official Journal of the EU): Regulation (EU) 2016/679, General Data Protection Regulation (arts. 5, 9, 28 and 35)
  21. AEPD: “Cuidado con lo que le confIAs”, ten-point guide (27 January 2026)
  22. AEPD: Basic summary of obligations and recommendations for managing generative AI at the AEPD (January 2026)
  23. BOE: Royal Decree 135/2021, General Statute of the Spanish Legal Profession (art. 22)
  24. General Council of the Spanish Legal Profession: Code of Professional Conduct of the Spanish Legal Profession (arts. 5, 7 and 21)
  25. General Council of the Spanish Legal Profession: Interpretative Circular 3/2026, use of generative AI and the duty to verify
  26. General Council of the Spanish Legal Profession and Valencia Bar Association: White Paper on Artificial Intelligence and the Legal Profession (January 2026)
  27. BOE: Law 41/2002, basic law on patient autonomy (art. 7)
  28. CGCOM: Code of Medical Ethics 2022 (published by the Valencia Medical Association), arts. 81 to 83
  29. BOE: Law 3/1991 on Unfair Competition (arts. 5 and 27)
  30. BOE: Royal Legislative Decree 1/2007, General Law for the Protection of Consumers and Users (art. 20.4)

NOR studio team

We are a studio in Valencia and Castellón that designs websites and gets them ranking on Google and in AI search. We write about what we do with our clients and always cite the original source of each figure. About us · How we write our guides.

(FAQ)(Frequently asked questions)© 2026

Frequently asked questions

Short answers to the most common questions on this topic.

Does Google penalise AI-generated content?

Not for being made with AI. Google rewards the quality of content, not how it is produced, and using AI gives no special advantage. What it does consider spam is generating lots of pages with no value to manipulate rankings, however they are made.

Do I have to label the text on my website as “AI-generated”?

Only in one case: text published to inform the public on matters of public interest, such as public health, justice or consumer safety, that nobody has reviewed in depth. If a knowledgeable person reviews the substance and someone takes editorial responsibility, it is not necessary (art. 50.4 of the AI Act). According to the Commission’s guidelines, advertising and product descriptions are excluded, unless they make, for example, health, consumer safety or sustainability claims.

When does the labelling requirement start, and has the digital omnibus changed anything?

From 2 August 2026. Regulation (EU) 2026/1744, the digital omnibus on AI, did not change that date or your obligation to label. On labelling, it only gave AI providers until 2 December 2026 for the technical marking of systems already on the market. Content published before August does not have to be labelled retroactively.

What is the fine for not labelling AI-generated content?

The AI Act sets a maximum of €15 million or 3% of worldwide turnover, and for an SME the lower figure applies. In Spain, the bill that implements it classifies it as a serious infringement and puts AESIA in charge of supervision. As of 2 October 2026 it is still going through Congress.

Can I paste a client’s data into ChatGPT to draft a text?

For a text on your website you do not need to, and you should not. The Spanish Data Protection Agency (AEPD) advises against entering your clients’ data into AI tools and recommends using fictitious cases. If you are a lawyer, professional secrecy is also at stake. If you run a clinic, it is health data, which the GDPR protects as a special category.

Can I use AI-generated images on my company’s website?

Yes, if they do not mislead. An obvious illustration or diagram is not a problem. A realistic photo of your team, your premises or your product may be a deepfake and must carry a clear notice from the first time it is seen. And if it shows something as better than it is, it may be misleading advertising.

More guides

Shall we talk about your case?

Tell us what you do, where, and who you want to reach. We reply within 24 working hours with an honest first opinion, even if that opinion is that you do not need us.

Or email us at [email protected] or message us on WhatsApp.