European Union flags outside an EU institutional building in Brussels

EU AI Act Article 50 Disclosure Guide

September 21, 2026 · 12 min read · By Thomas A. Anderson

On August 2, 2026, the transparency obligations in Article 50 of the EU AI Act became enforceable across all 27 member states. For the first time in a major jurisdiction, a company that fails to tell users they are talking to a chatbot, or fails to mark AI-generated content, faces fines of up to €15 million or 3% of global annual turnover, whichever is higher. The European Commission published its final Guidelines on July 20, 2026, thirteen days before enforcement began, and the Code of Practice on Transparency of AI-Generated Content followed a multi-stakeholder drafting process that ran from November 2025 to June 2026. For any team that generates images, video, audio, or text and serves EU users, the question is no longer whether to disclose, but what minimum implementation actually satisfies the regulator.

Key Takeaways:

  • Article 50 sets four separate obligations (chatbot disclosure, machine-readable marking, deepfake labeling, emotion/biometric notification), each with a different responsible party.
  • The Code of Practice requires at least two marking layers at once because no single technique meets all four criteria of being effective, interoperable, solid, and reliable.
  • C2PA signed metadata alone is strippable by a single screenshot, so the Code pairs it with an imperceptible watermark; for free-form text, watermarking alone is sufficient.
  • Systems on the EU market before August 2, 2026 get a marking grace period to December 2, 2026; new systems must comply immediately.
  • Signing the Code provides a presumption of conformity, and about 190 organizations had signed by the end of July 2026.

What Article 50 Actually Requires

Article 50 contains four distinct transparency obligations, and the most common compliance error is treating them as one. The same company can be a “provider” for one product and a “deployer” for another, and the obligations differ sharply. The Commission’s Guidelines on transparency obligations clarify which party carries which burden.

The first obligation, under Article 50(1), applies to providers of AI systems designed to interact directly with people. Chatbots, voice assistants, and AI agents must inform users they are interacting with AI at the first point of contact, unless it is obvious to a reasonably well-informed person. The Guidelines confirm that AI agents fall within this scope and must also identify the person on whose behalf they act.

The second, under Article 50(2), requires the most technical effort. Providers of generative AI systems must embed machine-readable markings in AI-generated audio, images, video, and text so the output is detectable as artificially generated. This is the marking requirement, and it received a targeted deferral under the Digital Omnibus: systems already on the EU market before August 2, 2026 have until December 2, 2026 to comply, while systems launched on or after August 2 must comply immediately.

The third obligation, under Article 50(4), applies to deployers. Anyone publishing AI-generated or manipulated content depicting real or realistic people, objects, places, or events must visibly disclose that it is a deepfake. The fourth, under Article 50(3), requires deployers to inform people when they are exposed to emotion recognition or biometric categorization systems.

European Union flags outside an EU institutional building in Brussels
Enforcement sits with national market surveillance authorities in each member state, coordinated by the AI Office in Brussels.

Penalties are set out in the Act and repeated in the Commission’s Quick Facts page: fines up to €15 million or 3% of total worldwide annual turnover for companies, up to €750,000 for EU institutions, with proportionality applied for SMEs and micro-enterprises. Enforcement is carried out by national market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor when EU institutions are involved.

The Detectability Question: Is C2PA Enough?

The short answer is no. C2PA Content Credentials alone do not satisfy Article 50(2), and the reason is written into the Code of Practice itself.

The Act requires that machine-readable markings be effective, interoperable, solid, and reliable, four criteria that must be met simultaneously. The Code, published June 10, 2026, acknowledges that no single marking technique currently satisfies all four at once. C2PA metadata is cryptographically signed and interoperable, but it is removed when content is screenshotted, uploaded to a platform that rewrites files, or converted to another format. An imperceptible watermark embedded in pixels or tokens survives recompression but weakens under cropping and adversarial manipulation.

The result is a mandated multi-layer approach. Under the Code, providers must implement at least two active layers of machine-readable marking at the same time: signed metadata following an open standard such as C2PA, plus an imperceptible watermark. For free-form text, watermarking alone is sufficient, because text cannot carry metadata the way an image or video file can. Legal firm Clayton Utz described this structure in its analysis of the rules now in force, noting that providers must implement two layers of machine-readable marking as the baseline.

The verification side differs between the two layers. C2PA credentials are verified with open-source tooling such as libc2pa, maintained by the Content Authenticity Initiative. The imperceptible watermark is verified through a detection API such as Google’s SynthID. A visible label or disclaimer does not fulfill the marking requirement, because Article 50(2) specifically requires automated detection without human interpretation.

The Commission’s Guidelines add a point small teams often miss: technical feasibility under Article 50(2) is an objective notion, not dependent on an individual provider’s resources. A startup cannot claim exemption on cost grounds. Providers who choose not to sign the Code must show compliance through alternative, equivalently adequate means, assessed individually by different market surveillance authorities.

Minimum Implementation by Modality

For a product team shipping an image, video, or text generator in 2026, the minimum compliance path is now clear. The table matches each modality to the two required layers and the verification tool, based on the Code of Practice and the vendor implementations described in the research.

Modality Layer 1 (signed metadata) Layer 2 (imperceptible mark) Verification
Images C2PA manifest (ISO/IEC 22144) SynthID pixel watermark libc2pa + SynthID detection API
Video C2PA manifest SynthID (Veo) or Video Seal libc2pa + SynthID detection API
Text Signed metadata where applicable SynthID-Text token watermark SynthID-Text detection API
Audio C2PA manifest SynthID (Lyria) or AudioSeal SynthID detection API

Text is the weakest part of this system, and product teams should plan accordingly. SynthID-Text works by biasing token selection so a detector can later identify the pattern, but paraphrasing through a second model erases the statistical signal. Anthropic’s watermark travels with copied text and may survive some editing, but the company’s own limitations section is explicit that a detected mark indicates Claude may have processed content, not that Claude authored it. Independent researchers such as GPTZero’s Alex Cui have argued that text watermarks can be defeated by heavy paraphrasing.

The Code also carves out narrow exceptions worth knowing. Content under 200 tokens is exempt from marking requirements, and source code, ephemeral real-time content, machine-to-machine content, and closed B2B outputs sit outside marking scope. Critically, the Code bans “humanizer” tools: providers may not offer tools designed to remove AI markings from content.

The practical steps for a team building this in 2026 are straightforward. Sign the Code of Practice first; it shifts the evidentiary burden toward regulators and provides legal certainty across all member states. Then embed C2PA credentials at generation time using libc2pa or Content Authenticity Initiative libraries. Then add the imperceptible watermark, either by adopting SynthID through a partner model or integrating an open-source method. Finally, connect verification into your own upload and moderation pipeline so you can document, with logs, that a given piece of content was marked and that the mark remained.

Labeling UI and Visible Disclosure

The marking requirement under Article 50(2) concerns machine-readable detection. The labeling requirement under Article 50(4) concerns what a human sees, and the two are often confused. They are separate obligations with separate responsible parties, and the provider’s watermark does not cover the deployer’s labeling duty.

The Code of Practice introduced standardized icons for labeling AI-generated content. The Commission created three optional icons, tested with 1,016 respondents across France and Romania: a basic “AI” badge, an “AI GENERATED” badge for fully synthetic content, and an “AI MODIFIED” badge for human content altered by AI. The key finding from that testing is that the “AI” acronym paired with a text label consistently outperformed icon-only designs in comprehension, trust, and reliability.

The placement rules differ by modality. Labels must be clearly perceivable at time of first exposure. Persistent on-screen labels apply to video, visible markings to images, and audible disclaimers to audio. The Commission is explicit that the icons do not establish legal compliance by themselves; they must accompany plain-language disclosure such as “This image was created with AI.”

Two exemptions matter for real products. Personal content like group chats is exempt, as are “evidently artistic,” satirical, and fictional works, where disclosure is limited to a manner that does not hamper display or enjoyment. Content generated before August 2, 2026 does not have to be labeled retroactively, though the Commission encourages voluntary labeling of older material.

The evidence requirement is the part most teams under-invest in. A working notice is not enough; teams need logged proof that disclosure appeared in a specific customer’s actual interaction, not just that it exists somewhere in the product. A vendor’s claim that its platform “supports AI Act compliance” does not relieve the deployer’s obligation to verify disclosure appears correctly in its own customer journey.

The Four Exemptions

Article 50 contains four exemptions that narrow its reach, and understanding them prevents over-labeling and under-labeling alike.

The first is the artistic and satirical deepfake exemption. Where content is “evidently artistic, creative, satirical, fictional or analogous,” the transparency obligation is limited to disclosing the existence of generated content in an appropriate manner that does not hamper the work’s display or enjoyment.

The second is the publisher exemption for text. The obligation to disclose AI-generated text on matters of public interest does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. This is the safe harbor for businesses that draft with AI but maintain a human review step.

The third is the standard editing exemption. Systems that perform only assistive functions for standard editing, or that do not substantially alter input data or its semantics, fall outside the Article 50(2) marking obligation. The Guidelines cite grammar correction and minor stylistic changes as examples.

The fourth is the obviousness exemption for interactive AI. Providers must inform users they are interacting with AI unless it is obvious from the point of view of a reasonably well-informed, observant person, taking into account circumstances and context of use.

Each exemption carries ambiguity. “Evidently artistic” is subjective, “substantially alters” is undefined, and “obvious” depends on context. The Commission’s Guidelines narrow these but do not eliminate the gray areas, which is why most firms err toward labeling when in doubt.

The Enforcement Gap

The rules are in force, but enforcement has been slow to start. Five weeks after August 2, 2026, the ledger of enforcement actions under Article 50 remained at zero, according to a Forkast analysis. This is not a signal that the rules lack teeth; it reflects structural constraints.

The AI Office operates with roughly 125 staff, and 12 EU member states missed the deadline for appointing competent authorities, with 19 yet to appoint single points of contact. When enforcement capacity is this thin, regulators gravitate toward simpler cases rather than the technical work of auditing marking and detection systems.

The consequence for product teams is a window, not a pass. The obligation exists now, the fines are real, and the gap between the legal requirement and the enforcement capacity is a matter of months, not years. Teams that sign the Code and implement the two-layer marking now will be ahead of the enforcement curve when authorities begin issuing fines.

Limitations and Trade-offs

The realistic view on Article 50 compliance in 2026 is that it sets a minimum standard, not a maximum, and the minimum has known gaps. Independent practitioners have documented where the two-layer approach fails.

The screenshot attack is the cheapest and most common. A single screenshot removes both C2PA metadata and any visible watermark, defeating metadata-based detection in about two seconds. The same crop-and-recompress vulnerability persists: Reuters’ July 2026 test found Meta’s Muse Image detector missed 55% of its own cropped images, a gap Meta itself had flagged in its 2024 threat model, as covered in our analysis of Meta’s watermarking risks.

Unsecured open-source models create a permanent pool of unmarked content. Stability AI has not integrated SynthID into Stable Diffusion, and Meta’s Llama models do not embed SynthID-Text by default. Any provenance strategy relying solely on watermarking inherits that coverage gap, because older unmarked models remain available and keep producing unmarked output.

There is also a subtle integrity risk most pipelines miss. A content asset can carry a cryptographically valid C2PA manifest asserting human authorship while its pixels simultaneously carry a watermark identifying it as AI-generated, with both signals passing their checks independently. Any verification process that checks C2PA and watermarking separately, without comparing results, is vulnerable to this contradiction. We explored this in our guide to verifying AI model outputs.

The regulation does not require that marking survive every attack. Compliance and security are related but not the same. A platform that deploys C2PA plus SynthID detection complies with Article 50(2). It is not protected from all attacks. The distinction matters because regulators will ask about compliance, but users will ask about trust, and trust breaks when an attacker succeeds. For a broader view of how these technologies fit within the 2026 regulatory environment, see our guide to AI watermarking and provenance and our earlier breakdown of Article 50 disclosure.

For security and platform engineers, the practical advice is to design defenses against the attacks you can block, not those you cannot. The screenshotter and metadata remover can be stopped with C2PA plus watermarking. The regenerator, who passes AI output through their own model, defeats all current defenses at once. Multiple pieces of evidence, verified provenance, checked embedded marks, and a retained “inconclusive” category is the production standard, and no negative result can prove content came from a camera.

More in-depth coverage from this blog on closely related topics:

Sources and References

Sources cited while researching and writing this article:

Thomas A. Anderson

Mass-produced in late 2022, upgraded frequently. Has opinions about Kubernetes that he formed in roughly 0.3 seconds. Occasionally flops, but don't we all? The One with AI can dodge the bullets easily; it's like one ring to rule them all... sort of...