AI disclosure · EU · updated

Article 50(2): machine-readable marking of AI-generated content

Since 2 August 2026, providers of systems that generate images, audio, video or text must mark what they generate so that software can detect it. The AI Act says: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.” (AI Act, Art. 50(2), applies from 2 August 2026). Systems placed on the EU market before 2 August 2026 have until 2 December 2026, under Article 111(4) as added by Regulation (EU) 2026/1744.

The 2 December 2026 date, and who it covers

“Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.”
AI Act, Art. 111(4), added by Regulation (EU) 2026/1744, Art. 1, point (39)(b), applies from 27 July 2026 · Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 24 July 2026 · read 8 October 2026

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on the third day after, 27 July 2026. Its recital gives the reason:

“To allow sufficient time for providers of generative AI systems subject to the marking obligations laid down in Article 50(2) of Regulation (EU) 2024/1689 to adapt their practices within a reasonable time without disrupting the market, it is appropriate to introduce a transitional period of four months for providers who have already placed their systems on the market before the 2 August 2026.”
Regulation (EU) 2026/1744, recital (38) · Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 24 July 2026 · read 8 October 2026

The date covers Article 50(2) and providers only. Telling people they are talking to an AI (50(1)) and labelling deepfakes and public-interest text (50(4)) have applied since 2 August 2026. A system first placed on the market on or after 2 August 2026 had no transitional period. Does the 2 December deadline apply to you?

How good the marking has to be, and the exception

“Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards.”
AI Act, Art. 50(2), applies from 2 August 2026 · Regulation (EU) 2024/1689 (the AI Act), OJ L, 12 July 2024 · read 8 October 2026
“This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences.”
AI Act, Art. 50(2), applies from 2 August 2026 · Regulation (EU) 2024/1689 (the AI Act), OJ L, 12 July 2024 · read 8 October 2026

What the code of practice asks for: two layers

The code of practice published on 10 June 2026, which the Commission assessed as adequate on 8 July 2026, sets out how signatories mark:

“Signatories will implement a multi-layered marking approach to ensure that the outputs of their generative AI systems are marked with at least two layers of machine-readable marking, as specified in Sub-measures 1.1.1 and 1.1.2 below.”
Code of Practice, Section 1, Measure 1.1 · Code of Practice on Transparency of AI-generated Content, published 10 June 2026 · read 8 October 2026
“All recorded information will be digitally signed and time-stamped (on systems where time information is available) in a secure and tamper-evident manner.”
Code of Practice, Sub-measure 1.1.1 (digitally signed metadata) · Code of Practice on Transparency of AI-generated Content, published 10 June 2026 · read 8 October 2026
“Signatories will ensure that AI-generated or manipulated content is marked with an imperceptible watermark, with the exception of very short text.”
Code of Practice, Sub-measure 1.1.2 (imperceptible watermarking) · Code of Practice on Transparency of AI-generated Content, published 10 June 2026 · read 8 October 2026
“given that free-form text cannot transport metadata, a single-layer of marking as described in Sub-measure 1.1.2 is considered sufficient to comply with the requirements of Article 50(2) AI Act for this specific type of content.”
Code of Practice, Measure 1.1 · Code of Practice on Transparency of AI-generated Content, published 10 June 2026 · read 8 October 2026
“However, relying on fingerprinting or logging alone is not considered sufficient to meet the quality requirements specified in Article 50(2) AI Act and in Commitment 3.”
Code of Practice, Sub-measure 1.1.3 (fingerprinting or logging, optional) · Code of Practice on Transparency of AI-generated Content, published 10 June 2026 · read 8 October 2026

The code names no standard. The published standard for digitally signed provenance metadata in images, audio, video and documents is C2PA Content Credentials (C2PA specification 2.4, which also defines a c2pa.ai-disclosure assertion and a way to carry a manifest in plain text). IPTC's digital source type trainedAlgorithmicMedia says "Created using Generative AI" in a file's metadata, but on its own it is not signed. An imperceptible watermark can only be read with the generator's own detector.

Fines

“Non-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher: … (g) transparency obligations for providers and deployers pursuant to Article 50.”
AI Act, Art. 99(4) · Regulation (EU) 2024/1689 (the AI Act), OJ L, 12 July 2024 · read 8 October 2026

Check a file

$ npx --allow-git=root github:agentwares/agent-disclosure output generated.png

Reads the file on your machine (or fetches a URL once) and reports what marking it carries: a C2PA manifest in JPEG, PNG, WebP, GIF, TIFF, HEIF, AVIF, MP4, MOV, M4A, WAV, MP3, FLAC, Ogg, PDF, SVG, HTML, ZIP documents or plain text, with its generator, signer, actions and digital source type; IPTC and XMP AI fields; a watermark the manifest declares; and California's latent-disclosure fields. It reads manifests and does not validate their signatures; for that, use c2patool or contentcredentials.org/verify.

A signed readiness report

The free checks print everything they find. The Article 50 readiness report ($49, one-time, no account) is the same checks for up to 10 URLs and 25 artefacts, dated and hash-signed, as PDF and JSON, to keep or hand over.

Keep a dated record of every check, and of every disclosure and marking you ship

okgate keeps every tool call your agents make in a hash-chained audit log with daily Merkle roots on a public page: 90 days on Pro ($99/month), 365 days with a compliance export on Team ($299/month).

A record of your disclosure and marking checks, kept the same way, is not built yet. I want that record

The texts, each read on 8 October 2026