Skip to content
Skip article header Engineering

AI Act Article 50

What Article 50 of the EU AI Act actually requires for marking AI-generated content, the two mandatory layers, the transitional date hidden in Article 111(4) and the failure modes the Code of Practice admits marking cannot survive.

Updated 12 min read 113 views
Skip key takeaways

Key takeaways: AI Act Article 50 content marking 5

What Article 50 requires for marking AI-generated content, the two mandatory layers, the transitional date hidden in Article 111(4) and where marking can be defeated.

  • Two layers, not one Digitally signed metadata and an imperceptible watermark are both mandatory under the Code of Practice, while fingerprinting or logging is only an optional third layer.
  • The transitional date is not in Article 50 The 2 December 2026 transitional deadline for legacy systems sits in the new Article 111(4), not inside Article 50 itself.
  • No named standard means no vendor gets default compliance The Code of Practice names zero specific marking techniques or standards, so no vendor's product can claim default compliance with Article 50.
  • Marking can be defeated, and the reference material says so Recompression, cropping and the analogue hole of print-and-scan or screen recording all defeat marking, and the Code admits no quantitative metric exists to measure robustness against them.
  • Grandfathering is narrower than it sounds Grandfathering under Article 111(4) covers only the Article 50(2) marking duty, so a hybrid system's Article 50(1) disclosure duty still starts on 2 August 2026.
See our AI integration services

In short: EU AI Act Article 50(2) requires providers to mark synthetic audio, image, video and text output as machine-readable and detectable, applying from 2 August 2026. A transitional deadline of 2 December 2026 covers systems already on the market, and that date sits in the new Article 111(4), not in Article 50 itself. The Code of Practice that operationalizes the duty requires at least two mandatory marking layers and names no single technique or standard for either one. Because the standards consortium behind the leading provenance-metadata format admits its own manifests can be stripped from an asset entirely, a compliant pipeline has to assume no single layer will survive and be designed around that admission.

What Article 50 actually requires, paragraph by paragraph

Paragraphs 1 to 6, unchanged by the Omnibus

Of Article 50's seven paragraphs, the Omnibus touched exactly one, and the statute already splits the rest by role: providers under paragraphs 1 and 2, deployers under paragraphs 3 and 4. The split matters later: the Code mirrors it exactly, Section 1 for providers under Article 50(2), Section 2 for deployers under Article 50(4).

Paragraph 7, amended by point (20): the Commission, not the AI Office, encourages the codes

Point (20) of the amending act replaces Article 50(7) in full. The encouraging party moves from the AI Office to the Commission, the word marking joins a list that previously read only "detection and labelling," and approval becomes an adequacy assessment: "The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article."

The compliance dates, and the trap in Article 111(4)

2 August 2026 - Article 50(2) applies

Article 50(2) carries no date inside its own text. It falls under the AI Act's general application date, which the amended Article 113, second paragraph still sets at 2 August 2026, and any provider placing a generative system on the market on or after that date owes the marking duty with no grace period.

2 December 2026 - the transitional period, added by point 39(b) to Article 111(4), not to Article 50

A reader who opens only Article 50 will not find a transitional period, because none is there. Point 39(b) of the amending act instead adds a new fourth paragraph to Article 111: "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026." The grace period is real, but it lives in a different article than most summaries check.

Three exceptions to Article 50(2), not two

Article 50(2)'s second sentence carries three carve-outs, though most summaries mention two: "This obligation shall not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof, or where authorised by law to detect, prevent, investigate or prosecute criminal offences." Assistive editing, no-substantial-alteration and law enforcement are three conditions joined by "or," each sufficient on its own.

A reference architecture for the marking duty

The Code of Practice translates Article 50(2)'s four adjectives, effective, interoperable, robust and reliable, into a stack of three layers, two of them mandatory. Its own modal-verb key states: "'will' is used for mandatory measures under the Code that need to be met for the Signatory to be compliant with Article 50(2) and (5) AI Act, and for which compliance will be monitored by competent market surveillance authorities," while "encouraged" and "may" mark measures that are "purely voluntary."

Layer 1, mandatory digitally signed metadata

Under Sub-measure 1.1.1, providers record whether content is AI-generated or manipulated in the file's metadata wherever the format supports it, then digitally sign and time-stamp that record "in a secure and tamper-evident manner."

Layer 2, mandatory imperceptible watermarking

Sub-measure 1.1.2 is also mandatory: providers must embed an imperceptible watermark, applied either after generation or during inference, with an exception only for very short text. The Code frames it as a complement, not a substitute: "The watermark is intended to serve as a robust mechanism to complement the digitally signed metadata under Sub-measure 1.1.1."

Optional layer, fingerprinting or logging

Sub-measure 1.1.3 adds fingerprinting or logging, marked "may" rather than "will." The Code is explicit that it cannot stand alone: "relying on fingerprinting or logging alone is not considered sufficient to meet the quality requirements specified in Article 50(2) AI Act."

The Code's own condition: no single technique can satisfy all four requirements alone

Two layers are mandatory rather than one for a stated reason: "So long as no single marking technique can, under the state of the art, ensure by itself compliance with the four requirements in Article 50(2) AI Act of effectiveness, interoperability, robustness, and reliability... Signatories will implement a multi-layered marking approach." A provider shipping only a watermark or only signed metadata falls short before anyone even asks whether either layer resists tampering.

What is carved out

Closed, embedded products

The two-layer floor drops to one layer "in specific cases where a generative AI system is embedded in physical products capable of generating synthetic outputs in a technically controlled and closed environment mainly instructive in nature," provided the product stops the output from leaving that environment, for example a single-purpose voice assistant that cannot save or forward its own audio.

Free-form text under the 200-token floor

Free-form text gets a single-layer allowance for a structural reason: "free-form text cannot transport metadata," so watermarking alone satisfies the requirement. Above 200 tokens, watermarking must still apply, though the Code concedes it "may have lower reliability compared to that of watermarking very long text," and allows providers to restrict detection access to verified expert users to offset that.

The interoperability solution due 2 February 2027

Measure 3.4 sets a deadline separate from the two already on the calendar: providers must implement "an interoperability solution for their detection mechanisms by 2 February 2027," choosing an industry-standard API, a public signpost, a shared consortium solution or another comparable route.

The central tension - a Code that names no standard, marking that can be removed

Zero mentions of C2PA, Content Credentials, SynthID, ISO/IEC or IETF (only the accessibility standards ETSI EN 301 549 and WCAG 2.1)

A string search across the final Code returns zero for every named technique a builder might expect: C2PA, Content Credentials, SynthID, ISO, ISO/IEC, IETF, IPTC, XMP, Exif, JPEG, CEN and CENELEC all return no hits. The Code names only generic classes: digitally signed metadata, imperceptible watermarking, fingerprinting and logging. It defers the standard itself: "At the time of publication of this Code, relevant interoperability standards and/or best practices are yet to be developed, except for digitally signed metadata." The only external standards named anywhere in the document are the accessibility standards in Section 2, "the harmonised standard ETSI EN 301 549" and "the W3C Web Content Accessibility Guidelines 2.1," governing presentation, not marking or detection.

C2PA's own Security Considerations v2.4: no protection against complete manifest removal

C2PA's own standards body, the Coalition for Content Provenance and Authenticity, a multi-stakeholder group building the leading metadata-provenance format rather than a vendor or a government body, states the limit of its own design directly: "C2PA does not offer any protection against the complete removal of C2PA manifests from assets." Its threat catalog spells out what that means: an attacker can strip a manifest from downloaded media and repost the asset, and "it is possible for an attacker to remove metadata as described." That gap is the same provenance question AI supply chain security pipelines already answer: a manifest that can be deleted is a claim, not a chain of custody.

The Code's answer: best efforts plus a terms-of-service prohibition, downstream compliance not guaranteed

Measure 1.2, Non-removal of markings, is the Code's response, and it is candid about the limit: signatories "will make best efforts to preserve metadata markings," while separately conceding they "recognise that downstream compliance and enforcement cannot be guaranteed." The control is contractual: a prohibition written into "the acceptable use policy, terms and conditions or the documentation accompanying" the system. None of that stops a determined actor; it narrows who is allowed to try.

Failure-mode table - what survives, what does not

Measure 3.3, Robustness, is the Code's own list of "typical processing operations" and "adversarial attacks" a marking-and-detection solution must withstand "to the extent technically feasible," a duty capped at what is currently possible, not a guarantee.

Attack or transformation Layer it defeats What the Code requires What a builder actually has to do
Recompression, filtering, noise addition or removal Watermark Robustness to typical processing operations, "to the extent technically feasible" Test watermark survival after your own re-encoding pipeline, not a single lossless copy
Screenshot and screencasting Metadata outright, watermark depending on technique Named among the in-place modifications requiring robustness Treat metadata as gone once content is re-rendered; the watermark carries this path alone
Homoglyph substitution Text watermark Named under in-place modifications Validate detection against character-swapped text specifically, not just paraphrase-level attacks
Lexical substitution Text watermark Named under in-place modifications Test against synonym-swapped variants; watermarks depend on the exact wording chosen
Cropping Image or video watermark, metadata Named under desynchronization mechanisms Do not rely on a single-region watermark; a crop removes it entirely
Mirroring Image or video watermark Named under desynchronization mechanisms Check detection against a horizontally flipped output, a one-line transform for an attacker
Paraphrasing Text watermark Named under desynchronization mechanisms Budget for this as an open problem, markedly harder than image or audio watermarking
Translation cycles Text watermark Named under desynchronization mechanisms Treat translated or round-tripped text as effectively unmarked and plan a fallback signal
The analogue hole: print-and-scan with OCR, audio playback and re-recording, screen camcording Every machine-readable layer at once Its own named category, "survival of the analogue hole" Accept that no technique crosses it; route this risk to forensic detection instead, itself optional

What the Code admits it cannot measure or cover

Two limits sit right next to Measure 3.3. Robustness itself has a stated exception: "This requirement does not apply to AI systems that are exceptionally subject only to one layer of metadata marking as specified in Measure 1.1," so the single-layer carve-outs above owe no robustness duty at all. The neighboring Effectiveness measure, 3.1, admits it cannot be scored either: "There is no quantitative evaluation metric linked to this Measure; instead, it requires a user-based assessment of the detection functionality."

Hybrid and interactive systems - what the Guidelines actually say

Grandfathering applies only to 50(2); 50(1) is owed from 2 August 2026 regardless

The Commission's Guidelines on transparency of AI-generated content, dated on their own cover page "Brussels, 20.7.2026" and numbered C(2026) 5054 final, confirm the Article 111(4) transitional period without ever citing the article number, the string "111(4)" appears zero times in the document. What they add is narrower for one category of system: "Systems that are partly interactive and partly generative may benefit from this transitional period only with regard to the marking obligation under Article 50(2) AI Act, while compliance with the disclosure obligation for AI systems directly interacting with natural persons must be ensured as of 2 August 2026." A chatbot that also generates images gets the grace period only for the images.

Content generated before 2 August 2026 needs no retroactive marking

The Guidelines close a separate question directly: outputs "which have been generated or manipulated before 2 August 2026 do not need to be marked or labelled retroactively." It also narrows provenance depth going forward: "providers are not required to record or keep a full provenance chain," and draws a line vendor pitches often blur: a mark invisible at the point of interaction can satisfy Article 50(2) even though it cannot satisfy the separate Article 50(1) and (5) disclosure duty.

The three EU icons and the audio-only alternative

Section 2 of the Code ships three ready-made icons: one to disclose fully AI-generated content, a second for AI-manipulated or partially modified content, and "a third basic icon... to enable deployers to supplement it with an interactive layer with further information or an alternative textual label." All three are "publicly available for Signatories to use... without the need for attribution to the Commission or the AI Office."

Where a visual icon cannot appear, audio-only content being the clear case, the Code substitutes a spoken disclosure: "a short audible disclaimer in plain and simple natural language... disclosing the artificial origin of the audio deep fake in a perceivable manner," placed at the start of the clip. Signatories may also use an earcon as an interim alternative ahead of a common EU-wide audio solution still in development.

How Pharos Production builds Article 50-compliant marking pipelines

A marking pipeline that only labels content after it is generated has already missed Article 50(2): the metadata has to be signed and the watermark applied inside the same generation step that produces the audio, image, video or text, not attached afterward by a separate service.

Our AI integration services team wires that signing and watermarking into the generation path itself, tested against the failure modes above, then hands the resulting controls to our AI governance practice to document and monitor alongside the rest of EU AI Act compliance and the AI governance framework.

Sources: Regulation (EU) 2024/1689 (the EU AI Act), Article 50, via EUR-Lex; Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), points (20) and (39), via EUR-Lex, ELI data.europa.eu/eli/reg/2026/1744/oj; the European Commission's Code of Practice on transparency of AI-generated content and its Guidelines on transparency of AI-generated content; and the Coalition for Content Provenance and Authenticity's Security Considerations, version 2.4. This article is engineering guidance, not legal advice. Confirm every date and technique claim against the primary text with qualified counsel before you rely on it.

FAQ

Last updated: Reviewed by: Dmytro Nasyrov (Founder and CTO)

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    Article 50 requires providers to mark synthetic audio, image, video and text output as machine-readable and detectable under Article 50(2), while deployers face separate disclosure duties under Article 50(3) and (4) instead. The Code of Practice that operationalizes the provider duty sets a two-layer floor under Sub-measures 1.1.1 and 1.1.2: mandatory digitally signed metadata plus a mandatory imperceptible watermark.

    A third layer, fingerprinting or logging under Sub-measure 1.1.3, is optional and cannot substitute for the two mandatory ones.

  • Copy link Copies a direct link to this answer to your clipboard.

    The Article 50(2) marking obligation starts on 2 August 2026, the general application date the AI Act sets under Article 113, second paragraph. Systems already placed on the market before that date get a transitional period to 2 December 2026 instead, added by the new Article 111(4).

    That transitional article, not Article 50 itself, is where the grace period actually lives, which is why a reader who checks only Article 50 will miss it.

  • Copy link Copies a direct link to this answer to your clipboard.

    No single marking technique satisfies Article 50 on its own, because the Code of Practice names none. A search of the final Code returns zero mentions of C2PA, Content Credentials, SynthID, ISO/IEC or IETF standards, and its only named external standards cover accessibility, not marking.

    What the Code requires instead, under Sub-measures 1.1.1 and 1.1.2, is a two-layer combination of signed metadata plus an imperceptible watermark, since Measure 1.1 states that no single technique can meet all four required qualities of effectiveness, interoperability, robustness and reliability alone.

  • Copy link Copies a direct link to this answer to your clipboard.

    Yes, watermarking and metadata marking can both be removed or defeated. The Coalition for Content Provenance and Authenticity states in its own Security Considerations, version 2.4, that C2PA offers no protection against complete removal of its manifests from an asset.

    Measure 3.3 of the Code of Practice lists further failure modes including recompression, cropping, mirroring, paraphrasing and the analogue hole of print-and-scan or screen recording, and admits no quantitative evaluation metric exists for measuring robustness against them.

  • Copy link Copies a direct link to this answer to your clipboard.

    No, Article 50 does not apply retroactively. The Commission's Guidelines on transparency of AI-generated content confirm that content generated or manipulated before 2 August 2026 does not need to be marked or labeled after the fact.

    Systems already on the market before that date instead get the separate Article 111(4) transitional period, running to 2 December 2026, for their ongoing marking duty going forward.

  • Copy link Copies a direct link to this answer to your clipboard.

    Yes, Article 50(2) carries three exceptions rather than the two most summaries mention: an assistive editing function, output that does not substantially alter the input data or its meaning and content used under legal authorization to detect, prevent, investigate or prosecute crime. The Code of Practice adds further carve-outs on top of the statute, including closed embedded products in a controlled environment and free-form text under a 200-token floor.

    A separate interoperability solution for detection mechanisms is due by 2 February 2027 under Measure 3.4, a Code deadline rather than a statutory exemption.

  • Copy link Copies a direct link to this answer to your clipboard.

    Section 2 of the Code of Practice ships three ready-made icons: one for fully AI-generated content, one for AI-manipulated content and a basic third icon that deployers can pair with their own explanatory text. All three are free to use without any attribution to the Commission or the AI Office.

    Where a visual icon cannot appear, such as audio-only content, the Code substitutes a short spoken disclaimer at the start of the clip, with an earcon allowed as an interim alternative.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day