European Union · Regulation (EU) 2024/1689

EU AI Act Article 50: who must mark, who must disclose, and what proves it

Applies from 2 August 2026. It was not delayed by the Digital Omnibus — but it was amended, and the enforcement structure changed underneath it. Four duties, split between the provider and the deployer.

Applies
2 Aug 2026Not deferred by the Digital Omnibus.
Penalty tier
€15m / 3%Whichever is higher. This is the Art. 50 tier, not the Act's ceiling — prohibited practices reach €35m or 7%.
Marking layers
TwoThe Code requires signed metadata and imperceptible watermarking. Neither alone suffices.
Harmonised standard
NoneArticle 50 sits outside the standardisation request. There is no presumption of conformity.

01The clock

Start here, because the single most common error about this article right now is that it moved. It did not. The Digital Omnibus deferred the high-risk obligations and left Article 50 alone — while quietly rewriting one of its paragraphs and adding a transitional nobody expected.

  1. The AI Act enters into force

    Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, with duties phased across four years.

  2. The Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 moves the Annex III high-risk obligations to 2 December 2027 and the Annex I ones to 2 August 2028. Article 50 appears nowhere in the deferral. It does replace Article 50(7) in full and insert a new transitional.

  3. Article 50 begins to apply

    All four transparency duties, for systems placed on the market from this date. California's SB 942 becomes operative the same day — the alignment was deliberate.

  4. The transitional closes

    Providers of systems generating synthetic audio, image, video or text that were already on the market before 2 August 2026 have until this date to comply with the Article 50(2) marking duty. The other duties bite on 2 August regardless.

  5. Detection interoperability deadline

    Under the Code of Practice, signatories must by this date route detection through a publicly available interoperable method, or signal in the content which detection solution to use.

One caveat on sources: as of this writing there is no consolidated text on EUR-Lex reflecting the amendment, and the Commission's own service desk still displays the superseded version of Article 50(7) behind a disclaimer. To read the current article you have to read the 2024 regulation together with the 2026 one.

02Who owes what

Article 50 is not one duty with four parts. It is four duties split across two different legal persons, and getting the allocation wrong is the most expensive mistake available here.

ParagraphBindsDuty
50(1)ProviderDesign interactive systems so people are informed they are dealing with an AI
50(2)ProviderMark synthetic audio, image, video and text in a machine-readable format, detectable as AI-generated
50(3)DeployerInform people exposed to emotion recognition or biometric categorisation
50(4)DeployerDisclose deep fakes; disclose AI-generated text published to inform the public on matters of public interest
50(5)BothClear and distinguishable, at the latest at first interaction or exposure

Three consequences follow that are easy to miss. An organisation that builds a generative tool and also publishes with it is both, and the obligations apply cumulatively — map them per system per use case, not per company. Light fine-tuning does not make you a provider; putting your own name on the system, substantially modifying it, or changing its intended purpose does. And a platform that merely distributes third-party AI content is not a deployer — it exercises no authority over the generating system, and applying a label does not make it one. It is encouraged to preserve upstream marks, not obliged to.

03The duties

50(1) · Tell people they are talking to a machine

Provider · unless it is obvious

Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed so that those persons are informed they are interacting with an AI system — unless this is obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and context of use.

Regulation (EU) 2024/1689, Art. 50(1)

The obviousness exception is to be read restrictively: the Commission's guidance is explicit that general public awareness that chatbots exist does not mean people recognise one in front of them. The benchmark flexes with the audience — children, older users and people with disabilities lower the expected level of circumspection; a specialist professional audience raises it.

50(2) · Mark the output, machine-readably

Provider · the duty most of this page is about

Providers of AI systems generating synthetic audio, image, video or text content shall ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions shall be effective, interoperable, robust and reliable as far as technically feasible, taking into account the specificities of content types, implementation costs and the generally acknowledged state of the art.

Regulation (EU) 2024/1689, Art. 50(2)

Text is on the face of the provision. Summaries claiming Article 50(2) omits text are simply wrong. Exceptions are narrow: systems performing an assistive function for standard editing, systems that do not substantially alter the input data or its semantics, and law enforcement.

And read "technically feasible" carefully, because it does not mean what defendants would like. The Commission's guidance states that technical feasibility is an objective notion that is not dependent on the specific resources and capabilities of individual providers. Cost may inform proportionality. Being small is not an exemption.

50(4) · Deep fakes, and text that informs the public

Deployer · two separate duties in one paragraph

Deployers of a system generating or manipulating image, audio or video constituting a deep fake shall disclose that the content has been artificially generated or manipulated. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is limited to disclosing its existence in a manner that does not hamper the display or enjoyment of the work.

Regulation (EU) 2024/1689, Art. 50(4), first subparagraph

The artistic carve-out is an attenuation, not an exemption — the guidance is explicit that such works are not excluded from the duty; only the manner of disclosure softens. "Evidently" is the gate, judged on format, context of presentation and audience expectation. Where content mixes categories, the informative character prevails. Every advertising example in the Commission's guidance is classified as requiring ordinary labelling, however avant-garde its styling.

Note also that intent to deceive is irrelevant to deep-fake status, and photorealism makes it more likely without being decisive.

The editorial carve-out — and the trap inside it

Art. 50(4), second subparagraph

The duty to disclose AI-generated text published to inform the public on matters of public interest does not apply where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication.

Regulation (EU) 2024/1689, Art. 50(4), second subparagraph

Both conditions are cumulative, and the review must be substantive — cursory sign-off without real engagement does not qualify. The identity and contact details of whoever holds editorial responsibility should be publicly available in an easily findable place.

Here is the trap, and it is the reason this duty belongs in an evidence discussion at all: any substantive AI intervention that happens after editorial sign-off voids the exception. Whether you are inside the carve-out therefore depends on the order and timing of two events — the editorial act, and any later machine edit. That is a question a sealed, ordered record answers and a document history does not.

One more thing clients get backwards: this carve-out disapplies 50(4) only. It does not switch off the provider's 50(2) marking duty. The same article can be machine-marked by its provider and carry no visible label from its publisher.

04Marking in practice

"Machine-readable" means marks structured so software can identify, recognise and extract them without human intervention. The Act names no technology; a recital lists watermarks, metadata identifications, cryptographic methods for proving provenance, logging methods and fingerprints as candidates.

There is no harmonised standard for Article 50, and none is coming. The standardisation request given to the European standards bodies covers the high-risk chapter only; Article 50 sits outside it entirely. The Commission's 51-page guidance on this article does not contain the phrase "harmonised standard" even once. So there is no presumption of conformity available here — a fact worth internalising before budgeting for one.

And no EU instrument names C2PA. Neither the Guidelines nor any of the three drafts of the Code of Practice mention C2PA or Content Credentials. A quantity of vendor content currently asserts that the Commission "points to C2PA as the reference implementation"; it does not, and the claim does not survive a full-text search of the official documents. C2PA is a credible way to discharge the signed-metadata layer. It is not a named safe harbour, and on its own it is not enough.

Marking is also not the whole duty. Outputs must be detectable, which means the means of detection must be available to the people exposed to the content and must produce human-readable results. Providers may implement marking anywhere in the value chain and may rely on an upstream model provider or a third-party solution — without displacing their own responsibility to demonstrate compliance.

Worth knowing what is not required: the guidance states that providers are not obliged to record or keep a full provenance chain of a content item's origin and modifications. The duty is to mark and to enable detection. What you choose to retain about your own compliance is a separate decision — and, as the next section shows, one the supervisory model makes for you in practice.

05The Code of Practice

The Code of Practice on Transparency of AI-generated Content was finalised on 10 June 2026, found adequate by Commission opinion on 8 July, and had roughly 190 signatories announced on 31 July — 83 to the provider section, 152 to the deployer section.

Be precise about what signing does. The Commission's opinion states that adherence to the code does not constitute conclusive evidence of compliance, and the amending regulation's recitals confirm that such codes do not grant a presumption of conformity. What signing buys is supervisory posture: for signatories, the Commission and market surveillance authorities will focus their activity on assessing whether the signatory has actually adhered to the code. Non-signatories are expected to demonstrate compliance by other adequate means, to run a gap analysis against the code, and may face more requests for information and access.

Read that supervisory sentence again, because it defines the evidence problem precisely. For a signatory, the question an authority asks is not "is your marking good?" but "did you do what you committed to, continuously, across the period?" That is a question about a record.

What the Code actually requires of providers is at least two layers of machine-readable marking, because no single technique currently satisfies all four statutory criteria:

  • Digitally signed metadata — mandatory. Recorded information must be digitally signed and time-stamped in a secure and tamper-evident manner, with controls over signing certificates and private keys.
  • Imperceptible watermarking — mandatory.
  • Fingerprinting or logging — optional, and expressly insufficient on its own.
  • Richer provenance information — explicitly optional.

Signatories also commit not to strip existing metadata markings from content they take as input, and to prohibit intentional removal in their acceptable-use terms. Single-layer marking is accepted for closed physical-product environments and for free-form text, which cannot carry metadata.

06Duty → receipt

This is where Planisphere enters, and not before. One event type per act, following Article 50's own split between the provider's marking and the deployer's disclosure — including the two acts that are pure judgement calls, the editorial act and the exemption.

ActEvent typeWhat is committed
Declaring what is in scope system_declared role output_classes marking_techniques counter_binding effective_from · commits scope_sha256
Output marked, 50(2) output_marked marking_techniques marking_payload_ids model model_version detection_check_result · commits content_sha256
Disclosure shown, 50(1) and 50(5) disclosure_rendered exposure_ref disclosed_at channel disclosure_version · commits disclosure_text_sha256
Deep fake or public-interest label, 50(4) label_published label_form label_placement · commits content_sha256
The editorial act claiming the carve-out editorial_review reviewed_at · commits content_sha256
An exemption relied on exemption_relied exemption_ground decided_at · commits rationale_sha256

Two of these deserve attention because they have no analogue in the other regimes on this site.

editorial_review commits the hash of the content as it stood when a human took responsibility for it. Since a substantive machine edit after that moment voids the carve-out, the pairing of a content commitment with a sealed timestamp is exactly the artefact that shows the later version is the reviewed version — or that it is not.

exemption_relied commits the rationale, hashed, at the moment the call was made. Every exception in Article 50 is self-asserted: obviousness, assistive editing, the artistic character of a work, editorial responsibility. Nobody grants them to you. The difference between a defensible position and an unfalsifiable one is whether the reasoning was recorded when relied on, or reconstructed afterwards.

Content never leaves your systems — commitments are hashes. Records are sealed on write: hash-chained, signed and periodically anchored, so an edit to an earlier record breaks the chain in a way a third party can detect without trusting either of us.

07The integration

One HTTPS call per act, from wherever the act happens. Nothing sits in your generation path.

# The editorial act that claims the Art. 50(4) carve-out, bound to the exact text. curl -X POST https://api.planisphere.ooo/v1/record \ -H "Authorization: Bearer $PLANISPHERE_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "pack": "eu-ai-act", "event_type": "editorial_review", "occurred_at": "2026-08-02T11:03:22Z", "system_id": "newsroom-cms", "source_payload": { "content_sha256": "a91d…" // the text as signed off. Never sent. }, "metadata": { "reviewed_at": "2026-08-02T11:03:10Z" } }'

If a later machine edit touches that article, its hash changes and the mismatch is visible. That is the whole mechanism — no policy engine, no attestation, just a commitment made at a moment that cannot be moved afterwards.

Marking records follow the same shape with output_marked, carrying the techniques used and the payload identifiers so a specific mark can be tied to a specific output. At volume you would batch these; batching changes the transport, not the evidence — each item remains its own record in its own place in the chain.

The full API reference covers authentication, idempotency, batching and rate limits; pricing is per record with a monthly free allowance.

08Who enforces it now

This is the part of the Omnibus that got the least coverage and may matter most. The amending regulation replaced Article 75(1) in full, and the change is structural.

The AI Office is now exclusively competent for supervision and enforcement in relation to AI systems built on general-purpose AI models where the model and system come from the same provider or undertaking, and AI systems that constitute or are integrated into a designated very large online platform or search engine.

Regulation (EU) 2024/1689, Art. 75(1), as replaced by Regulation (EU) 2026/1744

In plain terms: for the major frontier-lab assistants and image generators, and for AI built into the largest platforms, Article 50 is enforced centrally by the AI Office rather than by national market surveillance authorities. New provisions give it investigatory powers, a binding commitments procedure, and the ability to impose fines directly — including periodic penalty payments of up to 5% of average daily worldwide turnover, per day, to compel cooperation with an investigation or a corrective measure. The Court of Justice has unlimited jurisdiction to cancel, reduce or increase those fines.

For everyone else, enforcement runs through national market surveillance authorities, with the European Data Protection Supervisor covering EU institutions. Authorities may act on their own initiative or on a complaint — and any affected person, or anyone with grounds to consider there has been an infringement, may lodge one.

On penalties: an Article 50 breach sits in the tier at up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is not the Act's ceiling — prohibited practices reach €35,000,000 or 7% — and pages describing the 3% tier as the maximum are understating the Act elsewhere while overstating it here. For SMEs and small mid-caps the same figures apply, but whichever is lower. Where an authority sets a fine it weighs, among other things, the duration of the infringement and the degree of cooperation — and adherence to an adequate code of practice can be taken into account as mitigation.

09What Planisphere does not do

Stated plainly, because a vendor who is vague here will be vague in front of a regulator. Planisphere is an evidence layer. It sits beside your systems, never inside the act.

  • It does not mark or watermark outputs, write metadata, or provide a detection solution. Those are the duty itself, and they are yours.
  • It does not render disclosures to your users or apply labels to deep fakes.
  • It does not decide whether a work is evidently artistic, whether an interaction is obvious, or whether your editorial process is substantive enough to hold the carve-out. It records the ground you relied on and when — it does not endorse it.
  • It is not a notified body, does not issue CE conformity marking, and confers no presumption of conformity — which, for Article 50, does not exist for anyone.
  • It does not certify compliance or make a legal determination. No vendor can. A record is evidence a third party can check; it is not a finding that you complied.
  • It does seal the acts you performed, in order, at the moment you performed them — which is what a supervisory model built around "did you adhere to what you committed to" actually asks for.

10Questions

Our system launched last year. Do we have until December?
For the marking duty only. The new transitional gives providers of synthetic-content systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Everything else — the interaction disclosure, the deployer duties, the manner-and-timing rule — applies from 2 August. A system that is partly interactive and partly generative gets the extension for its marking and not for its disclosure.
Do we have to go back and mark everything we generated before?
No. There is no retroactive marking duty for outputs generated before 2 August 2026. But note one asymmetry in the guidance: text generated before that date and published on or after it does need to be labelled.
We signed the Code. Are we covered?
You are in a much better supervisory position and you have a mitigating factor available at the fining stage. You do not have a presumption of conformity, because none exists for this article, and the Commission has said adherence is not conclusive evidence of compliance. What signing does is change the question from "is your marking adequate?" to "did you adhere?" — which is a question about what you can show over a period.
Is C2PA enough?
No EU instrument names it, so there is no official answer. On the Code's own terms it addresses one of the two mandatory layers — digitally signed metadata — and the imperceptible watermarking layer is separately required. Note also that a stripped provenance manifest is silent rather than flagged, which is precisely why the Code does not accept metadata alone.
Does Article 50 apply to us from outside the EU?
It reaches providers and deployers whose output is used in the Union. The guidance narrows this at the edges — incidental, unforeseeable or unauthorised downstream use should not on its own trigger the obligations — but publishing to the open internet does not obviously fall on the safe side of that line.
How does this compare with California, which starts the same day?
Different shape entirely. California binds one class of duty holder, prescribes four data elements in the disclosure, requires a public detection tool, and runs a 96-hour licence revocation clock. Article 50 splits duties between provider and deployer, prescribes no data elements, and has no detection-tool duty. The California page walks through it.

11Sources

Every date, figure and quotation on this page was checked against the Official Journal text rather than a summary of it. Where the article is paraphrased, the citation points at the provision.

Start the evidence trail

The console opens on the EU pack with each Article 50 act listed — the marking, the disclosure, the label, the editorial act and the exemption — showing the exact call that seals each one. Sealing a record takes about a minute, and the first thousand each month are free.