AI Watermarking & Content Marking Under the EU AI Act
From 2 August 2026, the EU AI Act requires providers of AI systems that generate synthetic audio, image, video or text to mark their outputs as artificially generated — in a machine-readable format. This is Article 50(2), the Act's answer to a web filling up with synthetic content. This guide covers who is caught, the transition period for systems already on the market, and the practical approaches — provenance metadata, watermarking and visible labels — that actually satisfy the duty.
Who Article 50(2) covers
The duty falls on providers of AI systems — including general-purpose ones — that generate synthetic audio, image, video or text content. That is deliberately broad: image generators, video tools, voice-cloning and text-to-speech products, and text-generation features are all in scope. The output must be marked so that it is detectable as artificially generated or manipulated.
The standard the Act sets is that technical solutions must be effective, interoperable, robust and reliable as far as technically feasible — taking into account the specifics of content types, implementation costs and the state of the art. It is a proportionate standard, not a demand for unbreakable marking; but "we did nothing" clears no bar at all.
Deployers have a related duty for deepfakes under Art. 50(4): content depicting real people, places or events must be visibly disclosed as artificially generated — a human-facing label on top of the machine-readable layer. Not sure which of these duties apply to you? Run the Article 50 readiness checker.
The dates: 2 August 2026, with a transition to 2 December 2026
Article 50 applies from 2 August 2026. For marking specifically there is one accommodation: providers whose generative systems were already placed on the market before that date have until 2 December 2026 to bring machine-readable marking into place.
Read the transition narrowly. It covers the Art. 50(2) marking mechanics only — it does not defer chatbot disclosure, deepfake labels or emotion-recognition notices, and it does not cover systems placed on the market after 2 August 2026, which must mark outputs from launch. Breaches sit in the €15M / 3% penalty tier of Article 99(4). For the full picture of what that date brings, see what changes on 2 August 2026.
Practical approaches that satisfy the duty
There are three complementary layers, and mature products typically ship at least the first two:
- Provenance metadata (C2PA / Content Credentials). The C2PA standard attaches a cryptographically signed manifest to media recording that it was AI-generated and by what tool. It is the closest thing to an industry default — supported by major model providers, camera makers and platforms — and directly answers the "machine-readable" and "interoperable" language of the Act. For images, video and audio, C2PA manifests should be your baseline.
- Invisible watermarking. Statistical watermarks embedded in the content itself (pixel-level for images, token-distribution for text, spectral for audio) survive the metadata stripping that happens on upload to many platforms. Watermarking complements provenance metadata precisely because it degrades differently: metadata is precise but strippable, watermarks are robust but probabilistic. Text is the hardest case — the Act's "as far as technically feasible" language acknowledges this — but documented use of state-of-the-art methods is what proportionate compliance looks like.
- Visible labels for deepfakes. Where content depicts real people, places or events, Art. 50(4) requires disclosure the viewer can actually see — an on-screen label, caption or audible notice. Metadata alone does not satisfy this; limited accommodations exist for evidently artistic and satirical works.
Whichever combination you use, document the design decision: which mechanism, why it is state-of-the-art for your content type, and how you tested robustness. That record is what you show an authority.
A compliance checklist for providers
- Inventory every generative surface — including embedded features (an email tool's "draft with AI" counts) and third-party models you expose under your own product.
- Pick your marking stack per content type — C2PA manifests for media, watermarking where available, and state-of-the-art methods for text.
- Check your dates — on the market before 2 August 2026 means marking by 2 December 2026; launching later means marking from day one.
- Handle deepfakes separately — add the visible-disclosure layer wherever real people, places or events are depicted.
- Test and document robustness — verify marks survive your export paths (compression, resizing, format conversion) and record the results.
- Fold it into your wider programme — marking is one duty among several. Check your Article 50 readiness, then classify your systems to see the full obligation set.
Frequently asked questions
Does Article 50(2) require visible labels on all AI-generated content?
No. Article 50(2) requires machine-readable marking — metadata or watermarks that software can detect. Visible disclosure is a separate duty under Art. 50(4) and applies specifically to deepfakes: content depicting real people, places or events. Many providers add visible "AI-generated" indicators anyway as good practice.
Is C2PA mandatory under the EU AI Act?
No specific standard is mandated. The Act requires solutions that are effective, interoperable, robust and reliable as far as technically feasible. C2PA provenance metadata is the most widely adopted way to meet that description for images, video and audio, which makes it a natural default — but the obligation is outcome-based, not standard-based.
How does the December 2026 transition work?
Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable marking. The transition covers only the Art. 50(2) marking duty — chatbot disclosure, deepfake labels and emotion-recognition notices are not deferred, and systems launched after 2 August 2026 must mark from day one.
What happens if AI content isn't marked?
Article 50 breaches carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher (lower of the two for SMEs), under Article 99(4). From 2 August 2026 these penalties are enforceable — the transparency layer is no longer a soft obligation.
Free, no sign-up. Deterministic — not a chatbot.
Still have questions about how this applies to you? Talk to us — we're happy to help.