Skip to content
Assay Layer
Menu

EU AI Act

AI Act Article 50: who must label AI content, by when, and how

Article 50 is the transparency article of the EU AI Act. It puts one obligation on the companies that build generative systems and a narrower one on the organisations that publish their output. This page sets out both, the dates, the penalties, and a checklist for the second group.

Updated

Built for the EU

  • EU AI Act Article 50 ready
  • Hosted in Frankfurt, Germany
  • GDPR: inputs not stored

No official EU certification scheme for Article 50 tooling exists yet, so nobody can be certified against it — us included. Ready here means the pipeline produces the evidence the obligation asks for: a layered check, and an export carrying the input hash, the pipeline version and a UTC timestamp. It is not an approval, an endorsement, or a certificate.

The obligation

What Article 50 actually requires

Article 50 sits in the transparency chapter of Regulation (EU) 2024/1689 — the AI Act. It splits its duties between two roles, and most confusion about it comes from mixing them up.

Providers — the organisations that build and place a generative AI system on the market — must ensure that synthetic audio, image, video and text output is marked in a machine-readable format and detectable as artificially generated or manipulated. The marking has to be effective, interoperable, robust and reliable as far as is technically feasible. In practice this is the watermarking and content-credential work the large model vendors have been doing since 2024.

Deployers — the organisations that use such a system — carry a narrower duty. Where an AI system generates or manipulates image, audio or video content that constitutes a deep fake, the deployer must disclose that the content is artificially generated or manipulated. Where the system generates or manipulates text that is published with the purpose of informing the public on matters of public interest, the deployer must disclose that too.

That text obligation carries an exception worth reading twice: it does not apply where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. An edited, bylined article is treated differently from an unreviewed automated feed.

Article 50 also covers the two cases people forget: systems that interact directly with people must make clear that the person is dealing with an AI, and deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Disclosure has to arrive at the first interaction or exposure, in an accessible form.

Who owes what, in one table.
Role Obligation under Article 50
Provider of a generative system Mark synthetic output in a machine-readable, detectable format
Deployer publishing a deep fake Disclose that the content is artificially generated or manipulated
Deployer publishing AI text on matters of public interest Disclose, unless there was human review and someone holds editorial responsibility
Deployer of a chat-style system Make clear the person is interacting with an AI system
Deployer of emotion recognition or biometric categorisation Inform the people exposed

Dates and penalties

What applies, and from when

Applies since 2 August 2026

The transparency obligations in Article 50 became applicable on 2 August 2026. They are live now, not on a future horizon.

Grace until 2 December 2026

Under the Digital Omnibus, systems already placed on the market before 2 August 2026 have until 2 December 2026 to come into line. If your stack predates August, that is the date in your calendar, and it is close.

Up to 15 million euro, or 3 per cent

Infringements of Article 50 attract administrative fines of up to 15 million euro or 3 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. Enforcement sits with national market surveillance authorities.

The fine ceiling is the headline, but it is rarely the operative risk for a publisher. The operative risk is being asked, by a regulator or by a counterparty, to show how you decided that a given piece of content did or did not need a label — and having nothing written down.

Guidance

The Code of Practice on marking and labelling

The Code of Practice on marking and labelling AI-generated content was finalised on 10 June 2026. It is the practical companion to Article 50: it describes how the marking obligation can be met and what a reasonable deployer-side check looks like.

Its central recommendation is that no single technique is sufficient. It describes a layered stack:

  • a watermark embedded in the output at generation time,
  • metadata travelling with the file, such as a C2PA manifest,
  • and a fingerprint or detection step for the cases where the first two are missing or have been stripped.

That stack is not a coincidence — it is the only arrangement that degrades gracefully. A watermark survives copy-paste but only exists if the generating vendor implemented one. Metadata is rich and verifiable but is removed by almost every screenshot, re-encode and copy-paste. Detection works on anything but is inference rather than proof.

Checklist

Five things a deployer should be able to show

Work down this list. Each row is something you should be able to produce on request, with a date on it.

Step What it means in practice How Assay Layer helps
1. Inventory inbound content Know which content streams can contain AI-generated material at all: freelance copy, agency deliverables, user submissions, translations, agent output. Give each stream a reference on the assay and filter your history by it later.
2. Check provenance before publication Run a provenance check as a step in the workflow rather than as an investigation after a complaint. One API call per item, or the MCP tool inside the agent that handles the content.
3. Label where the obligation bites Decide, per stream, whether the deployer text obligation applies and whether the human review exception covers you. Then apply the label consistently. The report gives you the evidence for that decision; the labelling itself stays yours.
4. Keep an audit trail Retain, per item, what you checked, when, and what came back — in a form that still means something months later. JSON and PDF exports carry the SHA-256 of the input, the pipeline version and a UTC timestamp.
5. Review the policy on a schedule Detectors, watermarks and guidance all move. A policy written once and never revisited is a liability. Our detector changelog records every threshold and provider change against a pipeline version.

Standards and frameworks we map to

  • EU AI Act, Article 50
  • Code of Practice on marking and labelling, June 2026
  • cr C2PA / Content Credentials
  • GDPR

Mapped to, and aligned with. Not certified against, not approved by, not endorsed by any of them. Two of the four — the Code of Practice and C2PA — are technical guidance rather than schemes anyone can be certified under at all.

Steps 2 and 4 are where a tool helps and the rest is organisational work no vendor can do for you. Be suspicious of anyone who says otherwise. If you want the detail of what the check returns, the accuracy page has the thresholds and the evidence behind them, and the API reference has the exact response shape you would store.

Talk to us

Compliance conversations, not a checkout

The compliance tier exists because retention rules, data processing agreements and audit requirements differ enough between organisations that a pricing page cannot honestly cover them. It adds workspace-level input retention with an audit log, a signed DPA, and a conversation about your actual volume rather than a credit pack.

Tell us what you publish, roughly how much of it, and what your legal team has asked for. We will tell you plainly whether this product is the right shape for the problem — including when it is not.

Compliance enquiry

Four fields, straight to a person. No sequence, no demo booking widget.

This opens your mail client. You can also write to [email protected] directly.

Questions

Article 50, answered plainly

Does Article 50 mean every AI-generated sentence must carry a label?

No. The deployer-side text obligation is narrow: it applies to text published with the purpose of informing the public on matters of public interest, and it falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it. A newsroom that edits and stands behind a piece is in a different position from an automated feed that publishes unreviewed model output.

We only publish marketing copy. Are we in scope?

Probably not for the deployer text obligation, which is about informing the public on matters of public interest. That does not make provenance checking pointless — it makes it a quality and contract question rather than a regulatory one. Read the obligation, decide honestly, and write the decision down.

Can a detector satisfy Article 50 on its own?

No, and we will not claim it does. The marking obligation in Article 50 belongs to the provider of the generative system, and it is about marking output at the point of generation. Detection is what you do on the receiving end, when you cannot trust that marking happened. The Code of Practice treats them as complementary layers, not substitutes.