On 2 August 2026, the transparency obligations for AI providers and deployers under Article 50 of the EU AI Act start to apply.
To help providers and deployers meet those obligations, the European Commission has published the Code of Practice on Transparency of AI-Generated Content (the Code), together with complementary Guidelines on the Transparency Obligations. The Code is voluntary - and, in any event, signing up to it does not by itself guarantee compliance with Article 50.
The scope of Article 50 is easily overstated: it does not impose a general obligation on every operator or user of a generative AI system to label all AI-generated content.
Instead, it sets out four distinct obligations - two for providers and two for deployers - each carrying its own mix of technical and legal complexity:
- Interactions with lifelike AI: providers must design their AI systems so that individuals are told when they are interacting with an AI, unless this is obvious from the circumstances.
- Marking and detection of synthetic content: providers must mark synthetic content so that it is detectable as artificially generated or manipulated.
- Emotion recognition and biometric categorisation: deployers of an emotion-recognition or biometric-categorisation system must inform the individuals exposed to it.
- Deepfakes and public-interest text: deployers who generate or manipulate deepfakes must disclose that fact, and the same obligation applies to AI-generated text published to inform the public on matters of public interest.
Timing
The recently adopted Digital Omnibus on AI sets different compliance dates for the Article 50(2) marking and detection obligations, depending on when a system was placed on the market:
- Already on the market before 2 August 2026: transition period until 2 December 2026.
- Placed on the market on or after 2 August 2026: obligations apply immediately.
Territorial Scope
Neither the EU AI Act nor the Code applies directly in the UK. However, UK (or other ROW) organisations that place AI systems on the EU market, or make them available to users in the EU, may still fall within scope.
Deployer obligations
We have summarised below the Code's key obligations and practical guidance for deployers.
- Deepfakes. Article 50 requires deployers to provide transparency notices when they deploy AI-generated or manipulated content - disclosing deepfake image, audio or video content, and AI-generated text published to inform the public on matters of public interest.
- Emotion recognition and biometric categorisation. Deployers of emotion-recognition and biometric-categorisation systems must also inform individuals that such systems are in use.
- Labelling. The Code provides guidance on making disclosure Article 50-compliant. Signatory deployers commit to:
- Using clear, easily identifiable disclosures - standardised visual labels (such as an "AI" icon) or, where visual disclosure isn't possible, plain-language audio disclaimers
- Presenting disclosures prominently at the point of first exposure, embedded within the content where possible, and repeated at appropriate intervals in audio and video
- Text on matters of public interest. The Code also addresses the exemption for AI-generated text that has undergone meaningful human review. Regulated media organisations can generally rely on their existing editorial standards and processes. Other deployers must put human review and editorial control in place before publication, and designate a person or organisation with editorial responsibility for the content.
Provider obligations
Article 50(2) requires providers to mark synthetic audio, image, video or text outputs in a detectable, machine-readable format. The obligation falls on providers, but the technical measures they adopt will have practical knock-on effects for deployers too.
No single, off-the-shelf solution meets every Article 50(2) requirement - effectiveness, interoperability, robustness and reliability all at once. Signatories must therefore combine multiple techniques for both marking and detection, with two exceptions: free-form text, and certain closed-system applications.
Marking
In practice, this means:
- Digitally signing metadata to record that content has been AI-generated or manipulated
- Embedding watermarking that is difficult to separate from the content
- Adopting alternative techniques, where providers can show these achieve an equivalent or higher level of effectiveness, interoperability, robustness and reliability
Detection
In parallel, signatories must provide the means to detect machine-readable markings. In particular:
- Results must be presented clearly, distinguishably and accessibly
- Detection results should include information about the marking technique used, together with any information available from the mark itself
- Detection may take the form of a publicly available specification, software, or cloud-based services accessible through an API
Access and cost
Providers must ensure the detection solution is:
- Available to users at all times and free of charge - except where a provider has fewer than 100,000 monthly users and the solution incurs substantial operational costs, in which case a reasonable fee may be charged
- Accessible to the relevant audience and compliant with applicable EU privacy and data protection requirements
Providers may rely on third-party marking and detection solutions, provided they remain able to demonstrate that the techniques used satisfy the requirements.
Example in practice
A useful illustration of how GPAI model providers are approaching compliance with the marking and detection requirements comes from OpenAI, which has formally endorsed the Code (see blog post) and is using the C2PA content credentials standard for metadata, combined with Google DeepMind's SynthID technology for watermarking, alongside a public tool for verifying content.
Integrity of markings
The Code also seeks to preserve the integrity of AI markings. Signatories commit to:
- Use best efforts to preserve metadata markings and refrain from intentionally removing existing ones
- Include contractual restrictions - in their terms of use or acceptable use policies - prohibiting deployers and other third parties from removing or tampering with those markings
- Not place on the market, promote or advertise tools whose purpose is to circumvent machine-readable markings
Importantly, though, the Code makes clear that providers are not responsible for third-party compliance with those obligations.
Optional measures
Beyond these minimum requirements, the Code encourages providers to add optional transparency measures, such as provenance information in metadata, functionality allowing deployers to apply perceptible labels to AI-generated or manipulated content, and other supplementary measures such as fingerprinting, logging or forensic detection mechanisms.
Governance and accountability
The Code places significant emphasis on governance and accountability. Signatories commit to:
- Maintaining appropriate internal compliance processes
- Promoting AI awareness and literacy among relevant personnel
- Cooperating with regulators through review and feedback mechanisms
The Code also acknowledges that marking and detection technologies are still evolving, and that the current state of the art may not always meet every transparency objective.
Compliance is therefore treated as an ongoing, iterative process - signatories must assess, test, verify and monitor the effectiveness of their transparency measures, both before placing systems on the market and throughout their lifecycle.

/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2025-09-29-13-48-10-128-68da8e1af6347a2c4b96de4e.png)
/Passle/5f3d6e345354880e28b1fb63/SearchServiceImages/2026-07-30-11-35-40-160-6a6b370c7f6e92629d6bd205.jpg)
/Passle/5f3d6e345354880e28b1fb63/SearchServiceImages/2026-07-30-09-58-02-499-6a6b202a084549892d338aab.jpg)
/Passle/5f3d6e345354880e28b1fb63/SearchServiceImages/2026-07-29-16-53-34-954-6a6a300ec76f2a1ae04064bc.jpg)