Watermarks and Metadata: How to Actually Comply With the EU AI Act's Article 50 Transparency Rules

· Source: Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations, Artificial Intelligence & Machine Learning · Depth: Intermediate, long

Summary

The European Commission and European AI Office published the final Code of Practice on Transparency of AI-Generated Content on June 10, 2026, providing concrete guidance for complying with the EU AI Act's Article 50 transparency rules. Article 50, which becomes legally binding on August 2, 2026, mandates that providers of generative AI systems mark outputs in a "machine-readable format" and deployers label deepfakes "clearly." The Code, while voluntary, outlines two core marking mechanisms for providers: digitally signed metadata, often using C2PA standards, and imperceptible watermarking for durability. It also details deployer duties for visible labelling of deepfakes and public-interest text, including using standardized EU icons. A transitional period extends to December 2, 2026, for systems placed on the market before August 2, 2026. Non-compliance can result in administrative fines up to 15 million euros or 3% of total worldwide annual turnover.

Key takeaway

For Directors of AI/ML and AI Engineers deploying generative AI in the EU, you must immediately assess your systems against the EU AI Act's Article 50 and the new Code of Practice. Your teams should implement both signed metadata and imperceptible watermarking for provider systems, and design visible labels using EU icons for deployer obligations. Ensure your terms of service prohibit marking removal and track the December 2, 2026, transition for existing systems to avoid significant fines.

Key insights

The EU AI Act's Article 50 transparency rules are operationalized by a new Code of Practice endorsing specific marking and labelling mechanisms.

Principles

Method

Providers should implement digitally signed metadata (e.g., C2PA) and imperceptible watermarking, making detection tools freely available. Deployers must surface these markings visibly using EU icons.

In practice

Topics

Best for: Legal Professional, Director of AI/ML, AI Engineer

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Global Privacy Laws & Compliance Frameworks | ComplianceHub.Wiki.