Europe's AI label is written for machines
Since August 2, generative systems covered by the AI Act must add a machine-readable mark to their outputs. The Commission concedes that no single technique does the job.

The August headline was short: Europe now requires AI content to be labelled. The central obligation, though, produces nothing you can see. Article 50 of the AI Act tells the provider to add a machine-readable mark to the system's output, and the Commission's definition is literal. A machine-readable format, the text says, means marks "structured in a way that allows software applications to easily identify, recognise and extract them without human intervention".¹ ⁶
What the law requires to exist is a signal aimed at software. The label that shows up on your screen is a separate obligation: it falls on a different party, and it applies only in some cases.
The rules took effect on August 2, 2026, alongside the rest of the package Europe only half switched on.² The guidelines explaining how to comply landed two weeks earlier, on July 20, as an annex to communication C(2026) 5054 final.¹ They run to 51 pages of definitions, and what they concede matters as much as what they demand.
Who owes what
Article 50 splits its duties between whoever supplies the system (the provider) and whoever puts it to professional use (the deployer). Most of the coverage collapsed all of it into a single rule.
| Obligation | Who complies | What appears | In force since |
|---|---|---|---|
| Tell people they're talking to an AI (art. 50(1)) | Provider | A notice the user can see | Aug. 2, 2026 |
| Mark synthetic content and make it detectable (art. 50(2)) | Provider | Nothing visible: a machine-format mark | Aug. 2, 2026, transition to Dec. 2, 2026 |
| Notify people exposed to emotion recognition or biometric categorisation (art. 50(3)) | Deployer | A notice to those exposed | Aug. 2, 2026 |
| Label deepfakes and public-interest text (art. 50(4)) | Deployer | A visible or audible label | Aug. 2, 2026 |
That December transition is narrower than it looks. It covers only the marking duty in Article 50(2), and only for generative systems placed on the market before August 2.³ A system that is part interactive and part generative gets the extra time for marking, but has had to disclose that it's a machine since August.¹ Content generated before August 2 needs no retroactive labelling either, though the Commission encourages it where possible.³
What "machine-readable" allows
The law picks no technology. The guidelines point back to recital 133, which lists watermarks, metadata identifications, cryptographic methods for proving provenance, logging, fingerprints and combinations of those.¹ A provider may use one technique or several, so long as the overall solution is machine-readable and satisfies four requirements the Commission defines this way:¹
- Effectiveness: the solution detects its own marks and lets people distinguish content the system produced.
- Reliability: it accurately identifies and distinguishes AI content under nominal conditions.
- Robustness: it holds that accuracy "under varying conditions, covering both common alterations and adversarial attacks".
- Interoperability: marking and detection solutions from different vendors work "across multiple systems, actors, contexts and technical implementations".
All four apply "insofar as this is technically feasible", weighing the limits of each content type, the cost of implementation and the generally acknowledged state of the art.¹ That clause isn't decorative. It carries everything that follows.
The requirement nobody fully meets
Marking is the easy half. Keeping the mark attached once the file starts moving is where the engineering breaks, and the failure modes are well documented.
Start with metadata. C2PA, the provenance standard much of the industry has adopted, attaches a signed manifest recording origin and edit history. It is verifiable and tamper-evident for as long as it stays with the file. Platforms that recompress, resize or convert formats routinely discard embedded metadata along the way. The ecosystem's own answer has a name: Durable Content Credentials, which keep a copy of the manifest in an online registry and embed a soft binding in the content, a watermark or a fingerprint, so the manifest can be found again after the metadata is gone.¹² That is recovery engineering built on the assumption that the strong link will be removed.
Which brings in the second layer, and the academic literature. In 2024, Zhang, Edelman and co-authors proved that strong watermarking is impossible under assumptions they describe as natural: an attacker holding a quality oracle, which judges whether an output is still good, and a perturbation oracle, which alters it without wrecking it, can scrub the mark. The result holds even when insertion and detection share a secret key the attacker never sees.⁹ That same year, Saberi and co-authors demonstrated the practical version for images. A diffusion purification attack strips low-perturbation watermarks with minimal changes, and spoofing attacks run the other way, marking real photographs so they get classified as synthetic.¹⁰
Text is the worst case. SynthID-Text, from Google DeepMind, is the largest text watermark deployment there is. ETH Zürich's SRI Lab probed it in December 2024 and found two things at once: it resists spoofing far better than earlier schemes, at 4% baseline attack success against more than 80% for red-green designs, and an off-the-shelf paraphrasing tool still removed the mark in over 90% of attempts on the scrubbing metric the authors use.¹¹
None of this is news to the regulator. The guidelines accept that the cost of some solutions "may be disproportionate to marginal gains" and carve out narrowly defined cases where less robust metadata marking suffices; the worked example is an AI system embedded in a vehicle navigation system, with measures preventing the output from leaving the product.¹ The Code of Practice that the Commission and the AI Board deemed adequate pushes providers toward stacking: signed metadata plus imperceptible watermarking, precisely because no single layer delivers all four requirements.⁷ ⁸ IPTC, which sets technical standards for the news industry, put the practical consequence plainly for anyone trying to verify content today: you have to check each system in turn.⁸
The date that closes the gap hasn't arrived. Signatories have until February 2, 2027 to stand up an interoperable watermark-detection solution, whether through a standardised API, a readable signpost embedded in the content indicating which detector to use, a shared detector run by a consortium, or an equivalent route.⁷ Until then, a machine-readable mark means a mark readable by the machine that put it there.
The part you actually see
The visible label comes from Article 50(4), and it belongs to the deployer rather than the provider. Anyone publishing a deepfake has to disclose it "at the latest at the time of first exposure", clearly and distinguishably, perceivable without any special tooling.³ And the guidelines close the obvious shortcut: a deployer may not simply point at the machine-readable mark the provider embedded and call the duty discharged.³ Two layers, two responsible parties.
Artistic, creative, satirical and fictional work gets its own treatment: disclosure still applies, but in a manner that doesn't spoil the experience. The final guidelines instruct authorities to read that exception strictly, and classify most advertising as subject to ordinary labelling.⁷
The passage that touches newsrooms is public-interest text. AI-generated text published to inform the public on a matter of public interest needs a label unless two cumulative conditions are met: it went through human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.¹ The guidelines read public interest broadly, covering what is "relevant to society at large" and merits debate or scrutiny, and they exclude superficial checks from the definition of review. Spell-checking and grammar fixes don't count.³ A site pumping out model output with nobody's name behind it has no exception. A newsroom with a responsible editor does.
The exits
The marking carve-outs are wider than the headline suggests. Out of scope: short sequences of numbers, symbols or letters; source code; machine-to-machine outputs no person ever sees; and closed industrial or business-to-business environments, subject to three cumulative conditions, namely that the output isn't meant to be shared externally, that the environment is controlled, and that safeguards against misuse exist.³ ⁷ Consumer-facing systems don't fit through that door.
Two exceptions come from Article 50 itself and deserve separate reading. The first is the assistive function for standard editing: preparing existing content for publication, small fixes to readability, grammar, quality and format, without generating new content.¹ The final guidelines placed machine translation in that category.⁷ The second covers law enforcement. A provider authorised by law to detect, prevent, investigate or prosecute criminal offences is exempt from telling anyone the system is an AI, and the example the document gives is blunt: an "AI-undercover agent".¹ A deployer publishing public-interest text without human review is likewise exempt where the activity is authorised by law.¹ "Authorised by law" includes national law adopted in compliance with Union law, and doesn't require the statute to name the specific system.¹
That is precisely the blind spot an analysis of the draft identified in May: the exemptions permit undisclosed chatbots, unlabelled deepfakes and emotion recognition against investigation targets, with little oversight.¹⁴ The final guidelines retained dedicated law-enforcement exceptions in both blocks, deepfakes and public-interest text.¹
Worth noting what doesn't get a pass: AI systems released under free and open-source licences sit outside the AI Act generally, yet remain subject to Article 50 when they fall within its scope.¹ Publishing weights doesn't excuse marking the output.
Where enforcement can fail
The penalty exists and sits in the familiar tier: up to €15 million or 3% of total worldwide annual turnover, whichever is higher; for SMEs, whichever is lower; up to €750,000 for the Union's own institutions and agencies.¹
Who collects is the murky part. Article 50 is enforced mainly by national market surveillance authorities, all 27 of them. The AI Office steps in only in two situations: when the system is built on a general-purpose model from the same provider, or when it's integrated into a very large online platform or search engine designated under the DSA.³ A rule about content that travels without borders ended up with an enforcement map cut along borders.
The Code of Practice is the shock absorber. Published on June 10 and found adequate by the Commission and the AI Board in July, it gives signatories predictability, and adherence can be weighed as a mitigating factor when a fine is set.⁴ ⁷ Anyone who declines has to demonstrate compliance by other adequate means and can expect more requests for information.³ On July 31 the Commission published the list: roughly 190 organisations, 82 in the provider section and 152 in the deployer section. The providers include Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; the deployers include Getty Images, Lenovo, Lufthansa and Bulgari. Around half of the signatories are small, recent companies.⁵
On territorial reach, the final guidelines went wider in one direction and narrower in another. Posting a deepfake on the globally accessible internet may trigger Article 50(4) if the content is "used in the EU", with no requirement that it be aimed at a European audience; at the same time, incidental, unforeseeable or unauthorised downstream use inside the EU shouldn't create obligations for a third-country provider.⁷ Lawyers have already named the uncomfortable corollary: for anyone determined to stay outside, the answer is geo-blocking.⁷
Then there's the question the law doesn't answer: does a label change behaviour? A survey of the labelling literature by Information Labs, published back in 2025, turned up an awkward result. AI-content labels have a much smaller effect than false-content labels, and small-scale studies find they shift what people believe about a piece of content's origin without meaningfully shifting likes, comments or shares.¹³ The authors' conclusion is that the binary logic of label-or-don't can't carry the weight on its own, without investment in media literacy.¹³
Brazil, which already labels AI, but only in an election year
Brazil has no general AI statute, yet it does have a labelling rule in force right now, and it is stricter than Europe's in one respect and much narrower in another.
On March 2, 2026, the electoral court approved Resolution 23.755, governing this year's elections. Any electoral advertising produced or materially altered by AI, whether text, audio, video or image, must state explicitly, prominently and accessibly that AI was used and which technology was applied. A missing label is itself an irregularity, even when nothing about the content is deceptive. Deepfakes that create, replace or alter a person's image or voice to help or harm a candidacy are banned outright, in any period. And there's a window in which new synthetic content can't be published or promoted at all: 72 hours before each round of voting and 24 hours after, labelled or not.¹⁵ ¹⁶
The contrast is instructive. The Brazilian court demands the label a person reads and ignores the mark a machine reads; Europe demands both, from different parties. Brazil enforces quickly, through content removal and joint liability for platforms; Europe enforces through fines, via 27 authorities. And Brazil's exception for adjustments that only improve image or sound quality, visual identity elements and customary campaign techniques, provided the content isn't substantially altered,¹⁵ is a sibling of Europe's assistive-standard-editing carve-out. Two independent regulators landed on the same cut-off.
The difference that matters is scope. The Brazilian rule covers electoral advertising, inside the campaign calendar. Once the election passes, synthetic content circulating in the country carries no labelling duty at all.
Verdict
Article 50 is the most concrete piece of the AI Act now in force, and the most candid about its own limits. The guidelines don't pretend the technology is ready: they write "insofar as this is technically feasible", define robustness to include adversarial attack, concede that cost can outrun benefit, and defer interoperability to February 2027. The Code of Practice recommends stacking metadata and watermarking precisely because no single layer holds.
What that architecture delivers is lopsided. For content nobody attacks, the image generated, posted and never touched again, marking works and provenance survives. For content someone wants to unmark, the literature has been clear since 2024: a pass through a paraphrasing tool or a diffusion step takes the mark off. The rule will meaningfully cut the volume of synthetic material circulating with no origin signal at all, and it won't stop anyone with a reason to remove one. Those are two different problems, and only the first has been addressed.
For anyone publishing with readers in Europe, the practical duty is already live, and it's the Article 50(4) one: a perceptible label on deepfakes at first exposure, and a label on model-generated public-interest text unless someone with genuine editorial responsibility read it, judged it and signed off. That part depends on no watermark, waits for no February 2027, and gets no December grace.
Sources
- Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (51 pages; machine-readable format defined at point 71; recital 133 techniques; effectiveness, reliability, robustness and interoperability defined at points 79-80; technical feasibility and state of the art at points 81-83; disproportionate cost and the vehicle navigation example at point 86; law-enforcement exception at points 46-48 and 139, with the AI-undercover-agent example; standard editing at point 90; human review and editorial responsibility at point 133; open-source systems within scope; penalties of €15 million, 3% and €750,000 at point 152; transitional period at point 153) · European Commission, C(2026) 5054 final, Brussels · https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems · 2026-07-20.
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August (start of application; duties for interactive systems to identify themselves, deepfake labelling and machine-readable marks) · European Commission · https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august · 2026-08.
Show 14 more sourcesHide sources
- Transparency obligations under Article 50 of the AI Act (official Q&A: provider and deployer definitions; exemptions for short sequences, source code, machine-to-machine outputs and B2B contexts; deepfake disclosure at first exposure at the latest, and the bar on relying solely on the provider's mark; public interest and the exclusion of superficial checks; grace period limited to art. 50(2) until 2026-12-02 and no retroactive labelling; division of competence between national authorities, the AI Office and the EDPS; consequences of adhering or not adhering to the Code of Practice) · European Commission · https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act · accessed 2026-08-18.
- Code of Practice on Transparency of AI-generated Content (final code published; two sections for providers and deployers; EU icon set available for labelling; voluntary adherence with compliance value) · European Commission · https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content · 2026-06-10.
- Strong backing for the Code of Practice on Transparency of AI-generated Content (around 190 signatories; 82 in the provider section and 152 in the deployer section; named companies; around half small and recent firms) · European Commission · https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content · 2026-07-31.
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems (consolidated article text, including the law-enforcement provisos and the artistic and satirical works clause) · EU Artificial Intelligence Act · https://artificialintelligenceact.eu/article/50/ · accessed 2026-08-18.
- Transparency obligations for AI-generated content: the Code of Practice adequacy decision and the final EU Commission Guidelines on Article 50 AI Act (adequacy decision by the Commission and the AI Board in July; 2027-02-02 deadline for an interoperable watermark-detection solution; layered marking with signed metadata and imperceptible watermarking; territorial reach for deepfakes posted on the global internet; incidental downstream use out of scope; strict reading of the creative exception and advertising subject to labelling; machine translation treated as standard editing; three cumulative conditions for the B2B carve-out; geo-blocking as a possible response; code adherence as a mitigating factor) · Reed Smith · https://www.reedsmith.com/our-insights/blogs/viewpoints/102nbz0/transparency-obligations-for-ai-generated-content-the-code-of-practice-adequacy/ · 2026-07.
- European AI Office releases Code of Practice on Transparency of AI-Generated Content (news-standards body's reading: no technical solution meets all four criteria; the present need to check each system in turn; February 2027 deadline for interoperable detection) · IPTC · https://iptc.org/news/eu-ai-transparency-code-of-practice-june-2026/ · 2026-06-10.
- Zhang, H.; Edelman, B. L. et al. Watermarks in the Sand: Impossibility of Strong Watermarking for Generative Models (impossibility of strong watermarking under quality-oracle and perturbation-oracle assumptions; result holds in the private-key detection setting; experiments on KGW, EXP, Unigram, Stable Signature and Invisible Watermark) · ICML 2024, arXiv:2311.04378 · https://arxiv.org/abs/2311.04378 · 2024.
- Saberi, M.; Sadasivan, V. S.; Rezaei, K. et al. Robustness of AI-Image Detectors: Fundamental Limits and Practical Attacks (diffusion purification attack against low-perturbation watermarks; model substitution adversarial attack against high-perturbation watermarking; spoofing attacks that mark real images) · arXiv:2310.00076 · https://arxiv.org/abs/2310.00076 · 2023-2024.
- Jovanović, N.; Gloaguen, T.; Vechev, M. Probing Google DeepMind's SynthID-Text Watermark (4% baseline spoofing success against more than 80% for red-green schemes; watermark removal above 90% with a baseline paraphrasing tool, on the authors' metric at a 1e-3 false-positive rate) · SRI Lab, ETH Zürich · https://www.sri.inf.ethz.ch/blog/probingsynthid · 2024-12-20.
- Durable Content Credentials (C2PA manifest combined with soft bindings, watermark and fingerprint, to recover provenance after platforms strip metadata) · Content Authenticity Initiative, open-source documentation · https://opensource.contentauthenticity.org/docs/durable-cr/ · accessed 2026-08-18.
- De Cock, C. Too Much, Too Little, Never Just Right? The Labelling Dilemma of Article 50 of the EU AI Act (AI labels showing smaller effects than false-content labels; small-scale studies where labels shift belief about origin without significantly shifting likes, comments and shares; over-labelling risk; case for media literacy) · Information Labs · https://informationlabs.org/too-much-too-little-never-just-right-the-labelling-dilemma-of-article-50-of-the-eu-ai-act/ · 2025-06-18.
- Ava. Concerning Law Enforcement Exemptions in Draft AI Act Transparency Guidelines (critique of the law-enforcement exemptions in the draft guidelines: undisclosed chatbots, unlabelled deepfakes and emotion recognition used against investigation targets) · https://blog.avas.space/le-exempt-draft-aiact/ · 2026-05-25.
- Resolução nº 23.755, de 2 de março de 2026 (electoral advertising rules for the 2026 Brazilian elections, including labelling of AI-produced or AI-altered content, the deepfake ban, the 72-hour and 24-hour window around voting, and the quality-adjustment exceptions) · Tribunal Superior Eleitoral · https://www.tse.jus.br/legislacao/compilada/res/2026/resolucao-no-23-755-de-2-de-marco-de-2026 · 2026-03-02.
- IA nas eleições: as novas regras do TSE para propagandas eleitorais e plataformas (explicit, prominent and accessible labelling naming the technology; deepfake ban; restriction window; platform duties and joint liability) · Data Privacy Brasil · https://www.dataprivacybr.org/ia-nas-eleicoes-as-novas-regras-do-tse-para-propagandas-eleitorais-e-plataformas/ · 2026.