EU AI Act Article 50: The New Rules for AI-Generated Content
Since 2 August 2026, publishing an AI-generated image, video or audio clip in the European Union without saying so is no longer merely questionable — in a well-defined set of situations, it is unlawful. Article 50 of the EU Artificial Intelligence Act — the AI Act — now applies, and it reaches far more organisations than most people assume.
This article sets out what the text actually requires, who it binds, what falls outside it, and above all a blind spot the regulation does not fill: the law organises the labelling of the fake; it creates no way to prove the real. We are not a law firm and none of this is legal advice — it is an operational reading, sourced from the European Commission's own published documents.
What Article 50 actually says
Article 50 is not one rule but four stacked obligations aimed at different actors. The structural distinction is between the provider (who develops the AI system and places it on the market) and the deployer (who uses it under their own authority, in a professional capacity).
- Article 50(1) — providers. A system that interacts directly with people (chatbot, agent, avatar) must be designed so users know they are talking to an AI. Unless it is obvious — an exception the Commission asks to be read restrictively.
- Article 50(2) — providers. The outputs of a generative system (image, audio, video, text) must carry a machine-readable mark that is "effective, reliable, robust and interoperable", allowing them to be detected as AI-generated or manipulated.
- Article 50(3) — deployers. People exposed to emotion recognition or biometric categorisation systems must be informed — whether the system runs in real time or after the fact.
- Article 50(4) — deployers. Deepfakes must be labelled. So must text published to inform the public on matters of public interest, unless it has undergone human review.
The point almost everyone misses
There is a widespread confusion between obligations 50(2) and 50(4), and it is an expensive one. The Commission is explicit in its FAQ: a deployer cannot simply rely on the machine-readable marking embedded by the provider to discharge its own disclosure duty.
In other words: the fact that your image generator embeds an invisible watermark and signed metadata exempts you from nothing. These are two distinct layers, with two distinct audiences:
- machine marking (50(2)) addresses systems — platforms, search engines, verification tools;
- visible labelling (50(4)) addresses the human looking at the content, and must be perceivable "without any specific technical tools or performing dedicated actions".
Disclosure must happen upon first exposure at the latest, in a clear and distinguishable manner. A pale grey line at the bottom of the page does not meet that bar.
What counts as a deepfake under the Act
The word is used loosely everywhere; the Act defines it precisely in Article 3(60). Three criteria must be met cumulatively:
- Resemblance: a high level of similarity between the content and the simulated subject.
- Existence: the simulated person, object, place or event must resemble something that exists, existed, or could plausibly have existed.
- False appearance of authenticity: the content must be capable of misleading a person as to its authenticity or truthfulness.
The guidelines invite you to assess that third criterion in context: level of resemblance, the substantive message of the content, the deployment context, and the composition and expectations of the intended audience. A special effect in a science-fiction film does not lead the audience to believe they are seeing reality — so it does not automatically fall into the category.
What falls outside the obligation
The scope is broad but not unlimited. Several situations are explicitly out of scope or benefit from a lighter regime.
Outputs outside the marking duty
- uses authorised by law to detect, prevent, investigate or prosecute criminal offences — an exemption that runs across paragraphs 1, 2 and 4;
- a short sequence of numbers, symbols or letters;
- source code;
- outputs intended exclusively for machine-to-machine communication, processed automatically without human exposure;
- outputs used only in closed-loop industrial or product-development environments — film production is the Commission's own example — unless they are the final output.
To which one very common case must be added: the marking obligation does not apply where the AI system performs a mere assistive function for standard editing. Where does standard retouching end and manipulation begin? The guidelines give examples; this is the point that will generate the most interpretation over the coming months. A narrow exemption is also envisaged for certain strictly business-to-business or industrial contexts.
Artistic and satirical works: lighter, not exempt
This is a frequent misreading. Where a deepfake forms part of an evidently artistic, creative, satirical or fictional work, the obligation is not removed: it is limited to appropriate disclosure that does not hamper the display or enjoyment of the work. Content that is exclusively informative or commercial cannot claim this category.
Text: the editorial exemption
Published text need not be labelled if it has undergone human review or editorial control, with a natural or legal person holding editorial responsibility for the publication. Do not over-read it: the Commission specifies that superficial, purely formal or procedural checks — spell-checking or grammatical correction — do not constitute human review.
The real timeline
- 20 July 2026 — the Commission adopts the final version of its guidelines on the transparency of AI-generated content.
- 2 August 2026 — Article 50 applies. Providers and deployers must comply.
- 2 December 2026 — end of the only grace period. It covers only the marking and detectability obligation of Article 50(2), and only for systems already placed on the market before 2 August 2026.
A frequently asked point: content generated before 2 August 2026 does not have to be labelled retroactively. The Commission nonetheless encourages deployers to do so where possible.
Who enforces it, and what it costs
Enforcement sits mainly with national market surveillance authorities. The AI Office has only a limited role: it is competent solely for systems built on general-purpose AI models where the same entity provides both model and system, or where the system is integrated into a very large online platform or search engine designated under the DSA. The European Data Protection Supervisor takes over for EU institutions.
Fines can reach EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year. Proportionality may be taken into account for SMEs and small mid-cap companies.
How marking works in practice
The Act sets an outcome, not a technology. In the current state of the art, two families of techniques share the field, and they combine rather than replace one another:
- cryptographically signed metadata, via the open C2PA standard ("Content Credentials"), which attaches a manifest describing the file's origin and history;
- imperceptible watermarking, written into the pixels themselves — Google's SynthID being the most widely deployed example. We covered how it works and where it stops in our guide to the SynthID watermark.
On the compliance side, the Commission and the AI Board have assessed the Code of Practice on Transparency of AI-generated content as adequate. Signing up remains voluntary, but carries a real benefit: legal certainty and predictability regardless of where you are established. Providers and deployers who choose not to adhere will have to demonstrate compliance through other adequate means, and may face more requests for information.
The final version of the code was published on 10 June 2026 and, by the end of July 2026, had been signed by roughly 190 companies and organisations. A rarely mentioned but immediately practical detail: the Commission publishes an official set of icons deployers can reuse to label AI-generated content — no need to invent your own signage.
The gap: labelling the fake does not prove the real
Here is what no law-firm briefing will tell you, because it is not a question of law but of logic.
Article 50 builds a system of positive signals: "this content was AI-generated." It does not build — and does not claim to build — the inverse signal: "this content is an authentic capture of reality." The two statements are not symmetrical, and the gap between them is exactly where disputes are lost.
Three reasons, all documented by the organisations behind these very technologies:
- The absence of a mark proves nothing. Google says so plainly about SynthID: not finding a watermark does not mean the image is authentic. The content may come from a model that does not mark, a non-EU model, or a modified open-source model.
- Marks get lost. The C2PA specification acknowledges it explicitly in its security considerations: an attacker can remove the metadata. And with no attacker at all, a screenshot, a messaging-app forward or a recompression is enough to erase the manifest.
- Provenance is not truth. The Content Authenticity Initiative puts it in its own words: Content Credentials do not indicate whether an image is fake. They tell you where a file came from, not whether the scene photographed was honest. We documented the measured limits of detection tools in our analysis of how reliable AI image detectors really are.
The practical consequence for a business: Article 50 compliance protects your liability when you publish synthetic content. It does nothing for you on the day you must show that a damage photo, a check-in inventory or a site report was not fabricated. On that day, the only thing that matters is what you did at the moment of capture.
Proving the authentic: the other half of the problem
The approach is the exact inverse of detection. Rather than analysing an image after the fact with no knowledge of its history, you seal up front the elements that cannot be recreated later: the moment, the place, the device, the binary content of the file. That is the principle of the authenticity certificate as we implement it — the detail is on our how-it-works page.
One important note on metadata: a file's EXIF is trivially editable and proves nothing on its own, as we explain in our guide to what EXIF metadata really proves. What changes everything is independent timestamping and third-party signature at the moment the picture is taken.
For organisations that must issue verifiable documents or visuals at scale — insurers, loss adjusters, public bodies, landlords — the same logic is industrialised through an API: see the Issuer API documentation.
Checklist: what to do this quarter
- Map it. List every place your organisation generates or publishes synthetic content: marketing, customer service, documentation, social media, avatars, chatbots. You will find more than you expected.
- Qualify your role. For each use: are you a provider, a deployer, or both? An employee acting under the company's authority is not a separate deployer — the company is, including where contractors act on its behalf.
- Check the marking chain. Do your AI vendors mark their outputs? Do your processing pipelines preserve those marks, or destroy them on crop and recompression?
- Add visible labelling everywhere you publish deepfakes or unreviewed public-interest text — and place it before first exposure, not in a footnote.
- Document your decisions. Record why a given use qualifies as standard editing, editorial exemption or creative work. Under scrutiny, that trail beats a reconstruction after the fact.
- Handle proof separately. Identify the images and videos whose authenticity you might one day have to demonstrate — and have them certified at capture, independently of Article 50.
Frequently asked questions
Does this apply to a small business?
Yes, as soon as it is a provider or a deployer within the meaning of the Act. Size affects the proportionality of the fine, not whether the obligation applies.
What if my company is outside the EU?
Providers established outside the EU are subject to the Act as soon as the output of their AI system is used within the Union.
I post AI images on my personal account — am I covered?
The strictly personal, non-professional use of a natural person falls outside the Act. But if that activity yields a regular economic benefit, or forms part of a business, trade, occupational or freelance activity, the person becomes a deployer.
Does marking prove a photo is authentic?
No. Marking flags generated content; its absence does not prove authenticity. Proving that an image is a genuine capture is a separate exercise, undertaken at the moment the picture is taken.
Key takeaways
- Article 50 has applied since 2 August 2026; only the machine-marking duty is deferred to 2 December 2026, and only for pre-existing systems.
- Providers and deployers carry different duties: the provider's machine marking does not discharge the deployer's visible labelling.
- Artistic and satirical works get a lighter obligation, not an exemption.
- Fines up to EUR 15 million or 3% of worldwide turnover, enforced by national authorities.
- The law labels synthetic content. It provides no means of proving that content is authentic — that proof is built at capture.
Sources
- European Commission — Transparency obligations under Article 50 of the AI Act (official FAQ, updated 24 July 2026)
- European Commission — Guidelines on transparency obligations for providers and deployers of certain AI systems
- European Commission — Code of Practice on Transparency of AI-generated content
- Regulation (EU) 2024/1689 — Article 50: transparency obligations (official text, AI Act Service Desk)
- Regulation (EU) 2024/1689 — Article 3: definitions (including 3(60), "deep fake")
- European Commission — EU icons for labelling AI-generated content
- C2PA — Security Considerations, specification 2.4
- Content Authenticity Initiative — Frequently-asked questions
- Google — Verify AI-generated images, videos, and audio (Gemini help)
- Google DeepMind — Identifying AI-generated images with SynthID
Try Truth-Check for free
Certify your photos and videos in seconds. 3 free credits, no commitment.
Download