EU AI Act Article 50: a watermark is not the whole disclosure
"Watermark AI content" sounds like a workable summary of Europe's new transparency rules. It is not. A machine-readable mark and a disclosure that a person can see or hear do different jobs, and Article 50 of the EU AI Act assigns them to different actors.
The rules began applying on 2 August 2026. Providers that build AI systems have duties at the system and output level. Deployers that use those systems may have duties at the moment content reaches the public. A company can occupy both roles in one product.
For engineering teams, this affects generation, export, publishing, accessibility, and review records. A provenance field hidden in a file does not satisfy every visible-labelling duty. A badge in an interface does not make a downloaded asset machine-detectable.
The four transparency cases
The European Commission's guidance separates Article 50 into four cases.
First, providers of systems that directly interact with people, including chatbots, agents, and avatars, must inform them that they are dealing with AI unless that fact is obvious. The notice should appear from the start of the first interaction and meet accessibility requirements.
Second, providers of generative systems must make synthetic audio, image, video, and text outputs machine-readable and detectable as AI-generated or manipulated, as far as technically feasible. The Commission's FAQ excludes some outputs, including source code, short sequences of numbers or symbols, machine-to-machine output never exposed to people, and certain closed-loop industrial output.
Third, deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to those systems.
Fourth, deployers must disclose deepfakes and some AI-generated or manipulated text published to inform the public about matters of public interest. The Commission's examples include politics, public services, justice, fundamental rights, public safety, health, environmental protection, consumer safety, and developments relevant to public debate.
These duties can overlap. The useful unit of analysis is the workflow: who built the system, who operates it, who publishes the output, and who encounters it.
Two layers that fail differently
Article 50(2) covers provider-side marking and detectability. A technical mechanism may use content credentials, metadata, watermarking, or another interoperable method. The requirement is framed around effective, reliable, robust, and interoperable marking as far as technically feasible. Modality, cost, and the generally acknowledged state of the art also matter.
Article 50(4) covers disclosure to people. For a deepfake, the deployer must disclose its artificial nature no later than first exposure. The Commission says a provider's machine-readable mark alone does not meet this duty. People must be able to perceive and understand the disclosure without special tools.
The EU has released optional icons for fully generated, partially modified, and other AI-involved content. Its icon guidance says that using an icon does not establish compliance by itself. In the Commission's user testing, performance improved when the basic icon appeared with a text label. The published display guidance also calls for plain language, accessible presentation, and placement that remains visible when content is downloaded or reshared.
An implementation therefore needs both layers where both duties apply:
- machine-readable provenance that survives the content pipeline;
- a clear human-facing disclosure in the interface or media.
Test each one independently in image-generation workflows. Transcoding can strip metadata. Cropping can remove an overlay. A source-file check catches neither failure after distribution.
Human review means reviewing the substance
The rule for text is narrower than a universal label on every AI-assisted sentence. It concerns generated or manipulated text that is published, informs the public, and covers a matter of public interest.
Such text does not need the Article 50(4) label when it has undergone human review or editorial control and a person or legal entity holds editorial responsibility. The Commission describes review as deliberate examination of the substance by people with relevant knowledge and professional judgment. Editorial control requires authority to approve, alter, or reject the substance, including fact-checking and source assessment. Spell-checking and grammar correction do not qualify.
A publisher relying on this exception needs more than a generic "human reviewed" status. The workflow should record who examined the claims, what sources were checked, who could reject publication, and who accepted responsibility for the result.
This also separates substantive review from humanizing AI-written prose. Editing cadence and word choice may improve readability. It does not establish that the claims were checked by someone with relevant knowledge.
Put disclosure into the content lifecycle
Teams can start with an inventory before choosing a watermarking vendor or redesigning the interface.
- Record whether the organisation acts as provider, deployer, or both for each system and output.
- Map each user journey to the applicable case: direct AI interaction, generative output, emotion or biometric use, deepfake, or public-interest text.
- Store provenance with the asset, including the model, transformations, review state, and disclosure policy. A filename convention is too easy to lose.
- Add a visible disclosure at first exposure when required. Test contrast, audio alternatives, screen readers, localization, downloads, embeds, crops, and reshares.
- Give substantive editorial approval its own workflow state. Keep grammar edits separate from fact review and publication authority.
- Export, compress, transcode, screenshot, copy, paste, and re-upload representative content. Then check the machine mark and visible disclosure again.
The voluntary Code of Practice gives providers and deployers an EU-wide framework for demonstrating compliance. The Commission and AI Board have assessed it as adequate. It does not replace Article 50 or the Commission guidelines. Organisations may use other measures, but they must be prepared to demonstrate that those measures are adequate.
The transition is narrow
Article 50 has applied since 2 August 2026. The grace period until 2 December 2026 covers only the marking and detection duty for generative AI systems placed on the market before 2 August. It is not a general delay for visible labels or chatbot notices. Content generated before 2 August does not need retroactive labelling.
Providers outside the EU can also fall within the Act when their system's output is used in the EU. Specific products and publishing arrangements need legal review. Engineering teams can make that review more useful by arriving with four answers: who generated the output, who published it, what a person sees at first exposure, and which provenance signals survive after the file leaves the product.



