Every statement on this page carries a source, and every source carries a date, since the law here has moved month by month and you should be able to tell how old each statement is. The date at the top of the page says when we last went over the whole thing.
This page is general information about the law, not legal advice. The rules change and depend on your specific situation — consult a qualified lawyer before acting on anything here.
What Article 50 of the EU AI Act says
The EU AI Act is Regulation (EU) 2024/1689, and Article 50 is the part of it that deals with transparency. The marking duty at the centre of it reads as follows, quoted word for word from the statute [EUR-Lex, CELEX:32024R1689]:
“Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible…” (Article 50(2))
Three things in that matter. The first is that text is named outright, so this was never only about pictures; the second is that the marking has to be machine-readable; and the third is that the output has to be detectable as something an AI made. The statute does not tell providers how to do it, so a watermark, or signed metadata, or fingerprinting could all qualify, and a provider serving the EU can no longer leave its output unmarked and say nothing about it.
The law gives one job to providers and another to deployers
Article 50 gives one set of duties to the companies that build and supply the AI systems, which the law calls providers, and a different set to the organisations that use them, which it calls deployers. Keep asking which of the two a given sentence is about and the article gets a great deal easier to read.
Providers, under Article 50(1) and (2), have to make sure that a person dealing directly with an AI system knows it is an AI, unless that is already obvious, and they have to mark every piece of synthetic audio, image, video and text they put out so that a machine can read the mark and pick the content up as AI made. The marking duty drops away where the AI only performs an “assistive function for standard editing” or does not substantially change what the deployer put in, so a spelling and grammar tool is outside it and a text generator is well inside it, and most of the products people ask us about are text generators [EUR-Lex].
Deployers get a different job under Article 50(4). They have to disclose deepfakes, meaning any image, audio or video that an AI generated or manipulated, with a lighter regime for work that is clearly artistic or satirical. With text it is narrower. A deployer has to say an AI generated it when the text “is published with the purpose of informing the public on matters of public interest”, so news and civic information and that kind of thing, unless the content “has undergone a process of human review or editorial control” and a person or a company “holds editorial responsibility” for it [EUR-Lex]. So a newsroom that drafts with AI but has a human editor sign everything off does not have to label each article, and a news feed that an AI writes and no person ever looks at does have to.
Whatever the disclosure is, it has to reach people “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure”, which is Article 50(5).
Three dates we would write down
The first is August 2, 2026, the day Article 50 became applicable. From that day a new generative AI system has had to mark what it puts out, so anything launched this summer was in scope from its first day [European Commission FAQ].
The second is December 2, 2026, when the grace period runs out. The AI Omnibus agreement reached in May gave a generative system that was already on the market before August 2 until December to meet the machine-readable marking requirement. The duty to tell people they are talking to an AI, and the deployer’s deepfake duties, applied from August whatever happened, so the grace period is narrower than a lot of people took it to be [CSA research note; ReedSmith].
The third is February 2, 2027, the deadline for interoperable detection under the Code of Practice, which we come back to below. By then a provider has to have given the rest of us a working way to test for its marks, and from what we read it could do that with a public access point, or with a “signpost” embedded in the content, or with a solution shared with other providers in a consortium, and none of the lawyers we read seemed sure yet which of the three we will end up with [TechPolicy.Press; Stibbe].
What it costs a company that ignores it
A company that does not comply with Article 50 can be fined up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher, and for an SME it is whichever is lower. The people who come after it for the money are the national market surveillance authorities, which in most countries is a body you would never have heard of until it wrote to you [AI Act Article 99(4)(g)].
The Commission’s guidelines came out in July
Around July 20, 2026 the Commission published its final guidelines on Article 50, and that is the document to read if you are hoping for an exemption, since that is where the exemptions are set out. The ones we found were for AI-assisted translation, for source code, for very short outputs, and for traffic that only went from one machine to another or stayed inside a company. The rest of the document is of little help to a company looking for a way out, since it says a deepfake is to be read broadly, that the creative-work exception is to be read narrowly, and that content merely used in the EU can be enough on its own to bring you within reach of the law, which covers a lot of companies outside Europe that had assumed the law did not apply to them [ReedSmith].
The Code of Practice that the AI Office put together
Article 50(7) told the EU AI Office to go and facilitate a code of practice, and that is what it did. The Code of Practice on Transparency of AI-generated Content was published on June 10, 2026, and on July 8 and 9 the Commission and the AI Board looked at it and found it adequate, which was the step that turned it into the instrument the EU recognises when a company wants to show that it is complying with Article 50. It is a good deal more concrete than the article itself, so it is the document to read if you are working out what you have to do [European Commission; IPTC; ReedSmith].
By the end of July roughly 190 organisations had signed it. The provider section holds Anthropic, Google, Meta, Microsoft, Mistral, and OpenAI, and next to them Aleph Alpha, Cohere, Black Forest Labs and Synthesia, while the deployer section runs from Getty Images to Lufthansa. The name that is missing is xAI, reported as the only major language-model maker that had declined to sign, though not signing the Code does not take a company out of the AI Act itself, so xAI is bound by Article 50 like everyone else and has to show that it complies some other way [European Commission signatory list; CityAM].
A company that has signed the Code has three ways of marking its content open to it. It can use metadata that has been digitally signed and time-stamped, which usually means C2PA Content Credentials, or a watermark that people cannot see or hear, or fingerprinting with a registry behind it, and that last one was left optional. On top of that the Code says you have to make detection mechanisms available to the rest of us, which is the road that leads to the February 2027 interoperability deadline above. It is the part of the whole thing we care about most, since it is what would let a site like this one look for the provider’s own mark in a file, which is a much better test than the statistical estimate we run today [IPTC; TechPolicy.Press].
The people who wrote the Code admitted two things in it that you should know about. The first is that they could not point to any single marking technique that meets all four of the words in the statute at the moment, and those words were effective, interoperable, robust and reliable. The second is about what AI detectors like this site do, which is try to spot unwatermarked AI text from its statistics, and the Code said that kind of detection “is not yet considered reliable enough”. We agree with them, and we say the same thing on our methodology page [TechPolicy.Press].
California passed its own law, SB 942 and AB 853
California has its own law, and it came into effect on the same day as the European one. The AI Transparency Act is SB 942, as amended by AB 853, which was signed on October 13, 2025, and the date was picked so that it would line up with the EU. A covered provider, meaning one with over 1 million monthly users that is publicly accessible in California, has had to offer a free public AI detection tool since August 2, 2026, may offer visible disclosures if it wants to, and has to embed latent disclosures where it feasibly can. AB 853 reaches large online platforms and GenAI hosting platforms from January 1, 2027, and capture devices from January 1, 2028. Breaking it costs $5,000 per violation per day [aicomplianceatlas.com; Hintze Law; Troutman].
Almost every summary we have read gets the scope of it wrong. SB 942 covers image, video, and audio, and it does not cover text. So a student essay, a marketing blog post or a fake product review does not fall under California’s marking rule or under its free detection tool rule. As of August 2026 our own review of the United States found no federal or state law that requires AI-generated text to be marked, and we want to be careful about how we put that, since it is a conclusion drawn from not finding such a law in our searches, in an area where the legislation is moving fast, and not from any authority saying so. So as things stand a duty to mark text exists in Europe and in China, and in America a provider marks its text only if it decides to.
China got there first
China had got there before either of them did. On September 1, 2025 the “Measures for Labeling of AI-Generated Synthetic Content” took effect, issued by the Cyberspace Administration of China and three other regulators on March 14 of that year, with a mandatory national standard, GB 45438-2025, sitting behind them. A company there has two jobs. It has to put explicit labels on what it puts out, meaning a visible sign on any text, image, audio, video or virtual scene that an AI has made, so that a person who looks at it can tell. And it has to put implicit labels inside the files too, meaning embedded metadata, and a watermark if it wants to add one. A platform has to look for the labels, and an ordinary user who uploads something an AI made has to say so. So if you put the three side by side, the Chinese rules cover text where California’s do not, and they want a label a person can see where the EU settled for one that only a machine can read [Loeb & Loeb; ChinaLawTranslate; Bird & Bird].
What this means for you
If you write, as a student, a freelancer or an author, then no law anywhere requires you to watermark your own writing, and there is nothing that would let you prove a text was written by a person. But any text you generated in the Gemini app or on the Gemini web experience (since 2024), or with the new Claude models (since August 2026), carries a provider watermark that the provider can detect, and as far as we can tell it will go on being able to detect it for good. So if you published AI-generated text as your own in a setting where that mattered, assume it could be proved one day. And if you are ever accused of using AI on the strength of a statistical detector score alone, the EU’s own Code of Practice said that kind of detection was “not yet reliable enough”, which is a fact you can cite, and our response playbook explains how you would use it.
If you deal with chatbots as a customer, then since August 2026 you have had a right, under Article 50(1), to be told when the thing you are talking to is an AI. How far that right goes, and what you can do yourself when nobody has told you anything, is all on one page, which is Am I talking to a bot?
If your business publishes content, and you operate in the EU or into it, and you publish AI-generated text “to inform the public on matters of public interest”, then you have to disclose it, unless a human editor reviewed it and a person or a company holds editorial responsibility for it. That editorial-control exception is the practical way in for most businesses, so put a named human review step in your pipeline and write down that you did. Deepfake-style image, audio and video have to be disclosed regardless. If you serve California at scale with image, video or audio generation, the SB 942 detection-tool and disclosure duties may reach you as well. And go and ask your vendors, since from December 2, 2026 every major model provider that serves the EU should be marking its text output, so ask yours how they are doing it.
If you build with AI models, and your product writes text or makes images, audio or video for people in the EU, then Article 50(2) applies to you as a provider, and the marking is your job and not only OpenAI’s or Google’s. If you built on top of someone else’s API, the main thing we would ask of you is that you do not strip their marks out on the way. Keep the C2PA metadata intact as it passes along your pipeline, do not re-encode files when you do not have to, and do not push the output into anything that would destroy a watermark. Keep an eye on the February 2027 date as well, since whatever the providers have shipped by then for interoperable detection is what your compliance tooling will be able to call. The exemptions for assistive editing, source code, short outputs and internal machine-to-machine traffic are real but narrow, so read the Commission’s guidelines before you rely on one of them.
Is this content legally labeled? How to check
Article 50 has been enforceable since August 2026, and that means “is this content compliant?” has turned into a question you can partly test for yourself, though only partly, since with text there is nothing you can test at all. We would go medium by medium, with a note on what each result would and would not prove.
- Images and video files: run the file through our Content Credentials check. If it finds a valid C2PA manifest and the manifest names an AI generator, that is the machine-readable marking the law had in mind, provided the signature traces back to an authority we recognise. If it traces back to nobody, what you have is a claim somebody attached to the file rather than a labelling you can rely on. If the check finds nothing at all, what you have is an unknown, which is a different thing from non-compliant, and we would want you to hold on to that difference, since a screenshot, a file sent over a messenger or a second upload will strip those credentials off without telling anybody, and that is not the provider’s fault.
- Text: with text there is no compliance test that you can run as a consumer, and a product that claimed to offer one would be promising more than it could deliver. The watermarks that the providers put in text are keyed, so only the provider can verify its own mark, and none of them has opened a detection API to the public yet (the live status is here, and we keep it current). A statistical scan like ours estimates how likely it is that the text was written by an AI, which is a different question from the one about the mark the law requires, and our scan cannot answer the second one.
- Chatbots: with a chatbot, the test is the conversation you had with it. Since August 2026, if you are in the EU and you are talking to an AI, the provider or the deployer has to tell you that, unless it is already obvious from the context, so if nobody told you then that on its own is a problem under the law. If you want to test it for yourself anyway, the tests we have found work are written up on Am I talking to a bot?
If one of these tests came back wrong somewhere the law said it should not have, the first place we would take it is the deployer or the provider, and if that went nowhere then the next stop is your national market-surveillance authority, which is who enforces the AI Act where you live. We would not go after the person who shared the file with you, since as we said above they may have stripped the marking off without ever knowing it was there, and most people have no idea that a screenshot does that.
Sources
- Regulation (EU) 2024/1689, Article 50 (verbatim) and Article 99 — EUR-Lex, CELEX:32024R1689 (accessed Aug 16, 2026)
- European Commission, FAQ on Article 50 transparency obligations, digital-strategy.ec.europa.eu (accessed Aug 16, 2026)
- European Commission, Code of Practice on Transparency of AI-generated Content — policy page and “Strong backing” signatory announcement (Jul 2026; list updated Aug 12, 2026; accessed Aug 16, 2026)
- IPTC, “EU AI transparency Code of Practice” (Jun 2026; accessed Aug 16, 2026)
- TechPolicy.Press, “The EU's AI Transparency Code of Practice, Explained” (accessed Aug 16, 2026)
- ReedSmith, “Transparency obligations for AI-generated content: the Code of Practice adequacy” (accessed Aug 16, 2026)
- Cloud Security Alliance, research note on Article 50 and the AI Omnibus grace period (Jul 29, 2026; accessed Aug 16, 2026)
- Stibbe, “The AI Act's transparency obligations” and “(Water-)marking the machine” (accessed Aug 16, 2026)
- CityAM, “ChatGPT might follow Claude's watermark pledge — but Grok to swerve it” (Aug 12, 2026; accessed Aug 16, 2026)
- California SB 942 / AB 853: aicomplianceatlas.com; Hintze Law (Oct 19, 2025); Troutman Amin (Oct 2025); accessed Aug 16, 2026
- China labeling measures: Loeb & Loeb (Mar 2025); ChinaLawTranslate; Bird & Bird (accessed Aug 16, 2026)