Regulation
Machine-Readable AI Marking: EU AI Act Article 50 Rules
Article 50(2) of the EU AI Act tells providers to mark generated audio, image, video, and text so software can detect it as artificially made. It never says how. Not C2PA, not SynthID, not any named standard at all. That silence is deliberate: the Code of Practice and the Commission's own Guidelines both set the bar at "effective, interoperable, robust and reliable" and leave the engineering to each provider, a design choice around 190 companies have now formally signed onto.
Key takeaways
- Article 50(2) requires providers to mark synthetic audio, image, video, or text in a machine-readable format, detectable as AI-generated, "as far as technically feasible," a duty separate from deployer-facing disclosure and backed by fines up to 15 million euros or 3 percent of global annual turnover.
- Both the Code of Practice and the official Guidelines name no specific technology anywhere: not C2PA, not SynthID, not Content Credentials. Law firm Jones Day reads this as intentional, arguing "no single labelling or marking technique is sufficient in all cases" and recommending providers stack visible and machine-readable signals together.
- A specific claim that the EU AI Office endorsed C2PA as the mandatory technical pathway, with exact icon specs, is circulating on marketing sites and is not supported by any primary source, so it is flagged as Rumor/speculation below.
- Enforcement readiness already looks uneven: Germany has named a national authority and set its own supplementary fines, France reportedly had not as of an early-2026 report, and a technical-standards committee working on marking specifics has not published a finished standard.
Regulatory timeline
EU AI Act Article 50 marking deadlines
2026-08-02
In effect · Transparency rules apply
Article 50 provider marking and deployer disclosure duties took effect. Providers must ensure synthetic audio, image, video, or text output is marked in a machine-readable format and detectable as AI-generated, as far as technically feasible.
2026-12-02
Upcoming · Transitional deadline
Marking deadline for certain Article 50(2) obligations on systems already on the market before August 2, 2026. Systems placed on the market on or after that date had no grace period.
What this does not settle
Article 50 is technology-neutral: it requires machine-readable marking "as far as technically feasible," not one named technology. Whether a given provider's current marking (or lack of it) satisfies the obligation is a separate, provider-specific question. See the provider tracker pages for what is actually documented.
The obligation, precisely
Official announcementYou'll get the exact scope of Article 50(2), the five outputs it exempts, and what missing it costs.
Article 50(2) applies to providers of AI systems, including general-purpose AI models, that generate synthetic audio, image, video, or text. They must mark that output in a machine-readable format, detectable as artificially generated or manipulated, as far as technically feasible.
It took effect 2 August 2026 alongside the rest of Article 50's transparency rules. A transitional deadline of 2 December 2026 applies to certain marking obligations for systems already on the market before that date, and that grace period comes from the later Digital Omnibus reform rather than the AI Act's original text.
The phrase "as far as technically feasible" and a defined exemption list do real work here. Marking is not required for:
- Short sequences of numbers, symbols, or letters
- Source code
- Machine-to-machine outputs never exposed to a human
- Closed-loop industrial or product-development processes, except their final outputs
- Standard editing-assistive functions
Non-compliance has teeth. Companies face fines up to 15 million euros or 3 percent of global annual turnover, EU institutions up to 750,000 euros, enforced by national market-surveillance authorities, the AI Office, and the European Data Protection Supervisor.
This is a provider obligation about the output itself. A separate, deployer-facing set of duties covering deepfakes and public-interest text sits on the AI-generated content disclosure page.
Technology-neutral on purpose
Official announcementHere's why no standard is named anywhere, and why the lawyers advising providers say to stack signals rather than bet on one.
Neither the Code of Practice on AI-generated content, whose final text was published 10 June 2026, nor the Commission's implementing Guidelines, adopted around 20 July 2026, name a marking technology anywhere. Both set the bar at marking that is "effective, interoperable, robust and reliable," as far as technically feasible.
So a provider could plausibly meet that standard with C2PA-style signed metadata, an embedded statistical watermark like SynthID, or some other mechanism entirely. What matters is whether it works in practice.
That neutrality is deliberate, not an oversight. Around 190 organizations, including Anthropic, Google, Meta, Microsoft, and OpenAI, had signed the Code by the end of July 2026, with the initial-signatory window closing 27 July 2026.
Cooley's commentary notes that signatories get "a degree of presumption of conformity" plus favorable enforcement treatment. Jones Day goes further on the engineering question, writing that "no single labelling or marking technique is sufficient in all cases" and recommending a multilayered approach mixing visible labels with invisible, machine-readable signals.
The Code backs that flexibility structurally. It explicitly permits lighter or adapted labelling for artistic, fictional, or satirical works, so one rigid mechanism does not get forced onto every kind of generated content.
The C2PA rumor, and the real claim it grew out of
Rumor/speculationYou'll see exactly which circulating specs have no primary source behind them, and the legitimate industry opinion they appear to have been laundered from.
A cluster of marketing and SEO sites assert that the Commission or the AI Office effectively endorsed C2PA as the primary technical pathway for Article 50 compliance. The specifics they cite:
- A required icon at a 24x24px minimum
- PMS 286C blue as the mandated color
- A 5mm minimum size in print
- An "EU AI Office Q1 2026 guidance" mandating C2PA plus SynthID as the compliance default
- A February 2027 interoperable-detection deadline
None of this is supported by the Code of Practice, the Guidelines, or any Commission source. It also directly contradicts their explicit technology-neutral language, which contains no icon specs of any kind.
Treat the icon sizes, the Pantone code, and the C2PA mandate as rumor until an independent primary source confirms them. Jones Day's actual advice to providers, notably, is to combine multiple signals rather than lean on any single one.
Enforcement is patchy, untested, and unevenly staffed
ReportedHere's why the headline fine number doesn't tell you your real exposure, and which member states are visibly not ready.
No confirmed enforcement action, fine, or corrective order under Article 50 had been publicly reported as of 11 August 2026.
Veeam field CTO Edwin Weijdema, writing days after the deadline, predicted corrective and suspension orders will "significantly outweigh" major fines in year one. He also flagged a genuinely open question: whether AI agents embedded in ticketing or procurement portals even count as systems that trigger these duties in the first place.
Member states are at visibly different stages of readiness:
- Germany's KI-Marktüberwachungsgesetz names the Bundesnetzagentur as default national market-surveillance authority and EU AI Office contact point, backed by an internal coordination unit
- France, per a January 2026 report, had not formally designated its competent authorities at all, after a draft list of 17 candidates including CNIL, DGCCRF, and ARCOM was withdrawn from the relevant bill
- CEN-CENELEC's Joint Technical Committee 21, reportedly more than 300 experts across 20-plus countries working in five groups, is said to be developing harmonized standards partly aimed at Article 50 marking, with no finished standard confirmed
France's status was last confirmed in January 2026, so recheck it rather than assume it still holds months on. The same caution applies to JTC21's output, which rests on secondary sources rather than a fetched primary status page.
FAQ
Does machine-readable mean C2PA?
Not under the legal text. C2PA is one widely adopted provenance standard, and IPTC (an industry body closely tied to C2PA) has publicly called it "the only technology currently meeting" the Code's metadata-signing specification, but that is informed industry commentary, not the Code's or the Guidelines' own text. Neither document names C2PA or any other specific standard as required, and Jones Day's advice to providers is to combine multiple signals rather than rely on any single one.
Is there an official EU icon or color spec for AI marking?
No confirmed one. Marketing and SEO sites have circulated specific claims: a required icon at least 24x24px, PMS 286C blue, a 5mm print minimum, an "EU AI Office Q1 2026 guidance" mandating C2PA plus SynthID, and a February 2027 interoperability deadline. None of this is supported by the Code of Practice, the Guidelines, or any Commission source, and it directly contradicts their explicit technology-neutral language. Treat these technical claims as Rumor/speculation until an independent primary source confirms them.
Has anyone been fined yet for missing Article 50 marking?
Not as of 11 August 2026. No confirmed enforcement action, fine, or corrective order has been publicly reported. A Veeam executive has predicted corrective or suspension orders will outnumber major fines in year one, which is informed speculation about enforcement style rather than a reported outcome, and national enforcement infrastructure is itself uneven: Germany has a named authority in place, while France's designation status was last reported as unresolved.
Is a single required technical marking standard coming?
Maybe eventually, but nothing is confirmed. CEN-CENELEC's Joint Technical Committee 21 is reportedly working on harmonized technical standards that touch Article 50 marking, with hundreds of experts involved across dozens of countries. No finished, published standard from that effort has been confirmed, and until one exists, "effective, interoperable, robust and reliable" is the only legal bar providers actually have to clear.
Next steps
- See what C2PA actually specifies, so you can tell the real standard apart from the invented EU mandate built on top of it. C2PA Content Credentials
- Find out which Article 50 duties fall on deployers rather than providers, since the marking duty is only one of four. AI-generated content disclosure
- Look at how an actual embedded text watermark works, and what independent testing says about whether it survives editing. SynthID watermark
- Read the Code of Practice page yourself and search it for a technology name. You will not find one. EU Code of Practice on AI-generated content
Sources and citation status
- RegulatoryEU AI Act Article 50
- RegulatoryEU Code of Practice on AI-generated content
- RegulatoryEU AI Act service desk: implementation timeline
- RegulatoryEuropean Commission: FAQ on transparency obligations under Article 50
- RegulatoryEuropean Commission: safer and more transparent AI (penalties)
- ReportingCooley: EU AI Act transparency obligations take effect
- ReportingJones Day: Commission publishes second draft Code of Practice on AI labelling and transparency
- ReportingHelpNetSecurity: Edwin Weijdema on EU AI Act transparency
- ReportingTechnology's Legal Edge: Germany's AI Implementation Act