Skip to main content
Encypher Logo
Back to all posts
EU AI Act Article 50: The Day-One Checklist for August 2nd
Encypher Team

EU AI Act Article 50: The Day-One Checklist for August 2nd

EU AI Act Article 50 applies August 2nd, 2026. Providers and deployers need tested records of machine-readable marking, disclosures, and exceptions from day one.

On Sunday, August 2nd, 2026, a provider that releases AI-generated text to EU users must be able to mark that output in a machine-readable form, and a deployer that publishes a deepfake or AI-written public-interest text must be able to show that a person was told󠇟󠇠󠇡󠇢󠇐󠄌󠅲󠆯󠅫󠆸󠆱󠄨󠆍󠆠󠅺󠄻󠅎󠄃︊󠇏󠄖󠄹󠅢󠆚󠆌󠆀󠄧󠆜󠇄󠇤󠄖󠇪󠇄︋󠆤󠆘󠅡󠄋󠆺󠇡󠅞󠅡︊󠆔. Article 50 turns both steps into legal transparency obligations, so the day-one task is to show where each duty is handled and that the controls work󠇟󠇠󠇡󠇢󠄏󠆨󠅛󠆳󠆓󠇅󠇞󠅊󠅖󠆔󠇎󠄄󠆞󠅓󠄬󠄝󠆸󠇠︆󠅾󠅩󠇈󠆈󠄟󠆎󠄅󠅂󠆽󠇠󠇌󠅍󠇋︈󠄰󠇕󠄷󠆄󠅿︆󠇦.

This post discusses legal developments for informational purposes only and does not constitute legal advice󠇟󠇠󠇡󠇢󠄁󠆫󠇛︎󠄾󠆮︊󠇅󠄫󠅗󠅔󠆩󠇒󠆧󠆶󠆬󠇈󠄐󠄔󠆄󠆊󠅘󠅰󠄇󠄧󠅭󠇟󠆲󠅈󠇯󠄕󠅱󠆨󠄋󠅸󠇊󠆥󠅖󠇘󠄽. Encypher is a technology company, not a law firm󠇟󠇠󠇡󠇢󠇡󠇚󠆦󠆅󠆴󠄒󠆎󠅘󠄩󠅠󠆴󠅩󠆱󠄞󠇈󠄶󠇀󠅝󠅛󠆹󠆇󠄾󠅀󠄢󠅨󠅔󠄾󠅄󠄠󠆚󠆙󠇯󠅥󠅙︆󠅹󠆢󠄫󠅰󠅉. Consult qualified legal counsel for advice specific to your situation󠇟󠇠󠇡󠇢󠄜󠄐󠆤󠅗󠄥󠄫󠅀󠄘󠅚󠅓󠄪󠅟󠆇󠇟󠆳󠆧󠇀󠅔󠅝︃󠇗󠆊︌󠆰︇󠄴󠆞󠅧󠅱󠇧󠇖󠅵󠄾󠆫󠅰󠆮󠆮󠆼󠅷󠄓.

What applies on August 2nd, 2026󠇟󠇠󠇡󠇢󠄒󠇉󠄃󠅯󠆘󠇀󠄬󠇅󠆒󠇍󠄧󠆏󠄆󠆄󠇖󠅓󠇝󠇇󠄱󠆦󠅗󠆰󠅔󠅀󠆧󠅪󠆍󠅖󠆆󠇩󠆐󠆖󠄨󠆔󠄺󠆥󠇄󠇓󠅐󠇓?

The EU AI Act's Article 50 transparency obligations apply from August 2nd, 2026󠇟󠇠󠇡󠇢󠇩󠄈󠅐󠇧󠇓󠇟󠄝󠄢󠇝󠇐󠆭󠇩󠄋󠅣󠆋󠇂󠆚󠆁󠅒󠅎󠆌󠄦︀󠆰󠆘󠄊󠆧󠆴󠇑󠄽󠅙︈󠄗󠅪󠆮󠅰︍󠄊󠆛󠆣. The date belongs to Article 50, not to the earlier general-purpose AI model rules󠇟󠇠󠇡󠇢󠆑󠄦󠇤︍︉󠆆󠄸󠅹󠆽󠇍󠅇󠄴󠄾󠅖󠆛󠇜󠆎󠇘󠄺󠄖󠆪󠄑󠄻󠆳󠅻󠄳󠄷󠄟󠄗󠅦󠅿󠆮󠅻󠇝󠄥󠅔󠄘󠅲󠅓󠅛.

  • Prohibited-practices provisions applied in February 2025󠇟󠇠󠇡󠇢󠅢󠆴󠇡󠅳󠆪󠅯󠄲󠆠󠄒󠄯󠆓󠇋󠆂󠆑󠇟󠆗󠆣󠆜󠆿󠄢󠄇󠆉󠇮󠆉󠄰︆󠅛󠄀󠅿󠇕󠆴󠆇󠄓󠇎󠅃󠅽󠆇󠄼󠅴󠆎.
  • General-purpose AI model obligations applied on August 2nd, 2025󠇟󠇠󠇡󠇢󠇨󠄋󠆝󠄏󠄴󠄬󠇄󠄺󠇌󠄗󠄔󠆊󠇋󠆥󠄦󠅟󠅳󠅋󠄈󠇏󠆗󠅱󠇖󠆞󠆋󠆗󠅡󠄮󠇊󠆎󠅔󠄩󠆺󠄩󠄽󠆔󠄝󠆨󠄥󠅔.
  • Article 50 transparency obligations apply on August 2nd, 2026󠇟󠇠󠇡󠇢󠆐󠄻󠅧󠄗󠇣󠅖󠅞󠄐︊󠆢󠇍󠄚󠆳󠅟󠆕󠄊󠆙󠄬󠆮󠅳󠄙󠄵󠄖󠄇󠅉󠅰󠄣󠇗󠆘󠄷󠇯󠅷󠅓󠄩󠆎󠄀󠆭󠄜󠄿󠅉.

The European Commission's Article 50 page sets out the enacted duties󠇟󠇠󠇡󠇢󠅗︁󠄯󠆳︈󠅒󠆩󠇄󠆙󠆧󠅠󠅠󠆾󠄅󠆨󠄳󠆔󠄝󠄇󠇀󠄁󠆠󠅘󠄧󠆸󠅫󠇟󠄟󠄐󠇑󠅩󠄬󠄩󠅎󠇍󠄱󠄢󠆋󠄫󠅽. Article 50 assigns different duties to different roles󠇟󠇠󠇡󠇢󠄹󠆂󠆩󠄜󠇇󠇣󠇬󠄈󠄸󠅐󠅳︎󠆀󠄣󠆎󠄟󠄊󠅷󠆭󠇎󠄢󠇁󠅘󠄓󠆿󠄁󠄻󠆋󠄭󠆇󠆜󠆾︌󠄫󠆑󠇗󠆠󠇤󠄗󠆫. The provider duty and the deployer duty are tested differently, so the sections below treat them separately󠇟󠇠󠇡󠇢󠇢󠇧󠄔󠆮󠆤󠆬󠆛󠆡󠄰󠄔󠇟󠆝󠅧󠄟󠄈󠅖󠇔󠄘󠇑󠆬󠅽󠄤󠅽︅󠄄󠆍󠆅󠅁󠅪󠄌󠇬󠆨󠅟󠄗󠅳󠄜󠅮󠅤󠆤󠄋.

What must providers do󠇟󠇠󠇡󠇢󠇎󠄤󠄇󠆼󠄐︅󠇓󠅕󠇉󠆕󠅅󠅏󠅯󠆟󠆁󠄰󠇤󠇀󠆚󠆞󠄽󠆪󠅿󠄻󠇂󠆯󠄿︍󠆛󠇁󠅤󠄚󠅶󠄘󠆇󠇜󠄃󠄻︉󠅩? (Article 50(2󠇟󠇠󠇡󠇢󠅃︀󠄸󠆔󠄘󠄜󠆌󠄊󠇆󠆝󠅲󠅋󠇁󠇄󠄌󠇉󠄋󠄁󠄠󠅜󠅒󠆛󠆁󠇡󠆞󠆊󠆮󠄏󠆊󠄙󠇈󠆈󠆓󠇘󠄄󠇤󠇏󠄉󠅍󠇦))

Providers of AI systems that generate synthetic text, images, audio, or video must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated󠇟󠇠󠇡󠇢󠆧󠇦󠄫󠅡󠄧󠄘󠄇󠆩󠇪󠄓󠅬󠄾󠆘󠅄󠅤󠇠󠄐󠄑󠅚󠄅󠄐󠆣󠇖󠆕󠅎󠆳󠇞󠄶󠅶󠅗󠇀󠆓󠅻󠄝︋󠇧󠆪󠇍󠅁󠄼. The Act asks for solutions that are effective, interoperable, robust, and reliable as far as technically feasible󠇟󠇠󠇡󠇢󠆧󠆩︃󠄇󠅇󠅸󠇝󠆁󠆙󠄶󠄐󠆬󠅝󠆲󠅴󠄥󠆒󠄝󠄢󠆑󠅌󠄵󠇥󠆧󠄠󠅑󠄑󠅁󠆺󠇇󠇞󠅭󠇞󠅶󠄴󠇪󠄟󠅷󠇛󠆙.

  • The mark lives in the content, not in a policy document󠇟󠇠󠇡󠇢󠅮󠆴󠅄󠅛󠅽󠄆󠅢󠇠󠆲󠆘󠅈󠇇󠅘︎󠅂󠅄󠄵󠄳󠆦󠄝󠄾󠆻󠄪󠇢󠅆󠄶󠆓󠅻︌󠄫󠆩󠄂󠄶󠅨󠄅󠅌︍󠄅󠅌󠅎. If the output leaves your system unmarked, the duty is unmet󠇟󠇠󠇡󠇢󠇃󠅔󠆎󠅖󠇂󠄜󠇟󠇗󠄼󠄪︄󠆗󠆊︀󠅸︌󠆋󠅙󠅸󠇪󠅭󠄷󠄇󠅅󠆺󠅍󠄜󠅔󠄙󠆉󠅼󠆕󠅢󠅨󠇪󠆨󠆖󠇡󠆹󠄊.
  • The duty follows the content through the pipeline󠇟󠇠󠇡󠇢󠄈󠆴󠄰󠆱󠅂󠆿󠆗︆󠅾󠇖󠅠󠇙󠅠󠆶󠄹󠅒󠆀󠄬󠆻󠄖󠇊󠅚󠆻󠄌󠄧󠄄󠅡󠇠󠆊󠄋󠇮󠇉󠄼󠇑󠇯󠆻󠅄󠇟󠆄󠆉. CMS ingestion, image resizing, transcoding, and platform re-uploads can strip metadata, so the test is whether the mark survives your real publication and distribution paths󠇟󠇠󠇡󠇢󠄲󠄆󠄎︌󠄰󠅏󠄞󠆿󠄰󠇇󠆴󠇕︍󠆴󠇣󠆚︎󠅻󠆸󠅂󠆽󠄲󠆶︎󠇮󠆖󠅝󠅜󠄙󠄇󠄂󠄑󠇯︅󠄑︎󠅺󠇔󠇘󠆱.
  • Passing a validator on the file you generated is the start of the evidence, not the end of it󠇟󠇠󠇡󠇢󠆶󠆎󠄬󠇕󠆽󠄀󠄫󠄅󠇊󠅔󠅅󠆀󠆙󠇫󠅩󠅁󠅣󠅅󠆌󠄊󠅛󠄇󠆺󠆗󠄼󠆑󠇌󠆈󠇀󠄛󠇬󠇟󠄼󠅔󠆿󠇤󠆡󠅷󠇭󠅋.

What must deployers do󠇟󠇠󠇡󠇢󠆠󠅢󠆨󠆃󠅶󠇫󠆓󠄥󠅱󠄬󠄦󠇙󠇓︂󠅷󠅓󠅎󠆠󠄊󠄮󠆑︍󠆭󠅼󠆐󠇅󠄀󠄪󠇭󠅊󠅠󠄡󠆦󠄪󠄒󠄺󠄚󠆄󠇥󠄔? (Article 50(4󠇟󠇠󠇡󠇢󠅛󠇩󠄠󠄸󠅲󠄛󠇦󠇌󠇡󠄝󠇊󠇊󠄝󠄵󠆆󠇝󠄅󠅢󠆊󠇢󠄁󠆩󠆊󠅷󠇝󠅃󠄑󠄳󠄼󠇭󠆭󠄀︄󠅫󠆖󠆒󠅺󠆂󠆆󠄙))

Deployers face a different duty󠇟󠇠󠇡󠇢󠆫󠆅󠆨󠄚󠄋󠇣︃󠅵󠅌󠅵󠇓󠇑󠆯󠄔󠄓󠇂󠄐󠅹󠅢󠆣󠇮󠇉󠄵󠄢󠄎󠄂󠅨󠆣󠅼󠇨󠆆󠆉󠄡󠅪󠇬󠅟󠄬󠄦󠆼󠇩. Article 50(4) requires those who use AI to generate or manipulate deepfake image, audio, or video content to disclose that the content has been artificially generated or manipulated󠇟󠇠󠇡󠇢󠄗󠇣󠅟󠄕󠄠󠆀󠇤󠇙󠆎󠇘󠆊󠅵󠆡󠆾󠅔󠅡󠆤󠄮󠆮󠅽󠅹󠄿󠇦️󠇄󠅠󠆷󠄳󠄞󠅈󠄖󠇧󠅰󠅧︊󠅍󠅀󠇉󠆞󠆖. The same paragraph covers AI-generated text published to inform the public on matters of public interest, unless the text has undergone human review and a person holds editorial responsibility󠇟󠇠󠇡󠇢󠄔󠄨󠅪󠇣󠅐󠄨󠅲󠆍󠄃󠇍󠅀󠄡󠆘󠇯󠅨󠅙󠆥󠅋󠆊󠆛󠄯󠆀󠆙︇󠆉󠆪󠄿󠄝󠆅󠅳󠆄󠇫󠆕󠇨󠆭󠄽󠄶󠆼󠆳󠄩.

  • The disclosure must reach the person viewing the content, clearly and distinguishably, no later than first exposure󠇟󠇠󠇡󠇢󠆃󠅵󠅑󠆀󠅷󠇇󠄛󠄊󠇣󠆒󠅅󠆈󠅬󠆩󠄱󠄃󠄭󠄽󠇕󠄣󠄿󠄃󠇆󠆣󠆋󠅘󠅽󠆯󠆢󠄩︂󠅣󠆁️󠇛󠆲󠆃󠅈󠄅󠄰. The Commission's draft transparency guidelines of May 8th, 2026 confirm this reading󠇟󠇠󠇡󠇢󠄨󠅵󠇙︌︋󠅸󠅆󠆇︁󠄢󠅌󠄦󠄟󠆀󠄶󠇠󠅇󠅎󠆴󠇯︃󠄫󠄚󠄛󠆿󠆪︀󠆫󠅛󠅼󠆪󠆠󠇔󠄴󠆤󠄩󠆅󠆹󠄞󠄭.
  • A machine-readable mark inside the file does not satisfy this duty by itself󠇟󠇠󠇡󠇢󠄮󠆓󠄥󠄍󠆁󠄡󠄑󠇇󠄕󠄝󠆡󠅐󠆴︉︀󠆆󠄄︎󠄝󠅓󠆂󠆃︅︎󠄵󠇛󠅺︋󠆝󠆳︍󠅶󠅬󠇦󠇤󠇋󠄴󠇄󠅰󠄰. A mark a validator can parse but a viewer never sees is provider compliance, not deployer compliance󠇟󠇠󠇡󠇢󠆫󠇯󠆜󠅉󠆣󠄑󠄞󠆫󠇭󠆫󠆪󠄭󠅒󠅓󠅢󠆑󠄤󠄟󠇮󠄼󠆱󠅫󠇇󠅹󠆒󠇔󠄗󠄇󠅡󠇯󠇉󠇧󠅇󠇪󠄪󠅂󠆠󠄚󠆣󠇂.
  • For evidently artistic, creative, satirical, or fictional work, the duty is attenuated, not removed: disclosure in an appropriate manner that does not hamper display or enjoyment of the work󠇟󠇠󠇡󠇢󠆾󠄎󠄁󠆧󠆺󠆘󠇜󠄹󠇑󠆱󠇫󠅤󠇀󠆏󠆺󠇛󠆣󠄟️󠆈󠅅󠅧󠆤󠇭󠆸󠆸󠆴︍󠅶󠅡󠆞󠇆󠅊󠅍󠇅󠅒󠆙󠄒󠅒️.
  • The obligation does not apply where use is authorised by law to detect, prevent, investigate, or prosecute criminal offences󠇟󠇠󠇡󠇢󠄍󠇈󠆣󠅰󠆅󠄸󠇈󠄲︊󠆽󠇝󠄜󠇕󠆉󠅄󠄼󠅚󠇤󠄁󠅉︄󠆧󠆐󠄆󠆕󠅫󠅨󠇗󠆝󠅬︀󠄀󠆁󠇂󠇬󠄫󠄥󠅐󠄁󠄰.

The two duties meet in the pipeline󠇟󠇠󠇡󠇢󠅡󠅕󠆵󠅹󠄔󠆶󠅤󠇋󠅣󠅶󠅦󠆮󠄈󠆟󠇟󠅬󠅭󠇠󠅙󠄭󠇓󠅀󠅹󠄴󠆯󠇞󠅫󠇬󠄑󠆸󠄘󠇏󠇕󠇯󠅂󠇌󠄏︊󠇙︋. The machine-readable mark is what lets a deployer's surface detect synthetic content and render the human-facing label automatically󠇟󠇠󠇡󠇢󠄮󠇟󠄁󠆦︅󠅢󠆋︂󠄨󠄘󠄱󠅼󠆻󠇋󠄿󠆷󠆡󠄾󠄼󠄉󠄭󠅀󠇯󠇩󠅢︋󠆚︅󠄪󠅙󠅬󠆀󠆹󠄞󠅒󠄠󠅔󠆹︆󠅛. Marking makes disclosure automatable󠇟󠇠󠇡󠇢󠆎󠇫󠆊󠄞󠅢󠅾︅󠄒󠄓󠆜󠄬󠆲󠅵󠄕󠅨󠄻󠄃󠅸󠇮󠇀󠅬󠆵󠅸󠆱󠇟󠇂󠇠󠄢󠅐󠄻󠄟󠄬󠆁󠄧󠇜󠄮󠇝󠆗󠆛󠇯. It does not make it automatic󠇟󠇠󠇡󠇢󠄱󠅮󠄊󠅺󠇗󠆾󠅱󠅎󠇇󠅑󠄳󠅂󠅴󠇀󠅩󠆕󠄳󠇫󠅤󠅰󠅧︌󠇖󠅄󠄶󠆣󠆑󠅾󠇯󠄑󠇥󠆵󠅿󠆶󠅎󠆔󠅣󠇘󠄉󠇦.

What should be in the day-one file󠇟󠇠󠇡󠇢󠆂󠇟󠆐󠄪󠇅󠆭󠇎󠆩󠇉󠄯󠄅󠅋󠇫󠇈󠆶󠅢󠅻󠇮󠄽󠅟󠄁󠆴󠅈󠇃󠇢󠄸󠆙󠆮󠅟󠅦󠆹󠄄󠇘󠆎󠇢󠇡󠆃󠄪󠆘󠆳?

A day-one file should map each system to an owner, a duty, and proof that the chosen control works󠇟󠇠󠇡󠇢󠅶󠇋󠇎󠇢󠄝󠆬󠇔󠇟󠄏󠅓󠄼󠄡󠄤󠇧󠆯󠅂󠄷󠇟󠅽󠅈󠄿󠅔󠅤󠅣󠇪󠇃󠆃󠅍󠄁󠄮󠄪󠇣󠇋󠆾󠅡󠇏󠅍󠇂󠇓󠄳. Keep the record short enough to update when a model, workflow, or disclosure changes󠇟󠇠󠇡󠇢󠆮󠄔󠄍󠅖󠅖️󠄼󠅺󠆼󠇃󠇂󠅚󠆖󠇋󠄊󠆖󠇑󠄴︅󠅍󠆋󠆄󠄎󠆟󠆥󠆾︋󠄤󠄞󠇋󠅮󠆆󠆢󠅳󠇠︎󠄇󠄢󠆿󠄇.

  1. List every AI system that creates or alters text, images, audio, or video󠇟󠇠󠇡󠇢󠆶󠇠󠆢󠇨󠆅︃󠄀󠆦󠆇󠄐󠆚󠆅󠆖󠆞󠄧󠇊󠄂󠅼󠆳󠇆󠆞󠄌󠄹󠅚󠅤󠅥󠅘󠇅󠄭󠅥󠅀󠄼󠄧󠇁󠅳󠆂︃󠆍󠇒󠅈.
  2. Classify the organization as provider, deployer, or both for each use󠇟󠇠󠇡󠇢󠄍󠄕︁󠆛󠇠󠆏󠆻󠅈󠇡󠅉󠇐󠆘󠆾󠅙󠇪󠅢󠇃󠅬󠇕󠆍󠄊󠅡󠄓󠄇︊󠇟󠅑󠄶󠄩󠄑󠅠󠅭󠅯󠇅󠄘󠅸󠅼󠇉󠆨󠄉.
  3. Provider evidence: test whether generated output carries machine-readable marking and remains detectable after your real publication and distribution paths󠇟󠇠󠇡󠇢󠅫󠆛󠄒︌󠇦󠅇󠆬󠅡󠅬󠅞󠆬󠅼󠆞󠆉󠄧󠄟󠅕󠆙󠅽󠆉󠅲󠇏󠇘󠄯󠅿󠄢󠄑󠅀󠇮󠅙󠆦󠆸󠆑󠆒󠄤󠄙󠆏󠄆︊󠅥.
  4. Deployer evidence: load each surface where the content appears and confirm a person sees the disclosure at first exposure󠇟󠇠󠇡󠇢󠅚󠅔︊󠄓󠇈󠄷󠄐󠆦󠅹󠄘󠆲󠄢󠄗󠇪󠅀󠇄︀󠆐︆󠄪󠄆󠄽󠆷󠄟󠄤󠅎󠆫󠄌󠆋󠇒󠇊︈︃󠇃󠅔󠄑󠇯󠄛󠆑󠅿. Save a dated screenshot or recording of what the viewer saw󠇟󠇠󠇡󠇢󠆴󠅌󠆨󠅋󠄏󠄖󠄝󠆹︄󠇪󠅉󠄣󠇟󠄬󠆦󠆰󠆾󠇓󠆥󠄉󠆹󠅯󠆇󠅨󠆤󠆾󠇨󠅆󠆑󠄈󠄏󠄲󠆽󠇗󠄘󠄜󠆣󠆄󠄢󠄴.
  5. Document any claimed exception, the human review used, and who holds editorial responsibility󠇟󠇠󠇡󠇢󠆤󠅥󠄤󠅧󠅷󠆂󠅢󠆋󠆼󠅦󠅘󠄧󠆎󠇑󠄏󠇃󠄜󠇠󠅐󠇄󠇎󠄶󠄝󠆲󠄕󠄳󠆳󠅸󠄯︂󠆅󠅔󠆤󠅓󠄁󠄇󠆵󠇬︅󠄫.
  6. Save dated test output, control versions, failures, and fixes󠇟󠇠󠇡󠇢󠅎︂󠄤︀󠆝󠄁󠇭󠆀︌󠄷󠅀󠄽󠅳󠄕󠅧󠆝󠇌󠇋󠆹󠄧󠅓󠇑󠆜󠆕󠇗󠅰󠅛󠄗󠆾󠆑︄󠆣󠅺󠄧󠇛󠇇󠄼󠆘󠅷󠇠.

Item 3 proves the mark survived󠇟󠇠󠇡󠇢󠅩󠄚󠅮󠇀󠆛󠄇︁󠆢󠅨󠇌󠆰︋󠇄󠄽󠅊󠄒︈󠅢󠆚󠆏󠄩󠇟󠅱󠇘󠇒󠆡󠇪󠄰󠆉󠆤󠄢󠆰󠆉󠇇󠄸󠄏󠅰󠆘󠄎󠆅. Item 4 proves a person was told󠇟󠇠󠇡󠇢󠆨󠅵󠄅󠇆󠄸󠆇󠄨󠆗󠅇󠄐󠆐󠆅󠄭󠄍󠇝󠅗︃󠄡󠄲󠄟󠄊󠆜󠄎󠇨󠄲󠆕󠆮󠆙︃󠇦󠆉󠄜󠆽󠆓󠆽󠄾󠇎󠄫󠆟󠄾. Regulators can ask for either, and one does not substitute for the other󠇟󠇠󠇡󠇢󠅢󠇩︀︎󠇢󠆘󠄙󠇌󠅬󠄍󠅎󠆓︊󠆷󠆄󠆬󠆹󠄩󠆩󠆸󠆟󠆸󠆍󠄠︃󠄒󠇍󠇕󠆻󠄹󠅧󠄱󠅔󠄛󠄭󠅁󠆰󠅍󠄲󠄹.

Use Encypher's EU AI Act readiness check to structure the first pass󠇟󠇠󠇡󠇢󠄜󠇥󠆥󠆁󠄊󠅛󠄴󠆵󠆧󠆓󠅹󠆻󠆉󠆂󠆺󠆽󠅏󠆥󠅶󠅰󠆽󠄸󠅻󠄲󠄷󠆦󠄷󠆢󠆨󠅟󠄵󠅞󠆈󠇒󠅹󠄚󠆠󠄚󠆂󠇎.

Is the Code of Practice mandatory󠇟󠇠󠇡󠇢󠅑󠆺󠄤󠇀󠄶󠆛󠅪󠆆󠆱󠆫󠄰󠅞󠆎󠇩󠄤󠄸󠄌󠄏󠅲󠇟󠄐󠄔󠅉󠇟󠆹󠇚󠅳󠇍󠄄󠄛󠅇󠄴󠅑󠅳󠆱󠅞︃󠅼󠆶󠅸?

The Code of Practice is voluntary󠇟󠇠󠇡󠇢󠄽󠅧󠇔󠄴󠅲󠅔󠄸󠄣󠅖󠇡︉󠅶󠆡󠅗󠄦󠇀󠆠󠇃󠆬󠄿󠄙󠄸󠄾󠅨󠇥󠅇󠄩󠆮󠅰󠄏󠆬󠆭󠄂󠅼󠆺󠄦︉󠇑󠇢󠄛. Article 50 is binding, and the Commission says organizations may comply through other adequate means󠇟󠇠󠇡󠇢󠄈󠄌󠄉󠅠󠆩󠅻󠄯󠅢󠇅︂︀󠄁󠆴󠇊󠆐󠆐󠄾󠅖󠅋󠄃󠄿󠅏󠄄󠄙󠅁󠇤󠄭󠄇󠆞󠄬󠆱󠅅󠆼󠆿󠆩󠄳󠆫󠄇󠄗󠅬.

  • Signatories can use the Code's measures to demonstrate compliance󠇟󠇠󠇡󠇢︇󠆿󠆽︄󠇌󠆰󠇍󠄭󠇒󠇆󠅊󠄇󠅤󠆉︈󠆤︈󠄗󠄷󠇥󠆀󠅬󠆗󠄲󠄀󠅔󠄽󠇟︁󠆺󠇈︃󠇙󠇡󠆆︀󠅗󠅚󠇞󠇚.
  • Non-signatories must show that their own measures are adequate󠇟󠇠󠇡󠇢󠅥󠅗󠄓󠆄󠅝󠇙󠄫︂󠆓󠄫󠄥︃󠅸󠄞󠇡󠇧󠄳󠇙󠆜󠄥󠅖󠇔󠅚󠄄󠅠󠆞󠆍󠅙󠅿󠄌󠆳󠄚󠇭󠆏󠆹󠆉󠆱󠄘󠄐󠅢.
  • The Code does not replace the Act or the Commission's guidelines󠇟󠇠󠇡󠇢󠄡󠄋󠆼󠅩󠄶󠆞󠅄󠆚︋󠇆︈󠆦󠄎󠇃󠇐󠇝󠆟󠆡󠅑󠄫󠅦󠄥︌󠅚󠆑󠄗󠄵󠇟󠆞󠇤󠄶󠅒󠇃󠆭󠆌󠅞󠅷󠆑󠇁󠅢.

The Code's structure mirrors the two duties above: Section 1 covers provider marking and detection, Section 2 covers deployer labelling of deepfakes and public-interest text󠇟󠇠󠇡󠇢󠅍󠅅󠅿󠅅󠅧󠇉󠅥󠆱󠆹︄󠄴󠅵󠆩󠆍󠇧󠆏󠄗󠄭󠅅󠆣󠆁󠄽󠅵󠆘󠅲󠆲󠄝󠄤󠆫󠆒󠇈󠅡󠄀󠅂󠆊󠄴󠆔󠆢󠄴󠆒.

For marking, the Code recommends two techniques used together: digitally-signed metadata such as C2PA provenance (sub-measure 1.1.1) and imperceptible watermarking (sub-measure 1.1.2), with fingerprinting or logging as an optional third layer (sub-measure 1.1.3󠇟󠇠󠇡󠇢󠅈󠆃󠇡󠇜󠅓󠆤󠇦󠄵󠄗󠇖󠅵󠇐󠇮️󠆝󠅥󠇞󠄇󠄾︅󠅄󠇄󠆲󠆱󠅵󠄬︊️󠄆󠆜󠄦󠆇󠆎︃󠆯︊󠄑󠄤󠆪󠄞). The layering is deliberate󠇟󠇠󠇡󠇢󠅶󠆨󠇋󠅨󠅝󠆷󠆛󠇪󠅧󠅷󠅾󠅋󠄺󠅆󠆖󠆅󠆾󠅧󠆓󠅰󠅷󠆙󠄌󠄂󠆰︉󠄸󠆃󠆋󠇒󠅎󠄒󠆲󠇮︎󠇮󠆅󠅨󠆷󠄗. The Code acknowledges that no single technique meets all four statutory criteria on its own: signed metadata carries rich, verifiable provenance but can be stripped in transit, while watermarks survive some transformations but carry less information󠇟󠇠󠇡󠇢󠅐󠇍󠄐󠆗󠅵󠆭󠅦󠅷󠆚󠇁󠄋︇󠇉󠄝󠄧󠄲󠅡︀󠆍󠅘󠅻󠅭󠄏󠅄󠄃︁󠅀󠅶󠄬︆󠄾󠅅󠇆︇️󠆄󠄹󠅥󠄳󠇬. Two modalities cover each other's failure modes󠇟󠇠󠇡󠇢󠆤󠆻󠅮󠅐󠅓󠅻󠄏󠅬󠄫󠇉󠆬󠄄󠅖󠇇󠅰󠆍󠄂󠆕󠅐󠄝󠄩󠇬︂󠇏󠄚󠆣󠆋󠆢︉󠆺󠆆󠅗󠅳󠆌󠇥󠆖󠄮󠆄󠆵󠄿.

The Commission published the final Code and its status on June 10th, 2026󠇟󠇠󠇡󠇢󠄋󠄪󠄁󠆀︊󠆶󠅛󠇃󠄁󠅌󠆆󠆧󠇟󠅬󠅑󠆱󠆵︎󠇫󠅰󠆏󠅴󠇭󠆯󠅦󠇉󠅳󠄒󠆢󠆴󠆾󠄄󠆋󠅢󠄓󠇞︍󠇛󠅧󠅥.

Does Article 50 require C2PA󠇟󠇠󠇡󠇢󠄖︇󠆷󠆊︄󠅃󠄒󠇟︆󠆮󠅄󠄚󠅩󠆪︋󠇯󠅊󠅁󠅉󠄻󠄨︄︊󠅀󠆏󠅩󠅓󠅞󠅑︀󠄡󠇈󠆈󠄂︁󠅰󠆌󠅜󠅐󠆀?

Article 50 is technology-neutral and does not mandate C2PA󠇟󠇠󠇡󠇢󠄟󠆠󠆭󠅿󠅿󠆘󠄜󠇮󠄀󠆚󠇚󠅮󠅐󠆁󠄼󠄋󠆍󠅯󠅭󠇨︃󠆔󠇀󠆇󠇈󠆯󠄅󠆻󠆓󠄎󠄘󠆊︌󠆣󠆾󠅳󠄡󠆲󠇋󠄫. It creates a machine-readable marking obligation which C2PA can satisfy when the implementation fits the system and content type󠇟󠇠󠇡󠇢󠆪󠆊󠆣󠆪󠇤︂󠇋󠄾󠅀󠇢󠆹󠆶󠄢󠄑󠆏󠇗󠇯󠆉󠆺󠄳󠅽󠆓󠇙󠄚󠇍︅︌󠅲󠄾󠅽󠇤󠅎󠆕󠄟󠇐󠄵󠅼󠆠󠆄󠄦.

  • A C2PA manifest covers a document as a whole󠇟󠇠󠇡󠇢︄󠇎󠄊󠅊󠇨󠆲󠅥󠇖󠅏󠄋󠆲󠆍󠅾󠄩󠅺︈󠆫󠇯󠅍󠄶󠆠󠄏󠄯️󠇀󠆾︃󠆪󠆪󠇇󠇐󠄴󠅏󠆲󠄒󠄙󠆗󠇢󠄤󠄴. Encypher's proprietary technology enables sentence-level attribution󠇟󠇠󠇡󠇢󠄴󠇯󠄢󠆮󠆡󠆤󠅟󠇍󠆼󠄇󠅋󠄎󠆻󠄇󠄰󠅀󠆇󠄫󠇓󠅹󠄆󠆲󠇀󠄷󠅏󠄛󠆅󠆑󠆷󠄊󠆝︅︎󠇉󠅁󠇓󠅙󠄢󠅽󠇁.
  • Provenance can show source and integrity claims󠇟󠇠󠇡󠇢󠅎󠆯󠇐󠇧󠆏︄󠆮󠅁󠄦󠅋󠇔󠆹󠅣󠇞︍󠇚󠆆󠇔︃󠅟󠅁󠅶󠄻󠅋󠆛󠅢󠇕󠄒󠅲󠄐󠄏󠆺󠄙󠆲󠅖󠄰󠇩󠅼󠄋󠆛. It does not prove that the content is true or guarantee legal compliance󠇟󠇠󠇡󠇢󠆬󠆐󠅟󠅟󠄳󠄂︉󠅚󠆘󠅥󠅨󠆩󠆺󠇇󠆥󠅴󠄕󠆐󠆃󠇓󠆀󠄇󠆗󠅪󠅗︈󠆆󠅍󠄣󠇙󠇣󠅑󠆟󠅎󠆟󠆤󠄕󠅊󠅖󠆞.
  • Downstream tools can strip or damage markers, so teams must test real publication and distribution paths󠇟󠇠󠇡󠇢󠆄󠅉󠅱󠆷󠅆󠅦󠅌󠅕󠆉󠆘󠅢󠄆󠄊󠆩󠅖󠅫󠄠󠆪󠄣󠆻󠇖󠅛󠄡󠄃󠅬󠄾󠄓󠄹󠇪󠇝󠆥󠇖󠅨󠄪󠅊󠅳󠅈󠆊󠇮󠄏. The Code's two-modality recommendation exists for exactly this reason󠇟󠇠󠇡󠇢󠄎󠇯󠇌󠆰󠅤󠅥󠇎󠆱󠅂󠄁󠇙󠆅󠆥󠄱󠇈󠅕󠆢󠇜󠄈󠄾󠅬󠄇󠆂󠆋󠆯󠇟󠆲󠅰󠇝󠄦󠆙󠇙󠅇󠆽󠄽󠄮󠇇󠇉󠆣󠄒.
  • For deployers, provenance is the detection substrate: a surface that reads the mark can render the Article 50(4) disclosure automatically instead of relying on manual labeling󠇟󠇠󠇡󠇢󠄆󠆰󠅾󠄖︎󠄇󠅘󠄗󠆕󠅯󠇋󠄱󠄕󠆄󠆿󠅟󠅓󠇡󠇖󠇁󠄮󠅇󠆬󠆡󠅲󠅺󠆠󠆛󠆄󠅓󠇙󠆇󠅷󠇈󠄨󠇙󠄘󠅲󠆷󠆱.

Encypher authored the C2PA unstructured-text provenance appendix - Section A.7 in C2PA 2.3, Section A.8 in C2PA 2.4󠇟󠇠󠇡󠇢󠅍︄󠆛󠄾󠇈󠄆󠆂󠆫󠅂︁󠄲︆󠇟󠆨󠄋󠆂󠆀󠆀󠄹󠄪󠅩󠄎󠅢󠄾󠄀󠆪󠇢︃󠅉󠅎󠅓󠇙󠅀󠆔󠅏󠅋󠄇󠇊󠆒󠇣. For more context, read our May 12th preparation guide and EU AI Act content provenance hub󠇟󠇠󠇡󠇢󠄌󠄻󠅂󠇪󠇃󠅵󠇅󠆉󠄔󠄯󠅗󠅧󠄇󠅛󠅴󠆕󠄩󠇊󠇕󠄲󠅅󠄦󠇖󠆛󠇬󠆙󠆒󠄱󠄯󠇡󠆺󠅍󠇜󠄨︃󠇍󠅡󠅂󠅸󠆇.

Get the weekly Encypher briefing

Analysis of AI copyright, content provenance, and publisher rights - written from inside the C2PA standard-setting process. No filler.

Share this field note