Europe’s new transparency rules for AI-generated content have been enforceable since 2 August 2026. Yet “AI watermarking” is a misleadingly simple name for what Article 50 of the EU AI Act now requires.
AI system providers must build machine-readable marking into certain outputs. Professional users must give people a clear, human-facing disclosure in narrower cases such as deepfakes and unreviewed public-interest text. Chatbots, emotion recognition and biometric categorisation bring their own notice duties.
This is a reporting explainer, not legal advice. The obligations turn on facts such as who controls a system, how content was produced, what it depicts and why it was published.
There is no single EU watermark
The starting point is the AI Act itself. Article 50(2) says providers of AI systems that generate synthetic text, audio, images or video must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical method must be effective, interoperable, robust and reliable as far as technically feasible.
That is primarily a product-design obligation. It sits with the company that develops an AI system, or has one developed, and places it on the EU market under its name. It can also reach providers outside Europe when their systems’ outputs are used in the EU.
A machine-readable mark is not necessarily a visible logo stamped across an image. It may involve metadata, content credentials, provenance information or a signal embedded in the output. The point is that software should be able to identify the artificial origin reliably. An ordinary reader may never see that layer.
The Commission’s final Article 50 questions and answers also place several outputs outside this duty, including source code, short strings of characters, purely machine-to-machine outputs and some material kept inside closed production environments. Standard editing and assistance that do not substantially alter the input or its meaning can also fall outside the marking requirement.
Visible labels belong to a different obligation
The public-facing duty usually sits with the deployer: the business, authority, publisher, freelancer or other professional user operating the AI system under its control. Employees working under a company’s instructions are not treated as separate deployers. Personal, non-professional use is generally excluded, although regular economic activity can bring an individual into scope.
Deployers must clearly disclose deepfakes. The Act defines these as AI-generated or manipulated images, audio or video that resemble existing people, objects, places, entities or events and would falsely appear authentic or truthful. The Commission says the label must be understandable and perceivable without special tools, and shown by the time a person first encounters the content.
This is why an invisible provider mark does not satisfy a deployer’s visible-disclosure duty. They solve different problems for different audiences. One helps detection systems inspect a file; the other tells a person what they are seeing or hearing.
The rule is contextual rather than a blanket label on every synthetic image. Resemblance, the message, likely audience and setting all matter. Evidently artistic, fictional, satirical and similar works receive a lighter treatment: disclosure is still required where the material is a deepfake, but it can be delivered in a way that does not spoil the work.
AI-written public-interest text has a major exception
Professional users must also label AI-generated or manipulated text published to inform the public about matters of public interest. The Commission describes that territory broadly, covering politics, public administration, justice, rights, safety, health, the environment and economic, financial, scientific or cultural developments that may be part of public debate.
But the Act does not require a label when the text has undergone human review or editorial control and a person or organisation holds editorial responsibility for publication. That exception is highly relevant to newsrooms, research organisations, corporate communications teams and any company using generative tools to help prepare public information.
The final guidance makes clear that a spelling pass or grammatical check is not enough. Human review means examining the substance with relevant knowledge and professional judgement. Editorial control means someone with authority can approve, alter or reject the substance, including by checking facts and sources. Editorial responsibility means a natural or legal person ultimately accepts legal responsibility for publication.
In practice, “a human was in the loop” is not a compliance plan. Organisations relying on this exception need a real approval chain and evidence that the review was substantive. The dividing line is governance, not whether a person clicked publish.
The EU icons are optional
The Commission has released a set of icons for labelling AI-generated content, including versions for generated and partially modified material. They offer a common visual language, but deployers are not required to use these particular graphics. They remain responsible for making a disclosure clear, distinguishable, accessible and correctly timed.
The same distinction applies to the Code of Practice on Transparency of AI-generated Content. The legal duties are mandatory; signing the code is voluntary. The Commission and AI Board have assessed the code as an adequate route for demonstrating compliance, but adherence is not conclusive proof that every use is compliant. Non-signatories must show that their alternative measures are adequate.
Not everything changed on 2 August
Article 50 is now in application, but there are transition details. Generative AI systems placed on the market before 2 August receive a limited grace period until 2 December 2026 for the provider-side machine-readable marking duty. Content generated and already made available before 2 August does not need to be labelled retrospectively.
That grace period does not postpone every transparency obligation. New systems and in-scope professional deployments must be assessed against the rules now. National market-surveillance authorities will handle most enforcement, while the AI Office has a narrower role for systems within its remit. Available fines can reach €15 million or 3 per cent of worldwide annual turnover, with proportionality for smaller businesses.
Technical reality will complicate enforcement. Metadata can be stripped when a file is copied. Screenshots break provenance chains. Compression and editing can weaken embedded signals. Text marking is harder than image labelling because a paragraph can be copied, retyped or lightly rewritten without preserving its origin data. The Act recognises technical feasibility and the state of the art, but those qualifications will not produce identical answers across every medium.
The new compliance map
Our July account of the AI Act timetable focused on the political sequence: lighter transparency duties arriving while many high-risk rules were delayed. The final guidance now makes the operational sequence clearer.
Providers need to decide what their systems generate and how machine-readable provenance will survive ordinary use. Professional deployers need to inventory deepfakes and public-interest text, decide when visible disclosure applies, and document any reliance on human review. Publishers need to distinguish substantive editorial responsibility from a cosmetic approval step. Procurement teams need to know whether a vendor’s marking travels with exported content.
Europe’s watermarking era has begun, but it is not a rule that says “put an AI badge on everything”. It is a chain of responsibility running from system design to publication and first exposure. The organisations most likely to stumble are not those that missed a logo. They are those that never worked out which link in that chain belongs to them.