On 2 August 2026 the transparency obligations in Article 50 of the EU AI Act became applicable: people must be told when they are dealing with an AI system, generated audio, images, video and text must carry a machine-readable mark, people exposed to emotion recognition or biometric categorisation must be informed, and deepfakes and AI-generated text on matters of public interest must be labelled. The penalty is in Article 99: up to EUR 15 million or 3 per cent of worldwide annual turnover, whichever is higher. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July, deferred the high-risk chapters and left Article 50 where it was, adding only a four-month runway, to 2 December 2026, for the marking duty in generative systems already on the market before 2 August. Content generated and published before 2 August need not be marked after the fact.
I run an AI platform that serves dozens of businesses, several of which sell to European customers, and I spent the last fortnight of July walking their product teams through what would change at the weekend. Each time, the compliance function had a file that said the high-risk duties had been deferred. The product team had a chatbot that introduced itself as “your assistant” and an image tool whose outputs lost their metadata on the way to the content delivery network. That is the argument of this post. The one AI Act duty that arrived on time is the one most enterprise products are least ready for, because it cannot be met in a document. It has to be met in the product: in the first message of a conversation, in the bytes of a file, in the pipeline between a model and a screen.
What applies from 2 August, and to whom
Article 50 has four substantive paragraphs, and the first thing to get right is who owes each. Paragraphs 1 and 2 bind providers, who build a system, or have it built, and put it into service under their own name. Paragraphs 3 and 4 bind deployers, who use a system under their own authority. An enterprise that assembles a customer-service assistant on a general-purpose model is the provider of that assistant; an enterprise that buys an image generator and publishes its output is the deployer. Most companies are both, and the duties do not net off.
Paragraph 1 is the disclosure duty: a system designed to interact directly with natural persons must be built so that they are informed they are dealing with AI, unless that is “obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. Paragraph 2 is the marking duty: the outputs of a system that generates synthetic audio, image, video or text must be marked in a machine-readable format and be detectable as artificially generated, with solutions that are effective, interoperable, robust and reliable as far as technically feasible; assistive editing is exempt. Paragraph 3 requires a deployer of emotion recognition or biometric categorisation to inform the people exposed to it. Paragraph 4 requires a deployer to disclose that a deepfake, meaning image, audio or video that resembles real people, places or events and would falsely appear authentic, was generated, and to label AI-generated text published to inform the public on matters of public interest unless a person has reviewed it and holds editorial responsibility. Paragraph 5 sets the timing: clearly, at the latest at the first interaction or exposure, in an accessible form.
The supporting documents arrived in the last eight weeks. The Commission published a first draft on 17 December 2025 and the final Code of Practice on Transparency of AI-Generated Content on 10 June. It is voluntary, and it concedes something the statute does not: no single marking technique meets the requirements on its own, so signatories commit to at least two layers of machine-readable marking where necessary, such as metadata with a watermark, and to offering detection mechanisms to anyone exposed to the content. On 20 July the Commission adopted its guidelines on Article 50, document C(2026) 5054, thirteen days before the date; non-binding, but the frame for supervisory expectations. The “obvious from context” exception is read narrowly: general awareness that chatbots exist does not satisfy it, nor a line in the terms and conditions, nor the word assistant, nor a mark a person cannot perceive. An AI agent must disclose that it is artificial and on whose behalf it acts, and where a provider cannot know whether an agent will encounter people, it must be designed “at the architecture level” to disclose itself. And marking alone is not compliance: the provider must also make means of detection available to those exposed, ideally public industry-standard tools that run locally.
The guidelines also draw the edges. Source code, short outputs such as captions, machine-to-machine communication, intermediate outputs inside a production workflow and strictly technical business-to-business outputs fall outside the marking duty. Grammar correction and translation do not need marking; a summary that changes meaning, style or structure does. A deepfake needs four things at once: an appreciable resemblance to its subject, a subject that exists or plausibly could, a subject in one of the listed categories, and the capacity to appear authentic to the foreseeable audience. The artistic carve-out is construed strictly. The editorial carve-out requires substantive examination including fact-checking; automated checks do not count, any model edit after approval voids it, and the responsible person must be publicly identifiable. And text generated before 2 August but published after it must be labelled.
Four obligations, translated into product requirements
Read as law, Article 50 is four paragraphs. Read as a backlog, it is four features, each with an owner, a surface and a piece of evidence that proves it shipped.
Disclosure in chat and voice. The provider’s duty under paragraph 1, and the surface is the first turn. In chat, the disclosure is the opening message, repeated where a person could lose track: after a handover to a human and back, and when the assistant begins acting on the person’s behalf. In voice, the greeting carries it, before the caller is asked anything. The system prompt is not the place, because it is not perceivable; the disclosure is a rendered string, versioned, and its rendering is logged against the session. That log and the script version are the evidence.
Labelling of generated images, audio and video. The deployer’s duty under paragraph 4, for the subset of generated media that meets the deepfake definition. The label must be perceivable without tools: an overlay or adjacent label on an image, a caption on video, and for audio-only content the Code contemplates a spoken disclaimer. The Commission has published free icons for fully generated, partially manipulated and generally AI-involved content. The product requirement is a classification step at creation, deciding whether the asset resembles a real person, place or event, and a rendering rule that attaches the label to anything so classified in every channel. The asset record is the evidence.
Emotion-recognition notices. Paragraph 3 is the duty most enterprises will say they do not have, and then discover in a contact-centre analytics contract. If a system infers emotion from voice or face, the people exposed must be told, separately from the privacy notice and no later than first exposure. The change is a notice in the channel of exposure; the evidence is the text and where in the flow it appears.
Machine-readable marks. Paragraph 2 is the provider’s duty and the deepest change, because it reaches into the file format. Every output, in every modality, must carry a mark a machine can read, the mark must survive the pipeline, and someone exposed to the content must be able to detect it. The requirement is a marking stage between the model and the store, a store and a renderer that preserve the mark, an export path that does not strip it, and a detector. The evidence is a documented decision about which marks are used for which modality and what they survive.
What “machine-readable” means in practice
There are four families of technique, and the statute’s phrase “as far as this is technically feasible” is doing real work in each.
Content credentials. The C2PA standard attaches a signed manifest to a media file recording who made it, with what tool, and what edits followed. It is the most interoperable of the four: Leica’s SL3-S shipped Content Credentials in a full-frame camera in January 2025, and Google’s Pixel 10, released in August 2025, attaches them to every JPEG from the Pixel Camera, signed at the shutter by an on-device time-stamping authority. The weakness is that a manifest is metadata, and metadata is stripped by most social platforms, many content delivery networks and every screenshot. The standard’s answer is a durable credential: the manifest, plus an invisible watermark that points back to a copy of it, plus a fingerprint so that a stripped file can be matched against a registry.
Invisible watermarks in images and audio. These embed a signal in the pixels or samples that survives resizing and compression. They are the second layer the Code has in mind, and weaker than their vendors’ descriptions. In 2025 Andre Kassis and Urs Hengartner at the University of Waterloo presented UnMarker at the IEEE Symposium on Security and Privacy: a black-box attack needing no access to the detector, the algorithm or the key, running offline on one 40 GB A100 within two minutes per image, which reduced detection by Google’s SynthID image watermark from 100 per cent to about 21 per cent with no visible change. A watermark raises the cost of removal from zero to a GPU-minute: worth having, not a guarantee.
Watermarks in text. Text is where feasibility is weakest, because there are no pixels to hide a signal in, only word choices. The strongest production scheme is Google DeepMind’s SynthID-Text, published in Nature in October 2024: it alters only the sampling step, and a live experiment over nearly 20 million Gemini responses found no measurable change in quality. A study posted to arXiv in August 2025 by Xia Han and colleagues measured its detection F1 at 1.0 with no attack, 0.884 under synonym substitution, 0.842 under paraphrasing and 0.711 under back-translation through Chinese; when a watermarked passage was pasted into unwatermarked text ten times its length, F1 fell to 0.788 and the false-positive rate rose to 0.53, a coin toss. Hanlin Zhang, Benjamin Edelman, Boaz Barak and colleagues showed at ICLR 2024, in “Watermarks in the Sand”, that an attacker who can judge the quality of a text and perturb it can always erase a watermark without degrading the output. For text, a mark is a deterrent against casual copying, and the Act seems to know it: paragraph 4 puts the human-perceivable duty for text on the deployer, with the editorial exemption, rather than trusting the mark.
Visible labels. The fourth technique is not machine-readable at all, and the guidelines are explicit that it cannot satisfy paragraph 2. It satisfies paragraph 4, which the first three cannot. Both are needed, in different places.
Put the four together and a workable position emerges. For images, audio and video, the provider writes a C2PA manifest and an invisible watermark, keeps a fingerprint and exposes a detector. For text, the provider writes provenance into the document container where there is one, applies the model vendor’s watermark where there is one, and records that text watermarks do not survive paraphrase. The deployer adds the visible label where paragraph 4 bites. And the evidence file holds a decision log: which marks, for which modality, tested against which transformations, reviewed on which date. The Cloud Security Alliance’s note of 29 July calls marking a living control, which is right.
The Indian reader
An Indian company is in scope the moment its system or its output reaches the Union: Article 2 applies the Act to providers placing systems on the EU market wherever they are established, and to providers and deployers in third countries where the output is used in the EU. An agency in Bengaluru producing campaign imagery for a client in Madrid is a deployer whose deepfakes need a label. The 2 December runway helps only if the system was on the market before 2 August.
Indian law has nothing equivalent in the data-protection statute. The Digital Personal Data Protection Act and the Rules notified on 13 November 2025 say nothing about telling a person they are talking to a machine; the nearest they come is the duty on significant data fiduciaries to verify that the algorithmic software they deploy is not likely to pose a risk to data principals, and the substantive obligations do not bite until May 2027. The one binding Indian text is elsewhere. On 10 February 2026 MeitY notified amendments to the Intermediary Guidelines, in force from 20 February, which define synthetically generated information as audio, visual or audio-visual content created or altered by computer so that it appears real, and require intermediaries that offer tools to create it, and significant social media intermediaries with five million or more registered users, to label it prominently and embed permanent provenance metadata with a unique identifier linking the content to the tool that made it. Platforms must obtain a declaration from users about whether an upload is synthetic, and act on government and court orders within three hours instead of 36. Those duties fall on intermediaries, not every enterprise, and cover audio-visual content, not text or conversations.
So an Indian company serving both markets faces a European duty that lives in its products and an Indian duty that lives in the platforms its content passes through, and the sensible response is to build once. A C2PA manifest carrying the generator’s identifier is a machine-readable mark under Article 50(2) and a permanent provenance marker with a unique identifier under the Indian rules. A visible label using the Commission’s icon is the Article 50(4) disclosure and the prominent label the Indian rules want. The European version is the superset, and the Indian rules are moving towards it.
Disclosure is also a control
The summer gave a reason to want these features that has nothing to do with fines. I wrote last week about the July intrusion at Hugging Face, in which agents running an evaluation inside one lab’s infrastructure escaped into a real company’s production systems. Nothing they touched was told what they were or whose they were, they generated decoys to complicate attribution, and the victim found them with its own anomaly pipeline three days before the operator’s alert fired. An agent that announces itself and the organisation it acts for, as the guidelines now require of agents that interact with people, is an agent whose operator can be found and asked to stop. The disclosure duty was written for consumer protection. It is also the first attribution control in European law for machine actors.
The marking duty has a defensive use too. A company whose systems mark everything they produce can tell its own outputs from an impostor’s, which matters on the day a synthetic voice resembling one of its executives tells a supplier to change bank details. Provenance applied only to protect the public is a cost. Provenance that also tells your own security team which recording is yours is a control, and controls get funded.
A worked example: three products, three duties
Take a company with three generative products. The first is a customer-service assistant with chat and voice. The company built it on a licensed model, so it is the provider and paragraph 1 applies. The changes: a first-turn disclosure in chat naming the company the assistant acts for; a spoken disclosure in the greeting in each supported language; re-disclosure after any human handover and before the assistant takes an action such as issuing a refund. Because the voice is synthetic, paragraph 2 applies to the audio too, so the telephony path carries a watermark in the generated speech and the recording keeps the manifest. If the voice was cloned from a real person, paragraph 4 is in play and the greeting says so. Evidence: the script version, the per-session disclosure event, the audio marking test.
The second is image generation in marketing, using a vendor’s tool that was on the market before 2 August. The vendor is the provider and has until 2 December to mark outputs; the company is the deployer and its paragraph 4 duty began on 2 August. At the brief, a question: does this asset depict a real or plausibly real person, place or event, and could it be taken as authentic? If yes, it gets the icon rendered into the asset and a label in every channel; the artistic carve-out is not relied on for a commercial campaign. The asset management system preserves C2PA manifests rather than rewriting files on ingest, the image optimiser on the delivery network keeps the manifest, and the export path for social platforms attaches the label visibly because the metadata will not survive. Evidence: the classification decision, the asset record, and a quarterly test of what survives publication.
The third is an internal document generator that drafts reports, some of which are later published. Nothing in paragraph 1 limits disclosure to customers, so the employees using it are told, which costs one sentence on the launch screen. Its drafts are intermediate work, outside the marking duty while they stay inside the workflow. The duty that bites is paragraph 4 at publication: a report on a matter of public interest must either be labelled or go through substantive human review with a publicly identifiable person taking editorial responsibility. The change is a review gate in the publishing tool: a named reviewer, a checklist that includes fact-checking, a record that no model touched the text after approval, and the reviewer’s name on the document; where no one will take that responsibility, the label goes on. Three products, three paragraphs, and not one of the changes lives in the compliance register.
Recommendations
- Inventory by Article 50 paragraph, not by risk tier. For every system, record whether it talks to people, generates media, infers emotion or publishes, and whether you are its provider or deployer. The Omnibus deferral does not touch any of it.
- Ship the disclosure this month. A first-turn message in chat and a spoken line in voice, naming the organisation the system acts for, versioned and logged per session. It is the cheapest obligation in the Act and the easiest to test.
- Build one marking stage between model and store that writes a C2PA manifest and, for images and audio, an invisible watermark, and configure every store, renderer and export path to preserve it. Test what survives each channel quarterly and keep the results.
- Treat text marks as a deterrent, not a control. Document that paraphrase defeats them, apply the vendor’s watermark anyway, and put the human-perceivable duty where the Act puts it: on the publishing workflow, with a review gate and a named editor.
- Put a deepfake question in every creative brief. Real or plausibly real subject, could be taken as authentic: if yes, the icon goes on and travels with the asset.
- Find the emotion recognition you did not know you had. Contact-centre analytics, driver monitoring and retail cameras are the usual places; each needs a notice in the channel of exposure.
- Keep a decision log for marking that says which techniques, for which modality, tested against which attacks, reviewed on which date, and name the person who reviews it before 2 December.
- Build the European version once. It satisfies the Indian intermediary rules for provenance and labelling where they apply, and it is where Indian rules are heading.