Skip to main content
AI Watermark Removal

Regulation

EU AI Act and AI Watermarking: Article 50 Explained

Article 50 of the EU AI Act names no watermarking technology. Not C2PA, not SynthID, nothing at all. It just requires outputs to be marked in a machine-readable format and detectable as artificially generated, as far as technically feasible, and leaves the how to providers. That rule took effect on 2 August 2026, carries fines of up to 15 million euros or 3 percent of global turnover, and has already changed how Claude, Gemini, and dozens of other products behave everywhere, not only inside the EU.

By Rowan ValePublished Revised Sources verified Official announcement

Key takeaways

  • Article 50's transparency rules took effect 2 August 2026. A separate transitional deadline, 2 December 2026, covers certain Article 50(2) marking duties for systems already on the market before that date, and that grace period comes from the EU's later Digital Omnibus reform, not the Act's original text.
  • Getting it wrong is expensive: fines up to 15 million euros or 3 percent of global annual turnover for companies, up to 750,000 euros for EU institutions.
  • The Commission's Guidelines, adopted 20 July 2026 as C(2026) 5054 final, close the gap the article leaves: marking on its own is not compliance. They state that fulfilling only one element, "for machine-readable marking of outputs without the means for their detection being available," "will not suffice to comply with that provision," and that a provider must ensure the means of detection are available to "the persons potentially exposed to the content."
  • The same Guidelines define machine-readable, which the article never does: marks structured so software can "easily identify, recognise and extract them without human intervention." Watermarking is one option among watermarks, metadata identifications, cryptographic provenance methods, logging methods, and fingerprints, and providers may combine them.
  • The Code of Practice permits the one restriction that matters most for text, and only for a while. Detection of free-form-text watermarks "may be restricted to verified expert users," limited in time, while detection must be free of charge and unrestricted for regulators, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations.
  • About 190 organizations, including Anthropic, Google, Meta, Microsoft, and OpenAI, signed the EU's Code of Practice on AI-generated content by the end of July 2026. It names no vendor product (not C2PA, not SynthID), but it is more prescriptive than "technology-neutral" suggests: it commits signatories to an imperceptible watermark, exempts text under 200 tokens, and expects two marking layers for media but only one for free-form text, because free-form text cannot carry metadata.
  • Signing is not a safe harbour. The Commission concluded on 8 July 2026 that the Code adequately covers the Article 50(2), (4) and (5) obligations, the AI Board adopted its Adequacy Assessment the next day, and the Commission states in the same breath that "Adherence to the code does not constitute conclusive evidence of compliance with these obligations."
  • Providers mark outputs. Deployers separately disclose deepfakes and certain public-interest AI text, and lawyers still disagree on what counts as genuine human editorial review.
  • Anthropic's Claude marking rollout says its watermark applies "wherever Claude is offered, worldwide." A regional compliance deadline is already the reason Claude's output looks the way it does no matter where you live.

Regulatory timeline

EU AI Act Article 50 marking deadlines

  1. 2026-08-02

    In effect · Transparency rules apply

    Article 50 provider marking and deployer disclosure duties took effect. Providers must ensure synthetic audio, image, video, or text output is marked in a machine-readable format and detectable as AI-generated, as far as technically feasible.

  2. 2026-12-02

    Upcoming · Transitional deadline

    Marking deadline for certain Article 50(2) obligations on systems already on the market before August 2, 2026. Systems placed on the market on or after that date had no grace period.

What this does not settle

Article 50 is technology-neutral: it requires machine-readable marking "as far as technically feasible," not one named technology. Whether a given provider's current marking (or lack of it) satisfies the obligation is a separate, provider-specific question. See the provider tracker pages for what is actually documented.

What does EU AI Act Article 50 require of providers?

Official announcement

Article 50's provider duty quoted exactly, followed by the five output categories it exempts from marking altogether.

Article 50 tells providers, general-purpose AI providers included, that synthetic audio, image, video, and text output has to be marked in a machine-readable format and detectable as artificially generated or manipulated. The qualifier is "as far as technically feasible."

It deliberately names no vendor product. Signed C2PA-style metadata, a statistical watermark like SynthID, or something nobody has built yet could all satisfy it, so long as the result is genuinely effective and interoperable.

The obligation also carries a specific exemption list. Marking is not required for:

  • Short sequences of numbers, symbols, or letters
  • Source code
  • Machine-to-machine output no human ever sees
  • Closed-loop industrial processes, short of their final output
  • Standard editing-assistive functions

That last category is the loosest of the five and the one most likely to be argued over. For the full breakdown and why the rule stays technology-neutral, see the machine-readable AI marking page.

What do the Commission's Guidelines require?

Confirmed

Adopted 20 July 2026 as C(2026) 5054 final. They interpret Article 50 rather than change it, and they are far more specific than the article about detection.

The Guidelines require two things together, marking and available detection, and they define what machine-readable means, which Article 50 never does. The Commission adopted its Guidelines on the Article 50 transparency obligations on 20 July 2026, as document C(2026) 5054 final. They call themselves "a first interpretation with practical examples" rather than new law, and they answer several questions the article leaves open.

Start with what machine-readable actually means, because the article never defines it. The Guidelines do: marks must be "structured in a way that allows software applications to easily identify, recognise and extract them without human intervention," and perceptible labels are "not excluded as a complementary measure" on top of that.

Watermarking is one technique among several, not the mandated one. Providers "may rely on a single marking technique or a combination of techniques," and the Guidelines point at Recital 133's examples: watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity, logging methods, and fingerprints.

The detection duty has a named audience. The Guidelines say the provider "is obliged to ensure that the means of detection are available to the persons potentially exposed to the content," and that detection should produce human-readable results indicating whether content was AI-generated or manipulated.

There is also a preference about whose detector it should be. Providers "must rely on publicly-available industry standard detection solutions" that any third party can implement, ideally executable locally on the device; a provider's own or a third party's detector is permitted where such standards do not yet exist, "in particular at the initial stage of the implementation of Article 50(2) AI Act for watermarking technologies."

That fallback is explicitly temporary. The Guidelines say the possibility "should be limited in time until harmonised standards and a standardised provider-agnostic interoperable detection solution emerge that is secure, privacy-preserving and locally executable."

Two timing points close the document, and both get misread. Systems that are partly interactive and partly generative get the 2 December 2026 transitional period "only with regard to the marking obligation under Article 50(2)," while the duty to disclose that a person is interacting with an AI applied from 2 August 2026 with no grace period at all.

And nothing has to be marked backwards. Content generated or manipulated before 2 August 2026 "do not need to be marked or labelled retroactively," though text generated before that date and published on or after it does need labelling.

Who is allowed to check whether text is AI-generated?

Confirmed

The Code of Practice permits a gated detector for free-form text, for a limited time, and names the groups that must get free and unthrottled access anyway.

Under the Code of Practice, free-form text detection may be restricted to verified expert end-users, while regulators, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations must get free and unrestricted access. The Code of Practice draws a distinction the Guidelines do not: text detection may be gated. In its own words, signatories "may restrict access to detection mechanisms associated to watermarking techniques for free-form text to the extent that they have a lower level of reliability and robustness and that they may produce misleading or low-confidence results."

The reasoning is that a weak result shown to the general public misleads more than it informs, while the same result is useful to someone trained to read it. So the Code routes it to "verified expert end-users with a legitimate need" under "appropriate access controls and safeguards."

That permission is time-limited on the Code's own terms. Any restriction "will be limited in time until more reliable and robust detection mechanisms have emerged and have been adopted as the state of the art for detection mechanisms for the watermarking of free-form text."

The Code also names who cannot be charged or throttled. Signatories "will make the detection solution available free of charge" and "will always provide free access to their detection solution, without any restriction on the volume of requests," to:

  • Competent market surveillance authorities and other regulators
  • Law enforcement authorities
  • Media and fact-checkers
  • Trusted flaggers
  • Independent researchers
  • Educational and research institutions
  • Civil society organisations

The Code is voluntary, and the Commission has assessed it rather than enacted it. On 8 July 2026 the Commission concluded that it "adequately covers the obligations provided for in Articles 50(2), (4) and (5) AI Act and facilitates their effective implementation," and the AI Board adopted its Adequacy Assessment the following day, 9 July 2026.

Read the caveat the Commission attaches to its own opinion: "Adherence to the code does not constitute conclusive evidence of compliance with these obligations." Signing buys a presumption and a smoother enforcement posture, not immunity.

About 190 organisations had signed by the end of July 2026, and the Commission names Anthropic among its examples of Section 1 signatories, alongside Aleph Alpha, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI, and Synthesia.

What must deployers disclose under the EU AI Act?

Official announcement

Here's the split that trips up most compliance checklists: the company that marks the output is usually not the company that owes the disclosure.

Deployers have to disclose deepfakes, and disclose AI-generated or manipulated text published to inform the public on matters of public interest. Providers mark; deployers disclose. They can be two entirely different companies, and one piece of content can trigger duties owed by both at once.

There are exceptions for human review and editorial responsibility.

Law firm Greenberg Traurig's reading of the Commission's own guidance adds texture the statute alone doesn't give you:

  • The deepfake duty applies regardless of whether anyone intended to deceive
  • It covers realistic depictions of fictional people, not only real ones
  • Whether content "appears deceptive" gets judged against potentially vulnerable audiences, a tougher bar than the EU's usual "average consumer" standard
  • Multiple Article 50 duties can stack on a single system

That is one firm's reading, not a Commission ruling. For the full four-duty breakdown, see the AI-generated content disclosure page.

When did EU AI Act Article 50 take effect?

Confirmed

Two dates, a ceiling of 15 million euros or 3 percent of global turnover, and zero enforcement actions nine days in.

Article 50's transparency rules applied from 2 August 2026. A second date, 2 December 2026, is a transitional deadline for certain Article 50(2) marking obligations, and only for systems already placed on the market before 2 August.

Fines run up to 15 million euros or 3 percent of a company's global annual turnover. EU institutions face up to 750,000 euros.

Enforcement is spread across three kinds of body:

  • National market-surveillance authorities in each member state
  • The EU AI Office
  • The European Data Protection Supervisor, for EU institutions specifically

As of 11 August 2026, nine days after the rule took effect, no fine, corrective order, or enforcement action had been publicly reported anywhere.

Veeam field CTO Edwin Weijdema expects corrective and suspension orders to significantly outweigh headline-grabbing fines in year one. He also flags an unresolved scope question: whether AI-agent interactions, or ticketing and procurement portals, even count as "direct interaction" with a person.

What do lawyers still disagree about in Article 50?

Community discussion

Three phrases in the Commission's own Guidelines still have no agreed meaning, months after the rule went live.

Three terms in Article 50 remain genuinely undefined, and law firm Cooley's reading names them:

  • The "already obvious" exception to interactive-AI disclosure
  • How far "public-interest matters" extends for the deployer text-disclosure duty
  • What counts as "substantive human editorial review" strong enough to trigger the editorial exemption

Greenberg Traurig adds a warning on that third one. Simply having a human check AI-generated content is not, on its own, sufficient to qualify.

Cooley flags one concrete upside too. Signing the Code of Practice earns "a degree of presumption of conformity" plus more favorable enforcement treatment, which is presumably part of why roughly 190 organizations signed on by the end of July 2026.

None of this has been settled by a court. It is informed legal commentary reading Commission text that leaves room, which makes it the live edge of the rule rather than background trivia.

Why does an EU rule change Claude's output worldwide?

Community discussion

Why does a European deadline change what Claude does in Ohio? Because maintaining two behaviors costs more than maintaining one.

Anthropic's marking applies wherever Claude is offered, worldwide, and the explanation this site finds most likely is cost: maintaining one behavior for EU users and another for everyone else is expensive and easy to get wrong. Anthropic has not published a reason. On 2 August 2026, the day the transparency rules took effect, an r/ClaudeAI thread thanking the EU for making Claude watermark its output collected the whole argument in one place. The reaction split three ways:

  • One camp welcomed the EU for forcing useful disclosure
  • Another resented that a European compliance deadline was shaping a product used everywhere
  • A third argued about whether biasing token choice can be done without hurting quality, citing Google's SynthID as proof subtler text watermarking is possible

The commenter who quoted Anthropic was right, and it's checkable. Anthropic's support article says the marking applies across Claude's products and surfaces "wherever Claude is offered, worldwide," not only in the EU.

California's own AI Transparency Act landed on the identical day, 2 August 2026, after a separate state law delayed it to that date. Nobody has confirmed the timing was coordinated rather than coincidental.

Treat the worldwide-scope fact as confirmed from Anthropic directly. Treat the opinions about whether that is good policy, and the California coincidence, as context rather than evidence either way.

FAQ

Does the EU AI Act mandate one specific watermark technology?

No. Article 50 requires machine-readable marking and detectability as far as technically feasible, but names no universal technology for any modality. Claims that the EU officially endorsed C2PA as the required pathway are not supported by the Code of Practice or the Guidelines themselves.

Does Article 50 prove a provider's text is watermarked today?

No. Article 50 creates regulatory obligations and pressure, nothing more. Deployment still needs provider-specific evidence, such as Anthropic's Claude marking article or Google's SynthID Text documentation.

Does an EU rule only affect EU users?

Not necessarily. Anthropic's own marking policy, introduced the same day Article 50 took effect, says it applies "wherever Claude is offered, worldwide." A regional transparency deadline can end up shaping a product for every user, not just the ones the regulation was written for.

Has anyone actually been fined under Article 50?

Not as of 11 August 2026, nine days after the rule took effect. No enforcement action, fine, or corrective order has been publicly reported. One industry prediction expects corrective and suspension orders to outnumber major fines in the rule's first year, but that is a forecast, not a reported outcome.

Is having a human check the output enough to count as editorial review?

Not necessarily. One law firm's reading of the Commission's guidance states that simply having a human check AI-generated content is not automatically sufficient, and the bar for "substantive human editorial review" remains undefined. Multiple Article 50 duties can also stack on one system, so clearing one exemption does not clear another.

Next steps

  • Read what Article 50(2) actually demands of providers, including the full exemption list and the fake icon spec circulating on compliance sites. Machine-readable AI marking
  • Work out which of the four duties lands on you, and whether you are the provider or the deployer in your own setup. AI-generated content disclosure
  • Check whether a specific provider actually marks its output today. Regulatory pressure is not deployment evidence. Anthropic watermark tracker
  • Read Article 50 in the original, and note the disclaimer about pending amendments before you quote a date. EU AI Act Article 50

Sources and citation status