The Week in One Line

Providers of generative AI have until 2 December to mark their outputs — and the Commission's own commissioned research concluded that no available technique satisfies all four requirements the law sets.

What the Act Actually Says

Article 50(2) contains two duties, not one. Providers of AI systems generating synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated. The Commission's guidelines are blunt about this: fulfilling only one element — machine-readable marking without the means of detection being available — will not suffice.

No technique is mandated. The Article names none. Recital 133 offers examples: watermarks, metadata identification, cryptographic provenance methods, logging, fingerprints, or combinations. Providers may use one or several, so long as the overall solution is machine-readable and meets the four requirements. The guidelines also state plainly that providers are not required to record or keep a full provenance chain.

The four requirements are where it gets hard. Solutions must be effective, interoperable, robust and reliable as far as technically feasible. The guidelines read robustness as accurate identification under adversarial attack and common alteration, and interoperability as working seamlessly across systems and actors regardless of which technique each provider chose.

And here is the finding almost nobody has reported. The AI Office commissioned three independent technical studies — on text, on audio, and on image and video — published in May. All three reached the same conclusion from different directions.

  • The text study found the methods are close to meeting each requirement individually, but no single one meets all of them. Metadata is the most effective and the least robust: stripping it requires no technical knowledge. Watermarks are robust but forgeable at scale.
  • The audio study states that no single technology currently fulfils all requirements of Article 50, and classes forensic detection of AI audio as a research tool rather than a regulatory compliance mechanism.
  • The image and video study finds none provide a complete solution across all contexts, and describes watermarking and passive detection as an arms race in which countermeasures improve too.

Interoperability is the blocker the studies keep returning to. It cannot be solved inside one company, because it requires agreement between providers and with authorities about how anyone else verifies your mark.

The Code of Practice answers this with layering. For signatories, Measure 1.1 requires at least two marking layers — digitally signed, time-stamped, tamper-evident metadata wherever the format supports it, plus imperceptible watermarking — precisely because no single technique can meet the four requirements alone. Free-form text cannot carry metadata, so watermarking alone applies there, required above 200 tokens. Fingerprinting and logging are optional and explicitly not sufficient on their own.

Two commitments in that Code deserve attention from anyone budgeting for this. Detection must be made available free of charge, and always free and unlimited for authorities, media, fact-checkers, researchers and civil society. And robustness testing must include the analogue hole — print and scan, playback and re-record, filming a screen.

The deadline. A new Article 111(4), inserted by the AI Omnibus (Regulation (EU) 2026/1744), gives providers whose generative systems were placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Only providers. Only Article 50(2). Only pre-August systems. Everything else applied in August.

Sources: AI Act Article 50; European Commission, Guidelines on transparency of AI-generated content, three studies on technical solutions to mark and detect AI-generated content, and the Code of Practice on Transparency of AI-generated Content.

What This Means for Your Business

You cannot buy your way to full compliance, and the law knows it. Technically feasible is an objective notion, not a function of your budget — but a provider is not obliged to use a technical solution that does not yet exist. That cuts both ways. It means nobody expects you to solve interoperability alone. It also means you are expected to keep up as the state of the art moves.

Detection is the half that gets forgotten and the half that costs. Marking is a one-off engineering change. Detection is a service you have to run, keep available, and — if you sign the Code — offer free to journalists and researchers who ask. Budget for the second one.

If you do not sign the Code, prepare to show your work. The guidelines say non-signatories should carry out a gap analysis comparing their measures against a code assessed as adequate, and may face more requests for information. Signing is not a safe harbour either — the Omnibus recitals state these codes do not grant a presumption of conformity.

This Week's Action Point

If you provide a generative system, answer four questions before 2 December.

  1. Was the system placed on the market before 2 August 2026? If yes, the transitional period applies to you and it ends in nine weeks.
  1. Which marking layers are in place today — signed metadata, watermarking, both, neither?
  1. Can a third party detect the mark, and how do they reach that detection tool?
  1. Has anyone tested whether the mark survives a screenshot, a re-encode and a print-and-scan?

I have turned this into a one-page readiness sheet — The 2 December Marking Checklist — with the layer matrix, the robustness tests and the exemptions. It is linked in the comments of today's post. Free, no sign-up.

Further Reading

One question I would like your answer to: if you provide a generative system, do you already know which of the two layers you have — or is this the first time anyone has asked? No judgement either way; I would just like to know the real distribution. Reply or leave it in the comments.

Next Tuesday

What the AI Office can actually do to a provider that misses 2 December, and what the first enforcement months have looked like in practice.

Matúš Paško — I design enterprise AI systems that have to run in production under real compliance and reliability constraints. If you are working out what marking would take in your own pipeline before December, my calendar link is in my profile.

#EUAIAct #Article50 #AICompliance #AIGovernance #EnterpriseAI