The EU AI Act entered a significant new phase on 2 August 2026 as Article 50 transparency requirements became applicable to providers and deployers of certain AI systems. Requirements around machine-readable marking, detection and disclosure of AI-generated content are moving compliance beyond policy and into engineering, raising a more important question for the industry: how do you build transparency into the technology itself?

For much of the debate surrounding the EU AI Act, regulation and technology appeared to occupy opposite sides of the table. Developers built increasingly capable artificial intelligence systems, while policymakers attempted to establish rules governing how those systems should be used.

That distinction is becoming much harder to maintain.

Article 50 transparency requirements became applicable on 2 August 2026, bringing obligations concerning interactions with certain AI systems and the identification of AI-generated or manipulated content into the operational environment. The European Commission has now published both detailed guidelines and a Code of Practice intended to help providers and deployers translate those obligations into practical measures.

The immediate impact is regulatory, but the longer-term significance is technical. If organisations must reliably identify AI-generated content, disclose particular forms of synthetic media and provide information that can be detected by machines, those requirements cannot be satisfied through policy documents alone. They have to be reflected in the systems producing and distributing the content.

The AI Act is therefore beginning to do something more consequential than regulate artificial intelligence. It is starting to influence how trustworthy AI is engineered.

From disclosure to engineering

Article 50 addresses several transparency scenarios, but one of its most technically significant requirements concerns generative AI.

Providers of generative AI systems falling within the scope of Article 50 must ensure that outputs including synthetic audio, images, video and text are marked in a machine-readable format and detectable as artificially generated or manipulated. The Commission’s Code of Practice goes further in describing the expected technical characteristics, calling for approaches that are effective, interoperable, robust and reliable as far as technically feasible.

That moves the discussion well beyond placing a small “AI-generated” label underneath an image.

Machine-readable identification requires information capable of travelling with, or remaining associated with, digital content. Depending on the implementation and media type, this can involve metadata, watermarking, provenance information or other technical approaches capable of communicating how content was produced.

The Commission itself has recognised that there is no single technical answer. Studies commissioned to support Article 50 examined marking and detection separately across text, audio, images and video, assessing the effectiveness and limitations of different techniques. This is important because content behaves differently once it leaves the environment in which it was generated. Images are resized, screenshots are taken, videos are edited, audio is recompressed and text is copied into other systems. Metadata may disappear and technical signals can be weakened by transformation.

Compliance therefore becomes connected to interoperability, provenance and robustness. These are engineering problems as much as regulatory ones.

The difficulty is that identifying content as probably AI-generated is not the same as establishing where that content came from, who created it or what has happened to it since. As generative systems improve, detection also risks becoming a continual contest between increasingly sophisticated generation and increasingly sophisticated attempts to identify it.

Slavko Kovačević, Co-Founder and CEO of DeepMark, argues that this is where the debate needs to move beyond detection. Commenting to The Quantum Space, he said:

I think the critical shift is moving from probabilistic ‘detection’, which is always chasing a moving target, to deterministic ‘provenance,’ which provides a verifiable chain of authenticity. We need to stop asking ‘is this AI?’ and start asking ‘who created this and what did they intend?’

That distinction is important because watermarking can provide a useful signal, while provenance addresses the broader question of whether the origin and history of digital content can be independently established and trusted. The challenge then becomes not simply creating that information, but ensuring that it remains attached to the content as it moves between systems, platforms and formats.

The difficult part is what happens afterwards

Generating a transparency signal is only the beginning of the problem. The more difficult question is whether that signal survives.

A piece of content generated inside one AI environment may subsequently move through social networks, editing applications, content-management systems and enterprise platforms before reaching its audience. Each transformation creates the possibility that provenance information will be lost, weakened or separated from the content it describes.

The Commission’s approach acknowledges this reality by focusing on effectiveness and technical feasibility rather than prescribing a single universal technology. It also creates an incentive for providers to develop approaches capable of working across different systems rather than building proprietary transparency mechanisms that function only inside their own platforms.

This is where standards become important.

The Coalition for Content Provenance and Authenticity, or C2PA, has been developing an open technical framework for recording the source and history of digital content. Its Content Credentials architecture uses digitally signed claims and assertions that can describe how an asset was created, what actions have subsequently been performed on it and information associated with its provenance.

C2PA is not the AI Act’s mandated technical solution, nor does the existence of a Content Credential automatically establish whether the information contained in an asset is true. What it demonstrates is how provenance can become machine-verifiable infrastructure rather than a simple visual label.

The distinction is important because the problem facing generative AI is increasingly about evidence rather than appearance.

Provenance becomes part of digital trust

Generative AI is rapidly becoming embedded within software development, corporate communications, scientific research, financial services and enterprise workflows. As the volume of machine-generated and machine-assisted material increases, organisations will need stronger mechanisms for understanding where information originated and what happened to it before it reached them.

A document may have been written entirely by a person, generated by an AI system or created through several stages of human and machine collaboration. An image may have originated in a camera before being modified using generative AI, while another may have been synthetically generated from the outset.

The binary distinction between “real” and “AI-generated” is therefore becoming less useful.

Provenance offers a different approach because it focuses on history rather than judgement. Instead of asking a detection system to infer whether something is authentic purely from its appearance, provenance mechanisms can provide evidence about where an asset originated, which processes were involved in its creation and whether subsequent modifications have occurred.

C2PA’s current specifications extend this thinking directly into artificial intelligence and machine learning. Its guidance describes how Content Credentials can be associated with AI models and their outputs, allowing provenance information to identify content as originating from a trained AI model and potentially provide additional information about the model, inputs and processing environment.

This brings AI transparency into the wider digital trust environment already familiar from identity, cryptography and software security. The underlying question is increasingly the same: can a claim about the origin or integrity of a digital object be verified rather than simply accepted?

Regulation moves into the technology stack

This development is part of a broader change taking place across European technology regulation. The Cyber Resilience Act is influencing how manufacturers approach secure software development and vulnerability management. NIS2 is forcing organisations to examine operational resilience, supply chains and incident response. eIDAS 2.0 is shaping the architecture of Europe’s emerging digital identity ecosystem. The AI Act is now beginning to follow the same pattern.

European regulation is increasingly specifying outcomes that cannot be delivered by legal departments alone. Transparency, cybersecurity, identity assurance and resilience require technical mechanisms capable of producing evidence that the required controls are actually operating. This changes the relationship between compliance and engineering.

Historically, technology could often be developed first and assessed against regulatory requirements afterwards. The direction of travel increasingly favours systems where regulatory requirements influence architecture much earlier in the development process.

For generative AI providers, machine-readable marking and detection provide an obvious example. Risk management, logging, documentation, human oversight and cybersecurity requirements provide others. As AI becomes embedded within critical business processes, separating responsible deployment from the engineering decisions made while those systems are being designed becomes progressively harder.

The Commission’s voluntary Code of Practice illustrates this transition particularly clearly. The Commission and AI Board concluded in July that the Code provides an adequate EU-wide mechanism for helping organisations demonstrate compliance with Article 50 transparency obligations. Providers and deployers can choose other approaches, but they must then be able to demonstrate that their alternative measures are adequate.

Compliance is therefore beginning to require evidence of implementation rather than simply evidence of intent.

Transparency does not automatically create truth

None of this means the problem of synthetic content has been solved. Watermarks can potentially be damaged or removed. Metadata can disappear as files move between platforms. Detection mechanisms can generate false positives and negatives, while different media formats present very different technical challenges. Open models and decentralised content-generation tools introduce additional complications. There is also a fundamental distinction between proving provenance and proving truth.

Knowing that an image was generated by an AI system tells us something important about its origin, but it does not automatically tell us whether the information it communicates is false. Equally, establishing that a photograph originated from a physical camera does not guarantee that the context in which it is presented is accurate.

The technology cannot eliminate misinformation or make judgements about truth on our behalf. What it can provide is better evidence about origin, transformation and integrity, giving people and automated systems more reliable information on which to base those judgements. That is a more realistic objective, and potentially a more valuable one.

What changes after 2 August

The significance of the latest AI Act milestone is therefore larger than another date on Europe’s regulatory calendar.

With Article 50 transparency requirements now applicable, providers and deployers have to translate concepts such as transparency, marking and disclosure into controls capable of functioning across real systems. That process will expose technical limitations, encourage competing approaches and place greater pressure on provenance and interoperability standards to mature.

It will also make compliance increasingly visible inside the technology itself. For organisations deploying AI, this creates a useful test. The question is no longer simply whether an organisation has an AI policy or can identify which provisions of the AI Act apply to it. Increasingly, it must be able to demonstrate how those requirements are reflected in the systems, processes and evidence surrounding its use of artificial intelligence.

The AI Act was designed to govern artificial intelligence. As its provisions move into the operational environment, one of its more lasting effects may be to change how trustworthy AI is actually built.

Sources and further reading

European Commission – Code of Practice on Transparency of AI-generated Content
The final Code supports compliance with Article 50 requirements covering machine-readable marking and detection of AI-generated content, together with labelling requirements for deepfakes and certain AI-generated publications. The Commission confirms that the relevant transparency obligations apply from 2 August 2026.
European Commission: Code of Practice on Transparency of AI-generated Content

European Commission – Guidelines on Article 50 transparency obligations
Published on 20 July 2026, the Commission’s guidelines provide practical guidance for providers, deployers and competent authorities on the implementation of Article 50.
European Commission: Article 50 transparency guidelines

European Commission – Technical studies on marking and detection
Three Commission-commissioned studies examine the state of the art for marking and detecting AI-generated text, audio, images and video, including the limitations and practical applicability of current approaches.
European Commission: Technical solutions for marking and detecting AI-generated content

European Commission and AI Board – Assessment of the Code of Practice
The Commission concluded in July that the voluntary Code adequately covers the relevant Article 50 obligations and provides an EU-wide framework through which signatories can demonstrate compliance.
European Commission: Assessment of the Transparency Code of Practice

C2PA – Content Credentials Specification 2.4
The Coalition for Content Provenance and Authenticity develops open technical standards for recording and cryptographically verifying information concerning the source and history of digital content.
C2PA Content Credentials specification

C2PA – Guidance for Artificial Intelligence and Machine Learning
C2PA’s AI guidance describes how provenance information and Content Credentials can be applied to AI models and AI-generated outputs, including mechanisms for identifying output originating from trained AI models.
C2PA guidance for AI and machine learning


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading