Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Tech & Innovation

EU AI Act Article 50: Machine-Readable Marks Are Not Universal Labels

|Author: QUASA Editorial Team|6 min read| 5
EU AI Act Article 50: Machine-Readable Marks Are Not Universal Labels

Article 50 does not impose one universal, visible “AI-generated” label on every output. Since 2 August 2026, providers of generative AI systems have generally been responsible for making covered synthetic output machine-readable and detectable, while professional deployers have separate audience-facing duties for deepfakes and certain public-interest text.

The answer therefore turns on role, content type and use. Source code, some machine-to-machine and closed-loop output, and standard editing may fall outside the provider marking requirement; substantive human review combined with editorial responsibility can remove the deployer disclosure duty for qualifying public-interest text.

1. Classify the provider and deployer separately

A provider documents technical marking while a professional deployer separately assesses disclosure.

A provider develops an AI system, or has it developed, and markets it or puts it into service under its own name or trademark. A deployer is the person or organisation using the system under its authority, excluding personal, non-professional activity. A company may be a deployer when using a third-party system and a provider when releasing a different system under its own brand.

The official AI Act text assigns the machine-readable marking obligation in Article 50(2) to providers, while Article 50(4) makes deployers responsible for disclosing deepfakes and specified public-interest text. The Act also covers providers and deployers established outside the EU when an AI system’s output is used in the Union.

Employees acting under a company’s instructions are not normally separate deployers. The same applies to contractors operating a system on the company’s behalf and under its responsibility and control: the organisation remains the deployer for that workflow.

2. The provider branch concerns technical detectability

Article 50(2) covers providers of AI systems, including general-purpose AI systems, that generate synthetic audio, images, video or text. Covered output must be marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as technically feasible, taking account of the medium, implementation costs and the recognised state of the art.

This is a performance obligation, not a prescribed badge. A provider may use embedded provenance information, a watermark or another suitable technique, but Article 50 does not require every medium to carry the same visible wording or symbol.

The Commission’s Article 50 FAQ identifies source code, short sequences of characters, output intended exclusively for automated machine-to-machine communication, and non-final output confined to closed-loop industrial or product-development environments as outside the marking obligation; it also describes a narrow exception for qualifying business-to-business or industrial contexts. Separately, the statutory exemption covers systems performing an assistive function for standard editing or not substantially changing the deployer’s input or its meaning.

Those boundaries depend on the actual output and workflow. A format conversion or limited correction may be standard editing, whereas replacing a scene or changing a passage’s substantive meaning is not. A production asset may also require reassessment if it becomes final, leaves the closed environment or is exposed to people.

3. The deployer branch depends on publication and content

Editorial review separates a deepfake disclosure decision from reviewed public-interest text.

For a professional user, Article 50(4) produces two main branches:

  1. For images, audio and video, determine whether the content is a deepfake: it must resemble an existing or plausibly existing person, object, place, entity or event and falsely appear authentic or truthful.
  2. If it is a deepfake, disclose that it was artificially generated or manipulated. The disclosure must be clear, distinguishable and available by the audience’s first exposure.
  3. If the deepfake forms part of an evidently artistic, creative, satirical, fictional or analogous work, disclosure is still required, but it may be presented without hampering display or enjoyment.
  4. For text, ask whether it is published to inform the public about a matter of public interest. Private communications, internal drafts and text published for another purpose do not automatically satisfy this test.
  5. If qualifying text underwent substantive human review or editorial control and a natural or legal person holds editorial responsibility for publication, the Article 50(4) disclosure duty does not apply.

Human review is not satisfied by spell-checking, formatting or a procedural sign-off. It requires deliberate examination of substance by people with relevant knowledge and professional judgment. Editorial control means practical authority to approve, alter or reject the substance, while editorial responsibility means ultimate legal responsibility for publication.

The exception is specific to the deployer’s disclosure duty for public-interest text. It does not automatically eliminate a provider’s separate technical-marking obligation at system level.

4. A machine-readable mark is not an audience disclosure

Software detects a machine-readable signal while a separate review checks the audience disclosure.

The two controls serve different recipients. A machine-readable signal enables technical detection, but a person may need special software or access to a detector to find it. A deployer’s disclosure must instead be understandable and perceptible to the person exposed to covered content; embedding a technical mark alone does not necessarily meet that requirement.

Technical marks also have evidential limits. In its description of Claude’s announced text-watermarking method, Anthropic says detection produces a probability that Claude was involved rather than proof of authorship, carries no identity for a user, organisation or chat, works less well on short samples, and can be defeated by a complete rewrite. That example illustrates why detectability, attribution and visible disclosure should not be treated as interchangeable concepts.

The reverse is also true. A visible caption can inform an audience but may disappear when a file is copied, cropped or transformed, so it does not necessarily provide the persistent technical detectability required from a provider.

5. Application dates and the voluntary code

The Article 50 obligations began applying on 2 August 2026. The Commission’s Code of Practice FAQ confirms a limited transition until 2 December 2026 for systems placed on the market before 2 August, while describing adherence to the code itself as voluntary. That transition concerns the Article 50(2) marking and detection obligation; it is not a general postponement of deployer disclosure duties.

The code separates provider commitments on marking and detection from deployer commitments on labelling deepfakes and public-interest text. It offers signatories a recognised way to demonstrate compliance, but it does not replace Article 50 or create a single mandatory label for every type of synthetic content.

The decisive distinction is therefore functional: providers implement machine-readable detectability for covered system output, while deployers communicate directly with audiences in the uses Article 50 specifies. Whether either duty applies must be tested against the organisation’s role, the output, its destination and the relevant exception.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0