Application of the EU AI Act in Practice (2026): Code of Practice on Transparency of AI-Generated Content
The European Commission, by its Opinion of July 8, and the AI Board, by its Assessment of July 9, confirmed the adequacy of the Code of Practice on Transparency of AI-generated content (the Code) to cover the obligations provided for in Articles 50(2), (4) and (5) of the AI Act and facilitate their effective implementation. Previously, on June 9, the Commission published the final version of the Code of Practice, compiled by independent experts through a multi-stakeholder process supported by the AI Office.
The application of Article 50 of the AI Act begins on August 2, 2026. However, Digital Omnibus on AI has introduced for providers of generative AI systems, including general-purpose AI systems, that were placed on the market before August 2, 2026, a transitional period of four months, requiring them to take the necessary steps in order to comply with Article 50(2) by 2 December 2026.
The Code is a supporting document that provides a framework for compliance with the transparency obligations of providers and deployers of generative AI systems, focusing on Articles 50(2), (4) and (5) of the AI Act.
The Code is voluntary. All providers and deployers of generative AI systems are invited to sign the Code. In that way, by accepting respective commitments, companies can rely on the Code to demonstrate compliance with the AI Act’s rules. Even then, adherence to the Code does not constitute conclusive evidence of compliance with these obligations. The market surveillance authorities remain competent for assessing such compliance.
At the same time, the Code can serve as a uniform reference framework for competent market surveillance authorities to assess compliance by providers and deployers.
Providers and deployers who choose not to sign, but to comply in another way, will have to demonstrate that their measures are adequate. This will be assessed individually by different market surveillance authorities.
In any case, regardless of the compliance manner, a company must develop an internal compliance protocol.
The Code has two sections that establish obligations and corresponding measures, separately for providers and for implementers of generative AI systems.
Section 1: Rules for marking and detection of AI-generated and manipulated content applicable to providers of generative AI systems (Article 50(2) and (5) AI Act)
LEGAL TEXT: Article 50(2) and (5) and recitals 133 and 135 AI Act
2. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards.
5. The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.
The Code states that the development of generative AI systems with large quantities of synthetic content increases the difficulty in distinguishing it from human-authored content and raises new risks of misinformation, manipulation at scale, fraud, impersonation, and consumer deception (Recital (a)). Therefore, as the main goal of these transparency obligations, the Code emphasizes the integrity of the information ecosystem and trust in it (Recital a)). The compliance framework of this Code Section is based on four core commitments of providers, followed by appropriate measures to implement them.
Commitment 1: Marking of AI-generated or Manipulated Content
In order to fulfil their obligation under Article 50(2) of the AI Act, Signatories commit to implement a marking solution with regard to audio, image, video or text content, or any combination thereof, generated or manipulated by the AI system(s), which they place on the market or put into service in the Union.
Machine-readable marking techniques (Measure 1.1)
As a general rule, providers must implement a marking solution that consists of at least one machine-readable marking technique, which, in conjunction with their respective detection mechanism, meets the required level of effectiveness, reliability, robustness, and interoperability.
So long as no single marking technique can, under the state of the art, ensure by itself compliance with these four requirements, in particular for content that can be disseminated online, providers must implement a multi-layered marking approach to ensure that the outputs of their generative AI systems are marked with at least two layers of machine-readable marking:
Digitally signed metadata (Sub-measure 1.1.1) If content is generated, manipulated or exported in a data format that supports attaching metadata (e.g., an audio, image, video, or containerised text), providers must record information in the metadata on whether the content is AI-generated or manipulated. All recorded information must be digitally signed and time-stamped, in a secure and tamper-evident manner.
The imperceptible watermark (Sub-measure 1.1.2) Providers must ensure that AI-generated or manipulated content is marked with an imperceptible watermark, with the exception of very short text. For free-form text longer than 200 tokens, watermarking still needs to be applied, even though it may have lower reliability compared to that of watermarking very long text (to compensate for this potential lower reliability, access to the corresponding detection solution may be restricted to verified expert users). The imperceptible watermark must be embedded in such a way that it is difficult to separate from the content, and it is intended to serve as a robust mechanism to complement the digitally signed metadata.
Fingerprinting or logging (optional)(Sub-measure 1.1.3) Where appropriate and taking into account potential trade-offs related to privacy and security, as well as scalability challenges and costs, providers may implement fingerprinting or logging as a supplementary solution to meet the quality requirements. However, relying on these techniques alone is not considered sufficient to meet the quality requirements.
Exceptionally (and proportionally), a single layer of marking will be considered sufficient in specific cases (i) where a generative AI system is embedded in physical products capable of generating synthetic outputs in a technically controlled and closed environment mainly instructive in nature, and (ii) for free-form text, as it cannot transport metadata.
The marking techniques may be implemented at different stages of the value chain (e.g., by the provider of the AI system itself or by an upstream model provider) and may also be provided by third parties (in particular, technology providers specialised in marking techniques and detection mechanisms for AI transparency).
Non-removal of markings (Measure 1.2)
Providers must make best efforts to preserve metadata markings on input data and content generated or manipulated by their AI system. At the same time, they are prohibited from making available and promoting tools to circumvent the machine-readable markings.
Transparency of the provenance information (optional) (Measure 1.3)
Functionality for perceptible markings (optional) (Measure 1.4)
Commitment 2: Detection of Markings of AI-generated or Manipulated Content
In order to fulfil their obligations under Article 50(2) and (5) AI Act to ensure that the outputs of their AI system(s) are detectable as AI-generated or manipulated, Signatories commit to provide the means to enable the detection of the machine-readable markings present in audio, image, video or text content, or a combination thereof, as generated or manipulated by their AI system.
Detection mechanisms for markings (Measure 2.1)
Providers must make available a detection solution, composed of one or more detection mechanisms, to enable deployers, users of their generative AI system, third-party integrators, end-users exposed to the content, and other legitimate parties (such as competent authorities, independent researchers, civil society and media organisations) to verify whether content has been generated or manipulated by their AI system based on the marking technique(s). Signatories must ensure that the detection solution, in conjunction with the associated marking solution, meets the required level of effectiveness, interoperability, robustness, and reliability.
Making the detection solution available (Sub-measure 2.1.1) Providers must make available the detection solution, which includes a detection mechanism for each marking technique implemented in their generative AI system, in one of the following ways: (i) a public, ideally standardised, specification allowing any third party to implement a detection mechanism; (ii) a piece of software (e.g., a standalone executable or library); (iii) a cloud-based service accessible to users in the Union through an API. The detection solution must be made available free of charge. Exceptionally, providers with fewer than 1,000,000 monthly users of their generative AI system, whose detection solution incurs substantial operational costs (in particular when it is provided for detection of watermarks as a cloud-based service), may charge a fee for the use of their detection solution (which must be reasonable, fair and proportionate to the overall operational costs of that solution) in cases where requests from a single user exceed a reasonable threshold due to large volume of requests.
Access to the detection solution (Sub-measure 2.1.2) Providers must ensure access to their detection solution through a user interface appropriate for the audience of end-users that may eventually be exposed to the content generated or manipulated by their AI system.
Personal data protection, privacy and security (Sub-measure 2.1.3) Providers must ensure that the detection is compliant with EU privacy and data protection law.
Forensic detection mechanism (optional) (Measure 2.2)
Clear and accessible disclosure of detection results (Measure 2.3) Providers must ensure that the detection results provided by their detection solution are presented in a way that is clear and easily comprehensible to natural persons exposed to the content generated or manipulated by their AI system and who want to verify its origin.
Support literacy on AI marking and detection solutions (optional) (Measure 2.4)
Commitment 3: Measures to Meet the Requirements for Marking and Detection Solutions
In order to fulfil their obligation under Article 50(2) AI Act, Signatories commit to ensure that their marking and detection solutions comply with the quality requirements described in the respective measures, holistically across all marking techniques employed rather than for each technique individually. In addition, Signatories commit to assess and demonstrate compliance with the requirements in accordance with the testing, verification, and compliance processes specified in Commitment 4 prior to placing their generative AI system on the market or putting it into service, and throughout its lifecycle.
Effectiveness (Measure 3.1)
Providers must implement technical marking and detection solutions which, in conjunction, are fit-for-purpose and capable of enabling natural persons to distinguish content generated or manipulated by their AI system. Those solutions will be considered effective when natural persons can access and understand the meaning of the detection results.
Reliability (Measure 3.2)
Signatories will implement marking and detection solutions which, in conjunction, achieve a high level of reliability in different expected contexts and across use cases, to the extent technically feasible and in alignment with the state of the art. Reliability refers to the capability of the marking and detection solutions to accurately identify and distinguish the origin of AI-generated or manipulated content from other content.
Robustness (Measure 3.3)
Signatories will implement marking and detection solutions which, together, maintain intended performance levels under varying conditions, covering both common alterations and adversarial attacks, to the extent technically feasible, and in alignment with the state of the art. This requirement does not apply to AI systems that are exceptionally subject only to one layer of metadata marking.
Interoperability (Measure 3.4)
Signatories will implement marking and detection solutions that operate seamlessly across multiple systems, actors, contexts and technical implementations to enable detection of AI-generated or manipulated content, regardless of the marking technique deployed in different AI systems, to the extent technically feasible. At the time of publication of this Code, relevant interoperability standards and/or best practices are yet to be developed, except for digitally signed metadata. Therefore, a staged implementation of interoperability requirements must be adopted as prescribed.
Advancing the state of the art (optional) (Measure 3.5)
Commitment 4: Testing, Verification, and Compliance
In order to effectively fulfil and demonstrate compliance with their obligations under Article 50(2) and (5) of te AI Act, as well as with the Commitments and Measures specified in this Section of the Code, Signatories commit to set up, keep up to date, and implement compliance, testing, verification and monitoring processes, as specified in the respective measures.
Compliance process (Measure 4.1).
Providers must document, implement, and keep up to date, in line with the state of the art, a compliance process that describes at a high-level how they have implemented the different Measures in this Section. This measure will be implemented in a proportionate manner, taking into account the size and resources of the Signatory, in particular with regard to providers that are SMEs and SMCs. Providers may demonstrate compliance through existing processes and compliance documentation to the extent that they fulfil the measures.
Testing, verification, and monitoring (Measure 4.2)
Prior to placing their generative AI system on the market or putting it into service, and regularly thereafter, providers must test the compliance of their marking and detection solutions with the requirements and the measures specified in this Section. Signatories may involve independent experts in the testing of their solutions, and/or conduct such testing and evaluation under regulatory supervision in the context of AI regulatory sandboxes, as provided for in Article 57 AI Act.
Training (Measure 4.3)
Providers must make proportionate efforts to provide appropriate training to their personnel who have roles relevant to ensuring compliance with Article 50(2) and (5) and Article 4 AI Act.
Cooperation with market surveillance authorities (Measure 4.4)
In line with Article 74 AI Act and Article 7 of Regulation (EU) 2019/1020 (the Market Surveillance Regulation), providers must cooperate with competent market surveillance authorities to demonstrate compliance with Article 50(2) and (5) AI Act and their Commitments under this Section.
Section 2: Labelling deep fakes and AI-generated and manipulated published text applicable to deployers of AI systems (Article 50(4) and (5) AI Act)
LEGAL TEXT: Article 50(4) and 50(5) and recitals 133 and 135 AI Act
4. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offence. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.
5. The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.
The Code highlights the objective of these transparency obligations: to protect public trust, safeguard democratic discourse, and inform individual decision-making. Clear and distinguishable disclosure that the content has been artificially generated or manipulated is a necessary safeguard to make individuals aware and inform their decision-making. This safeguard is not aimed at providing individuals with information about the trustworthiness of the content, but rather at informing them about its artificial origin or the role of the AI system in manipulating the content ( Recital (a)).
This Section of the Code applies only to Signatories in so far as they are deployers of AI systems that generate or manipulate image, audio or video content constituting a deep fake or text published with the purpose of informing the public on matters of public interest falling within the scope of Article 50(4) AI Act. In accordance to Article 3(60) of the AI Act ‘deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
Commitment 1: Disclosure of Deep Fakes and Published Text
To fulfil their obligations under Article 50(4) and (5) AI Act, Signatories commit to ensure consistent and effective disclosure of the artificial origin of deep fakes or published text, as well as to implement such disclosure through the available EU icon provided in Annex 1 of the Code or through an equivalent icon or label that complies with the design and placement specifications as described in the respective measures.
Design specifications (Measure 1.1).
The icon or equivalent label must comprise, as the main visual element, the capitalised acronym “AI” in the English language, unless use of English is incompatible with applicable national laws on the use of languages in commercial or administrative matters, in which case the acronym may be disclosed in the national language. Additionally, deployers are encouraged to supplement the acronym in the icon with further information indicating “generated” or “modified”, in an (interactive) second layer where this is technically implementable. In this way, a difference is made between content created autonomously by the AI system and that which is the result of human and AI input. Signatories are furthermore encouraged to disclose what has been modified by the AI system (e.g., text or pictogram describing that a face has been altered).
The disclosure for audio-only content must include, at the beginning of the deepfake itself, a short audible disclaimer in plain and simple natural language, either in the same language as the content or in English, in a perceivable manner.
Placement specifications (Measure 1.2)
To meet the legal requirements of labelling under Article 50(5) AI Act and considering the dissemination of published text and deep fakes in particular across online platforms or search engines in both offline and online environments, deployers must apply the described placement specifications.
Overarching principles for placement specifications (Sub-measure 1.2.1) Considering the content format and dissemination context, the icon or equivalent label:
- a) must be placed in an appropriate and perceivable manner that ensures immediate recognition by natural persons without requiring user (inter)action or sustained attention;
- b) must remain visible at least for a sufficient duration to be noticed under normal exposure conditions to ensure perceivability;
- c) must be directly embedded into the content, unless equivalent alternatives to an embedded icon are available (e.g., a user interface overlay that for natural persons appears to be on the content);
- d) must be clearly perceivable and distinguishable at the latest at the time of first exposure of a natural person to the deep fake or published text (e.g., by maintaining sufficient spacing to other overlay elements, disclaimers, and sound/visual on-screen/on-display elements and remain visible against any background).
Placement specifications where visual disclosure is possible (Sub-measure 1.2.2) In addition to the overarching principles, the following placement specifications must be implemented where visual disclosure is possible:
- The icon or equivalent label must appear in an appropriate place where no intervening overlay elements exist (e.g., in the top right corner of an image or video deep fake).
- For video (e.g., live content) and for downstream use (e.g., screenshots and clipped fragments), the icon or equivalent label must be displayed at the beginning of the video as well as, where possible, at regular intervals throughout the video and, at a minimum, after interruptions (e.g., after commercial or advertising breaks).
- Where a deep fake is exclusively used as part of a closed internal professional context (e.g., for the purpose of training or informing employees), the disclosure may be placed in the user interface, physical setting or any other appropriate medium readily available to the natural persons exposed to the deep fake, informing them before being exposed to the deep fake.
- For visual deep fakes, audible disclosures may only be implemented as an additional disclosure method and must always be accompanied by visual disclosures (e.g., where audio is part of the user experience or as appropriate for accessibility purposes).
- For audio deep fakes, when a screen is available, an additional visual disclosure based on the icon or equivalent label must be made available (e.g., when a screen is available in a car or on a smartphone display), in addition to the audible disclaimer.
- For published text, the icon or equivalent label must be placed, for example above or at the top of the text, near the headline of the text, or in the colophon at the beginning of the text, as long as placement is clear, consistent, and distinguishable for the end-user.
Placement specifications where visual disclosure is not possible (Sub-measure 1.2.3) In addition to the overarching principles, where visual disclosure is not possible, an audible disclaimer must be included at the latest at the time of the first exposure to the deep fake.
Commitment 2: Internal Processes
To effectively fulfil and demonstrate compliance with the obligations under Article 50(4) and (5) of the AI Act and the Commitments and Measures specified in this Section of the Code, Signatories commit to put in place or maintain internal processes, awareness measures and review mechanisms as specified in the measures below and proportionate to their size and available resources.
Internal compliance process (Measure 2.1)
Deployers must put in place or maintain appropriate internal compliance processes and documentation that specifies how they implement the disclosure obligations using the icon or equivalent label. Such documentation may include a general description and representative, concrete and real examples of how disclosures are implemented in practice in accordance with Commitments. Where appropriate and particularly in cases of regular use of AI systems to create deep fakes or published text, deployers must put in place or maintain a process to ensure and verify that the design and placement specifications are implemented properly to mitigate risks of non-labelled or incorrectly labelled content.
Awareness and literacy (Measure 2.2)
Deployers must make efforts proportionate to their size, available organisational resources, and capacities to ensure awareness of the disclosure obligations under Article 50(4) and (5) of the AI Act among their personnel, including employees, and external contractors directly involved in the implementation of disclosure measures or overseeing compliance with the measures in this Section of the Code.
Review, feedback and cooperation with authorities (Measure 2.3)
Deployers must support the effective implementation of the design and placement specifications through internal review and external feedback. They are encouraged to provide channels that allow individuals or third parties to flag missing or incorrect disclosures, where appropriate through existing reporting mechanisms (e.g., trusted flagger mechanisms, interfaces for third-party fact-checking services or notice and action mechanisms. However, deployers must review cases that have been reported in a substantiated manner as mislabelled or incorrectly labelled and take measures to remedy cases of non-compliance.
Commitment 3: Disclosure for Artistic, Creative and Similar Works
In accordance with Article 50(4) AI Act, Signatories commit to implement measures to disclose deep fakes that form part of evidently artistic, creative, satirical, fictional or analogous work or programmes in a way that does not hamper the display or enjoyment of the work, including its normal exploitation and use, while maintaining the utility and quality of the work.
In this context, Signatories will:
- a) use an icon or equivalent label following the design specifications in Measure 1.1. and place it in a manner appropriate to the type of artistic, creative, satirical, fictional or analogous work and to the context in which it is presented.
- b) ensure such disclosure and placement are clear, distinguishable, and accessible to all natural persons, and provided at the latest at the time of first exposure to the content containing the deep fake (e.g., in the accompanying notes or description provided to users, at the beginning/ end credits etc.).
- c) ensure the icon or equivalent label is perceivable for a sufficient duration to be easily noticed under normal viewing or exposure conditions to ensure perceivability.
Where deep fake content is made available in a digital or interactive manner (e.g., on websites, apps or other user interfaces), the icon or equivalent label may be placed outside but adjacent to the video or image frame, or adjacent to the audio content and integrated into user interface elements or overlays, under the control of the Signatory.
Where content is made available in a non-digital or non-interactive manner (e.g., exhibitions, art galleries, cinemas, festivals or similar contexts, audio or video on a physical carrier), disclosures may be provided at the online or physical point of entry or sale, as part of the introductory or accompanying information.
Commitment 4: Human Review and Editorial Control for Published Text
Signatories who are media service providers within the meaning of Art. 2(2) of Regulation (EU) 2024/1083 and already subject to editorial standards and to regulatory, co-regulatory, or self-regulatory frameworks, as applicable to those media service providers under EU and national media law and frameworks, may rely on the exception to the disclosure obligation in Article 50(4), subparagraph 2, AI Act by applying their existing review and editorial procedures and established professional standards, as applicable, to comply with this Commitment.
All other Signatories, including those without such review or editorial procedures, commit to establish, adapt, or maintain appropriate policies for human review or editorial control prior to publication and that a natural or legal person holds editorial responsibility for the publication.