Article 50 takes effect August 2. Is your AI-generated content ready to disclose its origin?
If your platform generates images, video, audio, or documents and any of that content reaches EU users, Article 50 requires machine-readable provenance disclosure starting August 2, 2026. The SSL Provenance API adds that disclosure to your pipeline through a managed API, sized for GenAI-scale volume.
EU AI Act, Article 50
Machine-readable AI content disclosure
The obligation follows the content, not your headquarters
Article 50 of the EU AI Act requires providers of AI systems that generate synthetic image, audio, video, or text content to mark that output as machine-generated, in a format that downstream tools and platforms can detect. The obligation attaches to any provider whose AI-generated content reaches EU users, regardless of where the company is incorporated.
C2PA is the technical standard regulators and platforms are converging on for this disclosure. A C2PA manifest, cryptographically signed by a certificate from an authorized Certificate Authority, travels with the file and states what generated it and what changed since. SSL.com is one of the certificate authorities on the official C2PA Trust List.
The compliance gap is usually not policy, it's plumbing: adding sign-and-attach provenance to a generation pipeline that already runs at volume.
A managed API, not a certificate you manage yourself
The Provenance API is a fully managed SaaS layer that creates, edits, and signs C2PA and CAWG manifests for your assets through simple API calls, built for the volume a production GenAI pipeline actually generates.
Sign at your volume
Built for providers whose generation volume runs past what a single free-tier certificate covers, without you operating your own signing infrastructure.
Manifest via API call
Create, edit, and sign C2PA and CAWG manifests through the API instead of building manifest handling in house.
Fit assessed, not assumed
We size the right path to your actual use case: the Provenance API, a Premium certificate, or the free tier, depending on your volume and integration.
Three steps before August 2
Talk to our compliance team
Tell us your content volume, generation pipeline, and EU exposure. No cost, no commitment.
Get the right fit
We recommend the Provenance API, a Premium certificate, or the free tier based on what you actually need.
Integrate and sign
Connect the API to your pipeline and start attaching signed, C2PA-conformant provenance before the deadline.
Built for GenAI providers, not just content platforms
The clearest fit is a GenAI provider whose output reaches EU users today, but the same disclosure obligation is coming for a wider set of companies:
If you are earlier stage and expect to stay under high volume, the free-tier certificate covers a single Level 1 signing certificate at no cost. We'll tell you plainly if that's the better starting point.
Backed by the organizations behind C2PA
SSL.com is one of the certificate authorities on the official C2PA Trust List, issuing conformant certificates on a standard developed with Adobe, Google, Microsoft, BBC, Reuters, Sony, Nikon, and the broader Content Authenticity Initiative.
Content credentials issued through SSL.com validate against the same C2PA Trust List that LinkedIn, TikTok, and C2PA-aware browser tools check when they display provenance to end users.
Before you talk to us
Do I need C2PA conformance before using the Provenance API?
Conformance is required for the free tier. For the Provenance API and Premium tier, we work through conformance and certificate issuance together as part of onboarding, so it does not have to be solved before you engage.
What happens on August 2 if we are not ready?
Article 50 enforcement begins that date. The fastest path to a signed pipeline before then is telling us your volume and integration now, so we can size the right certificate or API path and start onboarding ahead of the deadline.
Is this only relevant if we already have EU customers?
No. If your content reaches EU users at all today, the obligation applies now. If you don't yet have EU exposure, the same disclosure requirement is extending to more jurisdictions, so providers use this to prepare ahead of it reaching them.
How is the Provenance API different from the free-tier certificate?
The free tier issues one Level 1 signing certificate for a single generator product, sized for early-stage volume. The Provenance API is a managed service for signing manifests at production GenAI volume without you building or operating that infrastructure yourself.
Talk to our compliance team
Tell us about your generation volume and EU exposure. We'll size the right path, whether that's the Provenance API, a Premium certificate, or the free tier.