Starting August 2, 2026, any organization that builds or deploys generative AI systems that reach people in the EU has a new legal duty: it must disclose that the content is AI-generated. That duty derives from Article 50 of the EU AI Act and is among the most far-reaching provisions of the regulation.
Unlike the Act’s high-risk AI rules, which apply only to specific use cases such as hiring or credit scoring, Article 50 applies to nearly any AI system that interacts with people, writes for people, or presents people with synthetic media.
For organizations operating globally, understanding EU AI Act transparency requirements is becoming an essential part of any AI governance strategy. Fortunately, technologies such as C2PA Content Credentials, trusted timestamping, and CAWG identity assertions provide a practical framework for demonstrating AI content authentication and AI provenance.
Explore SSL’s C2PA SolutionsWhat Is EU AI Act Article 50?
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) sets out transparency obligations for providers and deployers of certain AI systems. In plain terms, it requires that people be told when they are interacting with AI, and that AI-generated or manipulated content be detectable as artificial. The goal, as the Act’s recitals put it, is to reduce the risk of deception, impersonation, and misinformation, and to preserve trust in the information people see and interact with online.
What makes Article 50 different from most of the AI Act is scope. The Act’s headline rules, the ones covering conformity assessments, technical documentation, and CE marking, apply only to AI systems classified as “high-risk.”
However, Article 50 doesn’t work that way. It applies to any AI system used in one of four specific situations, regardless of risk classification. A company with zero high-risk AI systems can still carry significant Article 50 obligations simply because it runs a customer support chatbot, publishes AI-drafted articles, or uses a tool that produces synthetic images.
From August 2, 2026, all AI systems within the scope of Article 50 that are placed on the market or put into service in the EU must meet these obligations, regardless of when the system was first released.
How EU AI Act Article 50 Affects Businesses Using AI
Many organizations assume EU AI Act Article 50 only affects AI developers or large technology companies. In reality, the regulation reaches much further.
If your organization uses generative AI to create or modify content viewed by audiences in the European Union, you may have AI transparency obligations.
Examples include:
- Marketing teams generating AI-assisted advertising campaigns
- Businesses publishing AI-generated blog posts or product descriptions
- News organizations using AI to summarize articles
- Financial institutions producing customer communications
- Healthcare providers creating educational content
- Law firms drafting AI-assisted documentation
- Retailers producing synthetic product imagery
- Media organizations publishing AI-generated audio or video
The regulation distinguishes between providers and deployers.
Providers of generative AI systems are responsible for ensuring synthetic outputs include machine-readable AI content labeling.
Deployers, meaning organizations that professionally use AI systems, are responsible for disclosing AI-generated or manipulated content presented to the public. This includes deepfakes and certain AI-generated content related to matters of public interest.
Both carry obligations, though which ones apply depends on the type of system and how it’s used. Importantly, the obligations extend to open-source AI systems too. There is no blanket exemption for open models.
Even when humans review AI-generated content, organizations should carefully evaluate whether transparency obligations still apply.
The Four Obligations Under Article 50
Article 50 covers four distinct categories of AI systems. It helps to think of them as four separate rules that happen to live in the same article:
1. Inform people when they are interacting directly with an AI system (Article 50(1))
Suppose an AI system is designed to interact directly with a person, such as a chatbot, virtual assistant, automated phone system, or AI agent. The provider must design it so the person knows they’re talking to a machine, not a human. There’s a narrow exception: if it’s already obvious to a “reasonably well-informed, observant and circumspect” person that they’re dealing with AI, disclosure isn’t required. Regulatory guidance has also confirmed that autonomous AI agents fall under this rule, and that where a provider can’t reliably predict whether an agent will interact with a human, the safer path is to design it to disclose its nature whenever that’s plausible.
There’s a separate carve-out for AI systems authorized by law to detect, prevent, investigate, or prosecute criminal offenses, unless the system is one the public can use to report a crime.
2. Ensure AI-generated media and text include machine-readable markings that identify them as artificial (Article 50(2))
Providers of generative AI systems, including general-purpose AI systems, that produce synthetic audio, images, videos, or text must ensure their outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. This is the “watermark your outputs” rule, and it’s the one most closely tied to standards like C2PA Content Credentials.
Critically, the marking has to actually work. The Act requires that the technical solutions used be effective, interoperable, robust, and reliable, taking into account the state of the art and implementation costs. A label that disappears the moment an image gets re-encoded or screenshotted doesn’t meet the bar.
3. Notify individuals when emotion recognition or biometric categorization systems are being used (Article 50(3))
Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them how the system works and how it handles any personal data in line with the GDPR and related EU data protection law. As with the other rules, there’s an exception for systems permitted by law to detect, prevent, or investigate criminal offenses.
4. Clearly disclose AI-generated or manipulated content, including deepfakes and certain public-facing AI-generated text (Article 50(4))
Deployers who use AI to generate or manipulate image, audio, or video content that qualifies as a deepfake must disclose that the content is artificial. Separately, deployers who publish AI-generated or AI-manipulated text specifically to inform the public on matters of public interest must also disclose that the text is AI-generated.
There’s a meaningful exception here: the text disclosure obligation doesn’t apply if the content has undergone human review and a natural or legal person assumes editorial responsibility for it. In practice, this means a fully AI-drafted article that a human editor reviews and takes ownership of may fall outside this specific disclosure duty, though other obligations may still apply. “Matters of public interest” is read broadly enough to pull in employment, health, financial, and legal communications, not just news.
Penalties for Non-Compliance
Article 50 violations are enforced seriously. Non-compliance can result in fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is greater, for offending companies. EU institutions, bodies, and agencies face a separate cap of up to €750,000.
The European Commission has also been developing a voluntary Code of Practice on Transparency of AI-Generated Content, along with implementation guidelines, to help standardize how companies meet the marking and labeling requirements. Organizations that adhere to an approved code can cite that adherence as a mitigating factor and may see enforcement focus shift toward monitoring code compliance rather than case-by-case investigations.
Why “We Added a Label” Isn’t the Same as Compliance
Here’s where most Article 50 implementation plans run into trouble. Meeting Article 50(2) isn’t just about slapping a visible watermark on an image or appending “AI-generated” to the bottom of an article. The Code of Practice makes clear that no single marking technique is sufficient on its own. A defensible compliance program needs to survive the real world: screenshots, re-encoding, social media re-uploads, format conversions, and deliberate attempts to strip markings out.
That means a workable approach layers several mechanisms together:
- Signed provenance (hard binding): A cryptographically signed manifest, such as a C2PA Content Credential, bound to the content and tamper-evident if altered.
- Watermark and fingerprint (soft binding): An imperceptible mark that can still be recovered even if the metadata gets stripped out.
- Human-readable labeling: The visible disclosure a person actually sees, ideally using a standardized AI indicator.
- Governance: Contract terms that prohibit stripping credentials, pipelines that preserve them end to end, and a way for people to verify a piece of content’s provenance publicly.
C2PA Content Credentials have emerged as the backbone of the first and second layer, and are effectively the only widely deployed standard that meets the Code’s bar for signed, tamper-evident, interoperable metadata.
The Trust Layer: What Actually Makes a Credential Believable
Anyone can generate a key pair and sign metadata. What makes a Content Credential something a viewer, a platform, or a regulator can actually rely on is the chain of trust standing behind that signature. Three things have to hold up:
What: the manifest signature. The manifest needs to be signed with a certificate that chains to a Certificate Authority on the published C2PA Trust List such as SSL.com. That’s what lets any compliant verifier validate the credential automatically, without a proprietary check.
When: a conformant timestamp. An independent timestamp from a Time Stamp Authority on the C2PA TSA Trust List, such as SSL, proves that the content was signed at a specific moment in time. It keeps the credential valid even after the signing certificate itself expires. This lines up directly with the Code of Practice’s call for information to be digitally signed and time-stamped.
Who: verified identity. The CAWG (Creator Assertions Working Group) identity-assertion layer binds a verified legal entity or individual to the credential. This moves the conversation from “which tool made this” to “who stands behind it.” Only a limited set of Certificate Authorities are currently authorized to issue CAWG identity assertions, and the Code of Practice specifically encourages their use.
Miss any one of these three proofs, and the credential is technically present but practically weak: unverifiable, undatable, or anonymous.
A Quick Compliance Checklist
If you’re building an Article 50 program, a few things are worth thinking about to build a strong system:
- Do your outputs carry a machine-readable marking, not just visible to humans?
- Does that marking survive re-encoding, screenshots, and platform uploads?
- Is your signing certificate rooted in the C2PA Trust List?
- Are you using a Time Stamp Authority on the C2PA TSA Trust List?
- Can you attach a verified identity to your content through CAWG assertions?
- Does your provider have a verifiable public CA track record with independent audits such as WebTrust?
- Is that provider active in standards bodies like the CA/Browser Forum?
- Does the signing service actually integrate into your existing content pipeline, or does it require rebuilding it?
Where SSL Fits
Getting the marking right is one problem. Getting the trust behind the marking right is a different one, and it depends on infrastructure that takes years to establish: trust-list membership, audited operations, and recognition across the verification ecosystem.
SSL is a C2PA Trust List-conformant Certificate Authority and a C2PA-conformant Time Stamp Authority, and is one of the limited set of public CAs authorized to issue CAWG identity-assertion certificates.
SSL brings all these vital trust components together under one globally trusted public PKI, making it easier for organizations to implement Article 50 compliance today while preparing for the future of trustworthy AI-generated content.
Talk to the SSL team about C2PA and CAWG certificates to learn more about how Article 50 compliance fits into your existing content pipeline, or explore SSL’s full range of Content Authenticity solutions to get started.
