EU AI Act · Article 50

Article 50 takes effect August 2. Is your AI-generated content ready to disclose its origin?

If your platform generates images, video, audio, or documents and any of that content reaches EU users, Article 50 requires machine-readable provenance disclosure starting August 2, 2026. The SSL Provenance API adds that disclosure to your pipeline through a managed API, sized for GenAI-scale volume.

Enforcement begins
Sunday · August
2
2026

EU AI Act, Article 50

Machine-readable AI content disclosure

Why this applies to you

The obligation follows the content, not your headquarters

Article 50 of the EU AI Act requires providers of AI systems that generate synthetic image, audio, video, or text content to mark that output as machine-generated, in a format that downstream tools and platforms can detect. The obligation attaches to any provider whose AI-generated content reaches EU users, regardless of where the company is incorporated.

C2PA is the technical standard regulators and platforms are converging on for this disclosure. A C2PA manifest, cryptographically signed by a certificate from an authorized Certificate Authority, travels with the file and states what generated it and what changed since. SSL.com is one of the certificate authorities on the official C2PA Trust List.

The compliance gap is usually not policy, it's plumbing: adding sign-and-attach provenance to a generation pipeline that already runs at volume.

The SSL Provenance API

A managed API, not a certificate you manage yourself

The Provenance API is a fully managed SaaS layer that creates, edits, and signs C2PA and CAWG manifests for your assets through simple API calls, built for the volume a production GenAI pipeline actually generates.

Sign at your volume

Built for providers whose generation volume runs past what a single free-tier certificate covers, without you operating your own signing infrastructure.

Manifest via API call

Create, edit, and sign C2PA and CAWG manifests through the API instead of building manifest handling in house.

Fit assessed, not assumed

We size the right path to your actual use case: the Provenance API, a Premium certificate, or the free tier, depending on your volume and integration.

How teams get compliant

Three steps before August 2

1

Talk to our compliance team

Tell us your content volume, generation pipeline, and EU exposure. No cost, no commitment.

2

Get the right fit

We recommend the Provenance API, a Premium certificate, or the free tier based on what you actually need.

3

Integrate and sign

Connect the API to your pipeline and start attaching signed, C2PA-conformant provenance before the deadline.

Who this is for

Built for GenAI providers, not just content platforms

The clearest fit is a GenAI provider whose output reaches EU users today, but the same disclosure obligation is coming for a wider set of companies:

GenAI companies with EU customers, especially smaller and mid-tier providers who are not yet compliance-ready
GenAI companies without direct EU exposure today who want to prepare ahead of the requirement reaching them
Content platforms, media, and publishing companies evaluating content authenticity for their own products
Engineering and compliance leads scoping what a provenance integration actually requires

If you are earlier stage and expect to stay under high volume, the free-tier certificate covers a single Level 1 signing certificate at no cost. We'll tell you plainly if that's the better starting point.

Built on the open standard

Backed by the organizations behind C2PA

SSL.com is one of the certificate authorities on the official C2PA Trust List, issuing conformant certificates on a standard developed with Adobe, Google, Microsoft, BBC, Reuters, Sony, Nikon, and the broader Content Authenticity Initiative.

C2PA Trust List CA C2PA Specification v2.x RFC 3161 Trusted Timestamps Content Authenticity Initiative Member

Content credentials issued through SSL.com validate against the same C2PA Trust List that LinkedIn, TikTok, and C2PA-aware browser tools check when they display provenance to end users.

Questions

Before you talk to us

Do I need C2PA conformance before using the Provenance API?

Conformance is required for the free tier. For the Provenance API and Premium tier, we work through conformance and certificate issuance together as part of onboarding, so it does not have to be solved before you engage.

What happens on August 2 if we are not ready?

Article 50 enforcement begins that date. The fastest path to a signed pipeline before then is telling us your volume and integration now, so we can size the right certificate or API path and start onboarding ahead of the deadline.

Is this only relevant if we already have EU customers?

No. If your content reaches EU users at all today, the obligation applies now. If you don't yet have EU exposure, the same disclosure requirement is extending to more jurisdictions, so providers use this to prepare ahead of it reaching them.

How is the Provenance API different from the free-tier certificate?

The free tier issues one Level 1 signing certificate for a single generator product, sized for early-stage volume. The Provenance API is a managed service for signing manifests at production GenAI volume without you building or operating that infrastructure yourself.

Talk to our compliance team

Tell us about your generation volume and EU exposure. We'll size the right path, whether that's the Provenance API, a Premium certificate, or the free tier.

We'll follow up to understand your content volume and EU exposure, then recommend the right path.

SSL.com

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.

Privacy Overview
SSL.com

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

For more information read our Cookie and privacy statement.

3rd Party Cookies

This website uses Google Analytics & Statcounter to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping these cookies enabled helps us to improve our website.

Show details