The question arises the moment you open Article 50: the marking has to be “machine-readable”, but readable by which machine, in what format? The answer is surprising, and it is verifiable.
The Regulation cites no technical marking standard. And the code of practice on transparency of AI-generated content, the only dedicated European instrument, names none either: an exhaustive search across its thirty-eight pages for C2PA, Content Credentials, ISO, IETF, JPEG Trust, SynthID, CEN, CENELEC, IEEE, NIST, ITU, MPEG, EXIF and XMP. None of those strings appears in it.
This page deals with the technical side: what to implement, under what constraints, and what detection costs. It does not deal with the legal obligation itself (who carries it, with which exemptions, on which dates) which belongs to Article 50.
What does the EU AI Act require for marking AI-generated content?
A duty to mark, but no named standard for doing it. Article 50(2) requires outputs to be “marked in a machine-readable format and detectable as artificially generated or manipulated”: on that point the duty is one of result. What the state of the art bounds is the quality of the technical solutions — they must be “as effective, interoperable, robust and reliable as the technology allows” — not the duty to mark itself. The text names no format, no protocol and no consortium. What follows is what the text says, then what the European code of practice proposes to fill the gap.
“Providers shall ensure their technical solutions are effective, interoperable, robust and reliable as far as this is technically feasible, taking into account the specificities and limitations of various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards.”
Source: Article 50(2)
This is a reinforced best-efforts obligation, not an obligation of result. Four qualities are targeted (effective, interoperable, robust, reliable) bounded by what is “technically feasible”, and weighted by three factors the text names together: the specificities and limitations of the content type, the costs of implementation, and the generally acknowledged state of the art. The text refers to the state of the art “as may be reflected in relevant technical standards”: it anticipates standards, it imposes none.
Is signed metadata enough on its own?
Not according to the European code of practice, and it says why in its own words. Its Measure 1.1 starts from the finding that no single marking technique can, on its own, meet the four requirements of Article 50(2) for audio, images, video and containerised text. Signatories therefore commit to at least two machine-readable layers: signed metadata and imperceptible watermarking. Free-form text is the exception, because it “cannot transport metadata”: there, a watermark alone is treated as sufficient.
The code of practice is voluntary, and binds only its signatories. It distinguishes itself between what adherents will do, what they are encouraged to do and what they may do; several measures in it are explicitly optional. It remains the most operational reference available at Union level, without being conclusive proof, as it states itself: adherence “does not constitute conclusive evidence of compliance with these obligations”.
“So long as no single marking technique can, under the state of the art, ensure by itself compliance with the four requirements in Article 50(2) AI Act of effectiveness, interoperability, robustness, and reliability for audio, images, video, and containerised text, in particular for content that can be disseminated online, Signatories will implement a multi-layered marking approach to ensure that the outputs of their generative AI systems are marked with at least two layers of machine-readable marking”
Source: Code of Practice, Section 1, Measure 1.1
The scope is in the quotation itself, and it is wider than the usual summary: audio, images, video, and containerised text. A PDF, an office document or an HTML page carries metadata, and therefore falls under the two-layer approach.
The two layers are digitally signed metadata and imperceptible watermarking. Fingerprinting and logging remain optional.
Two exceptions only. A generative system embedded in a physical product, in a closed technical environment and for instructive purposes, where technical measures prevent the output from leaving the product. And free-form text: “given that free-form text cannot transport metadata, a single-layer of marking […] is considered sufficient”. Raw text carries no metadata: watermarking alone suffices.
Marking can be done elsewhere in the chain: by the system provider, by an upstream model provider, or by third parties. But “without prejudice to the Signatories’ own responsibility”: implementation can be delegated, responsibility cannot.
Who has to be able to detect the marking, and at whose cost?
Anyone, and free of charge — this is the strand summaries forget. The code of practice commits its signatories to making the detection solution available at no cost, in one of three forms: a public specification, a piece of software, or a service. It commits far more than a metadata format does.
This is the strand summaries forget, though it commits far more than a metadata format.
The detection solution is free of charge. “Signatories will make the detection solution available free of charge.” It may take three forms: a public specification allowing any third party to implement a detection mechanism, a piece of software, or a cloud service accessible by API to users in the Union.
One quantified derogation in the whole code, and it turns on the audience of the system, not the size of the company: a signatory with fewer than one million monthly users of its generative AI system, whose detection solution incurs substantial operational costs, may charge a reasonable fee where requests from a single user exceed a reasonable threshold.
And a closed list of beneficiaries of unconditional free access, with no volume limit: market surveillance authorities and other regulators, law enforcement authorities, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations.
Two very concrete undertakings come with it. Signatories will ensure that a detection result can be downloaded, on request, in a digitally signed format, including at minimum a hash of the content submitted, a URL or identifier of the solution, and a timestamp. And that the content submitted “is stored only for the duration of the detection and is permanently deleted immediately thereafter (i.e. with a ‘zero retention’ policy)”, subject to a carve-out for minimal data such as traffic logs, kept briefly on a valid legal basis to ensure security and prevent abuse.
The one date in the code: 2 February 2027
The document contains a single calendar date:
“Signatories will implement an interoperability solution for their detection mechanisms by 2 February 2027”
Source: Code of Practice, Section 1, Measure 3.4, point c)
It is a deadline of the code, binding on its signatories only, not to be confused with the dates of application of Article 50 itself.
Every other deadline in the code is conditional, suspended on the emergence of the state of the art: lifting the restriction on free-form text detection, ending the derogation for forensic detection, ending the interim benchmarking regime, and lowering the 200-token threshold below which a text is treated as very short and not watermarkable.
Does the EU AI Act require C2PA?
No. C2PA, the Coalition for Content Provenance and Authenticity, is a provenance standard carried by a private industry consortium. It is neither a harmonised standard nor a Union instrument, and neither the Regulation nor the European code of practice names it. Presenting C2PA as “the standard required by the AI Act” is a sourcing error, however widespread.
What C2PA is, on the other hand, is the most mature candidate available for one of the two layers the code expects.
That said, it remains the most mature candidate for the digitally signed metadata layer, and the code itself acknowledges that this is the only one of the two layers where the state of the art has settled:
“At the time of publication of this Code, relevant interoperability standards and/or best practices are yet to be developed, except for digitally signed metadata.”
Source: Section 1, Measure 3.4
The code therefore owns the gap and says so. Its signatories recognise that “further efforts will be required for such standards to emerge from international and European standard-setting organisations”.
A telling detail: the only standards named anywhere in the thirty-eight pages are three accessibility standards (ETSI EN 301 549, WCAG 2.1 Level AA and the W3C WCAG 2.1) and the only two standardisation bodies named are W3C and ETSI. Not CEN, not CENELEC, not ISO, not IETF, not NIST.
What should you actually implement?
Two layers on audio, image, video and containerised text; one on free text. Signed metadata plus an imperceptible watermark in the first case, the watermark alone in the second. This is not what Article 50 requires — it imposes neither a number of layers nor a free detection solution: it is the state of the art as the European code describes it, and the only reference available.
What follows reflects the state of the art as the code describes it. A non-signatory is not bound by it: Article 50 imposes neither a number of layers, nor a free detection solution, nor a signed attestation. But it is today the only European reference against which to place a technical choice.
Two layers on audio, image, video and containerised text: signed metadata, and imperceptible watermarking. On free-form text longer than 200 tokens, one layer: the watermark; below that threshold the code treats the text as very short and expects none.
Detection is the recurring cost line. That is where to budget: free access for authorities, media and researchers, downloadable signed attestation, zero retention.
Document the technical choice and the reasoning behind it. Since no standard is imposed, what will be examined is not your choice but your justification: why that solution was, at the time of implementation, as effective and interoperable as the technology allowed, given your costs.
What this page rests on
Article 50(2) of Regulation (EU) 2024/1689 in the consolidated version of 27 July 2026, the authentic text remaining the one published in the Official Journal, quotations reproduced from the official English text. The Code of Practice on Transparency of AI-Generated Content, read in full on 23 August 2026: thirty-eight pages, with an exhaustive search across fourteen standard and body names. The code exists in English only.
Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026. The Commission’s pages on the guidelines on the transparency obligations in Article 50 and on the code of practice on transparency of AI-generated content, both consulted on the same date.
Frequently asked questions
Is C2PA the standard the AI Act requires?
No. The Regulation names no technical marking standard, and the European code of practice on transparency of AI-generated content names none either, checked word by word across its thirty-eight pages. C2PA is a provenance standard carried by a private industry consortium: neither a harmonised standard nor a Union instrument. It is a serious candidate for the signed-metadata layer, not an obligation.
How many marking layers are needed?
The code of practice, which is voluntary, has its signatories implement at least two layers of machine-readable marking on audio, images, video and containerised text: digitally signed metadata and imperceptible watermarking. Two exceptions only: a generative system embedded in a closed physical product, and free-form text, which cannot carry metadata and for which a single layer is considered sufficient.
Does signing the code of practice make you compliant?
No, and the code says so itself: it serves as a guiding document for demonstrating compliance, while recognising that adherence to the Code does not constitute conclusive evidence of compliance with these obligations. It is a recognised means of demonstration, not conclusive proof.
Can the marking be done by a third party?
Yes. The code expressly allows marking techniques to be implemented at different stages of the value chain: by the system provider, by an upstream model provider, or by third parties. But that remains, in the code’s words, “without prejudice to the Signatories’ own responsibility”: implementation can be delegated, responsibility cannot.
This content is a technical and regulatory information resource. It does not constitute legal advice.