EU AI Act Article 50: The Law, the Code of Practice, and What a Buyer Can Verify

Last updated: July 31, 2026

EU AI Act Article 50 sets transparency duties for certain interactive and generative AI systems. Its general application date is 2 August 2026. One narrower transition runs alongside it: providers of synthetic-content systems placed on the Union market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).

Verdict: treat the Regulation, the Code of Practice, and the vendor’s own product documentation as three separate layers of evidence. A Code signature identifies a route. It does not show what the system you are buying emits.

Best for

  • Procurement and vendor-risk teams building a question set tied to named provisions
  • Product and governance teams separating provider duties from the duties their own organization carries
  • Publishers deciding what a Code signature belongs in a procurement record as

Not for

  • A determination of whether your organization is in scope
  • A ranking of which named vendors comply
  • Evidence that a marking survives export, compression, upload or re-encoding. Nothing here was measured

Key facts

ItemPositionApplies toSource layer
General application of Article 502 August 2026Providers and deployers, by paragraphRegulation
Transition for the marking duty2 December 2026Article 50(2) only, systems placed on the market before 2 August 2026Regulation
Substantive dutiesParagraphs 1 to 4Providers: 1 and 2. Deployers: 3 and 4Regulation
Delivery conditionsParagraph 5Governs how the information in 1 to 4 is providedRegulation
Named marking or detection standardNone prescribedAll providers under 50(2)Regulation and Code
Code of Practice statusVoluntary; assessed by the Commission and the AI Board as adequateSignatoriesCommission page
Presumption of conformityNot grantedSignatoriesRegulation, recital 41
Detection interoperability commitment2 February 2027Signatories onlyCode, Measure 3.4(c)

One date, two populations

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It postponed the high-risk obligations in Chapter III, Sections 1 to 3, to 2 December 2027 and 2 August 2028. Article 50 sits in Chapter IV. Paragraphs 1 to 6 were not amended; paragraph 7, which concerns codes of practice, was replaced.

The timetable still moved for one group. A new Article 111(4) gives providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content that were placed on the Union market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Recital 38 describes this as a four-month transitional period. It covers the marking duty and nothing else.

So 2 August 2026 is a general date, not an identical deadline for every system and every paragraph. Two populations exist from that day: systems already on the market before it, which carry a later date for one paragraph, and everything else.

Timeline of four EU AI Act dates with the condition attached to each. 2 August 2026 is the general Article 50 application date, with paragraphs 1 to 6 unchanged and paragraph 7 replaced by the Omnibus. 2 December 2026 is the Article 50(2) deadline for systems placed on the market before 2 August. 2 February 2027 is a detection interoperability commitment for Code signatories, with four implementation routes listed. 2 December 2027 and 2 August 2028 apply to Chapter III high-risk systems.
Each date attaches to a different provision, system population or Code commitment. The first two come from the Regulation. 2 February 2027 is a Code commitment for signatories and appears in no legislative instrument. Sources: Regulations (EU) 2024/1689 and (EU) 2026/1744; Code of Practice, Measure 3.4(c).

One further date is frequently attached to the wrong thing. Chapter XII, which contains the penalty provisions, has applied since 2 August 2025 under Article 113, third paragraph, point (b), with the exception of Article 101. The Omnibus did not amend that point.

Sources: Official Journal of the European Union, 24 July 2026, recital 38, Article 1(39) and (40) · Official Journal of the European Union, 12 July 2024, Chapter IV, Article 113 · European Commission, 27 July 2026

Four duties, two actors, one delivery rule

Article 50 is often summarized as one requirement. It contains four substantive duties, split across two actors, plus a fifth paragraph that governs how the information from the first four reaches people.

ParagraphBound actorTriggerExceptions in the paragraph
50(1)ProviderSystem intended to interact directly with natural personsWhere interaction is obvious to a reasonably well-informed, observant and circumspect person; specified law enforcement use
50(2)ProviderSystem generating synthetic audio, image, video or textAssistive function for standard editing; where input data or its semantics are not substantially altered; specified law enforcement use
50(3)DeployerEmotion recognition or biometric categorisation systemPermitted law enforcement use, subject to safeguards
50(4)DeployerDeep fake image, audio or video; text published to inform the public on matters of public interestLaw enforcement; artistic, creative, satirical, fictional or analogous works, where disclosure is limited so as not to hamper display or enjoyment; for text, human review or editorial control where a natural or legal person holds editorial responsibility
50(5)BothApplies to the information referred to in paragraphs 1 to 4Requires clear and distinguishable delivery at the latest at first interaction or exposure, conforming to applicable accessibility requirements

Two consequences for procurement follow from the split.

Paragraph 4 sits with the deployer, defined in Article 3(4) as anyone using an AI system under their own authority outside a personal, non-professional activity. Publishing AI-assisted output does not by itself trigger it. The trigger is deep fake content, as defined in Article 3(60), or text published to inform the public on matters of public interest, and both limbs carry their own exceptions.

Paragraph 6 states that paragraphs 1 to 4 are without prejudice to other transparency obligations laid down in Union or national law for deployers.

Sources: Official Journal of the European Union, 12 July 2024, Article 3(4), Article 3(60), Article 50

An assessed route, not a certificate

The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026. It was drafted by independent experts appointed by the AI Office. Adherence is voluntary. Section 1 addresses providers under Article 50(2) and (5). Section 2 addresses deployers under Article 50(4) and (5).

Three statements about its status come from three different documents, and all three need to be held at once.

The Commission’s policy page for the Code states that the Commission and the AI Board have confirmed the Code as an adequate voluntary tool for demonstrating compliance with the transparency obligations. The same page describes what happens to organizations that choose a different path: their measures will have to be shown to be adequate, and that will be assessed individually by different market surveillance authorities.

Recital 41 of the Omnibus states that codes of practice under Article 50(7) and Article 56(6) have limited legal effect and do not grant a presumption of conformity. That is the reason given for removing the power to approve such codes by implementing act.

The Code says the same thing about itself. Both of its sections open with the qualification that adherence to the Code does not constitute conclusive evidence of compliance.

None of the three cancels the others. The Code has been assessed. It creates no presumption. It is not conclusive evidence on its own. A procurement record that carries only the word “signed” has captured the first of those and none of the rest.

Four things are worth keeping distinct when reading a vendor’s claim: signing the Code, adhering to the specific measures that apply to that vendor’s systems, implementing those measures in the product a buyer actually purchases, and any assessment a competent authority may later make. Only the first two are visible from a signature.

Diagram of three evidence layers for EU AI Act Article 50. Layer one, the Regulation, sets the relevant paragraph, the provider or deployer role, and the required marking or disclosure. Layer two, the Code of Practice, sets a signatory's applicable commitments and its marking and detection architecture. Layer three, the product artifact, covers system version, modality, and plan and export-path coverage. A footer bar states that a Code signature identifies an implementation route and does not show what the purchased product path emits.
The three layers a buyer needs to keep separate when reading an Article 50 claim. The first two are public documents. The third describes the system being purchased, and no public document supplies it. Sources: Regulation (EU) 2024/1689; Code of Practice on Transparency of AI-Generated Content, 10 June 2026.

The Code’s own modal verbs

willMeasures the Code treats as mandatory for a signatory to be compliant with the relevant paragraphs, and which competent market surveillance authorities will monitor
encouragedOptional, not legally required, recommended
mayOptional, or a choice of implementation method

Several measures a vendor is likely to cite sit under encouraged or may, including richer provenance metadata, a built-in perceptible labelling control, and forensic detection.

Sources: European Commission, Code of Practice policy page, captured 31 July 2026 · Official Journal of the European Union, 24 July 2026, recital 41 and Article 1(20) · European Commission, 10 June 2026, Code of Practice, Sections 1 and 2

What signatories commit to implement

Article 50(2) requires that outputs be marked in a machine-readable format and detectable as artificially generated or manipulated, with technical solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. The qualification is in the statute, not something the Code added. No marking or detection specification is named in Article 50, in recital 133, in the Omnibus, or in the Code. The Code does name standards, but for accessibility, citing ETSI EN 301 549 and WCAG 2.1 Level AA in connection with how detection results are presented.

Marking. The Code’s Section 1 records that for content which can be disseminated online, no single marking technique meets the four requirements in Article 50(2). Its default is therefore a multi-layered approach: digitally signed metadata under Sub-measure 1.1.1, plus an imperceptible watermark under Sub-measure 1.1.2. Fingerprinting or logging is optional and, the Code states, not sufficient on its own.

That default is not the only route. A single layer is treated as sufficient for generative AI embedded in physical products operating in a closed environment, and for free-form text, which the Code says cannot transport metadata. Separately, a signatory may use an alternative technique, possibly a single technique, if it can prove to the competent market surveillance authorities, on recognized performance evaluation methods and benchmarks, that the technique achieves at least equivalent robustness, reliability, effectiveness and interoperability. The Code notes that pending such recognized methods, documented internal testing may be used, subject to authority review.

Detection. Signatories make a detection solution available in one or more of three forms: a public and ideally standardized specification any third party could implement, downloadable software, or a cloud service reachable through an API. It is provided free of charge. A signatory with fewer than 1 000 000 monthly users, whose detection incurs substantial operational costs, may charge where a single user’s request volume exceeds a reasonable threshold. Free access without volume restriction is preserved for market surveillance authorities and other regulators, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organizations. Detection for free-form text watermarking may be restricted to verified expert users, a restriction the Code says will be limited in time.

Robustness and interoperability. Measure 3.3 lists the processing operations that marking and detection are expected to withstand, including recompression, screenshots and screencasting, format change, cropping, scaling, paraphrasing, translation cycles, and what the Code calls the analogue hole, meaning print-and-scan, playback and recording, and screen camcording. Measure 2.2 covers forensic detection, which works without prior marking; it is optional, and the Code records that at publication such mechanisms were not deemed mature enough for the quality requirements in Article 50(2). Measure 3.4 states that interoperability standards and best practices are yet to be developed except for digitally signed metadata, and sets 2 February 2027 as the date by which signatories implement an interoperability solution for their detection mechanisms.

Sources: European Commission, 10 June 2026, Code of Practice, Section 1, recital (b), Measures 1.1, 2.1, 2.2, 2.3, 3.3, 3.4 · Official Journal of the European Union, 12 July 2024, Article 50(2), recital 133

The vendor evidence pack

Everything above is public text, which makes a document-level request possible without accusing anyone of anything. The value of each item lies as much in what it does not establish as in what it does.

Evidence itemWhat it establishesWhat it does not
System and version identifierWhich product the claim coversWhether regional deployments or aliases behave identically
Modality mapWhich of text, image, audio and video are in scope of the claimWhether every feature or export route within a modality is covered
Marking descriptionThe declared metadata, watermark or alternative techniqueWhether the mark survives your publishing chain
Export sampleWhat one documented path emitsBehavior across other plans, APIs, downloads and integrations
Detection accessWhich of the three delivery forms exists, and for whomAccuracy under transformation or deliberate removal
Test summaryReported metrics, datasets, transformations and error ratesIndependent verification
Code status and applicable sectionWhich commitments the vendor says it follows, and whether they are mandatory or optional under the CodeConformity, and implementation in the purchased path
Acceptable use policy clause on metadataWhether Measure 1.2’s prohibition on removing markings has reached the terms you signWhether downstream tools in your workflow respect it
Placement-date record, where the December transition is claimedThe factual basis offered for invoking Article 111(4)How versions and updates are treated for that purpose

The last row is the one with an open question underneath it. Article 3(9) defines placing on the market as the first making available of a system on the Union market. Article 111(2), which governs the high-risk grace period, is triggered by placing on the market or putting into service and carries a design-change rule, and recital 39 of the Omnibus supplies a type-and-model clarification for it. Article 111(4) uses one trigger, carries no design-change rule in its operative text, and has no equivalent recital. Article 3(23) defines substantial modification by reference to Chapter III, Section 2 and to the initial conformity assessment, neither of which applies to Article 50.

Across the three documents named in the methodology below, this briefing located no rule applying the placement concept to a continuously updated cloud service for the purposes of Article 111(4). That is a statement about those three documents. Commission guidelines on Article 50 were not read for this briefing, and the question should be checked against them before anyone relies on the gap.

Sources: Official Journal of the European Union, 12 July 2024, Article 3(9), (11), (23), Article 111(2) · Official Journal of the European Union, 24 July 2026, recitals 38 and 39, Article 1(39) · European Commission, 10 June 2026, Code of Practice, Measures 1.2 and 2.1

Where this briefing stops

This is a document-first briefing. No product was tested for it, and no vendor documentation was audited. That boundary matters most at exactly the point buyers care about: whether a mark placed at generation time is still present after an edit, an upload, a re-encode or a screenshot. The Code lists those operations as things marking should withstand. Whether any particular product withstands them is a measurement, and no measurement was taken here.

Five-step chain showing what a buyer needs in order to test an Article 50 claim. Step one, the applicable duty, covering paragraph, actor, content trigger and exception. Step two, the Code path, covering the signed section, mandatory versus optional measures, and the marking and detection routes. Both are documented in public sources. Step three, product scope, is vendor-specific. Step four, observable artifacts such as signed metadata, watermark, detector and test record, needs a source. Step five, workflow evidence across export, edit, upload and detection, was not tested for this briefing.
The first two steps come from documents this briefing read in full. The last three do not, and the fifth would require measurement rather than reading. Sources: Article 50 of Regulation (EU) 2024/1689; Code of Practice, Measures 1.1, 2.1 and 4.2.

Two source states are unresolved as of 31 July 2026 and should be checked before this briefing is relied on. The Commission’s policy page refers to guidelines on the scope of the Article 50 obligations; their final publication state was not established here. The signature instructions page said signatories would be publicly listed in July 2026; a public list was not located during this work. Either could change the picture in section 05, and the second would change what a buyer can check without contacting a vendor at all.

Sources: European Commission, Code of Practice policy page, captured 31 July 2026 · European Commission, 10 June 2026, how to sign the Code

FAQ

Did the Digital Omnibus delay Article 50?

It did not postpone the chapter. Paragraphs 1 to 6 of Article 50 were left unamended and apply from 2 August 2026. It did change the timetable for one group: new Article 111(4) gives providers of synthetic-content systems placed on the Union market before that date until 2 December 2026 to comply with Article 50(2).

What exactly changes on 2 December 2026?

The Article 111(4) transition ends. It applies to the machine-readable marking duty in Article 50(2) and to systems generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026. It does not extend Article 50(1), (3), (4) or (5). Separately, two new prohibitions inserted into Article 5 by the Omnibus apply from the same date.

Does signing the Code of Practice prove implementation?

The Commission’s policy page states that the Commission and the AI Board have confirmed the Code as an adequate voluntary tool for demonstrating compliance. Recital 41 of the Omnibus states that such codes do not grant a presumption of conformity, and the Code says adherence is not conclusive evidence. A signature identifies the route a vendor has chosen. Which measures it implements, for which system and output path, is a separate question answered by product documentation.

Does Article 50 require C2PA, SynthID or another named standard?

No marking or detection specification is prescribed. Article 50(2) sets performance criteria: effective, interoperable, robust and reliable, as far as technically feasible, taking account of the state of the art as may be reflected in relevant technical standards. Recital 133 lists categories of technique without naming a specification, and the Code does not name one either. A claim that a particular specification satisfies Article 50 is a claim by whoever makes it.

What can a buyer outside the EU verify before procurement?

Article 2(1)(a) covers providers placing systems on the Union market irrespective of where they are established, and Article 2(1)(c) covers providers and deployers located in a third country where the output produced by the AI system is used in the Union. Article 2(12) states that systems released under free and open-source licences fall outside the Regulation unless placed on the market or put into service as high-risk systems or as systems falling under Article 5 or Article 50. Whether a specific organization meets any of these descriptions is a determination about that organization. What is verifiable in advance is the evidence pack in section 05.

Sources: Official Journal of the European Union, 12 July 2024, Articles 2, 50, recital 133 · Official Journal of the European Union, 24 July 2026, recital 41, Article 1(39) and (40) · European Commission, Code of Practice policy page, captured 31 July 2026

Methodology

Tier C, document-first. No hands-on testing, no product measurement, no vendor documentation audit.

Read in full as published PDFs. Regulation (EU) 2024/1689, 144 pages, with Articles 2, 3, 50, 99, 111 and 113 and recital 133 extracted directly. Regulation (EU) 2026/1744, 41 pages. The Code of Practice on Transparency of AI-Generated Content, 38 pages, including both sections, the glossary and Annex 1.

Read as captures dated 31 July 2026. European Commission pages for the Omnibus entry into force, the Code of Practice policy page, the signature instructions page, the AI Act Service Desk implementation timeline, and the 10 June 2026 press release. Page state after that date is not established here.

Located but not read. Commission guidelines on the scope of the Article 50 transparency obligations. The Commission opinion on the adequacy assessment, which is referenced from the policy page and reported here as that page’s statement. Any public list of Code signatories.

Not examined. Vendor documentation, national implementing measures, national market surveillance guidance.

Absence statements. Where this briefing reports that something was not located, the scope is the three full documents listed above and the captures listed above. That is a statement about those sources.

Interpretation. Passages that draw a consequence rather than report a text are the comparison of Article 111(2) with Article 111(4) in section 05, and the four-way distinction between signing, adhering, implementing and being assessed in section 03. Both are the writer’s reading, marked as such.

Quotations are limited to fewer than fifteen words and one per source. Not legal advice. No conclusion is reached about whether any organization complies with any provision.

Verdict

The statute fixes the duty and the date. The Code of Practice describes one implementation route in operational detail, and the Commission’s policy page reports that the Commission and the AI Board have assessed that route as adequate. Neither of those closes a procurement question, because neither speaks to the system a buyer is about to sign for.

What is worth building is not a compliance opinion. It is a versioned artifact bundle: which system, which modality, which output path, which marking, which detection route, and what has actually been tested. A signature records participation in a route. The bundle records what shipped.

Related FSR briefings

Tier B means hands-on tested. Tier C means document-first.

Future Stack Reviews is an independent publication. This briefing is a structural audit of published documents and is not legal advice. Readers who need a determination about their own position should consult a qualified adviser in the relevant jurisdiction. Last updated 31 July 2026. Recheck trigger: publication state of the Commission guidelines on Article 50, and of the Code of Practice signatory list.