EU code on AI content marking: the signatory list is out — is your supplier on it?
7 min read
Today, 31 July 2026, the European Commission published the list of signatories to the Code of Practice on Transparency of AI-generated Content. It had been promised “before” 2 August and arrived with two days to spare: about 190 organisations, of which 83 signed Section 1 (providers) and 152 signed Section 2 (deployers). Article 50(2), (4) and (5) of Regulation (EU) 2024/1689 applies from Sunday 2 August 2026. For almost every company the first working day is Monday the 3rd, which leaves a few hours to run a check that was impossible as recently as yesterday.
What the list says, and what it does not
It is a two-column table of company names. No products, no systems, no signature dates, no scope of use. Add the two columns together and you get 235 signatures for 190 organisations: 45 names appear in both sections — that is our own count on the list as published today, not a figure the Commission states.
As Section 1 examples the Commission names Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; for Section 2, Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo and Lufthansa. The full Section 2 list also contains the European Court of Auditors, the National Bank of Romania, Barcelona Provincial Council and Harghita County Council: signing Section 2 is an act performed by a user of the technology, not by a vendor of it, and some public bodies have already done it. The Commission adds that about half the signatories are small and recent companies, and that all of them will be invited to two task forces starting in September 2026.
Why a name on the list does not answer your question
Three reasons, all of them in the Commission’s own documents.
First: Section 1 is not restricted to those under the obligation. The signing Q&A make clear that it may also be signed by providers of generative AI models and by technology providers of marking and detection solutions, even though they are “not directly bound by the obligation under Article 50(2)”. Finding a name in Section 1 does not prove that the system you bought falls under Article 50(2), nor that marking is switched on for it.
Second: a signature binds a legal entity, and the list carries nothing but that entity’s name. If your contract is with a different company inside the same group, the list tells you nothing about your position.
Third: the signatures are conditional. Again from the Q&A: “the signatures are conditional on a positive adequacy assessments by the Commission and the AI Board, as indicated in the Signature Form”. And adherence remains a way of demonstrating compliance, not compliance itself — that is the substance of the 20 July guidelines, which we read in full on 29 July.
If your supplier is not on it
The easiest mistake first: absence today is not refusal. The Commission’s page states that the code “remains open for signature” and that the list “is updated with new signatories on an ongoing basis”. Anyone who filed the form after 18:00 CEST on 27 July is simply not in the initial list.
Second, what the Commission expects of a non-signatory. Non-signatories “remain responsible for complying with the transparency obligations under Article 50 of the AI Act and must be prepared to demonstrate compliance through other adequate means”; they “should be able to explain and document how their chosen measures ensure compliance”; they “may have to carry out a gap analysis, comparing their measures with those set out in the code”; and they “may be subject to a larger number of requests for information or access from competent authorities”.
In one line to send to a supplier: the question is not “why didn’t you sign”, it is “send me the gap analysis and the documentation of your measures”.
What to put in writing before Monday
- Which legal entity signed, and which section, in exactly the wording that appears on the list.
- Which of the systems you supply to us fall under Article 50(2), from what date their outputs are marked, and with how many layers of marking.
- Where the free detection solution is, and whether the verification result can be downloaded in digitally signed form: these are Section 1 commitments, summarised here on 26 July.
- If the system was already on the market before 2 August: the transitional rule moves Article 50(2) marking to 2 December 2026. Careful, though: the Q&A, last updated on 29 July, still describe it as a proposal “if adopted”, while Regulation (EU) 2026/1744 has been published. Do not plan on the FAQ wording; get the supplier to state in writing which reading it applies. Either way your own deployer obligations under Article 50(4) start on 2 August, with no extension.
- If they have not signed: the gap analysis, in a dated document signed by someone with authority to bind the company.
There is a sixth item, and it has nothing to do with the supplier. The list lives on a web page that, by its own admission, “is updated on an ongoing basis” — and a page that changes is not evidence. On the day you run the check, save a dated copy (the Commission page offers a print-to-PDF function) and file it next to the entity name, the section and the time of the check. Two years from now, in front of a market surveillance authority, the question will not be “was it on the list”, but “what did you verify, when, and how do you prove it”.
Why there is no act to cite in the Official Journal
The anomaly is worth explaining, because it confuses procurement documents. Article 50(7) provided that the Commission could approve codes by implementing act. The Q&A record the change: “the procedure for the adequacy assessment of codes of practice has been amended by the AI Omnibus”, and now “a single adequacy assessment with an opinion of the Commission after consultation of the AI Board will produce the same legal effects”.
The practical consequence: you will not find an act approving the code in the Official Journal of the European Union. You will find an opinion and a web page. Anyone drafting a contract clause cannot cross-refer to an act that does not exist: the reference has to be to the code by name and version, and to a documented verification of adherence. The 20 July guidelines restate the ceiling for penalties — EUR 15 million or 3% of total worldwide annual turnover, whichever is higher — but the everyday risk is different: turning up to an inspection with a belief instead of a document.
Where the evidence ends up
Three pieces of evidence matter: the marked output, the receipt from the detection check, the dated copy of the list. They only genuinely exist if they stay where you can read them, retain them and produce them without asking anyone’s permission. That is why we work in two delivery modes only: on-premise, inside the client’s own environment; or a dedicated cloud, an environment reserved to a single client, reached over a dedicated VPN, with the data centre in Italy and premises staffed directly by us. In both, the logs stay yours.
The argument about how supplier dependency changes when the models and the infrastructure sit somewhere else is set out on a page of its own; the way we hold logs, roles and compliance together is described under AI governance.
Do you need, by Monday, a list of your suppliers with the section signed, the exact legal entity and the date of verification? Write to us.
Sources
- European Commission — “Strong backing for the Code of Practice on Transparency of AI-generated Content” (31 July 2026), with the full list of Section 1 and Section 2 signatories
- European Commission — Q&A on signing the code: the 27 July 2026 deadline, other adequate means, gap analysis, and the Omnibus effect on the adequacy procedure (last updated 29 July 2026)
- European Commission — Code of Practice on Transparency of AI-Generated Content, policy page (last updated 31 July 2026)
- Regulation (EU) 2026/1744 — AI Digital Omnibus (EUR-Lex)