Operational notes Observatory

AI-generated content: has your vendor signed the EU code on marking?

6 min read

A hand-held ultraviolet lamp lighting up bundles of banknotes on a table, in black and white
An invisible mark exists only for whoever holds the tool that reads it. That is the part of the European code that concerns whoever receives the content.

On 27 July 2026, at 18:00 CEST, the deadline closed for joining the list of initial signatories to the code of practice on transparency of AI-generated content. That list, the European Commission writes, “will be published before the AI Act’s general date of entry into application of 2 August 2026”. It does not exist yet. Anyone already telling you who signed is describing a document that is not public.

One declaration does exist. On 24 July Google announced on its corporate blog that it is signing the code, adding a reservation in the same text: the concern that “adding more regulatory complexity — as technical solutions are still evolving” could contradict “Europe’s goals for competitiveness and simplification”. On 11 June OpenAI had published on its own site an announcement of support for the code: the text says support, it does not say it is signing. For other large providers of generative models we found no public statement, neither of signature nor of refusal. Absence of a statement does not mean refusal: it means absence of a statement.

What the code is, and what it is not

The final text — Code of Practice on Transparency of AI-generated Content — was published on 10 June 2026, at the end of a process facilitated by the AI Office. It has two sections. Section 1 covers providers of generative AI systems and implements Article 50(2) and (5) of Regulation (EU) 2024/1689: marking and detection. Section 2 covers deployers — those who use such systems professionally — and implements Article 50(4) and (5): disclosure of deep fakes and labelling of text published on matters of public interest. The sections can be signed separately, but each one in full.

On 8 July the Commission adopted the adequacy opinion provided for in Article 56(6): the code “adequately covers the obligations provided for in Articles 50(2), (4) and (5)”; the AI Board adopted its own adequacy assessment the following day. The same document carries the sentence that weighs more than most commentary: “adherence to the code does not constitute conclusive evidence of compliance with these obligations”. On 20 July the Commission’s guidelines on Article 50 followed, non-binding. And the Commission puts it plainly: the code “does not replace the AI Act”. Adherence is voluntary; Article 50 is not.

What changes between signing and not signing

From the Commission’s page: signatories “can rely on its measures to demonstrate compliance” across the Union, with “predictability, legal certainty and trust”, while future enforcement “will focus on monitoring adherence to the code”. Those who choose another route “will have to demonstrate that those measures are adequate”, and this “will be assessed individually by different market surveillance authorities”. Non-signatories, the Commission adds, “may be subject to a larger number of requests for information or access”.

No penalty flows from not signing, and the Commission says so: “not signing it does not constitute non-compliance with the AI Act; any enforcement consequences would relate to non-compliance with obligations in Article 50”. The penalty comes from Article 99(4)(g): up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher. The real tension is not about good guys and bad guys: a voluntary instrument is becoming the yardstick against which compliance with a legal obligation will be measured. Signing buys predictability. Not signing leaves you under the same rule, but having to prove compliance some other way, one national authority at a time.

The technical commitments, concretely

They are worth reading. Section 1: at least two layers of machine-readable marking — digitally signed metadata, time-stamped in a tamper-evident manner, plus an imperceptible watermark embedded in the content. A single layer is enough for free-form text, which cannot carry metadata, and for systems embedded in physical products in a closed environment. For free-form text longer than 200 tokens the watermark still has to be applied. Signatories also undertake not to remove markings already present in content their systems transform.

The part that matters to whoever receives the content: signatories must make available a free detection solution — a public specification, a piece of software or a cloud service via API — accessible to deployers, users, authorities, researchers and media, with volume exemptions allowed only to the smallest providers. And the detection result must be downloadable in a digitally signed format, including at least a hash of the content submitted, an identifier of the detection solution and a timestamp. Content uploaded for checking is deleted immediately: a zero retention policy. Section 2 sets the label for deployers: the capitalised acronym “AI” as the main visual element (the EU icon is free to use), perceivable at first exposure and repeated in video after interruptions; for audio, a spoken disclaimer at the start.

The part that concerns you, not them

Here is the asymmetry almost nobody has noticed. Regulation (EU) 2026/1744 — the AI Digital Omnibus, in force from tomorrow — added Article 111(4) to the AI Act: providers of systems generating synthetic content placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). But that window covers upstream marking only. Deployer duties under paragraph 4 — disclosing deep fakes, disclosing published text on matters of public interest — apply from 2 August 2026, with no extension.

Translated: in seven days you may have to label content your vendor is not yet required to mark. And if that vendor has not signed, you do not even have the commitment to receive the free detection tool and the signed receipt. You do the checking, you build the evidence. This is close to, but distinct from, yesterday’s piece on contractual use limits: there the point was that an unverifiable clause does not exist; here the commitment is public and written, but voluntary — and the duty towards your own users stays yours. The questions to put in writing to a model provider we already listed ahead of 2 August: add three. Which marking layers you apply, where the detection solution sits, from what date.

One underlying limit remains: marking can be checked and preserved only where the infrastructure is under control. An output received from an external service, checked with an external tool and archived elsewhere does not produce evidence you can still show in two years. Our set-up for AI governance comes in two delivery modes: on-premise in the client’s own environment, or a dedicated cloud reserved to a single client, with a dedicated VPN, a data centre resident in Italy and premises staffed directly by us. In both, the marking check and its evidence stay inside your perimeter: your logs, retention decided by you.

Want to know which of the content you publish falls under Article 50, and how to preserve the evidence? Half an hour with one of our experts for a map of the cases and the records.

Sources