Skip to content

Build1 publisher3 min readPublished

Article 50 makes the export pipeline carry the AI provenance

The EU's synthetic-content transparency duties took effect on 2 August 2026, and they ask for two different artifacts: a machine-readable mark that survives every export, and a human-readable notice in every channel the asset lands in.

The Engineer · Build desk

Illustration accompanying Article 50 makes the export pipeline carry the AI provenance

What happened

  • Article 50 of the EU AI Act took effect on 2 August 2026, making labelling of deepfakes and certain AI-generated or manipulated text a legal requirement instead of a voluntary practice.
  • The article sets two duties: AI-generated or manipulated material must be identifiable through machine-readable marking, and deepfakes or covered public-interest text also need a clear disclosure to users.
  • The European Commission's Code of Practice for AI-generated content is voluntary guidance, while the transparency duties it is meant to help satisfy are binding.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Provenance has to survive the export step. Label the video in one channel's publishing tool and the machine-readable duty is still outstanding for the same video pushed to three other destinations.
  • decision The call on whether an asset is a deepfake or public-interest copy now belongs to a named owner inside the approval flow, at the point where the asset gets signed off.
  • exposure Agencies, freelancers and stock libraries sit upstream of the obligation, and a publisher whose delivery specs skip origin and editing history holds the duty without the record to answer it.
  • cost Reviewing the pre-August back catalogue inside roughly four months is work that falls on whoever stores the assets, and it is proportional to how little origin data was kept.

The mark and the notice are different artifacts, and they fail in different places. A notice gets rendered at publish time, and each channel renders it its own way. The mark has to be in the asset. A dev.to explainer of the rules puts the awkward case plainly: a team may need to preserve the information needed for machine-readable identification when it exports a video for several platforms [11].

Coverage differs too. Machine-readable identifiability attaches to AI-generated or manipulated material, while the user-facing disclosure triggers where the content is a deepfake, meaning AI-generated or manipulated image, audio or video resembling real people or events, or where covered text concerns matters of public interest [4][2][3]. The post's comparison is useful: an AI-created visual in a campaign may need a different assessment from a realistic synthetic video of a person making a statement [16]. Article 50 does not prohibit AI use, and sets a transparency baseline around content that can mislead people about what is real, who said something, or whether an event occurred [17].

Two of the Commission's outputs are optional; the duty underneath them is binding. The Code of Practice for AI-generated content is voluntary, published to help providers and deployers meet the binding Article 50 requirements [5][6]. The icon set is free, three icons plus variations, and it sits alongside the required disclosure; on its own it does not make content identifiable in a machine-readable way [7][8].

The build work is the origin record. Content usually comes from a mix of internal tools, agencies, freelancers, stock assets and social platforms, which makes it easy to lose track of whether the final asset was generated, edited or materially manipulated by AI [12]. The recommended list starts with an inventory of AI content tools used by employees, contractors and agencies, then recording origin and editing history for anything that may be published externally [13]. It adds a review step before publication for realistic synthetic media and relevant public-interest copy [14], and asks teams to establish who decides whether a disclosure is required [15]. Agencies and external creators may need clearer delivery requirements so that clients can make informed publishing decisions [19].

Material placed on the market before the rules took effect should be reviewed before December 2026 [10], about four months after the obligations landed [18]. That review runs on the same origin record, because only assets someone can identify as AI-generated can be re-labelled [12].

I would write the mark at generation, in the tool that produced the file, since every later export is a transcode with no reason to know. The dev.to write-up is a practitioner summary rather than the regulation: it notes that the text obligation is subject to exceptions, and names neither the exceptions nor a format for the machine-readable mark [20]. The Commission's guidance addresses placement, accessibility and interoperability [9].

What to watch

  • Whether signatories of the voluntary Code of Practice converge on a named marking format, since the published guidance describes interoperability without specifying one.
  • Whether distribution platforms preserve AI-origin data through upload transcode, which decides if a mark applied at generation is still there after publishing.
  • How the December 2026 review point for pre-existing content is treated in practice by teams that never recorded asset origin.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories