EU AI Act and C2PA: What Article 50 Requires

Bluestein2 pts0 comments

EU AI Act and C2PA: What Article 50 Requires for AI Content | C2PA Viewer<br>Skip to main contentShare Feedback

Quick Reference<br>QuestionShort answerDoes the EU AI Act mandate C2PA?No, but C2PA is the named example in the Code of PracticeEffective dateAugust 2, 2026Maximum fine15M EUR or 3% of global turnover, whichever is higherWho is in scopeAny AI provider or deployer whose output reaches EU usersWhat gets markedSynthetic audio, image, video, and text outputsMarking standardMachine-readable, effective, interoperable, robust, reliable

The EU AI Act, formally Regulation (EU) 2024/1689, is the European Union's law governing artificial intelligence. Article 50 sets transparency obligations that take effect on August 2, 2026, and one of those obligations is specific to AI-generated content: outputs from generative AI systems must be marked in a machine-readable format detectable as artificially generated. The technical mechanism the European Commission's draft Code of Practice on Transparency names by example is C2PA Content Credentials. Article 50 takes effect on August 2, 2026. Penalties for non-compliance reach 15 million EUR or 3 percent of worldwide annual turnover, whichever is higher.<br>What Article 50 of the EU AI Act actually requires<br>Article 50 imposes transparency obligations on providers and deployers of certain AI systems. The clause that matters most for content provenance is Article 50(2): providers of generative AI systems must ensure that synthetic outputs (audio, image, video, or text) are marked in a machine-readable format and detectable as artificially generated or manipulated. The marking must be effective, interoperable, robust, and reliable, as far as is technically feasible.<br>Those four adjectives carry specific meaning under the Code of Practice on Transparency that the European Commission has been developing alongside the Regulation:<br>Effective : the marking must actually identify the content as AI-generated to a verifying party<br>Interoperable : any compliant verifier must be able to read the marking, not only the provider's own tool<br>Robust : the marking should resist common transformations such as format conversion or minor edits<br>Reliable : the marking should be tamper-evident, so that a verifier can detect whether it has been altered or forged<br>Article 50 also covers other transparency duties: deployers of emotion recognition systems must inform users, deployers generating deepfakes must disclose them, and providers of chatbot-style AI must make the artificial nature of the system clear to the person interacting with it. The marking obligation in 50(2) is the one with direct technical consequences for content credentials.<br>Does the EU AI Act mandate C2PA specifically?<br>No. The EU AI Act is technology-neutral and does not name C2PA in its operative articles. The Regulation describes the marking standard in functional terms (machine-readable, effective, interoperable, robust, reliable) and leaves the technical implementation to standards bodies and to the Commission's Code of Practice.<br>In practice, C2PA Content Credentials are the marking technology favored by the Commission's draft Code of Practice on Transparency. The Code lists C2PA as an example of a technical solution that satisfies all four criteria, alongside complementary signals like Google's SynthID watermarking. C2PA is an open standard already deployed by Adobe, OpenAI, and Google, with cryptographic signatures that make tampering detectable.<br>In short: the law does not require C2PA, but the regulatory ecosystem points firmly at it. Providers who adopt C2PA match the most concrete official guidance available on what compliant marking looks like.<br>Why C2PA, not just any watermark<br>Plain pixel watermarks (visible logos or invisible perceptual marks) are not interoperable in the Article 50 sense. Each provider would invent its own watermark, no third party could verify a competitor's mark, and there is no cryptographic chain of trust. C2PA solves this by defining a shared file format (JUMBF), a shared claim schema (JSON-LD), and a shared signature format (COSE). One verifier can read all of them. See what is inside a C2PA manifest for the technical detail.

Who must comply with Article 50?<br>Article 50 reaches two categories of organizations: providers of generative AI systems (the companies that build and offer the model) and deployers (companies that use the AI to generate content shown to people). Both bear obligations, but the marking duty in 50(2) sits with providers.<br>Geographic scope is broad. Article 2 of the Regulation places any provider in scope if it puts an AI system on the EU market, if its outputs are used in the EU, or if its users are located in the EU. A US-based provider like OpenAI, an Israeli image-generation startup, or a Japanese camera manufacturer is in scope as soon as European users encounter their content.<br>There are limited exceptions. Article 50(2) does not apply when the AI performs an assistive editing...

c2pa article marking content must code

Related Articles