
Related
The EU AI Act Marks a New Era of AI Transparency
10 minute read
Author
The rapid rise of AI-powered deception is forcing governments to rethink how synthetic content should be identified and disclosed online, and the European Union is among the first jurisdictions to address that challenge through comprehensive transparency requirements.
Beginning August 2, 2026, a new phase of the European Union’s AI Act comes into effect, introducing new transparency requirements for certain organizations that generate or deploy AI-generated content. These include obligations to disclose AI-generated content or manipulated, and, in some cases, make it machine detectable.
Even if your company is headquartered in the United States, these rules may still apply. The AI Act has extraterritorial reach, meaning certain organizations outside the EU may be subject to its requirements if they place AI systems on the EU market or if the outputs of those systems are used within the European Union.
For multinational companies, AI providers, software vendors, and enterprises serving European customers, these requirements may influence product design, governance, and compliance well beyond Europe.
The regulation reflects something larger: governments no longer assume people can reliably distinguish authentic content from synthetic media.
What Is the EU AI Act?
The European Union’s Artificial Intelligence Act is one of the world’s most comprehensive legal frameworks for regulating artificial intelligence.
Unlike an EU directive, the AI Act is a regulation, meaning it is binding in its entirety and directly applicable across all EU Member States without requiring separate national implementing legislation
Its provisions are being introduced in stages. Beginning August 2, 2026, Article 50’s transparency obligations become applicable.
What Does Article 50 Require?
At its core, Article 50 is about transparency. It creates two primary obligations: one for providers of generative AI systems and another for organizations or individuals deploying certain deepfake content.
The first obligation requires organizations that develop AI systems capable of generating synthetic image, audio, video, or text content, to make sure those outputs are marked in a machine-readable format and detectable as AI-generated or AI-manipulated.
A limited transition period extends the Article 50(2) marking obligation until December 2, 2026 for AI systems that were already on the market before August 2.
The second obligation requires organizations or individuals deploying deepfake content that depicts people, places, objects, or events in a way that could appear authentic to clearly disclose that the content has been artificially generated or manipulated.
How can organizations meet those requirements?
The AI Act establishes what organizations are required to achieve, but it doesn’t assign a single technical solution. To help organizations implement Article 50, the European Commission published a voluntary Code of Practice on Transparency of AI-Generated Content.
The Code doesn’t replace the law. Instead, it provides practical guidance on approaches providers can take to meet the AI Act’s transparency obligations.
Technical Approaches to Marking AI-Generated Content.
The AI Act does not prescribe a single marking technology. Instead, providers can use several complementary approaches to make AI-generated content machine-detectable. Each has different strengths and limitations, which is why the European Commission encourages layered approaches.
Metadata and Content Credentials
One approach is attaching cryptographically signed credentials to the metadata indicating that content was generated or modified using AI. Industry standards such as C2PA Content Credentials provide a common framework for capturing and preserving this information.
The primary limitation is that metadata can be removed during editing, compression, or distribution.
Imperceptible Watermarks
Another approach embeds information directly within the media itself using digital watermarking technologies.
“Solutions such as Google DeepMind’s SynthID and Adobe’s TrustMark have been adopted by several major AI providers and are more resistant to removal than metadata alone, although they also have practical limitations,” says GetReal co-founder Dr. Hany Farid
Fingerprinting
Some providers maintain perceptual fingerprints of generated content that allow them to recognize media they originally created, even if content credentials and watermarks have been stripped from the content.
What Makes a Marking Solution Effective?
The Code identifies four characteristics that marking and detection solutions should demonstrate:
- Effectiveness – Detection results should be understandable to the people using them.
- Reliability – Systems should accurately distinguish AI-generated or AI-manipulated content across a wide range of content types.
- Robustness – Marking should remain effective despite common processing operations and attempts to remove or alter it.
- Interoperability – Solutions should work across different platforms, products, and technical ecosystems.
Why Transparency Alone Isn’t Enough
The EU AI Act’s transparency requirements are an important step toward increasing trust in digital content. But transparency measures such as metadata, content credentials, and watermarks depend on someone choosing to disclose that AI was used.
The highest-risk uses of synthetic media like fraud, impersonation, and influence operations, are often carried out by actors with little incentive to preserve metadata, embed watermarks, or comply with disclosure requirements.
“A watermark is something someone chose to add,” explains Tina Nikoukhah, GetReal’s VP of Research.
“The traces we read in passive forensics are the ones an image cannot help but carry: every capture, every compression, every edit writes its own signature into the signal itself. Provenance markers are valuable when they are present but the highest-risk content comes precisely from tools and actors that never embed them in the first place. That is why provenance and forensic analysis are complementary, not substitutes.”
For enterprises that distinction matters. The AI Act may require transparency when organizations generate or deploy AI content, but security requires the ability to assess authenticity even when provenance information is absent, altered, or intentionally stripped.
Trust cannot depend solely on disclosures from those acting in good faith. It also depends on the ability to independently verify authenticity when those disclosures are missing.
See How GetReal Stops AI Impersonation