The European Commission today published its guidelines and a finalised Code of Practice on the transparency obligations for artificial intelligence systems under Article 50 of the AI Act, fixing the technical detail that providers and deployers of generative systems must meet before those duties become legally binding on 2 August 2026.

The two documents landed together. One is a set of Commission guidelines, issued as Communication C(2026) 5054 final and dated 20 July 2026 in Brussels, that interprets who falls within scope of Article 50 and how each obligation is meant to work in practice. The other is the Code of Practice on Transparency of AI-Generated Content, a voluntary framework drawn up by independent experts through a multi-stakeholder process facilitated by the AI Office. According to the Commission, adherence to the Code is voluntary, but the transparency requirements under Article 50 are legal obligations regardless of whether a company signs.

The timing carries weight for anyone producing or distributing synthetic media in Europe. The AI Act, formally Regulation (EU) 2024/1689, entered into force on 1 August 2024. Its transparency provisions were among the last major obligations to take effect under the original timetable, and they apply two years after entry into force, on 2 August 2026. For the advertising and publishing industries, the guidelines convert months of draft text into a settled reading of the rules just under two weeks before the compliance date.

Two obligations, two sets of duty-holders

Article 50 splits its content-transparency requirements across two distinct groups. The distinction determines who has to do what.

Under Article 50(2), providers of AI systems that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. A provider, defined in Article 3(3) of the AI Act, is the entity that develops a system and places it on the market under its own name. This is the marking-and-detection layer, and it sits with the companies that build the models.

Under Article 50(4), deployers of systems that produce deep fakes or text published to inform the public on matters of public interest must disclose that the content has been artificially generated or manipulated. A deployer, defined in Article 3(4), is the entity using a system under its own authority for professional purposes. This is the human-visible labelling layer, and it sits with the organisations that publish or distribute content, including advertisers, agencies and media outlets.

The guidelines stress that the two obligations can apply cumulatively to a single system engaging different actors. If a system generates images as part of a direct interaction with a person, the provider may have to comply with both Article 50(1) and (2). Where that system also produces deep fakes or public-interest text, the deployer may additionally have to comply with Article 50(4). PPC Land has tracked the split between the marking regime for providers and the labelling regime for deployers since the Commission released its free EU labelling icons earlier this month.

The 200-token line that governs text

The finalised Code sets a specific technical threshold for text. Under Sub-measure 1.1.2, providers must mark AI-generated or manipulated content with an imperceptible watermark, with an exception for very short text. For free-form text longer than 200 tokens, watermarking still has to be applied, even though the Code acknowledges it may carry lower reliability than watermarking longer passages. The glossary defines very short text as anything below that 200-token line, noting that state-of-the-art techniques can watermark text as short as 200 tokens with at least a basic level of reliability, with the expectation that the threshold will fall as methods improve.

To compensate for the weaker reliability of text watermarking, the Code permits providers to restrict access to the corresponding detection tool to verified expert users, a category that includes market surveillance authorities, law enforcement, media, fact-checkers, trusted flaggers, independent researchers and civil society organisations.

For most content that can circulate online, a single marking technique is not treated as sufficient. The Code requires a multi-layered approach: at least two machine-readable marking layers, combining digitally signed and time-stamped metadata under Sub-measure 1.1.1 with an imperceptible watermark under Sub-measure 1.1.2. A single layer is accepted only in narrow cases, such as a generative system embedded in a physical product operating in a closed, controlled environment, or for free-form text, which the Code notes cannot carry metadata.

Detection has to be free, with a usage carve-out

The marking obligation is inseparable from detection. Under Commitment 2, providers must make available a detection solution so that deployers, end-users exposed to the content, and legitimate parties such as authorities and researchers can verify whether content came from a given system.

That solution has to be free of charge as a default. The Code carves out one exception tied to scale: providers with fewer than 1,000,000 monthly users of their generative system, whose detection solution incurs substantial operational costs, may charge a reasonable and proportionate fee where a single user's request volume exceeds a reasonable threshold. Even then, free access without any volume restriction must always be provided to market surveillance authorities, other regulators, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations.

Detection results must be handled under a zero-retention rule. Under Sub-measure 2.1.3, content submitted for detection is stored only for the duration of the detection and permanently deleted immediately afterward, with providers barred from keeping a verbatim copy. The guidelines reinforce that the marking and detection obligation focuses on how content was created and its artificial origin, not on who created it, so information about the creator should not be processed for this purpose.

What actually has to carry a visible label

The labelling duty under Article 50(4) is narrower than the marking duty, and the guidelines spend considerable space defining its edges. Two categories trigger disclosure: deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest without human review or editorial control.

deep fake is defined in Article 3(60) as AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The guidelines break this into four cumulative criteria and work through them with examples. An AI-manipulated image of two real footballers in front of a building resembling a stadium qualifies. So does AI-generated audio cloning a podcast's regular presenters, or a synthetic avatar of a company CEO addressing employees. By contrast, an AI-generated image of a sphinx flying over the Eiffel Tower does not, because content that defies the laws of nature has no potential to mislead and falls outside scope.

For text, the guidelines define matters of public interest broadly, covering politics, public administration, justice, fundamental rights, public health, environmental protection, consumer safety, and economic, financial, scientific or cultural developments that merit public debate. An AI-generated summary of a human-written article about a town council decision, sitting on a newspaper site, falls within scope. AI-manipulated text inside a product description, absent claims about health, safety or sustainability, does not.

The advertising sector receives no lighter treatment. Article 50(4) provides an attenuated regime for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works, limiting disclosure to a manner that does not hamper enjoyment of the work. The guidelines exclude persuasive commercial content from that regime. An AI-manipulated video in the style of a teleshopping channel, using synthetic humans to advertise a product with the aim of persuading viewers to buy, is listed as content that does not constitute an artistic or satirical work. This aligns with earlier reporting that advertising content is explicitly excluded from the lighter disclosure regime available to genuinely creative material.

Placement, and the editorial-responsibility trade

The Code is specific about where a label goes. Under the placement rules in Section 2, the icon or equivalent label must be clearly perceivable at the latest at the time of first exposure, placed where no intervening overlay elements exist, and directly embedded into the content, with a limited exception for creative works and for user-interface overlays. For published text, the label belongs above or at the top of the text, near the headline, or in the colophon. Where content is reshared or clipped, the disclosure is expected to travel with it, including at the beginning of a video and, at minimum, after interruptions such as advertising breaks.

Three EU icons accompany the framework, published through the Commission's Shaping Europe's Digital Future portal. One marks fully AI-generated content, carrying the label "AI GENERATED"; a second marks partially AI-modified content, carrying "AI MODIFIED"; and a third basic icon carries only the capitalised "AI" acronym for deployers to supplement with their own text or an interactive layer. According to the Annex, the design was subject to empirical user-testing across several Member States, and variants that included a clear textual label such as "modified" performed significantly better on noticeability and clarity than the icon alone.

The text obligation contains an exemption that shifts, rather than removes, exposure. Under Article 50(4), second subparagraph, AI-generated text that has undergone human review or editorial control, where a natural or legal person holds editorial responsibility, falls outside the disclosure duty entirely. The guidelines set a substantive bar. Human review means deliberate examination of the content's substance by a person with relevant expertise, with fact-checking as a minimum requirement. Superficial or purely formal checks, such as spell-checking or a cursory approval, do not qualify. Where AI is used to modify content after editorial sign-off, the guidelines state the resulting content must be treated as AI-generated again, voiding the exemption.

The penalty structure, and who enforces it

The guidelines set out the consequences for getting this wrong. Providers and deployers that do not comply with Article 50 may be fined up to EUR 15,000,000 or, if the offender is an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. EU institutions, bodies and agencies that violate the obligations face administrative fines of up to EUR 750,000. For small and medium enterprises and startups, each fine is capped at whichever of the percentage or the fixed amount is lower.

Enforcement runs through the market surveillance system established by Regulation (EU) 2019/1020 and the AI Act. Market surveillance authorities designated by Member States, the AI Office, and the European Data Protection Supervisor supervise compliance within their respective remits. Those authorities can act on their own initiative or following a complaint, which any affected person has the right to lodge. When fixing a fine, competent authorities weigh factors including the nature, gravity and duration of the infringement, whether it was negligent or intentional, and the degree of cooperation shown.

Signing the Code changes where scrutiny concentrates rather than removing it. According to the guidelines, the Commission and the AI Board have confirmed the Code is an adequate voluntary tool to demonstrate compliance. For signatories, supervisory activity focuses on whether they have adhered to the Code and implemented its measures. Providers and deployers that do not sign are expected to demonstrate compliance through other adequate means, which the guidelines suggest may involve a gap analysis against the Code and can expose them to a larger number of information and access requests. The Code itself states that adherence does not constitute conclusive evidence of compliance.

A staged set of deadlines

The obligations do not all bite at once. Article 50 applies from 2 August 2026, requiring in-scope systems placed on the market to comply on that date regardless of when they were placed. A grandfathering rule under the recently adopted AI Omnibus gives providers of generative systems already on the market before 2 August 2026 a transitional period, until 2 December 2026, to bring their marking and detection under Article 50(2) into conformity. Systems that are partly interactive and partly generative can use that transitional period only for the marking obligation; the disclosure duty for direct interaction under Article 50(1) applies from 2 August 2026.

A separate interoperability deadline sits further out. Under Measure 3.4, signatories must implement an interoperability solution for their watermark-detection mechanisms by 2 February 2027, through one of several routes including a public industry-standard access method, a publicly readable signpost in the content, or a shared detection solution run by a consortium. Content generated before 2 August 2026 does not need to be marked or labelled retroactively, though text generated before that date but published on or after it must be labelled.

Why this matters for the marketing community

For advertisers, agencies and publishers, the guidelines close a question that has run since the Commission opened its Article 50 consultation in September 2025. The clarity is not abstract. It arrives against a backdrop of platform-level moves that have already redistributed compliance duties. PPC Land reported that Google shifted AI ad-labelling liability toward advertisers through a July 2026 changelog that gave advertisers a labelling control across five products while confirming that AdSense publishers carry no equivalent setting. The Article 50(4) framework points in the same direction, placing the labelling obligation on the deployer that publishes content rather than the platform that carries it.

The editorial-responsibility exemption is likely to matter most for organisations publishing AI-assisted commentary, market analysis or news on matters of public interest. It offers a route out of the labelling duty, but the guidelines make clear that claiming it means owning substantive review, not a formality. For a trade publication or a brand newsroom producing AI-assisted material at volume, the choice between labelling content and documenting a qualified editorial process is a structural one, not a cosmetic one.

The framework also intersects with regimes the marketing industry already navigates. The guidelines note that Article 50 applies in parallel to data protection, consumer protection and the Digital Services Act. Machine-readable marks under Article 50(2) can help providers of very large online platforms meet their obligations under Articles 34 and 35 of the DSA to identify and mitigate systemic risks from AI-generated content, including disinformation affecting electoral processes. The stated purpose across all of it is to let people recognise when content is synthetic, reducing the risk of deception at a moment when, as the Code puts it, distinguishing AI-generated material from human-authored material is becoming increasingly difficult.

Timeline

  • 13 June 2024 - The European Parliament and Council adopt Regulation (EU) 2024/1689, the EU AI Act.
  • 1 August 2024 - The AI Act enters into force.
  • 4 September 2025 - The European Commission opens a consultation on guidelines and a Code of Practice for Article 50 transparency obligations.
  • 7 May 2026 - The Council and European Parliament reach a provisional agreement under the Digital Omnibus package, fixing new 2027 and 2028 deadlines for high-risk AI systems without altering the Article 50 labelling deadline.
  • 10 June 2026 - The Commission publishes the free EU icons for labelling AI-generated content.
  • 5 July 2026 - PPC Land reports on the EU labelling icons and the marking-versus-labelling split.
  • 9 July 2026 - Google introduces an AI label setting across five advertising products, shifting labelling liability toward advertisers.
  • 20 July 2026 - The Commission publishes its guidelines on the implementation of Article 50 transparency obligations, issued as C(2026) 5054 final, alongside the finalised Code of Practice on Transparency of AI-Generated Content.
  • 22 July 2026 - Deadline for organisations to sign the Code of Practice to obtain a presumption of compliance.
  • 2 August 2026 - Article 50 transparency obligations become legally applicable.
  • 2 December 2026 - Deadline for generative AI providers already on the market before 2 August 2026 to bring Article 50(2) machine-readable marking into conformity.
  • 2 February 2027 - Deadline for providers to implement a watermark-detection interoperability solution.

Summary

Who: The European Commission published the documents through the AI Office. They bind providers of generative AI systems, defined under Article 3(3) of the AI Act, and deployers, defined under Article 3(4), including advertisers, agencies, publishers and platforms operating in or serving the European Union.

What: Guidelines on the implementation of the Article 50 transparency obligations, issued as Communication C(2026) 5054 final, together with the finalised Code of Practice on Transparency of AI-Generated Content. The guidelines interpret scope and mechanics; the Code sets technical measures including a 200-token watermarking threshold, a two-layer marking requirement, a free detection solution with a carve-out for providers below one million monthly users, and three EU labelling icons.

When: Both documents carry a publication date of 20 July 2026. The underlying Article 50 obligations become legally applicable on 2 August 2026. Organisations seeking a presumption of compliance through the Code must sign by 22 July 2026.

Where: The obligations apply across the European Union and European Economic Area, and extend to organisations established outside the bloc where the output of their AI system is used within it.

Why: The framework addresses the risk that AI-generated or manipulated content, particularly deep fakes and AI-written material on matters of public interest, could deceive audiences about its authentic origin. Advertising content is excluded from the lighter disclosure regime available to genuinely artistic or satirical work, meaning marketing organisations using synthetic avatars or spokespeople in persuasive campaigns face the full labelling obligation. Non-compliance carries fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher.