A further part of the EU’s Artificial Intelligence Act (Regulation (EU) 2024/1689, “AI Act”) takes effect from 2 August 20261 , placing new transparency obligations on providers and deployers of AI systems. Commission guidelines on these transparency obligations already provide one point of reference for affected companies (cf. our article of 5 June 2026), clarifying where and when they apply, and who they apply to. The new Code of Practice on Transparency of AI-Generated Content, published by the Commission on 10 June 2026 (“Code of Practice” or “Code”), addresses the technical and organisational issues involved in meeting them.
This article summarises key information for companies: What is the Code of Practice? What’s in it? Should you sign it? And how do you meet the obligations of Article 50 AI Act in practice?
I. What is the Code of Practice?
The Code is a voluntary tool: providers and deployers of generative AI systems are entitled but not obliged to sign it. Its job is to translate the abstract obligations arising from Article 50 AI Act into concrete, practical measures. But it does not replace the statutory obligations, nor does compliance with it constitute final proof of legal conformity. Following the Code’s recent approval by the Commission and the “AI Board”2 , companies can now prove their compliance with Article 50 obligations – across the EU – by invoking their signing of the Code. This move is intended to reduce the administrative burden for both companies and regulators, though the latter will still be able to establish violations in individual cases, i.e. even if the Code itself is complied with. Irrespective of who does or does not sign it, the Code is likely to become the practical standard for regulatory authorities.
The Code consists in two sections. Section 1 is addressed to providers of generative AI systems and includes four commitments that go into greater detail on machine-readable markings, the detection of AI-generated or manipulated content, and the accompanying quality, test and documentation requirements. Section 2 is directed at deployers (i.e. companies that merely use AI systems, rather than placing them on the market themselves) and also includes four commitments, governing the perceptible marking of deep fakes and AI-generated texts to inform the public of their provenance. There is also a glossary with definitions and an annex with standardised icons to be used across the EU in meeting the transparency obligations (Annex 1).
The Code differentiates between three levels of commitment: “will” refers to mandatory measures required and monitored by market surveillance authorities; “encouraged” refers to recommended but voluntary measures; and “may” refers to optional measures with flexibility in implementation. The Code simplifies compliance for all small mid-cap (SMC) companies, i.e. with no more than 750 employees, annual turnover up to EUR 150 million, and annual results up to EUR 129 million.
The advantage of the Code is that it fleshes out the deliberately unspecific provisions of the AI Act with specific, standardised requirements, many of them left out of both the Act and the guidelines. Where the Act stipulates merely a “machine-readable marking”, the Code requires a multi-layered approach that will generally combine two techniques. It specifies procedures, states practical thresholds, and makes the required detection solution concrete, including the stipulation that the solution be generally provided free of charge. For deployers, the Code also provides an EU icon together with design and placement specifications, and elaborates on the statutory exemption for texts where a natural or legal person holds editorial responsibility. Finally, the Code sets its own deadlines for implementation and creates a platform for future developments in practice.
II. Signing the Code: Who should sign and why?
The Code is targeted primarily at providers of generative AI systems (Section 1) and deployers of AI systems that generate deep fakes or use AI to create text intended to inform the public (Section 2). The two sections may be signed independently. But the Code can also be signed by operators not directly subject to Article 50 AI Act, such as providers of generative AI models that place such models on the market independently from AI systems, as well as third-party providers of marking and detection solutions. Their adherence to the Code can facilitate compliance by downstream providers who build on those models or such marking and detection solutions.
Signing the Code offers several practical advantages. It signals to both regulators and customers a commitment to compliance with the transparency obligations and provides a structured framework against which companies can document compliance with Article 50 AI Act. Conformity with the Code thus makes it easier to provide proof of compliance and reduces the associated administrative burden. It does not give rise to a genuine presumption of conformity, however, let alone an irrefutable one.
In any event, companies that sign up to the Code must comply with all measures designated as “will” measures. For operators that already have equivalent and well-established procedures in place, such as media service providers whose existing editorial processes already ensure an adequate level of AI transparency, the added value of signing the Code may be limited. In some cases, it may even be preferable to follow a defensible alternative interpretation of Article 50 AI Act rather than commit to the Code’s specific requirements.
It is particularly advisable for the following to sign the Code: providers of generative AI systems and models with a broad market presence, companies that place a premium on legal certainty and a straightforward means of providing proof of compliance, as well as providers of marking and detection technologies that enable compliance with the Code’s requirements. Any commitment to the Code may also be withdrawn at a later stage. Companies that do not sign the Code will need to demonstrate the adequacy of their measures to the competent market surveillance authority on a case-by-case basis, resulting in a greater compliance burden.
III. The Code’s measures in practice
Whether or not a company formally signs the Code, it provides a detailed implementation framework for achieving practical compliance with the transparency obligations under Article 50 AI Act. The measures set out in the Code are regarded as best practice and offer reliable guidance on how the statutory obligations can be implemented in practice. Even companies that choose not to sign the Code should ensure that their transparency measures are aligned with the standards set out in the Code. The key considerations for providers and deployers are outlined below.
1. Measures for providers of generative AI systems
The Code proceeds from the premise that, given the current state of the art, no single marking technique can simultaneously meet all four requirements in Article 50(2) AI Act (effectiveness, interoperability, robustness, and reliability). It therefore adopts a multi-layered approach, generally requiring at least two layers of machine-readable marking.
As a basic requirement, all AI-generated or manipulated content must be marked with an imperceptible watermark, though the reliability requirements for watermarking are less strict for very short texts (fewer than 200 tokens).
Formats that support metadata (audio, image, video, containerised text) must have a second layer of marking in the form of metadata that is digitally signed, time-stamped and tamper-proof. A single layer of marking is sufficient where a generative AI system is embedded in physical products and generates synthetic outputs in a technically controlled and closed environment, provided that effective measures are embedded to prevent the output from leaving that environment (e.g. AI-generated recommendations that can only be displayed on a physical vending machine and cannot be disseminated further). As far as free-form text is concerned, the watermark alone is sufficient to meet the marking requirement since such text cannot transport metadata. Fingerprinting or logging may be used as a supplementary measure, but cannot be relied on as the only means of compliance.
Providers must also ensure that any markings made are retained. As part of this, their use policies, terms and conditions and accompanying documentation must prohibit the intentional removal of or tampering with such markings. Under no circumstances may tools designed to circumvent the markings be made available on the market. Providers are further encouraged to incorporate richer provenance information in the metadata, in particular the name of the AI system, the provider’s company name and a timestamp. They may also include the model identifier and version number as optional information.
Providers must also make available a detection solution that can be used to verify whether content originates from the relevant AI system. This solution may take the form of a public specification, a piece of software or a cloud-based service accessible through an API. While this must generally be free of charge, providers with fewer than one million monthly users whose solution incurs substantial operational costs may charge a reasonable fee for excessive requests from a single user. However, access must always remain free of charge and unrestricted to market surveillance authorities and other regulators, law enforcement authorities, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations. The solution must be designed to comply with data protection law, especially the principle of data minimisation, and ensure immediate deletion of the processed data after detection. The detection results must be provided in a way that is clear, accessible, and easily comprehensible.
If a watermark has lower reliability for the purpose of detecting AI-generated content (as is permissible for very short texts, as noted above), access to the correspondingly less reliable detection results may be restricted to verified expert users, as they are better equipped to deal with these.
Providers must make the detection results available in a digitally signed format upon request.
The marking and detection solutions must comply with the quality requirements holistically across all techniques. These requirements include effectiveness, reliability, robustness to typical processing operations (e.g. image mirroring, change of file format, generation of screenshots/screencasts), resilience to malicious modification attempts or similar attacks, as well as interoperability. AI systems for which a single layer of metadata marking is deemed sufficient are exempt from the robustness requirement, however. Providers must implement an interoperability solution for watermarks by 2 February 2027.
Lastly, the Code requires a documented compliance process that includes testing before the system is placed on the market and regular testing thereafter, involving independent experts where necessary, for example through red-teaming exercises. Providers must also arrange for training courses for their personnel and cooperate with market surveillance authorities.
2. Measures for deployers of AI systems
For deployers of AI systems that generate deep fakes or text for the purpose of informing the public, the key obligation under Article 50(4) AI Act is to disclose that the content has been artificially generated or manipulated. The Code provides three EU icons for this: one for fully AI-generated content (AI + GENERATED), one for AI-manipulated content (AI + MODIFIED) and a basic icon that can be supplemented with an interactive layer or a textual label.
These EU icons are not mandatory, and deployers may instead use an equivalent icon or label to fulfil the disclosure requirements. However, as demonstrated by the pictogram for video surveillance, which has been standardised under DIN 33450, broad adoption of these icons could significantly enhance recognisability and, consequently, transparency.
The Code also provides specific guidance on the design and placement of the icons. The core element is the uppercase acronym “AI”, which should generally stay in English. The acronym may only appear in the respective national language if use of English is incompatible with national laws on the languages used in commercial or administrative matters. Deployers are also encouraged to add a second, interactive layer providing supplementary information. The labelling must be immediately recognisable without any user interaction – generally directly embedded into the content or presented via an equivalent alternative, such as a UI overlay, no later than on first exposure. In the case of videos, the labelling must appear at the beginning, at regular intervals, and after any interruptions, while audio-only content must include an audible disclaimer at the beginning, which may be supplemented by audible cues (earcons). For text content, the icon is to be placed above or at the top of the text, near the headline or in the introductory text (colophon). Deployers must also comply with the applicable accessibility requirements and take into account the needs of vulnerable groups, such as children.3
The Code also requires deployers to establish and document appropriate internal compliance processes. These include training for personnel and external service providers – in particular on when disclosure is required, how disclosures are implemented in the relevant workflow, and when exceptions may apply. Businesses must ensure the effective implementation of their labelling through internal review processes and external feedback channels. If deployers receive substantiated reports of mislabelling or incorrect labelling, they must review these immediately and take corrective action where necessary.
A less stringent disclosure regime applies to evidently artistic, creative, satirical, fictional or analogous work. In such cases, the disclosure may be provided in a way that does not hamper the display or enjoyment of the work, for example in accompanying notes or descriptions, opening or end credits, or at the point of entry or sale.
For AI-generated text on matters of public interest, the disclosure obligation may moreover be waived under the statutory exemption for content where a natural or legal person holds editorial responsibility. This exemption applies only where clear policies are in place to ensure human review and the corresponding assumption of editorial responsibility prior to publication. These policies must include at least the name, role and contact details of the person with editorial responsibility as well as an overview of the organisational measures and allocated resources. Unless they are already publicly available, the contact details of the person with editorial responsibility must be published.
3. General points
Finally, there are several overarching aspects to bear in mind.
All measures must be tailored to the size of the company in question; the Code expressly establishes simplified procedures for SMEs and startups.
However, anyone relying on marking and detection solutions from third party providers or upstream model providers remains responsible for overall compliance.
Compliance with AI transparency obligations does not exempt organisations from other EU or Member State obligations. In particular, data protection law (GDPR), unfair competition law, media law and intellectual property law must all be observed in parallel.4
IV. Outlook
The Code of Practice is the first concrete and EU-wide framework for implementing the transparency obligations set out in Article 50 AI Act. In the nick of time before those obligations become legal reality in August and December 2026, the Commission has provided companies with guidance on how to implement them. Without delay, companies should now take stock of the generative AI systems they offer and use, and prepare for implementation of the transparency obligations. This includes deciding whether to sign the Code or simply use it as a best-practice benchmark.
It is important to keep in mind, though, that the Code is not binding on either companies or regulators, and that the final say on the binding interpretation of Article 50 AI Act rests with the courts. So the Code’s principal value does not lie in creating formal legal obligations, but rather in fostering a coherent and broadly accepted standard whose widespread adoption can prevent the emergence of fragmented and inconsistent approaches. The extent to which this standard will prove sustainable in the long term remains to be seen, as regulatory and enforcement practice begins to take shape.
1 In principle, the transparency obligations of Article 50 AI Act apply from 2 August 2026. For AI systems placed on the market prior to that date, however, as well as for machine-readable markings under Article 50(2) AI Act, the Omnibus on AI Regulation (now adopted but not yet published) has provided for a transition period until 2 December 2026. For watermarking, the Code extends the deadline for implementing the interoperability solution to 2 February 2027.
2 An advisory committee set up under the AI Act, cf. here; for the corresponding decision by the Commission and AI Board, cf. here.
3 The Code refers in this respect to Directive (EU) 2019/882 (European Accessibility Act) and Directive (EU) 2016/2102 (Web Accessibility Directive) as well as the standards ETSI EN 301 549 “Accessibility requirements for ICT products and services” and WCAG 2.1 Level AA “Web Content Accessibility Guidelines”.
4 This list is not exhaustive and also includes consumer protection law, the Digital Services Act, political advertising provisions, and criminal law, according to the Code.