Since 2 August 2026, Article 50 of the EU AI Act (Regulation (EU) 2024/1689) is no longer a date on a compliance roadmap. It is law in force across the European Union — and it changes what "publishing AI-generated content" means for every company that does it.

What Article 50 requires

Article 50 is the AI Act's transparency chapter, and its obligations are concrete:

  • Providers of AI systems that generate synthetic audio, images, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The marking must be effective, interoperable, robust and reliable, as far as technically feasible.

  • Deployers who create deepfakes — AI-generated or manipulated content resembling real people, places or events — must clearly and distinguishably disclose that the content is artificial.

  • AI-generated or altered text published to inform the public on matters of public interest must be disclosed too, with limited exceptions such as editorially reviewed content under human responsibility.

  • People interacting with an AI system must be told they are, unless it is obvious from context.

Non-compliance carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

"Machine-readable" is the operative phrase

A visible "AI generated" caption is disclosure, not marking. The regulation asks for something machines can detect and verify at scale. In practice, that means two complementary techniques working together:

  • Content Credentials (C2PA) — a cryptographically signed manifest travelling with the asset, stating what it is, who produced it and how. Verifiable by anyone; but metadata can be stripped when a file is re-encoded or shared.

  • Invisible watermarking — a signal embedded in the pixels or the audio itself, designed to survive resizing, re-encoding, cropping and screenshots. It persists where metadata does not.

Marking that disappears the first time content is re-shared does not meet the spirit — or the letter — of "robust and reliable".

Marking is only half the job. Proving it is the other half.

Article 50 does not just require you to mark content; it exposes you to the question that follows: can you demonstrate that you did, for every asset, at the time it was published? A screenshot of your pipeline configuration or an export from your own database is self-attestation — it proves what your systems say today, not what happened then.

The companies that will pass this test are the ones whose marking events leave an evidence trail an outside party can verify independently.

How Artemis approaches it

Artemis was built for exactly this moment:

  • Every asset is marked with a signed C2PA manifest — using your own keys, held in your own KMS or HSM — plus an invisible watermark matched to its modality: images, video and audio.

  • Every marking event enters an append-only evidence chain, sealed daily with a Merkle root that is timestamped by an independent RFC 3161 timestamp authority and written to storage that physically cannot be overwritten. Nobody can backdate or rewrite that history — including us.

  • When a regulator asks, you produce a verifiable audit report in one click: every asset, every marking event, every anchor — checkable without trusting Artemis or you.

  • The marking plane runs inside your own infrastructure. Your content never leaves; only cryptographic fingerprints do.

Why acting now matters

Enforcement of Article 50 will ramp up, and guidance detailing expected marking techniques is on its way. But there is a more practical reason not to wait: evidence only accumulates forward. You can start marking your back catalogue any day; you cannot retroactively create a provable history of having done it. Every week between now and your first audit is either a week of accumulated, independently anchored evidence — or a gap.

Artemis plans start at €249/month, with every capability included on every plan. Book a pilot and be provably compliant this quarter.