MargelisLT

EU AI Act Article 50: how to mark AI output — and prove the marking is genuinely yours

From 2 August 2026, providers of generative AI must mark synthetic output in a machine-readable, detectable format. Most guidance stops at “add a label.” This page covers the harder half: how to make that label independently verifiable — so a buyer, auditor or AI agent can confirm a marking that is present is genuinely yours and unaltered, without taking your word for it.

Start here: run the free Article 50 readiness checklist — 16 checks, no sign-up, nothing is sent anywhere. Lietuviškai: 50 straipsnio čeklistas.

The obligation (what changes around 2 Aug 2026)

This is an operational summary, not legal advice. Your lawyer decides applicability.

What this means for you

If your company generates content with AI, or your people use AI at work, then from 2 August two things converge: the new Article 50 marking obligation takes effect, and enforcement of the Article 4 AI-literacy duty (in force since Feb 2025) begins. If you sell into the EU from outside it, the reach is extraterritorial — it can apply to you too.

How to mark AI content — and verify the marking

  1. Rules — a plain, role-specific statement of what your AI may and may not do (Art.4).
  2. Mark — machine-readable marking of AI output (C2PA / Content Credentials is the Commission’s named example; watermark and metadata are common approaches).
  3. Record — an evidence trail: what was produced, under what mandate, who reviewed it.
  4. Verify — make the marking and the record independently checkable, not just asserted.

Steps 1–3 many tools help with. Step 4 is where most “trust” quietly fails — a marking or a compliance PDF you could have edited isn’t proof. That’s the gap we close.

Don’t trust us. Verify.

For a trust company, our own marketing has to be verifiable. So it is:

Our public trust root is pinned in DNS and served over HTTPS, independent of this page:
margelis.ai/.well-known/margelis-trust.json · DNS _margelis-trust.margelis.ai

Every signed claim we issue is owner-signed (Ed25519 / eddsa-jcs-2022), the key held in a KMS, and independently recomputable by any third party with standard tools against that pinned key. A signed-but-disallowed claim is blocked by a published, re-runnable policy check — even when the signature is valid. (That check blocks known disallowed claim patterns from a versioned denylist; it does not decide whether a permitted claim is true.)

You don’t have to believe us. Open the trust root and verify it yourself. That property — verify without trusting the issuer — is the whole point.

Where this sits (above the marking layer)

C2PA / Content Credentials is the marking. Useful — but metadata can be stripped, and a valid signature proves the signer, not the truth of the claim. Margelis adds the accountability layer on top: is the marking genuinely from the owner, pinned out-of-band so it survives a compromised page, and re-verifiable by a third party — with a policy gate that blocks disallowed claims.

The building blocks — W3C Verifiable Credentials, Ed25519, DNS/.well-known — are standard, and policy-gated verifiable statements exist in adjacent domains (e.g. IETF SCITT for software artifacts). We have not found a shipping product that assembles these around a website’s own public claims: owner-signed, verified against an out-of-band pinned key, with a policy gate that blocks disallowed claims even when the signature is valid. This is integration novelty on a known standard base — not a new cryptographic primitive.

Common questions

Do I have to mark AI content by 2 August 2026?
If you provide generative AI, Article 50(2) requires machine-readable marking of synthetic output from that date (a grace period to 2 Dec 2026 applies to systems already on the market under the 2026 Digital Omnibus amendment).
Is C2PA enough?
C2PA is a strong marking mechanism (named by the Commission). But metadata can be stripped and a signature proves the signer, not the claim — you also need the marking to be independently verifiable and owner-pinned.
Watermark vs metadata vs C2PA — which?
They solve marking; none, on its own, proves the marking is genuinely yours and unaltered to a third party. That verification layer is separate.
I’m a deployer using AI, not a provider — does this touch me?
Article 50(4) disclosure (incl. deepfakes) and Article 4 AI literacy apply to deployers too.
How do I prove a marking is genuine?
With an owner-signed, DNS-pinned artifact a third party can recompute — the model on this page.

Get ready — one workflow at a time

Start with a free readiness look at one workflow ahead of the 2 August date: what your AI produces, how it’s marked, and how it could be independently verified. No cost, no obligation.

Request a free readiness review

Boundaries. This is an operational readiness and evidence layer. It is not legal advice, an audit opinion, official AI Act certification, or a guarantee of compliance. A valid signature proves origin and integrity, not that a claim is true; the policy check blocks known disallowed claim patterns, it does not decide truth. Current cryptography is Ed25519/JCS — crypto-agile / PQC-ready, not quantum-secure.
Margelis.ai · UAB Rūpestėlis Holding, Vilnius · Lietuviškai