EU AI Act Article 50: how to mark AI output — and prove the marking is genuinely yours
From 2 August 2026, providers of generative AI must mark synthetic output in a machine-readable, detectable format. Most guidance stops at “add a label.” This page covers the harder half: how to make that label independently verifiable — so a buyer, auditor or AI agent can confirm a marking that is present is genuinely yours and unaltered, without taking your word for it.
Start here: run the free Article 50 readiness checklist — 16 checks, no sign-up, nothing is sent anywhere. Lietuviškai: 50 straipsnio čeklistas.
The obligation (what changes around 2 Aug 2026)
- Article 50(2): providers must mark AI-generated / synthetic output in a machine-readable format, detectable as artificially generated.
- Article 50(4): deployers must disclose AI-generated content in defined cases (incl. deepfakes).
- Article 4: providers and deployers of AI systems must ensure a sufficient level of AI literacy among staff (and others operating the systems on their behalf).
- Dates: the Article 50 marking obligation takes effect 2 August 2026; systems already on the market are, under the 2026 Digital Omnibus amendment, set to have until 2 December 2026 for that marking obligation. The Article 4 AI-literacy duty has applied since 2 February 2025 — enforcement begins 2 August 2026.
- The Commission’s Code of Practice names C2PA Content Credentials as an example marking mechanism.
- Stakes: breaching the Article 50 transparency obligations falls under Article 99(4) — administrative fines up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher. (Article 4 carries no direct fine, but weak AI literacy can aggravate penalties for other breaches.)
What this means for you
If your company generates content with AI, or your people use AI at work, then from 2 August two things converge: the new Article 50 marking obligation takes effect, and enforcement of the Article 4 AI-literacy duty (in force since Feb 2025) begins. If you sell into the EU from outside it, the reach is extraterritorial — it can apply to you too.
How to mark AI content — and verify the marking
- Rules — a plain, role-specific statement of what your AI may and may not do (Art.4).
- Mark — machine-readable marking of AI output (C2PA / Content Credentials is the Commission’s named example; watermark and metadata are common approaches).
- Record — an evidence trail: what was produced, under what mandate, who reviewed it.
- Verify — make the marking and the record independently checkable, not just asserted.
Steps 1–3 many tools help with. Step 4 is where most “trust” quietly fails — a marking or a compliance PDF you could have edited isn’t proof. That’s the gap we close.
Don’t trust us. Verify.
For a trust company, our own marketing has to be verifiable. So it is:
Our public trust root is pinned in DNS and served over HTTPS, independent of this page:
margelis.ai/.well-known/margelis-trust.json · DNS _margelis-trust.margelis.ai
Every signed claim we issue is owner-signed (Ed25519 / eddsa-jcs-2022), the key held in a KMS, and independently recomputable by any third party with standard tools against that pinned key. A signed-but-disallowed claim is blocked by a published, re-runnable policy check — even when the signature is valid. (That check blocks known disallowed claim patterns from a versioned denylist; it does not decide whether a permitted claim is true.)
You don’t have to believe us. Open the trust root and verify it yourself. That property — verify without trusting the issuer — is the whole point.
Where this sits (above the marking layer)
C2PA / Content Credentials is the marking. Useful — but metadata can be stripped, and a valid signature proves the signer, not the truth of the claim. Margelis adds the accountability layer on top: is the marking genuinely from the owner, pinned out-of-band so it survives a compromised page, and re-verifiable by a third party — with a policy gate that blocks disallowed claims.
The building blocks — W3C Verifiable Credentials, Ed25519, DNS/.well-known — are standard, and policy-gated verifiable statements exist in adjacent domains (e.g. IETF SCITT for software artifacts). We have not found a shipping product that assembles these around a website’s own public claims: owner-signed, verified against an out-of-band pinned key, with a policy gate that blocks disallowed claims even when the signature is valid. This is integration novelty on a known standard base — not a new cryptographic primitive.
Common questions
- Do I have to mark AI content by 2 August 2026?
- If you provide generative AI, Article 50(2) requires machine-readable marking of synthetic output from that date (a grace period to 2 Dec 2026 applies to systems already on the market under the 2026 Digital Omnibus amendment).
- Is C2PA enough?
- C2PA is a strong marking mechanism (named by the Commission). But metadata can be stripped and a signature proves the signer, not the claim — you also need the marking to be independently verifiable and owner-pinned.
- Watermark vs metadata vs C2PA — which?
- They solve marking; none, on its own, proves the marking is genuinely yours and unaltered to a third party. That verification layer is separate.
- I’m a deployer using AI, not a provider — does this touch me?
- Article 50(4) disclosure (incl. deepfakes) and Article 4 AI literacy apply to deployers too.
- How do I prove a marking is genuine?
- With an owner-signed, DNS-pinned artifact a third party can recompute — the model on this page.
Get ready — one workflow at a time
Start with a free readiness look at one workflow ahead of the 2 August date: what your AI produces, how it’s marked, and how it could be independently verified. No cost, no obligation.
Request a free readiness review