Newsletter · week of 22 September 2026. Past the deadline, into the unglamorous business of making the rule actually operate.
Most of the attention on Article 50 of the EU AI Act arrived in a single week at the start of August, when the transparency obligations entered into force. The cameras have since moved on. That is usually the moment the interesting work begins, and it is where the regulation sits now.
A standard exists, and it has been adopted
Two things define the current phase. The first is that a standard now exists and has been widely adopted. The Commission's Code of Practice on Transparency of AI-generated Content was published on 31 July, and by the Commission's own account roughly 190 organisations have signed it — including nearly every foundation-model provider of note. Their technical commitments have converged on two primitives: C2PA Content Credentials and invisible watermarking. Implementation task forces were set to convene in September to turn signatures into shared practice. The debate over whether there would be a common approach is effectively settled.
The deadline nobody is covering
The second is a deadline that has attracted far less coverage than it deserves. Article 50's transitional period for machine-readable marking of systems already on the market before 2 August expires on 2 December 2026. Systems launched after August had no grace period; deployer disclosure duties had none either, and have applied since the summer (Article 50). For any organisation that shipped a generative feature earlier in the year, the next ten weeks are about retrofitting provenance into something already in production — an engineering problem wearing a legal deadline.
Marking is a commodity. Verification is not.
Put those two facts together and a clearer picture emerges. Marking content at the point of generation has become a commodity. The large providers give it away, and the Code has made it the expected baseline. What has not been solved — what almost no one is discussing — is verification. A mark is only worth what someone can later do with it. Can a platform, an auditor, or a downstream customer confirm that a given file still carries a valid, untampered credential, months after it has been re-encoded, cropped, screenshotted, and passed through systems that never heard of C2PA?
The Code hints at the weakness itself: it requires providers to hand out free detection tools. You only need a detector when a mark cannot speak for itself.
A provider's signature is not your compliance
This is the part worth saying plainly, because a comfortable misreading is spreading: that because a model vendor signed the Code, the companies building on it are covered. They are not. The Code separates provider obligations from deployer obligations for a reason, and a provider's signature discharges the provider's commitments, not the deployer's. The organisations most likely to feel safe are frequently the ones already carrying live disclosure duties they have not operationalised. Compliance is not a name on a list. It is something you can evidence about your own deployment — the disclosures you made, the marks you can verify, the record you can produce on request.
None of this is an argument against the Code, which is a good instrument, or against watermarking, which is a genuine advance. It is an argument about where the pressure moves next. Marking earned the headlines. Verification is where the architecture gets tested: an independent record that a mark existed, and an open, neutral way for anyone to check it — regardless of which provider or which standard produced it.
What to do before December
If your team shipped generative features this year, the practical task before December is narrow and answerable: make their output markable, anchor the mark somewhere it cannot quietly disappear, and make it verifiable by someone who does not have to take your word for it. The deadline is real. The work is doable. And the question that will still be open long after 2 December is not how to mark — it is how to prove.
Sources: European Commission — Code of Practice on Transparency of AI-generated Content (31 Jul 2026) and Guidelines on transparency obligations · Article 50, EU AI Act · Morrison Foerster, “Full Transparency” (11 Sep 2026) · Praxikon and ComplianceHub on the 2 December 2026 transitional deadline.
If the open question for you is not how to mark but how to prove — an independent record and a neutral way for anyone to check it:
Explore AI Act 50 →