For compliance officers, legal counsel, CTOs and AI governance leads at organisations deploying generative AI in the EU. Measured framing; this is an explainer, not advocacy.
1. What happened
On 10 June 2026 the European AI Office published the final Code of Practice on Transparency of AI-Generated Content — the voluntary instrument designed to help providers and deployers meet the marking, detection and labelling obligations in Article 50(2) and 50(4) of the EU AI Act (digital-strategy.ec.europa.eu; European Commission, IP/26/1328). It followed a first draft in January and a second draft in March, each opened to stakeholder consultation. The AI Office has asked organisations that intend to be listed as initial signatories to submit their signature form by 22 July 2026, 18:00 CEST; signing remains open after that date, but later signatories will not appear on the initial published list (signing FAQ).
This lands in the same window as two other moving parts. First, the Commission's draft guidelines on the scope and application of Article 50, published 8 May 2026, went through targeted consultation that closed 3 June 2026, with final guidelines expected before August (globalpolicywatch.com). Second, the Digital Omnibus simplification package — a provisional agreement reached by Council, Parliament and Commission negotiators on 7 May 2026 and endorsed by the European Parliament on 16 June 2026 — reshaped the wider AI Act timeline, though, as set out below, it largely left Article 50 alone [reported, OJ text pending] (consilium.europa.eu; White & Case).
2. What it actually changes
Less than the volume of coverage suggests, and that is the point worth internalising. The Code does not create new legal obligations; the obligations live in Article 50 of the Regulation. What the Code does is give those obligations operational shape. Where Article 50(2) says synthetic audio, image, video and text must be marked "in a machine-readable format" and made "detectable as artificially generated," the Code translates that into expectations a build team can act on: markers applied at the point of generation, robustness against ordinary handling and transformation, and interoperability so that the marks one tool writes can be read by another (Bird & Bird).
The instrument is voluntary. Signing it does not constitute compliance and not signing it does not constitute breach. Its function is closer to a safe-harbour signal: a documented good-faith effort to meet the standard the regulator considers adequate. The legal exposure — and the enforcement — attaches to Article 50 itself, not to the Code. Organisations that sign but mark cosmetically are not protected; organisations that never sign but mark robustly and verifiably meet the obligation. This distinction is the single most common misreading in circulation this month, and it is worth stating plainly in internal briefings.
3. Who is affected
Any provider or deployer of a generative AI system whose output reaches the EU market, regardless of where the provider is established. That includes providers of general-purpose AI systems capable of generating synthetic content, and deployers who put such content into the world — in particular those publishing deepfakes or AI-generated text on matters of public interest, who carry the 50(4) labelling duty. The transparency duties are explicitly not limited to high-risk systems; they apply wherever one of Article 50's four situations is present (artificialintelligenceact.eu).
In Spain, supervision runs through the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), which assumes full inspection and sanctioning competence with the Regulation's general application in August 2026, alongside sectoral authorities including the AEPD, the Banco de España and the CNMV (espanadigital.gob.es). For Spanish and Spain-facing deployers, AESIA is the authority that will look.
4. Implementation requirements
Three dates now structure the work:
- 22 July 2026 — deadline to be listed as an initial signatory to the Code. A signalling decision, not a compliance one.
- 2 August 2026 — Article 50 transparency obligations enter into application. New generative systems placed on the market on or after this date must mark from day one. Enforcement powers — fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher — become available to the AI Office and national authorities (datamatters.sidley.com).
- 2 December 2026 — under the Digital Omnibus grandfathering rule, generative systems already on the market before 2 August get until this date to meet the machine-readable marking obligation (Latham & Watkins; insideprivacy.com).
In engineering terms, "marking" means more than a visible badge. The Code's emphasis on robustness and interoperability points to two complementary mechanisms the wider industry has converged on: C2PA Content Credentials (a signed provenance manifest that travels with the file) and an invisible watermark embedded in the content itself (a durable signal that survives when metadata is stripped). The second requirement — "detectable as artificially generated" — implies the often-overlooked corollary: a way to read and verify those marks, including when they are absent or contradictory.
5. What to do this quarter
Treat the Code as a conformance specification and run a gap assessment against it now: take representative outputs across each modality you generate and test whether your current marking is machine-readable, survives a realistic transformation (re-encoding, screenshot, crop), and can be verified by a party who did not create it. Decide the 22 July signature question on its merits as a signalling choice, separately from the engineering. Triage your generative systems into "placed before 2 August" (December clock) and "new" (August clock) — then resist letting that split drive the build schedule, because the integration work is the same for both. Finally, stand up the verification path, not just the marking path: a label you cannot independently check is, for audit purposes, an unverified assertion.
6. AIACT50's reading
The final Code is quietly consequential because it moves the regulator's expectation from "is a label present" to "is the mark robust, interoperable and verifiable" — and in the same month, Google and OpenAI independently converged on the same answer, pairing C2PA Content Credentials with a durable watermark (blog.google; c2paviewer.com). That convergence settles the write side of provenance and exposes the part still largely unbuilt at ecosystem scale: independent, queryable verification, anchored so the record cannot be silently rewritten. That read side is where the obligation actually bites once cosmetic labelling is off the table — and it is the layer we build.
The honest framing for the quarter is not fear of the August fine. It is that the architecture regulators and the largest labs are both converging on now has a clear shape, the lead time to implement it well is real, and the calendar relief offered to older systems does nothing to shorten it.
Sources: digital-strategy.ec.europa.eu · European Commission (IP/26/1328) · consilium.europa.eu · espanadigital.gob.es · blog.google · Bird & Bird · White & Case · Latham & Watkins · Sidley · Covington (Inside Privacy / Global Policy Watch).
Verified to public sources only; Digital Omnibus final legal text pending Official Journal publication, anticipated July 2026.
If you want to see how marking, registry and public verification are combined into a single implementation:
Explore AI Act 50 →