Executive briefing · 20 July 2026. Every claim below is sourced to primary public documents.
1. What happened
On 8 July 2026 the European Commission concluded that the Code of Practice on Transparency of AI-generated content "adequately covers the obligations provided for in Articles 50(2), (4) and (5) AI Act and facilitates their effective implementation." The AI Board adopted its own Adequacy Assessment the following day. The Commission published both instruments on 9 July 2026 (Commission Opinion).
The Code itself was published in final form on 10 June 2026, following a multi-stakeholder drafting process coordinated by the AI Office. Until this month it existed in an ambiguous state: a detailed voluntary document whose legal standing had not been determined. Article 56(6) of the AI Act requires the AI Office and the AI Board to assess the adequacy of codes of practice and publish those assessments, and that step has now been completed.
Two operational dates follow. To appear on the list of initial signatories — to be published before the obligations take effect — a completed signatory form must reach the AI Office by 22 July 2026 at 18:00 CEST (how to sign). Article 50 becomes applicable on 2 August 2026.
2. What it actually changes
Less than the announcement implies, and more than a voluntary code normally would.
What changed. The Commission now designates the Code as, in its words, "the EU-wide adequate instrument" for demonstrating compliance with the relevant obligations, "regardless of their place of establishment, operation or competent market surveillance authority." For a group operating across several member states, that uniformity is the substantive benefit. Signatories may rely on adherence to the Code to demonstrate compliance, rather than constructing and defending a bespoke compliance argument in each jurisdiction they operate in.
The position of non-signatories is described with unusual candour in the Commission's FAQ. Not signing "does not constitute non-compliance," and any enforcement consequence attaches to Article 50 itself rather than to the absence of adherence. But non-signatories "must be prepared to demonstrate compliance through other adequate means," may need to carry out a gap analysis comparing their measures against the Code, and "may be subject to a larger number of requests for information or access from competent authorities" (signing FAQ). The cost of not signing is expressed as administrative friction, not penalty.
What did not change. The Commission's opinion states plainly that "adherence to the code does not constitute conclusive evidence of compliance with these obligations." Competent market surveillance authorities retain the assessment. Adherence also leaves every other obligation under the AI Act untouched, including those attaching to high-risk systems and to general-purpose AI models.
There is a further structural point that deserves more attention than it has received. The Code does not prescribe a marking technology, and it explains why: no single marking technique currently satisfies all four requirements Article 50(2) imposes — effectiveness, interoperability, robustness and reliability. Providers are instead directed toward layered approaches combining metadata, watermarking and content provenance mechanisms, assessed on whether the combination meets the four criteria. The Code additionally concedes that forensic detection is not yet reliable enough on its own and that common evaluation benchmarks have not emerged.
That is a regulator acknowledging, inside its own compliance instrument, that the technical state of the art does not yet reach the standard the law sets — and asking industry to close the gap through layering, standardisation and cooperation.
3. Who is affected
Providers of generative AI systems placed on the EU market — obligations under Article 50(2) and (5), covering machine-readable marking of synthetic audio, image, video and text, and the availability of detection mechanisms. They are invited to sign Section 1.
Deployers using generative AI systems under their authority for professional purposes, where those systems produce deepfakes or generate or manipulate text published to inform the public on matters of public interest — obligations under Article 50(4) and (5). They are invited to sign Section 2. An organisation acting in both capacities signs the whole Code. Sections may be signed independently; individual commitments within a section may not.
Two categories are eligible to sign Section 1 without being directly bound by Article 50(2), and this is the least-discussed element of the framework. Providers of generative AI models may sign. So may technology providers of marking and detection solutions — organisations that build the tools, services or infrastructure for marking, provenance, watermarking or detection of AI-generated content and place them on the EU market, whether paid or free.
The consequence is worth stating directly. The initial signatory list will not only record which obligated organisations chose the endorsed route. It will also record which parts of the supply chain underneath them were willing to put their name against the same commitments. For any compliance officer relying on a third-party vendor for Article 50(2) marking, that is a procurement question with a public answer.
Geographic scope is broad. The draft Guidelines confirm that both providers and deployers fall within the AI Act even when established outside the EU, provided the output of the system is used in the Union. Actors whose role is limited to hosting, transmitting or disseminating third-party AI-generated content — online platforms among them — are generally not deployers for these purposes (draft Guidelines consultation).
4. Implementation requirements
For providers signing Section 1, four commitments: implement machine-readable marking identifying AI-generated or manipulated content; make detection mechanisms available so users and relevant stakeholders can verify; meet quality requirements ensuring transparency measures are effective, reliable, robust and interoperable; and establish documented compliance, cooperate on an ongoing basis with market surveillance authorities, and contribute to technical standards work.
For deployers signing Section 2, two commitments: disclose deepfakes and AI-generated or manipulated published text through a harmonised set of EU "AI" labels or an equivalent mechanism, meeting the Code's design and placement requirements, with disclosure clear, accessible and visible at first exposure; and establish internal compliance processes, documentation, staff training, mechanisms for handling missing or incorrect labels, and cooperation with authorities.
The Commission published a set of three EU labelling icons on 10 June 2026 — a basic disclosure icon, a "Fully AI-Generated" icon, and a "Partially AI-Modified" icon — freely available in PNG and SVG without attribution (EU icons). Using the icons is optional. The labelling obligation is not, and the icons do not by themselves establish compliance.
Two qualifications limit the deployer duty: a more flexible disclosure regime applies to artistic, creative, satirical and fictional works, and the AI Act's exemption applies to AI-generated or AI-assisted published text that has undergone human review and where editorial responsibility has been assumed.
The signature must come from a senior executive with authority to bind the organisation. Signatures are conditional on the positive adequacy assessments, which have now been given, and may be withdrawn by letter from an executive of equivalent seniority.
5. What to do this quarter
Before 18:00 CEST on Wednesday 22 July. Decide whether to sign, and which sections. If yes, get the form signed by an executive with binding authority and submitted. If the decision cannot be made by Wednesday, note that later signature carries identical substantive weight — only initial-list placement is lost. Do not let the list deadline force a decision the organisation is not technically ready to stand behind.
Before 2 August. Establish which provision governs you, because the Omnibus grandfathering is narrower than most summaries suggest. The simplification package was endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026. It grandfathers the Article 50(2) marking and detection obligations to 2 December 2026 only for generative AI systems placed on the market or put into service before 2 August 2026. Systems placed on the market from 2 August mark from day one. Article 50(4) deployer labelling is not grandfathered and applies from 2 August. Content generated and already made available before 2 August does not require retroactive marking or labelling (Latham & Watkins).
Before 2 August, if you are a deployer. Implement labelling for deepfakes and for public-interest published text. Decide whether to adopt the EU icons. Document the exemption analysis for anything you are not labelling, particularly where you are relying on human editorial review — that reasoning is what an authority will ask to see.
Before 2 December, if you are a grandfathered provider. Do not treat the four months as slack. Given the Code's own acknowledgement that no single technique meets all four criteria, the work is architectural rather than procedural: assemble and evidence a layered marking and detection approach.
Across the quarter. Put the vendor question in writing. Ask each supplier in your marking and detection chain whether they are signing Section 1, and file the answer. Begin assembling the evidence file now — the documentation, the internal testing methodology, the reasoning behind your marking choices. Since the interpretive Guidelines remain in draft and common benchmarks have not emerged, the quality of your documented reasoning is, for the moment, a substantial part of your defensible position.
6. AIACT50's reading
The endorsement of the Code is a good outcome that solves a narrower problem than its reception suggests. It answers the procedural question — which route the Commission will accept — with welcome uniformity across the Union, and organisations that operate in several member states should sign for that reason alone. What it does not do, and does not claim to do, is answer the substantive question that follows: whether a given implementation is good enough. The Commission has deliberately kept that question open, the Guidelines that would inform it are still in draft with obligations two weeks away, and several of the Code's load-bearing concepts remain case-by-case. Signing is the beginning of the evidentiary conversation rather than its conclusion. The more consequential paragraph in the whole framework, to our reading, is the one where the Code declines to prescribe a marking technology and explains that no single technique satisfies Article 50(2)'s four criteria — because that turns an argument the provenance industry has been making as a vendor claim into a reading of the Commission's own instrument, and it means the organisations best positioned in December will be the ones that spent this quarter building layers rather than selecting a product.
Sources: Commission Opinion (9 July 2026) · Signing FAQ · How to sign (10 June 2026) · Code of Practice · EU labelling icons · Tech Policy Press · Latham & Watkins · Sidley · Draft Guidelines consultation.
Note on one discrepancy: two secondary sources encountered in preparing this briefing gave the signatory deadline as 27 July 2026. The Commission's own FAQ states 22 July 2026, 18:00 CEST in three separate places and has been followed here. Readers acting on this should confirm against the FAQ.
If you want to see how layered marking, registry and public verification are combined into a single implementation:
Explore AI Act 50 →