Key takeaways
- EU AI Act transparency duties have applied since 2 August 2026. The Omnibus left them in place.
- Generative systems on the EU market before 2 August have until 2 December 2026 to mark outputs.
- If you ship a product on someone else’s model, the EU marking duty usually sits with you.
- California’s AI Transparency Act became operative on 2 August 2026, and SB 1000 widened it on 30 September.
- For images, audio and video, plan on signed C2PA metadata plus a watermark.
Since 2 August 2026, any AI system that talks to people in the EU has had to tell them they are dealing with a machine, unless that is obvious. Any generative AI system has had to mark its images, audio, video and text in a machine-readable way, and deployers have had to label deepfakes and AI-written text published to inform the public. These duties come from Article 50 of the EU AI Act. The Digital Omnibus that delayed the Act’s high-risk rules left them in place, with one concession: generative systems already on the market before 2 August have until 2 December 2026 to add the marking.12
California’s AI Transparency Act became operative on the same day, and a bill signed on 30 September 2026 extended it to every publicly accessible generative AI system in the state.34 Connecticut’s provenance rules for large providers followed on 1 October.5
This post maps those rules to the features a product team has to build, and suggests an order to build them in. It is an engineering reading written for teams planning work. It is not legal advice, and the questions about who counts as a provider deserve a lawyer’s time.
What the Omnibus delayed and what it left alone
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July.62 Most coverage focused on the delay to the high-risk rules. The transparency rules kept their date. The timeline as of 8 October 2026:
| Date | What applies | Source |
|---|---|---|
| 2 August 2026 | Article 50 transparency duties apply | Commission Q&A |
| 2 December 2026 | Article 50(2) marking for generative systems placed on the market before 2 August 2026 | Commission Q&A |
| 2 December 2026 | New prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material | FPF |
| 2 December 2027 | High-risk rules for Annex III systems | Commission |
| 2 August 2028 | High-risk rules for AI embedded in Annex I products such as machinery, toys and lifts | Commission |
Content generated before 2 August 2026 does not have to be labelled retroactively, although the Commission encourages it.1 Fines for breaching Article 50 can reach €15 million or 3% of total worldwide annual turnover, with proportionality for SMEs and small mid-caps.17
The four duties, mapped to product features
Article 50 splits its duties between providers, who develop an AI system and place it on the market, and deployers, who use a system under their own authority for anything other than personal, non-professional activity.1 A company that builds a chatbot on a model API and sells it is usually the provider of that chatbot. A company that uses the same chatbot to draft its press releases is a deployer. Plenty of products are both.
| Article 50 duty | Who | What to build | Main exceptions |
|---|---|---|---|
| 50(1) Tell people they are interacting with an AI system | Provider | A notice from the start of the first interaction | Where it is obvious to a reasonably well-informed person, read restrictively |
| 50(2) Mark synthetic audio, images, video and text in a machine-readable, detectable way | Provider | Marking at generation, and a way to check marks | Assistive editing; outputs that don’t substantially alter the input; source code; short strings |
| 50(3) Inform people exposed to emotion recognition or biometric categorisation | Deployer | A notice, and data handling under EU data protection law | Certain law-enforcement uses |
| 50(4) Disclose deepfakes, and label AI text published to inform the public | Deployer | Visible labels at first exposure | Lighter treatment for evident art, satire and fiction; text under human editorial responsibility |
Every disclosure must be clear, distinguishable and accessible, and must reach people at the first interaction or exposure at the latest.8
Two details trip teams up. The first is the chatbot exception. The Commission’s Q&A says it “should be interpreted in a restrictive manner” because it takes transparency away from people.1 We would not rely on it for an assistant with a human name and an avatar. The second is that labelling a deepfake stays the deployer’s job even when the provider has marked the file. The Commission says machine-readable marks alone do not satisfy Article 50(4), and spell-checking or grammar correction does not count as the human review that exempts public-interest text.1
If you build on someone else’s model, the marking duty is still yours
The Article 50(2) duty falls on the provider of the AI system that generates or manipulates the content, including general-purpose AI systems.1 For most product teams that is the team itself, even when every token comes from a third-party model. The Commission’s Q&A describes marking techniques built in by general-purpose model providers as there “to facilitate compliance by downstream AI system providers”, which leaves the duty with the downstream provider.
In our reading, that means three things for a team building on a model API. You need to know whether your vendor marks the specific models, endpoints and output types you use. You need evidence that the marking meets the Article 50(2) criteria for your outputs, which matters most if your pipeline edits, composites or re-encodes what the model returns. And you need a way for people to check marks on content your product made.
The Q&A also narrows the scope.1 Source code and short sequences of numbers, symbols or letters are out. So are outputs exchanged only between machines with no human exposure, and outputs used inside closed-loop industrial and product development settings unless they are the final output. A narrow exemption for business-to-business and industrial use is “envisaged”, subject to conditions set out in the Commission’s guidelines, which were adopted on 20 July 2026.9 Features that perform an assistive function for standard editing are exempt.
What the Code of Practice asks for
The Commission published the final Code of Practice on marking and labelling AI-generated content on 10 June 2026.10 On 8 July it concluded that the Code adequately covers Article 50(2), (4) and (5), and the AI Board adopted its own adequacy assessment the next day.11 Signing is voluntary, and the Commission states that adherence “does not constitute conclusive evidence of compliance”. About 190 organisations had signed by the end of July.12 TechCrunch lists Anthropic, Google, Meta, Microsoft and OpenAI among the companies that committed to it.13
The detailed measures are in the Code document. Freshfields’ summary of the final text, published on 25 June 2026, lists the parts that drive engineering work:14
- Where no single technique can meet all four quality criteria (effectiveness, interoperability, robustness and reliability), the Code expects at least two layers of machine-readable marking. Metadata must be cryptographically signed and timestamped. A public watermark is one of several options, and fingerprinting and logging are optional extras.
- One layer is enough for free-form text, which cannot carry metadata, and text under 200 tokens does not need a watermark.
- Providers must offer a way to detect their marks, in principle free of charge, hosted in the EU or runnable locally.
- Watermark detection must be interoperable by 2 February 2027, through a public API, a readable signpost in the content, a shared detector run by a consortium, or an equivalent.
- Deployers get three optional EU icons for AI-generated and AI-modified content, with rules on placement and how long a label stays visible.
For images, audio and video, the combination most teams will reach for is a signed C2PA manifest plus an invisible watermark. The C2PA specification already provides for the second layer: a “soft binding” such as a watermark or fingerprint lets a verifier look up a manifest after the metadata has been stripped.15
What model vendors now mark for you
Two of the largest model vendors changed their outputs in response, and they made different choices.
Anthropic’s support page says Claude models launched in the EU on or after 2 August 2026 support machine-readable marking at launch.16 Text carries an imperceptible watermark, and files Claude creates carry C2PA Content Credentials. Marking is applied at the model level and to output “wherever Claude is offered, worldwide”, including the API and the AWS, Google Cloud and Microsoft Foundry deployments. Anthropic says it is adding watermarks to models released before 2 August, and the page lists which models carry which marks. Detection is in private preview for regulators, law enforcement, media, fact-checkers, researchers and civil society groups, and enterprises with their own compliance duties may qualify.
OpenAI announced on 5 October 2026 that it will watermark text from ChatGPT and Codex for users in the EU, rolling out over several weeks.13 In the API, text watermarking is off by default and can be switched on for selected models. Detector access goes first to approved researchers and expert organisations. OpenAI’s own test results, as reported by TechCrunch, show how fragile text marks are: replacing 10% of the words with synonyms cut detection from about 92% to 66%.
We did not find Google documentation stating whether Gemini API text output carries a watermark. If you build on Gemini, ask your account team before you assume either way.
Both Anthropic and OpenAI say a detected mark is a signal and that a missing mark proves nothing about authorship. For a product team the practical consequences are these:
- If you use OpenAI’s API for EU users, switching on the text watermark is your decision, and it becomes part of your Article 50(2) evidence.
- Vendor marks cover what the vendor’s model produced. If your pipeline edits, composites or re-encodes media afterwards, check whether the vendor’s manifest survives, and sign your own.
- Neither vendor’s detector is open to the public yet. If you rely on vendor marks, you still need your own way to answer “did our product make this?”
California: the AI Transparency Act and SB 1000
California’s AI Transparency Act (SB 942, signed in 2024) was due to start on 1 January 2026. AB 853 moved its operative date to 2 August 2026, to line up with the EU, and added duties for large online platforms and generative AI hosting platforms from 1 January 2027 and for capture-device makers from 1 January 2028.317
As first enacted, the Act covered providers of publicly accessible generative AI systems with more than one million monthly visitors or users in California. They had to offer a free AI detection tool and a visible “manifest” disclosure option, and to embed a latent disclosure in image, video and audio content.173 The latent disclosure carries the provider’s name, the system’s name and version, the time and date of creation or alteration, and a unique identifier. Text is outside these disclosure duties. The civil penalty is $5,000 per violation, and each day of non-compliance counts as a separate violation.3
SB 1000 was signed on 30 September 2026 and chaptered as Chapter 861, Statutes of 2026. As an urgency statute it took effect immediately.418 It changes the core duties:
- The one-million-user threshold is gone, so every publicly accessible generative AI system in California is covered.
- The “AI detection tool” becomes a “disclosure verification tool”.
- The duty to offer a manifest disclosure is deleted.
- The latent disclosure must now say whether the system created or altered the content.
- Systems designed primarily as assistive technology get a delayed start, and falsely claiming that status exposes a provider to a civil action.
The Governor signed AB 2713, on system provenance data, the same day.18 We have not been able to read its chaptered text, so we don’t summarise it here. Morrison Foerster’s alert says SB 1000 leaves the 2027 and 2028 dates from AB 853 unchanged.17
Connecticut joined on 1 October
Connecticut’s SB 5, the Connecticut Artificial Intelligence Responsibility and Transparency (CART) Act, became Public Act 26-15.19 Kilpatrick Townsend gives the signing date as 2 June 2026 and the start date of its provenance duty as 1 October 2026.5 Providers of consumer-facing generative AI systems with more than one million monthly users must take commercially reasonable measures to authenticate AI-generated audio, images and video, and must make provenance information difficult to remove or alter. The law does not mandate a standard but refers to industry efforts such as C2PA. The Attorney General enforces most of the Act. Its companion chatbot rules, including a duty for chatbots to disclose that they are not human, start on 1 January 2027.19
One build that covers all three
The three regimes differ in scope and wording, but the components overlap. This is the table we would plan from, as of 8 October 2026:
| Component | EU Article 50 | California AI Transparency Act | Connecticut CART Act |
|---|---|---|---|
| Notice that the user is talking to an AI | Required for interactive systems unless obvious | Not part of this Act | Companion chatbots, from 1 January 2027 |
| Machine-readable marks on images, audio and video | Required; older systems have until 2 December 2026 | Latent disclosure required | Authentication and durable provenance for providers above one million monthly users |
| Marks on text | Required; the Code accepts a single watermark layer | Not required | Duty covers audio, images and video |
| Public verification | Detection mechanism expected | Free disclosure verification tool | Not specified in the summaries we read |
| Visible labels | Deployers label deepfakes and public-interest text | Manifest option removed by SB 1000 | Not specified in the summaries we read |
The engineering pieces behind that table:
- A provenance step at the generation boundary. Every image, audio or video file your system produces gets a signed C2PA manifest before it leaves your service, plus a watermark from your model vendor or your own.
- Metadata that survives your own pipeline. Image resizers, CDNs and transcoders can drop embedded metadata, so test every hop between generation and the user.
- A generation log keyed by content hash, so you can answer “did we make this?” after the marks are gone. The Code treats logging as optional. We would build it anyway, because both a detection mechanism and California’s verification tool are easier to run with one.
- A verification endpoint, rate-limited, that reports whether a file came from your system and shows the provenance data it found.
- Interface components: an AI notice at the start of each conversation, a label component for deepfakes and public-interest text, and the EU icons if you follow the Code.
- A short decision record for each feature, covering whether you are provider or deployer, which exemptions you rely on, and why.
A checklist for the eight weeks to 2 December
- List every feature that generates or edits media or text for users in the EU, California or Connecticut, and note its launch date against 2 August 2026.
- For each feature, decide whether you are the provider, the deployer or both.
- Get written confirmation of which vendor marks apply to your models, endpoints and regions, including whether OpenAI’s text watermark is switched on.
- Add C2PA signing for generated media, and test that manifests survive storage, resizing and delivery.
- Ship the AI interaction notice on every conversational surface, at the start of the first interaction.
- Build deepfake and public-interest text labels into publishing flows, and record who holds editorial responsibility for reviewed text.
- Stand up a verification path before 2 December 2026, even if the first version is a manual lookup.
- Decide whether to sign the Code of Practice, and write down the reasoning.
-
European Commission, “Transparency obligations under Article 50 of the AI Act” (questions and answers), https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act ↩↩↩↩↩↩↩↩
-
European Commission, “AI Omnibus enters into force”, 27 July 2026, https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force ↩↩
-
National Law Review (Bradley Arant Boult Cummings), “California’s Ongoing AI Regulation: Key Deadlines Arriving in 2026 and Beyond”, 9 July 2026, https://natlawreview.com/article/californias-ongoing-ai-regulation-key-deadlines-arriving-2026-and-beyond ↩↩↩↩
-
CalMatters Digital Democracy, SB 1000, California AI Transparency Act, https://calmatters.digitaldemocracy.org/bills/ca_202520260sb1000 ↩↩
-
Kilpatrick Townsend, “Connecticut Enacts New AI Legislation: What Businesses Need to Know About SB 5”, 29 June 2026, https://ktslaw.com/insights/alert/2026/6/connecticut-enacts-new-ai-legislation-what-businesses-need-to-know-about-sb-5 ↩↩
-
Future of Privacy Forum, “The AI Act implementation timeline: What changes under the AI Omnibus?”, 28 July 2026, updated 5 August 2026, https://fpf.org/blog/the-ai-act-implementation-timeline-what-changes-under-the-ai-omnibus/ ↩
-
European Commission, “Quick facts: transparency rules for AI systems”, https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems ↩
-
AI Act Service Desk, Article 50, consolidated text as at 27 July 2026, https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 ↩
-
European Commission, “Guidelines on the transparency obligations for providers and deployers of AI systems”, published 20 July 2026, https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems ↩
-
European Commission, “Commission publishes Code of Practice on marking and labelling AI-generated content”, 10 June 2026, https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content ↩
-
European Commission, opinion on the assessment of the Code of Practice on transparency of AI-generated content, 9 July 2026, https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content ↩
-
European Commission, “Code of Practice on Transparency of AI-generated Content”, https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content ↩
-
TechCrunch, “OpenAI will start watermarking ChatGPT’s text in the EU”, 5 October 2026, https://techcrunch.com/2026/10/05/openai-will-start-watermarking-chatgpts-text-in-the-eu/ ↩↩
-
Freshfields, “EU AI Act Unpacked #33: The final Code of Practice on Transparency of AI-generated content”, 25 June 2026, https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-33-the-final-code-of-practice-on-transparency-of-ai-generate-102n4yx ↩
-
C2PA Specifications 2.4, “Soft Binding API”, https://spec.c2pa.org/specifications/specifications/2.4/softbinding/Decoupled.html ↩
-
Anthropic, “How Claude marks AI-generated content”, support article, read on 8 October 2026, https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content ↩
-
Morrison Foerster, “California Revamps AI Transparency Requirements”, 1 October 2026, https://www.mofo.com/resources/insights/261001-california-revamps-ai-transparency-requirements ↩↩↩
-
Office of the Governor of California, bill signing release, 30 September 2026, https://www.gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more/ ↩↩
-
CT Mirror, “New CT AI, data privacy laws go into effect Oct. 1. What to know”, 28 September 2026, https://ctmirror.org/2026/09/28/artificial-intelligence-data-privacy-laws-october-ct/ ↩↩
Frequently asked questions
When do the EU AI Act transparency obligations apply?
Article 50 has applied since 2 August 2026. Providers of generative AI systems placed on the market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
Does a chatbot have to say it is an AI under the EU AI Act?
Yes, unless that is obvious to a reasonably well-informed person. The Commission says the exception should be read restrictively, and the notice should come at the start of the first interaction.
If my product uses OpenAI or Anthropic models, who is responsible for marking outputs?
The duty falls on the provider of the AI system that generates the content, which is usually the company shipping the product. The Commission says model-level marking facilitates compliance by downstream providers, so vendor watermarks help but do not move the duty.
Do I need to watermark AI-generated text?
Usually yes, if you provide a generative AI system used in the EU. Article 50(2) covers synthetic text as well as images, audio and video, but the Commission’s Q&A puts source code and short strings of numbers, symbols or letters out of scope, and assistive editing features are exempt.
What did California SB 1000 change?
Signed on 30 September 2026 as an urgency statute, it removes the one-million-user threshold, replaces the AI detection tool with a disclosure verification tool, drops the manifest disclosure option and requires the latent disclosure to say whether content was created or altered.
What are the penalties for breaking these rules?
In the EU, fines for Article 50 breaches can reach €15 million or 3% of total worldwide annual turnover. Under California’s AI Transparency Act, the civil penalty is $5,000 per violation, and each day counts as a separate violation.
Building something like this?
9io is a small team of senior engineers with a fractional CTO, and we work by the hour. Send us a note about your product. The reply comes from the person who'd do the work.