The European Commission has published the final Code of Practice on the marking and labelling of AI-generated content, representing a significant practical step toward implementing the EU Artificial Intelligence Act. Although the Code is voluntary and does not, per se, create new legal obligations, it will play a vital role in practice, particularly in interpreting and demonstrating compliance with the transparency obligations set out in Article 50 of the AI Act[1].
The relevant obligations take effect on 2 August 2026, and the Code provides providers and deployers with a voluntary, practical framework for their implementation. From this date onwards, the AI Act will mandate clear disclosure of AI usage in several instances. Users must be informed when interacting with an interactive AI system, such as a chatbot or virtual assistant, unless the circumstances make this obvious. Furthermore, deepfakes and texts generated or manipulated by AI that are published with the intention of informing the public on matters of public interest must be appropriately marked.
The objective of these rules is to mitigate the risk of deception and manipulation. Content generated or significantly modified by AI can be difficult for users to identify, particularly where realistic images, audio recordings, videos, or texts capable of influencing public discourse are concerned. Transparency is therefore not merely a formal requirement, but a fundamental prerequisite for the responsible use of generative AI.
The Code distinguishes between the obligations of providers and deployers of AI systems. For providers, the focus lies primarily on the technical aspect of transparency. Providers of generative AI systems that generate or manipulate text, image, audio, or video content must ensure that the system’s outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. In this regard, the Code emphasises the practical application of visual labels and detection mechanisms. Recommended solutions include standardised EU-created icons or other clear markings that inform users in an understandable manner that the content was generated or substantially modified by AI. These markings should be complemented by technical mechanisms enabling the detection of content origin, such as watermarking, metadata, or other machine-readable solutions.
This obligation is not relevant solely for developers of general-purpose or foundation models. In practice, it may also encompass undertakings that integrate existing models into their products or services which they place on the market or put into service under their own name. An organisation that embeds a language model into an application for generating marketing text, legal drafts, images, or videos may, with respect to such a system, be positioned as a provider of a generative AI system. Consequently, it cannot rely merely on the fact that it did not develop the underlying foundation model itself.
The second part of the Code pertains to deployers of AI systems. Their obligations are generally less technical, yet highly consequential in practice. Deployers will be required to clearly label deepfakes and certain texts generated or manipulated by AI when intended to inform the public on matters of public interest and where they have not undergone human review or editorial control. A key issue in practice will be determining when disclosure is required, how it must be designed, and where it must be displayed to ensure it is sufficiently clear and intelligible to the user.
In this context, distinguishing between different degrees of AI deployment is essential. Not all content produced with the aid of AI is identical. Fully autonomous AI content generation differs substantially from a purely auxiliary role in proofreading, summarising, translating, or preparing a draft that subsequently undergoes substantive human review. This distinction is crucial as it affects the scope and format of disclosure. Over-labelling every minimal instance of AI usage risks diluting the significance of the markings, whereas under-disclosure could compromise user trust.
Despite its voluntary nature, the Code’s practical weight will be substantial. Signatories to the Code will be able to demonstrate compliance with the AI Act more easily by implementing the envisaged technical and organisational measures (with supervision expected to focus primarily on monitoring compliance with the Code itself). For market surveillance authorities, the Code will likely serve as a primary reference point when assessing whether an organisation has complied with transparency requirements. By signing the Code, providers and deployers confirm their intention to adhere to it in their operations, and their status as signatories will be publicly disclosed. Undertakings choosing a different approach will consequently bear the burden of proving that their alternative measures are comparable and sufficient.
The Code will be supplemented by forthcoming Commission guidelines intended to clarify the scope of legal obligations further and matters not fully addressed within the Code itself. Nevertheless, it is critical for undertakings to treat AI transparency as an integral part of their broader compliance framework, and to do so immediately. This entails identifying AI systems, assessing the roles of respective actors, regulating contractual relationships with suppliers, establishing internal rules for content marking, and setting up clear procedures for human review and editorial oversight.
The Code of Practice on Marking AI-Generated Content is therefore not merely a technical addendum to the AI Act, but a practical execution framework. It offers guidance to organisations on how content generated or modified by AI should be marked, how disclosures should be presented to users, and how undertakings can demonstrate the establishment of appropriate processes. Ultimately, the central question in practice will no longer be whether AI was utilised, but whether its deployment was clearly disclosed, promptly, and in a way that enables the user to comprehend the origin of the content.
—
[1] Article 50 of the EU AI Act lays down transparency rules for specific AI systems, notably the obligation to inform natural persons when interacting with AI, to mark artificially generated or manipulated content, to provide notification when using emotion recognition or biometric categorization systems, and to disclose deepfakes as well as certain AI-generated text.