EU AI Act Article 50: A Practical Evidence Framework for AI Transparency

21. Juli 2026 AI Act Article 50 EN 13 min

This article is a technical guide to documentation and evidence. It is not legal advice.

Article 50 of the EU AI Act applies from 2 August 2026 — twelve days after this article was verified. On 20 July 2026 the Commission approved the content of its Article 50 Guidelines and published them. The final Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 and assessed as adequate by Commission Opinion of 8 July 2026.

Primary sources: Article 50, Regulation (EU) 2024/1689 · the Commission's Article 50 guidelines, published 20 July 2026.

The interpretive material has landed. The operational question has not been widely answered:

On 3 August 2026, a market surveillance authority asks how you comply with Article 50(2). What do you hand over?

The dates, precisely

"It shall apply from 2 August 2026. However: (a) Chapters I and II shall apply from 2 February 2025; (b) Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101; (c) Article 6(1) and the corresponding obligations in this Regulation shall apply from 2 August 2027."

— Art. 113, Regulation (EU) 2024/1689

Article 50 sits in Chapter IV, which Article 113 does not carve out. The Guidelines confirm this and add that Article 50 applies regardless of when a system was placed on the market.

One narrow transitional carve-out. The Guidelines report that a Regulation amending the AI Act (the "AI Omnibus") provides a grandfathering rule only for the marking and detection obligations under Article 50(2), for generative systems placed on the market before 2 August 2026, giving them until 2 December 2026. The disclosure obligation under Article 50(1) is not covered and remains due on 2 August 2026. We report this as stated by the Commission in the Guidelines; we have not reviewed the amending Regulation itself.

Penalties. Article 99(4)(g): up to EUR 15 000 000 or 3 % of total worldwide annual turnover, whichever is higher. This is not the 7 % / EUR 35 M figure, which applies only to the prohibited practices in Article 5. For SMEs including start-ups, the cap is the lower of the two.

Provider or deployer? The split decides everything

WhoObligationTrigger
50(1)ProviderDesign the system so people are informed they interact with an AI systemSystem intended to interact directly with natural persons
50(2)ProviderMark outputs in a machine-readable format, detectable as artificially generatedSystem — including general-purpose AI systems — generates synthetic audio, image, video or text
50(3)DeployerInform exposed persons of the system's operationEmotion recognition or biometric categorisation
50(4)DeployerDisclose artificial generation/manipulationDeep fakes; and text published to inform the public on matters of public interest

The same entity is frequently both, and must satisfy both sets independently.

Three carve-outs decide a large share of real cases:

50(1) obviousness is not available as an assumption — the Guidelines state that providers need to assess and demonstrate that the artificial nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person.

50(2) assistive editing — marking does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input or its semantics.

50(4) editorial review — AI-generated text published to inform the public is exempt where it underwent human review or editorial control and a natural or legal person holds editorial responsibility. The Guidelines add that the identity and contact details of that person or function should be made publicly available in an easily findable location.

Note too that a deployer cannot discharge Article 50(4) by pointing at the provider's machine-readable mark: the Guidelines state such markings are not immediately clear and distinguishable to the natural persons exposed to the content.

What is binding, and what is not

This distinction is doing a lot of work in the current commentary, so it is worth setting out plainly.

CategoryStatusExample
Legal obligationBinding. Enforceable. Fines under Art. 99(4)(g)Article 50(1)–(5) themselves
Guideline expectationNon-binding. Commission's stated view of good practiceThe gap analysis described in Guidelines ¶148
Voluntary Code pathOptional. A recognised way to demonstrate complianceSigning the Code of Practice
Alternative adequate meansEqually lawful. Must be demonstrableYour own documented measures
Practical preparationPrudent, not requiredHaving answers ready for an information request

Three things follow, and all three matter:

  1. The Article 50 obligations are legally binding. Nothing below changes that.
  2. Adherence to the Code of Practice is voluntary. Signing it is not a legal requirement, and not signing it is not a breach.
  3. Non-signatories may demonstrate compliance through alternative adequate means. The Guidelines say so expressly.

The Guidelines are themselves non-binding — they state that any authoritative interpretation of the AI Act may ultimately only be given by the Court of Justice of the European Union. A procedural nuance worth stating accurately: the accompanying Communication says the Commission approved the content of the draft, with formal adoption to follow once all language versions are available; the Commission's library page describes them as adopted. Both are primary sources.

The paragraph most teams have not read

Source: Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, C(2026) 5054 final ANNEX, published 20 July 2026, §8.1, paragraph 148, printed page 48 (PDF page 49).

"Providers and deployers that are not signatories to a code of practice that is deemed adequate … are expected to demonstrate how they have complied with their obligations under Article 50(2), (4) and (5) AI Act through other adequate means. … For instance, they should carry out a gap analysis that compares the measures they have implemented with the measures set out by a code of practice that is assessed as adequate."

What this is, precisely. It is a guideline expectation, phrased as "are expected to" and "should", inside a document that declares itself non-binding. It is not a new standalone legal duty, and there is no statutory obligation to produce a gap analysis. What is binding is the underlying duty to comply with Article 50(2), (4) and (5) — and, if asked, to be able to show how.

The same paragraph explains the practical consequence: authorities will have less understanding of how non-signatories ensure compliance and will likely need more detailed information; non-signatory providers may be subject to a larger number of requests for information and requests for access to assess the effectiveness, interoperability, robustness and reliability of their technical solutions. Deployers may face equivalent requests regarding their labelling practices.

The Guidelines also note that commitments implemented in line with an adequate code may be taken into account as a mitigating factor when fixing the amount of fines.

Read commercially rather than legally: not signing is a legitimate choice that shifts explanatory effort onto you. The gap analysis is the cheapest known way to be ready for that effort — which is why we treat it as a planning artefact, not a legal requirement.

What the reviewed documents name — and what they do not

A factual observation, offered as an observation only.

Across the Guidelines and the Code of Practice, no specific content-provenance or watermarking technology is named. A full-text search of both documents returns no mention of C2PA, Content Credentials, JPEG Trust, SynthID, IPTC, EXIF or XMP. The only technical standards named by name in either document are ETSI EN 301 549 and WCAG 2.1 Level AA, both of which are accessibility standards. The Code itself notes that interoperability standards are yet to be developed, except for digitally signed metadata.

What this does not mean. It does not mean any of those technologies is unsuitable, disapproved or excluded — the documents are technology-neutral by design, and the Guidelines expressly allow a single technique or a combination. It does not mean marking is optional: Article 50(2) requires machine-readable marking, and no amount of documentation substitutes for it. Evidence records what you implemented; they are not themselves a marking technology.

The Guidelines reuse Recital 133's list — watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity, logging methods, fingerprints — and the Code requires a multi-layered approach with at least two layers of machine-readable marking, with a carve-out for free-form text, which cannot carry metadata.

Four distinct layers people collapse into one

Source for the provenance point: Guidelines, C(2026) 5054 final ANNEX, 20 July 2026, §4.2, paragraph 73, printed page 24 (PDF page 25):

"…providers are not required to record or keep a full provenance chain containing information on content origin and modifications or any other relevant assertion concerning the history of the content. However, such provenance methods may also be used for compliance with Article 50(2) AI Act and be conducive in enabling natural persons to distinguish AI-generated or manipulated content from authentic content."

Both halves matter. A full provenance chain is not a legal requirement. Provenance methods may be used for compliance and are described as conducive. Keeping these apart:

LayerStatusWhat it is
1. Transparency requirementLegal obligationArticle 50 itself: inform, mark, disclose
2. Machine-readable markingLegal obligation under 50(2)The technical mark on the output. Cannot be substituted by documentation
3. Evidence of the implemented measureNeeded in practice to answer authoritiesRecords showing what you implemented, when, and why
4. Extended evidence chain / full provenanceVoluntaryOptional. Explicitly not required by ¶73 — and explicitly permitted

FeedOracle's evidence tooling sits at layer 3, and optionally layer 4. It is a technical demonstration pattern, not a prescribed legal instrument, and it does not replace layer 2.

Which claim needs which evidence

ObligationClaim you are makingEvidenceOwner
50(1)"Users were told they interact with an AI"UI disclosure snapshot + build version + activation timestampProvider
50(1) exemption"It was obvious"Documented assessmentProvider
50(2)"Outputs are machine-readably marked"Per-output record: system ID/version, marking layers, mark digest, timestampProvider
50(2)"Solutions are effective, interoperable, robust, reliable"Method-selection record; testing results; known-limitations registerProvider
50(2)"Detection is available"Publicly available detection with human-readable outputProvider
50(3)"Exposed persons were informed"Notice text, channel, exposure timestamp, accessibility conformanceDeployer
50(4) deep fake"Artificial origin disclosed"Publication record binding disclosure to artefact digestDeployer
50(4) text"Human review exemption applies"Reviewer, timestamp, publicly findable editorial responsibility holderDeployer
50(5)"Given at first exposure, accessibly"Timing evidence; ETSI EN 301 549 / WCAG 2.1 AA conformanceBoth

Log, attestation, receipt, timestamp, signature

ArtefactEstablishesDoes not establish
LogAn event was recorded by a system you controlThat it happened as recorded, or was not edited later
SignatureData was endorsed by a key holderWhen; or that the holder was authorised
Timestamp (RFC 3161)Data existed at a point in timeAnything about content correctness
AttestationA named party asserts a fact and accepts responsibilityThat the assertion is true
ReceiptA transaction occurred between partiesThat the underlying obligation was discharged

The Code arrives at the same place for marking metadata: recorded information is to be digitally signed and time-stamped in a secure and tamper-evident manner.

A machine-readable evidence record

FeedOracle publishes an Evidence Pack Manifest schema v1.0 (EPM) at https://feedoracle.io/.well-known/epm.schema.json, which carries its own disclaimer: "Universal evidence pack schema. Data infrastructure only - not compliance certification."

Its type enum has no Article 50 type today. What follows is a proposed profile using the schema's extensions field — a design pattern for any schema, not a shipped feature, and a layer 3 artefact in the table above.

{
  "epm_version": "1.0",
  "manifest_id": "EPM-ART50-20260802T094500",
  "type": "generic",
  "issued_at": "2026-08-02T09:45:00Z",
  "manifest_hash": "sha256:<digest of this manifest without this field>",

  "issuer":  { "id": "did:web:example.com", "name": "Example Organisation" },
  "subject": { "id": "sha256:<digest of the generated artefact>",
               "type": "ai.output.image" },
  "jurisdiction": "EU",

  "extensions": {
    "ai_act_article_50": {
      "role": "provider",                     // provider | deployer | both
      "paragraph": "50(2)",
      "system": { "id": "example-imagegen", "version": "4.2.1" },

      // Layer 2 evidence — records the marking, does not replace it.
      // The Code requires at least two layers unless the output is free-form text.
      "marking_layers": [
        { "layer": "signed_metadata", "signed": true, "timestamped": true },
        { "layer": "watermark", "detector_public": true }
      ],

      // Marking without available detection does not satisfy Art. 50(2)
      "detection": {
        "publicly_available": true,
        "endpoint": "https://example.com/detect",
        "human_readable_output": true,
        "industry_standard_solution": false,
        "interim_justification": "no harmonised standard available at time of selection"
      },

      // Voluntary. Guideline expectation for non-signatories, not a legal duty.
      "code_of_practice": {
        "signatory": false,
        "gap_analysis_digest": "sha256:<digest of the dated gap analysis>",
        "gap_analysis_date": "2026-07-28"
      },

      "robustness": {
        "tested_at": "2026-07-15",
        "report_digest": "sha256:<...>",
        "known_limitations": ["mark may not survive re-encoding below 480p"]
      },

      // Only when relying on the Art. 50(4) editorial exemption
      "editorial_responsibility": null,

      // Layer 4 — optional, explicitly not required (Guidelines ¶73)
      "provenance_chain": null
    }
  },

  "attestors": [
    { "role": "issuer", "id": "did:web:example.com",
      "name": "Example Organisation", "signature_ref": "urn:sig:es256k:<...>" }
  ],
  "sources": [
    { "name": "EU AI Act Art. 50",
      "uri": "http://data.europa.eu/eli/reg/2024/1689/oj",
      "retrieved_at": "2026-07-21T00:00:00Z" }
  ],
  "validity": { "from": "2026-08-02T09:45:00Z" },
  "handling": { "class": "INTERNAL", "retention_days": 3650 }
}

Four design points worth reusing:

  1. subject.id is a content digest, not a filename. Evidence not bound to content by hash is not evidence.
  2. marking_layers is an array — a single-value field encodes the wrong model.
  3. detection is first-class. Marking without available detection does not satisfy 50(2).
  4. provenance_chain is explicitly null. It records a deliberate decision not to keep a full chain — which ¶73 permits — rather than leaving the question open.

Limits and open questions

Definitions remain soft at the edges. "Substantially alter … the semantics", "assistive function for standard editing" and "matters of public interest" are elaborated in the Guidelines but not defined in the operative text.

Marks can be removed. Article 50(2) asks for robustness as far as technically feasible. No scheme survives every transformation. Record known limitations.

Interoperable detection is still emerging. The Guidelines require reliance on publicly available industry-standard detection where it exists and permit other solutions in the interim; the Code sets 2 February 2027 for an interoperability solution.

Compliance is not lawfulness. Recital 137 is explicit that complying with the transparency obligations does not indicate the system or its output is lawful under other law. GDPR applies independently. Joint Commission/EDPB guidelines on the AI Act × data protection interplay are described in the Guidelines as under preparation — they do not yet exist.

As of 21 July 2026 we found no published list of Code signatories. The Code contains no numeric KPIs and no periodic reporting obligation; documentation is produced on an authority's reasoned request.

Adjacent, and in German: AI governance under DORA and the AI Act covers the operational-resilience side of the same question.

What this proves — and what it does not prove

What a well-formed evidence record proves: that a specific artefact carried specific marking layers, produced by a named system version, at a verifiable time, endorsed by an identified party, with detection available and method reasoning fixed in advance.

What it does not prove:

No technical artefact is a regulatory verdict. Human review remains required. This article is not legal advice.

Where FeedOracle fits

FeedOracle is data infrastructure. It produces evidence and indicators at layer 3. It is not a marking technology, does not perform Article 50(2) marking, and does not issue compliance verdicts.

Do this before 2 August 2026

  1. Classify yourself per paragraph — provider under 50(1)/(2), deployer under 50(3)/(4), or both. Date it.
  2. Confirm your marking works — at least two machine-readable layers unless the output is free-form text. This is the binding obligation.
  3. Make detection available and human-readable.
  4. Decide on the Code. Voluntary. Not signing is legitimate.
  5. If not signing, consider the gap analysis described in ¶148. Not a legal duty; the cheapest way to be ready for information requests.
  6. Name the editorial responsibility holder publicly for AI-generated text informing the public, or accept the exemption is unavailable.
  7. Bind evidence to content digests, not filenames.

Sources

Regulation (EU) 2024/1689 (OJ L, 2024/1689, 12.7.2024), Arts. 50, 99, 113, 2(7); recitals 132–137 · European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, C(2026) 5054 final ANNEX, published 20 July 2026 (¶73 p. 24; ¶¶146–149 pp. 47–48) · Code of Practice on Transparency of AI-Generated Content, 10 June 2026 · Commission Opinion on the adequacy of the Code, 8 July 2026.

Verified 2026-07-21. Technical evidence guide, not legal advice.

Evidence records, not compliance verdicts

FeedOracle is data infrastructure. It produces evidence and indicators; it does not perform Article 50(2) marking and it does not issue compliance verdicts.

evidence terminal

Related: continuous DORA evidence · all articles