ISHIGHRISK AI
Analysis

Should you sign the Code of Practice on AI-generated content?

Signing is voluntary, the Article 50 duties are not. What Sections 1 and 2 of the Code commit providers and deployers to, and what signing actually buys.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

The Code of Practice on transparency of AI-generated content, final text 10 June 2026, has two sections that are signed separately: Section 1 for providers marking and detecting output under Article 50(2), Section 2 for deployers labelling deepfakes and public-interest text under Article 50(4). On 8 July 2026 the Commission concluded it adequately covers Article 50(2), (4) and (5), and the AI Board adopted its adequacy assessment the next day, but adherence does not constitute conclusive evidence of compliance. Signing buys a recognised, EU-wide way of demonstrating compliance in exchange for binding yourself to specific measures, such as two-layer marking, a free detection tool and an "AI" label placed to set rules. Not signing is not a breach, but you then have to show by your own means that your measures are adequate.

The question is not whether to comply

Since 2 August 2026, providers of generative AI systems owe machine-readable marking under Article 50(2), subject to the transitional period to 2 December 2026 in Article 111(4) for systems already on the market, and deployers owe disclosure of deepfakes and certain AI-generated text under Article 50(4). None of that depends on the Code of Practice on AI-generated content. What the Code changes is how you prove you have done it.

On 8 July 2026 the Commission concluded, in opinion C(2026) 4839, that the Code "adequately covers the obligations provided for in Articles 50(2), (4) and (5) AI Act and facilitates their effective implementation". The AI Board adopted its own adequacy assessment the next day. By the Commission's signatory table, last updated 24 September 2026, 95 organisations have signed Section 1 and 192 have signed Section 2. So the practical question for a provider or deployer in scope is narrower than "should we comply": it is whether to bind yourself to the Code's specific measures in exchange for a recognised way of demonstrating compliance, or to build and defend your own.

This page sets out what each section actually commits you to, by commitment and measure number, and what signing buys and costs on each side. Whether Article 50 reaches your system at all is the prior question, and the Article 50 transparency guide and the classifier deal with that.

What the Code is, and what it is not

The Code was drawn up by independent experts, in working groups led by independent chairs and vice-chairs, in a process facilitated by the AI Office, with a first draft on 17 December 2025, a second on 3 March 2026 and the final text published on 10 June 2026. It rests on Art 50(7), which in the current consolidated text reads: "The Commission, taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article". The same paragraph continues: "If it deems the code of practice to be inadequate, the Commission may adopt an implementing act specifying common rules for the implementation of those obligations". With a positive assessment in hand, there is no implementing act and the Code is the reference instrument.

Three limits on its status are written into the documents themselves.

  • It is not conclusive. Both sections state in their objectives that adherence "does not constitute conclusive evidence of compliance", and the Commission's opinion repeats it.
  • It can be reassessed. The opinion states that it "does not prevent the Commission from assessing the Code as inadequate in the future" following monitoring under Articles 50(7) and 56(6).
  • It will change. The opinion records that the AI Office "will consider facilitating formal updates to the Code at least every two years", for instance as standards or technology develop.

It is also a different instrument from the General-Purpose AI Code of Practice, which concerns the model-provider duties in Articles 53 and 55 and is covered in the GPAI obligations guide. Teams that signed the GPAI Code have not thereby signed anything about Article 50 marking or labelling.

Section 1: what providers commit to

Section 1 covers providers of generative AI systems under Article 50(2) and (5). Within it, "will" marks a mandatory measure "for which compliance will be monitored by competent market surveillance authorities", while "encouraged" and "may" mark optional ones. That distinction is the first thing to read before signing, because the "will" measures are more specific than the bare statutory text. The technical detail of marking is covered in the guide to meeting the Article 50(2) marking duty; what matters here is what the signature adds.

Commitment 1, marking. Measure 1.1 requires at least one machine-readable technique and, so long as no single technique meets all four Article 50(2) criteria, "at least two layers": digitally signed, time-stamped metadata where the format supports it (Sub-measure 1.1.1) and an imperceptible watermark (Sub-measure 1.1.2). Free-form text cannot carry metadata, so a watermark alone suffices for it, and "very short text", defined in the glossary as text shorter than 200 tokens, is excepted from watermarking. A single layer is also sufficient for a generative system embedded in a physical product working in "a technically controlled and closed environment mainly instructive in nature", to the extent effective technical measures stop the output leaving the product. Fingerprinting or logging is optional and, under Sub-measure 1.1.3, "not considered sufficient" on its own. Measure 1.2 requires best efforts to preserve existing metadata markings on inputs, to prohibit removal of markings in your terms or acceptable use policy, and not to market tools designed to circumvent markings. Measures 1.3 (richer provenance) and 1.4 (an option for users to apply a visible label) are optional.

Commitment 2, detection. Measure 2.1 requires a detection solution for each marking technique, as a public specification, software or an API. It has to be free of charge; a signatory with fewer than 1,000,000 monthly users whose detection solution incurs substantial operational costs may charge a proportionate fee only where a single user's requests exceed a reasonable volume threshold, and authorities, media, fact-checkers, researchers and civil society always get free unlimited access. Detection of free-form text watermarks may be restricted to verified expert users. Uploaded content must be deleted immediately after detection under Sub-measure 2.1.3(e), and Measure 2.3 requires results that a member of the public can understand.

Commitment 3, quality. Measures 3.1 to 3.4 turn the four statutory adjectives into tests: user-based assessment for effectiveness, error rates for reliability, and robustness against compression, cropping, screenshots, paraphrasing, translation and print-and-scan as well as deliberate removal attacks. Measure 3.4 requires an interoperability solution for watermark detection "by 2 February 2027", chosen from a standard query API, a public signpost in the content, a shared consortium detector or an equivalent.

Commitment 4, process. A documented compliance process (Measure 4.1), testing before placement on the market and regularly after (Measure 4.2), staff training (Measure 4.3), and cooperation with market surveillance authorities, including access to your marking and detection solutions on reasoned request (Measure 4.4).

Section 1 also allows reliance on upstream work. Marking and detection may be supplied by a model provider or a specialist vendor, and Measure 4.2 lets a downstream system provider rely on their test results, "without prejudice to the ultimate responsibility of the Signatory". Providers of models placed on the market separately, and vendors of marking and detection tools, may sign Section 1 voluntarily so that their customers can build on it.

Section 2: what deployers commit to

Section 2 covers deployers under Article 50(4) and (5), and only "in so far as" they are deployers of systems generating or manipulating deepfakes, defined in Art 3(60), or text published with the purpose of informing the public on matters of public interest, within the scope of Article 50(4). Everything else a deployer generates is outside it. The page on deepfake disclosure rules covers what falls inside that scope.

Commitment 1, disclosure. Signatories label through the EU icon in Annex 1 "or through an equivalent icon or label" meeting the design and placement specifications. Measure 1.1 makes the capitalised acronym "AI" the main visual element, in English unless national language law requires otherwise; audio-only deepfakes get a short audible disclaimer at the start. Measure 1.2 governs placement: perceivable without user action, embedded in the content or an equivalent overlay, clear of other overlay elements (the example given is the top right corner), at the start of a video and after interruptions such as advertising breaks, and for published text above the text, near the headline or in the colophon. Measure 1.3, joining the icon task force, is optional.

Commitment 2, internal processes. Proportionate documentation of how you label (Measure 2.1), staff awareness (Measure 2.2), and a review process that remedies substantiated reports of missing or wrong labels "without undue delay" (Measure 2.3).

Commitment 3, artistic and similar works. Evidently artistic, creative, satirical or fictional works still carry the icon or an equivalent label, but placed so as not to hamper the work, for example in credits, accompanying notes or at the point of entry or sale.

Commitment 4, editorial control. Media service providers under Regulation (EU) 2024/1083 may rely on the Article 50(4) editorial exception through their existing procedures. Other signatories relying on it commit to an internal policy for human review or editorial control that identifies the person with editorial responsibility and the organisational measures and human resources allocated to review, and to publish that contact where it is not already public.

The Commission's icon page offers three icons: a basic "AI" icon, "AI + GENERATED" for fully generated content and "AI + MODIFIED" for partially modified content, each in four variations: black, white, and each of those at 50% transparency. The same page states that using the icons is optional, but the labelling requirements are not, and that using them "does not establish legal compliance by itself".

Signing versus not signing: what each buys

The Commission's signing questions and answers frame the trade directly. Signatories "may rely on the code to demonstrate compliance". Not signing "does not constitute non-compliance with the AI Act", but non-signatories "must be prepared to demonstrate compliance through other adequate means", may need a gap analysis against the Code, and "may be subject to a larger number of requests for information or access from competent authorities".

Signs Does not sign
Provider, Article 50(2) Relies on an instrument the Commission and Board found adequate for 50(2) and (5), recognised in every Member State. Takes on the Section 1 "will" measures: two-layer marking, signed metadata, a free detection tool with zero-retention uploads, removal prohibitions in its terms, and an interoperability solution by 2 February 2027. Keeps freedom of technique, for example a single marking layer it believes meets all four criteria. Must document why its measures are effective, interoperable, robust and reliable, and defend that separately to each market surveillance authority that asks.
Deployer, Article 50(4) Relies on the Section 2 placement rules as the recognised standard for "clear and distinguishable" under 50(5). Takes on the "AI" label specification, documented processes, a correction process and, if it relies on the editorial exception, a published editorial-responsibility contact. Free to design its own disclosure, which still has to meet Article 50(4) and (5). Can use the EU icons anyway, but the Commission notes that use by non-signatories should not be read as adherence to the Code.
Both roles Invited to sign both sections. Carries both burdens of proof.
Neither role A model or marking-tool vendor may sign Section 1 voluntarily to support downstream providers. No Article 50(2) or (4) duty in that capacity.

Two points cut across the table. First, a signature does not create the duty, and the duty applies identically either way: enforcement, as the Commission puts it, relates to non-compliance with Article 50, "not the absence of adherence to the code". Second, signing raises the floor you will be held to. A non-signatory under 50(2) is measured against four statutory adjectives; a signatory is also measured against the measures it committed to, and those are monitored.

A hypothetical to test your position. A small image-generation start-up already embeds signed provenance metadata and a watermark, and runs a public detector. For it, Section 1 adds mainly the interoperability deadline and documentation, so signing is close to free. A start-up relying on metadata alone would be committing to build a second layer and a detection service before it could honestly sign. The same Code is a formality for one and a project for the other.

Who has signed, and how signing works

The Commission reported about 190 signatories by the end of July 2026, around half of them small and recent companies. Its table, last updated 24 September 2026, now lists 95 signatories for Section 1 and 192 for Section 2. Examples it names for Section 1 include Aleph Alpha, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; for Section 2, Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo and Lufthansa. The list is public, which makes it a quick first check when you assess a generative AI vendor.

The mechanics, per the Commission's signing questions and answers:

  1. Sections, not commitments. Each section is signed as a whole. You cannot pick commitments within it.
  2. A senior signature. The form must be signed by "a senior executive with sufficient authority to bind" the organisation.
  3. No closing date. 27 July 2026 was the cut-off for the initial list; signing remains open and the list is updated on an ongoing basis.
  4. Withdrawal is possible, by a letter from an executive at the same level, after which the benefits of adherence no longer apply.
2 Feb 2027 Section 1 signatories must have a watermark-detection interoperability solution in place under Measure 3.4(c).

What to check before you sign

  1. Fix your role per system. Article 50(2) attaches to the provider of the generative system, Article 50(4) to the deployer publishing the content. Many organisations are both for different products, and the provider versus deployer guide sets out how to tell.
  2. Read the "will" measures as a checklist against what you run today. For providers, the gaps are usually the second marking layer, a public detector and its data-retention terms, and the 2 February 2027 interoperability solution. For deployers, it is usually label placement in video and on syndicated text.
  3. Check what your vendors have signed. If your marking comes from an upstream model or tool, their Section 1 signature and documentation are what Measures 4.1 and 4.2 let you rely on, though responsibility stays with you.
  4. Budget for change. The Code anticipates formal updates at least every two years, and both sections provide for signatory task forces, which the Commission said would be launched in September 2026. Their output on audio icons, interactive second layers and interoperability will feed later versions.
  5. Do not wait on the signature to start the work. Whatever you decide, the obligations already apply, and the Article 50(2) grace period page explains which providers still have until 2 December 2026.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is the Code of Practice on AI-generated content mandatory?

No. Signing is voluntary, and the Commission's own questions and answers state that not signing "does not constitute non-compliance with the AI Act". The underlying duties are not voluntary: Article 50(2) binds providers of generative systems and Article 50(4) binds deployers publishing deepfakes or public-interest text, whether or not they sign. A non-signatory has to demonstrate that its own measures are adequate, assessed individually by market surveillance authorities.

Does signing the Code mean I comply with Article 50?

Not automatically. The Commission's opinion of 8 July 2026 concludes that the Code adequately covers Article 50(2), (4) and (5) and that signatories may rely on it, "while recognising that adherence to the Code does not constitute conclusive evidence of compliance with these obligations". What counts is implementing the measures, not the signature. A signatory that does not actually mark, detect or label as the Code requires is in the same position as anyone else who fails Article 50.

Can I sign only part of the Code?

You can sign one section without the other, but not individual commitments. The Commission's signing questions and answers state that separate sections "may be signed individually, while individual commitments may not". A provider of a generative system under Article 50(2) is invited to sign Section 1, a deployer under Article 50(4) to sign Section 2, and an organisation that is both is invited to sign both.

Is this the same as the GPAI Code of Practice?

No. The General-Purpose AI Code of Practice concerns the model-provider obligations in Articles 53 and 55 and was approved in 2025. The Code of Practice on transparency of AI-generated content concerns Article 50(2), (4) and (5) and was published on 10 June 2026. Signing one says nothing about the other, although a model provider can sign Section 1 of the transparency Code voluntarily to support downstream system providers.

Do I have to use the EU AI icon to label deepfakes?

No. Commitment 1 of Section 2 allows the EU icon "or an equivalent icon or label" that meets the Code's design and placement specifications, whose main visual element is the capitalised acronym "AI". The Commission's icon page is explicit that using the icons is optional but the Article 50 labelling requirements are not, and that using them "does not establish legal compliance by itself".

Can I still sign the Code after the July 2026 deadline?

Yes. The 27 July 2026 date was the deadline for appearing in the initial list of signatories published before Article 50 applied on 2 August 2026. The Commission's questions and answers state that providers and deployers can sign at any time by submitting the signature form, and the signatory list is updated on an ongoing basis. Signatures can also be withdrawn, after which the benefits of adherence no longer apply.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 5 October 2026. Final classification for ambiguous cases needs qualified counsel.