The EU Code of Practice on Marking AI-Generated Content: What It Is, and Whether to Sign
TL;DR
- The Code of Practice on marking and labelling AI-generated content was published in final form on 10 June 2026. It gives providers and deployers of generative AI a practical route to meeting the Article 50 transparency obligations that apply from 2 August 2026.
- It is voluntary. It creates no obligations of its own, and the Article 50 duties apply whether or not you sign.
- It has two sections: Section 1 for providers (machine-readable marking of generative outputs), Section 2 for deployers (deepfake labelling and public-interest text disclosure).
- It is technology-neutral. It does not mandate C2PA. It asks for a layered approach (machine-readable metadata, watermarking, and detection), on the reasoning that any single marker can be stripped in normal distribution.
- Signing gives you a defined set of measures you can point to as evidence of good-faith compliance. It is not legal immunity, and competent authorities remain the final judge.
- To appear on the Commission's initial signatory list, forms were due by 27 July 2026, 18:00 CEST. You can still sign after that; you simply are not on the first published list.
- Eligibility is wider than most people assume: it includes technology providers of marking and detection solutions, for Section 1.
- If you do not sign, nothing breaks. You just have to demonstrate compliance by your own means, which is a harder conversation with a regulator.
What the Code is
The EU AI Act sets out transparency duties in Article 50, but the regulation says little about how to satisfy them technically. The Code of Practice fills that gap. It translates the legal text into a set of concrete measures that providers and deployers of generative AI systems can adopt.
The Commission published draft versions through the first half of 2026 and adopted the final text on 10 June 2026, ahead of the obligations applying on 2 August 2026.
The most important thing to understand is what kind of instrument this is. The Code is voluntary. It is not a regulation, not a delegated act, and not a harmonised standard. It does not add obligations, and it cannot excuse you from any. Article 50 applies to you on 2 August 2026 on exactly the same terms whether you sign or ignore it.
Is your AI system high-risk?
Find out in 2 minutes, free, no signup required.
Take the free assessmentThe two sections
The Code mirrors the AI Act's split between who builds a system and who uses one.
If you build a generative product, Section 1 is yours. If you publish AI-generated material, Section 2 is yours. Plenty of organisations are in both. If you are unsure which you are, the provider vs deployer guide works through it, and getting this wrong is the most consequential mistake in the whole area.
It is not a C2PA mandate
This is the single most widely repeated error about the Code, and it is worth being precise.
The Code is technology-neutral. It does not require any particular marking technology. It asks for a layered approach, and the reasoning is practical rather than legal: any single marker can be stripped. Metadata disappears when an image is screenshotted, re-encoded, or passed through a social platform. A watermark can survive that but is harder to read reliably. Detection tooling covers different ground again.
So the Code describes layers:
- Machine-readable metadata following recognised standards
- Watermarking embedded in the content signal itself
- Detection and verification capability, so the marking is actually useful to someone downstream
Within that, C2PA / Content Credentials is the obvious reference point for images and media. That status comes from industry adoption (Adobe, Microsoft, Google, OpenAI, camera manufacturers), not from any legal designation. You may satisfy the obligation by other means, provided the outcome is machine-readable and detectable.
For text, there is no signal to embed a watermark in, so provenance metadata is the practical route. Statistical text watermarking remains experimental and is not required.
Practical guidance on assembling these layers is in content marking.
What signing actually gets you
Here is the honest version, without the marketing gloss that has attached to this topic.
What it gives you:
- A defined, externally recognised checklist you can complete and point to, instead of inventing your own compliance story.
- Evidence of good-faith compliance with Article 50, which is a materially better position in a conversation with a national authority than an ad-hoc justification.
- Public visibility on the Commission's signatory list, which carries some credibility signal with customers and partners.
What it does not give you:
- Legal immunity. It is not a get-out-of-jail card.
- A formal presumption of conformity in the sense that a harmonised standard confers. Competent authorities still assess your actual compliance.
- Any reduction in the underlying obligations. Article 50 applies regardless.
Anyone telling you that signing makes you compliant is overselling it. Anyone telling you it is meaningless is underselling it. It is evidence, and evidence is worth having.
Who can sign
Eligibility is broader than the usual assumption that this is a big-tech instrument:
- Providers of generative AI systems capable of generating synthetic audio, image, video or text
- Deployers using generative AI systems professionally, with obligations under the AI Act
- Providers of AI models, and technology providers of marking and detection solutions, for Section 1 only
That last category is the one people miss. If you build tooling that marks or detects AI-generated content, you can sign in respect of Section 1 even though you are not the one generating the content.
Signing has to be done by someone with authority to bind the organisation, for example a senior executive. In practice, for a startup, that is a founder.
The deadlines
Missing 27 July is not fatal. Organisations may still sign afterwards by submitting the signature form; they simply will not appear on the initial list published before the AI Act's general date of application. If the credibility of being on the first list matters to you, the date matters. If not, the substance is unchanged.
Should you sign? A straight answer
The general rule: sign if the Code's measures describe work you genuinely have to do. Do not sign as a marketing gesture, because the commitments are real and you would be publicly bound to measures you may not implement.
If you do not sign
Nothing breaks on 2 August. You are in exactly the same legal position under Article 50 as a signatory. The difference is evidential. A signatory can point to a recognised set of measures; a non-signatory has to explain, in its own words, why what it did was sufficient. That is a harder conversation, not an impossible one, and for a small company with a simple chatbot notice it is a conversation that is unlikely to ever happen.
What you should do either way is keep a record: what AI you use, what you disclosed, how you marked generated content, and when. Documentation is what turns a defensible position into a provable one.
How to sign
Signing is a form, not a process. Complete the Commission's signatory form and send it to the AI Office at the address published on the Commission's how to sign page. The Commission also publishes a Q&A covering the mechanics, and a set of EU icons for labelling AI-generated content that are worth adopting regardless of whether you sign, since a common visual vocabulary helps users more than a bespoke label does.
Frequently asked questions
Is the Code of Practice mandatory?
No. It is voluntary. Article 50 is mandatory; the Code is one route to demonstrating you have met it.
Does the Code require C2PA?
No. It is technology-neutral and asks for layered marking. C2PA is the obvious reference point for images and media because of industry adoption, not because the Code mandates it.
Can I still sign after 27 July 2026?
Yes. You will not appear on the initial signatory list published before 2 August 2026, but you can still sign.
Does signing protect me from fines?
No. It is evidence of good faith, not immunity. Competent authorities remain the final judge of compliance.
I only have a chatbot. Do I need any of this?
Probably not the Code itself. You need the disclosure. See do I need to disclose my AI chatbot? and, if you run WordPress, how to add the disclosure.
What if I am outside the EU?
The AI Act can still reach you where your AI's output is used in the EU or you target EU users. Eligibility to sign is not restricted to EU-established organisations.
Next steps
- Read the interpretation: the Commission's final Article 50 guidelines
- Confirm your obligations: free EU AI Act assessment
- Implement marking: content marking guidance
- Full transparency guide: Article 50, deepfakes and labelling
This article is general information, not legal advice. For your specific situation, consult a qualified professional.



