# Synthetic content labelling and provenance marking

- **Record type**: Control
- **Kind**: Technical measure
- **Owner**: Engineering lead
- **Frequency**: Continuous
- **Duties served**: 5

## What the control achieves

Makes AI-generated or manipulated audio, image, video and text identifiable as such, both to people looking at it and to software checking it, so that it cannot easily be passed off as authentic.

## How it is typically implemented

Generation pipelines attach a machine-readable provenance signal to output, for example a content credential manifest, an invisible watermark or metadata, using a method that survives the common ways the content will be shared. Where the audience needs to see it, a visible label or spoken notice is added as well. The team documents which methods are used for which modality, tests detectability and robustness to editing, and keeps a verification tool or endpoint available. Downstream products that display deepfakes or AI-written material of public interest apply the label rules set by the organisation's editorial policy.

## Evidence it produces

- Content labelling and provenance standard (procedure): Methods used per modality, label wording and exceptions.
- Watermark and provenance robustness test (evaluation_report)
- Visible AI-generated content label (disclosure_notice)

## Legal duties this control serves

- Disclose AI interaction and label synthetic content — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-transparency-article-50
- Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-50-2-synthetic-content-marking
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-art-50-4-deepfake-and-public-interest-text-disclosure
- Report incidents and mark AI-generated content (generative AI framework) — Singapore Model AI Governance Framework, Singapore (satisfies): https://aipolicytracker.org/obligations/singapore-mgf-genai-incident-reporting-and-provenance
- AI business operators must label generative AI output and clearly flag realistic synthetic media — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea (satisfies): https://aipolicytracker.org/obligations/south-korea-ai-basic-act-art-31-generative-output-labelling-and-deepfake-notice

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.8.2, A.9.3
- NIST AI RMF 1.0: MEASURE 2.8; MANAGE 4.1 — Transparency measures for generative AI outputs.
- OWASP Top 10 for LLM Applications: LLM09 Misinformation

## MIT AI Risk Repository subdomains addressed

3.1, 3.2, 4.1, 4.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/synthetic-content-labelling-and-provenance
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
