Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
Context fileUnder EU AI Act, Article 50(2)
What does it require?
Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as the state of the art allows, taking account of content type and cost. Systems that only perform assistive editing or do not substantially alter the input, and law-authorised criminal-detection uses, are outside the duty.
Practical action
Implement watermarking or content credentials on generated output and keep test evidence that the mark survives common transformations.
Who does it apply to?
Providers of systems that generate synthetic media or text, whatever the risk tier; codes of practice under Article 50(7) will detail acceptable techniques.
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
satisfiesTechnical measureEngineering lead · continuousSynthetic content labelling and provenance marking
Serves 5 recorded duties · evidence: Content labelling and provenance standard, Watermark and provenance robustness test, Visible AI-generated content label
Machine-readable marking with robustness evidence.
-
supportsTechnical measureQuality or testing lead · at launch and on material changeAccuracy, robustness, fairness and security testing
Serves 15 recorded duties · evidence: Pre-release test report, Test plan and acceptance criteria, Release test sign-off
Tests that the mark is robust and reliable.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Provenance marking design and robustness test report | report | |
| Output sample with embedded machine-readable mark | record |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A.8.2, A.6.2.4 | System documentation; verification and validation of the marking. | low |
| NIST AI RMF 1.0 | MEASURE 2.7, MANAGE 4.1 | Provenance mechanisms as recommended in NIST AI 600-1. | medium |
Cite this record
AIPolicyTracker (2026). “Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-50-2-synthetic-content-marking (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Provide deployers with clear instructions for use — EU AI Act, European Union
- Employers must inform workers and their representatives before using high-risk AI at work — EU AI Act, European Union
- Disclose AI interaction and label synthetic content — EU AI Act, European Union
- Deployers of emotion recognition or biometric categorisation must inform exposed persons — EU AI Act, European Union
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest — EU AI Act, European Union
- Deployers must explain individual decisions taken with high-risk AI on request — EU AI Act, European Union
- Deployers must tell natural persons that a high-risk AI system is used in decisions about them — EU AI Act, European Union
- Notify individuals about the use of personal data in AI recommendations and decisions — PDPC AI advisory guidelines, Singapore
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.