AI Act Article 50 requires machine-readable AI watermarks. Here's what SynthID and C2PA actually deployed, what studies show, and the consequences.

Since 2 August 2026, marking AI-generated content is no longer an optional best practice in the European Union — it is a legal obligation carrying fines of up to 3% of worldwide turnover. Major providers — Google, OpenAI, Adobe, Meta, Microsoft — have in fact deployed watermarking technology at scale. But independent studies published alongside that rollout converge on an uncomfortable conclusion for compliance teams: none of these technologies, on its own, holds up durably against a determined actor.

This article covers what has actually been deployed, what independent testing shows about how well it works, and what that means in practice — for providers subject to the obligation, and for anyone who has to judge whether a piece of content can be trusted.

For the full legal framework, see our dedicated page on Article 50 transparency obligations and our analysis of what changed on 2 August 2026. This article takes a different angle: the technology itself, its measured results, and its practical consequences.

Three different things called "watermark"

The most common confusion comes from the fact that "watermark" actually refers to three distinct mechanisms with very different properties.

  1. The visible label — a banner, icon, or caption reading "AI-generated." Easy for a human to understand, but not machine-readable, and it disappears the moment a screenshot or crop excludes it from the frame.
  2. The invisible mark embedded in the signal — an imperceptible pattern woven into an image's pixels, an audio file's samples, or the statistical distribution of tokens in generated text. This is SynthID's principle, developed by Google DeepMind. It survives compression and format conversion reasonably well because it is part of the content itself rather than attached data.
  3. Signed provenance metadata — a cryptographic manifest attached to the file, documenting who created the content, with what tool, and what edits followed. This is the approach of the C2PA (Coalition for Content Provenance and Authenticity) standard, marketed as Content Credentials.

Article 50(2) of the AI Act requires "machine-readable marking" without mandating any specific technology — which is why the market has converged on combining categories 2 and 3 rather than relying on either alone.

What has actually been deployed in 2026

Deployment accelerated sharply over the past year, driven both by the EU's regulatory deadline and by competitive pressure between major providers.

Technology Developed by Marking type Notable adoption
SynthID Google DeepMind Invisible, embedded in the signal (image, audio, video, text) Deployed across Google's own generative outputs; SynthID-Text open-sourced for third-party integration
C2PA / Content Credentials C2PA coalition (Adobe, Google, Microsoft, Meta, OpenAI, Sony, BBC, Amazon…) Cryptographically signed metadata Coalition with several thousand members and affiliates; built into many cameras and editing tools by default
Sora 2, DALL·E 3, ChatGPT images OpenAI C2PA + SynthID-style invisible watermark OpenAI joined the C2PA steering committee on 19 May 2026 and committed to layering both on its outputs
Meta AI Meta Visible label + proprietary detection signals and industry standards Deployed across content generated in Meta products
Firefly, Copilot, TikTok Adobe, Microsoft, TikTok C2PA Emit Content Credentials on generated content

This table makes one point clear: leading providers no longer rely on a single technique. The Code of Practice on Transparency of AI-generated Content, which the Commission has confirmed as an adequate means of demonstrating Article 50 compliance, explicitly recommends a multi-layer approach — C2PA metadata and a pixel-level invisible mark able to survive compression, cropping, and format conversion. The Code itself acknowledges that no single technique meets all four legal criteria — effective, interoperable, robust, and reliable — at once, which is precisely why the industry has converged on layering rather than choosing one.

What the results actually show

This is where the picture gets more complicated. Several independent research efforts published through 2024 and 2025 have tested how well these mechanisms hold up against deliberate attempts to defeat them — and the results considerably qualify the vendor narrative.

C2PA metadata is structurally fragile. It is not anchored in the visual or audio content itself: strip it, and any trace of provenance disappears. Most major social platforms strip file metadata by default on upload — for file-size and privacy reasons, not to dodge regulation. In practice, the provenance chain breaks at exactly the moment content reaches the most people: the moment it's shared.

Invisible watermarks hold up better, but not indefinitely. SynthID's core idea — embedding the mark in the signal itself — makes it considerably more resistant to compression, format conversion, or simple cropping than a metadata file. But research teams have repeatedly shown, since 2024, that a watermark of this kind can be degraded below detection thresholds through targeted perturbations, or simply by regenerating the content through another generative model to strip the original mark.

A study from the University of Waterloo's Cybersecurity and Privacy Institute captures the scope of the problem well: its researchers demonstrated that virtually any AI image watermark can be removed, without the attacker needing to know the watermark's design, or even whether the image carries one at all. The same team notes that a bad actor can evade both deepfake detection and copyright enforcement simply by passing content back through a diffusion model.

Providers themselves acknowledge this. A Microsoft report on media integrity and authentication, published in February 2026, explicitly concedes that it is not possible to prevent every attack, nor to stop certain platforms from stripping provenance signals during file processing.

A parallel arms race has taken hold. As major providers expanded watermark coverage through 2026, publicly available tools — open-source repositories and commercial services alike — added support for stripping exactly those marks within weeks. That extremely short gap between a watermark's rollout and the availability of a removal tool is telling: watermarking isn't a static protective mechanism, it's a moving technical contest.

The practical consequences

Three groups of actors are directly affected, and not in the same way.

For bad-faith actors, watermarking changes almost nothing. A voluntary — or technically defeatable — mechanism doesn't stop someone determined to produce a deepfake for election disinformation, identity fraud, or impersonation. Election-integrity research has noted across several cycles that groups producing malicious deepfakes have, by definition, no reason to use a tool that marks them — and will develop or borrow the means to strip a mark if one is technically imposed on them. That is precisely the argument for a legal mandate rather than a purely voluntary best practice: it shifts legal risk onto the provider that fails to mark, even though it doesn't technically stop a downstream bad actor.

For good-faith companies, compliance becomes both costly and short of a full guarantee. Article 50 imposes an obligation of result — marking that is "effective, reliable, robust and interoperable" — even as the Code of Practice itself acknowledges that no current technology meets all of those criteria alone. In practice, providers subject to the obligation must layer multiple technical mechanisms (C2PA plus an invisible watermark, at minimum), document their method, and still carry residual exposure if their marking is stripped at scale — a risk they don't fully control, since it also depends on how downstream distribution platforms behave. Signing the Code of Practice remains, at this stage, the most documented route to demonstrating good-faith compliance, without amounting to immunity.

For platforms, newsrooms, and fact-checkers, watermarking creates a false-security risk. The absence of a mark doesn't prove authenticity — it may simply mean the mark was stripped during sharing, or that the content came from a non-compliant tool. Conversely, a provenance badge can be mistaken for a guarantee of reliability when the underlying mechanism remains, by design, defeatable. The real reliability lever remains human verification and contextual analysis — technical marking is a supporting signal, not proof.

Regulation itself appears to be drawing the same conclusion. Beyond 2 December 2026 — when the transitional period for machine-readable marking of pre-existing generative systems closes — the Code of Practice envisages building interoperable detection infrastructure, so that detection tools from different vendors can recognise marks emitted by other providers. That effort, distinct from marking itself, is an implicit admission that system reliability can't rest on watermarking alone, but on a shared detection ecosystem — a considerably harder problem than the marking technique itself.

What this means for a company subject to Article 50

Our compliance checklist covers the full obligation set, and the AI Act deadline tracker lets you check the dates that apply to your situation. The full text of the obligation is at Article 50 of the Regulation, and the applicable penalties at Article 99.

Sources

Official AI Act Compliance Deadline Calendar

Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.

Obligation Applies to Original date New date Status Countdown Legal basis
Prohibited Practices (Art. 5) All providers and deployers active AI Act Art. 5
GPAI Rules (Chapter 5) GPAI model providers active AI Act Art. 51-56
Commission Enforcement Powers over GPAI GPAI model providers active AI Act Art. 88-94, 101
Transparency Obligations (Art. 50) Providers and deployers of chatbots, generative, emotion recognition systems active AI Act Art. 50
New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) Providers and deployers of generative AI systems active AI Omnibus 2026 Art. 5
AI-Generated Content Marking (pre-existing systems) Providers of generative AI systems on the market before 2 Aug 2026 active AI Act Art. 50(2) — transitional
Regulatory Sandboxes National competent authorities deferred AI Omnibus 2026 Art. 57
High-risk AI — Annex III (standalone) Providers of standalone Annex III systems deferred AI Omnibus 2026 Art. 6(2)
High-risk AI — Annex I (embedded) AI embedded in Annex I regulated products deferred AI Omnibus 2026 Art. 6(1)

Download JSON · CC BY 4.0

Frequently Asked Questions

The term covers three distinct techniques that get conflated: a visible label (an on-screen 'AI-generated' badge), an invisible mark embedded in the signal itself (image pixels, audio samples, text token distribution), and cryptographically signed provenance metadata, such as the C2PA / Content Credentials standard. Article 50 of the EU AI Act requires the second category — machine-readable marking — without mandating any specific technology.

Yes, since 2 August 2026. Article 50(2) of Regulation (EU) 2024/1689 requires providers of generative AI systems to mark their synthetic outputs in a machine-readable format. A transitional period until 2 December 2026 applies only to systems already placed on the EU market before 2 August 2026 — any system launched after that date must mark its outputs from day one.

In nearly all cases, yes. C2PA metadata disappears the moment a platform strips it on upload — which most social platforms do by default. Invisible watermarks embedded in pixels or audio samples resist compression and cropping better, but research, including work at the University of Waterloo, has shown a watermark can be degraded below detection thresholds without the attacker knowing its design, for example by regenerating the content through another generative model.

C2PA (Content Credentials) is a signed-metadata standard that documents a file's provenance — who created it, with what tool, and what edits followed. That metadata is not anchored in the visual or audio content itself and disappears if the file is re-encoded or a platform strips it. SynthID, developed by Google DeepMind, is an invisible mark embedded directly in the signal (image, audio, video, text) — more resistant to common manipulation, but also defeatable through targeted attacks. The Commission's Code of Practice recommends combining both.

No, and this is one of the most underappreciated practical risks. The absence of a mark proves nothing: the content may have been marked and then stripped of its metadata during sharing, generated by a non-compliant tool, or simply be genuine. Conversely, a 'verified AI' badge can create a false sense of reliability when the underlying marking mechanism remains, by construction, defeatable.

Non-compliance with Article 50 carries fines of up to €15 million or 3% of total annual worldwide turnover, whichever is higher, enforced by national market surveillance authorities. Signing the Code of Practice on Transparency does not confer legal immunity, but it is the most documented compliance route and the one the Commission has recognised as adequate.

Stay ahead of AI Act changes

Get compliance alerts when deadlines or obligations change.

No spam. One-click unsubscribe.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.