Generative models already in service before 2 August 2026 must mark their outputs by 2 December. Anthropic is the first to date its migration model by model — where the other providers stand, and what a deployer should demand.
Since 2 August 2026, every model provider has managed to announce that its new models mark their outputs. That was the easy part: a model born under the rule is born marked. The question almost nobody asks concerns the models already in service — the ones thousands of companies wired into their products before the obligation existed, and for which the Regulation grants only a reprieve.
That reprieve closes on 2 December 2026. As this article is published, less than three months remain. And one provider has just put dates on its migration, model by model.
For the full legal framework, see our page on the Article 50 transparency obligations. For the technology of marking and its demonstrated limits, see our analysis of watermark deployment. This article is about something else: the existing fleet, and what a deployer should be demanding from a provider before December.
What the reprieve covers — and what it does not
Article 50(2) of Regulation (EU) 2024/1689 requires providers of generative AI systems to mark their outputs in a machine-readable format, detectable as artificially generated or manipulated. That obligation has applied since 2 August 2026.
The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — carved out a narrow exception: generative AI systems already placed on the Union market before 2 August 2026 get four additional months, until 2 December 2026, to satisfy that single marking duty.
Three points decide your actual exposure.
The reprieve covers marking only. The other three Article 50 duties have applied since 2 August with no delay whatsoever: telling people they are interacting with a conversational system, informing people subject to emotion recognition or biometric categorisation, and labelling deepfakes and text published on matters of public interest. A company that believes it is covered until December for the whole of Article 50 is wrong about three obligations out of four.
The test is when the system was placed on the market, not when you integrated it. A pre-August model you wire into your product today is still a pre-August model: the delay belongs to its provider, and it is the provider who must have closed it by December.
The obligation falls on the provider of the generative system, not on you as an integrator — until the point at which you become the provider yourself, notably by putting your own mark on the system or substantially modifying it. Our guide to third-party AI obligations covers that shift in detail. But even as a pure deployer, your product inherits a dependency: if the model you consume does not mark its outputs in December, it is your product that ships unmarked content.
The first dated migration schedule
At Anthropic, models launched on or after 2 August 2026 mark their outputs from the moment they enter service. The Claude Platform release notes of 1 September 2026 confirm this for Claude Fable 5.1 and Claude Mythos 5.1: text carries the house watermark, and image, video and audio files produced through the code execution tool carry C2PA Content Credentials when retrieved through the Files API.
That left the older fleet. According to a notice sent to Claude Platform customers, seen by this publication and not publicly reported to date, Anthropic is extending its text watermark to Claude Opus 5 outputs from 9 September 2026. It is the first pre-application model to be caught up; the other models in service are to follow over the coming weeks, with each change announced in advance. The move is presented explicitly as getting ahead of the December deadline, so that marking is already in place for customers working through obligations of their own.
Four technical properties matter to anyone integrating these models.
- The mark is applied at the model layer. It therefore holds everywhere the model is served — Amazon Web Services, Google Cloud and Microsoft Foundry included. This is the legally significant property: the mark travels with the model, including through a cloud reseller, and does not depend on the interface you reach it through.
- The pattern is statistical, carried in word choice. It adds no characters and no tokens, changes neither meaning nor readability, and has no effect on pricing, latency, or request and response formats.
- The mark carries no information about the user, their organisation, or their conversations. That is the first objection compliance teams and data protection officers raise; it is answered at source.
- No action is required on the customer side. The switch is transparent to existing integrations.
That last point is worth stating for what it implies in reverse: a well-designed marking migration should not break an integration. If a provider tells you otherwise, the question to ask is which layer the mark is applied at.
Where the other providers stand
| Provider | New models | Older fleet | Text marking |
|---|---|---|---|
| Marked | Already marked — SynthID deployed on images since 2023, extended to text and video in 2024 | Yes | |
| Anthropic | Marked since 2 August 2026 | Dated migration — Opus 5 on 9 September, others announced in advance | Yes |
| OpenAI | Images and audio marked | Images marked since 2024 (C2PA), invisible watermark added in 2026; audio extended 31 July 2026 | No — method built, never deployed, no announced date |
| Meta | C2PA, proprietary image and audio marking, visible label | Progressive rollout across consumer products | Not documented |
| Microsoft | C2PA Content Credentials on Designer and Copilot | — | Not documented |
| Mistral | Transparency code signatory | No public detail | Not documented |
| xAI | Visible logo on images | No commitment | No — signed neither code |
The instructive contrast is not between good and bad pupils but between two strategies. Google had no migration to run: it was marking its outputs three years before it had to, and its fleet was compliant before the rule existed. Anthropic has the most visible migration because it is the most recent — and because it is being dated publicly, model by model. OpenAI, by contrast, signed the code of practice that provides for text marking and still does not mark ChatGPT's text, with no schedule announced.
Two codes of practice, two lists of signatories
This is the most widespread confusion in the analysis published this summer, and it changes how each provider should be judged.
The code of practice on general-purpose AI models, published in July 2025, covers model safety, security, transparency and copyright. Around thirty providers signed it. Meta refused to sign; xAI signed only its safety and security chapter.
The code of practice on transparency of AI-generated content is a separate instrument, published on 10 June 2026, which the Commission found adequate on 8 July and the AI Board on 9 July. The Commission's Article 50 guidelines followed on 20 July, and the list of signatories was published on 31 July 2026: roughly 190 organisations, of which 82 under Section 1 — providers, subject to the marking duties — and 152 under Section 2, the deployers subject to labelling.
Meta signed this second code, having refused the first. xAI signed neither. A non-signatory is not exempt from Article 50: it remains bound by the Regulation, but must build and defend a method of its own and demonstrate that it is as robust as the code — with, on the AI Office's consistent position, a heavier burden of proof and more requests for information.
Section 2 signatories include companies well outside the sector: Bulgari, Getty Images, Iberdrola, Lenovo, Lufthansa. A useful reminder that labelling generated content is not an AI-lab problem.
What a deployer should demand before December
If you integrate a third-party model into a product that generates text, images, audio or video, four written requests are worth more than passive monitoring.
- The list of models you consume, with the marking status of each. A provider who cannot answer model by model does not know where it stands.
- The dated migration schedule for models predating 2 August 2026. Anthropic has just established that such a schedule can be communicated in advance, model by model. That is now a precedent you can cite to other providers.
- The layer at which marking is applied. A model-layer mark follows you across every platform serving that model; a mark applied only to the consumer interface does not cover your API calls.
- How to obtain detection access. Detection APIs are, at most providers, in restricted access — reserved for regulators, law enforcement, media, researchers, and companies under a verification obligation of their own. If you are in that last category, ask explicitly.
And two checks on your own side: your processing chain must not destroy the provenance metadata on files you redistribute — many resizing and compression pipelines strip it by default; and your status must be settled, because putting your own mark on a third-party system, or substantially modifying it, makes you the provider, with the obligations that follow.
What marking does not prove
One final caution, to hold in any public communication on the subject. A detected mark means the model processed the content — it does not say the model wrote it unaided, or in what proportion. Absence of a mark proves nothing either: the content may come from a model outside the scheme, from a non-compliant provider, from a rewrite deep enough to fall below the detection threshold, or from a file whose metadata was stripped at publication. The independent research on marking robustness, which we set out in a dedicated analysis, converges on exactly this point.
Marking is a compliance instrument and a provenance signal. It is neither an AI detector nor proof of authorship — and presenting it as either creates exposure of its own.
Our compliance checklist covers the full set of obligations, and the deadline tracker gives the dates that apply to your situation. The text of the obligation is at Article 50, the penalties at Article 99.
Sources
- European Commission — Code of Practice on Transparency of AI-generated Content
- European Commission — Strong backing for the Code of Practice on Transparency of AI-generated Content, 31 July 2026
- Anthropic — How Claude marks AI-generated content
- Anthropic — How Claude's text watermarking works, 14 August 2026
- Anthropic — notice to Claude Platform customers regarding Claude Opus 5, seen by this publication
- OpenAI — Advancing content provenance for a safer, more transparent AI ecosystem
- Google DeepMind — SynthID
- Regulation (EU) 2024/1689 — Article 50
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
It is extra time granted to one obligation only — the machine-readable marking duty in Article 50(2) — and only to generative AI systems already placed on the Union market before 2 August 2026. It was introduced by the Digital Omnibus, Regulation (EU) 2026/1744. After 2 December 2026 those systems must mark their outputs like every other.
Only if it was already placed on the Union market before 2 August 2026. Any system launched on or after that date had to mark from day one, with no grace period at all. The test is when the system was placed on the market, not when you integrated it: an older model wired into your product in September is still an older model.
No, and this is the most common misreading. It covers only the machine-readable marking of synthetic content. The other three duties have applied since 2 August with no grace period: telling people they are interacting with a conversational system, informing people subject to emotion recognition or biometric categorisation, and labelling deepfakes and text published on matters of public interest.
Three things, in writing: the list of models you consume with the marking status of each; the dated migration schedule for models predating 2 August 2026; and the layer at which the mark is applied. A mark applied at the model layer holds everywhere that model is served, including through a cloud reseller; a mark applied only to the consumer interface does not cover your API calls.
For providers that have documented their scheme, no. Statistical text marking works through word choice without adding characters or tokens, and has no effect on pricing, latency, or request and response formats. Provenance metadata is different: it is attached to files and can be stripped by your own processing chain — that is the part to check on your side.
Breaching Article 50 carries fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. These are imposed by national market surveillance authorities rather than the Commission — for most companies the regulator that comes calling is national.
No, and the converse matters just as much. Absence of a mark may mean the content came from a model outside the scheme, from a non-compliant provider, or that it was rewritten enough for the mark to fall below detection. A detected mark means the model processed the content, not that it wrote it unaided. Marking is a provenance signal, not proof of authorship.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.