AI Board

Should you sign the AI transparency Code of Practice?

The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026. The European Commission’s Opinion of 8 July 2026 concluded it adequately covers Articles 50(2), (4) and (5) of the EU AI Act, and the AI Board adopted its own adequacy assessment the following day. And yet the Code’s own text, in the Objectives section of both its parts, states that adherence does not amount to conclusive proof of compliance. Signing is also severable — the provider-facing and deployer-facing halves can be signed independently, by different kinds of organisation, for different reasons. This is a real commercial decision with asymmetric costs on each side, not a box-ticking formality.

What the Code is and isn’t

The Code is voluntary. It doesn’t replace the Act, and it doesn’t replace the Commission’s separate guidelines on implementing Article 50 — a draft of those guidelines was published on 8 May 2026, a targeted consultation closed on 3 June 2026, and the final version is expected before 2 August 2026. The Code and the Guidelines do different jobs: the Guidelines interpret what the law requires; the Code offers one accepted way to meet it. It imposes no obligation beyond what the Act already imposes on providers and deployers within its scope.

Within the Code itself, every commitment is graded. Measures marked “will” are what a signatory commits to as binding; measures marked “encouraged” are recommended but not required; measures marked “may” are left entirely optional. That grading matters more than it looks — it’s the difference between something you’re accountable for and something you can quietly skip.

What signing buys you

The Commission’s own framing is direct: signatories get an EU-wide recognised way to demonstrate compliance, regardless of where they’re established or which national market surveillance authority has jurisdiction over them, and future enforcement effort will focus on monitoring adherence to the Code rather than re-litigating compliance from scratch. That’s a real reduction in administrative burden and a real increase in predictability.

Weigh that against the other half of the sentence. The Code does not guarantee compliance, and — as commentary on the equivalent regime for general-purpose AI models under Article 56 has already established for that adjacent Code — alternative routes to compliance may exist alongside it. Signing narrows your risk. It doesn’t eliminate the need to actually do the thing the Code describes.

The two sections, and why you might sign only one

Section 1 covers providers under Article 50(2). Because no single marking technique is currently considered reliable enough on its own, the Code generally expects a multi-layered approach: digitally-signed, tamper-evident metadata recording that content is AI-generated or manipulated, combined with imperceptible watermarking embedded in the content itself. Fingerprinting or logging sits alongside these as an optional third layer. Providers also commit to offering a detection mechanism — typically free of charge, though the Code allows smaller signatories to charge where detection carries substantial operational cost — while forensic detection of content that’s been stripped of its marking stays optional, on the Code’s own acknowledgment that the technology isn’t mature enough yet to meet the Act’s reliability bar. A staged interoperability requirement follows, with a working solution for watermark detection due by 2 February 2027.

Section 2 covers deployers under Article 50(4) and (5): labelling deepfakes, and labelling AI-generated or manipulated text published to inform the public on matters of public interest that hasn’t been through human review. Notably, the Code doesn’t leave the visual form of that label to the deployer’s judgment — it obliges use of the Commission’s own EU AI icon, or an equivalent, wherever visual disclosure is possible, with an audible disclaimer as the fallback where it isn’t.

The split explains why an organisation might reasonably sign only one half. A model or system provider with no deployment role of its own has nothing to gain from Section 2’s labelling commitments. A retail business running marketing campaigns through a third-party generative tool is a deployer with no marking infrastructure to build — Section 1 isn’t its problem, Section 2 is. Only a company that both builds and ships generative features to end users has a reason to sign both.

The alternative route, and its price

Nothing about the Code forecloses building your own approach instead. The Code’s own drafting on this point directs signatories testing marking and detection solutions to weigh them against current state-of-the-art benchmarks and testing methods generally, expressly including any that the AI Office develops or recognises together with the AI Board — phrasing that concedes those AI Office-recognised benchmarks are still a work in progress rather than a finished reference you can simply cite.

That’s the real price of the alternative route. Until the AI Office publishes its own benchmarks, an organisation going it alone is testing against internal benchmarks and general industry practice, and carrying the burden of proving that’s good enough — optionally strengthened with independent red-teaming or a run through an Article 57 regulatory sandbox. A signatory can point to the Code. A non-signatory has to build and defend an equivalent case from scratch, to a market surveillance authority that hasn’t pre-approved the yardstick.

Who else is signing

The Code is open well beyond the organisations Article 50 actually binds. Technology providers of marking and detection solutions — companies with no generative AI system of their own — can sign Section 1 to demonstrate their tools meet the Code’s technical bar. That matters commercially: a generative AI provider choosing a third-party watermarking vendor has a direct reason to prefer one that has already signed, since the Code lets a signatory rely on a third party’s solution only where that third party has itself adhered to the Code and demonstrated compliance with it.

A subtler case is generative AI model providers, as distinct from the system providers Article 50 actually addresses — the Act’s transparency duties are pinned to systems, not to the underlying models that power them. The Code’s first draft tried to impose hard obligations on model providers directly; the final version backed away from that and merely encourages them to implement marking and detection at the model level, so that system providers built on top of their models can comply more easily downstream. It’s a voluntary, upstream courtesy, not a binding duty — and the softening between drafts is itself a signal of how contested that question was.

The decision

Three questions do most of the work. Do you ship generative output — audio, image, video or text — into the EU market at all, as a provider or a deployer? If not, none of this applies yet. If you do, can you evidence your marking or detection performance independently, against a benchmark a regulator would accept, without the Code’s cover? If that’s expensive or uncertain, signing is the cheaper insurance. And do you sell to enterprise customers who are starting to ask suppliers whether they’re Code signatories as part of their own due diligence? If procurement teams are already asking, being on the list answers the question before it’s asked.

Frequently asked questions

Is the signatory list public?

Not yet, as of this writing. The deadline to be included in the first published list is 22 July 2026 at 18:00 CEST, and the Commission has said that list will be published before the Article 50 obligations take effect on 2 August 2026.

Can we join later?

Yes. Signing remains open after 22 July 2026 — organisations that miss that date simply submit the signature form afterward and aren’t on the first published list, without losing the ability to sign at all.

Does signing bind our downstream customers?

No. Each organisation in a generative AI supply chain has its own role and its own Article 50 obligations. Signing signals your own adherence and, where relevant, supports customers building on top of you — the Code specifically encourages provider-level tooling that helps deployers meet their own duties — but it doesn’t extend your signature to bind anyone downstream.

Does the Code cover Article 50(1)?

No. The Code addresses Articles 50(2), (4) and (5) — marking, deepfake and public-interest text labelling, and the form those disclosures take. Article 50(1), the general AI-interaction disclosure duty, and Article 50(3), the emotion-recognition and biometric-categorisation notice, sit outside the Code entirely and are addressed only by the Commission’s separate Article 50 guidelines.

What happens if you sign and then fail to implement?

The Code frames signing as signalling intent to adhere to its commitments, not as a one-time filing that stands in for the work. An organisation that signs but doesn’t actually implement the marking, labelling or detection measures it committed to isn’t shielded by having signed — it has simply made a compliance claim that doesn’t match its practice, which is a weaker position than never having claimed Code adherence in the first place.

Posted by admin in What happened with...

AI Act deepfake labelling: artistic and editorial carve-outs

Article 50(4) of the EU AI Act (Regulation (EU) 2024/1689) requires deployers to disclose when image, audio or video content is a deepfake, and when text has been artificially generated or manipulated for publication on matters of public interest. Two carve-outs sit inside that duty — a lighter disclosure for content that is “evidently” artistic, creative, satirical or fictional, and no disclosure at all for text that passed through genuine editorial control. Both sound generous on a first read. Neither is as wide as it looks, and the European Commission’s draft guidelines, published 8 May 2026, spend more time narrowing them than most summaries let on.

Which content counts as a deepfake under Article 50(4)?

The duty sits with the deployer, not the provider — whoever publishes or puts the content in front of people, not whoever generated it. It applies to AI-generated or manipulated image, audio or video content that constitutes a deepfake under Article 3(60): content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic or truthful.

The Commission’s draft guidelines read that definition wider than most people assume. Three clarifications matter:

  • Intent is irrelevant. Whether the content falsely appears authentic doesn’t depend on whether the deployer meant to deceive anyone. An absence of fraudulent intent doesn’t defeat the labelling duty.
  • “Existing” is read broadly. A realistic synthetic depiction of a fictitious but natural-looking person can still be a deepfake, even where no identifiable real person is implicated — it’s enough that the subject resembles someone or something that could exist, or could once have existed.
  • Not every edit counts. Routine adjustments — lighting, colour correction, noise reduction, sound cleanup — normally don’t turn content into a deepfake, because they don’t meaningfully affect how truthful it appears. More substantial changes that alter meaning or context, such as edits to a photograph used in journalism, can. The guidelines treat this as a case-by-case judgment rather than a bright line.

The artistic, creative, satirical and fictional carve-out

Where a deepfake forms part of a work or programme that is artistic, creative, satirical, fictional or similar in nature, Article 50(4) is satisfied by a lighter disclosure: making known that the content exists in generated or manipulated form, in a way that doesn’t hamper the display or enjoyment of the work — a credit rather than an overlay stamped across the frame.

The word doing the real work in that sentence is one most summaries drop. The original text requires the work to be evidently artistic, creative, satirical or fictional — not arguably, not defensibly, but obviously so. That’s not loose paraphrasing: it’s the actual qualifier in the operative text, and the Commission’s draft guidelines lean on it directly, treating it as a threshold the content has to clear plainly rather than a label a deployer can assert after the fact.

That threshold has teeth, and the clearest illustration is political satire — the case that looks safest on paper. A deepfake of a real politician, shared on social media to mock a decision they made, looks like a textbook fit for the satirical carve-out. Commentary on the draft guidelines gives exactly this example and reaches the opposite conclusion: the exception doesn’t apply, because the same content also touches public discourse on a matter of public interest. Satire and public-interest commentary aren’t mutually exclusive categories under Article 50(4) — they can describe the same clip, and where they do, the more consequential reading controls, not the more convenient one.

The Code of Practice on Transparency of AI-Generated Content addresses this carve-out too, in the section covering deployer labelling of deepfakes and public-interest text. It’s a voluntary compliance tool, not a substitute for reading the exception correctly — signing it demonstrates a method, it doesn’t relax the “evidently” test underneath.

The text carve-out and its two cumulative conditions

Article 50(4)’s second limb catches AI-generated or manipulated text published to inform the public on matters of public interest. It doesn’t catch text that isn’t public-interest text in the first place — an AI-drafted product description or an internal memo was never in scope, carve-out or not.

For the text that is in scope, disclosure drops away entirely, but only where two conditions are both met: the content has undergone a process of human review or editorial control, and a natural or legal person holds editorial responsibility for publishing it. Both, not either. A generative system that drafts news summaries with nobody reviewing them, and nobody named as accountable for what goes out, gets neither condition and has to label every piece.

“Editorial control” is doing more work here than a quick skim suggests. The guidelines and the underlying text point toward an actual review process tied to an identifiable person or role who could be held to account for the publication — not a general policy that content is “monitored,” and not a single glance before hitting publish. A newsroom with a named editor who reviews AI-assisted copy before it runs has a real claim to both conditions. A platform that auto-publishes AI summaries with a disclaimer buried in the terms of service has neither.

Why “obvious” means something narrower here than in Article 50(1)

Article 50(1)’s chatbot-disclosure exception and Article 50(4)’s deepfake exception both turn on how a reasonable person would perceive the content — but they’re not the same reasonable person, and the draft guidelines are explicit about the gap.

Article 50(1) asks whether it would be obvious to a reasonably well-informed, observant and circumspect member of the system’s target audience that they’re dealing with AI. Article 50(4)’s deepfake assessment asks something broader: it has to account for the actual, potentially more varied audience the content is likely to reach, including foreseeable exposure to children, older people, or audiences with less digital or AI literacy than the primary audience the deployer had in mind. A deployer who tests disclosure against their core audience’s media literacy and stops there has answered the wrong question if the content is likely to circulate further than that audience — which most social content is.

The EU icon and the taxonomy nobody has finished building

The Code of Practice’s Section 2 covers Article 50(4) and 50(5) labelling specifically, distinct from the Section 1 marking obligations under Article 50(2). Alongside it, the Commission has floated a standardised visual label for AI-generated content — an “AI” mark, localised as “KI” in German or “IA” in French — together with a taxonomy that would distinguish “fully AI-generated” content from “AI-assisted” content and attach different disclosure requirements to each. Neither the icon nor the taxonomy is settled law; both are proposals moving alongside the Code rather than requirements written into Article 50 itself. Whether to sign the Code at all is a separate decision with its own trade-offs, worth working through on its own terms.

What’s left over

The law enforcement exception applies here as it does throughout Article 50: use authorised by law to detect, prevent, investigate or prosecute criminal offences falls outside the disclosure duty. Open-source licensing doesn’t help elsewhere — Article 2(12) exempts free and open-source AI systems from large parts of the Act, but the exemption specifically carves out Article 50, so a deepfake or text-generation system released under an open licence is fully subject to the labelling duties described here. And none of this shifted in the Digital Omnibus reshuffle: Article 50(4) applies from 2 August 2026 regardless of what happened to the high-risk timeline.

Frequently asked questions

Does a satirical deepfake of a real politician escape labelling?

Not reliably. If the content also bears on public discourse about that person’s decisions or conduct, it’s simultaneously public-interest content, and the guidelines’ worked example treats that overlap as defeating the satire carve-out rather than being resolved in the deployer’s favour. Political content aimed at a real, identifiable person is the case to assume you can’t rely on the exception, not the case to assume you can.

Does someone glancing at AI output before publishing count as editorial control?

That’s a thin claim to either condition. The stronger reading requires an actual review process and a person who holds editorial responsibility for the publication — not evidence that a human technically looked at the text. If you can’t name who is accountable for what goes out, you likely don’t meet the second condition regardless of the first.

Does an AI-written product description count as a matter of public interest?

No. The text limb of Article 50(4) only reaches content published to inform the public on matters of public interest — news, safety information, and similar categories. Commercial copy was never in scope, so the editorial-control carve-out is irrelevant to it; there was never a disclosure duty to carve out of.

Do you need both a visible label and machine-readable metadata?

Generally yes, and they’re not substitutes. Article 50(2) machine-readable marking is a provider duty attached to the output itself; Article 50(4) labelling is a deployer duty attached to how the content is published or presented to people. A provider marking its model’s output doesn’t relieve the deployer of disclosing a deepfake to its actual audience.

Who has the labelling duty — the agency that made the content or the client that published it?

Article 50(4) attaches to the deployer — whoever puts the content in front of the public — not necessarily whoever operated the generative tool. An agency producing a deepfake on a client’s behalf isn’t automatically who Article 50(4) is speaking to if the client is the one publishing it; that allocation is worth fixing in the contract rather than assuming.

Posted by admin in Data, Identity & Compliance UX Knowledge Base

Police can deploy high-risk AI before it’s authorised

Article 46(2) of the EU AI Act (Regulation (EU) 2024/1689) lets law enforcement or civil protection authorities put a specific high-risk AI system into service without prior authorisation, in a duly justified situation of urgency, for exceptional reasons of public security or a specific, substantial and imminent threat to the life or physical safety of natural persons — on condition that authorisation is then requested during or after use, without undue delay. If that authorisation is refused, use of the system stops with immediate effect, and all results and outputs of that use are immediately deleted. A statutory evidence-destruction clause sitting inside what is, on paper, a product-safety regulation — and almost nothing has been written about what it actually does.

Two different derogations, often confused

Article 46 contains two distinct mechanisms, and conflating them gets the sequencing wrong.

Article 46(1) is the general derogation. Any market surveillance authority — not limited to law enforcement — may authorise placing a specific high-risk system on the market or putting it into service, for exceptional reasons of public security, protection of life and health, environmental protection, or protection of essential industrial and infrastructure assets. The authorisation lasts for a limited period while the necessary conformity assessment is carried out, and that assessment has to be completed as quickly as possible. Authority acts first here too, but conditionally — it has to conclude compliance before authorising anything.

Article 46(2) is narrower and more dramatic. Only law enforcement authorities or civil protection authorities can use it, and only in genuine urgency — the deployment happens with no authorisation at all, and the paperwork follows during or after the fact. This is the deploy-now, ask-later route, and it’s the one carrying the discard consequence.

One scope point worth having on hand: neither derogation touches high-risk AI embedded in products covered by Annex I Section A legislation. Those systems use only whatever conformity-assessment derogations their own sectoral legislation provides — Article 46 doesn’t reach them at all.

The discard rule

If the Article 46(1) authorisation is refused after a paragraph 2 deployment, two things happen simultaneously: use stops immediately, and every result and output the system produced during that use is immediately deleted. Both are unconditional — there’s no grace period, no partial retention for review.

What the Act doesn’t say is where that leaves anything built on top of those outputs. If an officer already acted on a system’s flagged match, or an output already made its way into a case file, the text gives no answer for what happens to the decision or the file once the outputs behind it are gone. That’s a genuine, open gap rather than something this piece can resolve — and it’s worth knowing it’s open before you assume the Act has an answer.

The 15-day clock

The paragraph 1 authorisation is only granted if the market surveillance authority concludes the system actually complies with the Chapter III Section 2 requirements. Once granted — whether under paragraph 1 directly or via the paragraph 2 route — the authority notifies the Commission and other Member States, though that notification duty doesn’t extend to sensitive operational data tied to law enforcement activities specifically.

From there, a silent-consent structure runs on calendar days, not business days. If no Member State or the Commission raises an objection within 15 calendar days of receiving that notification, the authorisation is deemed justified — no further action needed. If a Member State does object to another Member State’s authorisation, or the Commission itself considers the authorisation contrary to EU law or the underlying compliance conclusion unfounded, the Commission consults with the Member State concerned without delay, and the operators involved are consulted and given a chance to present their views before the Commission decides. If the Commission ultimately finds the authorisation unjustified, the market surveillance authority that granted it has to withdraw it.

Who assesses police AI in the normal case

Outside of Article 46’s emergency mechanics, high-risk AI intended for use by law enforcement, immigration or asylum authorities, or EU institutions, doesn’t go through a notified body of the provider’s choosing at all — the market surveillance authority itself carries out the assessment. And when these systems are registered, the entry sits in the EU database’s secure, non-public section rather than the ordinary public one. Emergency deployment isn’t a shortcut around an otherwise-open marketplace of assessors; it’s a shortcut inside a system that was already centralised and restricted.

What this means if you sell to police forces

The commercial consequence is straightforward and worth putting in writing before it happens, not after. Your customer can lawfully deploy your system under genuine urgency, use it, and then be told — days or weeks later — to stop immediately and delete everything it produced. If your contract assumes deployment implies an ongoing, stable engagement, it doesn’t account for this. Build the discard scenario into your terms: what data reverts to you, what your customer owes you notice of, and what happens to your own copies of anything derived from that use.

Frequently asked questions

Does Article 46 override the Article 5 prohibitions?

No. Article 46 is a derogation from the conformity assessment procedure for high-risk systems — it has nothing to do with the absolute prohibitions in Article 5, which ban certain practices outright regardless of risk classification or urgency. A practice that’s prohibited under Article 5 doesn’t become available under emergency conditions; Article 46 only ever touches something that would otherwise be lawful but for the timing of its paperwork.

Who decides what counts as urgent?

The law enforcement or civil protection authority makes that call itself in the moment it deploys under paragraph 2 — that’s the point of the mechanism. The market surveillance authority’s role comes after, when it decides whether to grant the paragraph 1 authorisation the deployment is retroactively seeking.

Is there an appeal if authorisation is refused?

The text gives operators a consultation right specifically within the paragraph 5 process — where the Commission is reviewing a granted authorisation that another Member State or the Commission has challenged, operators are consulted and get to present their views before the Commission decides. It’s less clear there’s an equivalent route for challenging an initial refusal itself; nothing in the article spells one out.

Does the discard rule reach models trained on the deleted outputs?

The text doesn’t address this, and it would be overreaching to assume an answer either way. If a derived model or downstream system incorporated something built from the discarded outputs before deletion happened, the Article doesn’t say what that means for the derived material — treat it as unresolved rather than settled.

Does this apply to migration or asylum authorities?

Not under paragraph 2 specifically — that provision names only law enforcement authorities and civil protection authorities. Migration and asylum authorities aren’t included in the deploy-first mechanism, even though they’re treated alongside law enforcement for other purposes elsewhere in the Act, such as who conducts the conformity assessment in the ordinary case.

Posted by admin in Public Authority & Certified Provider Integrations Knowledge Base