Transparency Code of Practice

Should you sign the AI transparency Code of Practice?

The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026. The European Commission’s Opinion of 8 July 2026 concluded it adequately covers Articles 50(2), (4) and (5) of the EU AI Act, and the AI Board adopted its own adequacy assessment the following day. And yet the Code’s own text, in the Objectives section of both its parts, states that adherence does not amount to conclusive proof of compliance. Signing is also severable — the provider-facing and deployer-facing halves can be signed independently, by different kinds of organisation, for different reasons. This is a real commercial decision with asymmetric costs on each side, not a box-ticking formality.

What the Code is and isn’t

The Code is voluntary. It doesn’t replace the Act, and it doesn’t replace the Commission’s separate guidelines on implementing Article 50 — a draft of those guidelines was published on 8 May 2026, a targeted consultation closed on 3 June 2026, and the final version is expected before 2 August 2026. The Code and the Guidelines do different jobs: the Guidelines interpret what the law requires; the Code offers one accepted way to meet it. It imposes no obligation beyond what the Act already imposes on providers and deployers within its scope.

Within the Code itself, every commitment is graded. Measures marked “will” are what a signatory commits to as binding; measures marked “encouraged” are recommended but not required; measures marked “may” are left entirely optional. That grading matters more than it looks — it’s the difference between something you’re accountable for and something you can quietly skip.

What signing buys you

The Commission’s own framing is direct: signatories get an EU-wide recognised way to demonstrate compliance, regardless of where they’re established or which national market surveillance authority has jurisdiction over them, and future enforcement effort will focus on monitoring adherence to the Code rather than re-litigating compliance from scratch. That’s a real reduction in administrative burden and a real increase in predictability.

Weigh that against the other half of the sentence. The Code does not guarantee compliance, and — as commentary on the equivalent regime for general-purpose AI models under Article 56 has already established for that adjacent Code — alternative routes to compliance may exist alongside it. Signing narrows your risk. It doesn’t eliminate the need to actually do the thing the Code describes.

The two sections, and why you might sign only one

Section 1 covers providers under Article 50(2). Because no single marking technique is currently considered reliable enough on its own, the Code generally expects a multi-layered approach: digitally-signed, tamper-evident metadata recording that content is AI-generated or manipulated, combined with imperceptible watermarking embedded in the content itself. Fingerprinting or logging sits alongside these as an optional third layer. Providers also commit to offering a detection mechanism — typically free of charge, though the Code allows smaller signatories to charge where detection carries substantial operational cost — while forensic detection of content that’s been stripped of its marking stays optional, on the Code’s own acknowledgment that the technology isn’t mature enough yet to meet the Act’s reliability bar. A staged interoperability requirement follows, with a working solution for watermark detection due by 2 February 2027.

Section 2 covers deployers under Article 50(4) and (5): labelling deepfakes, and labelling AI-generated or manipulated text published to inform the public on matters of public interest that hasn’t been through human review. Notably, the Code doesn’t leave the visual form of that label to the deployer’s judgment — it obliges use of the Commission’s own EU AI icon, or an equivalent, wherever visual disclosure is possible, with an audible disclaimer as the fallback where it isn’t.

The split explains why an organisation might reasonably sign only one half. A model or system provider with no deployment role of its own has nothing to gain from Section 2’s labelling commitments. A retail business running marketing campaigns through a third-party generative tool is a deployer with no marking infrastructure to build — Section 1 isn’t its problem, Section 2 is. Only a company that both builds and ships generative features to end users has a reason to sign both.

The alternative route, and its price

Nothing about the Code forecloses building your own approach instead. The Code’s own drafting on this point directs signatories testing marking and detection solutions to weigh them against current state-of-the-art benchmarks and testing methods generally, expressly including any that the AI Office develops or recognises together with the AI Board — phrasing that concedes those AI Office-recognised benchmarks are still a work in progress rather than a finished reference you can simply cite.

That’s the real price of the alternative route. Until the AI Office publishes its own benchmarks, an organisation going it alone is testing against internal benchmarks and general industry practice, and carrying the burden of proving that’s good enough — optionally strengthened with independent red-teaming or a run through an Article 57 regulatory sandbox. A signatory can point to the Code. A non-signatory has to build and defend an equivalent case from scratch, to a market surveillance authority that hasn’t pre-approved the yardstick.

Who else is signing

The Code is open well beyond the organisations Article 50 actually binds. Technology providers of marking and detection solutions — companies with no generative AI system of their own — can sign Section 1 to demonstrate their tools meet the Code’s technical bar. That matters commercially: a generative AI provider choosing a third-party watermarking vendor has a direct reason to prefer one that has already signed, since the Code lets a signatory rely on a third party’s solution only where that third party has itself adhered to the Code and demonstrated compliance with it.

A subtler case is generative AI model providers, as distinct from the system providers Article 50 actually addresses — the Act’s transparency duties are pinned to systems, not to the underlying models that power them. The Code’s first draft tried to impose hard obligations on model providers directly; the final version backed away from that and merely encourages them to implement marking and detection at the model level, so that system providers built on top of their models can comply more easily downstream. It’s a voluntary, upstream courtesy, not a binding duty — and the softening between drafts is itself a signal of how contested that question was.

The decision

Three questions do most of the work. Do you ship generative output — audio, image, video or text — into the EU market at all, as a provider or a deployer? If not, none of this applies yet. If you do, can you evidence your marking or detection performance independently, against a benchmark a regulator would accept, without the Code’s cover? If that’s expensive or uncertain, signing is the cheaper insurance. And do you sell to enterprise customers who are starting to ask suppliers whether they’re Code signatories as part of their own due diligence? If procurement teams are already asking, being on the list answers the question before it’s asked.

Frequently asked questions

Is the signatory list public?

Not yet, as of this writing. The deadline to be included in the first published list is 22 July 2026 at 18:00 CEST, and the Commission has said that list will be published before the Article 50 obligations take effect on 2 August 2026.

Can we join later?

Yes. Signing remains open after 22 July 2026 — organisations that miss that date simply submit the signature form afterward and aren’t on the first published list, without losing the ability to sign at all.

Does signing bind our downstream customers?

No. Each organisation in a generative AI supply chain has its own role and its own Article 50 obligations. Signing signals your own adherence and, where relevant, supports customers building on top of you — the Code specifically encourages provider-level tooling that helps deployers meet their own duties — but it doesn’t extend your signature to bind anyone downstream.

Does the Code cover Article 50(1)?

No. The Code addresses Articles 50(2), (4) and (5) — marking, deepfake and public-interest text labelling, and the form those disclosures take. Article 50(1), the general AI-interaction disclosure duty, and Article 50(3), the emotion-recognition and biometric-categorisation notice, sit outside the Code entirely and are addressed only by the Commission’s separate Article 50 guidelines.

What happens if you sign and then fail to implement?

The Code frames signing as signalling intent to adhere to its commitments, not as a one-time filing that stands in for the work. An organisation that signs but doesn’t actually implement the marking, labelling or detection measures it committed to isn’t shielded by having signed — it has simply made a compliance claim that doesn’t match its practice, which is a weaker position than never having claimed Code adherence in the first place.

Posted by admin in What happened with...

AI Act deepfake labelling: artistic and editorial carve-outs

Article 50(4) of the EU AI Act (Regulation (EU) 2024/1689) requires deployers to disclose when image, audio or video content is a deepfake, and when text has been artificially generated or manipulated for publication on matters of public interest. Two carve-outs sit inside that duty — a lighter disclosure for content that is “evidently” artistic, creative, satirical or fictional, and no disclosure at all for text that passed through genuine editorial control. Both sound generous on a first read. Neither is as wide as it looks, and the European Commission’s draft guidelines, published 8 May 2026, spend more time narrowing them than most summaries let on.

Which content counts as a deepfake under Article 50(4)?

The duty sits with the deployer, not the provider — whoever publishes or puts the content in front of people, not whoever generated it. It applies to AI-generated or manipulated image, audio or video content that constitutes a deepfake under Article 3(60): content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic or truthful.

The Commission’s draft guidelines read that definition wider than most people assume. Three clarifications matter:

  • Intent is irrelevant. Whether the content falsely appears authentic doesn’t depend on whether the deployer meant to deceive anyone. An absence of fraudulent intent doesn’t defeat the labelling duty.
  • “Existing” is read broadly. A realistic synthetic depiction of a fictitious but natural-looking person can still be a deepfake, even where no identifiable real person is implicated — it’s enough that the subject resembles someone or something that could exist, or could once have existed.
  • Not every edit counts. Routine adjustments — lighting, colour correction, noise reduction, sound cleanup — normally don’t turn content into a deepfake, because they don’t meaningfully affect how truthful it appears. More substantial changes that alter meaning or context, such as edits to a photograph used in journalism, can. The guidelines treat this as a case-by-case judgment rather than a bright line.

The artistic, creative, satirical and fictional carve-out

Where a deepfake forms part of a work or programme that is artistic, creative, satirical, fictional or similar in nature, Article 50(4) is satisfied by a lighter disclosure: making known that the content exists in generated or manipulated form, in a way that doesn’t hamper the display or enjoyment of the work — a credit rather than an overlay stamped across the frame.

The word doing the real work in that sentence is one most summaries drop. The original text requires the work to be evidently artistic, creative, satirical or fictional — not arguably, not defensibly, but obviously so. That’s not loose paraphrasing: it’s the actual qualifier in the operative text, and the Commission’s draft guidelines lean on it directly, treating it as a threshold the content has to clear plainly rather than a label a deployer can assert after the fact.

That threshold has teeth, and the clearest illustration is political satire — the case that looks safest on paper. A deepfake of a real politician, shared on social media to mock a decision they made, looks like a textbook fit for the satirical carve-out. Commentary on the draft guidelines gives exactly this example and reaches the opposite conclusion: the exception doesn’t apply, because the same content also touches public discourse on a matter of public interest. Satire and public-interest commentary aren’t mutually exclusive categories under Article 50(4) — they can describe the same clip, and where they do, the more consequential reading controls, not the more convenient one.

The Code of Practice on Transparency of AI-Generated Content addresses this carve-out too, in the section covering deployer labelling of deepfakes and public-interest text. It’s a voluntary compliance tool, not a substitute for reading the exception correctly — signing it demonstrates a method, it doesn’t relax the “evidently” test underneath.

The text carve-out and its two cumulative conditions

Article 50(4)’s second limb catches AI-generated or manipulated text published to inform the public on matters of public interest. It doesn’t catch text that isn’t public-interest text in the first place — an AI-drafted product description or an internal memo was never in scope, carve-out or not.

For the text that is in scope, disclosure drops away entirely, but only where two conditions are both met: the content has undergone a process of human review or editorial control, and a natural or legal person holds editorial responsibility for publishing it. Both, not either. A generative system that drafts news summaries with nobody reviewing them, and nobody named as accountable for what goes out, gets neither condition and has to label every piece.

“Editorial control” is doing more work here than a quick skim suggests. The guidelines and the underlying text point toward an actual review process tied to an identifiable person or role who could be held to account for the publication — not a general policy that content is “monitored,” and not a single glance before hitting publish. A newsroom with a named editor who reviews AI-assisted copy before it runs has a real claim to both conditions. A platform that auto-publishes AI summaries with a disclaimer buried in the terms of service has neither.

Why “obvious” means something narrower here than in Article 50(1)

Article 50(1)’s chatbot-disclosure exception and Article 50(4)’s deepfake exception both turn on how a reasonable person would perceive the content — but they’re not the same reasonable person, and the draft guidelines are explicit about the gap.

Article 50(1) asks whether it would be obvious to a reasonably well-informed, observant and circumspect member of the system’s target audience that they’re dealing with AI. Article 50(4)’s deepfake assessment asks something broader: it has to account for the actual, potentially more varied audience the content is likely to reach, including foreseeable exposure to children, older people, or audiences with less digital or AI literacy than the primary audience the deployer had in mind. A deployer who tests disclosure against their core audience’s media literacy and stops there has answered the wrong question if the content is likely to circulate further than that audience — which most social content is.

The EU icon and the taxonomy nobody has finished building

The Code of Practice’s Section 2 covers Article 50(4) and 50(5) labelling specifically, distinct from the Section 1 marking obligations under Article 50(2). Alongside it, the Commission has floated a standardised visual label for AI-generated content — an “AI” mark, localised as “KI” in German or “IA” in French — together with a taxonomy that would distinguish “fully AI-generated” content from “AI-assisted” content and attach different disclosure requirements to each. Neither the icon nor the taxonomy is settled law; both are proposals moving alongside the Code rather than requirements written into Article 50 itself. Whether to sign the Code at all is a separate decision with its own trade-offs, worth working through on its own terms.

What’s left over

The law enforcement exception applies here as it does throughout Article 50: use authorised by law to detect, prevent, investigate or prosecute criminal offences falls outside the disclosure duty. Open-source licensing doesn’t help elsewhere — Article 2(12) exempts free and open-source AI systems from large parts of the Act, but the exemption specifically carves out Article 50, so a deepfake or text-generation system released under an open licence is fully subject to the labelling duties described here. And none of this shifted in the Digital Omnibus reshuffle: Article 50(4) applies from 2 August 2026 regardless of what happened to the high-risk timeline.

Frequently asked questions

Does a satirical deepfake of a real politician escape labelling?

Not reliably. If the content also bears on public discourse about that person’s decisions or conduct, it’s simultaneously public-interest content, and the guidelines’ worked example treats that overlap as defeating the satire carve-out rather than being resolved in the deployer’s favour. Political content aimed at a real, identifiable person is the case to assume you can’t rely on the exception, not the case to assume you can.

Does someone glancing at AI output before publishing count as editorial control?

That’s a thin claim to either condition. The stronger reading requires an actual review process and a person who holds editorial responsibility for the publication — not evidence that a human technically looked at the text. If you can’t name who is accountable for what goes out, you likely don’t meet the second condition regardless of the first.

Does an AI-written product description count as a matter of public interest?

No. The text limb of Article 50(4) only reaches content published to inform the public on matters of public interest — news, safety information, and similar categories. Commercial copy was never in scope, so the editorial-control carve-out is irrelevant to it; there was never a disclosure duty to carve out of.

Do you need both a visible label and machine-readable metadata?

Generally yes, and they’re not substitutes. Article 50(2) machine-readable marking is a provider duty attached to the output itself; Article 50(4) labelling is a deployer duty attached to how the content is published or presented to people. A provider marking its model’s output doesn’t relieve the deployer of disclosing a deepfake to its actual audience.

Who has the labelling duty — the agency that made the content or the client that published it?

Article 50(4) attaches to the deployer — whoever puts the content in front of the public — not necessarily whoever operated the generative tool. An agency producing a deepfake on a client’s behalf isn’t automatically who Article 50(4) is speaking to if the client is the one publishing it; that allocation is worth fixing in the contract rather than assuming.

Posted by admin in Data, Identity & Compliance UX Knowledge Base

When you don’t have to label your chatbot as AI

AI Act chatbot disclosure: when you don’t need a label

Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) requires providers to design AI systems that interact directly with people so those people are told they are dealing with an AI — “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use.”

That phrase is not new drafting. It is the average consumer benchmark from EU consumer law, almost word for word, and it has been litigated at the Court of Justice since 1998. Which means the question “do we need a disclosure banner?” has an answer with thirty years of case law behind it — and it is not the answer the compliance-banner vendors are selling.

What Article 50(1) actually requires

Providers — not deployers — must ensure that AI systems intended to interact directly with natural persons are “designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system.” It is a design obligation, discharged at build time, and it sits with whoever puts the system on the market under their own name.

In practice the deployer inherits it. If you buy a chatbot and drop it on your checkout page, the provider owes the design duty, but you are the one whose customers see the result — and the exception turns on your circumstances and context of use, which the provider never saw. That gap is the reason contract terms on this matter more than most people assume.

The exposure is not theoretical: Article 99(4)(g) places breaches of Article 50 in the tier of up to €15,000,000, or 3% of total worldwide annual turnover for the preceding financial year if the offender is an undertaking, whichever is higher. Article 50 applies from 2 August 2026 and the Digital Omnibus did not defer it.

Systems in scope

White & Case’s EU AI Act Handbook reads the category as covering chatbots, voice assistants and robo-services — anything intended to interact directly with individuals. It explicitly does not include AI systems designed to interact exclusively with other AI systems or other non-human systems.

That exclusion is narrower than it sounds. An agent that calls your supplier’s API all day is out. An agent that calls your supplier’s switchboard and talks to a person is in, because the person on the other end is a natural person interacting directly with an AI system. The test is who is on the other end, not what your architecture diagram says.

The three exceptions, in order of usefulness

Article 50(1) can be switched off three ways. Only one of them is a live question for most businesses.

  • The “obvious” exception. No disclosure where it would be obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use. This is the one you will actually argue about.
  • Law enforcement. The obligation does not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties — unless the system is available for the public to report a criminal offence. White & Case gives the worked example: a chatbot on a law enforcement authority’s website. Public-facing crime-reporting bots get no exemption.
  • Out of scope entirely under Article 2. Chiefly individuals using AI systems in the course of a purely personal, non-professional activity. This is not an exception you can invoke as a business.

How far does “obvious” go?

The standard is contextual, not absolute — the Act says so, twice, with “taking into account the circumstances and the context of use.” So there is no such thing as a system that is obviously AI. There are only surfaces on which it is or isn’t obvious, and the same model can be on both sides of the line in the same company.

The reference person is where the argument gets decided, and the Act imported that person rather than inventing them. In Gut Springenheide (Case C-210/96), decided on 16 July 1998, the Court of Justice held that a national court assessing whether a description is misleading must take into account the presumed expectations of “an average consumer who is reasonably well-informed and reasonably observant and circumspect.” That formula became Recital 18 of the Unfair Commercial Practices Directive (2005/29/EC) and the default benchmark across EU consumer law. Article 50(1) reproduces it with one word dropped.

Three things follow, and none of them help a provider hoping for a bright line.

Nobody has defined it, deliberately. When the UCPD was negotiated, the definition of the average consumer was removed from the operative text — the European Parliament’s legislative record explains that a fixed definition was dropped precisely so the concept could keep evolving with the Court’s jurisprudence. The AI Act repeats the pattern: the formula appears in Article 50(1) and again in Recital 132, and is defined in neither. If you were waiting for the legislature to tell you what obvious means, it has told you it isn’t going to.

The reference person is not a rational maximiser. The Court has kept moving. In Compass Banca (Case C-646/22) it accepted that the average consumer’s assessment can be affected by cognitive bias — the benchmark is a notional typical consumer, not a perfectly rational market actor. A provider arguing “anyone would have realised” is arguing against a standard that has been explicitly loosened away from that assumption.

The reference person shifts when your audience does. Recital 132 says that in applying the obligation, account must be taken of the characteristics of people belonging to vulnerable groups due to their age or disability, insofar as the AI system is intended to interact with those groups too. This mirrors the UCPD, which makes specific provision for vulnerable consumers. Build a homework helper for teenagers and the person deciding what’s obvious is a teenager.

Apply that to two real surfaces. A support widget on your own site, opened by a user who clicked a button labelled “Chat”, staffed by a bot called AI Assistant, answering instantly at 3am: a decent argument that disclosure adds nothing a reasonably observant person doesn’t already have. An outbound call to a customer’s mobile in a synthetic voice: not obvious, ever. The recipient did not choose the channel, has no context, has one second of audio to work from, and the entire history of the average consumer test runs through cases about people being misled in exactly that posture.

White & Case’s own advice is to treat the exemption with caution, on the reasoning that a court or regulator may read the level of information a reasonably well-informed user is deemed to have more narrowly than a provider would like. One more reason for caution is on the calendar. The Commission is obliged under Article 96(1)(d) to develop guidelines on the practical implementation of Article 50, and its published FAQ confirms those guidelines will address AI interaction specifically, that a public consultation on the draft has closed, and that the final version will be published before the obligations start to apply. The guidelines can narrow the exception. They cannot widen it beyond the text.

What the Code of Practice does not cover

Worth knowing before you go looking: the Code of Practice on Transparency of AI-Generated Content is no help on this question. Article 50(7) directs the AI Office to facilitate codes of practice on the detection and labelling of artificially generated content — that is Article 50(2) and (4). When the Commission issued its opinion on 8 July 2026, it concluded the Code adequately covers Articles 50(2), (4) and (5). Article 50(1) is not on that list. There is no code to sign that demonstrates your chatbot disclosure is adequate.

Form and timing you can’t negotiate away

If the exception doesn’t apply, Article 50(5) governs how you tell people, and it is short enough to quote in full: the information “shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The information shall conform to the applicable accessibility requirements.”

Four consequences:

  • Clear and distinguishable. Distinguishable from what surrounds it. A line in the terms of service is not distinguishable; a greyed-out footer under the input box is a bad bet.
  • At the latest at first interaction. White & Case reads this as akin to the point-in-time notice requirements under the GDPR — the notice attaches to the moment, not to a document you have somewhere. You cannot disclose on turn three.
  • Accessibility requirements. Recital 132 adds that the information must be provided in a format accessible to persons with disabilities. A purely visual badge on a voice product fails this on its face.
  • Vulnerable users. This one is Recital 132, not Article 50(5) — worth knowing, because summaries routinely present it as an operative requirement. It shapes how the obligation and the exception are applied rather than adding a fifth element to the form rules.

Why the obligations stack

Article 50(6) says paragraphs 1 to 4 “shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.” Chapter III is the high-risk regime. So clearing Article 50(1) tells you nothing about Articles 13 and 26, and nothing about the GDPR notice you already owed.

The general-purpose AI overlap is real but comes from elsewhere — Article 50(2) applies to providers “of AI systems, including general-purpose AI systems”, and Chapter V imposes its own model-level duties. White & Case reads the whole set as applying cumulatively. A conversational assistant built on a general-purpose model, deployed in a high-risk context, can owe disclosure under 50(1), marking under 50(2), instructions for use under Article 13 and model documentation under Chapter V, all at once. They are not alternatives and satisfying one is not a defence to another.

Frequently asked questions

Does a bot name count as disclosure?

Calling it “AI Assistant” is evidence that the fact was obvious, not compliance with the disclosure duty. The two are different arguments: one says the exception applies so no notice was owed, the other says notice was given clearly and distinguishably at first interaction. If you are relying on the name, you are relying on the exception — write down why, in context, before a regulator asks.

Does the exception apply to voice?

Not to outbound voice, realistically. The recipient did not initiate the interaction, has no visual context and no prior expectation, and synthetic speech is now good enough that “reasonably observant” does not get you there. Inbound voice on a line the caller dialled knowing it is automated is a different and better argument.

Who is liable, the provider or the deployer?

Article 50(1) puts the design duty on the provider. But the exception depends on the circumstances and context of use, which the deployer controls — so a provider who ships without disclosure on the assumption that deployment will be obvious has made a bet on someone else’s product decisions. Allocate it in the contract: who decides whether the exception is relied on, and who evidences it.

What about an AI agent that calls a customer?

In scope of Article 50(1), and the exception almost certainly does not apply. See outbound voice above. This is the single clearest case in the whole provision.

Does this apply to internal-only tools?

Yes, if the tool interacts directly with natural persons — the Act does not distinguish between customers and employees here. The Article 2 carve-out covers individuals using AI in a purely personal, non-professional activity, which is the opposite of an internal work tool. Whether disclosure is obvious to a trained employee using a named internal assistant is a much easier argument than the customer-facing case, but it is still the argument you have to make.

Posted by admin in Data, Identity & Compliance UX Knowledge Base