The Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026. The European Commission’s Opinion of 8 July 2026 concluded it adequately covers Articles 50(2), (4) and (5) of the EU AI Act, and the AI Board adopted its own adequacy assessment the following day. And yet the Code’s own text, in the Objectives section of both its parts, states that adherence does not amount to conclusive proof of compliance. Signing is also severable — the provider-facing and deployer-facing halves can be signed independently, by different kinds of organisation, for different reasons. This is a real commercial decision with asymmetric costs on each side, not a box-ticking formality.
What the Code is and isn’t
The Code is voluntary. It doesn’t replace the Act, and it doesn’t replace the Commission’s separate guidelines on implementing Article 50 — a draft of those guidelines was published on 8 May 2026, a targeted consultation closed on 3 June 2026, and the final version is expected before 2 August 2026. The Code and the Guidelines do different jobs: the Guidelines interpret what the law requires; the Code offers one accepted way to meet it. It imposes no obligation beyond what the Act already imposes on providers and deployers within its scope.
Within the Code itself, every commitment is graded. Measures marked “will” are what a signatory commits to as binding; measures marked “encouraged” are recommended but not required; measures marked “may” are left entirely optional. That grading matters more than it looks — it’s the difference between something you’re accountable for and something you can quietly skip.
What signing buys you
The Commission’s own framing is direct: signatories get an EU-wide recognised way to demonstrate compliance, regardless of where they’re established or which national market surveillance authority has jurisdiction over them, and future enforcement effort will focus on monitoring adherence to the Code rather than re-litigating compliance from scratch. That’s a real reduction in administrative burden and a real increase in predictability.
Weigh that against the other half of the sentence. The Code does not guarantee compliance, and — as commentary on the equivalent regime for general-purpose AI models under Article 56 has already established for that adjacent Code — alternative routes to compliance may exist alongside it. Signing narrows your risk. It doesn’t eliminate the need to actually do the thing the Code describes.
The two sections, and why you might sign only one
Section 1 covers providers under Article 50(2). Because no single marking technique is currently considered reliable enough on its own, the Code generally expects a multi-layered approach: digitally-signed, tamper-evident metadata recording that content is AI-generated or manipulated, combined with imperceptible watermarking embedded in the content itself. Fingerprinting or logging sits alongside these as an optional third layer. Providers also commit to offering a detection mechanism — typically free of charge, though the Code allows smaller signatories to charge where detection carries substantial operational cost — while forensic detection of content that’s been stripped of its marking stays optional, on the Code’s own acknowledgment that the technology isn’t mature enough yet to meet the Act’s reliability bar. A staged interoperability requirement follows, with a working solution for watermark detection due by 2 February 2027.
Section 2 covers deployers under Article 50(4) and (5): labelling deepfakes, and labelling AI-generated or manipulated text published to inform the public on matters of public interest that hasn’t been through human review. Notably, the Code doesn’t leave the visual form of that label to the deployer’s judgment — it obliges use of the Commission’s own EU AI icon, or an equivalent, wherever visual disclosure is possible, with an audible disclaimer as the fallback where it isn’t.
The split explains why an organisation might reasonably sign only one half. A model or system provider with no deployment role of its own has nothing to gain from Section 2’s labelling commitments. A retail business running marketing campaigns through a third-party generative tool is a deployer with no marking infrastructure to build — Section 1 isn’t its problem, Section 2 is. Only a company that both builds and ships generative features to end users has a reason to sign both.
The alternative route, and its price
Nothing about the Code forecloses building your own approach instead. The Code’s own drafting on this point directs signatories testing marking and detection solutions to weigh them against current state-of-the-art benchmarks and testing methods generally, expressly including any that the AI Office develops or recognises together with the AI Board — phrasing that concedes those AI Office-recognised benchmarks are still a work in progress rather than a finished reference you can simply cite.
That’s the real price of the alternative route. Until the AI Office publishes its own benchmarks, an organisation going it alone is testing against internal benchmarks and general industry practice, and carrying the burden of proving that’s good enough — optionally strengthened with independent red-teaming or a run through an Article 57 regulatory sandbox. A signatory can point to the Code. A non-signatory has to build and defend an equivalent case from scratch, to a market surveillance authority that hasn’t pre-approved the yardstick.
Who else is signing
The Code is open well beyond the organisations Article 50 actually binds. Technology providers of marking and detection solutions — companies with no generative AI system of their own — can sign Section 1 to demonstrate their tools meet the Code’s technical bar. That matters commercially: a generative AI provider choosing a third-party watermarking vendor has a direct reason to prefer one that has already signed, since the Code lets a signatory rely on a third party’s solution only where that third party has itself adhered to the Code and demonstrated compliance with it.
A subtler case is generative AI model providers, as distinct from the system providers Article 50 actually addresses — the Act’s transparency duties are pinned to systems, not to the underlying models that power them. The Code’s first draft tried to impose hard obligations on model providers directly; the final version backed away from that and merely encourages them to implement marking and detection at the model level, so that system providers built on top of their models can comply more easily downstream. It’s a voluntary, upstream courtesy, not a binding duty — and the softening between drafts is itself a signal of how contested that question was.
The decision
Three questions do most of the work. Do you ship generative output — audio, image, video or text — into the EU market at all, as a provider or a deployer? If not, none of this applies yet. If you do, can you evidence your marking or detection performance independently, against a benchmark a regulator would accept, without the Code’s cover? If that’s expensive or uncertain, signing is the cheaper insurance. And do you sell to enterprise customers who are starting to ask suppliers whether they’re Code signatories as part of their own due diligence? If procurement teams are already asking, being on the list answers the question before it’s asked.
Frequently asked questions
Is the signatory list public?
Not yet, as of this writing. The deadline to be included in the first published list is 22 July 2026 at 18:00 CEST, and the Commission has said that list will be published before the Article 50 obligations take effect on 2 August 2026.
Can we join later?
Yes. Signing remains open after 22 July 2026 — organisations that miss that date simply submit the signature form afterward and aren’t on the first published list, without losing the ability to sign at all.
Does signing bind our downstream customers?
No. Each organisation in a generative AI supply chain has its own role and its own Article 50 obligations. Signing signals your own adherence and, where relevant, supports customers building on top of you — the Code specifically encourages provider-level tooling that helps deployers meet their own duties — but it doesn’t extend your signature to bind anyone downstream.
Does the Code cover Article 50(1)?
No. The Code addresses Articles 50(2), (4) and (5) — marking, deepfake and public-interest text labelling, and the form those disclosures take. Article 50(1), the general AI-interaction disclosure duty, and Article 50(3), the emotion-recognition and biometric-categorisation notice, sit outside the Code entirely and are addressed only by the Commission’s separate Article 50 guidelines.
What happens if you sign and then fail to implement?
The Code frames signing as signalling intent to adhere to its commitments, not as a one-time filing that stands in for the work. An organisation that signs but doesn’t actually implement the marking, labelling or detection measures it committed to isn’t shielded by having signed — it has simply made a compliance claim that doesn’t match its practice, which is a weaker position than never having claimed Code adherence in the first place.
