techpolicy.press web signal

EU AI Act transparency rules go live with major gaps

TL;DR

  • The EU AI Act's Article 50 transparency obligations for AI-generated media entered into effect on August 2, 2026, alongside a new Code of Practice.
  • Provenance information under Section 1, Measure 1.3 is only 'encouraged' rather than mandatory, leaving a binary AI-generated marking as the baseline requirement.
  • Open-weight releases, weak text watermarking, and a personal-use exemption for viral deepfakes push much of the enforcement burden onto downstream platforms.

The EU AI Act's transparency obligations for synthetic content went live on August 2, 2026, and the first serious read of the accompanying Code of Practice is already less than flattering. Writing in Tech Policy Press, Bruna Santos and Jacobo Castellanos of the human rights group WITNESS argue that the code operationalising Article 50 settles for the thinnest possible version of transparency: a binary 'this was AI-generated' marking, with the harder work left optional.

The specific complaint is precise. Provenance information, the richer metadata trail that lets a downstream viewer see where a piece of media came from and how it was modified, sits in Section 1, Measure 1.3 of the code, and the authors note it is 'designated optional and encouraged while a binary AI generated marking is all that the code requires.' That is a meaningful gap if you were expecting the AI Act to hard-wire something like the C2PA content-credentials approach into European law. It didn't. It gestured at it.

The other two soft spots are structural. Open-weight models, once released, cannot really be made to comply, because 'compliance with regulation cannot be enforced once weights are released and models are fine-tuned or stripped of provenance signals downstream.' And enforcement ultimately leans on detection tools that WITNESS's own TRIED benchmark shows are uneven across languages and faces, with universal, provider-agnostic watermarking for text not yet a solved problem. Put those together and the labeling promise depends on infrastructure that is either voluntary, strippable, or unreliable.

The most operationally consequential carve-out is the personal-use exemption, which the authors say 'lifts the labeling duty from exactly the viral, privately created deepfakes that cause so much harm, pushing the burden downstream onto platforms.' Model providers get the compliance win; platforms get the moderation bill.

The honest caveat is that this is a WITNESS advocacy read, not a neutral audit, and the piece doesn't set out the European Commission's enforcement priorities, penalty scale, or any timeline for tightening Measure 1.3 from encouraged to mandatory. What it does do is name the seam in the regime early, which is useful. As the authors put it, 'a label is not the same as protection, and it should not be mistaken for one.' For anyone shipping generative products into the EU, the forward-looking read is that the Code of Practice is a floor to clear on day one, and the ceiling, provenance done properly, is where the next round of pressure is going to land.

Shared on Bluesky by 2 AI experts