Marking is an engineering problem
Telling a user they are talking to a chatbot is a string. Making every generated output detectable in a format that survives the internet is a provenance pipeline, and the deadline for it is December.
Article 50 requires synthetic audio, image, video and text to be marked in a machine-readable format and detectable as generated. Systems already on the market have until 2 December for the marking requirement specifically.
The staggered deadline is an admission
Everything else in Article 50 applied immediately. Marking got four extra months, which is the regulator conceding that retrofitting provenance into a shipped product is a different order of work from adding a disclosure banner.
It is a realistic concession and it has a consequence worth stating: most synthetic media in circulation right now carries no machine-readable mark, and will not until well into next year. Detection tooling deployed before then is looking for something largely absent.
Audio is the underdeveloped case
Watermarking discussion has overwhelmingly concerned images, where the techniques are mature and the attacks catalogued. Audio has different physics — resampling, compression and re-recording degrade a signal differently from how cropping degrades pixels — and the literature is far thinner.
Models generating synchronised audio and video jointly raise a question with no settled answer: one mark or two. Mark separately and an attacker strips one channel. Mark jointly and the mark must survive two processing pipelines that are rarely applied together.
The compliance path is voluntary in name only
A code of practice endorsed by the enforcing authority is where compliance is presumed. Departing from it means arguing your alternative is equivalent, to the body that wrote the one you declined. That is a familiar pattern and generally a good one — it gives industry a specification instead of a legal standard.
The gap is detection. A code can specify what providers embed and does nothing about who checks. Marking without deployed detectors is a compliance artefact rather than a public protection, and nothing currently in force addresses the second half.
EU Artificial Intelligence Act — The EU AI Act's transparency rules: a practical guide to Article 50 → · European Commission — Code of Practice on Transparency of AI-generated Content → · Pearl Cohen — New guidance under the EU AI Act ahead of its next enforcement date →