Catena metallica i cui anelli si fanno progressivamente incompiuti, con un'etichetta appesa a un anello che non esiste ancora

Immagine creata con IAAI-generated image

Labelling today what will be marked in December: AI content transparency after 2 August

Since 2 August 2026 the transparency obligations in Article 50 of the AI Act have been enforceable. Two days earlier, on 31 July, the European Commission published the list of signatories to the Code of Practice on Transparency of AI-generated Content: about one hundred and ninety organisations, of which eighty-three signed the section addressed to providers and one hundred and fifty-two the section addressed to deployers. The two figures are not equivalent, and the gap between them says something about how the transparency chain will hold up over the coming months.

What became enforceable

Article 50 of Regulation (EU) 2024/1689 spreads the obligations along the value chain. Paragraph 1 requires providers of systems intended to interact directly with natural persons to design them so that the person knows they are dealing with a machine, unless this is obvious from the circumstances. Paragraph 2 requires providers of systems generating synthetic audio, image, video or text content, including general purpose AI systems, to ensure that the outputs are marked in a machine readable format and detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, robust and reliable as far as this is technically feasible. Paragraph 3 requires deployers of emotion recognition or biometric categorisation systems to inform the persons exposed to them. Paragraph 4 requires deployers to disclose that a deep fake has been artificially generated or manipulated, and to do the same for generated or manipulated text published in order to inform the public on matters of public interest, unless the text has undergone human review and is subject to editorial responsibility.

These obligations carry penalties. Article 99(4)(g) places their infringement in the band of up to EUR 15 000 000 or, where the offender is an undertaking, up to 3 per cent of its total worldwide annual turnover for the preceding financial year, whichever is higher; for SMEs, including start-ups, paragraph 6 caps the fine at the lower of the two. The chapter on penalties has applied since 2 August 2025: what was missing, until a few days ago, was the conduct to be penalised.

One hundred and ninety signatures, and how they are distributed

The code of practice was drawn up by independent experts in a process facilitated by the AI Office and is divided into two sections: the first concerns providers, the marking and detection of content; the second concerns deployers and the labelling of deep fakes and generated text. By the end of July about one hundred and ninety organisations across sectors had signed, from IT and telecoms to education and retail. Among the signatories to the first section the Commission lists Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; among those to the second, Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo and Lufthansa. About half of the signatories, the Commission notes, are small and recently established companies.

The detail worth reading closely is a different one. The first section has eighty-three signatories and the second one hundred and fifty-two, and the first may also be signed by parties who bear no obligation at all: the Commission itself points out that, although the legal obligation applies only to providers of AI systems, Section 1 is also open to providers of marking and detection solutions and to providers of AI models who can help providers of generative systems implement the mandatory measures. Eighty-three signatures, therefore, are not eighty-three obliged providers. The end of the chain on which everything else rests, upstream marking, is the less represented one.

The list remains open and is updated as new adherences arrive. Signatories will be invited to take part in two task forces which the AI Office intends to launch in September 2026, dedicated to sharing practices, providing feedback on the implementation of the transparency measures and advancing the state of the art.

No presumption of conformity, and now the legislature says so

That adherence to the code is not conclusive evidence of compliance had already been stated in the opinion by which the Commission assessed its adequacy. For a few days now the same statement has had a firmer source. Recital 41 of Regulation (EU) 2026/1744, the Digital Omnibus on AI which entered into force on 27 July, states that the codes of practice referred to in Article 50(7) and Article 56(6) have limited legal effect and, in particular, do not grant a presumption of conformity. That is the reason why the legislature considered it not strictly necessary for such codes to be approved by an implementing act, and removed the corresponding empowerment of the Commission.

The new Article 50(7) nonetheless keeps the rest of the structure in place: the Commission encourages and facilitates the drawing up of codes, assesses whether adherence to them is adequate to ensure compliance with the obligations in paragraphs 2 and 4, taking the utmost account of the opinion of the AI Board, and, if it considers a code inadequate, may adopt an implementing act specifying common rules for the implementation of those obligations. The distinction from harmonised standards remains sharp: a reference to a harmonised standard published in the Official Journal produces the presumption of conformity under Article 40, whereas signing a code produces predictability and a pathway recognised across the Union, not a shift in the burden of proof.

Four more months for marking, not for labelling

The Digital Omnibus on AI added a paragraph 4 to Article 111, under which providers of AI systems, including general purpose AI systems, generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026. Recital 38 calls this a transitional period of four months and justifies it by the need to give providers a reasonable time to adapt their practices without disrupting the market.

The deferral is precise and narrow: it concerns only paragraph 2, only providers and only systems already on the market. It does not touch paragraph 4, which falls on deployers and has been fully applicable since 2 August. What follows is an asymmetry worth putting on record: for four months, a party using a generative system may have to disclose that an image or a video is artificial while the system that produced it is not yet required to mark its outputs in a machine readable format. In legal terms the two positions remain distinct, because the deployer’s obligation is to disclose, not to apply a marker, and the upstream delay is no excuse. In operational terms, however, for some months whoever declares the synthetic nature of a piece of content will do so without being able to rely on a technical signal confirming it, and the question of what a marker actually attests remains what it has always been.

Those who do not sign, and those who check

Not signing is not an infringement. Those who choose to comply by other means will, however, have to show that those means are adequate, and that assessment, the Commission warns, will be made individually by the various market surveillance authorities. This is where signing produces its practical effect: not a presumption, but a common reference point that reduces the risk of divergent readings from one Member State to another. Those who do not sign do not have that reference point, and face the authorities of every Member State in which they operate.

In Italy the institutional picture is not yet settled. The draft legislative decrees adapting national law to the AI Act received the opinions of the Italian data protection authority on 14 July 2026, which asked among other things for clarification of its own role in the conformity assessment procedures for high-risk systems. Until the decree is published, anyone deciding today how to implement Article 50 is working with a fully applicable European obligation and a national supervisory framework still taking shape.

The picture, at the time of writing, is this. The transparency obligation applies to everyone from 2 August and its infringement can be penalised. The code of practice offers signatories a pathway recognised across the Union, but not a presumption of conformity, and this time the statement does not come from a guidance document: it comes from the recital of a regulation. Providers of generative systems already on the market have until 2 December to make their outputs marked and detectable, and would do well to use those months to choose their technical solutions rather than to postpone the choice. Those who use such systems have no extra time at all: they must disclose what they publish, from now, with the tools they have.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article