From 2 August 2026 the transparency obligations in Article 50 of Regulation (EU) 2024/1689, the Artificial Intelligence Act, begin to apply: whoever makes available a system that generates synthetic content must ensure that its outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The obligation is European, a European legislature wrote it, and it binds anyone addressing the Union market. Its effectiveness, however, rests on a condition that Union law cannot produce on its own: that the mark should remain legible once the content leaves the European perimeter, passes through an American platform, is recompressed by an Asian messaging service and comes to rest in an archive that no European market surveillance authority oversees. A watermark that nobody outside can decipher does not deliver transparency: it delivers a file with something inside it.
In the very week in which the European Commission completed its assessment of the transparency code of practice, the layer that is actually building that condition made two moves in Geneva. On 9 July 2026 the ITU (International Telecommunication Union, the United Nations agency for digital technologies) announced a new working group on the identity and the trustworthiness of artificial intelligence agents. The following day, the chair of the international collaboration on multimedia authenticity took stock of a year of work. Read together, the two announcements say one and the same thing.
What Article 50 asks, and what it presupposes
On 10 June 2026 the Commission published the Code of Practice on Transparency of AI-generated content, the voluntary instrument through which providers and deployers may demonstrate compliance with Article 50. On 8 July the Commission concluded that the code adequately covers the obligations laid down in paragraphs 2, 4 and 5 of that article and facilitates their effective implementation; on 9 July the AI Board adopted its own adequacy assessment. This is the same regulatory technique already deployed for general-purpose models, discussed here in relation to GPAI models and the Code of Practice: the legislature fixes the result, a voluntary code describes the conduct that leads to it.
One passage of the Commission document deserves more attention than it has received. The AI Office will consider facilitating formal updates to the code at least every two years, for instance in the light of the emergence of standards or of relevant technological developments. Put differently, the Union has stated in writing that the technical substance of its own transparency obligation is destined to be rewritten as standards come into being. This is not an oversight but an acknowledgement. Marking is a question of formats, of the resilience of the mark to transformations of the file, of provenance metadata that must survive the distribution chain. None of this is settled in a regulation. It is settled in a technical forum, and on this terrain the technical forums that matter are not European.
Where the interoperability of marking is being built
On 10 July 2026 Alessandra Sala, who chairs the AI and Multimedia Authenticity Standards Collaboration, published on the ITU website a piece on building trust in AI-generated media announcing two documents: a policy paper on the emerging legal landscape for generative AI across different regions, and an updated technical paper on multimedia authenticity standards. As the group’s institutional page explains, the collaboration is led through the World Standards Cooperation, the strategic partnership between the IEC (International Electrotechnical Commission), the ISO (International Organization for Standardization) and the ITU, and it brings together standards developers, technology companies, academic experts, policymakers, start ups and civil society.
Its declared mandate is instructive: to map the landscape of technical standards for multimedia authenticity, to identify the gaps where new standards are needed, to recommend and cross-reference existing standards while flagging opportunities for interoperability, and to support the regulatory requirements and the policy measures that governments intend to implement. Sala condenses the problem into a single question: how can trust in authenticity travel, in her words, “across platforms, borders, and legal systems”. That is precisely the question Article 50 cannot answer by itself, because a legal order may impose the duty to mark, yet it cannot impose upon the rest of the world the ability to read the mark.
An asymmetry opens up here that a lawyer will recognise at once. The Union has already experienced the distance between an international technical standard and domestic legal effect: an ISO standard may describe an excellent management system and still produce, in itself, no presumption of conformity, as discussed in relation to ISO/IEC 42001 and the AI Act. In the European system the bridge between the two worlds is the harmonised standard, such as the one intended for the quality management system of Article 17, EN 18286. On the terrain of transparency, however, the asymmetry is reversed: it is not the international standard that seeks European legal effect, it is the European legal obligation that seeks an international standard capable of making compliance possible at all.
From content to agent: who did what
On 9 July 2026, at the AI for Good Global Summit, the ITU announced the establishment of the Focus Group on Trust and Identity for Humans and Agentic AI, tasked with developing frameworks for trusted digital identity and for the verifiability of the behaviour of AI agents throughout their lifecycle. The group will report to ITU-T Study Group 17, the expert group responsible for security standards; it will be co-chaired by Debora Comparin and Amir Banifatemi; it will hold its first meeting in Paris in November 2026 and its second in Geneva in January 2027. Its work programme covers common terminology and definitions, reference architectures for identity, trust, agent discovery and interoperability, trust frameworks and lifecycle assurance models, interoperability mechanisms for digital identity and credentials, security criteria and benchmarks for the continuous assessment of AI agents, and a standardization roadmap. The press release makes clear that the group is open not only to technical experts but also to specialists in policy, law and regulation.
The legally interesting point is the shift in the object. Article 50 asks the content to declare its artificial origin, and thus answers the question of what a given image or a given recording is. The Focus Group takes up the next and harder question, that of who performed a given act, when the actor is a piece of software that negotiates, transacts and decides on someone’s behalf. An agent that impersonates a person or an organisation, or that takes unauthorised actions across interconnected systems, does not raise a problem of product labelling: it raises a problem of attribution. And attribution, absent an infrastructure of identity and verifiable credentials that works beyond the borders of a single legal order and a single platform, remains a rhetorical exercise. The ITU press release puts it in terms a lawyer would endorse: identity systems establish who is acting, while trustworthiness determines whether that actor is reliable.
A regional obligation, a standard the Union does not control
Set side by side, the two developments reveal the same structure. The European Union has the regulatory power: it wrote the obligation, it equipped it with a code of practice declared adequate, and it applies it from 2 August 2026 to anyone addressing its market, regardless of the place of establishment. What it does not have is a monopoly over the technical grammar that makes that obligation operable outside its own house. That grammar is written where the IEC, the ISO and the ITU sit together, where the platforms that distribute content and the makers of the models that generate it sit as well, and where the Union is one participant among others, authoritative but not sovereign.
This is not a weakness in itself: it is the ordinary condition of any regulation whose object is a global phenomenon. It becomes a problem if the legislature ignores it, that is, if it builds an obligation and tacitly entrusts its effectiveness to a table at which it has no decisive voice, without occupying that table. The decision to update the code in step with the standards that will emerge is, in the end, an admission of dependence. And the dependence is bound to widen: once autonomous agents begin to sign, to order and to dispose, the question will no longer be merely whether an image is synthetic, but whether a given transaction was carried out by the party that claims to have carried it out.
In the light of the foregoing, one may ask whether the European Union, having chosen to be the first to impose the duty to mark AI-generated content, should not now occupy with equal determination the international forums in which it is decided whether that mark will be legible at all, and whether the time has not come to acknowledge that regulatory sovereignty, deprived of a corresponding technical presence, produces rules that are impeccable on paper and mute in the rest of the world.




