On June 10, the European Union released the Code of Practice (CoP) under Article 50 of the EU AI Act, the provision requiring transparency in the labelling of AI-generated content. It has two sections aimed at two different stakeholders:
Providers: Those who build AI systems; and
Deployers: Those who use these systems to create and publish content.
For AI Deployers: Obligations for Labelling Deepfakes, Including Text: Under the new guidelines, AI deployers/platforms are obligated to label AI-generated content in the manner specified by the EU. The broad categories of AI-generated content covered under this section are:
Deepfakes: AI-generated or manipulated images, audio, or video that “resemble existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.”
Published text on matters of public interest: AI-generated text published to inform the public, “without human review or editorial control and where no natural or legal person holds editorial responsibility for the publication.”
Labeling deepfakes clearly, visibly, at the first exposure: The legal requirement is that AI-label disclosures must appear “at the latest at the time of the first interaction or exposure.” Late disclosure does not comply.
Three EU icons are available and free to use, without attribution. They were empirically tested across Member States for noticeability, recognisability, and clarity:
“AI GENERATED” — for fully AI-generated deepfakes or published text.
“AI MODIFIED” — for partially AI-manipulated content.
Basic “AI” icon — a minimal version that can be supplemented with a custom interactive layer.
EU-recommended labels for AI generated content. Source: [ URL ]
The Code notes that user testing found that “the variants that include a clear textual label (i.e. ‘modified’) performed significantly better in terms of noticeability and clarity.”
Equivalent custom labels are permitted but must follow the same design specifications. The main visual element must be the capitalised acronym “AI” in English (or a national language if required by law). Proportions must be preserved if resized, and the label must remain clear and distinguishable at any context-appropriate size.
Label placement for visual content: The icon must appear “in an appropriate place where no intervening overlay elements exist (e.g., in the top right corner of an image or video deepfake).”
For video: The label must be displayed at the beginning and at regular intervals, at a minimum after interruptions such as ad breaks.
For published text: The label should appear “above or at the top of the text, near the headline… or in the colophon at the beginning of the text.”
Label placement for audio-only content: A spoken disclaimer must appear at the beginning, “in plain and simple natural language… disclosing the artificial origin of the audio deepfake in a perceivable manner.”
For long-form or live audio, reminders must be repeated “at regular intervals… for the entire duration of the audio deepfake.”
When a screen is also available (e.g., a car display or smartphone), a visual icon is required in addition to the audio disclaimer.
Accessibility Requirements: Compliance with the European Accessibility Act and the Web Accessibility Directive is mandatory. The Code requires:
Audio descriptions for visual labels;
Tactile or haptic cues for audio content (e.g., “a vibration alert before audio playing”);
High-contrast icons and screen-reader compatibility; and
Detectability by assistive technologies.
What Are the Obligations for Low-Risk Fictional Content?
Artistic and Satirical Works Are Not Exempt: they are simply given more flexible placement requirements. Deployers must still label such content, but “in a way that does not hamper the display or enjoyment of the work.” The icon must continue to follow the designated design specifications.
Digital and Interactive Contexts: For websites, apps, smart glasses, and similar interfaces, the icon may be placed “outside but adjacent to the video or image frame, or adjacent to the audio content and integrated into user interface elements or overlays.” A non-obtrusive icon that reveals more information on click or hover is acceptable, provided it is “perceivable by the end-user without the need to perform dedicated actions.”
Non-Digital Contexts: For galleries, cinemas, festivals, and similar venues, AI disclosures may appear “at the online or physical point of entry or sale, as part of the introductory or accompanying information (e.g., exhibition leaflet or entrance ticket), or information provided via a physical carrier (e.g., packaging).”
Additional Recommendations for AI Deployers:
Documentation: Deployers must document how they implement labelling, proportionate to their size. Documentation may include “a general description and representative, concrete and real examples of how disclosures are implemented in practice.” Publishing this documentation publicly is encouraged.
Staff Training: Staff awareness training is required and should be proportionate to organisational size. Training should cover: When disclosure is legally required; How to implement disclosures in workflows; Edge cases such as artistic works and editorial responsibility; Accessibility requirements; and Procedures for correcting incorrect or missing labels.
Fact-Checking and Flagging Channels: The Code encourages mechanisms that allow “trusted flaggers, independent researchers, academics, fact-checkers” and others to report missing or incorrect disclosures. Reported cases of mislabelling must be reviewed and remedied “without undue delay.”
Maintaining Humans in the Loop:
Licensed media organisations may rely on their editorial processes to satisfy disclosure obligations for published text, provided those processes meet the Code’s requirements.
Mandatory Editorial Controls: “All other deployers publishing AI-generated text on matters of public interest must establish internal editorial control policies, which must include at minimum:
The identification of the natural or legal person with editorial responsibility (name, role and contact details);
An overview of the concrete organisational measures as well as human resources, allocated to ensure adequate human review or editorial control is performed and editorial responsibility is assumed before publication of the published text.”
Public Accountability: Contact details of the person or entity with editorial responsibility must be publicly available. Deployers must “publish the contact details of the function, the natural persons or the legal persons with editorial responsibility to ensure accountability.”
Protection of Press Freedom: “The implementation of this Commitment shall in no way affect media freedom, editorial independence and protection of journalistic source information.”
For AI Providers: Marking and Detection
The Core Problem: The Code argues that “AI systems can generate and manipulate large quantities of synthetic content and it is becoming increasingly difficult for humans to distinguish this content from human-authored content,” creating risks of misinformation, large-scale manipulation, fraud, impersonation, and consumer deception.
Two Mandatory Layers of Marking: “No single marking technique suffices to meet the four requirements in Article 50(2) AI Act, namely effectiveness, interoperability, robustness, and reliability… only an appropriate combination of marking techniques and associated detection mechanisms can allow satisfaction of those requirements in a holistic manner.”
The two mandatory layers are:
Digitally signed metadata: Where content formats support metadata (audio, image, video, PDFs, Word documents, etc.), providers must record whether content is AI-generated or manipulated and digitally sign and timestamp this information “in a secure and tamper-evident manner.” Providers are encouraged to include additional provenance information, such as: AI provider name; AI system name; Timestamp; Model ID; and Model version.
Imperceptible watermarking: This is mandatory for all content except “very short text,” currently defined as fewer than 200 tokens. “For free-form text longer than 200 tokens, watermarking still needs to be applied, even though it may have lower reliability compared to that of watermarking very long text.” The Code identifies two approaches:
Post-hoc watermarking: applied after generation and
Model watermarking: embedded during the inference-level.
Inference refers to the “‘doing’ part of artificial intelligence. It’s the moment a trained model stops learning and starts working, turning its knowledge into real-world results.” The EU encourages model-level watermarking to simplify compliance for downstream developers.
Optional: Fingerprinting and Logging: AI providers may optionally implement fingerprinting or logging mechanisms. However, “relying on fingerprinting or logging alone is not considered sufficient to meet the quality requirements.” The Code clarifies that this measure applies only to how a provider designs and implements its AI system and does not require logging, monitoring, or retaining prompts or user interactions generally.
Preserving Existing Markings: AI providers must “retain, and abstain from intentionally altering or removing, existing metadata markings” when content is reprocessed. They must also prohibit the removal of markings through their terms of use and acceptable-use policies.
Key exception: An exception exists for “good faith, legitimate processing where the modification… is necessary to maintain accurate and functional information following downstream processing or… security audits and research purposes.”
AI Providers cannot sell circumvention tools. Providers must not “place or make available on the market, nor promote or advertise the use of tools whose purpose is to circumvent the machine-readable markings.”
AI Providers are encouraged to embed richer provenance metadata (Optional): Providers are encouraged to include: AI system name; Provider company name; Generation timestamp; Model ID and version; and For manipulated content, the type of modification performed (e.g., object removal). Multiple operations may be combined into a single marker to reduce complexity.
AI Providers are encouraged to build in a labelling tool for AI deployers (optional): AI providers can offer an optional labelling tool for deployers (especially for deepfake or text systems), allowing them to add required labels at their discretion. This is to support deployers’ compliance without shifting responsibility. However, responsibility for labelling remains with deployers.
How the EU plans to make deepfake detection accessible?
Free Detection as the Default: “Signatories will make the detection solution available free of charge.” However, providers with fewer than one million monthly users may charge a fee if the detection solution incurs substantial operational costs and a single user exceeds a reasonable request threshold. Any fee must be “reasonable, fair and proportionate.”
Free deepfake detection access without any limits on volume: “All Signatories will always provide free access to their detection solution, without any restriction on the volume of requests, to competent market surveillance authorities and other regulators, law enforcement authorities, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions, and civil society organisations.”
Text watermark detection may be gated to expert users: Because free-form text watermarking remains less reliable, access to some text watermark detection systems may be restricted to verified expert users until more robust solutions emerge.
Transparency about detection methods: “Signatories will ensure that detection results indicate whether they are based on a metadata marking, a watermark marking, forensic detection or other techniques, to the extent technically feasible.”
Downloadable Signed Results: Providers must ensure detection results can be downloaded in a “digitally signed format, including at least a hash of the content submitted for detection, a URL or other identifier of the detection solution, and a timestamp.”
Zero Data Retention: “The content is stored only for the duration of the detection and is permanently deleted immediately thereafter (i.e., with a ‘zero retention’ policy).” Content submitted for detection cannot be used for any other purpose, including AI training.
Forensic Detection Remains Optional: Detecting AI-generated content without prior markings remains optional and is currently considered immature. “At the time of publication of the Code, forensic detection mechanisms were not deemed mature enough to comply with the quality requirements.” Providers using such systems may restrict results to verified expert users.
The four-tier testing framework: All marking and detection solutions must satisfy four quality requirements:
Effectiveness: Normal users should be able to understand the results.
Reliability: AI-content labelling should maintain low error rates across diverse content types.
Robustness: Labels should survive compression, cropping, paraphrasing, screen recording, and deliberate attempts at removal.
Interoperability: Solutions should function across different AI systems and platforms.
By February 2, 2027, AI providers should implement at least one of four prescribed interoperability approaches for watermark detection:
A publicly available interoperable API standard;
A publicly readable signpost embedded in content;
A shared AI industry consortium detection solution; or