Quick answer
The EU's final Code of Practice on Transparency of AI-Generated Content, published June 10, 2026, gives providers a real technical menu for marking image, audio and video: digitally signed metadata, imperceptible watermarking, or both, plus a public detection requirement due by February 2, 2027. Text gets the same paperwork but a much weaker technical answer, because there is far less redundant signal in a sentence to hide a durable watermark inside.
What the Code of Practice actually is
I'm Hlib Storchak. I build outbound systems for B2B founders and sales teams, and I've booked 2000+ meetings for B2B clients doing it. A growing share of what I now vet for clients isn't copy or infrastructure, it's whether the AI tool generating a voice note, an avatar clip or a line of cold email copy is actually keeping up with what regulators expect of it. This is one of those documents.
Article 50 of the EU AI Act is the law: it says AI-generated content has to be marked so it is machine-detectable, and certain uses have to be disclosed to the person seeing them. What it does not do is say how. That gap is what the Code of Practice on Transparency of AI-Generated Content fills. It's a voluntary instrument, not a regulation, built by the European Commission and the European AI Office to turn a one-paragraph legal duty into something a provider can actually build against.
Voluntary doesn't mean toothless. Signing it is the easiest way for a provider to demonstrate compliance with Article 50(2), and non-signatories still have to show they meet the same bar some other way. In practice, most serious providers sign it rather than invent their own proof.
The timeline, in the order it actually happened
Worth laying out plainly, because the Code, the law, and the grace period are three different clocks that people keep collapsing into one date.
| Date | What actually happened |
|---|---|
| January 2026 | First draft of the Code of Practice published for comment |
| June 10, 2026 | Final Code of Practice on Transparency of AI-Generated Content published |
| July 8-9, 2026 | Commission adequacy decision on the Code issued |
| July 20, 2026 | Final Commission Guidelines on Article 50 published |
| August 2, 2026 | Article 50 obligations, including deployer disclosure, take effect |
| December 2, 2026 | Grace period ends for machine-readable marking on systems already on the market before Aug 2 |
| February 2, 2027 | Deadline for providers' detection solution to be interoperable |
I covered the August 2 and December 2 dates and what they mean for an outbound team's own obligations in an earlier piece. This one is about the document that actually tells providers what to build, and where its own logic starts to strain.
The provider side: three marking measures, not one
The Code splits provider commitments into a small set of measures rather than one blanket rule, which is the first thing that surprises people who assume "marking" means one watermark format everyone implements the same way.
- Measure 1.1, machine-readable marking. A provider marks AI-generated output using digitally signed metadata, imperceptible watermarking, or both. Metadata means recording provenance information inside the file itself, in a way that resists tampering. Watermarking means embedding a signal into the content, into pixels, an audio waveform, or the statistical pattern of a text output, so it survives things that strip metadata, like a screenshot or a re-encode.
- Measure 1.2, non-removal. If AI-generated content becomes the input to a new generation step, the provider is expected to preserve the existing marking rather than let it get stripped along the way. This matters more than it sounds: a lot of real content passes through two or three AI tools before a human ever sees it.
- Measure 1.3, optional richer provenance. Providers are encouraged, not required, to attach fuller provenance data using open standards like C2PA and CAWG metadata, the kind of record that can show not just "AI made this" but which tool, and roughly when.
Tip. The metadata standard doing most of the real-world work right now is C2PA, the Coalition for Content Provenance and Authenticity's "Content Credentials" format. It's the one format compliance trackers describe as actually deployed at any scale today, which tells you how early this whole ecosystem still is.
Commitment 2: detection has to be public, and interoperable
Marking something is only half the job if nobody outside the provider can check it. Commitment 2 requires providers to make detection available to the public free of charge, through an API, downloadable tooling, or participation in a shared consortium solution. The reason this needs its own separate deadline, February 2, 2027, is that a world where you have to individually query every AI vendor's own detector to check one piece of content isn't actually usable. The Code pushes providers toward a common, interoperable way to ask "was this AI-generated," rather than fifty incompatible ones.
That deadline hasn't landed yet as I'm writing this. It's the next real checkpoint to watch, because it's the point where "we mark our content" turns into "anyone can actually verify that."
The deployer side: icons, not code
Section 2 of the Code covers deployers, meaning anyone using a generative AI tool rather than building one, which is most B2B teams reading this. The obligation here is simpler and less technical: when disclosing a deepfake or AI-generated content, deployers should use a set of generalised icons the EU AI Office provides, rather than inventing their own label wording or symbol.
If you're a deployer, this is the part that actually touches your workflow. Your AI avatar or voice tool provider handles the marking. You handle telling the person in front of it, using a recognisable icon rather than a paragraph of fine print they'll never read.
Where the Code actually holds up, by content type
This is the honest answer to "does this actually work," and it depends heavily on what's being marked.
| Content type | Marking mechanism | Real-world maturity |
|---|---|---|
| Image | C2PA metadata + pixel watermarking | Reasonably mature, C2PA already used commercially |
| Video | Metadata + frame or audio-track watermarking | Workable, but re-encoding and clipping remain a stress test |
| Audio / voice | Waveform watermarking + metadata | Workable for full clips, weaker on short snippets |
| Text | Token-distribution watermarking | Least mature, degrades fast with editing or short passages |
Notice the pattern: every modality above text has a physical medium with a lot of redundant data to hide a signal inside. A watermark in a video frame or an audio waveform has room to be robust because there's a lot of "space" the human eye or ear doesn't notice.
Why text is the modality the Code can't fully solve
Text doesn't have that spare room. A watermark in generated text works by nudging the statistical distribution of word or token choices in a way that's invisible to a reader but detectable by a matching algorithm. That only works if there's enough text to carry a statistically meaningful pattern, and if nobody rewrites, trims, or translates it afterward. A two-sentence cold email opener is close to the worst case for this technique: short, likely to get edited by a human before it ships, and exactly the kind of content this blog's readers actually generate with AI every day.
The Code's own structure quietly admits this. Unlike a deepfake video or a cloned voice, AI-generated text doesn't get classified as a deepfake at all under the Act, and the deployer disclosure duty for text only bites when it's "informing the public on a matter of public interest," which is almost never a sales email. The marking duty on text output still technically exists for providers, but it is, by a wide margin, the shakiest piece of the whole framework right now.
A live example: Claude's own watermarks under the same Code
The clearest real-world test of all this landed the same week Article 50 took effect. Anthropic signed the EU's Code of Practice and, starting with Claude models launched from August 2, 2026, began embedding an imperceptible watermark directly into Claude-generated text, alongside C2PA-standard provenance metadata for generated image files. Anthropic says the marks are meant to apply worldwide, not just to EU users, which is itself a signal of how a voluntary EU code ends up shaping a global product decision once a major provider signs it.
What's more useful than the announcement is Anthropic's own stated limitation: the text watermark isn't fully conclusive. Heavy editing weakens it, very short passages may not carry enough signal to detect reliably, and the absence of a mark doesn't prove a human wrote something either. That's not a knock on Anthropic's implementation, it's the same physics problem every text-watermarking approach runs into, playing out in a shipped product instead of a policy document.
What the Code still leaves open
A few things the final text doesn't resolve, worth knowing before you treat "the Code covers this" as a settled question:
- The line between editing and generating. A human writing a first draft and having AI tighten it is exempt. Where exactly that line sits for a heavily AI-assisted but human-edited email is still a judgment call, not a bright rule.
- Common evaluation benchmarks. There isn't yet an agreed, independent way to score how reliable a given provider's marking or detection actually is. Everyone is grading their own homework for now.
- Enforcement in practice. The Code and the Guidelines exist. What a regulator actually does with a provider's imperfect text-watermark, versus a provider with none at all, is untested.
What this means if you buy or run AI prospecting tools
Most of the tools an outbound team actually touches sit in one of two buckets under this Code. AI avatar video and voice-clone tools sit in the bucket where marking is technically real and improving. AI copywriting and sequencing assistants sit in the bucket where the underlying technology is, by the Code's own admission, the weakest link.
This is the audit I actually run for clients now: I don't ask "is this tool compliant," I ask which bucket a given tool falls into, because the honest answer changes what I tell a client to check. For a voice-clone or avatar tool, I want to see the vendor's C2PA or watermark implementation in writing. For a copywriting assistant, I tell clients not to lean on "it's marked" as a compliance answer at all, because the mark is the part most likely to not survive the edit a human makes anyway.
The four questions worth asking a vendor now
- Have you signed the EU Code of Practice, or are you demonstrating Article 50(2) compliance some other way?
- For video or voice output specifically, do you use C2PA metadata, watermarking, or both, and does the mark survive a re-encode or a screenshot?
- What's your plan for the February 2, 2027 public detection interoperability deadline?
- For text output, what do you tell customers about the mark's reliability once a human edits the draft?
A vendor with a real answer to all four has actually engaged with this. A vendor that just says "we're compliant" hasn't told you anything you can check.
Key takeaways
- The Code of Practice, final as of June 10, 2026, is the technical playbook behind Article 50's marking duty. It's voluntary to sign but the easiest path to demonstrating compliance.
- Providers get three measures: signed metadata, watermarking, or both (1.1), preserving existing marks through further generation (1.2), and optional richer provenance via C2PA/CAWG (1.3), plus a public, interoperable detection commitment due February 2, 2027.
- Deployers get a simpler job: disclose using the EU AI Office's standard icons, not custom wording.
- Image, video and audio marking is real and improving. Text marking is the weakest link, by the Code's own logic, because there's far less redundant signal to hide a watermark inside.
- Anthropic's own Claude watermark rollout under this same Code, live from August 2, 2026, is a working example, limitations included: it degrades on heavy editing and short text.
- For outbound teams, the practical split is: verify a video/voice vendor's marking implementation directly, and don't treat "it's marked" as a compliance answer for AI-drafted copy at all.
FAQ
Is the EU's Code of Practice on AI-generated content actual law?
No. It's a voluntary instrument published by the European Commission and European AI Office that gives providers a concrete way to demonstrate compliance with the actual legal duty, Article 50(2) of the EU AI Act. Signing it is the easy path; a non-signatory still has to prove compliance some other way.
What are the three marking measures the Code sets for providers?
Measure 1.1 is machine-readable marking via digitally signed metadata, imperceptible watermarking, or both. Measure 1.2 requires preserving existing marks when AI-generated content is reused as input to further generation. Measure 1.3 is an optional, richer provenance layer using open standards like C2PA and CAWG.
Why does text get weaker marking than video or audio under the same Code?
Watermarking text works by nudging word or token choices in a statistically detectable but invisible way, which needs enough text to carry a reliable signal and breaks down once a human edits, trims, or translates it. Video and audio have far more redundant signal, a pixel grid or an audio waveform, to hide a durable mark inside, which is why those formats hold up better in practice.
What is the February 2, 2027 deadline about?
It's when providers' detection solutions are expected to be interoperable, through a shared API, an embedded signpost, or a consortium solution, so the public isn't forced to query every AI vendor's own detector individually to check one piece of content.
Does any of this actually affect my cold email or LinkedIn copy?
Barely, in terms of legal exposure: one-to-one sales copy almost never triggers the public-interest text-labeling duty. What it should affect is how much trust you place in a copywriting tool's marking claim, since text marking is the part of this whole framework that's admittedly least reliable once a human edits the output, which is exactly what happens to AI-drafted cold email in practice.
Hlib Storchak · 2026-08-11 · ~11 min read