Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →Code of Practice on Transparency of AI-Generated Content
Issued by
European Commission
The European Commission published this voluntary Code of Practice to support compliance with Article 50 of the EU AI Act, which mandates transparency obligations for AI-generated content. It applies to providers and deployers of generative AI systems operating in the EU market. The Code establishes practical standards for content labeling, provenance controls, and disclosure workflows.
Applies To
Overview
The Code of Practice on Transparency of AI-Generated Content is a voluntary instrument developed by the European Commission to operationalize the transparency requirements set out in Article 50 of the EU AI Act. It provides concrete technical and organizational guidance for generative AI providers and deployers responsible for ensuring that AI-generated content is identifiable by end users. Key provisions address machine-readable provenance signals, human-readable disclosure labels, and internal governance processes for maintaining content authenticity records. The Code functions as a safe harbor reference: organizations demonstrating adherence can use it as evidence of Article 50 compliance in regulatory proceedings. Enforcement of the underlying Article 50 obligations remains with national market surveillance authorities and, for general-purpose AI model providers, the European AI Office. The final text was published on 10 June 2026, aligning with the broader EU AI Act enforcement timeline for generative AI obligations.
Key Requirements
- •Providers and deployers of generative AI systems must ensure AI-generated content is marked with machine-readable provenance signals, such as watermarks or metadata, where technically feasible.
- •Human-readable disclosures must be presented to end users at the point of content delivery, indicating the content was AI-generated.
- •Organizations must maintain internal records of content provenance and disclosure workflows sufficient to demonstrate compliance upon request by competent authorities.
- •Signatories commit to annual self-assessment reporting against the Code's transparency benchmarks, submitted to the European AI Office.
- •Deployers operating platforms that disseminate AI-generated content at scale must implement detection and labeling systems capable of processing content in near real time.
- •Non-compliance with Article 50 of the EU AI Act, which this Code supports, can attract fines of up to EUR 15 million or 3% of global annual turnover, whichever is higher.
What Your Organization Must Do
- →Audit all generative AI systems in use across the organization and identify which produce content distributed to external users or the public.
- →Map existing content pipelines to determine where Article 50 disclosure obligations are triggered and where gaps in labeling currently exist.
- →Implement technical provenance mechanisms, such as C2PA-compliant metadata or watermarking, for all covered AI-generated outputs before enforcement windows close.
- →Update procurement and vendor contracts to require suppliers of generative AI tools to provide documentation confirming their systems support machine-readable provenance standards.
- →Establish an internal disclosure governance procedure, including approval workflows and record retention policies, to demonstrate ongoing compliance to national market surveillance authorities.
- →Register as a signatory to the Code of Practice and calendar the annual self-assessment submission cycle to the European AI Office.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does signing the CoP-AIGC create a safe harbor against EU AI Act Article 50 enforcement?
- Adherence to the Code can be presented as evidence of Article 50 compliance in regulatory proceedings, functioning as a practical safe harbor. It does not eliminate enforcement risk entirely, but it significantly strengthens a compliance defense before national market surveillance authorities and the European AI Office.
- What are the maximum fines for violating Article 50 of the EU AI Act that the CoP-AIGC supports?
- Non-compliance with Article 50 can result in fines of up to EUR 15 million or 3% of global annual turnover, whichever is higher. The Code itself is voluntary, but the underlying Article 50 obligations carry these binding penalties.
- Which technical standards satisfy the machine-readable provenance signal requirement under the CoP-AIGC?
- The Code references approaches such as C2PA-compliant metadata and watermarking as acceptable provenance mechanisms. Organizations should confirm their chosen standard produces signals detectable by third-party verification tools and document the technical feasibility assessment supporting that choice.
- Does the CoP-AIGC apply to SMBs deploying third-party generative AI tools, or only to model developers?
- The Code applies to both providers and deployers, meaning SMBs that distribute AI-generated content through third-party models are in scope. Compliance obligations extend to procurement controls, vendor contracts, and disclosure workflows, not just to organizations that build the underlying models.
- How often must CoP-AIGC signatories submit self-assessment reports, and to which authority?
- Signatories must submit annual self-assessment reports to the European AI Office, benchmarked against the Code's transparency requirements. Organizations should establish an internal calendar and governance procedure to ensure these submissions are prepared with adequate lead time.
- When does the CoP-AIGC take effect relative to the broader EU AI Act enforcement timeline for generative AI?
- The final Code was published on 10 June 2026, aligning with the EU AI Act's enforcement timeline for generative AI transparency obligations. Organizations should treat this date as the practical deadline for having provenance signals, disclosure workflows, and internal records fully operational.
