The Code of Practice on transparency of AI-generated content (“CoP”) and the European Commission’s Guidelines on the implementation of Article 50 transparency obligations under the AI Act (“Guidelines”) will be familiar to most companies working with generative AI systems. What has changed is that these instruments now carry significantly greater weight: 

  • AI Board and Commission have formally assessed the CoP as adequate to demonstrate compliance with Article 50 obligations, and
  • EU Commission Guidelines have moved from draft to final. 

Together, these two developments provide meaningfully greater certainty for providers and deployers on how to structure and demonstrate compliance with the AI Act’s transparency requirements ahead of the 2 August 2026 deadline for Article 50(4) obligations (with Article 50(2) obligations extended to 2 December 2026 under the AI Omnibus).

1. The Code of Practice: Now formally adequate

a) Background and contents

The CoP was developed through a multi-stakeholder process facilitated by the AI Office, involving participants from industry, academia, civil society, rightsholders and EU Member States. Published on 10 June 2026, the CoP provides practical guidance on implementing the transparency obligations under Articles 50(2), (4) and (5) AI Act. It is structured into two sections: 

  • Section 1 addresses provider obligations for marking and detection of AI-generated content under Art. 50(2) AI Act
  • Section 2 addresses deployer obligations for labelling deep fakes and AI-generated text published in relation to matters of public interest under Art. 50(4) AI Act.

b) The adequacy decision: Why it matters

On 8 and 9 July 2026, the European Commission and the AI Board, respectively, concluded that the CoP is adequate to facilitate the practical implementation of Articles 50(2), (4) and (5) AI Act. This is the key development: providers and deployers that adhere to the CoP can rely on it as the only current EU-wide practical compliance tool assessed as adequate for demonstrating compliance with these transparency obligations, regardless of their place of establishment or competent market surveillance authority.
The practical significance of the adequacy decision is that signatories can have greater confidence that they are meeting their compliance obligations. The Commission has stated that for signatories, future enforcement will focus on monitoring adherence to the code. This represents a more predictable enforcement posture compared to non-signatories. Adherence does not constitute conclusive proof of compliance. Market surveillance authorities retain the power to investigate, but signatories benefit from a clearer and more harmonized compliance pathway across all Member States.
For companies deploying generative AI, signing the CoP offers practical advantages:

  • Enforcement predictability: Signatories benefit from a more predictable enforcement posture and increased trust from market surveillance authorities.
  • Penalty mitigation: Competent authorities may take adherence to the CoP into account as a mitigating factor when setting fines.
  • Reduced supervisory burden: Non-signatories must demonstrate compliance through other means and may face more requests for information from authorities.
  • Regulatory certainty: The CoP provides a harmonized implementation framework across the EU, reducing fragmentation and compliance burdens.

2. The final EU Commission Guidelines

On 20 July 2026, the European Commission published its final Guidelines, replacing the previous draft version. The Guidelines provide further interpretive clarity on key concepts, additional examples, and practical guidance for both providers and deployers. While the CoP addresses how to implement the obligations, the Guidelines clarify what those obligations require and their legal scope.

a) Evolution, not revolution

The final Guidelines retain the same nine-section structure as the draft, covering interactive AI systems, synthetic content marking, emotion recognition, biometric categorization, deep fakes, horizontal information requirements, and enforcement. While the foundational concepts remain unchanged, the final version introduces several material clarifications and expanded guidance that are relevant for industry stakeholders. Organizations that began compliance preparations based on the draft Guidelines can proceed with confidence that the overall regulatory framework remains as expected, while refining their approach in light of the updates below.

b) Key clarifications in the final version

We highlight below the key additions and clarifications between the draft and final Guidelines that are most relevant for clients deploying generative AI:

  • AI literacy and cumulative obligations: The final version expressly links Article 4 AI literacy requirements to the Article 50 obligations, clarifying that providers and deployers must ensure adequate AI literacy among staff involved in transparency compliance. A new example illustrates how Articles 50(1), (2), and (4) can apply cumulatively to a single system. For instance, an image-generating chatbot whose outputs may also qualify as deep fakes.
  • AI agents: A substantially expanded section addresses AI agents, covering the obligation to disclose both the agent’s artificial nature and the identity of the person on whose behalf it acts. The final Guidelines also address multi-agent architectures and require disclosure at key steps such as authorization, reporting, and validation. Notably, agents must be designed at the architecture level to disclose their AI nature in any situation where direct interaction with a natural person is reasonably likely.
  • Third-country providers and open-source components: The final version narrows the scope for third-country providers by clarifying that incidental, unforeseeable, or unauthorized downstream use of an AI system in the EU should not by itself trigger Article 50 obligations. It also draws a sharper distinction between open-source AI systems (which remain subject to Article 50) and open-source AI components (software, data, models, or tools that are not themselves a complete AI system), which therefore fall outside the scope of those obligations.
  • Vulnerable groups and complex value chains: The scope of protective disclosure obligations has broadened: the final version extends these to situations where a system is “reasonably likely” (not just “intended”) to interact with vulnerable groups. The new guidance also addresses deployers in complex content production and distribution chains, requiring proportionate measures, including contractual provisions with distribution partners, to ensure AI content labeling remains visible downstream.
  • Expanded content exclusions: The final version significantly expands the list of AI-generated content excluded from the Article 50(2) marking/detection obligation. This now explicitly includes: AI-generated translations, source code, short outputs, machine-to-machine outputs, and closed-loop production workflow outputs at intermediate stages (although final outputs must still be marked). This expanded scope is highly relevant for engineering and cybersecurity teams building internal AI-assisted tooling.
  • Repeated disclosure of AI-generated content: The draft Guidelines addressed repeated disclosure only through a single example on live broadcasts. The final Guidelines generalize this into a broader principle: where it is reasonably foreseeable that a person may not perceive content from its very beginning, a single disclosure at the outset is not enough, and disclosure should be repeated at later points. This is particularly relevant for audio consumption in background or “eyes-free” contexts.
  • Distributor/deployer distinction: The final Guidelines confirm that providers of hosting services, including online platforms, or broadcasters are not deployers where their role is limited to disseminating AI-generated content created by third parties and they lack authority over the use of the AI system. Merely applying or displaying a label does not convert a distributor into a deployer. Platforms can facilitate labeling without triggering deployer status. Still, distributors are strongly encouraged to implement labeling and marking measures and take measures like contractual safeguards or UX designs to facilitate deployers to comply with the transparency obligations.
  • CoP cross-reference: The final version now cross-references the CoP, as a compliance mechanism that organizations can adopt, thereby, creating a coherent compliance ecosystem between the two instruments.
  • Deepfake definition clarified: The final Guidelines provide important interpretive guidance on the four-element deep fake test under Article 3(60) AI Act. Notably, the “existing” element is interpreted broadly: content resembling something that exists, could plausibly exist, or could have plausibly existed, such as a photorealistic portrait of an invented person, remains within scope. The Guidelines also clarify that whether content “falsely appears to be authentic” requires a holistic assessment considering the level of resemblance, substantive message, deployment context, and audience expectations. While photorealism makes deep fake status more likely, it is not determinative. Practical examples are provided: in film production, AI-generated backgrounds and special effects are unlikely to trigger labeling, but AI-generated actors, digital replicas, and de-aging require disclosure. In advertising, a product shown against an AI-generated background is out of scope, but an AI image that makes the product appear better than reality constitutes a deep fake.
  • Creative works exception narrowed: The Guidelines confirm that the lighter disclosure regime for artistic, creative, satirical, or fictional deep fakes is to be interpreted strictly. Content that is exclusively informative or commercial in nature cannot benefit from reduced labeling, and where content combines informative and creative characteristics, the informative character always prevails. For advertising, the Guidelines accept that it can be “evidently creative” only in “specific situations” and all advertising examples provided in the Guidelines are classified as requiring standard labeling. The scope to rely on reduced labeling in advertising contexts therefore appears very narrow.
  • Pre-August 2026 content: The final Guidelines confirm there is no retroactive labeling obligation. For image, audio, and video deep fakes, the relevant date is the date of generation. Content created before 2 August 2026 does not need to be labeled. For text published on matters of public interest, the relevant date is the date of publication, so text generated before 2 August but published on, or after that date must be labeled (unless it benefits from the editorial control exception). Organizations in possession of pre-existing unlabeled content are encouraged to label it, but disproportionate efforts such as auditing content databases or modifying printed packaging are not expected.
  • B2B/industrial carve-out tightened: The business-to-business and industrial carve-out from Article 50(2) marking is retained but subject to three cumulative conditions: (i) the output must not be intended for sharing outside the organization; (ii) the system must be deployed in controlled environments; and (iii) safeguards against foreseeable misuse must be in place, such as cloud isolation and role-based access controls. Public-facing and consumer-facing AI systems are explicitly excluded from this carve-out.
  • Territorial scope for deployers: The Guidelines take a broad view of territorial scope for deployers: posting deep fakes on the globally accessible internet may trigger Article 50(4) obligations if the content is “used in the EU,” without requiring specific EU targeting. This will make it challenging to shield online content from deep fake labeling requirements unless geo-blocking is applied for the EU market.

3. Timeline of Article 50 obligations

  • 2 August 2026 – Article 50(4) AI Act transparency obligations (labeling of deep fakes and AI-generated text on matters of public interest) become applicable.
  • 2 December 2026 – Extended deadline for the machine-readable marking requirement under Article 50(2) AI Act for generative AI systems already on the market before 2 August 2026, under the AI Omnibus grace period.
  • 2 February 2027 – Deadline for providers to implement an interoperability solution for watermark detection.

4. Key takeaways

With the CoP adequacy decision and final Guidelines now in place, companies developing or deploying generative AI should:

  • Stay the course: If your organization began compliance work based on the draft Guidelines, no fundamental pivot is required. Refine your approach with the clarifications above, but the architecture of your compliance program should remain sound.
  • Consider signing the CoP: Evaluate whether to sign the CoP to benefit from enforcement predictability, penalty mitigation, and reduced supervisory burden.
  • Review the final Guidelines: Use the final Guidelines for interpretive clarity on scope, concepts and practical examples relevant to your AI systems and deployment contexts.
  • Map your value chain: Deployers in multi-party content distribution chains should assess contractual and technical measures to keep AI labels visible downstream.
  • Act now: With the 2 August 2026 deadline imminent for Article 50(4) obligations, the publication of the final Guidelines and the adequacy decision removes many remaining ambiguities. Organizations should finalize their compliance measures without delay.

Many thanks to Patricia Geyler who contributed to the drafting of this Viewpoint.

Providers and deployers of AI systems falling within the scope of the transparency obligations laid down in Articles 50(2), (4) and (5) AI Act may rely on the Code [of Practice] as the EU-wide recognised instrument that is considered adequate to ensure compliance with their respective obligations, regardless of their place of establishment, operation or competent market surveillance authority, while recognising that adherence to the Code does not constitute conclusive evidence of compliance with these obligations.

Read more