Published on · 9 mins read

AI watermarks and content: what Article 50 of the AI Act requires

Since 2 August 2026, Article 50 of the AI Act requires transparency and labelling of AI-generated content. What a law firm needs to check, and what can wait.

Frédéric Dechamps

Since 2 August 2026, Article 50 of the AI Act (Regulation (EU) 2024/1689) applies to anyone using generative AI in a professional context. The chatbot on the firm's website, the image created for a LinkedIn post, the blog article drafted with an AI assistant: each of these potentially falls within the scope of the new transparency obligations. And unlike the high-risk part of the regulation, this part has not been postponed.

For a law firm, the division of roles is rather reassuring. The technical obligation everyone talks about, the digital watermark on generated content, rests on the providers of AI systems, not on their users. Two labelling obligations, however, target deployers directly, meaning anyone who uses an AI system under their own authority in a professional context. A lawyer who publishes AI-generated content is a deployer within the meaning of the regulation.

The line between what falls on you and what falls on your tools comes down to a few rules. You do need to know them, because confusion is everywhere: between the omnibus package that shifted part of the timeline, the grace period for marking and the human review exemption, you can read just about everything and its opposite.

Before you start: four things to gather

Taking stock of Article 50 takes half a day if you have these elements at hand:

  • the list of generative AI tools used at the firm, including those that do not present themselves as such (website chatbot, drafting module of your practice management software, image generator, machine translation);
  • an inventory of what the firm publishes: website, blog, newsletter, social media, and the share of that content produced or reworked by AI;
  • the name of the person who assumes editorial responsibility for the firm's publications, because the most useful exemption in Article 50 rests on that person;
  • your usual ethical constraints: professional secrecy for any tool that touches case files, and your Bar's rules on lawyer advertising for anything published.

On the budget side, bringing a firm into compliance requires no software or licence: it costs process time, not tooling.

What Article 50 of the AI Act requires since 2 August 2026

Article 50 creates four transparency obligations, split between providers and deployers of AI systems. The provider develops the system and places it on the market under its own name. The deployer uses it under its own authority, outside strictly personal use. A firm that subscribes to a generative AI tool is a deployer; the tool's publisher is a provider.

ProvisionWho is boundObligationWhat it means for a firm
Art. 50(1)ProviderInform people they are interacting with an AI, unless it is obviousThe chatbot on your site must announce itself as an AI from the first exchange
Art. 50(2)ProviderMark generated content in a machine-readable format (watermark, metadata)That is your tools' job, to be verified contractually
Art. 50(3)DeployerInform people exposed to emotion recognition or biometric categorisationRarely relevant for a firm, but worth knowing to advise clients
Art. 50(4)DeployerVisibly label deepfakes and certain AI-generated texts of public interestConcerns the firm's blog, newsletter and visuals

The text of Article 50 is short; the interpretation sits mostly in the Commission's guidelines and its official FAQ, updated in July 2026. That is the source to keep at hand, ahead of the dozens of commentaries in circulation.

The real Article 50 timeline after the digital omnibus

Three dates are enough to situate your obligations. Since 2 August 2026, the transparency obligations of Article 50 apply: informing people who interact with an AI and visibly labelling the content concerned. On 2 December 2026, the grace period for machine-readable marking ends: it only covers generative AI systems placed on the market before 2 August 2026, and only for the marking obligation of Article 50(2). Finally, the digital omnibus package pushed the obligations for Annex III high-risk systems back to 2 December 2027, which fed the false rumour of a general postponement.

Another point the Commission has settled in black and white: no retroactivity. Content generated before 2 August 2026 does not need to be labelled after the fact. The Commission encourages deployers to do so where possible, without obligation.

Who enforces this? National market surveillance authorities, with a limited role for the European AI Office. In Belgium, the formal designation is still pending: as of late August 2026, no Belgian law has yet named the competent authority, and the FPS Economy coordinates the implementation of the regulation. That institutional gap does not suspend the obligations: the regulation applies directly, and an authority from another Member State can act as soon as non-compliance produces effects on its territory.

date of application of Article 50 of the AI Act
2 August 2026
https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
end of the grace period for marking systems placed on the market before 2 August 2026
2 December 2026
https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
organisations that had signed the code of practice by late July 2026
≈ 190
https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
cap on fines (of worldwide annual turnover), with proportionality for SMEs
€15M or 3%
https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act

The watermark on AI-generated content is the providers' job

Machine-readable marking, often called digital watermarking, falls on the providers of generative AI systems, not on the firms that use them. Article 50(2) requires them to mark the outputs of their systems (text, image, audio, video) in a machine-readable format, detectable as generated or manipulated by AI, using techniques that are effective, interoperable, robust and reliable as far as technically feasible.

This watermark is not a visible notice: it is a mark embedded in the content itself (metadata, a statistical signal in the text or the pixels) that lets detection tools identify the artificial origin, even after copying. The Commission's guidelines exclude a few cases from the scope: short sequences of numbers or letters, source code, outputs exchanged machine-to-machine without human exposure, and systems limited to an assistive function for standard editing, such as grammar correction, that does not substantially alter the input.

To organise all this, the Commission published on 10 June 2026 the final version of its Code of Practice on Transparency of AI-generated Content, assessed as adequate by the Commission and the AI Board. By late July 2026, about 190 organisations had signed it, including Anthropic, Google, Meta, Microsoft, Mistral and OpenAI. The code remains voluntary; the obligations do not. A non-signatory provider will have to demonstrate compliance by other means, with less predictability.

Your role as a deployer here boils down to two questions to put to every publisher of an AI tool the firm uses: what machine-readable marking solution do you apply, and have you signed the code of practice? The answers belong in the contract or its annexes, alongside the GDPR processing clauses.

Gros plan sur une presse à embosser en laiton marquant une feuille de papier vélin, lumière rasante dorée
The marking required by Article 50(2) works like a watermark: a mark embedded in the content, machine-readable, not necessarily visible to the eye.

What your firm must label, and what does not change

A law firm is a deployer within the meaning of the AI Act as soon as it uses a generative AI system in a professional context. On that basis, Article 50(4) imposes two visible labelling obligations.

The first covers deepfakes: images, sounds or videos generated or manipulated by AI that resemble existing persons, objects, places or events and would falsely appear authentic to a reasonably attentive person. The disclosure must be clear, perceivable without any technical tool, at the latest upon first exposure. The Commission's FAQ specifies that a deployer cannot simply rely on the machine-readable marking embedded by the provider: a visible or audible label is required.

The second covers AI-generated or manipulated text "published with the purpose of informing the public on matters of public interest". The Commission's list of examples includes the administration of justice, fundamental rights and consumer protection. A legal blog article or a firm newsletter commenting on a reform ticks those boxes effortlessly.

The exemption that saves everyday practice: no labelling is required where the text has undergone human review or editorial control and a person assumes editorial responsibility for the publication. By that, the Commission means a deliberate examination of the substance by someone with the relevant knowledge, not a spelling correction.

And everything else stays as it was. Submissions to a court, an opinion, a letter to a client or a colleague are not texts "published to inform the public": they remain outside the scope of Article 50(4). Internal research, unpublished by definition, too.

flowchart TD
    A["Content produced with generative AI"] --> B{"Is the content published?"}
    B -- "No: internal research, submissions, letters" --> C["No labelling required under Article 50(4)"]
    B -- "Yes" --> D{"Realistic image, sound or video evoking existing persons, places or events?"}
    D -- "Yes" --> E["Visible label upon first exposure (deepfake)"]
    D -- "No" --> F{"Text intended to inform the public on a matter of public interest?"}
    F -- "No" --> C
    F -- "Yes" --> G{"Substantive human review and assumed editorial responsibility?"}
    G -- "Yes" --> H["No label required: document who reviews and who assumes responsibility"]
    G -- "No" --> I["Visible mention of AI generation"]

The concrete trap: the automated newsletter

Symptom: to keep up the publication pace, a firm plugs in a tool that turns legislative news into a monthly newsletter. The tool drafts, formats, sends. Someone glances at it before sending, fixes two phrasings, approves.

Diagnosis: that text is AI-generated, published, and informs the public on matters of public interest. The glance before sending does not amount to human review within the Commission's meaning, which expressly excludes superficial, solely formal or procedural checks. Without a label, the newsletter has been non-compliant since 2 August 2026.

Fix: two options, each defensible. Either accept the mention, one visible line such as "text generated by AI" in the newsletter, and the matter is settled. Or reintroduce substantive review: a lawyer reads the substance, verifies the claims, corrects or rejects, and their name appears as editorially responsible. Formalising that circuit, who reviews, when, with what trace, takes an afternoon. We lean towards the second option: it removes the label and, above all, it protects the value of the firm's signature.

Why we would never publish a 100% AI text, Article 50 or not

The editorial control exemption describes nothing other than the lawyer's job: read the substance, check the sources, sign and assume responsibility. If a firm needs Article 50 to instil that reflex, the problem is not regulatory.

Our position is clear-cut: publishing under a firm's name a legal text that nobody has reviewed on the substance is a professional fault in the making, with or without a label. The fine under Article 99 is capped; the cost of a wrong analysis published under your signature is not. The "generated by AI" label does not fix an error of law, it flags it.

The real operational issue behind Article 50 is traceability. A text in which every claim points to an identifiable source can be reviewed in minutes; a text without references gets rewritten. That is the choice made with Jef: every answer cites the passages used, drawn from the firm's documentation and from official Belgian and European sources, which makes substantive review workable day to day rather than theoretical.

Article 50 of the AI Act therefore does not ask firms to become experts in digital watermarking. It asks three manageable things: know what the firm publishes and with which tools, put the marking questions to your suppliers, and keep a responsible human between the AI and the publication. Jef (https://www.jef.chat/en) turns a firm's document base into an AI assistant with sourced answers; signing up is free, with 50 messages included.

FAQ

Was Article 50 of the AI Act postponed by the digital omnibus?
No. The transparency obligations of Article 50 have applied since 2 August 2026. The digital omnibus pushed the Annex III high-risk part back to 2 December 2027; for transparency, only the machine-readable marking of systems placed on the market before 2 August 2026 benefits from extra time, until 2 December 2026.
Does content generated before 2 August 2026 need to be labelled?
No. The European Commission confirms that no retroactive labelling is required for content generated before 2 August 2026. It encourages deployers to do so where possible, without obligation.
Must a lawyer disclose the use of AI in court submissions?
Not under Article 50(4): submissions or an opinion are not texts published to inform the public on matters of public interest. The lawyer's professional responsibility for the content remains, however, fully intact.
Does a law firm's blog need an AI notice?
An AI-generated blog article that informs the public on matters of public interest, such as the administration of justice, must be labelled. The obligation falls away if the text has undergone substantive human review and a person assumes editorial responsibility for the publication.
What is the penalty for breaching Article 50?
The fine can reach 15 million euros or 3% of worldwide annual turnover for the preceding financial year. Proportionality can be taken into account for SMEs and small mid-cap companies.

Cited sources

Also read