EU algorithmic accountability

The EU's AI Transparency Rules Are Live, But Their Enforcement Depends on Watermarks That Break for $50

Article 50 of the EU AI Act now requires AI disclosure and content labeling, but the marking technology it leans on is provably easy to defeat.

Article 50: Transparency Rules in Numbers People of Internet Research · EU ~190 Code of Practice signatories Organizations signed before the Au… €15M / 3% Maximum fine Of global turnover, whichever is h… <$50 Watermark spoofing cost Researchers demonstrated defeating… 4 months Legacy system grace period Systems already on the market get … peopleofinternet.com
Article 50: Transparency Rules in Numb… People of Internet Research · EU ~190 Code of Practice signatories €15M / 3% Maximum fine <$50 Watermark spoofing cost 4 months Legacy system grace period peopleofinternet.com

Key Takeaways

A Modest Rule, Finally Live

Article 50 of the EU AI Act took effect on August 2, 2026, and it is, by the standards of the Act's higher-risk provisions, a light-touch rule. It does not ban any AI system or require pre-market approval. It asks for disclosure: chatbots and AI agents must tell users they're AI "unless this is obvious," synthetic images, audio, video and text must carry machine-readable marks, deepfakes and AI-generated content on public-interest topics like politics or public health must be labeled unless a human editor substantively reviewed them, and emotion-recognition or biometric-categorization systems must notify the people they're scanning (European Commission FAQ). Enforcement sits mainly with national market surveillance authorities, with the AI Office handling only general-purpose-model-integrated systems and very large platforms, and penalties topping out at €15 million or 3% of global turnover (European Commission).

The steelman case for this is straightforward and worth taking seriously. Voters cannot evaluate a political ad if they don't know a machine generated it. A customer venting to what they believe is a human support agent behaves differently than one who knows it's a bot. And the asymmetry between how cheaply synthetic media can now be produced and how slowly detection tools have caught up is real — labeling requirements are a reasonable response to a genuine information problem, not regulatory overreach for its own sake.

The Industry Actually Showed Up

What's notable is that compliance arrived ahead of the deadline rather than after it. By July 31, roughly 190 organizations — including Anthropic, Google, Meta, Microsoft and OpenAI on the provider side, and firms like Getty Images, Lenovo and Bulgari as deployers — had signed the voluntary Code of Practice on Transparency of AI-Generated Content, which gives signatories a presumption of compliance with the marking and labeling obligations (European Commission). About half the signatories are small or newly founded companies. That's a meaningfully different pattern than the DSA rollout, where large platforms complied and smaller players scrambled or ignored the rules until enforcement caught up. A voluntary code with a compliance carrot — rather than a mandatory standard imposed unilaterally — is the right instrument for a technically unsettled area, and the AI Office deserves credit for using it.

Where the Rule Outruns the Technology

The problem isn't the disclosure principle. It's that Article 50 requires marking to be "effective, interoperable, robust and reliable as far as this is technically feasible" — and that qualifier is doing a lot of work, because current watermarking does not clear that bar. A Cloud Security Alliance research note published days before the deadline documents that researchers have demonstrated spoofing and scrubbing of watermarking schemes "previously considered safe" for under $50 per attack, that a public tool can defeat Google's SynthID detector on Gemini-generated images, and that API access to watermarked language models allows attackers to reverse-engineer the scheme with better than 80% success (Cloud Security Alliance). Watermarks also routinely fall off during ordinary compression, cropping, or a platform re-upload — meaning a mark can be technically present at generation and functionally absent by the time content reaches a reader.

This creates an odd compliance posture: a company that watermarks in good faith today may find its scheme publicly broken within months, through no fault of its own. Regulators should treat marking compliance as an ongoing, evolving obligation rather than a one-time box to check — and enforcement discretion in the early months should reflect that the underlying cryptographic problem is, at present, unsolved, not merely under-implemented.

The Definitional Fights Are Just Starting

The other soft spot is the "obvious" exemption for chatbot disclosure. The Commission's guidelines, adopted July 20, interpret this narrowly: providers must assess whether a reasonably well-informed, circumspect member of the system's actual intended audience — not a tech-savvy sophisticate — would recognize the AI without being told. In practice, that pushes toward more disclosure wherever children, older users, or other vulnerable groups are likely present. That's a defensible reading, and it is meaningfully more protective than a blanket carve-out for anything vaguely bot-like would have been. But it also means the line between "obvious" and "requires disclosure" will be litigated system by system, and national market surveillance authorities — 27 of them, with varying capacity and appetite — are the ones who'll draw it first.

The Actual Risk

The honest case against over-worrying here is that Article 50, unlike the Act's high-risk-system provisions, doesn't gate market access — it's a disclosure duty, and disclosure duties are the least distortive form of AI regulation available. The honest case for vigilance is that a €15 million exposure tied to a technical standard nobody can fully satisfy invites two bad outcomes: large firms over-comply defensively in ways that degrade product usability, and small firms — the ones least able to absorb readiness costs that industry estimates already put at tens of thousands of euros — under-comply and eat the enforcement risk. The Commission's own SME provisions, including proportional fee caps, are the right mitigant. Regulators should lean on them, and should calibrate early enforcement toward good-faith effort rather than watermark perfection that the underlying technology cannot yet deliver.

Sources & Citations

  1. European Commission — Article 50 FAQ
  2. European Commission — "Safer and more transparent AI" announcement
  3. European Commission — Code of Practice signatory backing
  4. Cloud Security Alliance — Article 50 watermarking research note
  5. Cooley — AI Act transparency obligations analysis