On 17 December 2025, the European Commission published a draft “Code of Practice on Transparency of AI-Generated Content” (the “Code“). If you’re wondering what this is, why it matters, or how it relates to the AI Act, then this post is for you.
1. What is the Code of Practice?
The Code is designed to help providers and deployers of generative AI systems comply with their transparency obligations under Article 50 of the AI Act.
Under this Article:
- Providers (i.e. developers) of generative AI systems must mark AI-generated or manipulated content, such as audio, image, video or text, in a machine-readable format so that it can be detected as artificially generated (Art 50(2)).
- Deployers (i.e. users) of generative AI systems must label AI-generated or manipulated content if it constitutes a ‘deep fake’ or text published on matters of public interest (e.g. news reports) as artificially generated or manipulated (Art 50(4)).
These rules will apply from August 2026 and, although the Act says what providers and deployers must do, it is less clear how they should fulfil these requirements in practice.
This is where the Code steps in, seeking to clarify the specific measures that providers and deployers can take to meet Article 50 requirements.
2. Why is Article 50 and the Code necessary?
We have all, at one time or another, experienced difficulty telling “real” human-created content from “artificial” or “synthetic” content generated by AI systems (most likely on multiple occasions).
This blurring of lines between what is real vs what is artificial/synthetic impacts integrity and trust in digital content and increases risks of misinformation, fraud, impersonation and consumer deception. If you don’t know who made it, how can you possibly trust it?
For those reasons, Article 50 imposes specific transparency obligations on providers and deployers of generative AI systems, so that individuals exposed to content created or manipulated by these systems can tell what is real vs what is not.
3. What is the current status of the Code?
The current draft of the Code is just that – a draft. A further draft will be published around March 2026, before a final Code is published in May or June 2026.
The Code is drafted by independent experts appointed by the AI Office, with inputs from stakeholders across industry, academia and civil society, including contributions from Member States. The drafting has been split between two working groups: one focussing on provider transparency obligations (under Art 50(2)) and the other focussing on deployer transparency obligations (under Art 50(4)).
To learn more about the process, see here.
4. Is the Code mandatory?
No. While Article 50’s transparency requirements are mandatory, the Code itself serves simply “as a voluntary tool… to demonstrate compliance” with Article 50 (see here).
To this end, the Code itself explains that it serves “as a guiding document for demonstrating compliance“, but “does not constitute conclusive evidence of compliance“, with Article 50. Instead it will enable regulatory authorities “to assess compliance” of providers and deployers “who choose to rely on the Code” (see Objective a), Sections 1 and 2).
So, in short:
- Your overriding duty is to comply with Article 50, where it applies.
- Complying with the Code will help to comply with Article 50, but doesn’t guarantee it.
- If you can comply with Article 50 without adhering to the Code, that’s ok too.
5. How does the Code relate to the GPAI Code of Practice?
Both sets of codes are important for helping to manage the risks associated with generative AI, but each have different audiences and serve different purposes.
The Code of Practice on Transparency of AI-Generated Content is addressed to providers and deployers of generative AI systems and focusses only on transparency requirements (i.e. marking requirements for providers, and labelling requirements for deployers).
By contrast, the General Purpose AI Code of Practice is addressed to providers of general-purpose AI models and, while it also contains certain transparency requirements, these focus on the transparency of the model itself (rather than the content it produces). It also contains additional requirements relating to copyright compliance and safety and security.
Generative AI systems will, of course, normally be powered by General Purpose AI models – so, in many cases, the provider of the generative AI system and the provider of the general purpose AI model will be one and the same (think OpenAI with ChatGPT, or Google with Gemini). Where this is the case, both codes of practice will be relevant to these providers.
6. How to read and understand the Code
The Code follows a very clear, logical and organised structure:
- The Code is divided into two Sections – Section 1 addresses provider transparency duties, and Section 2 addresses deployer transparency duties.
- Each Section provides a series of Commitments that participants to the Code are expected to satisfy. The Commitments essentially break up the requirements of Articles 50(2) or (4) (as applicable) into more digestible chunks that impose specific duties.
- Each Commitment then lists a series of Measures that participants to the Code can implement to satisfy the related Commitment.
7. What are the key measures for providers?
Under Section 1 of the Code, providers are expected (among other things) to:
- use ‘multi-layered’ marking techniques – i.e. mark content by including AI provenance information within the content’s metadata (if possible), within the content itself (e.g. by watermarking) and through content fingerprinting and logging;
- synchronise marking techniques across “multimodal” content – i.e. mark AI output with mixed content types (e.g. a document with text and embedded images) in a way that it can still be detected as synthetic even if one or a subset of its modalities (i.e. embedded content types) are altered or exchanged;
- for participants that are providers of generative AI models integrated into downstream AI systems, embed the marking techniques within the model to facilitate compliance by the downstream providers of the generative AI systems;
- implement appropriate measures to prevent tampering or removal of AI marking, including contractual measures (look sharp, all your lawyers out there!);
- maintain provenance transparency – where marked AI content is used as an input for further generation or editing, providers should supplement existing markings, in order to distinguish new operations from earlier ones;
- support deployers of their systems by embedding labelling functionality within their generative AI systems, and
- provide users with tools to test whether content has been generated or edited by their generative AI systems (including, for providers of generative AI models, through “forensic detection mechanisms”).
There’s much more to the Code than the above, including Commitments and Measures relating to effectiveness, reliability, robustness and interoperability, and testing, verification, monitoring, training and compliance – so, for more detail, read Section 1 of the Code.
8. What are the key measures for deployers?
Section 2 of the Code sets out the Commitments and Measures with which deployers can comply to demonstrate compliance with Article 50(4) of the AI Act.
Deployers are expected to use a common “taxonomy” when labelling content under Art 50(4). In simple terms, this means deployers should distinguish between “fully AI-generated content” (with no human authored element) or “AI-assisted content”, and apply labels accordingly.
The category of “AI-assisted content” refers to content which has had a mix of human and AI involvement, and captures such things as “AI rewriting or summarising human-created text” and AI-powered image or video editing tools, such as “object removal”, “face/voice replacement or modification” and “beauty filters that change perceived age”.
The Code also proposes to develop EU-wide common, interactive icons for content labelling based on this taxonomy – but, until such icons have been developed – it encourages the use of ‘interim’ icons, setting out some examples (shown below) in an Appendix to the Code:
or
Deployers should make their icons “clearly visible” at the time of “first exposure” and place them in a position that is “appropriate” to the content format and dissemination context. For audio-only content, this might potentially include interactive audio disclosures too.
Section 2 continues on to provide additional requirements around internal compliance documentation, training to personnel involved in the creation of these types of AI content, monitoring and cooperation with regulators, and ensuring accessible disclosure.
It also lists measures that are “specific” to each type of content (i.e. deep fake vs generative text on matters of public interest). These include internal processes for identifying content within the scope of Art 50(4), how to apply labels based on content modality, and how to apply the labelling limitations and exemptions that exist under Art 50(4).
9. What questions remain outstanding?
The Introductory Statement at the outset of the Code identifies several areas in need of further development. Besides further development of a common EU icon for labelling AI-generated content, these include:
- Feasible approaches to marking AI-generated software code (given that software code is, itself, a type of AI-generated text),
- Feasible approaches to marking other challenging types of content – e.g. very short texts, where marking them would reduce their quality and/or utility very significantly (and where traditional watermarking and fingerprinting methods may not even work) – including whether to set “thresholds” to account for these limitations,
- Whether the measures should apply to (or new measures be proposed for) agentic AI, gaming, VR voice assistants and other novel kinds of AI-generated content, and
- Audio-only labelling, and providing interactive audio disclosures for the EU common icon.
10. Will the Code be ready in time?
If the final Code only arrives in May or June 2026, as proposed, providers and deployers will rightly wonder whether this leaves them enough time to implement the Code ahead of the AI Act’s transparency requirements under Article 50 entering into effect.
As things stand currently, there is a distinct possibility that Article 50 may enter into effect – and therefore expose providers and deployers to penalties for non-compliance – before they have had sufficient time to implement the requirements of the Code. This is particularly so given that many Measures proposed by the Code will require technical implementation – and, as any in-house professional knows, getting engineering time to implement “compliance” changes is never easy.
The Commission appears alive to this potential timing issue. In November, it published its “Digital Omnibus on AI” proposal which, among other things, seeks to push back the date for provider transparency duties (under Art 50(2)) to February 2027. If this happens, it will give providers of generative AI systems some relief – though the labelling requirements applicable to deployers (under Article 50(4)) will still take effect in August 2026.
There is, however, a separate question as to whether the Digital Omnibus proposal itself will be adopted in time before Article 50’s August deadline. Taking into account the time needed for the legislative stakeholders to review, debate and negotiate the proposal, there’s a decent likelihood it won’t.
That, however, is a post for another day….