EU AI Act · Article 50

Last reviewed 9 July 2026

Compliance-ready provenance
for AI-generated content

From 2 August 2026, the EU AI Act expects providers of generative AI to mark their output in a machine-readable form so it can be identified as artificially generated. Certivu is built to be exactly that technical measure — cryptographically verifiable, post-quantum, and signed at the moment of creation. Full text: Regulation (EU) 2024/1689, Article 50 .

The European Commission published the final Code of Practice on Transparency of AI-Generated Content on 10 June 2026, setting out how providers and deployers are expected to meet these obligations in practice. Systems already on the market before 2 August 2026 have until 2 December 2026 to comply.

Aug 2026
Article 50 transparency obligations take effect. Providers must mark AI-generated content in a machine-readable form; deployers must disclose certain synthetic or manipulated content. Marking content as you generate it is far cheaper than retrofitting provenance after the fact.
The obligation

What the Act expects

The EU AI Act's transparency provisions aim to ensure people can tell when they are interacting with, or consuming, AI-generated material. The emphasis is on machine-readable markers, applied where technically feasible.

That is a provenance problem, not a detection problem. The reliable way to satisfy it is to mark content at the source — when the AI system produces it — with a signal that travels with the artifact and can be verified independently by anyone.

This page is general information about the EU AI Act, not legal advice. Consult qualified counsel for your specific obligations.

Providers Mark generative output in a machine-readable form
Deployers Disclose synthetic or manipulated content
Form Machine-readable, where technically feasible
Applies from 2 August 2026
Requirement → Certivu

How Certivu maps to Article 50

Each transparency expectation has a concrete technical answer in the platform.

Mark AI output as artificially generated
Certivu signs content at generation time and embeds a provenance token in a format-native container — declaring it AI-generated with a cryptographic record behind the claim.
Make the marking machine-readable
Provenance is embedded as structured metadata (XMP, ID3/VORBIS, atom/trailer, HTML meta) plus a ctv_ token — readable by software, not just humans.
Keep it verifiable and trustworthy
Every record is signed with post-quantum ML-DSA (NIST FIPS 204). Anyone can verify it for free — tampering fails the signature instantly.
Survive real-world distribution
A resilient watermark and perceptual fingerprint recover provenance after recompression, resizing, and re-uploading.
Interoperate with standards
Certivu reads third-party C2PA manifests and embeds its own ML-DSA-signed C2PA manifests into JPEG/PNG, so your provenance plugs into the wider content-credentials ecosystem.
Demonstrate it to auditors
Audit logs, exports, and per-record verification analytics give you a defensible, timestamped trail of what was signed and when.
Honest positioning

What Certivu does not claim

A compliance tool that over-promises is a liability. Here is where the line sits.

Certivu does not detect undisclosed AI content

It verifies signed provenance when present. It cannot tell you whether unsigned content is AI-generated, and absence of provenance never implies human origin.

Certivu is not a guarantee of compliance

It provides the technical disclosure measure and an auditable record. Your obligations depend on your role and use case — and nothing here is legal advice.

Watermarks are not unremovable

They are resilient to ordinary transforms, not targeted removal. The cryptographic signature — not the watermark — is the source of truth.

FAQ

Common questions

Does Certivu make me compliant with the EU AI Act?

Certivu provides the technical measure the Act expects — machine-readable, cryptographically verifiable marking of AI-generated content at creation time. Compliance overall depends on your role, your use case, and your internal processes. Certivu gives you the infrastructure and an auditable record; it does not constitute legal advice or a guarantee of compliance.

What does EU AI Act Article 50 actually require?

Article 50 sets out transparency obligations that apply from 2 August 2026. Providers of generative AI systems must mark their outputs in a machine-readable form so the content can be identified as artificially generated, and deployers must disclose certain synthetic or manipulated content. The Act emphasises machine-readable markers where technically feasible — which is precisely what verifiable provenance delivers.

Does Certivu detect AI content to flag violations?

No. Certivu verifies signed provenance when it is present — it never claims to detect unsigned AI content, and absence of provenance says nothing about origin. Certivu helps you mark and prove the content you generate, not police what others fail to disclose.

Is the marking machine-readable and durable?

Yes. Provenance is embedded in a format-native metadata container and signed with post-quantum ML-DSA, and a resilient watermark plus perceptual fingerprint help the marking survive recompression, resizing, and re-uploading. Anyone can verify it for free, with no account.

Get started

Mark your AI content before the deadline

500 free signatures per month. No credit card required.