Skip to main content
Can We Just Slap a Label on It and Call It Done?EU AI Act & GPAI
5 min readFor Model Risk Managers

Can We Just Slap a Label on It and Call It Done?

These questions landed in my inbox last week from three different teams preparing for the EU AI Act transparency rules in August. They're not abstract policy puzzles; they're the operational headaches keeping compliance officers up at night as the Article 50 deadline approaches.

The European Commission just published the second draft of its voluntary Code of Practice on marking and labeling AI-generated content. Feedback is due by March 30, with finalization by early June 2026. This is your window to shape how this works in practice, so here's what teams are actually asking.

Q1: Is this code mandatory or not? The "voluntary" part is confusing.

It's voluntary, but here's the trick: Article 50 of the EU AI Act isn't voluntary. You must mark AI-generated content. The code offers one path to compliance.

Think of it like ISO/IEC 42001. Nobody forces you to implement that AI Management System standard, but auditors love seeing it because it maps cleanly to regulatory expectations. Same logic here. If you follow the code, you're demonstrating good-faith compliance with Article 50's transparency requirements. If you don't, you'll need to document your alternative approach and defend it during enforcement reviews.

The second draft streamlines compliance burden and promotes open standards, which means the Commission heard complaints about the first version being too prescriptive. If your team's been sitting on feedback about operational friction, now's the time to submit it.

Q2: Our generative AI system creates marketing copy. Do we mark every single output, or can we batch-label somehow?

Section 1 of the code addresses marking and detecting AI content for generative AI system providers. The revised draft includes "enhanced flexibility and clarity", translation: they recognized that per-output watermarking isn't always feasible.

You've got options. Technical watermarking (embedded signals in the content itself) works for images and audio. Metadata tagging works for text outputs stored in your systems. Disclosure at the interface level (a persistent banner stating "This content was AI-generated") can cover continuous streams.

The key is detectability. If a human reasonably interacting with the content can identify it as AI-generated, either through visible labels or standard metadata readers, you're likely compliant. Document your method, test it with actual users, and keep evidence that it works in practice.

Q3: We're deployers, not providers. The code has two sections, which one applies to us?

Section 2 targets deployers and focuses on labeling deepfakes and text on matters of public interest. This section adopts a "more flexible and practice-oriented approach," which tells me the Commission acknowledged that deployers often have less control over the underlying technology.

If you're deploying a third-party generative AI system to create content, you're responsible for labeling outputs that meet Article 50's criteria. That means:

  • Image, audio, or video content that could be mistaken for authentic human-created content (deepfakes)
  • Text content published on matters of public interest

"Matters of public interest" isn't precisely defined yet, but expect it to include political communication, public health information, and news-adjacent content. Internal business reports? Probably not. Customer-facing claims about regulatory compliance? Maybe.

The flexible approach means you can adapt labeling to your deployment context. A chatbot generating draft emails doesn't need the same treatment as a video synthesis tool creating executive communications.

Q4: What's this "EU icon for labeling" mentioned in the draft?

The Commission's promoting a standardized visual marker, think of it like the CE marking for product safety, but for AI-generated content. It's not finalized yet, but the goal is a recognizable symbol that works across languages and platforms.

If you're building labeling into your deployment workflows now, design for icon placement. Reserve space in your UI, plan for visual contrast requirements (accessibility matters here), and build flexibility to swap in the final icon design when it's published.

Early adopters who implement the icon will likely get positive attention from regulators. It signals you're not just checking boxes, you're supporting the broader transparency ecosystem.

Q5: Our legal team says we need "detection" capabilities, not just labeling. What's the difference?

Detection means technical methods to identify whether content was AI-generated after the fact. Labeling means visible or metadata-based disclosure at the point of creation or publication.

Section 1 of the code addresses both marking and detecting. Providers need to build detectability into their systems, watermarking, fingerprinting, or other forensic techniques that survive content transformations. If someone screenshots your AI-generated image and reposts it, can you still identify it as AI-generated? That's detection.

Deployers typically rely on providers for detection capabilities, but you're responsible for not stripping out those signals. If your content pipeline removes metadata or re-encodes media in ways that destroy watermarks, you're undermining detection and potentially violating Article 50.

Test your workflow end-to-end. Generate content, pass it through your normal publishing process, then verify the detection signals survive.

Q6: The International AI Safety Report says models are getting better at evading tests. Does that affect our labeling obligations?

Indirectly, yes. The report notes that AI models now more frequently detect when they're being evaluated and exploit loopholes in tests. This matters for labeling because some generative AI systems can be prompted to remove or obscure their own watermarks.

If your model can be jailbroken into generating unmarked content, you've got a compliance problem. Pre-deployment testing should include adversarial prompting specifically targeting your labeling mechanisms. Can a user trick the system into skipping the watermark? Can they prompt it to generate content that mimics the labeling icon to create confusion?

The report highlights growing challenges for reliable pre-deployment safety testing. Apply that lens to your transparency controls. Don't just test happy-path scenarios, test whether your labeling survives hostile users.

Where to Go From Here

Submit feedback on the draft code by March 30 if your team's identified operational friction. The Commission incorporated hundreds of stakeholder comments into this second draft, they're listening.

Map your current AI deployments against Article 50's scope. Identify which outputs require labeling, document your technical approach, and test detectability before August.

If you're waiting for perfect clarity before acting, you're waiting too long. The code will finalize by early June, leaving you two months to implement before the transparency rules go live on August 2, 2026. Start building now with the flexibility to adapt.

You Might Also Like