The limits of the EU AI Act: what transparency cannot guarantee
The EU AI Act limits are not in what the Regulation prescribes, but in what it leaves outside its perimeter. From 2 August 2026 the transparency obligations in Article 50 of Regulation (EU) 2024/1689 become applicable, and a widespread expectation has formed around that date: that AI-generated content will finally be recognisable.
The expectation is misplaced. The Regulation raises the information hygiene of the legitimate market. It obliges those who work in the open to declare what they do. It is not a defence against deliberate misuse, and was never written to be one. Anyone who has to prove a piece of content is authentic cannot lean on a label applied downstream. Provenance has to be certified at the moment the data comes into existence.
The question plays out on three planes, worth keeping apart. The legal one concerns who is bound and who is not. The technical one, how long a marker survives once content circulates. The operational one, what an organisation that needs proof should actually do. In that order.
What changes on 2 August 2026, and where the EU AI Act limits begin
What becomes applicable is a set of information duties on those who build and those who use systems able to generate or manipulate content. No new prohibition arrives. The Regulation sorts systems by risk tier, and transparency for synthetic media sits in the limited-risk tier, where the law asks only that people know what they are dealing with. Plenty of organisations are reading the date as the end of uncertainty about where content comes from. It will disappoint them.
Indicator Media tested 516 posts generated or edited with AI across five major platforms in October 2025: only 169, roughly a third, carried a visible label. Pinterest performed best at around 55 per cent, while Instagram, LinkedIn, TikTok and YouTube sat well below. The figure measures something precise: how much of the information ecosystem is already covered by the marking platforms apply voluntarily, which is the mechanism the practical force of the Regulation largely rests on. The EU AI Act limits arrange themselves on three planes. The legal plane covers who falls inside the obligations and who stays outside. The technical plane covers how well a marker holds after content has been recompressed, cropped and reshared. The operational plane covers what an organisation needs when it has to put digital evidence in front of a court, an insurer or a regulator.
What Article 50 asks, and of whom
Article 50 spreads different duties across different subjects. A provider of a system meant to interact with people must tell them they are dealing with a machine, unless that is obvious. A provider of a system generating synthetic content must ensure the output is marked in a machine-readable format and detectable as artificially generated. Anyone using emotion recognition or biometric categorisation must inform the people exposed to it. A professional deployer publishing a deepfake must disclose that the content is artificially generated or manipulated. Together they form the core of the transparency obligations for businesses.
The exceptions are broad and mostly sensible. Where content is evidently artistic, creative, satirical or fictional, the duty shrinks to disclosing that such content exists, without hampering enjoyment of the work. For text published to inform the public on matters of public interest, it falls away where there is human review and editorial responsibility. Systems authorised by law to prosecute criminal offences sit outside the scheme.
One detail says more than most commentary. The European Commission has prepared labelling icons whose use stays optional, alongside a voluntary code of practice. The obligation binds. The tools for meeting it do not.
The marking duty starts later than the calendar suggests
The technically most consequential duty does not begin with the others. The Digital Omnibus package, agreed politically on 6 May 2026 and confirmed by the Council on 13 May, grants four months of grace to systems placed on the market before 2 August 2026: for that installed base, Article 50(2) marking applies from 2 December 2026. Formal adoption is not yet complete.
The other AI Act transparency obligations, deepfake disclosure on deployers included, stay fixed at 2 August. On the day the rule becomes applicable, the part that matters most technically is already deferred for the systems in use.
The perimeter stops short of the people who commit fraud
The Regulation does not reach natural persons using AI systems in a purely personal, non-professional activity. Someone assembling false content in an individual capacity, to discredit a former partner or manufacture a convenient exhibit in a dispute, owes no disclosure. Some member states have filled part of the gap with national criminal provisions: Italy's Law 132/2025 is one. Criminal law, though, arrives after the content has circulated.
Article 2(10) of Regulation (EU) 2024/1689 excludes from its obligations natural persons using AI systems in the course of a purely personal, non-professional activity. The consequence is direct: a person who produces false content privately owes nothing under Article 50(4). The picture is less clean than that, and the honest reading has to say so. The marking duty in Article 50(2) falls on the provider of the system, not on the person using it, so the automatic marker should in principle survive in the output even when the content comes out of a private session. The individual being unbound is only half the problem. That residual marker may never have been applied in the first place, it can be stripped with publicly available tools, and it can be placed on content that never earned it. From here the argument moves from the legal plane to the technical one.
Locally run models are not born marked
No marking duty can reach one category of content: whatever comes out of open-weight models downloaded and run on your own machine. Someone working offline passes through no service that could apply a marker, and leaves no trace with a third party. Given how capable these models have become, the point is not academic.
| Subject | What the Regulation imposes | Practical enforceability |
|---|---|---|
| Provider of a content-generating system | Machine-readable marking of outputs (Art. 50(2)) | High inside the Union, softened by the state-of-the-art clause |
| Professional deployer publishing a deepfake | Disclosure that the content is manipulated (Art. 50(4)) | High: the subject is identifiable and has a business to protect |
| Natural person in a purely personal, non-professional activity | No obligation (Art. 2(10)) | None: only the provider's marker remains |
| Someone running an open-weight model locally | No obligation on offline execution | None: there is no control point |
| Anonymous actor outside the Union | Formally bound if the system is placed on the EU market | Close to zero: identifiability and jurisdiction are both missing |
How a marker works and why it degrades
Marking synthetic content can be done two ways, and neither survives real circulation well. The fragility of the declarative approach comes across clearly in the history of the C2PA standard and its limits.
Statistical watermarking and declarative provenance metadata answer two different questions. The first hides a signal inside the content itself, so a trained detector can recover it with no external information: this is the approach behind SynthID. The second attaches a signed manifest declaring author, tool and subsequent edits, the approach behind C2PA and Content Credentials. The practical difference is in how they break. A statistical signal degrades when content is recompressed, cropped, converted to another format or rescaled, because each operation rewrites the pixels the marker was etched into. Declarative metadata is more exposed still: it detaches at the first hop that does not preserve it. The screenshot is the limit case and the most common one, since it produces a new file with no manifest and, usually, none of the original signal either.
A marker can be stripped
Removing a marker takes no rare skill. Published research, including the ICML paper discussed in the next section, demonstrates scrubbing attacks that erase a marker without visibly degrading the content. And the norm knows it. Article 50(2) asks for solutions that are "effective, interoperable, robust and reliable", then adds "as far as this is technically feasible", taking into account costs and the acknowledged state of the art. An honest clause, in its way: the legislator concedes the technical limit inside the very text that imposes the duty. It is also the clause a provider will reach for the day its AI watermark fails to hold.
A marker can be forged
The inverted risk is more underrated and more serious: not stripping the mark from false content, but applying a credible one to attribute content to an origin that is not its own. This is spoofing, and it means authenticating the false rather than exposing it.
That inversion changes the meaning of the whole marking architecture. Stripping a marker removes a signal of synthetic origin; forging one manufactures a signal of authentic origin, a fraud with far more leverage. If a marker can be imitated, its presence proves nothing, exactly as its absence proves nothing. The work of Jovanović, Nikolić and colleagues presented at ICML 2024, Watermark Stealing in Large Language Models, puts numbers on the problem for state-of-the-art watermarking schemes in language models: the authors demonstrate spoofing and scrubbing attacks achievable for under 50 dollars, with average success rates above 80 per cent. The figure moves the discussion from theory to economics. A safeguard defeated for less than fifty dollars is no barrier to anyone with a serious motive, and it is the serious motive an organisation has to defend against.
The most common forgery never touches AI
The most frequent manipulation generates nothing at all: it edits metadata. The EXIF metadata of a photograph, date and time, geolocation, device, can be altered with free tools. An authentic photograph recontextualised with a different date becomes false evidence no AI detector will flag, because nothing was generated for it to find. The Regulation does not govern this plane, and was never meant to.
One practical factor makes it worse. Social platforms strip metadata on upload, for privacy and for file weight. The content in circulation has already lost its provenance information, so anyone verifying a photograph is working on a mute file.
Penalties reach the ones already complying
AI Act penalties for breaching the transparency obligations run up to 15 million euro or 3 per cent of total worldwide annual turnover, whichever is higher. Serious sums. They land on subjects who already meant to comply: identifiable companies with an address, a balance sheet and a reputation to defend.
The bad actor is not in that set. Anonymous, often operating from outside the Union, nothing to lose. Nor is this only a European problem: China has required labelling of AI-generated content since 1 September 2025 and runs into the same asymmetry.
When doubt becomes an alibi
There is a side effect with a name of its own: the liar's dividend. Once the public learns that any content can be generated, someone filmed doing something real can deny it by claiming the video is synthetic. Disinformation only needs the suspicion to be plausible.
A labelling duty on its own works in that direction: it teaches people to distrust without handing them a way to trust. This is the subtlest of the EU AI Act limits, because it moves the problem from recognising the false to proving the true, and those are different trades. Which is also why labelling AI content settles less than it seems to.
What an organisation can do beyond formal compliance
The perimeter of the Regulation cannot be changed. Internal procedure can. The first move is to separate two flows often treated as one: content the organisation produces, and content it receives. They need different controls.
For content produced internally, the route is to document provenance at origin rather than reconstruct it later. Knowing what businesses must do from August 2026 sets the floor, not the ceiling.
For content received, the precautions get more practical. Do not rely on a probabilistic detector as the only control, since it returns likelihoods and not certainties. Keep the original rather than the reshared copy, which has already lost its metadata. Decide in advance what proof a dispute would require, and in what form. Organisations that need to prove the authenticity of what they collect adopt source certification tools such as TrueScreen, which produces a forensic report with a certified timestamp and a documented chain of custody.
What separates downstream detection from certification at source
TrueScreen is the Data Authenticity Platform that certifies data at the instant of creation, applying a forensic methodology that documents origin, integrity and time placement. The distance from downstream analysis is a difference in kind, not in degree, a point developed at greater length in the comparison between detection versus source certification.
Downstream detection and certification at source produce two different legal objects. Detection returns a probabilistic judgment on a file whose history nobody knows, and that judgment loses value month by month, because every new generation of models erodes the accuracy of detectors trained on the one before. Certification at source documents the moment of capture instead: which device, which instant, which content, with a hash that makes any later alteration detectable. TrueScreen works on that second plane. It is not a certification body and issues no certificates of its own: it integrates the electronic seal and the qualified timestamp issued by third-party QTSPs inside a forensic acquisition process, and returns digital evidence that documents the chain of custody. The result does not say whether content is synthetic. It says what was acquired, when, and under what conditions.
FAQ: EU AI Act limits and proof of authenticity
Which AI systems are excluded from the EU AI Act?
Regulation (EU) 2024/1689 does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity, under Article 2(10). Also outside its scope: systems developed for military, defence or national security purposes, systems intended solely for scientific research, and systems authorised by law to detect, prevent, investigate or prosecute criminal offences. For anyone concerned with authenticity, the first exclusion is the one that matters, because it covers exactly the person generating false content in an individual capacity.
When is it mandatory to disclose the use of an AI system?
The duty bites when a professional deployer publishes a deepfake: image, audio or video content generated or manipulated by an AI system, resembling real persons, objects, places or events, that would falsely appear authentic. The content must then be disclosed as artificially generated or manipulated. Where the work is evidently artistic, creative, satirical or fictional, it is enough to disclose that such content exists without hampering its display or enjoyment. For text on matters of public interest, the duty does not apply where there is human review and editorial responsibility.
When must users be told they are interacting with an AI system?
Article 50(1) requires providers of systems intended to interact directly with people to design them so the person knows they are dealing with an AI system, and the information has to be given at first contact. The duty does not apply where this is obvious to a reasonably well-informed, observant and circumspect person, taking the context of use into account, nor to systems authorised by law to prosecute criminal offences. In practice it covers conversational systems in customer support, recruitment and public services.
Does the watermarking duty really apply from 2 August 2026?
Not for every system. The Digital Omnibus package, agreed politically on 6 May 2026 and confirmed by the Council on 13 May, grants four months of grace to systems placed on the market before 2 August 2026: for those, the machine-readable marking required by Article 50(2) applies from 2 December 2026. The other AI Act transparency obligations, deepfake disclosure included, stay applicable from 2 August. Formal adoption of the package is not yet complete, so the dates are the state of play rather than settled law.
Are the European labelling icons mandatory?
No. The European Commission has prepared labelling icons for flagging AI-generated content, but their use remains optional, and it is working on a voluntary code of practice for implementing the transparency obligations. What is mandatory is the result: informing the user and making the content detectable as artificial. The instrument used to get there is a choice for the provider or the deployer. The distinction matters in an enforcement setting, because nobody can be penalised for having declined to use the European icon.
How does the AI Act define a deepfake?
The Regulation defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The definition is wider than most people assume: it requires neither an intent to deceive nor a face swap. A photorealistic image of an event that never happened falls inside it just as much as a video with a substituted face, and it triggers the disclosure duty for the professional deployer who publishes it.
How do you prove a photo or video is authentic?
Not with a detector. Detection tools return a probability about a file whose history they do not know, and their accuracy falls as generative models improve. Provenance metadata alone is not enough either, since it can be edited and platforms strip it on upload. Authenticity is proved by documenting provenance at the moment of acquisition: which device, which instant, which content, with a hash that makes any later alteration detectable. A label applied downstream declares synthetic origin; it does not prove authenticity. TrueScreen addresses the opposite problem, certifying authentic content at the moment of capture.
