The 2 August change belongs in the purchase order

Article 50 of the EU AI Act began to apply on 2 August 2026. The European Commission's final guidelines clarify duties for systems that interact directly with people, providers of systems generating synthetic content, deployers of emotion recognition or biometric categorisation, and professional deployers publishing deepfakes or certain AI-generated public-interest text. The Commission says enforcement can include fines up to €15 million or 3% of total worldwide annual turnover, with proportionality for smaller companies.

This does not turn every AI-assisted frame into a deepfake or require the same label on every deliverable. It does change the buying question. A brand can outsource production, but it cannot treat the supplier's tool choice as the whole transparency system. The contract needs to allocate who is the provider, who is the deployer, who classifies the final use, who verifies machine-readable marking, who approves an audience-facing disclosure, and who preserves the proof.

The Code of Practice is voluntary. The Commission and AI Board have assessed it as an adequate way for signatories to demonstrate compliance with the relevant marking and labelling duties, but adherence is not conclusive proof that any particular delivery is compliant. Non-signatories can use other adequate means. Buyers therefore need evidence at asset level rather than a logo, policy statement, or generic assurance in a pitch deck.

Map the legal role before mapping the workflow

The final guidance draws a useful line around the deployer. A legal person using an AI system under its authority for professional activity is the deployer. Employees working under its control are not separate deployers, and contractors or freelancers operating on its behalf do not automatically take that responsibility away. For an advertising company commissioning a freelancer to operate a model inside the company's process, the company can remain the deployer.

That makes the first supplier question structural: under whose authority is each system being used? A production company may be the deployer for development and production, while a brand becomes the deployer for a consumer-facing avatar or campaign it operates. A vendor that develops or commissions a branded system and places it on the EU market under its own name may also act as a provider. The same organisation can carry more than one role.

Put a one-page role map in the statement of work. Name the system provider, model provider where different, professional deployer, commissioning client, publisher or platform, target markets, final audience and accountable owner. Add a change rule: if the use moves from an internal animatic to a public advert, from a human-mediated service to a direct chatbot, or from a fictional composite to the likeness of a real person, classification and approval reopen before publication.

European Commission illustration for provider obligations in the AI-generated content transparency code
Section 1 of the EU transparency code addresses provider-side marking and detection obligations. Official European Commission artwork from its Code of Practice materials.

Ask the system provider for a marking and detection sheet

Providers of generative AI systems must ensure relevant synthetic audio, image, video and text outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The standard is not merely that metadata exists somewhere. The Act calls for solutions that are effective, interoperable, robust and reliable as far as technically feasible, taking account of content type, implementation costs and the generally acknowledged state of the art.

A buyer should request a short technical sheet for every approved system: product and model version, EU market status, whether the provider has signed Section 1 of the code, the marking technology used, supported output formats, where the signal is stored, how it is validated, known transformations that remove or weaken it, detection instructions, retention or lookup dependencies, and the date the evidence was last tested. If a platform aggregates third-party models, the answer may differ by model and export path.

Do not accept 'C2PA supported' or 'watermarked' as a complete response. Run a sample through the actual pipeline: generation, edit, transcode, colour, audio mix, captioning, localisation, ad platform and download. Record whether the mark is present and valid at each boundary. Provider-side marking does not replace a deployer's visible or audible disclosure where Article 50(4) applies, but a broken mark is still a supplier and workflow defect worth discovering before release.

Classify the final output and the audience context

The Commission's Article 50 questions and answers make the production boundary more concrete. Outputs used only inside closed-loop film development can fall outside provider marking unless they are the final output. Standard editing assistance can also sit outside the marking duty. For deepfake assessment, the final guidelines ask whether the work resembles an existing or plausibly existing person, object, place, entity or event and could falsely appear authentic or truthful in its intended context.

Audience expectation therefore matters. Background generation, visual effects and technical pre- or post-processing inside an evidently fictional film are not automatically treated like a fabricated recording of a real event. Evidently artistic, creative, satirical or fictional works can use an appropriate disclosure that does not hamper enjoyment. But the exception should not become a blanket 'creative work' checkbox: a synthetic testimonial, cloned executive voice, generated property view, reconstructed news event and fictional creature carry different claims about reality.

Require an asset-level classification memo for every final-facing use. It should state the real subject represented, substantive message, target audience and channel, foreseeable interpretation, whether the work can appear authentic or truthful, whether it is evidently fictional or analogous, any standard-editing rationale, and the chosen marking and disclosure treatment. Use in scope, out of scope with reason, and escalate as explicit states. Counsel should settle difficult scope questions; production should make sure the answer follows the asset into delivery.

European Commission artwork representing transparency requirements for AI systems
Article 50 separates provider-side system transparency from deployer-side disclosures to the people encountering the output. Official artwork via the European Commission's AI transparency guidance.

Make the evidence pack a contractual deliverable

The pack does not need to expose every exploratory prompt or a supplier's proprietary craft. It needs enough structured evidence for the buyer to understand, approve, publish and later retrieve the production decision. At minimum, include the asset ID and file hash; brief and intended use; provider, deployer and publisher map; system, model and version; source references and their rights or consent status; generation and material edit history; final-output classification; machine-readable marking test; audience disclosure wording and placement; named reviewers; approved derivatives; delivery date; and live proof.

For AI-generated public-interest text, record the substantive human review or editorial control and the person or organisation holding editorial responsibility. The Commission says superficial checks such as spelling or grammar are not enough for the exemption. For deepfakes, preserve proof that a clear and distinguishable disclosure reached the person by first exposure. Embedded metadata alone cannot fulfil that deployer duty.

Treat the disclosure like versioned creative, not boilerplate. The EU icon set is optional, and the Commission says an icon alone does not establish compliance. Its user testing found better performance when a basic icon was paired with text. Save the approved language, location, duration, accessibility treatment and localisations, then connect each exported derivative to that decision.

European Commission illustration for the Code of Practice on Transparency of AI-Generated Content
The voluntary code gives providers and deployers a recognised operational route for demonstrating Article 50 marking and labelling compliance. Official European Commission artwork from the transparency Code of Practice.

Test one delivery before scaling the supplier

Choose a real asset already moving through the production schedule. Ask the supplier to retrieve its evidence pack without calling the original operator. Validate the machine-readable signal in the delivered master, then inspect the files or live placements the audience actually receives. Check the 16:9 master, vertical crop, short cutdown, thumbnail, captioned version, localisation, broadcaster or ad-platform transcode and downloadable file separately.

Score the exercise on retrieval time, missing fields, marking survival, disclosure survival, approval clarity and whether every derivative resolves to the same asset record. A supplier that can produce attractive work but cannot reconstruct the decision is still in prototype mode. A buyer that receives a good pack but loses it in email is also not operating a production system. Store the record beside the approved master with a retention owner and expiry or review date.

Add four clauses to future briefs: notification before changing a model or marking method; evidence-pack delivery as a condition of final acceptance; correction and re-delivery when a mark or disclosure is lost; and cooperation if a regulator, platform, client or audience challenge requires retrieval. Then measure first-pass evidence completeness alongside creative approval. The mature supplier is not the one that promises compliance in the abstract. It is the one that can make the finished work, its decisions and its public treatment legible after the launch team has moved on.

Build

Make compliance evidence part of delivery

Build the asset records, review gates and supplier handoffs that keep AI provenance and disclosure attached to the work.

Build an accountable AI production systemSend a brief

Keep reading

European Union black and white label reading AI GeneratedAI Production Systems / 9 min readThe EU AI Act Turns AI Labelling Into a Production WorkflowContent Credentials official flow graphic showing how a provenance signal travels with mediaCommercial AI Safety / 8 min readAI Provenance Is Now a Review Workflow, Not a LabelAdobe Firefly Video Model interface image from Adobe's official Firefly Video Model announcementCommercial AI Safety / 7 min readCommercially Safe AI Video Is a Production Standard, Not a Badge