Synthetic Media Disclosure (EU AI Act)
Synthetic media disclosure refers to Article 50(2) of the EU AI Act: the general requirement that providers of AI systems generating synthetic audio, image, video, or text mark their outputs in a machine-readable format that is detectable as artificially generated or manipulated. It's broader and provider-facing, distinct from the deployer-facing deepfake disclosure duty in Article 50(4). This page is general information, not legal advice.
What Article 50(2) actually requires
The obligation sits with providers — the organizations building or offering the generative AI system — rather than the people or businesses using it. Providers of systems that generate synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated, and that the marking solutions used are technically robust, reliable, and interoperable, to the extent technically feasible. This is a marking-at-source obligation: it's about how the content is produced, not a downstream disclosure statement shown to an end user.
Exceptions
The marking duty doesn't apply to assistive editing functions that don't substantially alter the input data a user supplies, or to AI systems authorized by law for detecting, preventing, investigating, or prosecuting criminal offenses. Beyond that, the obligation is broad by design — it covers any provider whose system generates synthetic media, regardless of whether the output ends up being used to create anything resembling a deepfake.
How machine-readable marking maps to provenance tooling
A machine-readable mark that's technically robust and reliable is close to a description of a cryptographically verifiable provenance record: something a machine, not just a human eye, can check, that survives ordinary handling, and that can't be trivially forged. Certivu's signed tokens, embedded metadata, and resilient watermarks are built to satisfy that kind of technical marking, though whether a specific implementation satisfies Article 50(2) for a given provider is a compliance judgment outside Certivu's scope to make.
Source: Regulation (EU) 2024/1689, Article 50
FAQ
Who has to comply with Article 50(2) — the AI company or the person using it?
Providers — the organizations that build or offer the generative AI system — are responsible for marking its outputs. This is different from Article 50(4)'s deepfake disclosure duty, which falls on deployers using the system.
Does Article 50(2) require a visible watermark on every AI image?
It requires marking that is machine-readable and detectable as artificially generated, not necessarily a visible watermark a human eye would notice. Invisible cryptographic or frequency-domain markers can satisfy the machine-readability intent, provided they meet the robustness and reliability standard the article sets out.
How is this different from deepfake disclosure?
Article 50(2) is a provider obligation to mark synthetic outputs at the point of generation, applying broadly to any synthetic audio, image, video, or text. Article 50(4)'s deepfake disclosure is a narrower, deployer-facing duty to actually disclose to an audience that specific deepfake content — or public-interest text — is artificially generated.