Strategy

    EU Article 50 marking versus the platform label

    The AI Act transparency duty is on providers and deployers. The TikTok/YouTube/Meta label is the platform's own detector. They are not substitutes.

    Versely Team6 min read

    Article 50 of the EU AI Act is a legal duty on providers and deployers of certain AI systems. The sparkle on a TikTok, the AI Info on a Reel, the altered-content note on a YouTube description — those are each platform's own detector and composer control. They started applying on different dates, they fire on different signals, and clearing one does not clear the other.

    C2PA is the technical path platforms already read. Stripping it on re-export does not cancel the legal duty. It only breaks the cooperative signal.

    This is a map, not legal advice. If a campaign has EU exposure, counsel reads Article 50 against the actual file and the actual deployer. The point of this page is to stop treating a platform badge as that reading.

    Two duties, two actors

    Article 50 has applied since 2 August 2026. The Commission's transparency FAQ and the text of Article 50 split the work by actor.

    Providers — the people who place the system on the market under their own name — must mark synthetic audio, image, video, or text in a machine-readable format so it is detectable as generated or manipulated (Art. 50(2)). They must also make it obvious when a person is interacting with an AI system, unless that would already be obvious to a reasonably well-informed user (Art. 50(1)). A limited runway to 2 December 2026 exists only for the 50(2) marking duty on systems already on the market before 2 August. It is not a general postponement of Article 50.

    Deployers — the people who use the system under their authority, which is most brands and creators — must disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest (Art. 50(4)). Emotion recognition and biometric categorisation have their own notice duty (Art. 50(3)). Artistic, satirical, and similar contexts get a more limited form of disclosure, not a free pass to present a fake as a record.

    If you generate a photoreal talking-head ad in a hosted studio and publish it in the EU, you are almost certainly a deployer of someone else's system. The provider was supposed to mark the bytes. You are still the one who has to label a deepfake at first exposure. Those are two different sentences on two different parties.

    A platform badge is not a legal substitute

    Instrument Who it binds What it proves
    Art. 50(2) machine-readable marking Provider of the generative system The file can be detected as synthetic
    Art. 50(4) visible deepfake label Deployer who publishes A person sees that this depiction is generated
    TikTok AIGC / auto-label TikTok's rules on TikTok TikTok applied or received a toggle
    YouTube altered-content / C2PA auto-label YouTube's rules on YouTube YouTube applied a player or description label
    Meta AI Info Meta's rules on Meta A file signal or a self-disclosure fired

    A TikTok label is evidence that TikTok's composer or detector ran. It is not evidence that a provider's marking was robust, interoperable, and still bound to the bytes, which is the 50(2) test. It is not evidence that a deployer put a perceivable deepfake disclosure in front of an EU viewer at first exposure, which is the 50(4) test.

    YouTube auto-labelling from C2PA metadata is the same kind of object: a platform reading a manifest when the manifest survives ingest. Platforms re-encode on upload. Why C2PA manifests die on upload is the mechanics. A label that never appeared because the hash broke is not "Article 50 complied by omission."

    C2PA is the path platforms already read

    Providers looking for a machine-readable mark that other companies will actually consume are, in practice, writing C2PA Content Credentials or an equivalent watermark-plus-manifest scheme. TikTok, YouTube, and Meta have all said they read those credentials when they are present. That is why C2PA keeps showing up in production meetings. It is not because the AI Act named C2PA. It is because it is the interoperability the platforms implemented.

    Use that fact in the right direction. Keep the manifest through your own export. Do not screenshot a generated still and call the PNG a new original. Do not treat a surviving credential as the deployer label — a cryptographic assertion in the file is not a caption a viewer can read.

    The Code of Practice on Transparency of AI-Generated Content is a voluntary implementation guide around Article 50(2), (4) and (5). Signing it does not replace the Act. Not signing it does not cancel the Act.

    Stripping the file does not cancel the duty

    Teams strip metadata because they have seen a surprise label on a real photograph, or because they have heard that labels hurt reach. Two problems.

    First, the provider's 50(2) duty is to make outputs detectable. If you are the provider, stripping is you breaking your own mark. If you are the deployer, stripping a mark the provider attached does not delete 50(4). The visible disclosure is still yours when the content is a deepfake.

    Second, the platform label you were trying to avoid is the wrong object. Originality, spam, and inauthentic-content policies are what move money and distribution. The badge is a transparency control. Burning the manifest to dodge it leaves you with a file that is harder to defend and no less synthetic.

    Keep the mark. Add the visible line when the law or the platform requires it. Do not use one as a broom for the other.

    FAQ

    If YouTube or TikTok labelled the video, have I met Article 50?

    No. Platform labels are each product's own detector and composer path. Article 50 binds providers and deployers under EU law. A badge on one app is not a filing that the machine-readable mark is intact or that a deepfake was disclosed at first exposure.

    Does C2PA by itself satisfy Article 50?

    It is the technical path most platforms already read, and it is how many providers attempt 50(2). It is not a visible deployer label, and it often dies on re-encode. Treat it as necessary machinery, not as the whole duty.

    Can I strip Content Credentials so the platform does not label me?

    You can break the hash. That does not cancel Article 50, it does not cancel photoreal self-disclosure rules, and it removes the signal platforms are actually built to trust. Keep the manifest.

    Who is the deployer when a brand runs ads generated in a studio?

    Usually the brand (and the agency acting for it) as the party publishing under its authority. The model host is the provider. Both duties can be in play on the same file. Do not assume the studio's watermark is the ad's legal disclosure.