The EU transparency code of practice is voluntary
Roughly 190 organisations signed the transparency code finalised on 10 June 2026. The Article 50 duties beneath it bind signatories and non-signatories alike.
The European Commission's Code of Practice on Transparency of AI-Generated Content was finalised on 10 June 2026 and has been signed by roughly 190 organisations. Every one of those signatures is optional. None of the obligations the Code operationalises are.
That gap is where most of the confusion sits. Coverage of the Code tends to describe signing as though it were the compliance event, which produces two opposite errors: vendors treating a signature as a finished job, and buyers treating the absence of one as evidence of a problem. Neither reading survives contact with how the instrument actually works.
What the Code is, structurally
The Code is a voluntary instrument that maps onto the transparency duties in Article 50 of the AI Act. It splits along the same line the article does — one section for providers of generative AI systems, covering the machine-readable marking of output, and one section for deployers, covering disclosure and labelling of deepfakes and certain AI-generated public-interest text to the audience.
Signing is section-by-section. An organisation signs the part that corresponds to its actual role, and the two populations look structurally different: the provider section draws model companies, while the deployer section draws publishers, brands and businesses that use AI content rather than build it. Which section applies to you follows the same test as the statute, walked through in where a creator actually sits in the transparency code.
What matters for this post is the layer beneath: the Article 50 duties existed before the Code, apply to organisations that never sign it, and would continue to apply if the Code were withdrawn tomorrow.
What signing does buy
The value is real, it is just not legal immunity.
A worked specification. "Mark output in machine-readable form" is a sentence. A team has to turn it into a decision about metadata schema, watermark strength, what happens on re-encode, and what an export contains. The Code is the closest thing to an agreed answer, produced with the Commission rather than by one vendor.
Predictability with the regulator. Adhering to a Commission-facilitated code is a documented, recognised way to demonstrate how you are meeting an obligation. That is a meaningfully better position than an internal policy nobody outside your company has seen.
A common vocabulary with clients. Procurement questionnaires are converging on the Code's language. Being able to answer in the same terms shortens a lot of conversations.
Visible commitment. For a provider selling into the EU, the signature is a market signal about roadmap intent. That is worth something even though it is not worth what a safe harbour would be.
A set of disclosure conventions. The Code arrived alongside official EU disclosure iconography intended to make labels legible across languages and contexts — the three EU AI disclosure icons covers what each one is for and where using them helps.
What signing does not buy
| Claim | True? | Why |
|---|---|---|
| Signing makes you compliant with Article 50 | No | The Code is a route to demonstrating compliance, not a substitute for the duty |
| Not signing is a violation | No | The Code is voluntary; the statute binds either way |
| Signing moves a deadline | No | Application dates come from the Act, not the Code |
| Signing covers platform policy | No | YouTube, Meta and TikTok rules are contract, and change without notice |
| Signing helps with likeness or publicity claims | No | Different body of law entirely, and the fastest-moving risk area |
| A signature tells you what a vendor's exports contain today | No | It tells you what they have committed to, not what shipped |
The last row is the one worth dwelling on if you are a buyer. A signature is a statement of intent by an organisation, made at a point in time, about a programme of engineering work. It is not a test result. The useful procurement question is not "did you sign" but "what does an export from this specific model contain today, and can I verify it."
Why a voluntary code exists at all
The obvious question is why the Commission would spend a year facilitating an instrument nobody has to sign.
The answer is that the underlying obligation is technically underdetermined. "Machine-readable marking" does not specify a technique, and no single technique currently on the table survives a real distribution pipeline on its own. A content credential manifest is a hard binding to a file: any re-encode, format conversion, screenshot or edit in a non-aware tool invalidates it, and major social platforms re-encode on ingest as a matter of routine. Durable approaches layer an invisible watermark and a perceptual fingerprint alongside the manifest so that something survives recompression — and even that stack is defeated by heavy crop, deliberate removal, or a fingerprint database you cannot reach.
A statute cannot sensibly freeze a technical answer into law while the answer is still moving. A code can be revised. That is the trade: the Code carries the detail, the Act carries the force, and the detail is expected to change faster than the force.
For anyone shipping files rather than drafting policy, the practical consequence is the same either way. Provenance data is a compliance aid, not proof, and your pipeline determines whether any of it survives. Sign, strip, survive walks the chain step by step.
What this means if you publish rather than build
If you are an agency, a brand or a creator, three things follow.
- Your duty was never conditional on the Code. The deployer-side label — a perceivable synthetic media disclosure delivered at first exposure — applies to you whether or not you or your vendors signed anything.
- Signing is probably not your decision to make. The deployer section is signed by organisations, and for a two-person studio the meaningful work is the label on the video, not a signature on an instrument.
- The platform layer is separate and stacks. The AI content label toggle is contract law between you and a platform, unaffected by the Code. One disclosure, five destinations is the per-destination checklist.
There is a fourth, quieter point. Voluntary industry instruments are becoming a standard shape in this space, and they are consistently better at describing intent than at describing current behaviour. The same caution applies to licensing announcements: a signed deal or a public commitment is not the same as a verified state of the world, which is the argument in a label deal is not a cleared model. Apply the same discount rate here.
How to evaluate a vendor's transparency posture
A short list that beats checking a signatory roster:
- Ask what a finished export contains — metadata fields, watermark, or both — for the specific model you would use, not for the platform in general.
- Ask whether marking survives their own render and download path, or only the raw generation.
- Ask which of their systems were on the market before 2 August 2026, because those are the ones whose marking behaviour is most likely to change over the coming months.
- Check the file yourself rather than taking the answer. Verification tooling is becoming an obligation on large providers in California, which makes independent checking realistic rather than aspirational.
- Separate the transparency answer from the training-data answer. They are different questions with different documents behind them, and a good answer on one implies nothing about the other — licensed training data as a buying criterion covers the second.
FAQ
Is the Code of Practice legally binding?
No. It is voluntary. The Article 50 transparency obligations it operationalises are binding on providers and deployers regardless of whether they sign.
Does signing protect a company from enforcement?
It does not create immunity. Adherence to a Commission-facilitated code is a recognised way to demonstrate how an obligation is being met, which is useful in a regulatory conversation, but the obligation itself is assessed against the Act.
Should a small agency sign the deployer section?
For most small studios the practical answer is that the label on the asset matters more than the signature. If a client's procurement process asks about it, the section-by-section structure means you would be committing only to the deployer half.
If a vendor has not signed, should I avoid them?
Not on that basis alone. A signature is a commitment, not a measurement. Ask what their exports actually contain and verify it — that answer is far more informative than a roster entry.