
Blog Post
The AI Marking Deadline That Applies Only to Systems Already Running
October 1, 2026
Transitional relief normally works one way. A new rule arrives, existing products are carved out or given years, and anything built afterwards complies from the start.
The marking obligation for synthetic content inverts that. Article 50 has applied since 2 August 2026, and a targeted transitional period gives extra time to systems that were already on the market rather than to new ones. Two identical products from the same provider have different deadlines depending only on when each reached the market.
Who Gets the Extra Time?
The installed base only, which is the reversal worth understanding before assuming it applies to you.
Providers of generative systems placed on the market or put into service before 2 August 2026 have until 2 December 2026 to bring machine-readable marking into conformity. Anything placed on the market on or after that August date carries the obligation immediately, with no transition at all.
Which Creates an Odd Incentive on Release Timing
A product held back past early August lost four months of grace it would have inherited by shipping earlier. Nobody schedules a launch around a transitional provision, and the consequence is real for anything that slipped across that date.
Does the December Date Cover All of Article 50?
No, and this is the misreading that leaves obligations already overdue.

The transition is the only one inside the article and it covers the marking paragraph alone. Disclosure that a person is interacting with an AI system, notice for emotion recognition and biometric categorization, and labeling of deepfakes and certain public-interest text all took effect in August with no transitional period.
Three Duties Are Already Live
An organization that read the December date as an Article 50 deadline has three obligations running now and one arriving later. The December work is the narrow technical piece, and the disclosure obligations were the ones with no runway.
What Does Marking Require?
Two things, and the second gets forgotten because the first has a name.
Outputs generating or manipulating synthetic audio, image, video or text have to be marked in a machine-readable format and detectable as artificially generated or manipulated. Alongside that sits a detection obligation, requiring providers to make available a mechanism through which people, authorities, researchers and fact-checkers can verify the origin of content.
Which Makes Marking Half the Duty
A watermark nobody can check satisfies the marking requirement and not the detection one. Signatories to the voluntary code on this topic committed to offering a watermark detection interoperability solution by February 2027, which indicates where the practical standard is heading.
What Does the Code of Practice Say?
It supplies the technical answer the statute withheld, which matters because the article never defined what counts as machine-readable.

The code published in June 2026 endorses a layered approach, pairing cryptographically signed and timestamped provenance metadata with imperceptible watermarking, and optional fingerprinting through a registry. Around a hundred and ninety organizations had signed by the end of July.
Is Signing Necessary?
No, and the code is voluntary. Its value is that it defines a defensible interpretation of an undefined term, so a provider using a different technique should record which technique it chose, why that fits the state of the art, and how it establishes the marking works, and records that survive an audit is the property that reasoning needs.
What Is the Real Work?
Finding the paths output leaves by, which is where a fourteen-week retrofit becomes an eight-month one.
Marking a generation endpoint is straightforward. Establishing that every route synthetic content takes out of the system passes through that marking is the part nobody scopes. An interface, a download, an API, a batch export, a webhook and an integration are six paths, and instrumenting one of them is a common starting position.
Which Makes It an Inventory Exercise First
Enumerate the egress paths before choosing a technique, since the technique has to survive whatever transformation each path applies. A watermark that does not survive re-encoding on a download route is absent on that route, and getting the unit right in an inventory is the same discipline applied to systems.
What Else Arrives on That Date?
New prohibitions, which is worth knowing because they sit in a different part of the Act and carry the highest penalties.
Regulation (EU) 2026/1744 added prohibited practices covering the use of AI for child sexual abuse material and non-consensual intimate content, and those apply from the same December date. Prohibited practices carry the top penalty tier rather than the transparency tier.
Which Reaches Generative Image Systems Directly
A provider of a generative image system has a marking deadline and a new prohibition landing together, and the second is the more serious. Anything permitting that category of output needs addressing on its own terms rather than as part of the marking program.
Is This Only a European Requirement?
No, and treating it as one is how the same capability gets built three times.
Content provenance requirements have appeared in more than one jurisdiction, with a California transparency statute and a Connecticut provenance requirement arriving on their own timetables through 2026. The technical answer is the same in each case, being signed provenance metadata and a durable mark that survives the paths content travels.
Which Argues Against a Jurisdictional Project
A program scoped to one regulation produces a capability scoped to one regulation. Building the provenance layer once and mapping it to each requirement is cheaper than building for Brussels and then again for Sacramento, and normalizing one control set across frameworks is the same reasoning applied to security controls.
What Should Not Depend on the Marking?
High-consequence authentication. Provenance metadata is a positive signal inside a controlled pipeline that preserves it, which describes an internal workflow rather than the open internet. Payment authorization, evidentiary material and anything relying on establishing that content is genuine needs an independently authenticated channel, since absence of a mark proves nothing.
What Should Be Established?
Four things, and the first decides whether December is a deadline for you at all.
Which systems you provide that generate synthetic output, and whether each reached the market before or after 2 August 2026, since that single fact determines the date. Every path output leaves by, because marking one is not marking the system. Whether a detection mechanism exists alongside the marking. Then which of the three disclosure obligations already apply to you, since those have no transition and have been live since August. AI compliance readiness assessed per requirement is what separates the four.
The Grace Went to the Installed Base
The marking obligation inverts the usual pattern, giving four months of transition to generative systems already on the market while anything placed on the market from August 2026 complies immediately. So two identical products differ only by when each reached the market. The transition is the only one inside the article and covers marking alone, so the chatbot disclosure, the emotion recognition notice and the deepfake labeling have been live since August with no runway. Marking is half the duty, since a detection mechanism has to accompany it. The real work is also enumerating every path synthetic output leaves by, because marking a generation endpoint is not marking a system. Kovrr's AI Security and Governance Platform establishes which systems generate output and where that output goes.
To see which systems generate synthetic output and every path it leaves by, book a demo mapped to your own estate.
Content Marking Deadline FAQs
Speak to an ExpertWhen does the EU AI Act watermarking deadline apply?
It depends on when the system reached the market. Providers of generative systems placed on the market or put into service before 2 August 2026 have until 2 December 2026 to bring machine-readable marking under Article 50(2) into conformity. Anything placed on the market on or after that August date carries the obligation immediately with no transition, so two identical products from the same provider can have different deadlines.
Does the December 2026 deadline apply to all of Article 50?
No, and this is the misreading that leaves obligations overdue. The transition is the only one inside the article and it covers the machine-readable marking paragraph alone. Disclosure that a person is interacting with an AI system, notice for emotion recognition and biometric categorization, and labeling of deepfakes and certain public-interest text all took effect in August 2026 with no transitional period at all.
What does machine-readable marking require under the AI Act?
Two things. Outputs generating or manipulating synthetic audio, image, video or text have to be marked in a machine-readable format and detectable as artificially generated or manipulated. Alongside that sits a detection obligation requiring providers to make available a mechanism through which people, authorities, researchers and fact-checkers can verify the origin of content, so a watermark nobody can check satisfies only half the duty.
What is the Code of Practice on Transparency of AI-Generated Content?
A voluntary instrument published in June 2026 that supplies the technical answer the statute withheld, since the article never defined what counts as machine-readable. It endorses a layered approach pairing cryptographically signed and timestamped provenance metadata with imperceptible watermarking, and optional fingerprinting through a registry. Around a hundred and ninety organizations had signed by the end of July 2026, and signatories committed to offering detection interoperability by February 2027.
What is the hardest part of retrofitting content marking?
Enumerating the paths output leaves by rather than applying the marking. Marking a generation endpoint is straightforward, while establishing that every route synthetic content takes out of the system passes through that marking is the part nobody scopes. An interface, a download, an API, a batch export, a webhook and an integration are six paths, and the technique also has to survive whatever transformation each path applies.
What else arrives on 2 December 2026?
New prohibited practices. Regulation (EU) 2026/1744 added prohibitions covering the use of AI for child sexual abuse material and non-consensual intimate content, and those apply from the same December date. Prohibited practices carry the top penalty tier rather than the transparency tier, so a provider of a generative image system has a marking deadline and a more serious prohibition landing together.




