Ask a vendor how to comply with the AI Act’s marking requirement and you will be sold a marking product. Ask an engineer who has traced a single asset from model output to published page, and you will get a different answer: the mark was probably applied correctly and then destroyed somewhere in the middle by infrastructure that nobody thought of as a compliance surface.
This is the practical shape of Article 50(2). Compliance is less about acquiring a marking technique than about preserving provenance through a delivery chain that was built to throw it away. The reason the middle of that chain is unprotected is structural: providers are regulated at the point of generation, deployers at the point of publication, and nothing in Article 50 regulates the transform layer in between. That is also why no vendor sells you anything for it.
Why provenance dies by default
Content delivery pipelines exist to minimise bytes. Resizing, re-encoding, transcoding, thumbnail generation and format conversion all optimise for the smallest payload that preserves perceptual quality, and metadata is not perceptual. It goes first.
Google DeepMind’s own assessment of metadata-based provenance, published alongside its watermarking work, puts it plainly: metadata is vulnerable to removal and is “often stripped accidentally and can also be trivially removed”. That is the authors of the most widely deployed AI watermarking system describing the failure mode of the approach the AI Act’s marking obligation most naturally implies. The same paper is candid that watermarking alone does not solve the provenance problem either, which is an argument for layering rather than for picking a winner.
The consequence for engineering is that preservation is never a default and never a single decision. It is a per-stage property that has to be asserted and tested at every hop where bytes are rewritten.
The two families, and what each one gets wrong
Article 50(2) requires marking solutions to be effective, interoperable, robust and reliable, as far as technically feasible. Two families of technique exist to meet it, and each fails a different one of those criteria.
Cryptographic provenance attaches a signed manifest of assertions to the asset, describing origin, modifications and whether AI was involved. The C2PA specification is the reference approach here, and on format it is strong: anyone with the specification can read a manifest, and the signature tells you whether it has been altered. Its interoperability is weaker in practice than on paper, because validation depends on trust lists, and whose certificates you accept is an unsettled operational question rather than a solved one. It is weak on robustness, because the manifest is data attached to a file and any stage that rewrites the file can drop it. C2PA’s own answer to this is soft binding, which is to say it delegates robustness to watermarking.
Watermarking embeds the signal in the content itself, so it survives transformations that discard metadata. Google’s SynthID is the most widely deployed example, and the measured robustness of its external variant, SynthID-O, is genuinely strong: the SynthID-Image work reports a true positive rate of 99.72% in its Aggregated Worst benchmark category at a fixed 0.1% false positive rate, across 10,000 ImageNet images at 512 by 512 and 30 transformations, without error correction. The weakness is interoperability. Production verification is described as available to trusted testers, with the external variant offered through partnerships, so a third party cannot independently check the mark.
The trade-off is not a rounding error. In the separate, harder Combination Worst benchmark category, which tests stacked transformations rather than a single worst transformation, and at the same 0.1% false positive rate, the open scheme TrustMark-P lands in the range 4.16% to 4.76% true positive rate against SynthID-O’s 98.06%. Choosing the openly verifiable option, in that specific category, costs roughly 93 percentage points of detection.
Text is the weakest modality and your largest exposure
For most regulated enterprises, the bulk of AI-assisted output is text: customer communications, reports, summaries, documentation. Text is where the marking story is thinnest, and where the failures are triggered by ordinary business process rather than by attack.
Research on SynthID-Text robustness reports that detection falls from an F1 of 1.00 to 0.711 under English to Chinese to English round-trip translation, and that the false positive rate reaches 0.53 when watermarked text is diluted ten to one into unwatermarked text, with the area under the curve dropping to 0.62. Both figures come from a 1.3B-parameter backbone on 200 watermarked and 200 unwatermarked samples, reported at the best threshold, so read them as the shape of the degradation rather than as a universal rate. The point survives the caveats: translating a document and pasting a watermarked paragraph into a longer one are not adversarial acts. They are Tuesday.
The regulator has already conceded this. The Code of Practice provides that free-form text may be marked with a single layer, using watermarking above 200 tokens, in its own words “even though it may have lower reliability”, and permits providers to restrict access to the corresponding detection solution to verified expert users, for a limited time, to compensate. Text is the modality where the standard bends furthest, and it is the modality carrying most of your content.
Watermark-free detection is not a substitute. Beyond accuracy limits, research published in Patterns found that GPT detectors systematically misclassify writing by non-native English speakers as AI-generated. Deploying one across an EU workforce creates a foreseeable discrimination problem on top of an unreliable control.
Layering is mandated, and one layer is not verification
Two findings should govern procurement.
First, the Code of Practice does not ask you to find a technique that meets all four criteria. Measure 1.1 opens conditionally, “so long as” no single technique can, under the state of the art, do so, and then requires at least two machine-readable marking layers for audio, images, video and containerised text. The conditional matters: the Code leaves room for a single technique to suffice if one later can meet all four criteria. For now, buying a layer plan is the correct posture rather than buying a technique.
Second, verifying one layer is not verification. Work presented at the CVPR 2026 APAI workshop (arXiv:2603.02378) demonstrates what its authors call an integrity clash: a cryptographically valid C2PA manifest asserting human authorship over pixels that carry an AI watermark, with each layer passing verification independently. Producing it required no cryptographic compromise, only the semantic omission of a single assertion field permitted by the current specification, using standard editing tools. Their cross-layer verification protocol reports 100% accuracy over 3,500 images, and the authors describe the gap as technically straightforward to close.
No commercially available product we identified in this research ships that configuration. That is the gap between what the regulation asks for and what the market offers, and it is a build problem rather than a procurement one.
Separately, the ease of forging marks is moving quickly. Work from Meta FAIR and ETH Zurich (arXiv:2510.20468) reports forging an image watermark from a single watermarked example with no access to the watermarking model and no decoder API, achieving 0.83 bit accuracy against Video Seal at PSNR 31.3. Earlier attacks needed hundreds to thousands of samples. Note that this work does not evaluate SynthID, and the result should not be extended to it.
Know what is out of scope before you mark it
A surprising amount of engineering effort gets spent marking things Article 50(2) never reached. Scoping the obligation down is as valuable as meeting it, and the Guidelines are specific enough to do that with confidence.
Source code, an agent’s chain-of-thought, machine-to-machine output and very short strings all fall outside the marking obligation. For teams building agentic systems, that matters: intermediate reasoning traces passed between components are not published synthetic content, and treating them as though they were adds cost with no compliance benefit.
There is also a full exemption for certain business and industrial output, described in the Guidelines as limited cases and expressly excluding public and consumer-facing systems. Three conditions must be met cumulatively: the output is strictly technical in nature, it is only intended to be perceived and processed by a limited pre-defined number of professionals inside the provider’s and deployer’s organisations, and it is not intended to be shared outside the company or to be usable by external persons, with appropriate safeguards against reasonably foreseeable misuse such as cloud isolation and role-based access controls.
Note that the third condition is about intent backed by safeguards rather than technical impossibility. A document that could in principle be forwarded is not automatically outside the exemption. What usually fails is the safeguards limb: the intent is asserted in a policy and nothing in the environment enforces it.
The practical sequence is therefore to classify before you build. Establish which outputs are published synthetic content in scope of Article 50(2), which are deployer-facing disclosure problems under Article 50(4), and which are neither. The middle category needs perceptible labelling rather than machine-readable marking, and the two are easy to conflate.
The Provenance Chain of Custody Map
The method that makes this tractable is a per-channel map of six stages, each with a named owner, its default behaviour, the control that changes that default, and the evidence that the control held.
- Generation. Where the mark and manifest originate. Regulated, and usually the only stage anyone has looked at.
- Ingest and storage. DAM, CMS and object storage. Does the record survive the upload?
- Editing. Human and automated. Which tools rewrite the file, and do they re-sign or silently drop?
- Transform and delivery. Image services, CDN transforms, server-side resizing, PDF generation, email rendering. This is where the mark dies.
- Publication. Regulated again, and the point where a deployer’s disclosure duty attaches.
- Redistribution and inbound. Third-party and agency content arriving with or without provenance you did not create.
Stages 1 and 5 are regulated. Stage 4 is regulated by neither party and typically sits with platform or infrastructure engineering, a function that in our experience is rarely represented in AI compliance discussions. That misalignment is the single most useful thing this map surfaces.
The Code of Practice adds a positive duty here that most implementation plans miss: Measure 1.2 requires signatories to retain existing metadata markings, to the extent technically feasible and recognisable under open standards, and to prohibit their removal contractually. Even with those qualifiers, it pushes provenance from a stamp applied once towards a property the whole chain has to respect, including services you buy rather than build.
The test is cheap. Push one marked asset through each publishing channel end to end, inspect what arrives, and colour each stage red, amber or green. It is the fastest way to find out whether you have a problem, and the red stage is rarely the one people expect before they run it.
One architectural caution worth stating precisely, because it is widely muddled: displaying a provenance-derived label to a viewer is not the same operation as preserving the manifest in the delivered file. A platform may do the first and not the second. Verify the delivered bytes rather than the badge in the interface.
Evidence, when nothing is mandated
Assume you get this right. How do you show it?
Article 50 mandates no record set and no retention period. The automatic logging duty in Article 12 and the documentation retention in Article 18 belong to the high-risk regime, so Article 50 leaves the evidentiary architecture entirely to you, while a market surveillance authority will still judge it after the fact. Compounding that, Code Measure 4.2 tells signatories to use internal benchmarks for testing and verification until methods recognised by the AI Office emerge, which is as close to an official confirmation as you will get that no agreed measurement method exists yet.
The design rule that follows: record the reasoning, not only the result. A retained decision about which layers you chose for a modality, what you tested, what you accepted as residual risk and why, survives a change of benchmark. A stored detection score does not.
What this means for the build
The honest summary is that Article 50(2) asks for a property that only a composition delivers, that the composition is well understood and unshipped, and that the layer where compliance actually fails belongs to a team nobody has invited to the meeting.
There is no credible published figure for what Article 50 implementation costs, and anyone quoting one is guessing. What can be scoped concretely is the work: map custody per channel, test one asset end to end, choose a layer plan per modality against the criterion the regulator has already conceded there, build cross-layer verification that can abstain rather than guess, and retain the reasoning.
That is engineering work with a governance question wrapped around it, which is the combination Zartis exists to handle: advising on where the obligation lands, then building the marking, preservation and verification layers in the pipeline itself. Talk to us about an Article 50 pipeline assessment.