The transparency obligations in Article 50 of the EU AI Act, Regulation (EU) 2024/1689, apply from today. There is no grace period written into the date and no announcement to wait for. The text has been public since 2024 and the schedule was set in the regulation itself.
What the obligation is, in one screen
Article 50 requires that people are told when content they encounter was generated or manipulated by an AI system. Providers of generative systems must ensure the output is marked in a machine-readable format as artificially generated or manipulated. Deployers, meaning whoever uses such a system and publishes the result, must disclose it. Deep fakes and AI-generated or manipulated text published to inform the public on matters of public interest are named specifically. The obligations apply from 2 August 2026.
If you publish, you are almost certainly a deployer, and the disclosure duty is yours. A fuller reading of scope and roles is on our Article 50 page.
A label is a claim, and claims get tested
Disclosure is a statement you make about your own content, in your own words, on a surface you control. That is what the rule asks for and it is worth doing carefully.
The difficulty starts when somebody has a reason to check it. That somebody is rarely a regulator. In practice it is one of four people:
- A client running procurement, working through a supplier questionnaire that now has an AI disclosure section in it.
- A counterparty in a dispute, where who produced what and when is suddenly the whole argument.
- A platform or distribution partner asking you to substantiate a declaration you attached to an asset months ago.
- A competitor, who has an interest in your statement being wrong and no obligation to be charitable about it.
At that point the label stops being the answer and becomes the thing being questioned.
What proving it actually looks like
Set aside the courtroom image. The realistic version is far more mundane and far more frequent: an email from a client asking what in a delivered campaign was AI-assisted, with a deadline of Friday, cc'ing their legal team.
What that email is really asking is three questions. Which version was published. What touched it between the first draft and that version. On what date each of those things was true. A policy document does not answer any of the three. A screenshot answers none of them in a way the recipient has any reason to accept.
Most teams then reach for what they have: file modified dates, an email thread, project management history, cloud version history. All of it sits inside systems the answering party controls and can change. It is useful for reconstructing your own memory. It is weak the moment its value depends on somebody else believing it.
What evidence actually holds
A record that survives being questioned has four parts, and the order matters.
1. A hash of the file. A cryptographic hash computed from the artefact itself. Change one character or one pixel and the hash no longer matches. This is what pins the claim to one exact version rather than to a document that has since moved on.
2. A declaration of how it was produced. AI generated, AI modified, AI assisted, or human authored. Attached to the hash, so the statement and the thing it describes travel together instead of living in two different systems that have to be reconciled later.
3. A qualified timestamp. Issued by a Qualified Trust Service Provider over the hash and the declaration. This is the part that fixes when the record existed, independently of any date field you control.
4. A certificate a third party can verify. Checkable without an account and without contacting you. This is the only part your counterparty actually experiences, and it is the reason the other three are worth doing.
Remove any one of the four and the record weakens in a specific way. Without the hash it is not tied to a version. Without the declaration it proves existence but says nothing about production. Without the timestamp the date is your word. Without third-party verification the recipient still has to trust you, which is the problem you were trying to solve. See how the flow works, or check an existing sealed document to see what the recipient sees.
Why qualified services, and which ones
The word qualified is doing real work here. It is not a marketing adjective, it is a legal status.
Under eIDAS, Regulation (EU) No 910/2014, a qualified electronic timestamp issued by a Qualified Trust Service Provider carries a legal presumption as to the date and time it indicates and the integrity of the data it is bound to. An ordinary timestamp, whether from your own server or a public ledger, does not carry that status.
In Switzerland the framework is ZertES, which governs certification services for electronic signatures under Swiss federal law. Handwritten equivalence itself does not come from ZertES. It comes from Art. 14 para. 2bis of the Swiss Code of Obligations, which places a qualified electronic signature with a qualified timestamp on the same footing as a signature by hand. Those two instruments are frequently collapsed into a single citation. They are separate, and the equivalence rule lives in the Code of Obligations.
The practical consequence for an Article 50 disclosure is straightforward: a declaration sealed with a qualified timestamp is a record whose date does not rest on your own systems, which is exactly the property a disclosure needs when it is being questioned rather than merely read.
Four steps for this week
None of these need a legal opinion first.
One. List what you published in the last quarter that had any model involvement. Not everything you have ever produced. The recent, live, client-facing material.
Two. For each item, pick the declaration that is actually accurate. Most working teams land on AI assisted more often than they expect, and that is a perfectly respectable position to hold in writing.
Three. Seal the ones that matter. Client deliverables, anything published into the EU, anything on a public-interest topic. You do not need to seal a draft nobody saw.
Four. Put the process at the point of publication rather than at the point of audit. A record created when the work goes out costs a few minutes. The same record reconstructed a year later costs considerably more and convinces considerably less.
Article 50 asks you to disclose. It does not ask you to prove your disclosure. The people who read your disclosure are the ones who will ask, and today is a reasonable day to be ready for that.





