EU AI Act Article 50

Compliance Checklist

For Studios+ creators, studios, and organisations that publish AI-generated content. Article 50 applies from 2 August 2026. Source: Regulation (EU) 2024/1689 and the European Commission’s Code of Practice on marking and labelling AI-generated content. GENERAITR (Provider) applies the official EU icons by default on every export, so you as Deployer are covered at the point of publication.

The checklist

This checklist is for Deployers: the studios, creators, and organisations that use GENERAITR to produce and publish AI-generated content. GENERAITR acts as the Provider: we build and operate the platform, embed the technical compliance layer, and carry the provider obligations under Article 50. As a Deployer, you hold the disclosure duty at the point of publication. GENERAITR gives you the tools to meet all nine points automatically.

01

Machine-readable provenance metadata

Every AI-generated asset must carry machine-readable metadata identifying it as AI-generated. The standard the EU Commission points to is C2PA Content Credentials.

Are your AI-generated outputs embedded with C2PA metadata?

02

Disclosure at point of publication

When you publish or deliver AI-generated content, the audience must be informed that it is AI-generated. This applies to images, video, audio and certain text. Exception: no disclosure is required when the synthetic origin is already obvious to a reasonably informed person (e.g. a stylised illustration no one would mistake for a photograph). When content could be perceived as real, disclosure is mandatory.

Do you label AI-generated content that could be perceived as real when you publish or deliver it?

03

Deepfake declaration

AI-generated or manipulated images and video that depict real people, places, objects, or events must carry a clear, visible label stating the content is artificially generated or manipulated. Article 3(60) defines a deepfake to include places, objects, and events, not only people. This is directly relevant to GENERAITR's core flows: AI interior design applied to a real room, or a photorealistic render of an existing building, both fall under the definition.

Do you label manipulated media before distribution?

04

Audit trail per asset

You must be able to answer: who generated it, what model was used, what parameters, and when. Six months later, in front of a regulator, client or journalist.

Can you trace every AI-generated asset back to model, user, timestamp and parameters?

05

Model and system documentation

Technical documentation per generation: which AI model, which version, which template or pipeline produced the output.

Is the AI model and system documented per output?

06

Human oversight in the workflow

Article 14 requires human oversight before AI-generated content is approved and exported. A review or approval step must exist in the production workflow.

Is there a human approval step before AI content is published or delivered?

07

AI competence in the team

Article 4 (in force since February 2025): your team must have sufficient AI competence to understand the tools they use and the obligations that apply.

Does your team understand what EU AI Act requires of them?

08

Data residency and processing

Know where your data is processed and stored. For EU organisations, this means understanding whether prompts, source material and outputs leave the EU.

Do you know where your AI-generated data is processed and stored?

09

Provenance: Generation Verification

The ability to verify whether an image received from an external source was AI-generated. C2PA handles outbound provenance (labelling your own outputs). Generation Verification handles inbound provenance — checking content you receive before using it in deliverables.

Can you verify whether incoming images are AI-generated before using them in deliverables?

When is a visible label mandatory?

Article 3(60) defines a deepfake to include real places, objects, and events, not only people. A visible label is mandatory whenever the result could be mistaken for a real photograph of something that exists. GENERAITR gives you the tool (an optional visible label in the Export panel); this guide shows when you are obliged to use it.

  • Source is a real photo of an existing place: visible label required
  • Source is a 3D model of an existing building: visible label required
  • Source is a drawing or sketch of a future or fictional building: C2PA manifest is enough, no visible label required
  • Audience is the general public or social media: visible label required regardless of source
  • Audience is a professional client who already knows the work is AI: an exemption may apply

When in doubt, label it. The invisible watermark and C2PA manifest are always embedded; the visible label is the one control you choose at export.

How GENERAITR handles each point

#RequirementGENERAITR
1Machine-readable metadataC2PA Content Credentials embedded in every exported asset. Organisation identity and generation metadata included in the manifest. Signed by GENERAITR (self-signed cert in Early Access; CA-signed cert planned for Beta).
2Disclosure at publicationC2PA manifest embedded in the asset file itself. Provenance metadata (model, workflow, user, timestamp) readable by any C2PA-compatible tool. Exportable .meta.json disclosure document available via the Metadata button in the Export panel.
3Deepfake declarationInvisible DCT watermark embedded automatically in every image. Visible watermark / label configurable at export: text overlay (custom text, font, position, opacity) and GENERAITR-branded image overlay in multiple variants. Both controls are available in the Export panel with a built-in compliance note. C2PA manifest also embedded in the exported file.
4Audit trailEvery generation is logged automatically: model, pipeline, parameters, user, organisation, and timestamp. Queryable via the asset lineage database.
5Model documentationModel identity and workflow version recorded per generation in the C2PA manifest and the lineage record.
6Human oversightPer-output human review toggle on every generated image. Reviewer identity and timestamp persisted on the media record. Tagged-media export requires the reviewed flag — unreviewed outputs cannot be exported through the bulk export path. Auditable trail without requiring a full approval workflow.
7AI competenceModality badge (Image / Video / Audio / 3D) and an AI Act usage notice shown on every template card at the moment of selection. Onboarding flow and compliance page also in place.
8Data residencyOnline plan: processed and stored on Hetzner servers in the EU. Local plan: fully on-premise, no data leaves the organisation's infrastructure.
9Generation VerificationIn development — Early Access. Upload any image to the Admin panel to check for steganographic AI markers and receive a confidence score. Enables teams to verify incoming content before use in deliverables.

Key dates

  • 1 August 2024EU AI Act entered into force
  • 2 February 2025AI competence requirements apply (Article 4)
  • 2 August 2025General-purpose AI model rules apply
  • 2 August 2026Full application: Article 50 transparency, high-risk obligations, enforcement

Penalties for non-compliance

Article 99 of Regulation (EU) 2024/1689 sets out fines by infringement category. The tier relevant to Article 50 transparency and labelling obligations:

  • Article 50 violations (transparency and labelling): up to €15 million or 3% of global annual turnover, whichever is higher. Applies to providers and deployers who fail to label or disclose AI-generated content.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1% of global annual turnover, whichever is higher.
  • Prohibited AI systems (for context): up to €35 million or 7% of global annual turnover, whichever is higher. This is the upper bound of the Act; Article 50 violations fall under the tier above.

Enforcement is decentralised: each EU member state designates its own supervisory authority. In practice, enforcement is triggered by complaints from competitors, consumers, journalists, or advocacy groups; proactive market surveillance by national regulators; and cross-mandate reviews.

In Sweden: PTS (Post and Telecom Authority) is the proposed coordinating market surveillance authority. IMY (Swedish Data Protection Authority) retains jurisdiction where AI intersects with personal data.

The risk is real even if it is not immediate. Once a complaint is filed, organisations must produce an audit trail. GENERAITR provides that trail automatically on every export.