eu ai act compliance guide

The EU AI Act:
Watermarking Rule Explained

eu ai act compliance guide

The EU AI Act:
Watermarking Rule Explained

eu ai act compliance guide

The EU AI Act:
Watermarking Rule Explained

14 mins read

This is a deep dive follow-up to The EU AI Act: Global Impact & Compliance Guide.

The EU AI Act introduces mandatory watermarking for pre-existing AI system providers with a compliance deadline of December 2026, while disclosure requirements for deployers have already been in full effect since 2 August 2026. This shift reflects a global trend in AI governance, mirrored by California’s SB 942 and even stricter synthetic content labeling measures in China. The legislation differentiates between "AI models" and "AI systems," focusing provider obligations on the latter. While tools for watermark removal have emerged, they violate the Terms of Service of major providers, posing significant legal and operational risks. Companies building AI products for a global audience must audit and design their AI infrastructure for long-term provenance.


Note: This document provides technical and operational analysis and does not in any form constitute formal legal counsel.

Beyond the Uproar

The recent industry flutter over hidden text watermarks have triggered a fair amount of angst, but it marks our transition toward a maturing AI ecosystem. Regulatory pressures ensure that provider-hopping is not a sustainable strategy. With Google’s SynthID already operational and the rest facing a December 2026 deadline for statutory alignment, the mainstream model providers are converging on a unified marking standard.

The Global Ripple Effect

The EU isn't the first in this governance. China sets a higher bar even earlier than the EU — its synthetic content labelling measures have already been in effect since 1 September 2025, requiring AI service providers to add visible and hidden labels, and banning tools or services that remove or tamper with those labels. California's SB 942 (the AI Transparency Act, amended by AB 853) also became operative since 2 August 2026, aligning with the EU AI Act. It requires covered providers to supply AI detection tools and disclose AI-generated content. For those building for a global audience, the EU framework is just the floor, and China's crackdown on watermark removal is a forecast of where global governance is heading.

The new AI regulation is a structural shift that one cannot outrun. Understanding your obligation in the governing system is key to navigating global AI compliance without crippling your workflow.

Need help applying these frameworks to your product roadmap? Schedule a strategic consultation

Watermarking vs. Disclosure: Who Does What?

The EU AI Act defines several roles across the supply chain, including importers, distributors, and authorised representatives. (Art. 3). Two functional roles, Deployers and Providers, concern the watermarking and disclosure rules. Deployers are responsible for human-readable disclosure (Art. 50(4)), while providers are responsible for machine-readable marking (Art. 50(2)).

  • Deployers are those who use AI products or services in a professional context.

  • Providers are those who build or commercialise AI systems.

For Deployers

The Regulatory Definition of Deepfake

So what is the legal definition of deepfake media? Art. 3(60) defines it as “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

One might ask, isn’t all AI outputs inherently artificial? What distinguishes a deepfake from standard synthetic generation? We will explain this distinction with a commercial product marketing example:

Deepfake Media Content (AI Disclosure Required):

A pair of non-waterproof mesh running shoes are depicted in an AI-generated scene running through a rushing mountain stream and thick mud, appearing completely dry inside with effortless traction.

Deepfake Media Content
(AI Disclosure Required):

A pair of non-waterproof mesh running shoes are depicted in an AI-generated scene running through a rushing mountain stream and thick mud, appearing completely dry inside with effortless traction.

The synthetic environment creates a false impression of the product's actual physical properties, water resistance, and grip. It misinforms viewers regarding how the product actually functions under wet real-world conditions.

Because this video meets the Article 3(60) deepfake definition, the deployer is subject to Article 50(2) of the AI Act. They must explicitly disclose via clear visual labelling that the video content has been artificially generated or manipulated.

Non-Deepfake Media Content (AI Disclosure exempted):

The exact same pair of shoes, truthful reflecting the product’s actual appearance, are placed in an AI-generated scene sitting against a dramatic canyon sunset.

Non-Deepfake Media Content
(AI Disclosure exempted):

The exact same pair of shoes, truthful reflecting the product’s actual appearance, are placed in an AI-generated scene sitting against a dramatic canyon sunset.

The synthetic environment is a stylised backdrop where it showcases the shoe's appearance without making any false implicit claims about its weatherproofing, durability, or mechanical capabilities.

Because it’s unlikely to mislead the viewer about the product’s actual appearance or its characteristics and use, the disclosure of AI use is exempted.

What Counts as Public Interest

The text generation rule under Art. 50(4) states that if the AI text is (i) published (ii) with the purpose of informing the public (iii) on matters of public interest, it must be labelled as AI-written. Caveat: The Act has no official definition over the term “public interest”. While the EU guidelines focus on established case law standards to bring clarity, they also explicitly state that matters that may be considered to be of public interest can evolve over time and across contexts.

As specified in Section 6.2.1. of the EU Guidelines published in 20 July 2026:

i. Published: accessible by an indeterminate, fairly large number of unrelated, potential readers simultaneously and/or successively

ii. Informing the public: intend to communicate knowledge, opinions or facts

iii. On matters of public interest: relevant to society at large, meriting public debate or scrutiny, covering topics on politics and democratic processes, public administration, the administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, any economic, financial, political, scientific, or cultural development that may be relevant subject of public debate.

i. Published: accessible by an indeterminate, fairly large number of unrelated, potential readers simultaneously and/or successively

ii. Informing the public: intend to communicate knowledge, opinions or facts

iii. On matters of public interest: relevant to society at large, meriting public debate or scrutiny, covering topics on politics and democratic processes, public administration, the administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, any economic, financial, political, scientific, or cultural development that may be relevant subject of public debate.

Disclosure Flexibility: Satirical, Artistic, or Fictional Use

While deployers of satirical, artistic, or fictional works must still disclose the synthetic nature of the media, they can do so in a manner that does not hamper the viewer's experience, such as at point of entry, accompanying materials. However, this relaxation only applies if the creative intent is clear. If a piece of "satire" is indistinguishable from reality and risks crossing the line into disinformation, a prominent AI label is required.

Disclosure Exception: Human Review & Editorial Oversight

If a piece of AI-generated text has (i) undergone human review or (ii) editorial control and (iii) a legal or natural person holds editorial responsibility for the publication, then it can be exempted from the AI label. So what constitutes “substantive” contribution? A human must do more than procedural check or cursory editorial approval than just spell checks or grammar correction. They must fact-check to ensure accuracy of the content or make structural edits. As specified in Section 6.2.3. of the EU Guidelines:

i. Human review refers to the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny (e.g. academic peer review or professional validation chains)

ii. Editorial control refers to the control exercised in practice by a responsible editorial entity (e.g. an editor-in-chief) over the content having the authority to approve, alter or reject the substance of the text based on substantive grounds (incl. fact-checking of information and ensuring the trustworthiness of sources).

iii. Editorial responsibility refers to a natural or legal person who must hold ultimate legal responsibility over the publication.

i. Human review refers to the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny (e.g. academic peer review or professional validation chains)

ii. Editorial control refers to the control exercised in practice by a responsible editorial entity (e.g. an editor-in-chief) over the content having the authority to approve, alter or reject the substance of the text based on substantive grounds (incl. fact-checking of information and ensuring the trustworthiness of sources).

iii. Editorial responsibility refers to a natural or legal person who must hold ultimate legal responsibility over the publication.

This article, as an example, qualifies as content published for the purpose of informing the public on a matter of public interest. Had this been written solely by AI without human review or editorial control and editorial responsibility, it would be subject to an AI label.

The rule of thumb is if your AI text is publicly accessible by a person in the EU, covering matters of public interest, substantially alters the original input and has not undergone substantial human edit and review, then it must be clearly labelled as AI.

Not sure where you land? Run the checker:

Deployer Compliance FAQ

Does the disclosure rule apply to non-EU companies?

Yes. The EU AI Act applies extraterritorially. If a non-EU entity uses AI tools to generate or manipulate text intended to inform the public on matters of public interest, and publishes it such that it is accessible by an EU audience, the deployer must comply with Article 50 disclosure rules, regardless of where the business is located or registered. Read more in the full compliance guide

Are all news articles drafted using AI subject to the disclosure rule?

It depends on the topic covered (e.g. commercial advertorials are unlikely considered matters of public interest) and the extent that the semantics of the input/original text have been altered. Article 50(4) targets substantive text generation or manipulation. If you use AI tools for assistive edits such as grammar correction, language translation, or headline suggestions, then disclosure of AI usage is not required.

Does AI voiceover audio need to be labelled synthetic?

Whether an AI voiceover requires a disclosure labelling depends on the type of voice used. The narration only triggers public labelling if it crosses into voice-cloning or impersonation. Using a generic text-to-speech voice to read out a script, when there’s no deception as to the identity of the narrators, doesn’t require a human-audible disclaimer under Article 50(4). But if the AI clones a real, recognisable individual’s voice and sounds as though the person narrated it, it meets the definition of a deepfake.

Does it matter when and where the AI label is shown if disclosure is required?

Yes, timing and placement matter under Article 50(5) of the EU AI Act. The disclosure must be directly perceivable by a human without requiring special technical tools, prior or at their first interaction or exposure to the content. Placing a disclaimer at the bottom of a long scrollable web page after a user has already consumed the content, in fine print, or behind obscure expandable menus all violate the requirement.

For Providers

The Legal Distinction: AI Models vs. AI Systems

Think of a model as a component (car engine) and the system as an end product (the vehicle). A General-Purpose AI (GPAI) model is the underlying algorithmic engine (parameters, weights, architecture). It becomes an AI system when the model is used and wrapped with software tools, data pipelines, user interfaces, or operational loops capable of interacting with an environment.

Dimension AI Model AI System
EU AI Act Definition General-Purpose AI model Art. 3(63)) trained with large-scale data displaying significant generality, capable of competently performing a wide range of distinct tasks regardless of how placed on the market, and integratable into downstream applications A machine-based system (Art. 3(1)) designed to operate with varying levels of autonomy and adaptiveness that infers from inputs how to generate outputs (predictions, content, recommendations, decisions) that influence physical or virtual environments
General Definition The trained algorithm e.g. Large language models The entire end-to-end software ecosystem
Function Converts raw inputs (tokens/vectors) into outputs (logits/predictions) Solves end-user problems by orchestrating data, tools, and interfaces
Key Components Model architecture, weights, fine-tuning data Models, user interfaces, APIs, vector databases, security guardrails
Maintenance Retraining, parameter tuning, quantization Cloud DevOps, monitoring, latency optimization, security patches
Analogy A high-performance car engine The complete automobile, including steering wheel, brakes, safety airbags etc
Examples GPT-4o, Claude 3.5 Sonnet, Llama 3, Whisper ChatGPT web platform, Midjourney web app

In-Content vs. Container Watermarks

  • In-Content watermark is a digital identifier embedded into the pixels, words, waveform or spectrum. They are not easily stripped.

  • Container watermark is a cryptographic envelope attached to a file. It can be easily stripped

Watermarks Comparison In-content (pixels/tokens) Container (metadata)
Core characteristics
Storage Location Generated Content Embedded identifiers File Header Metadata wrapper
Visibility Machine visible Invisible to humans Visible to humans via provenance viewer tools
Fragility Durable Resistant to manipulation Fragile Easily removed
Robustness against tamper
Sharing & Exports Screenshots, crops, copy-paste, social sharing Intact Stays in pixels or words Removed Re-encoding wipes metadata
Rewriting & Edits Paraphrasing, translating, summarizing Degraded Fades as text changes Intact Via original file edits
Deep Editing & Scrubbing Photoshop edits or AI removal tools Degraded Hard to erase without damage Removed Re-saving wipes headers

If you’re an AI system provider, using a compliant upstream model gives you the technical foundation of watermarking, but you are still legally liable for ensuring the final output delivered to your end user retains compliant markings, and that they survive routine compression, editing, and distribution channels.

The EU's Code of Practice acknowledges that no single technique meets the robustness requirement, so it mandates three layers: visible disclosure, machine-readable marking, and server-side logging. Here’s a matrix to illustrate the types of watermarks supported by General-Purpose AI (GPAI) models, as of 23 Aug 2026:

AI Content Authentication Matrix: Provider Watermarks by Content Type

Provider & Product(s) Text Images Audio / Video Detection Methods
Anthropic Claude
In-content
Aug 2026
Container
In-content
Container
Aug 2026
N/A Does not generate AI audio/video content Forthcoming
Google Gemini, Imagen, Veo
In-content
May 2024
Container
In-content
Aug 2023
Container
Aug 2023
In-content
May 2024
Container
May 2024
Gemini app prompt SynthID Detector (Early access)
OpenAI ChatGPT, DALL-E, Sora
In-content
(Research)
Container
In-content
May 2026
Container
Feb 2024
In-content
May 2024
Container
May 2024
openai.com/verify portal SynthID inspectors
Meta Meta AI, Muse, Movie Gen
In-content
Jul 2024
Container
In-content
Oct 2023
Container
Feb 2024
In-content
Jun 2024
Container
Jun 2024
Open-source GitHub decoders
xAI Grok
In-content
Container
In-content
Container
Aug 2024
In-content
Container
Feb 2026
Forthcoming
Open-weight Stable Diffusion, Flux, Llama Optional Optional Optional Python CLI decoders

Navigating compliance for AI products can be technically demanding. Speak with our experts to map out your implementation strategy.

Provider Compliance FAQ

Are there exemptions to watermarking for AI system providers?

Yes. However, the exemption is evaluated per function, not entity. If an AI system can be used for both content generation/manipulation and non-substantial minor alterations of input data, then the marking rule will still apply to the content altered beyond a minor, non-substantial manner.

Take Grammarly as an example, if you use the Go assistant to write a 500-word essay, it generates synthetic text from a prompt and is no longer performing a standard editing function. In that specific use case, it acts as an AI system, and the provider is legally obligated to ensure that the output contains a machine-readable mark.

Does the watermarking rule apply to AI systems that “vibe code”?

No. The EU treats AI-generated code as a "technical output," not human-facing text. But if your vibe-coding assistant also generates natural-language outputs in addition to code, such as explanatory text, documentation, or chat responses, those "synthetic text" may be subject to marking.

Does open-source AI need to comply with the watermarking rule?

It depends if the open-source build is an AI model or system. Many conflate the two but there is a massive legal distinction between an AI model (the trained weights and architecture) and an AI system (the software application or service built around that model that interacts with users) under the EU AI Act.

The transparency rules do not apply to bot-to-bot interactions. What if a provider’s AI agent can't tell if it’s interacting with a human or another bot?

According to the EU guidelines, if the AI system cannot reliably predict whether it is interacting with a human or another automated system, the provider must design it to default to disclosing its AI nature in every interaction.

Watermark Removal

After Anthropic’s watermarking upheaval, watermark removers have emerged as a rising industry, among which Guillaume Meyer’s open-source watermarks-remover with over 18k GitHub stars is the most prominent.

Is it technically feasible to remove a watermark?

Fully stripping watermarks is not impossible, but not without significant effort. It can be expensive and unsustainable in the long run. Here's the reality:

  1. Stripping metadata is easy. A screenshot, a re-save, or a format conversion removes C2PA metadata without any special tool.

  2. Text requires paraphrasing. The practical method for stripping text watermarks is paraphrasing the content with a local model (Qwen, Ollama, Mistral) that has no watermark. Because the embedded watermark lives in the word choices, rewriting the output is the most reliable way to remove it, but you risk compromising the quality of the writing 

  3. Stripping embedded media watermarks is costly. Researchers have shown that invisible image watermarks can be removed with diffusion-based denoising (NeurIPS 2024), but it needs a dedicated GPU with high VRAM and ~10GB of model downloads, so this approach isn't one that can casually run on an everyday laptop and is order of magnitude more expensive.

  4. Complete removal is not guaranteed. Most “removers” tools cannot promise success. Even the popular “watermark-remover” tool is honest about providing "best-effort" service. It acknowledges that no tool can confidently boast of beating the system until official detectors become available.

Is it legally permissible to remove a watermark?

Legally, this is murky. While the AI Act hasn't explicitly banned deployers from removing watermarks, the official Terms of Service (ToS) and Acceptable Use Policies (AUP) of the major providers clearly prohibit it. A violation can get your access or API key revoked, which could come at a hefty cost if you build on their platforms.

  • OpenAI’s Terms of Use explicitly forbid users from taking actions that "bypass any protective measures or safety mitigations we put on our Services." They also explicitly prohibit users from attempting to "represent that output was human-generated when it was not."

  • Google’s policies stated that while SynthID is designed to survive heavy editing, actively attempting to strip it violates Google's terms. Such practice is considered an ethical and legal violation, where their AUP forbids disrupting the integrity of their services.

  • Anthropic's policies commit to "content provenance." Their AUP prohibits using their tools for deception or bypassing their systemic safety controls. Deliberately running scripts to un-shift the logits or scrub the C2PA tags violates their trust and safety guidelines.

  • Qwen (Alibaba's open-source model family) also has an explicit clause in their ToS for Qwen Studio. Section 2(k) states that users may not: "without proper permission, remove, obscure, modify, and/or tamper with any label or watermark (if any) applied in connection with the outputs."

Future-Proof Your AI Strategy

As global AI transparency standards emerge, compliance should be factored in from day one. And for business and technical teams alike, the grace period until 2 December 2026 offers a narrow window to audit existing deployments and design sustainable systems.

Are you building AI systems? At Leiwe & Partners, we are a data and AI consultancy helping organisations navigate the complexities of the EU AI Act. We work alongside your executive and engineering teams to identify regulatory exposure, design compliant architectures, and build robust infrastructure directly into your product. Book a strategic consultation today