On 2 August 2026, something small but important changed in Europe.
Certain machines that speak to human beings can no longer quietly leave the human being guessing what is on the other side. Article 50 of the European Union’s Artificial Intelligence Act now requires providers of AI systems designed to interact directly with natural persons to ensure that people are informed that they are interacting with AI, unless that fact is already obvious in the circumstances. Providers of systems that generate synthetic audio, images, video or text are also required, within the limits of technical feasibility, to make those outputs identifiable in machine-readable form. Deepfakes are subject to disclosure rules. So are certain AI-generated texts published to inform the public on matters of public interest when no human review or editorial responsibility intervenes.1
At first glance this is another labelling law.
I think it is more important than that.
Europe has begun shifting the burden of authenticity.
For most of the internet’s history, information appeared first and verification came later. A photograph circulated. A recording leaked. A video went viral. Only after somebody questioned it did journalists, courts, forensic analysts or ordinary users begin asking where it came from and whether it had been altered.
That arrangement depended upon fabrication being relatively expensive.
Photographs could always be staged. Recordings could be edited. Witnesses could lie. Propaganda did not begin with artificial intelligence.
But producing convincing evidence of an event that never occurred required some combination of money, skill, access and time.
Generative AI attacks those costs simultaneously.
The economically significant change is not that falsehood has suddenly become possible.
It is that convincing fabrication is becoming cheap.
Once the marginal cost of manufacturing apparently authentic text, speech, photographs and video falls far enough, society acquires a verification problem of a different order. It becomes unreasonable to expect every person who sees every image, hears every recording or reads every document to conduct a forensic investigation before deciding whether it deserves belief.
The burden has to move somewhere else.
Article 50 moves part of it upstream.2
That distinction matters because the European rules do not attempt the far more ambitious task of determining whether content is true.
They concern origin.
Who — or what — produced this?
Was artificial intelligence involved?
Has the content been generated or manipulated?
Can its artificial origin be detected?
These questions are related to truth, but they are not identical to it.
Lawyers already live with this distinction.
A document produced in litigation does not become reliable merely because someone hands it to a judge. Evidence has a history. Courts may ask where it came from, whether it is authentic, who possessed it, whether it was altered, and whether its chain of custody can be reconstructed.
Property law does something similar.
A house is not yours merely because you are standing inside it. Somewhere behind possession is a chain of title.
Money works through records.
Companies through registration.
Transactions through receipts.
The information economy has largely resisted this bureaucracy because the cost of proving origin was often greater than the perceived benefit.
Synthetic media is changing that calculation.
Article 50 does not prescribe one permanent technological solution. It requires machine-readable marking techniques to be effective, interoperable, robust and reliable as far as technically feasible, taking account of the characteristics of the content and the state of the art.3 The European Commission’s implementation materials contemplate techniques such as metadata, watermarks, fingerprints and other methods of establishing machine-readable provenance.4
This is sensible because the technical battlefield is moving.
A watermark that survives today may be removable tomorrow.
Metadata can be stripped.
A detection technique effective for images may perform badly on text.
NIST has found precisely these weaknesses. Its work on synthetic-content transparency notes that even supposedly robust image watermarks can be manipulated or removed, while text creates an especially difficult provenance problem because paraphrasing and structural modification can weaken or defeat many detection techniques.5
The Coalition for Content Provenance and Authenticity, whose C2PA standard is one of the major attempts to create interoperable provenance records for digital media, recognises another limitation that is even more fundamental.
Provenance does not prove truth.
A properly authenticated photograph may depict a staged event.
A genuine recording may be quoted dishonestly.
A real video may be attached to a false description.
A human journalist can publish something untrue without artificial intelligence touching a sentence.
C2PA states the distinction plainly — provenance can establish information about the origin, history and authenticity of a digital asset, but it cannot by itself establish whether the thing depicted or asserted is true.6
That may become one of the most important distinctions of the synthetic era.
We have spent decades teaching people that seeing something online does not make it true.
We may now have to teach the inverse lesson as well.
The existence of convincing artificial media makes genuine media easier to deny.
A politician confronted with an authentic recording can claim it was generated.
A corporation confronted with an embarrassing video can call it synthetic.
A criminal defendant can challenge genuine evidence by pointing to the general possibility of fabrication.
This is sometimes described as the liar’s dividend — the increasing ability of a person caught by genuine evidence to exploit public awareness of deepfakes in order to create doubt.
Synthetic content therefore creates two information problems at once.
It manufactures evidence for things that did not happen.
And it weakens evidence of things that did.
A provenance system matters for both reasons.
It can help us say not only this was made by a machine, but also this file has a traceable history.
That still falls far short of truth.
But in an environment saturated with plausible fabrication, origin itself acquires value.
There is, however, an obvious weakness in Europe’s approach.
The actors most interested in transparency are often the actors least likely to deceive.
A major technology company operating openly in the European market has regulators, shareholders and commercial reasons to comply.
A newspaper may have reasons to preserve provenance.
A government agency may want to authenticate its photographs.
A malicious propagandist wants something different.
He does not need the system to work.
He needs to know where it breaks.
This asymmetry should prevent exaggerated claims about what Article 50 can accomplish.
The rules are also narrower than the slogans surrounding them sometimes suggest. Personal, non-professional use does not automatically create all of the obligations imposed upon professional deployers. The legislation contains specific treatment for artistic, satirical, fictional and analogous works. Public-interest text that has undergone human review or editorial control and for which a person or legal entity holds editorial responsibility is treated differently from unattended machine publication.7 Content generated before 2 August 2026 does not generally have to be labelled retroactively, and providers of certain systems already placed on the market before that date have until 2 December 2026 to satisfy the Article 50(2) machine-readable marking requirement.8
These are not trivial qualifications.
They reveal what regulation always looks like when one stops reading the headline and reaches the boundary.
Messy.
Conditional.
Full of definitions.
That does not make the regulation weak. It makes it law.
The most revealing provision may be the exception for public-interest text that undergoes human review and editorial control.
The machine may generate.
A human being can still assume responsibility.
That looks like a narrow drafting detail, but it suggests something larger about the legal architecture forming around AI.
Intelligence can be distributed.
Responsibility still wants an address.
AI can research.
It can draft.
It can translate.
It can edit.
It can generate photographs, voices and video.
But legal systems remain deeply uncomfortable with accountability that dissolves into software.
Someone eventually has to stand behind the output.
Someone has to say —
I reviewed it.
I published it.
Ask me.
This is why the AI Act’s transparency rules should not be understood principally as an attempt to identify machines.
They are part of a larger attempt to preserve human accountability around machines.
There is another risk.
If provenance systems become common enough, authenticated content may acquire an undeserved presumption of truth.
A blue tick for reality.
That would be a serious mistake.
A provenance system can tell us that an image originated with a particular newspaper, agency, camera, software system or person. It can record that modifications occurred. It may allow the history of a file to survive transmission.
None of this prevents the original source from being wrong.
Trust therefore moves rather than disappears.
Instead of asking only whether the file is genuine, we also ask whether the source responsible for the genuine file deserves belief.
This is familiar territory.
For centuries, institutions have operated by converting impossible individual verification problems into manageable trust relationships.
I cannot personally audit the reserves of every bank.
I trust institutional structures that do.
I cannot inspect every pharmaceutical laboratory.
Regulatory systems attempt to do that work.
I do not independently verify every proposition in a court record.
Rules of evidence distribute that burden.
Provenance infrastructure may perform a similar function for digital content.
Not by certifying truth.
By reducing uncertainty about origin.
That is less glamorous than solving misinformation.
It is also more realistic.
Europe’s transparency regime is now enforceable, primarily through national market-surveillance authorities, with particular roles assigned to the AI Office and the European Data Protection Supervisor. Violations of relevant AI Act obligations can attract substantial administrative penalties — in applicable cases reaching €15 million or 3 per cent of worldwide annual turnover for the preceding financial year.9
That changes the nature of the exercise.
Provenance is no longer merely something responsible technology companies might voluntarily consider.
For covered systems in Europe, it has entered compliance.
There will be failures.
Marks will be stripped.
Standards will compete.
Bad actors will evade them.
Courts will eventually have to give content to words such as robust, reliable, obvious, deepfake and editorial control.
The technology will change faster than parts of the doctrine built around it.
None of this is unusual.
Land registries contain mistakes.
Corporate registries contain fraud.
Receipts can be forged.
Chains of custody can break.
We did not therefore abolish title, registration, receipts or evidence rules.
Institutions do not need to eliminate deception in order to make deception more expensive.
That may be the proper measure of Article 50.
For most of human history, sensory evidence carried enormous weight because reality had an expensive production process.
An event normally had to happen before somebody could convincingly record it.
That relationship has been broken.
A machine can now manufacture the witness without the event.
Once that becomes ordinary, authenticity can no longer remain merely an assumption carried inside the photograph, the voice or the moving image.
It needs a record outside them.
Money has records.
Land has title.
Evidence has custody.
Important transactions leave receipts.
Now reality is beginning to acquire paperwork.
Seeing will still matter.
Hearing will still matter.
But increasingly, neither will be enough.
The machine can manufacture the witness.
The witness will need identification.
- European Parliament and Council, Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, art. 50; European Commission, “Guidelines on Transparency Obligations for Providers and Deployers of AI Systems,” July 20, 2026. Article 50 transparency obligations became applicable on August 2, 2026. EUR-Lex. ↩
- European Commission, “Commission Starts Enforcing AI Act Rules and New Transparency Requirements on 2 August,” July 31, 2026. European Commission. ↩
- Regulation (EU) 2024/1689, art. 50(2). EUR-Lex. ↩
- European Commission, “Guidelines and Code of Practice on Transparent AI Systems.” European Commission. ↩
- Bilva Chandra et al., Reducing Risks Posed by Synthetic Content — An Overview of Technical Approaches to Digital Content Transparency, NIST AI 100-4. NIST. ↩
- Coalition for Content Provenance and Authenticity, C2PA Explainer. C2PA. ↩
- Regulation (EU) 2024/1689, art. 50; European Commission, “Transparency Obligations under Article 50 of the AI Act.” EUR-Lex. ↩
- European Commission, “Transparency Obligations under Article 50 of the AI Act.” European Commission. ↩
- European Commission, “Transparency Obligations under Article 50 of the AI Act.” European Commission. ↩
Leave a Reply