The EU AI Label Is Here: A First Look at the Official 2026 Transparency Icons and Watermarking Rules
The EU AI Label Is Here: A First Look at the Official 2026 Transparency Icons and Watermarking Rules

The EU AI Label Is Here: A First Look at the Official 2026 Transparency Icons and Watermarking Rules

New Publication European Commission · 5 March 2026 · Code of Practice on AI Content Marking — Draft 2
Regulatory Update · 9 min read · Published 10 March 2026

On 5 March 2026, the European Commission published the second draft of the Code of Practice on Marking and Labelling of AI-Generated Content — the document that defines exactly how the Article 50 transparency obligations translate into concrete, visual, and machine-readable implementation. For the first time, we can see what the EU AI Icon looks like, how watermarking must be embedded, and what technical specifications content creators, platforms, and AI tool providers must meet. This is one of the most practically important documents published under the EU AI Act to date.

Key Facts
  • The Code of Practice is currently a draft — comments are open until 30 April 2026. Final version expected June 2026. Compliance required by August 2026.
  • The EU AI Icon is a standardised visual symbol — a stylised “AI” mark with a specific design specification — that must appear on AI-generated content in defined contexts.
  • Machine-readable watermarking using C2PA Content Credentials is adopted as the de facto technical standard for embedded metadata watermarking.
  • The Code applies to providers of AI tools that generate content and to deployers (operators) who distribute AI-generated content to EU audiences.

1. What Is the Code of Practice on AI Content Marking?

The EU AI Act’s Article 50 requires that AI-generated content be disclosed as such — but Article 50 itself is relatively high-level. It mandates disclosure of AI origin without specifying exactly what the disclosure must look like, where it must appear, or what technical format must be used. The Code of Practice fills that gap.

The Code is developed by the EU AI Office in consultation with industry, civil society, and technical standards bodies. Draft 1 (published September 2025) established the conceptual framework. Draft 2 (5 March 2026) is the first version to include specific technical specifications, icon designs, and implementation timelines. A final version is expected by June 2026.

Legal status of the Code of Practice
The Code of Practice is not a regulation — compliance with it is voluntary. However, adherence to the Code creates a presumption of compliance with Article 50 of the EU AI Act for the requirements it covers. Organisations that do not follow the Code must demonstrate alternative means of complying with Article 50 — and risk being found non-compliant if their alternative approach does not meet the same standard. In practice, the Code is the implementation playbook for Article 50.

2. The EU AI Icon: Design and Display Requirements

Draft 2 introduces the official EU AI Icon — a standardised visual symbol that must accompany AI-generated content in defined contexts. The icon is described in Annex A of the Code as a stylised representation of the letters “AI” enclosed in a rounded rectangle with the EU star ring motif, in a specified blue pantone colour (PMS 286 C). A vector format asset is published alongside the Code for implementers.

AI ★★★ ★★★ ★★★
Conceptual approximation of the EU AI Icon (not the official vector — obtain the official asset from the EU AI Office)
Display RequirementSpecification in Draft 2
Minimum display size24×24 pixels for digital content; 5mm × 5mm for print. Must be legible at normal viewing distance.
PositionCorner of the content (any corner acceptable); must not overlap text that is part of the content. For video: persistent display in corner for entire duration or during AI-generated segments.
ColourOfficial EU blue (PMS 286 C / HEX #003399) on white or light backgrounds. White icon on EU blue background for dark backgrounds. No alternative colours permitted.
Tooltip / accessible labelThe icon must be accompanied by an accessible text label “AI-generated content” in the relevant EU language, accessible via hover, screen reader, or click.
Linking requirementIcon (or accompanying label) must link to or be accompanied by a disclosure that the content was AI-generated, identifying the AI tool or system used where technically feasible.
Where not requiredContent that is obviously AI-generated from context; content generated for internal use not published to EU audiences; content used in closed professional workflows. See Annex B of the Code for full exclusion list.
⚠️
The icon cannot be modified. Providers and deployers must use the official EU AI Office vector asset without modification of colour, proportions, or design elements. Creating a “similar” icon or an “inspired by” version that could be confused with the official icon but does not comply with specifications will not satisfy the Article 50 requirement and may create additional consumer protection liability.

3. Machine-Readable Watermarking: The C2PA Standard Adopted

Beyond the human-visible EU AI Icon, Article 50 requires AI-generated content to carry machine-readable disclosure — metadata that can be detected by browsers, platforms, search engines, and automated content moderation systems. Draft 2 formally adopts the C2PA (Coalition for Content Provenance and Authenticity) Content Credentials standard as the technical implementation pathway for machine-readable watermarking.

The C2PA specification is an open standard developed by Adobe, Microsoft, Intel, the BBC, and others, that enables the cryptographic signing of digital content with provenance metadata — including information about how content was created, what AI tools were used, and what modifications were made. C2PA metadata travels with the file even when downloaded or shared.

What C2PA Content Credentials contain (for AI-generated content)
Assertion that the content was AI-generated
Name and version of the AI model used
Date and time of generation
Provider identity (cryptographic signature)
Whether and how the content was modified post-generation
Link to a human-readable disclosure page
✓ Already C2PA compatible
Adobe Firefly, Microsoft Designer, Stable Diffusion XL (via Stability AI implementation), Getty Images AI generator, DALL-E 3 (limited metadata), Google’s SynthID (different approach — see below)
⚠ Implementation gaps
Many mid-tier and open-source image generation tools do not yet implement C2PA. Video and audio generation tools are largely behind. Text generation (LLMs) has no widely implemented equivalent — see the text content section below.
Note on Google’s SynthID: Google has deployed its own proprietary watermarking technology, SynthID, which embeds imperceptible signals into AI-generated images and audio. Draft 2 of the Code acknowledges SynthID as a technically valid alternative to C2PA for embedded watermarking — provided it meets the detectability and accessibility requirements of the Code. However, SynthID’s proprietary nature means it cannot be read by non-Google systems without a separate API integration, which the Code indicates is not sufficient for the open-access requirements of Article 50.

4. Requirements by Content Type

🖼️ Images
Visual label: EU AI Icon in corner of image (minimum 24×24px). Machine-readable: C2PA Content Credentials embedded in file metadata (EXIF/XMP). Platform obligation: Platforms that display AI-generated images must preserve and display C2PA metadata, and must render the EU AI Icon if detected. Stripping prohibition: Removing C2PA metadata from AI-generated images is explicitly prohibited.
🎬 Video
Visual label: EU AI Icon persistent in corner throughout AI-generated segments (or throughout entire video if majority AI-generated). For short-form content (under 60 seconds), the label must be visible for the entire duration. Machine-readable: C2PA credentials embedded in video container metadata. Deepfakes specifically: Any video depicting identifiable real persons in scenarios they did not participate in must include the disclosure “This video contains AI-generated content depicting [person name] in a fictional scenario” in addition to the icon.
🎵 Audio
Visual label: Where audio is distributed via a visual interface (music streaming platform, podcast app), the EU AI Icon must appear in the track or episode artwork and in the platform listing. Machine-readable: C2PA credentials embedded in audio file metadata (ID3/XMP). Synthetic voices: Audio that clones or replicates an identifiable real person’s voice must include an explicit spoken disclosure at the beginning (“This audio was generated by AI and does not contain a recording of [name]”) in addition to metadata requirements.
📝 Text
This is the most contested section of Draft 2. No machine-readable standard equivalent to C2PA currently exists for text content. Draft 2 proposes: (1) a human-readable disclosure statement appearing at the start or end of AI-generated text articles; (2) use of the EU AI Icon adjacent to the text; and (3) Schema.org markup in the HTML of web pages to indicate AI authorship. For text, the Code acknowledges this is an interim solution pending development of text provenance standards by W3C and IEEE. Threshold: The text disclosure requirement applies where content is “substantially AI-generated” — defined in Draft 2 as more than 50% of the substantive text being AI-generated without human editorial revision.

5. Who Must Comply: Providers vs. Deployers

The Code places obligations at two levels of the AI content supply chain:

AI Tool Providers
Companies that build AI generation tools
  • Implement C2PA credential generation as a default feature of the AI tool (not opt-in)
  • Include EU AI Icon generation capability in the tool’s output pipeline
  • Provide API access for platforms to read and verify C2PA metadata
  • Document C2PA implementation in technical documentation (feeds into Annex IV)
  • Cannot allow users to disable watermarking for public content distribution
Content Operators / Deployers
Publishers, platforms, agencies distributing AI content
  • Must not strip or modify C2PA credentials from AI-generated content before distribution
  • Must display the EU AI Icon alongside AI-generated content if C2PA credentials are detected
  • Must add the EU AI Icon and disclosure text to AI-generated content they produce using external tools
  • Social media platforms must preserve and surface C2PA metadata in their content display systems
  • News publishers must disclose AI authorship of articles meeting the >50% substantive AI generation threshold

6. Impact on Your Compliance Checklist

The Code of Practice Draft 2 significantly clarifies what Article 50 compliance requires in practice. For organisations using our EU AI Act Compliance Checklist, these are the specific items that now have technical specifications to meet:

Checklist ItemWhat Draft 2 Now SpecifiesYour Action
Chatbot AI disclosureText “This response was generated by AI” in conversation UI — not just in terms of serviceUpdate UI design for all AI chat interfaces
Deepfake labelingEU AI Icon in corner + C2PA metadata + person-naming disclaimer for identifiable real personsImplement C2PA credential pipeline in video/image generation tools
AI-generated text disclosureDisclosure statement + EU AI Icon + Schema.org markup for >50% AI-generated articlesUpdate CMS templates and editorial workflows for AI-assisted content
Synthetic voice disclosureSpoken disclosure at audio start + C2PA metadata in audio fileUpdate TTS/voice cloning tool output pipeline
Update your Article 50 compliance tasks
Our compliance checklist covers Article 50 transparency obligations in full. We are updating the technical specifications in line with Draft 2 now.
View Compliance Checklist →

7. Frequently Asked Questions

Where can I download the official EU AI Icon vector file? +
The official EU AI Icon vector file is published alongside the Code of Practice on the EU AI Office website. The Commission has made the icon available under an open licence for use in compliance with Article 50 — it may not be modified or used for other purposes. The download package includes SVG, PNG at multiple resolutions, and a dark-background variant.
Is C2PA implementation mandatory or are there alternatives? +
C2PA is not legally mandated — it is the Code of Practice’s recommended pathway for machine-readable watermarking, and adherence to C2PA creates a presumption of compliance with the machine-readable requirement. Alternative approaches are permissible if they achieve the same level of detectability and open accessibility. In practice, C2PA has emerged as the industry standard with broad tooling support — deviating from it requires significant additional justification. For text content, where C2PA equivalents do not yet exist, Draft 2 provides interim alternatives (Schema.org markup, HTML meta tags) while acknowledging these are imperfect solutions.
When does the final Code of Practice take effect? +
The public comment period for Draft 2 closes 30 April 2026. The EU AI Office will consider submissions and publish a final version in June 2026. Article 50 compliance is required from 2 August 2026 — so organisations have approximately 2 months between the final Code publication and the compliance deadline. This is a very tight timeline for implementing C2PA credential pipelines from scratch. Organisations should begin technical implementation now based on Draft 2 specifications, which are unlikely to change materially in the final version.
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like