
By Chris Meredith
The clock didn’t start ticking on August 2. The clock ran out.
That’s when Article 50 of the EU AI Act went live, making the European Union the first major jurisdiction on earth to legally require that deepfakes be labeled, chatbots identify themselves at first contact, and AI-generated content carry machine-readable watermarks. What you see on social media, what you hear on a customer support call, what you watch in a video conference — if it’s AI-generated and it reaches someone in the EU, compliance is no longer optional.
The fines for getting it wrong are €15 million or 3% of global annual turnover, whichever is higher. For most of the companies building or deploying generative AI, that’s not a rounding error.

The Fraud That Pushed Brussels Past the Line
Regulators don’t usually move this fast. The EU took four years to finalize the AI Act, so what made Article 50 feel urgent?
Part of the answer is a single incident involving a finance employee at the global engineering firm Arup. In early 2024, that employee joined a video call and watched what appeared to be the company’s CFO and several colleagues give instructions to transfer money. They were convincing. They were live. They were completely fake. When the call ended, the employee had authorized a $25.6 million wire transfer to accounts controlled by criminals.
Nobody in that call was real. Every face had been synthesized. Every voice had been cloned. The fraud worked because deepfakes had become good enough that trained professionals couldn’t tell the difference under normal working conditions.
That case became a case study in Brussels and a political accelerant. The EU hadn’t invented the transparency obligations in Article 50 in response to Arup specifically, but the incident crystallized exactly why disclosure requirements needed teeth, and why waiting for companies to self-regulate wasn’t going to work.
What Article 50 Actually Requires
The regulation breaks into four distinct obligations, each targeting a different type of AI interaction.
Chatbot disclosure. If you deploy a conversational AI system that interacts with humans, it must identify itself as an AI at the start of every session — not buried in a terms of service footnote, but at the moment of first contact. This applies to customer service bots, sales assistants, any system where a user might reasonably believe they’re talking to a person.
Deepfake labeling. Any image, audio clip, or video generated or substantially modified by AI must carry a visible disclosure. The requirement doesn’t distinguish between a harmless product-demonstration video and a political disinformation campaign. If the content is synthetic, the label is mandatory.
AI-generated text in public interest. News articles, government communications, and educational content generated by AI for public consumption require clear disclosure. This one has implications that go well beyond marketing teams — it reaches publishers, public institutions, and any organization producing AI-assisted content that shapes public opinion.
Biometric and emotion recognition. Any system that categorizes individuals based on biometric data or infers their emotional state must disclose that capability to affected individuals.
The penalties cover all four. And the structure of the regulation means there’s no minimum footprint threshold — if your product reaches EU residents, you’re subject to it.

The Watermarking Problem Nobody Has Solved
Here’s where the regulation gets complicated, and why it’s generating real anxiety inside AI companies: no single watermarking technology currently meets all four of the EU’s technical requirements. The law asks for watermarks that are effective, interoperable, robust, and reliable. The honest assessment is that nothing in existence checks all four boxes.
C2PA — the Content Credentials standard developed by an industry coalition that includes Adobe, Microsoft, and Leica — is the closest thing to an emerging industry norm. It embeds cryptographically signed metadata directly into a file, creating a verifiable chain of custody that records where content was created and what tools processed it. This works well when content stays in a controlled environment. It doesn’t work particularly well when someone takes a screenshot.
A screenshot strips C2PA metadata completely. Upload that screenshot to Instagram and the watermark is gone. The content credential never existed as far as any downstream verification system can tell. This isn’t a fringe scenario; it’s the most common way AI-generated content gets shared.
The alternative approach is imperceptible watermarking: altering the image or audio data itself in ways invisible to humans but detectable by specialized algorithms. Google’s SynthID uses this technique and has shown considerably better resilience to re-uploads and file format conversions. But it’s not universal, it’s not interoperable with competing systems, and it’s owned by one of the companies whose products it’s meant to police.
The EU’s response to this gap is to require both. Regulators are effectively mandating a multi-layer approach: C2PA credentials for machine-readable provenance plus imperceptible watermarking for robustness. Neither alone is sufficient, and the technical standards to implement this comprehensively across the industry don’t fully exist yet.
This is why existing systems get a compliance window through December 2, 2026. The EU knows the technology isn’t there yet. The regulation is setting direction while the standards bodies catch up.
Who’s Actually On the Hook
The language of Article 50 places obligations on “deployers” — the companies that put AI systems in front of users — rather than purely on the AI model providers. This matters a lot in practice.
If you’re running a customer service operation that uses an OpenAI API to power a chatbot, the responsibility for the disclosure at the start of that chat isn’t primarily OpenAI’s. It’s yours. The obligation flows to whoever made the decision to deploy the system and whoever controls the user-facing interface.
This creates immediate compliance exposure for businesses that have quietly deployed AI-generated content without thinking much about disclosure, because they assumed their AI vendor had it covered. Many of them don’t. And the enforcement structure makes it clear that “we used a third-party model” won’t function as a defense.
Enforcement runs through national market surveillance authorities across all 27 EU member states. That’s 27 separate regulatory bodies with varying levels of technical sophistication, political will, and interpretive frameworks. Some will be aggressive. Some will take time to build capacity. The variance across member states is real, but it doesn’t make the exposure go away — it makes it less predictable.
The Broader Compliance Posture This Demands
Businesses operating in the EU, or selling to EU customers, need to treat August 2 as the beginning of a compliance sprint rather than a distant milestone. The December window for existing systems is not a grace period in the conventional sense. It’s a technical accommodation for deployment complexity — the underlying legal obligation is already live.
The practical checklist looks something like this:
Every AI-facing customer touchpoint needs an audit. That means cataloging every use of generative AI in customer communications, support flows, content production, and sales materials. Companies that haven’t done this are usually surprised by how many deployment points they’ve accumulated over the past two years.
Every chatbot interaction needs a disclosure layer. Not a consent form at account creation. Not a privacy policy update. An active, session-level disclosure that tells the user they’re interacting with an AI, every time.
Every piece of synthetic media needs a labeling strategy. This requires decisions about which watermarking approaches to implement, how to handle legacy content, and what disclosure UI looks like across different distribution channels.
Every vendor relationship needs a review. If you’re relying on an AI provider to handle any of this on your behalf, you need written confirmation of what they’re actually providing — and whether it meets Article 50’s requirements as regulators interpret them.
What This Means Beyond the EU
The EU has an established track record of setting regulatory floors that become de facto global standards. GDPR became the baseline for privacy regulation worldwide, not because other jurisdictions had to adopt it but because serving a global user base with EU-specific exceptions is operationally expensive and reputationally awkward. Companies generally found it easier to just comply everywhere.
Article 50 is likely to follow the same trajectory. The content credential standards, disclosure UI patterns, and watermarking implementations that companies build to meet EU requirements will become the default architecture globally. The infrastructure investment happens once.
What regulators haven’t fully solved — and what won’t be resolved by December — is the deepfake detection problem on the receiving end. Labels require good-faith compliance from the content producers. They don’t stop a bad actor from stripping metadata and redistributing. The $25.6 million that left Arup’s accounts wouldn’t have been protected by Article 50 even if it had been in force, because the criminals creating the deepfake weren’t going to label their work.
The disclosure requirements protect against confusion and incidental harm. They don’t protect against deliberate fraud. That gap is real, and it’s one that no compliance framework has answered yet.
The Bottom Line
August 2 is not a drill. If your business deploys AI systems that interact with EU residents, you’re already operating under live disclosure requirements. The December window exists to accommodate technical complexity, not to delay legal exposure.
The companies that move quickly on compliance audits right now aren’t just avoiding fines. They’re building the institutional muscle to operate in an AI-regulated world, which is the world every major market is moving toward. The EU went first. It won’t be the last.
The deepfake problem is real. The Arup incident was not an edge case — it was a preview. The regulation that answered it is imperfect, technically incomplete, and necessary.
Chris Meredith writes about AI, technology, and the systems shaping how we work.
Chris Meredith writes about AI, technology, and what it actually means for real people. Follow along on Substack: monkeyattack.substack.com