Compliance
Does the EU AI Act make you watermark your chatbot's text?
Article 50(2) of the EU AI Act has required machine-readable marking of AI-generated text since 2 August 2026. No reliable way to do that exists yet.
Unity Horizon4 min read
Yes, if your product generates text and a person reads it. Article 50(2) of the EU AI Act has required machine-readable marking of AI-generated text since 2 August 2026. The obligation is real. A watermark that reliably survives contact with a reader does not exist, not for text.
Checked against the primary sources on 9 August 2026.
What exactly does Article 50 require, and from when?
Article 50 splits into four duties across two roles, and most coverage of "the AI Act deadline" flattens the split.
| Duty | Who owns it | What it requires | In force |
|---|---|---|---|
| Art. 50(1) | Provider | Tell the user they are talking to an AI system | 2 Aug 2026, no grace period |
| Art. 50(2) | Provider | Mark generated text, audio, image or video output in a machine-readable, detectable format | 2 Aug 2026, grace to 2 Dec 2026 for pre-existing systems |
| Art. 50(3) | Deployer | Tell people exposed to emotion recognition or biometric categorisation | 2 Aug 2026, no grace period |
| Art. 50(4) | Deployer | Label deepfakes and AI-generated public-interest text | 2 Aug 2026, no grace period |
If you built the feature, you carry (1) and (2). If you bought someone else's AI tool and run it in your business, you carry (3) and (4) when they apply. A studio shipping a chat agent is almost always a provider, which puts the harder of the four duties, the marking one, on us and not on the client.
Why does only one of these four duties have a grace period?
Because nobody could ship it on time. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026, six days before Article 50 took effect. It deferred the Annex III high-risk obligations from August 2026 to 2 December 2027, and gave the Article 50(2) marking duty a four-month transition, to 2 December 2026, for systems already on the market before 2 August.
Everything else in Article 50 stayed exactly on schedule. The disclosure duty is a sentence in a chat window. The marking duty is a piece of engineering, and the Commission's own implementation guidelines, published 20 July, only qualify it as required "as far as technically feasible." That phrase is carrying more weight than it looks like it can hold.
Does "machine-readable marking" mean watermarking, and does it work for text?
Watermarking is the practical answer for audio, image and video, where a file has room to spare. A JPEG can absorb noise a viewer never notices. Text cannot. Any change large enough for a detector to find later is also large enough for a reader to notice while reading, because text is already the compressed version of the idea.
The two methods in circulation today both fail on contact. Token-sampling watermarks, the SynthID-style approach, bias which word the model picks next according to a hidden pattern. A second model paraphrasing the output erases that pattern along with the original wording. Unicode-homoglyph marks hide invisible characters, like a three-per-em space, inside the text. A single find-and-replace strips them. Sean Goedecke laid this out in detail on 2 July 2026, and the argument holds regardless of who runs the model.
The law asks for a mark. Text has nowhere to hide it.
There is a second problem the regulation creates for itself. Article 50 also requires marking methods to be interoperable, which in practice means publishing how they work. A published watermark teaches its own removal.
So what does a small studio actually build before 2 December?
Not a working text watermark, because one does not exist to build. What exists is the disclosure duty, which is achievable this week: say plainly, in the interface, that the reply came from a system and not a person. Beyond that, the honest position is procedural rather than technical: keep a written record of what was tried and why it meets "as far as technically feasible," attach whatever metadata your generation pipeline can carry, and revisit this as the Commission's Code of Practice, last updated 31 July 2026, matures.
This splits by category, not by size on paper. A platform already piping content through a provenance system, Adobe's Content Credentials in its creative tools is one visible example, extends a pipeline that already exists. A five-person studio whose only generative surface is a paragraph of chat text has no pipeline to extend, and nothing to attach a manifest to.
Fines for getting this wrong are not small. Article 99 sets the ceiling for Article 50 non-compliance at fifteen million euros or 3% of global annual turnover, whichever is higher, per the EU AI Act Service Desk, with SMEs capped at the lower of the two figures. Enforcement runs through national market surveillance authorities, and nobody has published a first case yet.
We have not built a production text-marking pipeline ourselves. This is a reading of the guidelines and the watermarking research, not a system we run, and if the Commission's Code of Practice lands on a method that actually survives paraphrasing, we would rather use that than our own guess.
Which reply your product sent this week would a person mistake for one a human wrote, and does your interface say so yet? If you are scoping a generative AI feature and want the compliance boundary mapped before you build, that is the kind of thing we scope.
Common questions
- Does the EU AI Act require watermarking AI-generated text?
- Yes. Article 50(2) requires providers of generative AI systems to mark synthetic text, audio, image and video output in a machine-readable, detectable format, and it has applied since 2 August 2026. The obligation exists. A watermarking method that reliably survives contact with a reader does not, at least not for text.
- When does the machine-readable marking duty for AI-generated text take effect?
- It applies from 2 August 2026. Systems already on the market before that date get a four-month transitional period for the marking duty only, until 2 December 2026, added by the Digital Omnibus on AI, Regulation (EU) 2026/1744. The duty to disclose that a user is talking to an AI system has no such grace period.
- What is the difference between the Article 50 disclosure duty and the marking duty?
- Article 50(1) requires a provider to tell a user they are interacting with an AI system. Article 50(2) requires the AI system's own output to carry a machine-readable mark. They are separate duties with separate mechanisms, and the second is the harder engineering problem.
- Why is watermarking text harder than watermarking images or video?
- Image and video files have imperceptible bits to spare for a mark. Text does not. A change large enough to survive editing is also large enough for a reader to notice, and the two watermarking approaches in use today, token-sampling patterns and invisible Unicode characters, are both defeated by paraphrasing or a simple find-and-replace.
[ NEXT ]
Want this built for you?
Thirty minutes, no prep, no pitch. Tell us what slows your business down and we'll show you what an agent can do about it.
Book a call