Europe's AI transparency rules went live three weeks ago. Only half of them are enforceable.
Article 50 of the EU AI Act became enforceable on 2 August. Three weeks in, I keep coming back to the same observation: it contains two obligations that look similar on paper and behave nothing alike in production.
The first is disclosure. If a person is interacting with an AI system, the system has to say so. Chatbots, voice agents, interactive assistants — they identify themselves at the first point of contact.
The second is marking. Providers of generative systems have to mark their outputs in a machine-readable format so synthetic content can be detected. Deepfakes carry a visible label on top of that.
The Commission's AI Office and national authorities started enforcing both on the same day, and both carry the same exposure — up to 15 million euros or 3% of worldwide turnover.
One of them is a solved problem. The other one is not.
Disclosure is a string. A line in a system prompt, a preamble on a voice agent, a label above the first message. I have shipped interactive AI into an automotive deployment in Europe, and telling the user they were talking to a machine was never the difficult part. The difficult part was making it useful in multiple languages with no network connection. Anyone describing disclosure as a compliance burden is telling on themselves — they were hoping you would assume it was a person.
Marking is a different animal entirely.
Watermarks and signed provenance manifests are signals, not proof. A C2PA manifest survives exactly until something re-encodes the file. A resize, an ffmpeg pass, an upload pipeline that normalises media — most of them strip it without asking and without telling anyone. Imperceptible watermarks hold up better against casual handling and considerably worse against anyone actually trying; researchers have been degrading them below detection thresholds for years.
So you land in a position where a mark being present tells you something useful, and a mark being absent tells you nothing at all. That asymmetry is the entire story, and it is the part that disappears when this gets summarised as "AI content will now be detectable."
Then there is my own corner of this. The marking obligation sits with the provider of the generative system. But I build systems that run on the device — offline, on the customer's hardware, under their control, because that is where the data already is and that is where it should stay. When the model is running on a laptop in a plant or a handset in the field with no connectivity, the provider has no runtime left to reach into. You can ship the marking code inside the model runtime. You cannot ship a guarantee that it is still there after someone quantises the weights or pipes the output through their own tooling.
That is not an argument against the rule. It is an argument about where enforcement pressure actually lands: on the deployer, at the point of publication, rather than on the provider, at the point of generation. The Act does place a disclosure duty on deployers publishing AI-generated material on matters of public interest. I suspect that half will do more real work than the machine-readable half ever does.
Three things I would tell anyone shipping into the EU right now.
Do the disclosure properly and stop negotiating with it. First contact, plain language, in the user's own language, not buried three taps deep in a settings screen. If your product's value depends on the user not knowing, you do not have a product.
Treat marking as a chain-of-custody problem rather than a detection feature. Sign at generation, log what you generated, retain the log. When someone asks whether your system produced a given artefact, you want to answer from your own records, not from a scan of a file that has passed through four pipelines since it left you.
And do not build anything downstream that treats an unmarked file as human-made. That single inference is the genuinely dangerous thing this regulation could accidentally teach an entire industry.
There is a pattern here that goes well beyond this one law. The rule that survives contact with production is the one you can implement in an afternoon inside your own system. The rule that requires the whole internet to cooperate is going to take a great deal longer than a compliance deadline.