HOW AI GETS LABELLED
Since 2 August 2026, EU law requires AI content to be marked.
Article 50 of the EU AI Act now requires providers of generative AI systems to mark their outputs in a machine-readable format, with penalties reaching into the millions of euros or a percentage of global turnover. California's SB 942 took effect on 1 January 2026. There is no equivalent global rule — so most content you encounter still carries nothing at all.Sources: EU AI Act Article 50, in force 2 Aug 2026; EU transparency Code of Practice published 10 Jun 2026; California SB 942, in force 1 Jan 2026. Recorded 4 Aug 2026.
Two technologies, two different failures
The industry has converged on using both at once, for a reason worth understanding: each one fails in a way the other survives.
Content Credentials
An open standard. A cryptographically signed manifest travels inside the file, recording what made it and how it was edited. Because the signature is verifiable, tampering is detectable rather than silent.
Deployed by Adobe Firefly, OpenAI's image tools, Google Imagen, Microsoft's Office content, and in camera hardware from Leica, Sony and recent flagship phones.
Invisible watermarks
The mark lives in the pixels or the audio rather than the metadata, so it survives re-encoding, resizing and screenshots. Google reports watermarking on a scale of tens of billions of items and other providers have adopted the approach.Reported figures for SynthID-marked images vary by source and date between roughly 20 billion and 100 billion; treat the order of magnitude, not the number.
The European Commission's own Code of Practice endorses the layered approach explicitly, which is a quiet admission worth noticing: the regulator does not believe any single technique is sufficient.
The rule that matters most
A present, valid credential is useful evidence that content came from where it claims. An absent credential is evidence of nothing at all — the tool may not mark, the mark may have been stripped in transit, or the file may simply be an ordinary photograph. If labelling becomes widely expected, the dangerous failure mode is not fake labels; it is people treating "no label" as "not real", or worse, as "verified human".
Where it does not reach yet
Text has no working equivalent. Every technique on this page applies to images, audio and video. There is no widely implemented provenance standard for written words, which is precisely the category where the volume is highest — roughly half of new articles, by the figures in the quarterly record. Detection for text remains too unreliable to accuse anyone with, and provenance does not fill the gap.
Adoption is uneven. Some major generators mark by default; at least one very large image tool has been publicly noted as not implementing content credentials at all. Open-weights models running on private hardware are outside every scheme by construction — nobody can compel a marking step in software someone downloaded.
Certificates cost money. There is no free issuing service equivalent to what exists for website encryption, which puts credential signing out of reach for many independent creators — the people whose work most needs a way to prove it is theirs.
What to actually do with this
- Check credentials when the stakes are high — a news image, a document, a claim about a person. Platforms increasingly surface a credentials indicator; the issuing provider's own verifier is usually the most reliable place to check.
- Never read absence as authenticity. This is the failure this page exists to prevent.
- Label your own work. If you publish machine-assisted material, say so — as this site does on its about page. Voluntary disclosure is worth more than compelled disclosure, because it is the part nobody can strip.
- Keep verifying by provenance in the ordinary sense — where did this come from, does it exist elsewhere, is there a second witness. That test predates all of this technology and outlives it.
Labelling is the most encouraging development this site covers, and it is being oversold. It genuinely helps: a signed credential is stronger evidence than any detector score, and a legal requirement moves the default from "nobody marks" to "the largest providers must". But it covers the wrong half of the problem — images and video are marked while text, the highest-volume category, is not — and it can be stripped by a screenshot. Support it, use it, and do not mistake it for a solution.