Skip to content

All resources

Compliance

If It Was Made by AI, You Have to Be Able to Show It: Disclosure and Provenance

The EU AI Act's transparency duties apply from 2 August 2026 and land on the party that publishes. After-the-fact detection does not work, so the only workable answer is recording provenance while the work happens.

A reel of audio stamped before it leaves the desk as the vendor walks away
A reel of audio stamped before it leaves the desk as the vendor walks away

On 2 August 2026 the EU AI Act's transparency rules switch on. If you are a brand publishing into the European market and you AI-dub a product video or an e-learning course into EU languages, some of that content now carries a legal duty to be labeled, and the duty lands on you as the publisher rather than on your AI vendor.

There is a second problem sitting behind the first, and it is the one buyers underestimate. You cannot disclose what you do not know about. Localization budgets get split across more hands than most buyers realize: brand to agency, agency to boutique studio, studio to a freelancer or a tooling tier you never see. An AI step can enter anywhere along that chain, and nothing makes it travel back up.

This post covers what the Act actually requires, which duty lands on which party, why after-the-fact detection does not solve the second problem, and what does. It is an orientation for buyers, not legal advice.

[Average read time: 8 minutes]

What the Act requires

The relevant law is Regulation (EU) 2024/1689, the Artificial Intelligence Act, adopted on 13 June 2024 and published in the Official Journal on 12 July 2024 (Source: artificialintelligenceact.eu). The part that matters for localization is Article 50.

Two duties live inside it, and confusing them is the most common mistake we see.

Machine-readable marking. Article 50(2) says providers of AI systems that generate synthetic audio, image, video, or text must make sure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This is the technical watermark or provenance metadata embedded in the file.

Human-facing disclosure. Article 50(4) says deployers of an AI system that generates or manipulates image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. This is the visible or audible notice that tells an actual viewer.

These are not the same requirement and they do not fall on the same party.

The scope is narrower than the anxiety around it. The Act defines a deepfake at Article 3(60) as AI-generated or manipulated image, audio, or video content that resembles real persons, objects, places, or events and would falsely appear authentic to a viewer. That covers image, audio, and video, not standalone text. AI-generated marketing copy runs on a separate track, and only when published to inform the public on matters of public interest. So an AI-translated product description is usually a different question from an AI face-swapped spokesperson.

Two more things worth getting right. There are carve-outs that need verification case by case: Article 50(2) does not apply where the AI performs an assistive function for standard editing or does not substantially alter the input data or its meaning, and there is separate nuance for evident artistic, creative, or satirical work. A tool that cleans up a human translation is a different situation from a tool that generates the voice from scratch.

And a vocabulary point that saves arguments later. People call this the "limited risk" band. That phrase is common shorthand but it is not a defined tier in the legislative text. Article 50 is a parallel transparency track that can apply across risk levels. Say "transparency obligations under Article 50" rather than inventing a tier, because the invented tier is what leads teams to assume deferrals apply to them when they do not.

Who carries it, and why it lands on the brand

The Act splits duties between two roles.

Provider: the entity that develops the AI system, or has it developed, and puts it on the market. In localization, usually your AI dubbing or voice tool vendor.

Deployer: the entity that uses the AI system under its own authority. When you publish AI-localized content in the EU, that is typically you.

So the marking duty under 50(2) is the provider's job, and you should not assume you have to watermark your own output. Your core duty is the deployer disclosure under 50(4): telling viewers the content is artificial.

Two things complicate that clean split.

Tool access does not transfer the obligation. A vendor handing you a license does not absorb your disclosure duty.

And white-labeling reverses it. If you put the tool under your own trademark, you can be treated as the provider, which pulls the marking duty toward you as well. Flag that one with your legal team before a procurement team signs something on the basis that it is only a rebrand.

There is a chain version of the same problem. A subcontractor using an AI system under its own authority can meet the deployer definition too. But the obligation to tell the audience can still land on you as the publishing brand even when a third-tier subcontractor did the AI work and never told you about it. Liability does not dilute the way accountability does.

Timeline, as of mid-2026

Dates are where this gets risky, so here is the picture.

The Act entered into force on 1 August 2024, twenty days after publication. Obligations switch on in stages. The Article 50 transparency obligations apply from 2 August 2026, so the deployer disclosure duties under 50(4) are essentially at their starting line.

One piece of relief is worth knowing. For generative systems already on the market before 2 August 2026, there is a grace period to 2 December 2026 for the Article 50(2) machine-readable marking duty. That relief is about marking, and it is a provider-side allowance. It does not touch the deployer's duty to disclose.

The Commission's Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 (Source: digital-strategy.ec.europa.eu). It shapes how the marking and disclosure duties are expected to be met in practice, and it is worth reading before you set your own disclosure wording.

Two things you may have read that do not change your planning. The "Digital Omnibus" discussion around softening these rules was not in the Official Journal and not binding as of 30 June 2026, so we would not plan around it. And the longer deferrals reported into 2027 and 2028 concern high-risk systems, which is a different part of the Act.

Consent is a separate regime, and it may bite first

Voice cloning brings a second body of law into the room, and it is not the same law.

Under the GDPR, voice is always personal data. It becomes special-category biometric data only when processed for the purpose of uniquely identifying a person, which is when the Article 9 explicit-consent requirement attaches. The consent and likeness question exists regardless of where that biometric line falls: if you clone a presenter's voice to dub a course into 20 languages, you need the rights to do it, and a vendor's interface will not check that for you.

For a US brand, domestic law may bite before the EU does. California's AB 2602, effective 1 January 2025, requires a contract to include reasonably specific consent before a performer's voice or likeness is reproduced as a digital replica. AB 1836, effective 1 January 2026, extends estate permission to digital replicas of deceased performers. SAG-AFTRA's Interactive Media Agreement, ratified on 9 July 2025, requires separate, written, reasonably specific consent before a performer's digital replica is created or used, void if the use exceeds the described scope (Source: sagaftra.org). Our post on voice cloning covers how those terms get captured in practice.

Keep the two threads apart when you brief anyone. One is a disclosure duty owed to the audience. The other is a consent regime owed to a person. Meeting one does not meet the other.

Signals that an undeclared AI step happened

Suppose you suspect a deliverable came back with an AI step nobody declared. What can you actually read off the file?

Some things, in a lazy chain. In translated or subtitled deliverables the common tells are over-consistent terminology and register, where raw machine output repeats the same rendering everywhere including where a human would vary it; suspiciously literal idioms, calques, and false friends left in place; formality and gender handled inconsistently, the tu/vous or du/Sie problem a native post-editor catches on the first pass; subtitle lines that ignore reading-speed limits or mirror source segmentation one-to-one instead of being reshaped to the picture; flattened cultural references and smoothed-away wordplay; and file or metadata residue, meaning CAT-tool artefacts, segment-level uniformity, or machine-translation confidence fields left inside the delivered files.

In audio the tells sit in texture rather than words, because a modern cloned voice passes a casual listen: intonation that resets the same way across sentences, or emphasis landing on the wrong word; breath and room tone that is either too clean or spliced in at regular intervals; faint warble on sustained vowels and odd transitions between phrases; proper nouns and brand names pronounced in a way no local speaker would, with no self-correction; and metadata gaps, meaning no session details, no talent name, no studio, just a render timestamp.

Here is the limit. A careful post-editor erases nearly all the text signals, and a good render leaves few audio ones. These catch a careless chain, not a diligent one. On a well-edited file they give you no usable read at all.

A logbook entry written as the work passes, while others chase it with nets
A logbook entry written as the work passes, while others chase it with nets

Detectors give suspicion, not proof, and they give it after publication.

What detection tools actually do

It is tempting to reach for a detector and call the problem solved. The reality is thinner than the marketing.

AI-text detectors exist and some are credible: Pangram, GPTZero, Originality.ai, and Turnitin among them. Their reliability is contested. Headline accuracy for leading tools has been measured as low as the low-to-mid 60s percent in some studies, and near zero on hybrid text where a human edited AI output, which is exactly the lightly post-edited case you most want to catch (Source: published detector studies, 2026). False positives skew hard against non-native English writers: one study reported a mean false-positive rate of 61.3 percent for TOEFL essays by Chinese students against 5.1 percent for US students. Running a detector over a vendor's work is therefore not a neutral act.

For translation specifically it is worse. There is no reliable dedicated machine-translation detector as a product class. Machine translation and paraphrasing are documented mainly as things that confuse AI-text detectors and raise false positives, rather than as something those tools flag cleanly. A detector result on a translated file is close to noise.

Watermark detection is more solid where a watermark exists. If a vendor marked its output with something like SynthID, the matching detector can confirm it. That only works when the upstream tool applied the mark, and application is not yet universal: ElevenLabs, for example, began rolling out SynthID but as of mid-2026 it was default only for free-tier text-to-speech and not applied to every generation (Source: vendor documentation, 2026). So a missing watermark proves nothing, and a present one is a bonus rather than something you can rely on across the market. What is fixed is the Code of Practice; what is still uneven is how individual vendors implement marking under it.

The fix is provenance, not forensics

Stack those facts up and the conclusion is plain. Text signals catch only careless work. Voice signals catch only sloppy renders. Detectors are unreliable on exactly the hybrid and translated content you most need them for. Forensics gives you suspicion rather than proof, and it gives it after the file is already published under your name.

Provenance flips the order. Instead of reverse-engineering how a deliverable was made, require the chain to document it going in: who translated, who voiced, which tools touched the file, and what consent and licences sit behind any synthetic step. Recorded before the file ships rather than reconstructed after a dispute.

Three decisions stay with a named person on your side: deciding when Article 50 disclosure applies to a given asset, writing the disclosure so a real viewer understands it, and confirming consent and rights before any voice or likeness is cloned. A model can produce the dub. It cannot decide whether a given asset is a deepfake under Article 3(60), whether your disclosure wording is adequate, or whether you had the right to clone a particular voice.

This is a discipline built at scale rather than per file, and it is the reason we treat provenance documentation as a deliverable and hand over finished video rather than access to whatever tool produced it. If you buy localization across a chain, that paper trail is worth specifying before the work starts.

Bookmark this one. The dates and the Commission guidance are still moving, but the broad shape is unlikely to change: if you publish AI-altered content into the EU, someone on your side has to be able to say what is AI and show they were allowed to make it. Our white paper, Localizing in the Age of Generative AI, walks through where that review belongs in an AI-assisted pipeline.