Why AI Watermarking Was Introduced, and What It Means for Everyone Downstream
Watermarking became a legal duty in the EU on 2 August 2026, with fines up to 15 million euros. The reasons are specific: elections, fraud, non-consensual imagery, evidence, and a problem the models are causing themselves.
Outspoken Digest Technology Desk
Thursday, August 13, 2026/4 min read

On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act became applicable, with a grace period on watermarking implementation running to early December. Providers of systems that generate synthetic audio, image, video or text must now mark those outputs in a machine-readable format. Non-compliance carries penalties up to 15 million euros or 3 per cent of global annual turnover.
Rules of that weight do not appear without specific harms behind them. It is worth listing what they are, because the debate is usually conducted at the level of slogans about authenticity.
The five reasons
1. Elections
The most cited and the most immediate. Synthetic audio is the acute problem rather than video, because voice is cheap to clone, needs only seconds of source material, and carries no visual cues to interrogate. A fabricated recording of a candidate released hours before a vote cannot be debunked in time, and the debunking never reaches the audience the original did.
2. Fraud
Voice cloning has moved impersonation fraud from mass phishing to targeted deception. The corporate version, a video call with a convincing synthetic executive authorising a transfer, has already produced very large losses. The domestic version, a phone call in a family member's voice claiming an emergency, is more common and less reported.
3. Non-consensual intimate imagery
The largest category of deepfake content by volume, overwhelmingly targeting women, and the harm is not disputed by anyone. This was one of the earliest drivers of legislative attention in multiple jurisdictions and remains the clearest case.
4. The evidentiary problem
The subtler harm, and possibly the largest. When synthetic media is plausible, genuine media becomes deniable.
Researchers call this the liar's dividend. A politician recorded saying something damaging can now say it was generated, and a meaningful share of the audience will accept that. Photographic and audio evidence has functioned as a shared factual anchor for a century, and the erosion of it is a societal cost that no individual company has any incentive to prevent.
5. Model collapse
An industry-facing motivation that rarely appears in the public argument. As AI-generated content fills the web, the training data for future models increasingly contains the output of previous ones. Training on synthetic data degrades models over successive generations.
Labelling AI content lets developers filter it out. This gives the largest AI companies a genuine self-interested reason to support provenance systems, which is worth knowing when evaluating their enthusiasm.
What the law actually requires
Article 50 splits obligations between the companies building models and the people using them.
Providers of generative systems must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This is the technical watermarking duty, discussed in how AI watermarking actually works.
Deployers, meaning anyone using these tools, have disclosure duties. If you generate or manipulate an image, audio or video that is a deep fake, you must disclose that it is artificially generated. The same applies to AI-generated text published to inform the public on matters of public interest, unless the content has undergone human editorial review with someone holding editorial responsibility.
That editorial exemption is significant for publishers. It means a newsroom that reviews and takes responsibility for AI-assisted text is not obliged to label it, while an automated content operation is.
Chatbots must also disclose that a user is interacting with a machine, unless it is obvious.
The honest criticism
Two objections deserve to be taken seriously rather than dismissed.
The mandate outpaces the technology. Text watermarking is genuinely weak, particularly for short passages, and paraphrasing degrades it. Watermarks can be stripped. Metadata is routinely removed by platforms. A legal requirement to make content detectable does not create a technology that reliably does so, and several commentators have noted that the rule arrived ahead of the capability.
It regulates the compliant. Large providers will comply. Open-weight models run locally, and systems operated by actors who do not care about EU fines, will not. The people most likely to produce an election deepfake are the least likely to watermark it.
Both criticisms are correct. Neither is an argument for doing nothing, but they do define what success can look like.
What it actually achieves
Not the elimination of deepfakes. What it does is shift the default.
If the overwhelming majority of synthetic content carries a signal, then the effort required to produce untraceable synthetic media rises. It stops being a two-minute exercise for anyone with a phone and becomes something requiring deliberate circumvention. That will not stop a determined state actor, and it will substantially reduce the casual volume, which is most of the volume.
The second achievement is the inversion described in our technical piece: over time, the useful question becomes whether content can prove it is genuine, rather than whether it can be shown to be fake. Newsrooms, courts and platforms can build on a positive signal in a way they never could on a negative one.
What it means for you
- If you publish: understand the deployer duties. If you use generative tools for public-interest content, either apply genuine editorial review and take responsibility, or label it.
- If you create: expect provenance metadata to become normal, and expect platforms to start surfacing it. Adobe's Content Credentials and similar systems are already there.
- If you read: remember the asymmetry. A watermark tells you something was AI-generated. The absence of one tells you nothing whatsoever, and treating unmarked content as verified is the mistake this entire system is most likely to cause.
The rules will not restore the situation where a photograph was self-evidently true. That is gone. What they might do is build the infrastructure for deciding what to trust in a world where it is not, which is a more modest ambition and the only one available.
The wider regulatory timetable is in our coverage of the transparency rules.
Published in The Outspoken Digest
Editorial desk
Outspoken Digest Technology DeskSoftware, hardware, artificial intelligence and what they change for everyone else.
Newsletter
The Digest, in your inbox
One edition, sent when it is ready. No noise, and your address is never passed on.
Read Next
More Technology →
How AI Watermarking Actually Works, and Why It Is Two Different Things
Aug 13, 2026/4 min read


