
AI-generated content is becoming easier to create. The EU is now making it easier to detect.
But does that mean you will know when something you see on social media or elsewhere online was created or manipulated by AI?
In recent weeks, three people reached out to me with what turned out to be the same question, just dressed differently.
One was a compliance lead asking about scope. Another wanted to know whether this applied to his SaaS product. The third had no technical background at all, and he asked it more honestly than either of the others:
“When I post something, I made with AI, will people just… know?”
The short answer is: not necessarily.
And this is where Article 50 of the EU AI Act becomes particularly interesting from both a technology and an audit perspective.
What is changing?
From 2 August 2026, Article 50 introduces a number of transparency obligations for certain AI systems.
For providers of AI systems, including general-purpose AI systems, that generate synthetic audio, images, video or text, the outputs must be marked in a machine-readable format and be detectable as artificially generated or manipulated, subject to the scope and exceptions set out in the Regulation.
The important point is that machine-readable does not necessarily mean visible to a human reader.
Think of it more as a digital provenance signal that allows technology systems to identify that content has been generated or manipulated by AI.
The technical approach could include mechanisms such as:
- Metadata
- Watermarking
- Cryptographic methods for proving provenance or authenticity
- Logging methods
- Fingerprinting
- Other appropriate technical techniques
The objective is not necessarily for every reader to see a large “AI GENERATED” warning.
It is to make AI-generated or manipulated content detectable.
There is also a transition period for AI systems that were already placed on the market before 2 August 2026. For those systems, the specific marking and detection obligations under Article 50(2) apply from 2 December 2026.
So, will readers actually know?
Back to my friend’s question.
The honest answer is: not reliably, and not necessarily.
This is where the distinction matters.
If you use an AI tool to help draft a social media post, the existence of an underlying machine-readable mark does not automatically mean that every person reading your post will see a prominent “AI-generated” warning.
Article 50 creates different transparency obligations depending on the circumstances and the role of the organisation involved.
For example, there are specific disclosure requirements for deepfakes.
There are also requirements relating to AI-generated or manipulated text published for the purpose of informing the public on matters of public interest, subject to an important exception where the content has undergone human review or editorial control and a person or organisation holds editorial responsibility.
So, using AI as an assistant to improve the wording of a social media post is not necessarily the same regulatory scenario as publishing an AI-generated political statement, synthetic video or manipulated image.
That distinction is important.
The opportunity: restoring some trust in digital content
I see a significant opportunity here.
Today, we increasingly have a provenance problem.
- A photograph may be real.
- A video may be manipulated.
- A voice recording may be synthetic.
- An email may have been generated by AI.
- A document may contain AI-generated analysis.
And increasingly, humans cannot reliably determine the origin simply by looking at the content.
Machine-readable marking could provide another layer of assurance.
For businesses, this could eventually support:
- Content provenance and authenticity checks
- Detection of synthetic media
- Fraud and impersonation controls
- Brand protection
- More reliable digital evidence
- Improved incident investigations
- Greater transparency when customers interact with AI
From a cyber perspective, I find this particularly interesting because content provenance could become another control in the wider fraud and identity ecosystem.
Imagine an organisation receiving a voice recording supposedly from its CEO authorising a payment.
Today, the question might be:
“Does this sound like the CEO?”
In the future, we may increasingly ask:
“Can we establish where this content originated, whether it has been altered, and whether there is reliable provenance associated with it?”
That is a very different security model.
But there are consequences and limitations
We should also avoid treating AI marking as a silver bullet.
Machine-readable markings can potentially be removed, altered or lost as content moves between systems, platforms and file formats.
Content can also be transformed. For example, a screenshot of an AI-generated image may no longer retain the original metadata associated with the source content.
This creates an interesting cyber-security question:
How resilient is the marking mechanism when content leaves the original AI ecosystem?
There is also the risk of false confidence.
A piece of content without an AI marker should not automatically be treated as “human generated”.
Absence of evidence is not necessarily evidence of human origin.
That is particularly important for investigators, fraud teams and auditors.
The audit angle
From an IT and cyber audit perspective, I would not stop at asking:
“Does the AI system apply a watermark?”
I would ask a broader set of control questions.
- What is the organisation’s AI inventory?
Do we actually know which AI systems are being used across the organisation and which of them generate or manipulate content?
- What marking technology is being used?
Metadata? Watermarking? Cryptographic provenance? Fingerprinting? Something else? More importantly, is the chosen approach appropriate for the type of content being generated?
- Is the control effective after content leaves the AI platform?
Can the marker survive downloads, editing, conversion, publishing and redistribution? If not, what compensating controls exist?
- Can the organisation demonstrate compliance?
Are configuration records, testing results, policies, control assessments and other evidence retained?
- Who owns the control?
IT? Cyber Security? Data Governance? Legal? AI Governance? Communications? A control without clear ownership can quickly become a control without accountability.
- What happens when the control fails?
Is there monitoring, exception management, incident handling and escalation?
- Can the organisation distinguish AI-assisted work from AI-generated content?
This becomes particularly important where human review or editorial control can affect the applicable transparency requirements.
In other words, the audit question should move from:
“Have we implemented AI marking?”
to:
“Can we demonstrate that our AI-content transparency controls are appropriately designed, operating effectively and remain effective throughout the content lifecycle?”
That is a much more interesting control problem.
The bigger picture
I think Article 50 is less about putting a visible label on every piece of AI-generated content and more about creating an ecosystem where the origin of digital content becomes increasingly detectable.
That could ultimately become an important part of the digital trust infrastructure.
But there is a risk if organisations interpret compliance too narrowly.
AI governance cannot simply become a checklist saying:
✓ AI policy
✓ AI inventory
✓ Marking mechanism enabled
✓ Article 50 compliance
The harder questions are around resilience, provenance, monitoring, evidence and what happens when controls fail.
Where I landed
I still don’t have a tidy answer for my friend.
What I told him instead was:
Assume your readers cannot tell, until you have deliberately made it obvious.
And perhaps that is the more interesting question for all of us working in technology, cyber security, risk and audit:
Will AI provenance eventually become a standard cyber-security control, sitting alongside logging, authentication and digital signatures?
I suspect we may be heading in that direction.
Disclaimer: The author is a cybersecurity professional and researcher with an interest in information technology, cybersecurity, AI Governance, and emerging technologies. The views expressed are solely the author’s own and do not represent or constitute the views of any employer, affiliated organisation, or institution. This article is written in a personal capacity for informational and discussion purposes only.
AI tools were used to assist with research, source verification, and drafting of this article. The analysis, opinions, and conclusions are my own.
References
- EU AI Act — Regulation (EU) 2024/1689, Article 50 and Recitals 133–135
- European Commission — Transparency obligations under Article 50 of the AI Act
- European Commission — Guidelines on transparency obligations for providers and deployers of AI systems
- European Commission — Code of Practice on Transparency of AI-Generated Content