The second draft Code of Practice under Article 50 of the AI Act: key changes and practical implications
On 3 March 2026, the European Commission published the second draft of the Code of Practice on Transparency of AI-Generated Content. The Code is being developed to support compliance with Article 50 of the AI Act, which becomes applicable on 2 August 2026 (it remains to be confirmed whether Digital Omnibus can extend this deadline). Compared to the first draft, this version is notably more simplified: it reduces the compliance burden, introduces greater flexibility, and moves closer to the technical realities faced by providers and deployers of generative AI.
A final version is expected in June 2026. Although adherence remains voluntary, the Code is widely expected to become the de facto benchmark against which regulatory compliance with the Article 50 transparency obligations will be assessed.
Marking and detection: a tighter mandatory core
Providers of generative AI systems are now required to implement at least two active layers of machine-readable marking — an obligation expressly tied to the Article 50(2) criteria of effectiveness, interoperability, robustness, and reliability. Metadata requirements are also strengthened, with interoperable identifiers, digital signatures, and time-stamping now expected.
At the same time, a number of measures previously framed as obligations, including full provenance chain traceability, model-level marking, and forensic detection, are reclassified as optional. The result is a more focused mandatory framework with greater room for providers to design proportionate solutions.
On detection, the draft requires a free, accessible, and interoperable mechanism that produces results understandable to non-expert users, with outputs available as digitally signed downloadable documents. Organizations contracting or integrating AI tools will need to verify that their providers can meet these standards in practice.
Labelling: flexibility over taxonomy
This second draft removes the content taxonomy introduced in the first draft, abandoning the requirement to classify content as “fully AI-generated” or “AI-assisted.” The icon remains the central disclosure tool, but signatories may now use equivalent labels or notices, provided minimum design standards are met — including prominent display of the “AI” acronym, sufficient contrast, and visibility from first exposure.
For deepfakes embedded in artistic, creative, satirical, or fictional works, the new draft allows for contextual disclosure through labels or legal notices, and expressly accommodates non-digital contexts such as exhibitions, galleries, and physical formats, a meaningful expansion for operators in the cultural and creative sectors.
For AI-generated text on matters of public interest, the exemption available where human review and editorial responsibility are in place is now better defined, with a reduced documentary burden and express safeguards for press freedom and journalistic source protection.
What this means for organizations
With the August 2026 deadline approaching, the second draft signals that the time for preparation is now. Providers should assess whether their systems support multi-layered marking and auditable detection. Deployers should map their content workflows to identify where labelling obligations arise. Both should review their contractual arrangements across the AI supply chain, since responsibility is not assumed to rest with the original model provider alone.
The voluntary/mandatory tension and why it matters
The Code is formally voluntary. Providers and deployers may sign up to it as a means of demonstrating compliance with Article 50, and non-signatories are not automatically in breach. This distinction, however, is less significant in practice than it may appear. Where a code of practice has been approved by the Commission, it is expected to function as the primary reference for how national market surveillance authorities assess compliance, meaning organizations that choose not to sign will nonetheless need to explain how their approach achieves an equivalent outcome.
This dynamic is familiar from other EU regulatory instruments, and it creates a strategic consideration that goes beyond technical compliance. Companies that engage early with the Code, whether as signatories or by aligning their internal frameworks to its requirements, are better positioned to demonstrate good faith in the event of regulatory scrutiny. Those that delay risk not only operational disruption ahead of the August deadline, but a less favorable starting point in any dialogue with authorities.
There is also a competitive dimension. As the Code converges on interoperability standards and common iconography, organizations that have already embedded these into their products and workflows will find it easier to operate across the EU market without bespoke adaptation. For AI providers in particular, the Code is increasingly shaping what enterprise customers will expect to see, and require contractually, from their technology partners.
If your organization is assessing its obligations under the AI Act’s transparency framework or reviewing how the Code of Practice applies to its activities, Across Legal can assist in designing a proportionate and future-proof compliance approach.
↳ Discover more content in the section Insight.
↳ Do you want to stay up today about the sector related news? Follow us on LinkedIn.




