Skip to content

Does C2PA Adoption Satisfy the EU AI Act's Labelling Duty?

9 min read · updated August 11, 2026

The question gets asked in a procurement meeting, usually in the form “if we ship Content Credentials, are we done?” The answer is no, and the reason is more useful than the answer: Article 50(2) is drafted as a result to be achieved, not as a standard to be adopted, and no instrument in force names C2PA at all.

What Article 50(2) actually requires

Article 50(2) of Regulation (EU) 2024/1689 puts the duty on providers of AI systems that generate synthetic audio, image, video or text. They must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The qualifier is the operative part: the technical solutions must be effective, interoperable, robust and reliable as far as is technically feasible, taking into account the specificities and limitations of the various types of content, the costs of implementation and the generally acknowledged state of the art, as may be reflected in relevant technical standards.

Read that clause carefully and you find four adjectives, a feasibility limit, a cost limit, a state-of-the-art reference, and a conditional gesture at standards — “as may be reflected”, not “as set out in”. It is a performance obligation. There are exceptions in the same paragraph where the system performs an assistive function for standard editing or does not substantially alter the input data, which is the carve-out that keeps ordinary photo tooling out of scope. The duty on deployers for deep fakes is separate and lives in Article 50(4); do not merge the two, because they land on different parties and are satisfied differently. Primary text: Regulation (EU) 2024/1689 on EUR-Lex.

Article 50 applies from 2 August 2026 under the Regulation’s own application timetable in Article 113. Nothing on this page is legal advice, and whether a particular generation feature falls inside the assistive-editing exception is exactly the kind of question to put to counsel with the feature in front of them.

The short answer

C2PA is a technical means of discharging part of the duty. It is not a legal safe harbour, and three things follow from that.

  • No instrument names it. Neither Article 50 nor its recitals name C2PA, Content Credentials, or any other specification. An obligation that names no standard cannot be satisfied by pointing at one.
  • It covers marking well and detection partially. A C2PA manifest is unambiguously machine-readable and carries a signed assertion that content was AI-generated. That is the first half of Article 50(2) in good shape. “Detectable” after the manifest has been stripped is a different problem.
  • The regulator’s chosen route is elsewhere. Article 50(7) tasks the AI Office with encouraging and facilitating codes of practice at Union level to support effective implementation of the detection and labelling obligations. A code of practice is the instrument the Commission has reached for; adherence to one is a very different evidentiary posture from adherence to an industry spec, and it is worth tracking which one your sector ends up under. See how the GPAI code of practice worked in the parallel case.

Why the presumption of conformity is unclear here

In the New Legislative Framework tradition the AI Act inherits, the way a standard becomes legally powerful is the presumption of conformity: comply with a harmonised standard cited in the Official Journal and you are presumed to comply with the requirement it covers. The AI Act has that machinery in Article 40. But Article 40 is drafted by reference to the requirements for high-risk systems in Chapter III and to the general-purpose model obligations in Chapter V. Article 50 sits in Chapter IV.

It is therefore not settled that conformity with a future harmonised marking standard produces a formal presumption of conformity with Article 50(2) in the way it would for, say, Article 15 accuracy. Some practitioners read the standardisation request and the Article 50(7) code-of-practice route as together supplying the equivalent comfort; others read the omission as deliberate, on the view that a transparency duty owed to the public is not the kind of thing a conformity presumption should extinguish. What would settle it is the Commission citing a standard for Article 50 purposes, an implementing act, or guidance from the AI Office saying so in terms. Until then, describe your position as evidence of state-of-the-art compliance, not as a presumption. Standards work in support of the Act is running through CEN-CENELEC JTC 21.

Where C2PA falls short of the wording

The specification is published by the Coalition for Content Provenance and Authenticity and is worth reading rather than summarising; the current specifications are at c2pa.org. The relevant mechanics: a manifest, cryptographically signed by a certificate, is embedded in the asset and hard-bound to it by a hash of the content. Any re-encode that changes the bytes breaks the hard binding, and most pipelines that touch an image strip the metadata container entirely. Several large platforms remove or normalise metadata on upload as a matter of course.

Against the four adjectives, that produces a mixed result. Interoperable: strong, the format is open and multi-vendor. Machine-readable: strong. Effective and robust: weak on their own, because the signal does not survive the ordinary life of a file on the internet. This is why the ecosystem has moved towards pairing the manifest with a soft binding — an invisible watermark and a perceptual fingerprint that let a stripped asset be matched back to a manifest held elsewhere. A provider claiming robustness on the manifest alone is claiming something the format does not do.

There is also a scope mismatch that gets overlooked: Article 50(2) covers synthetic text. C2PA can sign a text asset as a file, but text copied out of that file and pasted into a message carries no manifest and no watermark that survives paraphrase. For text, the honest position is that the feasibility qualifier in Article 50(2) is carrying most of the weight, and that is a position you should be able to evidence rather than assert.

What a defensible position looks like

Treat the qualifier as the thing you are documenting. Article 50(2) asks what was technically feasible given the content type, the cost and the state of the art — so build the record that answers exactly that question, per modality, dated, with the options you considered and why you chose what you chose. Adopting C2PA and pairing it with a watermark is a good answer to that question; adopting C2PA and stopping is a partial one; adopting nothing and asserting infeasibility is one you will have to defend with evidence.

Keep the deployer duty separate in your documentation as well. If you also publish content generated by your own or somebody else’s system, Article 50(4) lands on you as a deployer and is discharged by disclosure to the audience, not by a manifest — covered in the deep fake labelling duty. And if you sell into California as well, note that SB 942 does name concrete artefacts where the AI Act names none, which means the two regimes are satisfied by overlapping but non-identical work; that asymmetry is covered in the SB 942 provenance tool page.