EU AI Act Article 50 — Who Must Label What, and How?

Article 50 divides transparency duties between AI providers and deployers, while Claude's watermarks expose the limits of provenance.

EU AI Act Article 50 — Who Must Label What, and How?

The short version

  • EU AI Act Article 50 divides machine-readable marking duties for providers from human-facing disclosure duties for deployers.
  • Claude uses keyed statistical word choices for text and signed C2PA metadata for supported files.
  • Buyers should stress-test multilingual detection, editing, translation, exports and CMS workflows before treating provenance signals as reliable.

Will an invisible Claude watermark survive Romanian translation, a CMS re-save and a determined intern with a paraphraser? Nobody knows yet. EU AI Act Article 50 makes providers responsible for identifiable synthetic output and deployers responsible for disclosures around covered uses and published content. Anthropic responded with statistical marks in supported Claude text and signed provenance metadata for supported files. I like the direction. Europe turned transparency into a market-access requirement, and Anthropic’s worldwide rollout shows how European rules can change software far beyond Europe.

But a watermark only suggests Claude processed a passage. It cannot show who developed the argument, whether Claude merely proofread it or how much survived rewriting. Treating it as proof of authorship would turn useful infrastructure into an accusation machine with a Brussels logo. I am aggressively pro-EU, but I do not applaud technical systems before anyone publishes the false-positive rate. Startup demos and suspiciously photogenic airport sandwiches taught me that.

Article 50 splits the work between providers and deployers

The division matters more than the label design. Providers have product-level duties, including machine-readable marking for synthetic outputs. Deployers owe human-facing disclosures for covered uses, including certain deepfakes and unreviewed AI-written text published to inform the public. Emotion recognition and biometric categorisation have separate notification duties. Chatbots generally must disclose that users are interacting with AI unless it is already obvious.

A company can hold different roles across products, so I map each use separately. Who puts the system on the European market? Who operates it when someone encounters the output? Then I find where control works: inside the model, during file creation, in the interface or before publication. Provider duties belong upstream in system design; deployer duties sit near the audience. Contracts can allocate implementation, but the audience still needs the right disclosure at the right time. Calling the organisation “a deployer” comforts lawyers and tells engineers almost nothing. Misclassify the role and a team can spend a quarter polishing somebody else’s compliance control.

In Finland, Article 50 transparency obligations began applying on 2 August 2026; before then, they were not applicable. Traficom’s guidance also notes a transition period for machine-readable marking on older generative systems. Anthropic says supported Claude models launched in the EU from that date include marking at launch, while it is adding support for earlier models covered by the transition. Anthropic applies the markings worldwide wherever it offers a supported model.

That is the Brussels effect with fewer conference panels and more code.

When Traficom issued its guidance as the obligations took effect, Jarmo Riikonen put it neatly:

Avoimuus tukee luottamusta digitaalisiin palveluihin.

“Transparency supports trust in digital services” is modest but important. Trust comes after vendors expose enough evidence for customers and researchers to test what they built. A footer badge cannot carry that weight.

How Claude watermarks text without adding hidden characters

Claude’s text watermark is not secret Unicode confetti. For supported models, Anthropic says it changes low-stakes word choices while preserving meaning. The prose gains a statistical pattern derived from a secret key and the preceding words.

A language model generates text one word at a time from several plausible candidates. Many fit equally well, so ordinary sampling chooses among them with arbitrary randomness. At suitable moments, Anthropic replaces that randomness with a keyed process based on preceding text. Repeated choices create a pattern without extra characters or identifying information. A detector with the key checks the sequence and calculates how closely it matches Claude’s keyed choices. The result is a likelihood that Claude helped produce the text, not a robot-police verdict. Heavy editing, paraphrasing or translation may replace enough marked choices to hide the pattern; short passages and mixed human-AI drafts may never produce a strong signal.

That cuts both ways. Finding a mark does not identify every sentence Claude wrote; finding none does not prove human authorship. Anthropic explicitly says a mark can appear after Claude proofreads, translates or summarises a human draft. File conversion can also create one because Claude may process content without originating it. The detector answers one narrow question: does the surviving sequence resemble text processed by a supported Claude model?

Supported files use different machinery. Claude can attach digitally signed provenance metadata under the C2PA standard to supported formats. A verifier can check whether Claude processed the file and whether someone tampered with the signed record. Screenshots or format conversion can strip metadata, while copied text may retain its word choices. Provenance workflows must test both paths instead of treating “watermarked” as one universal property.

File-conversion workstation junction with paired cables, compact adapter, and phone for screenshot testing in laboratory lighting.

The multilingual gap worries me most. Auditing Cross-Lingual Fairness in Language Model Watermarking evaluated six schemes across 11 languages, versus a research norm focused almost entirely on English. Alexander Nemecek and his co-authors found disparities mainly between typological language families, suggesting language structure affects watermark behaviour. Their paper did not test Anthropic’s deployed Claude system, so it cannot show whether Claude performs poorly in Finnish, Italian or Romanian. It does kill the lazy assumption that English benchmarks travel automatically.

Other research shows watermarking’s potential under controlled conditions. The PURA paper accepted to ACM CCS reports a 92% message-match rate for embedding a short payload in a fixed passage length, more than three times the strongest unbiased baseline in that experiment. PURA is research evidence, not a public benchmark of Claude’s deployed detector. Anthropic has not released independently reproducible accuracy, false-positive or robustness results for its live system, and its technical detection mechanism remains unpublished.

For a continent with two dozen official languages, “trust us, it works in prose” is a beta launch wearing a tie.

Human review changes disclosure, not provenance

The public-interest text exception will reveal whether a company’s “human in the loop” has authority or is a decorative approval button. Covered AI-written text can avoid visible publication disclosure if a human performs substantive review and a person or organisation assumes editorial responsibility. That does not erase the provider’s underlying machine mark.

I expected compliance theatre. I have seen workflows where the final reviewer could click Approve but could not edit the document—an impressively honest diagram of fake oversight. A defensible process gives reviewers sources, authority to change or reject text, and responsibility for what readers see. I would retain the model name and source material, then record factual checks and final approval. The machine-readable mark remains a technical signal; the editorial record explains why the organisation published. In a dispute, they answer different questions and should never become one magic “AI detected” field.

The strongest case for treating a watermark as authorship proof sounds reasonable: a secret-key pattern is hard to produce accidentally, so a positive result should identify Claude as the writer. Anthropic rejects that leap. Its guidance says detection indicates possible Claude processing and cannot establish complete provenance or original authorship. A journalist might write an article and ask Claude to translate one paragraph. An employee might use it for proofreading. A student could run a human essay through a summariser, then restore most of the original. One detection result can cover very different creative histories.

Procurement should test those messy histories. I would run representative output through the exact model, export path and CMS my team uses, then apply our editors’ routine changes. Next comes translation into users’ languages. I also want to know who holds the detector key, whether customers can request verification and what evidence an audit can retain. A gorgeous compliance page answers none of that, though the gradient may be excellent.

Digital sovereignty needs European models with better receipts

Article 50 advances digital sovereignty because one EU market rule can reshape a global AI product. Anthropic signed the Article 50 transparency Code of Practice and built machine-readable marking around that commitment. The engineering reaches supported Claude deployments worldwide. European buyers get one common requirement instead of separate national provenance regimes. Global providers face a market large enough to influence their road maps. European startups gain a shared home market instead of crossing another compliance border every few hundred kilometres.

Deeper European integration makes this possible. Twenty-seven watermark regimes would delight lawyers and give software builders a migraine. Federal capacity lets Europe set a technical floor, fund multilingual evaluation and procure across borders. Now Europe should put that purchasing power behind its own AI champions.

People searching for Mistral AI stock or the latest Mistral AI valuation will not find a reliable financial answer in the Article 50 evidence. These sources establish neither whether shares are publicly tradable nor a current valuation. I will not invent one for Google. Investment status requires current corporate filings and financing announcements; any private transaction figure can become stale after another round or secondary sale.

A useful Mistral AI vs Claude comparison hits the same evidence gap. The supplied sources document Claude’s approach but provide no equivalent primary evidence for Mistral’s current watermark coverage, detector access or product-by-product implementation. Model quality, price and deployment control still matter. Under Article 50, I would also test multilingual detection and what survives the customer’s publishing pipeline. Picking a winner first is spreadsheet cosplay.

Europe should make those checks part of public procurement. I want Mistral and every future European champion to publish marking coverage by model, multilingual benchmarks and clear detector access. EU institutions can create demand for interoperable provenance that works in Warsaw, Palermo and Helsinki, then help European vendors export that standard.

By 2029, serious European model tenders will include a provenance stress test beside latency and cost tests. I am writing down the date so future Luca can mock me if I am wrong. Digital sovereignty becomes real when a European model can issue a receipt that survives our languages, our editors and our terrible government CMS software.

Frequently asked questions

What does EU AI Act Article 50 require?

EU AI Act Article 50 requires providers to make covered synthetic outputs identifiable in machine-readable form. Deployers must provide human-facing disclosures for covered uses, including certain deepfakes and unreviewed AI-written public-interest text, while chatbots generally disclose AI interaction unless it is already obvious.

How does Claude watermark AI-generated text?

Claude watermarks supported text by using a secret-key process to guide low-stakes word choices, creating a statistical pattern without hidden characters. Its detector estimates whether Claude processed the text, but editing, paraphrasing, translation, short passages and mixed authorship can weaken or obscure the signal.

Does a Claude watermark prove that Claude wrote the text?

No. A Claude watermark indicates possible processing by a supported Claude model, not complete provenance or original authorship. It may remain after proofreading, translation, summarisation or file conversion, so a positive detection cannot establish which sentences Claude wrote or how much human work preceded it.

Sources

Related reading

Luca

Luca

Luca by the way is the personal blog of Los Angeles based entrepreneur Luca Capula. A true Italian who lives between Torino and LA.

More posts →