No hiding in plain text: the EU AI Act's transparency rules are now in force

Will Atfield, Alexander Horder, Isabella Stubbs, Emina Besirevic, James Yuan and Victoria Zhou
17 Sep 2026
6 minutes

Since 2 August 2026, every new piece of text generated by Anthropic's Claude AI assistant carries an imperceptible watermark, not just for EU users, but globally.  That is Article 50 of Regulation (EU) 2024/1689 (the Act) at work. The Act is the world's first comprehensive AI regulatory framework. Signed into law in June 2024, it is being rolled out in stages, with the transparency rules discussed in this article.

The rollout will continue through 2027 (with an AI literacy obligation under Article 4 already in force since February 2025), and includes requirements for high-risk AI systems and general-purpose AI models. It applies to any provider whose AI outputs are used in the EU regardless of where that provider is based. As Anthropic's decision to watermark all Claude outputs worldwide demonstrates, the practical impact extends beyond the EU.

The Act follows a risk-based approach, classifying AI systems into different risk categories. Its transparency obligations respond, in part, to the growing difficulty of distinguishing AI-generated content from human-generated content, creating real risks of misinformation and consumer deception at scale.

A provider is any entity that develops an AI system and places it on the market under its own name or trade mark, whereas a deployer is any entity that uses an AI system in connection with its operations. Providers are subject to the primary technical obligations under the Act (such as ensuring outputs are marked in a machine-readable format); meanwhile deployers carry the disclosure and labelling obligations that arise at the point of use.

The four transparency triggers

Article 50 of the Act imposes transparency obligations on providers and deployers in four categories:

Category
Who bears the obligation
What is required

Direct interaction with end users (Art. 50(1))

Providers

Providers of chatbots, virtual assistants and similar systems must ensure users are informed they are interacting with AI, unless it would be obvious to a reasonable person in that particular context.

Synthetic content generation (Art. 50(2))

Providers

Providers of generative AI systems (producing audio, images, video or text) must ensure outputs are both marked in a machine-readable format and are detectable as AI-generated or manipulated outputs.

Emotion recognition and biometric categorisation (Art. 50(3))

Deployers

AI systems that recognise people's emotions or categorise them biometrically must inform individuals of the operation of the system and process personal data in accordance with applicable EU data protection legislation.

Deep fakes and AI-generated public-interest text (Art. 50(4))

Deployers

Deployers must disclose that content has been artificially generated or manipulated.

A "deep fake" means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful.

Three practical boundaries worth noting are:

  • AI agents are caught: The European Commission’s Guidelines confirm AI agents fall within Article 50(1) and must disclose their artificial nature and identify the person on whose behalf they act.

  • Standard editing is excluded: AI systems performing only assistive editing functions (grammar correction, minor stylistic changes) are excluded from the Article 50(2) marking obligation.

  • Human editorial control provides a safe harbour: Where AI-generated text has undergone human review or editorial control and a person holds editorial responsibility for the publication, the deployer disclosure obligation under Article 50(4) does not apply. This serves as an important exemption for businesses that use AI to draft content but maintain a human review step.

The penalties for non-compliance are potentially significant for regulated entities. Non-compliance with the prohibited AI practices under Article 5 (including manipulative and deceptive practices) carries possible fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Non-compliance with the transparency obligations under Article 50 carries possible fines of up to EUR 15 million or 3% of global annual turnover.

By way of comparison, these thresholds exceed those provided for under the existing EU and UK General Data Protection Regulations. Enforcement sits with national market surveillance authorities in each Member State, coordinated by the European AI Office. Non-EU providers are also subject to these regulations through their obligation to cooperate with those authorities when their AI outputs are used in the EU. The consequences extend beyond fines: the EU's revised Product Liability Directive, to be transposed by 9 December 2026, classifies AI systems as products subject to strict liability, and non-compliance with the Act can give rise to a presumption of defect in civil proceedings.

Code of Practice and Guidelines

Ahead of these obligations taking effect, the European Commission has published two key instruments:

  • a voluntary Code of Practice (Code) on Transparency of AI-Generated Content, published on 10 June 2026, with approximately 190 companies and organisations signing by the end of July 2026; and

  • guidelines on transparency obligations under Article 50, published on 20 July 2026 (Guidelines).

While voluntary, the Code represents the European Commission’s view of "best practice" and is expected to form the benchmark against which compliance is ultimately assessed. The European Commission and the AI Office have confirmed it is an adequate tool to demonstrate compliance with the Act's transparency obligations. Signatories benefit from reduced administrative burden and legal certainty across all Member States. Providers and deployers who choose to comply through other means must demonstrate adequacy individually to different market surveillance authorities.

The Code is structured around three core elements:

  1. Multi-layered marking: Providers must implement at least two layers of machine-readable marking: first, digitally signed metadata (following open standards, such as the Coalition for Content Provenance and Authenticity (C2PA)), and second, imperceptible watermarks embedded in the content. For free-form text, watermarking alone is sufficient, because text cannot carry metadata in the same way as image, audio or video files.

  2. Detection solutions: Providers must make detection tools available (free of charge for most users) to allow verification of whether content has been generated or manipulated by AI. Detection solutions must be offered within the EU as a public specification, software, or cloud-based API.

  3. Visible labelling: The Code provides a standardised EU icon for deployers to use when disclosing AI-generated deep fakes and certain other AI content. Deployers are encouraged to use these icons alongside machine-readable markings to provide visible transparency to consumers.

The Brussels Effect in practice: Anthropic’s watermarking

Anthropic has signed the Code. Beyond test watermarking already in effect, new Claude models attach digitally signed provenance metadata to supported file types. These features have been rolled out globally, reflecting the practical difficulty of geofencing compliance measures.

The result is immediate. Australian users of Claude now generate watermarked text regardless of whether Australia has enacted comparable laws, and other major providers are implementing similar measures.

Practical steps for Australian businesses

Australian businesses whose AI-generated content, AI-powered tools or AI-enabled services operate in the EU, or otherwise reach EU users, should take steps now:

  1. Map your AI exposure: Identify which products, services or operations use AI systems whose outputs could reach EU users, including chatbots, generative AI tools, AI-generated marketing content and AI-powered customer interactions.

  2. Assess your role: Determine whether you are a ‘provider’ (developing or placing an AI system on the market) or a ‘deployer’ (using an AI system) under the Act. The obligations differ, and you may be both in different contexts.

  3. Review your content pipeline: Ensure that AI-generated content used in marketing, packaging, customer communications or public-facing materials can be properly marked and labelled in compliance with the transparency requirements.

  4. Engage with your AI providers: Understand what transparency and marking features your AI providers are implementing, and how those features affect your own compliance position as a deployer.

  5. Watch the domestic landscape: Australia’s own AI regulatory framework is developing rapidly (see below). Early movers on EU compliance will be well positioned.

The Australian context

Australia currently governs AI through a patchwork of laws, including consumer protection, privacy, anti-discrimination and sector-specific regimes, supplemented by voluntary guidance.

Some of those laws already have reach into AI-generated content. The ACL’s prohibition on misleading or deceptive conduct can apply where a chatbot, AI-generated product packaging, or AI-written marketing material conveys a false impression, and the Assistant Treasurer has confirmed that the prohibition reaches AI-generated representations and omissions. The ACCC has separately flagged generative AI as facilitating false representations about products and services. What the ACL does not clearly resolve, however, is whether failing to disclose that content was generated by AI is, in itself, misleading or deceptive. The Act cuts through that ambiguity by mandating disclosure regardless of whether the content is accurate.

The GDPR’s extraterritorial reach effectively made EU privacy standards the high watermark for global businesses, and the Act is designed with the same logic. Other jurisdictions, including the United Kingdom, Canada and Singapore, are actively developing AI regulatory frameworks.

In Australia, the Government has signalled its intention to mandate guardrails for AI in high-risk settings and has outlined a series of AI consumer safety priorities, with legislation addressing several of these priorities expected from early 2027. The Joint Select Committee on AI, established on 20 August 2026, is examining many of the same issues and is due to report by 30 November 2026. Meanwhile, other major AI providers will continue implementing marking and watermarking solutions in response to the EU Code of Practice, meaning the practical compliance landscape will evolve rapidly regardless of domestic law.

For Australian businesses, the EU AI Act’s impact is already concrete: every Claude output carries an imperceptible watermark regardless of where it is generated. With the Joint Select Committee on AI due to report by 30 November 2026, the window to comply with EU requirements and prepare for complying with domestic requirements is closing.

Be the first to know

Legal updates and articles on the topics that matter to you, sent as they happen.

Subscribe

Get in touch

Disclaimer
Clayton Utz communications are intended to provide commentary and general information. They should not be relied upon as legal advice. Formal legal advice should be sought in particular transactions or on matters of interest arising from this communication. Persons listed may not be admitted in all States and Territories.