Writing / 2026
Content Marking Is a Pipeline, Not a Policy
The EU AI Act marking deadline for existing generative systems is 2 December. Provenance survives only what your pipeline keeps, so test it in CI.
Two months from this post, on 2 December, the EU AI Act’s marking extension runs out. The scope, in one sentence each, because getting it wrong wastes the two months. Providers of generative AI systems owe machine-readable marking and detectability for synthetic audio, image, video, and text: new systems since 2 August, systems already on the market by 2 December. Deployers carry separate disclosure duties, and Article 50 includes exceptions for assistive and editing functions that don’t substantially alter the input, which is precisely the kind of line your counsel, not your intuition, should draw. I sorted the full obligation stack in September ; this post is the engineering column, because I keep seeing marking staffed as a legal memo when the hard part is a pipeline property. Marking survives only what your pipeline preserves.
Generation-side marking is genuinely the easy part now. Anthropic published in August how its text watermark works, a version of the SynthID-Text approach, with models released before 2 August to follow over the coming months, and provenance standards for media are mature. If your product returned model output untouched, you’d nearly be done. Almost nothing returns model output untouched, and pipelines remove provenance as a side effect of working normally. The audit that fills the two months is a map of those removals, and it has to name the actual artifact at each hop, because “the mark” is four different objects with four different failure modes. Embedded metadata dies wherever a processing library re-encodes without copying segments it doesn’t recognize. A signed provenance manifest is stricter: it doesn’t just get stripped, it gets invalidated, because any pixel change breaks the signature. An editing step must either leave the asset untouched or produce a new signed assertion that links the original as an ingredient; blindly re-attaching the old manifest to modified content misstates provenance, which is worse than losing it. A pixel- or audio-domain watermark degrades statistically under resampling and compression, a curve rather than a cliff. And a text watermark weakens under the paraphrase and summarization that may be your product’s whole value. Then the delivery tier: does your CDN’s image optimization re-encode, and with what metadata policy? Does the export path rasterize? Each hop gets a row: artifact in, operation, artifact out, verified by test rather than by the library’s documentation.
Screenshots launder everything, so why fund the pipeline? Two answers, one technical, one legal. Technically, it’s not even true. Capture-resistant watermarks exist precisely because vendors anticipated it; what’s true is that no scheme survives a determined adversary. Legally, the Act’s standard is marking as far as technically feasible, not marking that defeats adversaries. The obligation, and the value, is provenance across the ordinary flows that carry nearly all of your output. Write the limits plainly in your compliance documentation, because overclaiming robustness converts an engineering shortfall into a misrepresentation problem. Binary talk of marks “surviving” should become measurement anyway: detector recall and false-positive rate, per transformation, because that’s what a regulator’s technical annex and your own dashboards can actually hold.
Detectability is the half teams forget, and the Act requires it without specifying your vendor’s product roadmap. So treat the detector as procurement, not statute: the marking your model vendor embeds should come with a detection interface, documented rates, versioning, and a contractual commitment, one more row in the evidence exchange you should be negotiating anyway .
Then make the property permanent, because the audit decays the day someone upgrades the thumbnailer. A golden set of marked outputs, covering every format, size band, and locale you ship, runs through each real delivery route on a schedule and in staging before releases, with detection asserted at the far end against pinned detector versions, and a named owner for the failure. That check is to marking what the freshness instrument is to context : the difference between a compliance sentence and a system property someone would be paged about.
Last, the leadership decision with a clock on it: the voluntary Code of Practice on AI-generated content, which the Commission says signatories can rely on to demonstrate compliance, trades an ambiguous technical bar for a defined one. Have counsel read it this month. Then let December 2 arrive as a date your CI already enforces.