AI DetectiveEmail check Marking deadline: 2 Dec 2026 Book a call

EU AI Act · Article 50(2)

Your AI content must carry a mark.

Since 2 August 2026, AI-generated images, video, audio and text must carry machine-readable marking. The duty falls on whoever's system creates the content. A visible watermark does not satisfy it.

I don't write you a report about what the law requires. I wire the marking into your pipeline, so every new file comes out marked and nobody has to remember anything.

85
days

until 2 December 2026 — the deadline for machine-readable marking on systems that were already in use before 2 August.

REGULATION (EU) 2024/1689 · ART 50(2)

Estonian companyServers in Germany, EUNo cookiesEnglish, Estonian

01 — Who this is for

Does the duty fall on you?

Tick everything that applies. One tick is enough — under the Act you are then a provider.

Tick what applies to you.

That last line matters most. Adobe, Microsoft, Google and OpenAI mark their own output — which only helps you if you use nothing else. If your pipeline runs on several tools, none of them marks on behalf of the others.

02 — The requirement

Three things most people get wrong

01

A watermark is not enough

The requirement is machine-readable marking. A logo in the corner or a "made with AI" caption does not satisfy it.

02

The standard is already chosen

The Commission's guidance points directly at C2PA Content Credentials. This is no longer one option among many.

03

The mark goes in at creation

Not at publication, not retroactively. That makes this a change to your workflow, not a change to your copy.

One limit I state up front: most social platforms re-encode images on upload and strip the manifest. LinkedIn, TikTok and Cloudflare preserve it, Meta reads it and shows an "AI info" label — but nobody can guarantee the mark survives everywhere.

So the promise is always: marked at source and verifiable. Which is exactly what the law asks of you — your responsibility ends at your own output.

03 — Try it

Does your file carry a mark?

Upload one image your tool produced. I'll tell you straight away whether it carries machine-readable marking — and if it doesn't, you'll see exactly what's missing. Nothing is stored.

Drop a file here

or click to choose — images, video, audio or PDF, up to 8 MB

Choose file

Files are processed in memory and deleted immediately. Nothing is stored, nothing is used to train anything. The server is in Germany, inside the EU.

04 — The work

Three steps, three prices

Each is bought separately. Most start with the audit, because it's cheap and it shows immediately how much work is actually ahead.

Step 1

Marking readiness audit

Where content is created in your organisation, with which tools, where it goes — and where the mark has to go in.

  • Every place content is generated — including the ones everyone forgot about
  • Spot checks on real files — is a manifest present, and is it valid
  • A dated report with every checked point listed separately, with evidence
€490

See a sample audit →

3 working days.
About an hour of your time.
No system access needed.

Step 2 · the real work

Marking pipeline, live

I wire C2PA claim signing into your existing workflow. After that, every new file comes out marked without anyone having to remember anything.

  • Certificate obtained and verified against the trust list
  • Signing wired in — an API call before publishing, a folder watcher, or a plug-in to your CMS
  • The manifest asserts the right things — who created it, with which tool, what changed afterwards
  • Handover check — we take a random file and show the mark is in it and valid
€990

Typically 2–3 weeks.
Fixed price agreed before we start, not billed by the hour.

This is the real work

Step 3

Certificate custody and monitoring

Certificates expire. Keys need rotating. Trust lists change. Someone has to do this — and nobody wants to learn it.

  • Renewal before expiry — automatic, nothing for you to remember
  • Monthly verification that the pipeline is still marking
  • A dated record of every check — your evidence of diligence
€249 / month

Monthly, no lock-in.
Higher volumes by agreement.

Add-on

Email deliverability

Do your own emails reach the client, or spam? A separate service, independent of marking.

€150–300

Free check first. One-time fix. No monthly fee.
See the email service →

Book a 20-minute call

Write one line about what your company generates with AI. I answer the same day.

info@aidetective.eu

Opens your mail app with the subject filled in.

Or just call

Often faster than three emails. Estonian or English.

+372 5547670

Leinart Uuetoa · Vahitalu OÜ · EET (UTC+2)

What happens next

  1. I ask one question: does anything in your organisation generate content.
  2. If not, I say so and we stop. No pitch.
  3. If yes, I check one of your published files before we talk, so the call starts with facts.
01

Call, 20 minutes

I ask one question: does anything in your organisation generate content. If not, I say so and we stop.

02

Audit, 3 days

I find where marking is missing. After that you know exactly how much work is ahead.

03

Pipeline, 2–3 weeks

I wire in the signing. At handover we check together that the mark is in the file.

05 — Straight talk

I sell neither a detector nor advice

1 : 5

Roughly how often tools that claim to tell you whether text was written by AI get it wrong.

I don't build detectors. No honest tool can reliably say whether a given text was written by a person or a machine. I'm not building a business on accusations that might be false.

I don't sell advice either. What the law requires, you can ask any AI today and get a decent answer. There's no reason to pay for that.

I sell only the thing neither of them will do for you: a working marking pipeline inside your own system.

06 — The difference

Why not just hire a consultant?

An AI Act consultant

Tells you what the law requires.

Maps your obligations, writes a report, gives recommendations. The work ends when the document is handed over.

After that you have knowledge and a list. Your files are still unmarked.

AI Detective

Does it, inside your system.

Maps it, wires in the signing, obtains the certificate, keeps it running and verifies it every month.

After that files come out of the pipeline marked. No knowledge required on your side.

If you need a legal opinion, I'll gladly recommend a lawyer — I work with them. I do the technical half.

07 — Free

Two-minute check

Ten questions. You get back the list of obligations that apply to you, and whether the marking duty is one of them. Free, no sign-up.

Does the marking duty apply to you?

0 / 10 answered
This check gives a first overview. It is not legal advice and not an assessment of your compliance.

08 — Who I am

One person who actually does the work

Leinart Uuetoa

Leinart Uuetoa, southern Estonia. I read the EU AI Act and found that all the attention was in the wrong place: everyone talks about spotting AI content, while the law asks whoever creates it to put a mark on it themselves. Nobody was offering that as a service.

I do this work myself, as one person. That means you speak to the same person throughout, and that I don't take on more work at once than I can honestly deliver.

Vahitalu OÜ · registry code 11983738 · info@aidetective.eu · +372 5547670

09 — Questions

Frequently asked

What is C2PA?
Like the ingredients label on a food package, but inside the image or video. The file records which tool created it and what was changed afterwards — and that record is cryptographically signed, so it can't be forged unnoticed. The Commission's guidance points to this standard for machine-readable marking.
Will you tell me whether a text was written by AI?
No. That can't be done reliably and I don't sell it. I work on making sure your own content carries the right marking — that's a verifiable fact rather than a guess.
Does the mark survive upload to Facebook or Instagram?
Not always. Most platforms re-encode images and strip the manifest. LinkedIn, TikTok and Cloudflare preserve it; Meta reads it and shows an "AI info" label. That's why the promise is always "marked at source and verifiable" — which is precisely what the law asks of a provider.
Can't we just do this ourselves?
You can. The software is open source and free. The question is whether anyone in your organisation wants to learn certificate enrolment, key custody, manifest structure and trust lists — and then do it again every year. Most companies decide they don't.
What happens if something breaks?
The monthly service includes verification and renewal before expiry. If something breaks, I fix it under that. Without the monthly service it's separate work.
What happens to my keys if something happens to you?
The certificate and signing keys are issued in your company's name — you own them, I operate them for you under contract. If I'm ever out of the picture, nothing is locked to me: you already hold the certificate, and you get a documented handover so you or another provider can carry on without redoing the work.
Is this legal advice?
No, this is technical work. A lawyer gives the legal opinion, and I'll gladly recommend one who works in this area.
Where does my data go?
Servers are in Germany, inside the EU. Files are deleted 30 days after the work unless you ask otherwise. Nothing is used to train any model.