Article 50(2) is often reduced to “put a label on AI content.” In practice, the useful question is narrower: can your system put a machine-readable provenance record into every relevant output, and can you show what happens to it on the way to the user?
The transition deadline commonly relevant to systems already in use before 2 August 2026 is 2 December 2026. Whether and how the obligation applies to a particular service is a matter for legal advice. This checklist covers the technical side of preparing.
1. Map the outputs you actually deliver
Write down each output type your service creates: images, video, audio, PDFs and text. Then note the last file your user can download or receive. Do not stop at the AI model’s raw output if your own service resizes, converts, composites or wraps it first.
2. Mark at the source, not at the publishing desk
Machine-readable marking belongs in the generation or export workflow, before the file leaves your control. C2PA Content Credentials are the practical standard used for this. A visible watermark or a caption can help a human viewer, but it is not a machine-readable provenance record.
Do not try to solve this with an AI detector afterwards. A detector cannot reliably reconstruct a missing origin record from an ordinary file.
3. Test one normal delivery route end to end
Take one freshly generated file and inspect it. Then send the same file through a normal customer route: your download endpoint, a CDN, an image optimiser, an email attachment or a social upload. Inspect the resulting file, not just the source file.
That test is how you find the places where a credential is stripped or broken. See our guide on C2PA label survival on social media for typical platform behaviour. The honest target is marked at source and demonstrable, not a promise that the mark survives every platform.
4. Keep evidence and make it repeatable
Record what was tested, when, with which source file and which delivery route. Then make marking automatic rather than something a staff member has to remember. A dated technical record is far more useful than a one-off screenshot or a policy sentence.
Also decide who owns the signing setup, who can change it and who checks it after an update to your pipeline. Those operational details are where a working setup quietly stops working.
A small first step this week
- Choose one current AI output.
- Run the original and one delivered copy through a file check.
- Write down the first place the record changes or disappears.
- Use that result to scope the workflow fix.
AI Detective helps map the technical path, put marking into the workflow and keep a dated check of it. We do not sell an AI detector or provide legal advice.
Start with a real file
The free file check supports images, video, audio and PDF files up to 8 MB. It reports verifiable marking in the file; it does not decide retrospectively whether a file was AI-made.
Free file checkAsk about a workflow review