EU AI Act Article 50

Sign AI content under your own name

Article 50(2) requires AI-generated images, audio, video and text to be machine-readably marked. Most inference platforms do not mark at all, and the one that does signs in its own name, not yours. Signunder marks every output, signs it under your certificate, and gives you a public page that proves it.

2 Dec 2026
Marking grace ends for AI systems already on the market
1 of 11
Inference platforms that mark generated output today
€15M / 3%
Maximum Article 50 penalty, whichever is higher

verify.yourcompany.signunder.com

Verified
Signed by
Your Company Ltd
Certificate
SSL.com C2PA Level 1
Created with
FLUX.1 [dev] via Replicate
Signed at
2026-12-02 09:14:22 UTC
Watermark
Present · payload intact
Altered since signing
No

Illustrative example. Values are not from a real signed file.

Does your inference platform mark your output?

We checked eleven platforms that host open-weight image, video and audio models. One attaches content credentials, and it signs them in its own name. The rest attach nothing, and most of their terms make the obligation yours.

Marking behaviour of eleven inference platforms, as at 8 October 2026
PlatformMarks output
fal.aiYes — in its own name
ReplicateNo
TogetherNo
RunwareNo
BasetenNo
ModalNo
FireworksNo
Hugging Face InferenceNo
NovitaNo
DeepInfraNo
WavespeedNo

Read from each platform’s own documentation and terms on 8 October 2026. Platforms change; tell us if you find this out of date.

How it works

Four steps, and the only one you implement is the first.

  1. 01

    Send us the output

    One API call, or point your existing fal, Replicate or Together client at our proxy and change no code at all. Any content credentials the model already attached are kept as ingredients, never stripped.

  2. 02

    We mark it three ways

    A C2PA manifest signed under your certificate, an invisible watermark where the model added none, and a perceptual fingerprint. Platforms that strip metadata on upload cannot strip all three.

  3. 03

    Signed with your key, in your name

    Your signing key lives in a hardware-backed KMS and is never exported. The certificate names your company, so verifiers show your name rather than a vendor’s.

  4. 04

    Anyone can check it

    A public verification page and JSON endpoint on your own subdomain answer whether a file came from you, when, with what, and whether it has been altered since.

What you cannot get anywhere else

Hosted signing services sign as themselves. Certificate authorities sell you a certificate but not the conformance it depends on. Nobody maintains the rules for you.

Own-name signing

Signing under a vendor’s certificate shows the vendor’s name. We take you through C2PA conformance under your own legal name — no application fee, a median of 17 days — and request your free Level 1 certificate.

Maintained rule packs

The EU AI Act and Code of Practice, California SB 942 and AB 853, China, South Korea, India, New York, plus the platform labelling policies. Versioned with effective dates, so every output records which rules applied.

Your own detection endpoint

From 2 February 2027, Code of Practice signatories owe a public detection mechanism. Yours answers “is this one of ours?” for every output you have ever produced.

The dates that matter

Marking is already law. What changes on 2 December is that the transition period for existing systems runs out.

  1. 2 Aug 2026In force

    Article 50 applies

    Transparency obligations in force across the EU. Penalties up to €15M or 3% of worldwide turnover, whichever is higher, and lower for SMEs. The Digital Omnibus deferred other parts of the AI Act and left Article 50 untouched.

  2. 20 Jul 2026In force

    Guidelines confirm who is liable

    A company integrating a model by API into its own user-facing product is the provider of an AI system, and answerable under 50(2) for what that system generates.

  3. 2 Dec 2026Upcoming

    The grace period ends

    Systems already on the market before 2 August 2026 must be marking their output by this date. There is no further relief after it.

  4. 2 Feb 2027Upcoming

    Interoperable detection due

    Signatories to the Code of Practice owe a public detection mechanism for the content they generate.

Signunder is not a law firm and this is not legal advice. Each entry links to its primary source in our frequently asked questions.

Be marking by 2 December

Signunder is being built now, in the open. Leave your email and we will tell you when the free checker and the signing API are live, and nothing else.

One address, used only to tell you when Signunder is ready. No newsletter, no sharing with anyone.