Timothe AI(ティモシーAI)

AI Content Watermarking Laws in 2026 - EU AI Act, China, and California

Compare AI content labeling law requirements across the EU AI Act, China, and California SB 942, including deadlines, covered content, responsible actors

Ryosuke Suzuki
2,830 words13 min read
AI Content Watermarking Laws in 2026 - EU AI Act, China, and California

Several jurisdictions now require some form of AI-content labeling, but the duties differ by actor, content type, and geography. The EU AI Act Article 50 is the broadest, applying from August 2, 2026: providers must embed machine-readable marks and deployers must disclose certain AI-generated public-interest text. China's labeling measures took effect September 1, 2025. California SB 942, operative August 2, 2026, largely covers image, video, and audio rather than text. No U.S. federal AI-content labeling law has been enacted as of August 13, 2026.

This article is for general informational purposes only and is not legal advice.


Jurisdiction-by-jurisdiction comparison table

The table below summarizes the four key jurisdictions. Each row identifies the responsible actor(s), what content is covered, and the mechanism the law requires.

JurisdictionKey law / instrumentResponsible actor(s)Covered contentRequired mechanismEffective / operative dateTransition or later milestoneKey limitation
EUAI Act Article 50 (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744)Providers (marking); deployers (disclosure)Synthetic text, audio, image, videoMachine-readable marking (provider); visible disclosure for deepfakes and public-interest text (deployer)August 2, 2026Dec 2, 2026 (transition for pre-existing systems); Feb 2, 2027 (Code interoperability milestone)Human-review/editorial-control carve-out for public-interest text; standard editing excluded
ChinaCAC Measures for Labeling AI-Generated Synthetic Content + GB 45438-2025Service providers (labeling); platforms (verification, relabeling); users (declaration)Text, image, audio, video, virtual scenesExplicit labels (visible) + implicit labels (metadata)September 1, 2025None specifiedDigital watermarking encouraged but not universally mandated
CaliforniaSB 942 / AB 853 (BPC Ch. 25)Covered providers (1M+ monthly visitors/users); large online platforms (2M+ unique monthly users, from Jan 1, 2027)Image, video, audio (text largely excluded from core latent-disclosure mandate)Free AI detection tool; manifest and latent disclosuresAugust 2, 2026Jan 1, 2027 (large-platform provenance); Jan 1, 2028 (capture-device provisions)Text substantially outside the latent-disclosure scope
U.S. FederalS. 4915 (introduced)N/A (bill, not enacted law)Proposed: AI-generated content broadlyProposed: visible and machine-readable disclosuresNot enactedN/ANo enacted statute as of August 13, 2026

Key terms: labeling, watermarking, and provenance metadata

Different laws use different terms, and they are not interchangeable.

AI content label : A visible or machine-readable disclosure showing that content was generated or manipulated by an AI system. This is the broadest term and may refer to a text tag, an icon, or embedded data.

Digital watermark : An imperceptible signal embedded directly in the content (for example, statistical patterns in token selection for text, or pixel-level signals in images). It persists within the content itself, independent of file containers.

Provenance metadata : Digitally signed supply-chain data attached to a file, such as C2PA Content Credentials from the Coalition for Content Provenance and Authenticity. This records the creation and editing history of a file but can be stripped if the metadata container is removed.

Machine-readable marking : The EU AI Act's statutory term, covering any technique a machine can detect. It is mechanism-neutral: a watermark, metadata, logging, or another approach may meet the statutory criteria.

Note that "AI-generated," "AI-assisted," and "processed by an AI system" carry distinct meanings. Content that was lightly edited by an AI tool is not necessarily "AI-generated" under every legal definition.

Digital watermarking, provenance metadata, and visible labels form three layers of AI-content transparency.
Digital watermarking, provenance metadata, and visible labels form three layers of AI-content transparency.

What does EU AI Act Article 50 require?

Article 50 of the EU AI Act (Regulation (EU) 2024/1689) creates layered transparency duties for providers and deployers of AI systems that generate or manipulate synthetic content. It separates machine-readable marking (a provider duty) from user-facing disclosure (a deployer duty).

Provider duties under Article 50(2)

Providers of AI systems that generate synthetic text, audio, image, or video must make outputs machine-readable and detectable as artificially generated or manipulated. The marking must be "effective, reliable, robust, and interoperable" to the extent technically possible (Article 50, AI Act Service Desk).

Standard editing does not trigger this duty. The European Commission's July 2026 Guidelines clarify that grammar correction, formatting, and AI-assisted translation count as standard editing and do not amount to generating or manipulating content for Article 50(2) purposes (Commission Guidelines). Short outputs may also fall outside the marking duty where embedding a meaningful signal is not technically possible (Commission FAQ).

Deployer duties under Article 50(4)

Deployers face a separate duty. When AI-generated or manipulated text concerns matters of public interest, deployers must disclose this to the public, unless the publication involves human review or editorial control by a natural or legal person bearing editorial responsibility (Commission Guidelines).

Article 50(1) also requires operators of AI systems designed for direct human interaction (such as chatbots) to inform users that they are interacting with an AI system, unless this is obvious from the circumstances (Article 50, AI Act Service Desk).

Does Article 50 apply outside the EU?

Yes. Article 50 has extraterritorial reach. Article 2 covers providers placing AI systems or general-purpose AI models on the EU market regardless of where the provider is based, as well as third-country deployers whose output is used in the Union. A U.S.-based company that provides or deploys a covered AI system generating content consumed by EU audiences falls within scope.


Who owns the obligation: provider, deployer, or publisher?

The EU AI Act assigns duties by role, not company size or location. Knowing which role your organization fills is the first step toward compliance.

A provider develops or places an AI system on the market. A deployer uses an AI system under its authority, except for personal non-professional use. A content-marketing team that uses a third-party AI model to draft articles is typically a deployer, not a provider. The model vendor is the provider.

The provider must build in the machine-readable mark and detection capability. The deployer must preserve the mark and, where applicable, disclose AI generation or manipulation to the public.

Example scenario: A publisher uses Claude to draft an article about a policy issue. Anthropic, as the provider, embeds machine-readable marks in supported models' output. The Anthropic Help Center describes plans for embedded text watermarks and signed C2PA provenance metadata for supported files, noting that supported Claude models launched in the EU on or after August 2, 2026 support marking at launch. The publisher, as the deployer, must not strip those marks and must meet its own disclosure duty if it publishes the text on a matter of public interest without substantive human review or editorial control.


What are the EU deadlines?

Three dates matter for EU AI Act transparency compliance: the general application date, the transition for pre-existing systems, and the Code's interoperability milestone.

August 2, 2026: general application

Article 50 duties generally apply from August 2, 2026. From this date, providers of newly launched AI systems must ensure outputs carry machine-readable marks, and deployers must meet their disclosure duties (Commission Quick Facts).

December 2, 2026: transition for pre-existing systems

The Digital Omnibus (Regulation (EU) 2026/1744) grants providers of generative AI systems already on the EU market before August 2, 2026 a four-month transition for Article 50(2) marking and detection duties. Those specific provider-side marking duties extend to December 2, 2026 for qualifying legacy systems (Digital Omnibus; Commission FAQ). This transition does not delay all Article 50 duties: deployer duties, chatbot disclosure, and other provisions still apply from August 2.

February 2, 2027: Code interoperability milestone

Under the final Code of Practice on Transparency of AI-Generated Content, providers commit to making watermark-detection mechanisms interoperable by February 2, 2027. Options include query routing, an embedded readable signpost, or a shared provider-agnostic detection solution. This is a voluntary Code commitment among signatories, not a separate statutory deadline (as described in the Paul Weiss analysis of the final Code; Code of Practice page).

EU AI Act transparency milestones run from August 2026 through the interoperability commitment in February 2027.
EU AI Act transparency milestones run from August 2026 through the interoperability commitment in February 2027.

Does human editing remove the labeling duty?

Human review can affect the deployer's disclosure duty, but it does not automatically remove the provider's marking obligation.

Under Article 50(4), the deployer disclosure duty for AI-generated or manipulated public-interest text does not apply where publication involves human review or editorial control by a natural or legal person bearing editorial responsibility (Commission Guidelines). This is the editorial-control carve-out.

Separately, the Commission's July 2026 Guidelines clarify that standard editing, including grammar correction, formatting, and AI-assisted translation, does not itself amount to generating or manipulating content under Article 50(2). A human editor who cleans up AI-drafted text is not, by that editing alone, creating new Article 50(2) duties.

Superficial proofreading or an automatic approval step should not be assumed to count as substantive editorial control under Article 50(4). The Commission guidance does not set a bright-line test, and the standard will likely be interpreted by national market surveillance authorities. Organizations relying on this carve-out should document their review process and name the person or entity holding editorial responsibility.


Is the EU Code of Practice mandatory?

No. The Code of Practice on Transparency of AI-Generated Content is voluntary. The underlying Article 50 duties are mandatory.

The final Code was published on June 10, 2026, and about 190 organizations had signed by the end of July 2026. The Code has two sections: one for providers (covering marking and detection) and one for deployers (covering labeling).

On July 9, 2026, the European Commission and AI Board assessed the Code as adequate to help providers and deployers comply with Article 50. The assessment explicitly states that adherence is not conclusive evidence of compliance and does not create an automatic safe harbor.

The Code itself acknowledges that no single current marking technique meets all four Article 50(2) statutory criteria (effective, reliable, interoperable, and resilient to modification) for text in every context, as noted in analysis by Tech Policy Press. Providers that do not sign the Code must show compliance through other means (Code FAQ).


What EU penalties apply?

Article 99(4)(g) of the AI Act places Article 50 transparency violations under an administrative-fine ceiling of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher for an undertaking.

These are ceilings, not automatic fines. National market surveillance authorities in EU Member States enforce these provisions and must consider proportionality, including the situation of SMEs and startups (Commission Quick Facts).


How does China label AI-generated content?

China uses a broader dual-track system that places duties on service providers, platforms, and users alike.

Explicit and implicit labels

The CAC Measures for Labeling AI-Generated Synthetic Content, effective September 1, 2025, require both types of labels across five content categories: text, image, audio, video, and virtual scenes.

  • Explicit labels are visible to users (for example, a text tag or on-screen indicator).
  • Implicit labels are metadata-based, including fields such as the service provider's identity and a content reference number.

GB 45438-2025, the corresponding national standard published February 28, 2025, provides the technical specs for these labeling methods.

The four issuing bodies are the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology (MIIT), the Ministry of Public Security (MPS), and the National Radio and Television Administration (NRTA) (CAC official explanation).

Do Chinese platforms have to verify AI labels?

Yes. Online information content transmission platforms must verify that labels are present and must relabel content where needed. Users must declare when they upload AI-generated content. Maliciously deleting, altering, falsifying, or hiding labels is explicitly prohibited (CAC official explanation; China Law Translate).

Is digital watermarking mandatory in China?

No. Digital watermarking is encouraged but not universally required. The CAC has stated that a blanket watermark mandate was not adopted because of technical difficulty and cost. The Measures require metadata-based implicit labeling as the baseline, while leaving digital watermarking as an optional measure (CAC official explanation).


What do California SB 942 and AB 853 require?

California's AI Transparency Act (SB 942), as amended by AB 853, became operative August 2, 2026. It applies to covered providers with more than 1 million monthly visitors or users that are publicly accessible in California.

Key provisions:

  • Free AI detection tool: Covered providers must offer a publicly accessible, no-cost detection tool.
  • Manifest disclosure: Visible disclosure to users that content was generated by AI.
  • Latent disclosure: Machine-readable signals embedded in content.

The substantive latent-disclosure mandate covers image, video, and audio content. Text is largely outside the core latent-disclosure scope. A California legislative analysis explains that text was excluded because embedding disclosures into text was not considered practical at scale.

AB 853 also adds:

  • Large online platform (2 million+ unique monthly users) provenance duties starting January 1, 2027.
  • Capture-device provisions starting January 1, 2028.

The current statutory text is codified at California Business and Professions Code §§ 22757–22757.6.


Is there a U.S. federal AI-content labeling law?

No. As of August 13, 2026, no enacted federal AI-content labeling statute was found in live research.

S. 4915, the AI Labeling Act of 2026, was introduced on June 24, 2026 and referred to the U.S. Senate Committee on Commerce, Science, and Transportation. It proposes visible and machine-readable disclosures for AI-generated content. It remains a bill, not law, and does not create any current federal obligation.

Enacted AI-content labeling rules cover the EU, China, and California, while no U.S. federal law is enacted.
Enacted AI-content labeling rules cover the EU, China, and California, while no U.S. federal law is enacted.

Practical checklist for publishers and content teams

This checklist turns the legal sections above into a workflow for organizations that use AI in content production.

  1. Inventory all AI systems and vendors used across content workflows, including drafting, summarization, translation, and image generation.
  2. Determine your role under each jurisdiction's definitions: are you a provider, deployer, or both?
  3. Identify outputs that reach EU audiences or Chinese platforms. Article 50's extraterritorial scope means company geography matters less than audience geography.
  4. Classify each piece of content: generated, manipulated, translated, summarized, or standard-edited. Standard editing does not trigger Article 50(2).
  5. For EU-facing public-interest text, determine whether publication involves substantive human review and a named person or organization holding editorial responsibility. Document the process.
  6. Preserve machine-readable marks and provenance data supplied by the AI provider. Do not strip metadata or watermarks.
  7. Check provider documentation for current model support, available detection tools, and any limitations. Rollout status and detection APIs may change.
  8. For China, ensure both explicit labels (visible) and implicit labels (metadata) are applied and not removed, altered, or hidden.
  9. For California, confirm whether your content type (image, video, audio) triggers latent-disclosure duties. Text is largely outside the core mandate.
  10. Recheck legal texts, Commission guidance, and provider documentation right before publication. Regulations, guidance, and provider capabilities are evolving rapidly.

FAQ

Does a watermark prove who authored the content?

No. A positive detection indicates content may have been processed by a particular AI system. It does not prove the system "authored" the content, and a missing watermark does not prove human authorship. The Anthropic Help Center expressly lists heavy editing, paraphrase, mixing, short passages, and other factors as limits on detection accuracy.

Does the EU require a visible watermark on every AI-generated article?

Article 50(2) requires machine-readable marking, not necessarily a visible watermark. Deployer disclosure under Article 50(4) applies only to deepfakes and AI-generated or manipulated text on matters of public interest published without human review or editorial control. Not every AI-assisted article triggers a visible-disclosure duty.

Can signing the EU Code of Practice guarantee compliance?

No. The Commission assessed the Code as adequate to support compliance but stated that adherence is not conclusive evidence of compliance and does not create an automatic safe harbor. Organizations must still meet Article 50's statutory duties independently.

Does California's law require labeling AI-generated text?

The core latent-disclosure mandate under SB 942 / AB 853 covers image, video, and audio. Text is largely outside that scope because of practicality concerns identified during the legislative process. Covered providers must offer a free AI detection tool, but that is separate from a text-labeling mandate.

What happens if a U.S. company publishes AI text read by EU users?

Article 2 of the AI Act extends its scope to third-country providers placing AI systems on the EU market and third-country deployers whose output is used in the Union. A U.S.-based publisher may fall under deployer duties if it publishes qualifying AI-generated content reaching EU audiences, regardless of where the company is incorporated.


Sources

EU

China

California

U.S. federal

Provider / other