Blog

WITNESS on the Enforcement of EU’s New AI Transparency Rules: Progress but Key Gaps Remain

The EU’s new AI transparency rules take effect on 2 August. WITNESS, which contributed to the working groups that drafted the Code of Practice behind the EU’s new transparency rules, welcomes this important step. However, it warns that leaving the most meaningful safeguards optional makes them easier to sign than to enforce, and outlines what the next version must address.

On 2 August 2026, the transparency obligations under Article 50 of the EU AI Act will take effect. The EU AI Act is the world’s first comprehensive law regulating artificial intelligence. As part of that framework, Article 50 introduces transparency requirements designed to help people identify AI-generated content and reduce the risks of deception.

The new rules arrive alongside two instruments designed to support their implementation: the Code of Practice on Transparency of AI-Generated Content, published by the Commission’s AI Office on 10 June, and the Commission’s Guidelines on the implementation of Article 50, adopted on 20 July. The Act obligations themselves are binding law, but the Code of Practice designed to operationalise them is voluntary, and companies must choose to sign up to it. That makes the Code a first step towards the more robust guardrails needed to preserve truth in the age of AI, in an increasingly fractured information environment, not the last word.

WITNESS has worked on protecting audio-visual truth in the age of AI for close to a decade. We took part in drafting this Code of Practice and responded to every version of it. Our assessment is grounded in experience. So when we say the Code is real progress, we also know where it falls short. On the issues that matter most to those on the frontlines – human rights defenders, journalists, fact-checkers, and those documenting abuses, it simply does not go far enough.

WITNESS welcomes the Code’s multi-layered approach to identifying AI-generated content. The Code asks companies to label AI-made content in more than one way, to offer free tools that can detect it while respecting people’s privacy, and to build systems that are reliable and work well together. For a public that is fast losing the ability to trust what it sees online, these are meaningful steps. 

Our main concern is that the Code makes the most important part optional. To be genuinely useful, a label needs to carry privacy preserving provenance, a record of where a piece of content came from and what has been done to it, and not just a flag that says “made by AI”. But the Code only requires that bare “made by AI” flag. The fuller record that would actually help people understand what they are looking at, where it came from and what was changed, is merely encouraged, both for the companies that build AI tools and for those who publish AI content. Even basic labels can be easily stripped away when content is edited, compressed, or reshared. The result is that content can be considered “labelled” while reaching audiences with little or no meaningful information about its origin.

Throughout the drafting process, WITNESS consistently argued that provenance should be a mandatory requirement, not an optional one. That remains our clearest priority for the next iteration of the Code.

It is reassuring that this is not a finished, one-off framework. The Code will continue to evolve as AI technology develops. The European Commission has committed to reviewing and updating it at least every two years, and the AI Office has an ongoing role in supporting and improving these rules. We will hold the Commission to these commitments and continue to push for provenance and meaningful labelling to become mandatory requirements, so people can reliably tell when content has been created or altered by AI.

Beyond this, three further gaps in the Code of Practice matter deeply to the communities WITNESS works alongside:

  1. Open-weight models should also face content transparency requirements: The Code encourages, but does not require, developers to label AI-generated content created with open-weight models – AI models that anyone can download, modify, and run themselves. This is a major gap because some of the most harmful AI-generated content is often produced using these models. Without mandatory labelling, synthetic content can spread online with no indication that it was generated by AI.
  2. Oversight and accountability: The Code lacks strong requirements for public reporting and independent civil society oversight. Without greater transparency about how companies are implementing these commitments, it will be difficult to hold them accountable or build public trust.
  3. Meaningful transparency for people: The Code encourages, but doesn’t mandate, media literacy efforts and user-facing provenance disclosures. As a result, labels may exist without helping people understand what they mean, or disclosures may be so subtle that users never notice them.

We also urge that the guidelines, which are non-binding, be interpreted to clarify providers’ obligations not narrow them. Exemptions for editorially reviewed public-interest content, as well as creative or satirical deepfakes, should not become loopholes that weaken disclosure requirements.

At the same time, labeling alone is not enough. Some of the most serious harms, particularly non-consensual intimate imagery, are often created and shared privately, placing them outside the Code’s obligations for deployers. In these cases, a label does little to protect the person who has been harmed.

Addressing illegal content requires complementary legal frameworks. The Digital Services Act and, for image-based sexual abuse, the Directive on combating violence against women, provide the legal avenues for removing unlawful content and seeking redress. The Code should therefore be understood as one part of a broader regulatory framework, not as a substitute for these protections.

At the same time, any system for removing illegal content must include strong due process safeguards. This is essential to ensure that satire, advocacy, journalism, and human rights documentation are not mistakenly taken down, while genuinely harmful and misleading content is addressed effectively.

Furthermore, detection alone will not close the gap. It performs unequally across faces, languages and contexts, and it loses ground to generation over time. It has to be paired with provenance and clear disclosure, and built to protect vulnerable and global-majority communities rather than to surveil them. The right to remain unverified matters as much as the ability to verify.

As Article 50 takes effect, WITNESS calls on the European Commission, the Code’s signatories, and the standards bodies responsible for operationalising these rules to ensure they deliver on their promise of meaningful transparency and accountability. This means making provenance a core requirement with clear privacy protections, requiring developers of open-weight models to mark AI-generated content, introducing independent oversight and public reporting, and ensuring the technical standards behind Article 50 support provenance and are grounded in fundamental human rights.

Today the promise is on paper. Whether it helps reclaim the trust the internet urgently needs depends on the details still left open.

More on our previous positions on the Code of Practice 

TAGS



Top

Join our fight to fortify the truth and defend human rights.

Take me there

Support Our Work!