Blog

Making Generative AI Safer: EU AI Act Compliance and the Role of C2PA

September 02, 2026

By Dom Guinard, C2PA Strategic Advisor and Tony Rodriguez, CTO at Digimarc

Making Generative AI Safer: EU AI Act Compliance and the Role of C2PA

Generative AI is transforming the way we create, communicate, and solve problems. Yet the rapid adoption of these technologies is making it harder to distinguish between AI-generated and authentic content. In an era where trust is paramount, people need visibility into the source of the information they consume so they can assess its reliability and make informed judgments about it.

This challenge extends beyond individuals to companies. Organizations must protect their intellectual property, reputation, and customer trust as their products, logos, and creative assets are increasingly repurposed, manipulated, or misrepresented in AI-generated content and then consumed by potential buyers. Without clear transparency into the provenance of information and digital assets, we all face a greater risk of deception, fraud, manipulation, and misinformation.

Establishing trust in the digital ecosystem requires knowing not just what content says, but where it came from—and that’s why industry standards like C2PA and new regulations like the EU Artificial Intelligence Act were created. Let’s take a closer look at both and what they mean for businesses today.

Industry Standards Like C2PA Make Transparency and Trust Possible  

C2PA is one of the leading industry standards bringing provenance information to all types of media, including video, images, audio, documents (such as PDFs), and even text. The C2PA standard tracks the origin and history of online assets and documents this history as Content Credentials, which are attached to the assets so people can use them to fact check what they see online.  

Over the past two years, many industry players have been adopting C2PA, from camera and mobile phone manufacturers and providers of creative tools to generative AI companies and media firms and social media platforms.

Digimarc has been at the forefront of driving this standard with a particular focus on using digital watermarking technology to make C2PA Content Credentials (also referred to as C2PA manifests) more durable and recoverable in the event they are stripped from media assets. This can happen inadvertently (via social media posting, for example) or intentionally by bad actors. 

The EU AI Act Is Driving C2PA Adoption

The pace of C2PA adoption has accelerated in the past few months, thanks in part to new regulations around GenAI that are now in force within various countries and regions. In this first post, let’s look at one of the most timely regulations facing businesses today: the EU Artificial Intelligence Act, or more commonly, the “EU AI Act.”  

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. Designed to promote trustworthy AI while protecting safety, fundamental rights, and ethical standards, it takes a risk-based approach—meaning the higher the potential risk an AI system poses to society, the stricter the regulatory obligations.  

Compliance Requires Flagging of AI-Generated Content

Compliance with the EU AI Act is mandatory for high-risk AI systems, which include certain AI systems used in sensitive or high-impact sectors or operational areas such as hiring/recruitment tools, credit scoring, medical devices, law enforcement, and critical infrastructure. These systems require rigorous risk management, bias testing, technical documentation, clear logging, and human oversight.

Large GenAI platforms such as Google Gemini, OpenAI ChatGPT, or more recently Anthropic Claude, have been leading the adoption of C2PA and digital watermarking to comply with the law. However, the EU AI Act also applies to far more players due to its Article 50. In essence, Article 50 imposes obligations on providers of generative AI systems and, in certain circumstances, businesses that use generative AI products to produce content. Providers of AI systems must embed technical solutions to ensure the outputs that their customers generate are marked in a machine-readable format so they are detectable as artificially generated or manipulated. And businesses using those systems must also disclose certain AI-generated or manipulated content, including deepfakes and certain text published to inform the public on matters of public interest.

In other words, there must be a way to identify AI generation or manipulation where Article 50 requires it. 

How C2PA + Digital Watermarking Enable Compliance with the EU AI Act

The EU AI Act does not dictate a particular way of implementing marking requirements. However, the technical guidance defined in the Code of Practice on Transparency of AI-Generated Content is a strong match for C2PA Content Credentials. The Code of Practice, which Digimarc contributed to, is a voluntary framework for demonstrating compliance with the EU AI Act. Businesses that comply with the Code may be better positioned to demonstrate Article 50 compliance.

The core of C2PA is a machine-readable system of digitally signed metadata, which allows it to satisfy the need for providers to indicate in a machine-readable way if content is AI-generated or manipulated. However, a minimal implementation of C2PA with metadata attached to assets may not be sufficient to satisfy the robustness and reliability criteria of the EU AI Act: specifically, the information must be robust enough to resist common workflows (such as posting media on social media).  

Thanks in part to the digital watermarking task force of C2PA that Digimarc co-chairs, with the release of C2PA 2.1, the combination of C2PA with digital watermarking has become part of the standard. Digital watermarking can strengthen robustness because the watermark can persist when attached metadata is stripped, and it can be used to recover or reconnect the asset with the full provenance information contained in the C2PA manifest.

Start the conversation and learn how Digimarc can take your business to the next level.

C2PA & Digital Watermarking: New Business Opportunities

The other obvious advantage of implementing C2PA with digital watermarking to comply with the EU AI Act Article 50 is that it may open up new opportunities for your business. As C2PA is being implemented by hundreds of players, you may be able to interoperate with these machine-readable systems, which could:

  • Enable platforms and tools to recognize and process declared provenance. AI and search tools such as Claude, ChatGPT, and Gemini, as well as social media platforms like LinkedIn, have started supporting C2PA Content Credentials to identify how content was created or modified.
  • Allow you to better manage how your brand assets are being used. For example, digital watermarking of assets can help you monitor leakage of important media assets, while C2PA can support emerging rights-management and programmatic licensing systems.

These are just some of the ways digital watermarking and C2PA creates opportunities for your media assets to become part of a larger and vibrant ecosystem that is likely to serve as the backbone of digital media provenance, authentication, and licensing in the near future.

Article 50 Took Effect August 2, 2026. Are You Ready?

On August 2, 2026, the transparency obligations under Article 50 generally became applicable to providers and deployers. However, there is a specific extension that grants providers of generative AI systems that were already on the market before that date extra time—until December 2, 2026—to comply with Article 50(2)’s machine-readable marking requirement.

Learn More

To learn more about the EU AI Act and how Digimarc can help your business support its compliance efforts, visit the following links:  

In blog 2 of this series, we’ll take a deeper dive into the role of digital watermarking in C2PA and what it may mean for compliance—and your business. 

You May Also Like

Learn more
When Every Scan Becomes Risk Intelligence
Blog

Beyond Product Authentication: When Every Scan Becomes Risk Intelligence

Learn more
Serialized, But Not Authenticated
Blog

Serialized, But Not Authenticated

leadership-team