The regulatory story is often told as a global watermarking mandate. It is better understood as three differentiated systems converging on the broad objective of traceability — and declining, in each case, to name the stack.
Europe
Article 50 has applied since August 2, 2026. Providers of covered generative AI systems must ensure outputs are machine-readably marked and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust, and reliable to the legally required degree, taking technical feasibility and the state of the art into account. [6] [7]
The EU deliberately does not dictate C2PA, SynthID, or any other named implementation. Its guidance contemplates watermarks, metadata identifiers, cryptographic methods, logging, fingerprints, and combinations of these techniques. [7]
Deployers have a different obligation. They must clearly disclose deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest, unless the text has undergone substantive human review or editorial control and someone holds editorial responsibility. An embedded machine-readable mark is not enough to satisfy this human-facing disclosure duty. [6] [7]
Hosting services, platforms, and broadcasters that merely distribute third-party AI-generated content are not automatically “deployers” under Article 50. The Commission strongly encourages them to preserve markings and support detectability, but encouragement is not a general statutory preservation command. The Digital Services Act may create relevant systemic-risk obligations for designated very large platforms and search engines, but it does not convert Article 50 into a universal C2PA-preservation rule. [7]
California
California’s AI Transparency Act became operative on August 2, 2026. It applies to a “covered provider”: a publicly accessible GenAI-system provider with more than one million monthly visitors or users in California. Its core output duties concern image, video, and audio, not text. [69]
A covered provider must provide a free detection tool with upload, URL, and API access; offer a visible “manifest disclosure” option; and include a “latent disclosure” in covered media. The statute defines provenance data as data embedded in digital content or included in metadata. “Latent” means present but not manifest. California does not require a particular invisible pixel, audio, or model-native watermark. [69]
The statute’s durability and information requirements are qualified: disclosures must be permanent or extraordinarily difficult to remove, and prescribed fields must be included, to the extent technically feasible and reasonable. [69]
California’s downstream obligations start later. From January 1, 2027, qualifying large online platforms must detect standards-compliant provenance data, surface it to users, permit inspection, and must not knowingly strip compliant provenance data or digital signatures where technically feasible. [69] That is a genuine platform-preservation obligation, and it is California’s—not Article 50’s.
The same statute requires a covered provider that knows a third-party licensee has modified a licensed system so it can no longer include the required latent disclosure to revoke the license within 96 hours. That is a duty for a California covered provider, not every enterprise customer or every organization using AI. [69]
China
China’s Measures for the Identification of AI-Generated (Synthetic) Content have applied since September 1, 2025. They require explicit labels in specified circumstances and implicit identifiers in file metadata, including information on synthetic-content attributes, the provider name or code, and content identifiers. [72]
The CAC encourages providers to add digital watermarks and other forms of implicit marking, but does not universally mandate embedded digital watermarks. Its explanatory material explicitly notes that hidden text marks and multimedia watermarks remain technically difficult or potentially costly and are therefore not compulsory. [18] [72] China is, in this respect, more visible-label-centric and metadata-centric than the caricature of a universal latent-watermark regime suggests. It also places active responsibilities on dissemination services to inspect metadata and add prominent indicators in defined scenarios. [72]
Its enforcement posture is not theoretical. None of the three statutes converts a missing mark into a finding about a human author.