EU AI Act Article 50 creative provenance tracked through a DAM and creative workflow

EU AI Act Article 50: Why Provenance Belongs in Your DAM

By: Artstash Team

Last updated: August 2026

Quick answer: Since 2 August 2026, EU AI Act Article 50 and California's AI Transparency Act have both required AI-generated and AI-manipulated content to be marked and, in some cases, disclosed to the people who see it. China, South Korea and India already had comparable regimes live. For a mobile games publisher shipping hundreds of UA variants a month, the hard part is not the disclosure itself — it is being able to answer, six months and four re-edits later, which assets contain AI-generated content and how do we prove it. That is a creative operations problem, and it is solved in the DAM and the workflow, not in a legal review at the end.

Key takeaways

  • EU AI Act Article 50 has applied since 2 August 2026; one sub-obligation, machine-readable marking for generative systems already on the market, runs to 2 December 2026.
  • The rules are extraterritorial — what matters is where the creative is seen, not where the studio is registered.
  • No single label satisfies every market, but a single asset-level record can generate whichever one a market demands.
  • C2PA Content Credentials are the right standard, but manifests are routinely stripped by transcoding, so the durable system of record has to be your DAM.
  • Capture provenance at ingest and propagate it to derivatives; retroactive labelling of the back catalogue is not required.

Which AI disclosure laws are actually live right now?

JurisdictionWhat it requiresIn forceWho it catches
EU — AI Act Article 50Machine-readable marking of synthetic audio, image, video and text by AI providers; disclosure by deployers for deepfakes and certain published content2 Aug 2026 (marking for systems already on market: 2 Dec 2026)Anyone whose AI output is used in the EU, regardless of where they are incorporated
California — AI Transparency Act (SB 942, as amended by AB 853)Provenance data on generative output; from 1 Jan 2027, large platforms must surface it and must not strip it2 Aug 2026Content reaching California, regardless of company domicile
China — Measures for Labelling AI-Generated Synthetic ContentDual labelling: visible marks and embedded metadata or watermarks, across text, image, audio and video1 Sep 2025Services and content distributed in China
South Korea — AI Basic ActDeepfake and synthetic content labelling22 Jan 2026Korean market; penalties phase in later
India — IT Rules amendmentLabelling of synthetically generated information; accelerated takedown for harmful deepfakes20 Feb 2026Platforms and content in India
New York — synthetic performer lawPrior written consent and compensation for digital replicas of real people; officer-level liabilityJune 2026Advertising using synthetic likenesses or voices

Three things about this table matter more than the individual rows.

It is extraterritorial. Neither the EU nor the Californian rule turns on where your studio is registered. They turn on where the creative is seen. A UK agency cutting a video ad for a US publisher, served to players in Germany, is inside Article 50's scope.

It is not one label. China wants a visible mark and embedded metadata. The EU wants machine-readable marking plus, for deepfakes, a human-facing disclosure. New York wants a consent document you can produce on demand. There is no single artefact that satisfies all of them — but there is a single record that lets you generate whichever one a market demands.

Penalties are real but not the main risk. Article 50 breaches carry fines up to €15 million or 3% of worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities. For most publishers, the more probable pain is an ad platform rejection or a client indemnity claim.

What changed in 2026?

  • 2 August 2026 — Article 50 became enforceable, and California's AI Transparency Act took effect the same day, deliberately aligned. The European Commission adopted its implementation guidelines on 20 July 2026.
  • The Digital Omnibus split the timeline. The package agreed in May 2026 pushed the Annex III high-risk obligations back to December 2027, but left Article 50's core duties on schedule. Only one sub-obligation moved: machine-readable marking for generative systems already on the market before 2 August gets until 2 December 2026.
  • A voluntary Code of Practice on Transparency of AI-Generated Content now exists, including a standard icon set. Signatories get a degree of presumption of conformity — the closest thing to a safe harbour currently available.
  • Google shipped advertiser-side disclosure. Since 9 July 2026, a "How this ad was made" panel appears in My Ad Center across Search, YouTube and Discover. Ads built with Google's own AI tools are labelled automatically; if you used a third-party AI tool, you have to declare it yourself. Google also now permits AI labels burned into image and video creative without tripping its text-overlay and watermark policies.
  • Meta extended AI self-certification to all paid advertising, not just political and social-issue ads.
  • Nothing is retroactive. Content generated before 2 August 2026 does not need to be labelled after the fact, though the Commission encourages it where possible.

Why is this a DAM problem and not a legal problem?

Because the obligation is a retrieval obligation before it is a disclosure obligation.

Take a realistic mobile UA pipeline. A single campaign might produce 300 variants in a month, assembled from gameplay capture, CGI renders, licensed stock, an AI-upscaled 2019 hero render, AI-generated background plates, a synthetic voiceover for a Portuguese localisation, and twenty aspect-ratio renditions produced by an AI reframe tool. Those variants get remixed into next quarter's iterations. The editor who knows which layer came from where is on another account by March, or has left. This is the same sprawl that makes an AI art pipeline quietly become an asset management crisis — only now it has a statutory deadline attached.

Now a network asks you to certify AI use on a specific creative ID. Or a publisher's legal team asks which assets in the last twelve months contain synthetic likenesses. Or a Chinese partner needs visible labels on the subset that qualifies.

If your answer requires someone to open the project file and remember, you do not have a compliance process. You have an archaeology project — and one that gets more expensive every quarter.

The workable version is the opposite: provenance is captured at ingest, as a property of the asset, and propagates automatically to every derivative. Disclosure then becomes a query, not an investigation.

Why doesn't watermarking solve this on its own?

Because embedded provenance does not survive a video pipeline.

C2PA Content Credentials are the right standard and are genuinely maturing — the conformance programme is live, hardware signing ships in Sony, Canon, Nikon, Leica and Samsung bodies, and C2PA 2.3 extended signing to live streaming via CMAF segments. Adobe, Microsoft and Google are behind it. If you are choosing a provenance format, choose this one.

But research consistently finds that C2PA manifests are stripped or invalidated across the majority of common distribution channels. This is not censorship; it is a by-product of compression and transcoding pipelines built to minimise file size. Every ffmpeg pass, every network-side re-encode, every format conversion, every crop is a place the manifest can die. Screenshots and screen re-captures defeat it entirely.

For UA video specifically, this is close to fatal as a sole mechanism. Your asset is transcoded on the way into the DAM, again on export to each network spec, and again by the network itself. Assume the manifest will not reach the player.

Two design consequences follow:

  1. Extract the manifest before you transcode, and store it as data. The signed manifest is evidence you read once and record permanently. If your ingest pipeline transcodes first and reads metadata second, you have destroyed the evidence before capturing it.
  2. The system of record is the database, not the file. Embedded credentials are a nice-to-have that sometimes survives. The durable, queryable, auditable record is the one your platform holds and can re-attach or re-sign at export.

Note also the honest limit of any provenance system: a valid signature proves a specific key signed a manifest and the file has not changed since. It does not prove the claim is true. Provenance is documentation, not detection — worth saying plainly to any client who expects it to catch bad actors.

What does a provenance-capable creative workflow look like?

Seven requirements. If a DAM or creative operations platform cannot do these, it cannot carry this obligation for you — and it is worth checking against them when you evaluate a DAM for a game studio.

1. A provenance state on every asset, set at ingest. Four states is usually enough: no AI, AI-assisted (AI used in a supporting role such as upscaling, cleanup or rotoscoping), AI-generated (substantive synthetic content), and unknown for legacy library material that predates the policy. Unknown is not a failure state; it is an honest one, and it lets you scope remediation instead of guessing. This is the same metadata discipline that underpins AI asset management generally.

2. Lineage propagation with explicit rules. A derivative inherits its parent's state and can only escalate, never silently downgrade. Cut an AI-generated plate into a live-action edit and the master becomes AI-generated. This is the rule that stops provenance leaking away over successive iterations — and it needs to be enforced by the system, not by convention.

3. Renditions treated as first-class derivatives. If an aspect-ratio rendition is produced by an AI reframe or generative-expand tool, the rendition carries synthetic content the master did not. The same goes for AI-generated localisation audio. Auto-rendition pipelines are a common blind spot precisely because they feel mechanical, so the provenance rule has to live in the pipeline integration itself rather than in a manual step someone can skip.

4. Ingest ordering that preserves evidence. Manifest extraction before any transcode. Read once, store forever.

5. An immutable audit trail. Who set the state, when, on what basis, and every subsequent change. The value of a provenance record is entirely in whether a third party would believe it — an editable field that anyone can flip is worth nothing in a dispute.

6. Consent and rights artefacts attached to the asset. New York's synthetic performer rule needs a written consent document produced years after the shoot. Model releases, voice licences and stock licences belong on the asset record, not in someone's inbox.

7. An exportable disclosure register. One filtered view: every asset shipped to a given market in a given window, with its provenance state and evidence. That view is what you hand a network or a client's legal team when they ask.

Two deliberate exclusions. Do not start with a classifier. Automated "is this AI?" detection is a research problem with a false-positive rate you would have to review manually anyway; declared-at-ingest state is more accurate and far cheaper. A deterministic creative QC pass against rules you control will catch more real problems than a probabilistic origin guess. And do not attempt retroactive labelling of the whole back catalogue — neither the EU nor California requires it. Mark legacy as unknown, draw the line at the go-live date, and move on.

Where this lands, by team

Best for game publishers: the exportable disclosure register. Your exposure is aggregate and cross-market, and you need to answer questions about creative you did not produce yourself.

Best for creative agencies: lineage propagation and the audit trail. You are the party warranting to a client what is in the file, and you carry that warranty long after the campaign ends.

Best for UA teams: the rendition and trafficking layer. You are the one filling in Google's third-party AI declaration and Meta's self-certification, and you need the answer to come from a system rather than a Slack thread.

What is the actual risk of doing nothing?

Ranked by how likely you are to feel it:

Platform friction, this quarter. Undisclosed AI creative can attract an automatic label in wording you did not choose, or a disapproval. On Meta and Google, self-certification is already a submission-time field — someone is answering it today, accurately or not. That is one more place where approval bottlenecks quietly eat UA velocity.

Client warranty exposure, this year. Publisher MSAs increasingly carry representations about AI use and training-data provenance. Signing those without an asset-level record is signing an obligation you cannot evidence.

Regulatory penalty, eventually. Real, large, and the least likely of the three to reach you first.

There is also a demand-side argument that has nothing to do with law. A Q2 2026 Fractl survey reported that 39% of consumers say heavy AI use in a brand's marketing reduces their trust in that brand — up from 20% the year before — while over 90% want AI-generated media labelled. Whatever you think of that trajectory, the teams that can label accurately will have options that the teams that cannot will not.

Frequently asked questions

Does Article 50 apply to my studio if we are not based in the EU?

Yes, if your creative reaches people in the EU. The AI Act applies to providers, deployers, importers and distributors placing AI systems on the EU market or whose AI output is used within the EU. Incorporation is not the test; audience is.

Are we a "provider" or a "deployer" under Article 50?

Almost certainly a deployer. A provider develops and places an AI system on the market — that is your model vendor's role, and the machine-readable marking obligation sits primarily with them. As a deployer, your duties centre on disclosure where you publish deepfakes or certain public-interest content, and on knowing enough about your own library to comply. In practice the deployer duty is where the operational cost sits.

Is a game ad with AI-generated visuals a "deepfake"?

Not usually. Article 50(4)'s deepfake disclosure targets content resembling a real person, object, place or event that would falsely appear authentic. Stylised game creative rarely qualifies. But AI-generated realistic actors, cloned voices, or synthetic footage of real-world locations can, and localisation voiceover is a common trigger. Assess it per asset, which requires a per-asset record.

Do we have to label our existing back catalogue?

No. Content generated before 2 August 2026 does not need retroactive labelling under Article 50, although the Commission encourages it where feasible. Mark legacy assets as unknown provenance and apply the policy from your go-live date forward.

Does C2PA on its own make us compliant?

No, for two reasons. C2PA manifests are frequently stripped by transcoding and upload pipelines, so signed content often reaches the viewer without its credential. And the deployer-facing disclosure obligations are about what you tell people, not only what is embedded in the file. Treat C2PA as the interchange format and your DAM as the system of record.

What is the single highest-value thing to do first?

Turn on provenance capture at ingest, with lineage propagation, and let the record build from today forward. Every week you delay adds another cohort of assets you will have to classify by hand later.

Where Artstash fits

Artstash is the creative operations system of record for game and video teams: assets are catalogued on ingest, derivatives and renditions stay linked to their parents, and every state change is logged. That is the same substrate an Article 50 disclosure register needs — which is why provenance belongs in the DAM rather than in a spreadsheet maintained alongside it. Talk to us about your creative pipeline or see the plans.

Sources and further reading

This article is general information about a fast-moving regulatory area, not legal advice. Confirm your specific obligations with counsel before relying on any of it.

One cloud library versus a connected network of storage, version control and 3D assets, illustrating the Artstash vs Air comparison
Artstash vs Air (2026): Which Platform Fits Your Team?
Read More
Artstash character casting a search beam across separate clusters of image, video, 3D and document files, illustrating AI asset management indexing assets in place
What Is AI Asset Management? A Practical Guide for Distributed Creative Teams
Read More
Assets from Google Drive, Dropbox, Perforce and Git converging into a single search result in Artstash
Search Google Drive, Dropbox and Every Asset in One Place
Read More

All your 3D & 2D assets in one place. Organized and visualized.

Get started