AI Act from 2 August: Why a QR Code Does Not Replace AI Marking

Separate machine-readable marking, perceptible disclosure and QR-based provenance under Article 50 with a practical four-layer model.

le QR3 Redaktion

AI Act from 2 August: Why a QR Code Does Not Replace AI Marking

On 20 July 2026, the European Commission published its guidelines on the transparency obligations under Article 50 of the AI Act; the related overview page was last updated on 29 July 2026. The obligations generally apply from 2 August 2026. For teams publishing AI-generated images, video, audio or text, one technical distinction matters immediately: a machine-readable mark in the content, the ability to detect that mark and a perceptible disclosure for people are separate layers. A QR code can add a fourth layer for provenance and explanations. It does not automatically replace the other layers.

Article 50 separates providers from deployers

The text of Article 50 assigns different obligations to different roles.

Providers of systems that generate synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. As far as technically feasible, the solution must be effective, interoperable, robust and reliable. The article does not prescribe a particular barcode. It requires a property of the output and a corresponding way to detect it.

Deployers, by contrast, must inform people in certain situations: for example when using emotion recognition or biometric categorisation, when exposing people to deepfakes, and when publishing certain AI-generated or manipulated text on matters of public interest. The information must be clear and distinguishable, and it must be provided no later than the first interaction or exposure. Applicable accessibility requirements also apply.

A company may hold both roles. An organisation that develops an in-house generation system and publishes its outputs must therefore assess both the provider and deployer obligations.

Why “machine-readable” does not simply mean “QR code”

A QR code is machine-readable. It does not follow that a QR code placed beside an AI image satisfies the provider obligation. Article 50(2) requires the AI system's output to be marked and detectable as AI-generated or manipulated. A separate square usually points to an external page. If the image is copied, cropped or shared without its surrounding layout, the pointer may disappear while the content continues to circulate.

The architectural conclusion is therefore that an external QR code is normally a supplementary provenance layer, not the technical mark within the content. Whether a specific implementation complies depends on the system, output format and deployment context.

A scan requirement is not enough on the deployer side either. The Commission's Article 50 questions and answers state specifically for deepfakes that disclosure should be perceivable without special tools or a dedicated action. Deployers cannot rely solely on an embedded machine-readable mark. A notice that becomes visible only after scanning a QR code therefore arrives too late for the required first-exposure disclosure.

Four layers for a defensible implementation

1. Marking inside the content

The first layer belongs in the generation or export pipeline. Depending on the medium, possible techniques include signed metadata, watermarks, cryptographic proof of origin, fingerprints, logging methods or combinations of these. The Commission guidelines emphasise two linked elements: marking and detectability. A mark without an available means of detection does not achieve the stated objective.

The voluntary EU Code of Practice on Transparency of AI-generated Content describes one possible route for demonstrating compliance. For containerised content distributed online, it sets out a layered approach using digitally signed metadata and an imperceptible watermark. Free-form text has different technical constraints. The Code is voluntary; the Article 50 obligations are not.

2. A perceptible notice at first exposure

The second layer is for people. The notice belongs where the content is first encountered, not only in a general privacy policy or on a linked detail page. Depending on the medium, this can be a visible label, an audible disclosure or another clear and accessible form.

For editorial text, an important exception applies. The Commission FAQ explains that published text on matters of public interest does not require the disclosure if it has undergone substantive human review or editorial control and a natural or legal person holds editorial responsibility. Spell-checking or a purely formal review is not sufficient.

3. A QR code as a provenance and context path

The third layer is optional but operationally useful. A QR code can connect a printed image, package, exhibition panel or presentation to a durable provenance page. A dynamic QR code allows the destination to evolve under controlled conditions without replacing the physical carrier.

The destination should not make a blanket “AI Act compliant” claim. It should present verifiable facts instead:

  • a unique asset and version identifier,
  • the responsible organisation and contact point,
  • the AI system used where disclosure is appropriate,
  • generation time and material editing steps,
  • the status of human or editorial review,
  • the type of mark present and access to the detector,
  • current publication status plus correction or withdrawal notices.

Personal prompts, confidential model parameters and sensitive production data do not belong on a public provenance page. Transparency does not require the disclosure of personal data or trade secrets.

4. An internal evidence log

The public page is not a substitute for an internal audit trail. For each publication, an organisation should be able to show which source asset was generated, which transformations were applied, whether markings survived and who approved the release. Immutable asset IDs, hashes of approved files, timestamps, version relationships and recorded detection results are practical building blocks.

A seven-step implementation workflow

  1. Map the roles: Document who is the provider, deployer or both for every system.
  2. Inventory output types: Treat image, video, audio, free-form text and containerised text separately.
  3. Test marking at export: Do not wait until the end of the publishing chain to look for a marking solution.
  4. Test transformations: Compression, resizing, cropping, transcoding and platform uploads must not silently destroy marking or detection.
  5. Place the notice at first contact: Make it visible or audible, understandable and accessible; use the QR code only for detail.
  6. Version the provenance page: Keep a stable URL, current facts and explicit correction and withdrawal logic.
  7. Retain evidence: Record test results, approvals, detector version and the exact published asset version together.

Tool hand-offs are particularly important. A generator may produce correctly signed metadata that is removed during export from an image editor or upload to a content management system. The source file is therefore not enough: the file actually delivered to the public must be tested.

Common misconceptions

“The QR code is machine-readable.” True, but it often marks the carrier or layout rather than persistently marking the AI output itself.

“Metadata is always enough.” Not necessarily. Formats and platforms may strip metadata. For many widely distributed media types, the voluntary Code therefore proposes multiple marking layers.

“The visible disclosure can sit behind the QR code.” That is risky for first exposure because a person would have to take an additional action before receiving the notice.

“Every AI-assisted text needs a label.” No. Scope, standard editing, public-interest purpose, substantive human review and editorial responsibility must be assessed separately.

What to prioritise before 2 August

The Commission FAQ describes a limited grace period only for the marking and detection obligation for certain systems placed on the market before 2 August 2026: for those systems, 2 December 2026 is relevant. This is not a general postponement of the other obligations. Content generated before 2 August does not have to be labelled retroactively, although the Commission encourages voluntary labelling where possible.

For the remaining days, the first priority is therefore not a large QR campaign. It is role mapping, export and detection testing, perceptible disclosures at the actual point of delivery, and a defensible evidence trail. The QR code then becomes what it does well: a stable entry point to deeper, updateable provenance information.

Sources