If you publish content made with AI, three things happened this summer that are worth ten minutes. The one everyone is quoting is the least likely to reach you. The one almost nobody quotes is the one that attaches to whoever runs the service.
This describes what the sources say. It is not legal advice, and real exposure needs your own counsel.
What you actually owe
The EU AI Act applies from 2 August 2026, and Article 50 carries the transparency duties. It has four operative obligations, and they are aimed at different people.
The machine-readable marking duty is not yours. Paragraph 2 requires that synthetic audio, image, video and text be “marked in a machine-readable format and detectable as artificially generated or manipulated.” It lands on providers of the AI system, meaning whoever builds and supplies the model. A marketing team writing copy with an assistant is not the addressee. For systems already on the market when the regulation started applying, providers have until 2 December 2026 to retrofit that marking.
The duty that can reach a publisher is paragraph 4, and it splits. For image, audio or video constituting a deep fake, deployers must disclose that the content is artificially generated or manipulated. For text, the wording is much narrower: it applies to text “which is published with the purpose of informing the public on matters of public interest.” A pricing page or a case study is not obviously that. A commentary on an election or a contested health claim plausibly is.
And then there is the sentence that most summaries drop. Read paragraph 4 to the end. The text obligation “shall not apply … where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.”
Both halves have to hold: someone reviewed it, and someone is accountable for publishing it. For an organisation that already runs an editorial process, the compliance question is therefore not did AI touch this. It is whether you can show a human reviewed it and that responsibility sits somewhere nameable. That is a records question before it is a technology question.
Two things this does not cover. The deep-fake disclosure in paragraph 4 has no editorial carve-out; the artistic and satirical exception changes how the disclosure is made rather than removing it. And the December 2026 date is not a grace period for Article 50, it is a deadline for one paragraph for one group.
The label is not a shield
The obvious next thought is to lean on provenance metadata: let the file prove its own origin. Three events this month show what that layer does and does not carry.
A vendor promised it. On 11 August, Anthropic said it would embed watermarks in text and files generated by future models it launches in the EU, with work under way on already-released ones. That is an announcement of intent against a compliance deadline, not a description of a shipping product.
A vendor was already doing it. A teardown published on 20 August found that MS Paint and Photos embed an identifier into the pixels of AI-generated images, including images generated locally on the device. The server-side identifier, the value in the pixels and the C2PA soft-binding value are the same per-generation value. That is a precise object: it identifies one image, not a category.
And the signature layer underneath cracked. On 25 August a researcher published a way to defeat C2PA on rooted Android devices. The phone’s secure element will sign arbitrary data on request without the attacker learning any keys, and the mechanisms meant to detect a compromised device do not reliably do so. One of the routes in is hardware-level and not patchable. Google closed the report as “Won’t fix (infeasible)” and paid a $7,500 bounty anyway.
The researcher’s own explanation is the part a publisher should keep. Repairing this would mean rearchitecting the whole image pipeline, and even then, in their words, “you still can’t stop ‘picture of screen’ style attacks.”
That is the floor under the entire field. A camera pointed at a screen produces a genuinely signed photograph of a fake image. The signature is valid and the content is a lie. Provenance answers did this file come out of this pipeline precisely, and is this image true not at all.
Where the liability actually sits
Now the case that has nothing to do with labelling.
On 31 July, the 42nd Civil Chamber of the Regional Court of Munich I ruled largely for the German collecting society GEMA against Suno, in case 42 O 763/25. The chamber specialises in copyright, and the finding is not about training in the abstract:
“Nach Überzeugung der Kammer seien die streitgegenständlichen Musikstücke reproduzierbar in den Modellen Version v3.5 und v4 der Beklagten enthalten.”
The songs at issue are reproducibly contained in the finished models. The training run did not consume them. The court compared six named works against the generated outputs and held that, given the complexity and length of the pieces, coincidence was excluded.
Three consequences follow, and the third is the one that reaches a publisher.
The reproduction right was held infringed by the presence of the works inside the models. The text and data mining exception, the provision usually cited as the legal basis for training on copyrighted material in the EU, was held not to cover it. And the outputs were a second infringement: by reproducing the songs in outputs, the defendants infringed the works again.
That last one does not attach to whoever built the model. It attaches to whoever runs the service that produces the output. If the works are reproducibly contained in a shipped model, “we only used the weights” is a weaker position than it was assumed to be, and the exposure does not end when someone else’s training run does.
What this does not say
The Munich judgment is not final. The court’s press release says so in as many words. Suno disagrees and is considering an appeal, and the damages amount is still to be determined. A first-instance ruling is a real event with consequences for the parties, and it is not settled law.
A widely circulated figure about provisional enforceability is not in the source. A number claiming enforceability against security of 150,000 euros per claim appears in search results. The court’s press release says nothing about it. We looked.
The three provenance stories are one theme and three mechanisms. The Android break concerns C2PA signatures from camera hardware. It does not touch text watermarks or the identifier in Paint’s pixels. Anyone writing “AI watermarking is broken” has merged three things into a claim none of the three sources makes.
No penalty figures appear here. Fine levels get quoted confidently in secondary coverage, often without a link to the article they come from. If a number matters to your decision, take it from the regulation or from counsel.
What to do with it
Find out whether your process produces evidence of review and named responsibility. Those are the terms the exemption uses. An editorial workflow that leaves no trace of who checked what is a compliance gap in a place most teams do not look for one.
Sort your output into the two categories the text actually uses. Commercial copy is one thing; publishing on matters of public interest is another, and only the second attracts the text duty at all. Visual deep-fake content is a third, with no editorial exemption.
Do not build a compliance story on a signature you cannot verify. Provenance metadata is useful for the narrow question it answers. Treating its presence as proof of authenticity is a bet the researchers who broke it have already advised against.
Ask what is in the model you use, not only what you do with it. The Munich finding puts the copy inside the shipped weights and the second infringement in the output. That is the question a licence conversation should now contain, and it is the one that survives whichever way the appeal goes.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689 (retrieved 23 August 2026). Source of all quoted wording from Article 50, including the paragraph 4 text duty, the public-interest limitation and the editorial-review exemption, and of the application dates in Article 113.
- Regulation (EU) 2026/1744 of 8 July 2026, amending Regulation (EU) 2024/1689, Official Journal of 24 July 2026: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202601744 (retrieved 23 August 2026). Source of the transitional provision giving providers until 2 December 2026 to comply with Article 50(2), and of the revised application dates for high-risk systems. Both were read in the enacting terms, not in the recitals.
- Landgericht München I, press release on GEMA v. SUNO, 31 July 2026, published by the Bavarian State Ministry of Justice: https://www.justiz.bayern.de/gerichte-und-behoerden/landgericht/muenchen-1/presse/2026/16.php (retrieved 27 August 2026). Source of case number 42 O 763/25, the chamber and date, the six named works, the quoted reasoning on reproducible containment in models v3.5 and v4, the exclusion of coincidence, the infringement of the reproduction right, the inapplicability of the text and data mining exception, the second infringement through outputs, and the statement that the judgment is not final. The press release makes no statement about provisional enforceability; that absence was checked, not assumed.
- Gearnews, “GEMA vs. Suno”, 31 July 2026: https://www.gearnews.com/gema-vs-suno-tech/ (retrieved 26 August 2026). Source of Suno’s stated disagreement, the contemplated appeal, and the damages amount remaining to be determined.
- The Register, “Anthropic pledges to embed watermarks”, 11 August 2026: https://www.theregister.com/ai-and-ml/2026/08/11/anthropic-pledges-to-embed-watermarks-to-help-discern-ai-slop-in-sop-to-eu/5285792 (retrieved 27 August 2026). Source of the pledge and its scope for future models launched in the EU.
- Xusheng, “MS Paint invisible watermark”, 20 August 2026: https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ (retrieved 27 August 2026). Source of the pixel-embedded identifier, its presence with local generation, and the finding that the server identifier, the embedded value and the C2PA soft-binding value are the same per-generation value.
- David Buchanan, “Android C2PA”, 25 August 2026: https://www.da.vidbuchanan.co.uk/blog/android-c2pa.html (retrieved 27 August 2026). Source of the signing mechanism, the unreliability of attestation on compromised devices, the unpatchable hardware route, the “Won’t fix (infeasible)” resolution, the $7,500 bounty, and the quoted point about “picture of screen” attacks.
- All quotations were verified against the page sources rather than against summaries. This article consolidates three earlier pieces published on 23 and 27 August 2026; every primary source from all three is listed above.
