The European Commission has invited providers and deployers of generative AI systems to sign the new Code of Practice on Transparency of AI-generated Content, ahead of the AI Act’s transparency obligations becoming applicable across the European Union.
Although participation in the Code remains voluntary, organisations choosing to become signatories publicly demonstrate their commitment to complying with Article 50 of the AI Act and benefit from a more predictable compliance framework. According to the Commission, adherence to the Code should also facilitate interactions with market surveillance authorities by establishing a common approach to transparency obligations.
The publication of the final Code represents another important milestone in the implementation of the AI Act and provides valuable insight into how regulators expect organisations to approach AI-generated content.
Below are five key practical takeaways.
1. Transparency is becoming a core compliance obligation
The AI Act does not prohibit generative AI. Instead, it requires organisations to be transparent when AI-generated or AI-manipulated content is made available to the public.
The Code translates these legal obligations into practical measures, providing detailed recommendations on how organisations should mark, detect and disclose AI-generated content across different media formats, including text, images, audio and video.
For organisations deploying generative AI systems, transparency is no longer simply a matter of good practice. It is rapidly becoming an operational compliance requirement.
2. Watermarking alone will not always be enough
One of the most significant aspects of the final Code is its emphasis on layered transparency measures.
Rather than relying on a single technical solution, providers are encouraged to combine different marking techniques capable of ensuring effectiveness, robustness, interoperability and reliability. Metadata, watermarking and other technical mechanisms are expected to work together to facilitate the identification of AI-generated content.
This reflects a broader regulatory objective: ensuring that AI-generated content remains identifiable even as technology continues to evolve.
3. Providers and deployers have different responsibilities
The Code distinguishes between the obligations of providers and deployers.
Providers are expected to implement technical measures enabling AI-generated content to be identified and verified, while deployers must ensure that appropriate disclosures are made whenever AI-generated or manipulated content is presented to users.
For many organisations, compliance will therefore require coordination between AI developers, software vendors, marketing teams, legal departments and compliance functions.
4. Technical governance matters as much as legal compliance
The Code demonstrates that AI governance extends well beyond drafting policies.
Detection mechanisms, metadata management, interoperability, internal procedures, staff awareness, record keeping and governance processes all form part of the Commission’s recommended approach.
This reinforces an increasingly familiar message across digital regulation: effective compliance depends on governance, documentation and organisational processes as much as technology itself.
5. Voluntary today may become tomorrow’s benchmark
Although the Code is voluntary, organisations should not dismiss its practical significance.
European regulators have repeatedly relied on soft-law instruments, guidelines and codes of conduct when assessing compliance with broader legislative requirements. While the Code does not create new legal obligations, it provides a strong indication of regulatory expectations under Article 50 of the AI Act.
For organisations already developing or deploying generative AI systems, aligning internal practices with the Code now may significantly reduce future compliance risks.
Looking ahead
The AI Act continues to move from legislation to implementation.
The publication of the Code of Practice demonstrates that the focus is shifting away from broad legal principles towards practical compliance expectations. Organisations using generative AI should therefore begin reviewing not only their technical capabilities, but also their governance frameworks, transparency processes and internal responsibilities.
For many businesses, AI compliance is no longer simply about adopting AI responsibly. It is about demonstrating that responsibility in a transparent, verifiable and auditable manner.
Cornerstone Counsel regularly advises organisations on AI governance, the EU AI Act, GDPR compliance and digital regulation. If you would like to discuss how the AI Act or the new Code of Practice may affect your organisation, we would be delighted to hear from you.

