The challenge
Article 50 of the EU AI Act sets transparency duties on providers and deployers of generative AI. The point is that people are not misled by AI-generated or manipulated content. POPIA does not require machine-readable watermarks or the EU icon. Those duties apply when the organisation places a generative system on the Union market, deploys deepfakes or public-interest AI text there, or when the output is used in the Union. Personal information in prompts, logs or labelled files still sits under POPIA.
Key regulatory drivers
- Article 50(2) - Providers must ensure AI-generated outputs are marked in a machine-readable format and detectable as artificially generated.
- Article 50(4) - Deployers must clearly disclose deepfakes and certain AI-generated text published for public information.
- Article 50(5) - Information must be provided in a clear, distinguishable manner at first interaction or exposure.
- Code of Practice (2026) - Operationalises those duties through commitments and measures for marking, detection and labelling.
A point-in-time audit is not enough for systems that keep generating content. The organisation needs ongoing governance, evidence, and a way to show that work to a market surveillance authority.
What the system is
The Watermark Management System is a governance and compliance platform for Article 50. It holds the processes, evidence and audit trail needed to show marking, detection and labelling as a living duty, not a one-off technical install.
For providers
- Structured support for multi-layered marking (metadata and watermarking).
- Governance for detection solutions and access.
- Documentation of technical solutions against effectiveness, interoperability, robustness and reliability.
- Ongoing monitoring of marking and detection performance.
- Evidence packages ready for market surveillance authorities.
For deployers
- Guidance and records for perceptible labelling, including EU icon use.
- Support for human review and editorial control policies.
- Internal compliance process documentation.
- Traceable records of disclosure.
Transparency is treated as an ongoing, auditable process. Compliance becomes a capability the organisation can show, not a single implementation ticket.
Capabilities
1. Structured compliance governance
- Central repository for transparency decisions, policies and evidence.
- Separate provider and deployer workflows.
- Version-controlled documentation aligned with the Code of Practice.
- Approval and sign-off.
2. Multi-layered marking and detection
- Framework for machine-readable marking.
- Support for digitally signed metadata and imperceptible watermarking.
- Detection results and performance monitoring.
- Quality criteria: effective, reliable, robust, interoperable.
3. Lifecycle workflow
- From system registration through ongoing monitoring.
- Join points with risk management, change control and post-market surveillance.
- Audit trail from obligation to evidence.
4. Authority-ready evidence
- Structured evidence packages for market surveillance authorities.
- Minimum and full QMS-integrated deployment profiles.
- Traceable, signed records.
5. Continuous monitoring
- Performance tracking of transparency measures.
- Gap analysis against the Code of Practice as it moves.
- Corrective and preventive action.
Code of Practice
- Section 1 - Providers: multi-layer marking governance, detection documentation, quality criteria, interoperability planning, MSA cooperation records.
- Section 2 - Deployers: EU icon records, human review policies, internal processes, disclosure traceability.
- Measure 4.1 - Compliance process: documented, version-controlled processes with an audit trail.
- Measure 4.2 - Testing and verification: red-teaming records, benchmarks, performance monitoring, corrective action.
- Measure 4.4 - MSA cooperation: pre-prepared evidence packages and a documented response path.
How it runs
Phase 1 - Registration and scoping
- Register the AI system and its transparency-relevant characteristics.
- Decide provider, deployer, or both.
- Define the scope of marking, detection and labelling.
Phase 2 - Governance setup
- Open the compliance record against Code of Practice commitments.
- Document technical solutions, policies and internal processes.
- Set monitoring and evidence collection.
Phase 3 - Operationalisation and monitoring
- Implement and document marking and detection.
- Run performance monitoring and red-teaming.
- Keep the line from risk to measure to evidence.
Phase 4 - Evidence and authority engagement
- Generate structured, signed packages on demand.
- Respond to market surveillance requests.
- Show continuous compliance and improvement.
Two profiles: a minimum profile focused on transparency demonstrability, and an integrated profile that sits inside the QMS with change control and nonconformity.
Who it helps
Compliance and legal
- Lower risk of an Article 50 finding.
- Evidence ready for a market surveillance authority.
- A faster response to an inquiry.
Product and engineering
- A place to document how marking and detection actually run.
- A view of the duty across the system lifecycle.
Leadership
- A capability the board can point to.
- Less reputational and financial exposure on generated content.