AI Assurance Logo
AI Assurance aiassurance.co.za
Get In Touch

Watermark Management System

Transparency obligations under Article 50 of the EU AI Act.

The challenge

Article 50 of the EU AI Act sets transparency duties on providers and deployers of generative AI. The point is that people are not misled by AI-generated or manipulated content. POPIA does not require machine-readable watermarks or the EU icon. Those duties apply when the organisation places a generative system on the Union market, deploys deepfakes or public-interest AI text there, or when the output is used in the Union. Personal information in prompts, logs or labelled files still sits under POPIA.

Key regulatory drivers

  • Article 50(2) - Providers must ensure AI-generated outputs are marked in a machine-readable format and detectable as artificially generated.
  • Article 50(4) - Deployers must clearly disclose deepfakes and certain AI-generated text published for public information.
  • Article 50(5) - Information must be provided in a clear, distinguishable manner at first interaction or exposure.
  • Code of Practice (2026) - Operationalises those duties through commitments and measures for marking, detection and labelling.

A point-in-time audit is not enough for systems that keep generating content. The organisation needs ongoing governance, evidence, and a way to show that work to a market surveillance authority.

What the system is

The Watermark Management System is a governance and compliance platform for Article 50. It holds the processes, evidence and audit trail needed to show marking, detection and labelling as a living duty, not a one-off technical install.

For providers

  • Structured support for multi-layered marking (metadata and watermarking).
  • Governance for detection solutions and access.
  • Documentation of technical solutions against effectiveness, interoperability, robustness and reliability.
  • Ongoing monitoring of marking and detection performance.
  • Evidence packages ready for market surveillance authorities.

For deployers

  • Guidance and records for perceptible labelling, including EU icon use.
  • Support for human review and editorial control policies.
  • Internal compliance process documentation.
  • Traceable records of disclosure.

Transparency is treated as an ongoing, auditable process. Compliance becomes a capability the organisation can show, not a single implementation ticket.

Capabilities

1. Structured compliance governance

  • Central repository for transparency decisions, policies and evidence.
  • Separate provider and deployer workflows.
  • Version-controlled documentation aligned with the Code of Practice.
  • Approval and sign-off.

2. Multi-layered marking and detection

  • Framework for machine-readable marking.
  • Support for digitally signed metadata and imperceptible watermarking.
  • Detection results and performance monitoring.
  • Quality criteria: effective, reliable, robust, interoperable.

3. Lifecycle workflow

  • From system registration through ongoing monitoring.
  • Join points with risk management, change control and post-market surveillance.
  • Audit trail from obligation to evidence.

4. Authority-ready evidence

  • Structured evidence packages for market surveillance authorities.
  • Minimum and full QMS-integrated deployment profiles.
  • Traceable, signed records.

5. Continuous monitoring

  • Performance tracking of transparency measures.
  • Gap analysis against the Code of Practice as it moves.
  • Corrective and preventive action.

Code of Practice

  • Section 1 - Providers: multi-layer marking governance, detection documentation, quality criteria, interoperability planning, MSA cooperation records.
  • Section 2 - Deployers: EU icon records, human review policies, internal processes, disclosure traceability.
  • Measure 4.1 - Compliance process: documented, version-controlled processes with an audit trail.
  • Measure 4.2 - Testing and verification: red-teaming records, benchmarks, performance monitoring, corrective action.
  • Measure 4.4 - MSA cooperation: pre-prepared evidence packages and a documented response path.

How it runs

Phase 1 - Registration and scoping

  • Register the AI system and its transparency-relevant characteristics.
  • Decide provider, deployer, or both.
  • Define the scope of marking, detection and labelling.

Phase 2 - Governance setup

  • Open the compliance record against Code of Practice commitments.
  • Document technical solutions, policies and internal processes.
  • Set monitoring and evidence collection.

Phase 3 - Operationalisation and monitoring

  • Implement and document marking and detection.
  • Run performance monitoring and red-teaming.
  • Keep the line from risk to measure to evidence.

Phase 4 - Evidence and authority engagement

  • Generate structured, signed packages on demand.
  • Respond to market surveillance requests.
  • Show continuous compliance and improvement.

Two profiles: a minimum profile focused on transparency demonstrability, and an integrated profile that sits inside the QMS with change control and nonconformity.

Who it helps

Compliance and legal

  • Lower risk of an Article 50 finding.
  • Evidence ready for a market surveillance authority.
  • A faster response to an inquiry.

Product and engineering

  • A place to document how marking and detection actually run.
  • A view of the duty across the system lifecycle.

Leadership

  • A capability the board can point to.
  • Less reputational and financial exposure on generated content.
Arrange a Demonstration