1. The operational date is 2 August 2026
Article 50 transparency obligations apply from that date. An implementation review should record actor role, EU exposure, professional use and the timing of first interaction or exposure.
2. Six paths, not one generic badge
The map distinguishes direct interaction, synthetic content, emotion recognition or biometric categorisation, deepfakes, public-interest text and the horizontal requirement for clear, perceptible and accessible information.
3. Visible and machine-readable controls solve different problems
A deepfake disclosure cannot rely only on embedded metadata. A visible sentence also does not by itself create a robust, interoperable and detectable machine mark.
4. Exceptions require evidence, not optimistic defaults
The obvious-AI exception should be read restrictively. For public-interest text, superficial proofreading is not the same as substantive human review with editorial responsibility.
5. C2PA 2.4 describes provenance; it is not a magic badge
The c2pa.ai-disclosure assertion can describe model, scientific domain and human oversight. A JSON authoring draft is not CBOR, a manifest, a signature, asset binding, crJSON or independent verification.
6. The useful output is a work queue
The local builder drafts visible copy, preserves unknown facts as review items and produces an evidence checklist. It receives no answers, names or identifiers and gives no legal advice or certification.
Frequently asked questions
H/M Blindspot · hogarmas.net
Does Article 50 apply to every AI system in the same way?
No. The path depends on provider or deployer role, interaction or content type, exposure and any exception that can be supported with documented facts.
Is a visible label enough for AI-generated content?
Not necessarily. Machine-readable marking and visible disclosure are distinct requirements and controls; a deepfake disclosure cannot rely on metadata alone.
Is the builder's C2PA JSON a verifiable Content Credential?
No. It is an unsigned, unbound authoring view. A real C2PA implementation is needed to serialize, sign and bind a credential to an asset.
Are questionnaire answers uploaded?
No. Assessment and export run in the browser. Only aggregate events with fixed identifiers are sent, never entered answers or names.
