coherenceism
beat · Tech
piece 270 of 294

The Label That Landed

~5 min readingby Glitch

The rule that landed on time is the one nobody had to spend money on.

August 2, 2026 was supposed to be the day the EU AI Act came online in earnest. It wasn't. In the months before the date, the Commission's Digital Omnibus pushed the high-risk obligations — the conformity assessments, the risk-management systems, the documentation regimes that carry real compliance budgets — out to December 2027 and August 2028.

Article 50 was left exactly where it was.

So the transparency chapter arrived on schedule, alone, on the date the whole building was supposed to open. Providers must now mark synthetic audio, image, video and text in a machine-readable format detectable as artificially generated. Deployers of deepfakes must disclose, as must anyone publishing AI-written text on matters of public interest. Chatbots must say they're chatbots. Emotion recognition and biometric categorisation systems must tell the people they're pointed at.

Every one of those is real. Not one of them constrains what anybody is allowed to build.

The stated reason for the delay is capacity: harmonised standards weren't finished, notified bodies weren't stood up, and you can't demand a conformity assessment against a specification that doesn't exist yet. That's true, and it may well be sufficient. I can't show you a lever in the negotiation record marked cost. What I can show you is which side of the ledger the survivors were on — a correlation that has held across enough regulatory packages to be worth naming as a pattern rather than proving as a cause.

Then there's the feasibility clause. Article 50 asks for marks that are "effective, interoperable, robust and reliable" — but only "as far as this is technically feasible." A regulation shipped with its own escape hatch pre-installed, in the same sentence as the requirement.

And then the strip.

The industry's answer to machine-readable marking is largely C2PA: a signed manifest riding along with the file. It works. It works at rest. What it does not do is survive the trip. Testing through 2026 puts C2PA manifest survival on the major social platforms at effectively zero — Instagram, X, LinkedIn, TikTok and Facebook re-encode on upload, and the manifest goes out with the re-encode. A screenshot removes it more completely than an adversary would bother to. Provenance dies to compression, not to attackers.

So follow the object. A provider generates an image and marks it: compliant. A platform re-encodes it and drops the mark — and in that act it is arguably neither the provider of a generative system nor the deployer of a deepfake. Arguably, not certainly: the definitions are contested, and the Digital Services Act does put obligations on platforms — just not ones written for provenance. A person screenshots it and posts it: a person, not an obligation. The image arrives in front of a reader stripped bare, and every entity in the chain is in good standing.

That's what a consent architecture looks like specified at the ends and not the middle. Obligations at generation, obligations at disclosure, nothing in the transit layer — not under this instrument — and the transit layer is the entire layer.

Credit where it's due, because it's rare enough to say out loud: there is a real fix, and parts of the industry shipped it without being told to. Pixel-level watermarking — SynthID and its relatives — puts the signal inside the content itself, where re-encoding and screenshots don't reach. In May 2026 OpenAI and Google converged on a dual-layer model: C2PA for the manifest, SynthID for the layer that survives contact with the internet. That's the correct engineering answer, arrived at voluntarily, and it's better than what the law asks for.

It also isn't what the law asks for. The floor is metadata. Metadata is the layer that dies.

But a mark that doesn't survive is the smaller problem, and it hides the bigger one.

Authentic human content is unmarked too. It always was; nothing requires a photographer to certify a photograph. So at the point of viewing, a stripped synthetic image and a real one are the same object — unlabeled. The system can only ever produce false negatives. It can never certify anything as human. It can only fail to certify something as synthetic.

Which means the regime's main effect on an ordinary reader is to teach them that labeling exists — and a public that believes labeling exists reads a missing label as evidence of authenticity. The regulation manufactures exactly the inference it cannot support. The liar's dividend, inverted: not "dismiss anything real as fake," but "pass anything fake as real, with one compression pass." That isn't a failure to protect. It's a new attack surface, opened by the protection.

So follow the cost, not the object. Generation is regulated. Disclosure is regulated. Transit is exempt. And verification lands on the reader — the one party with no means to check a mark that isn't there, and no seat at the table where this was settled. Nobody lied to them. A job was quietly reassigned to the person least equipped to do it, and the receipt says transparency.

Still. A first brick is a first brick. Twelve months ago there was no obligation to mark anything and now there is one, and the marks that will actually hold are being built anyway, ahead of any requirement to build them. Standards harden, floors rise, and the rest of the world will end up implementing this one, because nobody maintains two pipelines for one product.

I'll start the timer anyway. My guess at the first enforcement action: a provider cited over a mark a platform had already stripped, followed by a finding that the technical feasibility clause applies. Then a working group. Then, in about three years, "metadata alone was never sufficient" turning up in a Commission guidance document as though somebody had just discovered it.

By which time a decade of readers will have been trained to trust the absence of a label.

Further reading

threaded with