euaiact toolkit / faq Independent project — not affiliated with the EUDeepBlueCoding logoDeepBlueCoding

Frequently asked questions

Straight answers about what these tools do, what they don’t, and where the standards are still moving.

What does the watermark tool actually add to my file?

Three layers, in one click:

1. A visible label (“AI GENERATED”, or your own watermark) baked into the pixels. 2. A machine-readable IPTC “digital source type” embedded in the file’s metadata, the same tag Google, Meta and Adobe use to flag synthetic media. 3. A signed C2PA manifest (Content Credentials) that cryptographically records the file was marked as AI content.

Is my content “EU AI Act certified” after using this?

No — and be wary of anyone who claims that. There is no “EU AI Act certificate” for images or videos. The Act has no certification scheme for this kind of content; CE marking only applies to high-risk AI systems, which this is not. What this tool does is apply the transparency measures Article 50 asks for. It helps you comply; it is not a stamp of compliance, and it is not legal advice.

Why does verify.contentauthenticity.org say “issuer not recognized”?

C2PA trust-list membership: in progress en trámite

Our signature is cryptographically valid and the AI disclosure is fully readable — but our signing certificate is not yet on the official C2PA trust list, so public verifiers show an “issuer not recognized” warning. We are going through the C2PA conformance program to get listed; until then, the manifest, the AI disclosure and the signature integrity all verify correctly, only the issuer identity is shown as unverified.

In plain terms: a verifier can confirm “this file is signed and marked as AI, and the signature hasn’t been tampered with”. What it can’t yet confirm is “…and the signer is a vetted organisation on the C2PA list”. That last step is the conformance process we’re completing. Our own Verifier labels this state honestly as “valid · issuer not on the C2PA trust list”.

Does the mark survive when I post to Instagram, X or WhatsApp?

Partly — and this is important to understand:

The visible label survives, because it’s painted into the pixels. Anyone looking at the image still sees it’s AI.

The machine-readable layers (metadata + C2PA) are often stripped by social platforms when they re-compress and re-upload your file. That’s a limitation of those platforms, not of your file: under Article 50 the obligation on a deployer is to apply the disclosure, which you did. If a third-party platform later removes the invisible marking, that is outside your control. This is a known, industry-wide issue — even the big AI labs lose their metadata the same way.

The emerging answer in the standard (C2PA 2.4 “Durable Content Credentials”) is to add an invisible watermark that survives re-compression. That technology isn’t openly available to third parties yet (Google’s SynthID for images is proprietary), so today the robust, defensible combination is exactly what this tool does: a visible label plus machine-readable marking plus a signature.

What’s the difference between “Fully AI” and “AI-modified”?

They’re the two IPTC source types the Act treats separately. Fully AI (trainedAlgorithmicMedia) means the whole image was generated by a model from a prompt. AI-modified (compositeWithTrainedAlgorithmicMedia) means real content was edited or combined with AI — a retouched photo, an AI inpaint, a composite. If your file already carries one of these tags, the tool detects it and pre-selects it for you.

Do my files get uploaded anywhere?

The watermark is composed entirely in your browser — those files never leave your device. Only the final C2PA signing step (and the Verifier) sends the file to our server, which processes it in memory, in an EU region, and stores nothing. The signing key itself lives in Google Cloud KMS in the EU and never leaves it.

Who is legally responsible for marking — me or the AI model?

The Act splits it. Article 50(2) puts machine-readable marking on the provider of the generative model (OpenAI, Google, or whoever ran the open-source model). Article 50(4) puts visible disclosure of deep fakes on the deployer — the person publishing the content. This tool is aimed at the deployer side, and is especially useful when the model you used (many open-source models) added no marking at all, leaving you to add it.

Why should I use this instead of waiting for the model to do it?

Because most models don’t. If you use an open-source model, a local generator, or you edited a real photo with AI, the output typically carries no provenance at all — drop it in our Verifier and you’ll see “not found” on every layer. This tool is the step that turns “nothing” into “visible label + machine-readable mark + signature”. Penalties under Article 50 reach €15M or 3% of global turnover, with first enforcement expected late 2026.

Is this legal advice?

No. It’s a practical tool to apply current best-practice transparency measures. For advice on your specific obligations, consult a qualified professional. See our legal notice and privacy policy.