Wakemark

You didn't train a model. You're still a provider under Article 50.

The Wakemark team9 min read
An orange pilot boat running alongside a cargo ship in morning sun, white bow wave churning

The most common thing a marketing agency, a studio, or a SaaS product tells itself about the EU AI Act is some version of: "We don't build AI. We call someone's API. The obligations are the model vendor's problem." It is a comfortable position, and for the machine-readable marking duty in Article 50(2) it is very likely wrong. If you call an image or video model and put the output in front of a user under your own name, the Regulation's own text points the marking obligation at you— not at whoever trained the model. Analysts have called this the market's biggest blind spot. Here is why it exists, and how to work out whether you're standing in it.

Three roles, and the one everyone skips

The Act splits the world into a few defined roles. For a generative-media pipeline, three matter:

  • The model provider — whoever develops and places the underlying model on the market (the lab that trained it).
  • The system provider — whoever builds an AI system and puts it into service under their own name. This is the role companies forget they occupy.
  • The deployer — whoever uses an AI system under their own authority.

The instinct is to place yourself in the third box: you're just using a model. But the Act does not define these roles by who trained anything. It defines "provider" by who ships a system under their own brand:

Read the second half. You become a provider by having a system developed and shipping it under your own name — training the model is nowhere in the test. A studio that wraps a third-party video model in its own product, and serves generated clips to its own customers, has "had an AI system developed" and "put it into service under its own name." That is the provider definition, met.

Your product is its own AI system

The move that trips people up is assuming the only "AI system" in the room is the model. It isn't. An AI system is defined broadly — "a machine-based system that… infers, from the input it receives, how to generate outputs such as content" (Art 3(1)). Your product, the thing with the prompt box and the render button and your logo on it, is itself a machine-based system that generates content. And the Act anticipates exactly your situation: a general-purpose AI system is defined as one "based on a general-purpose AI model… including for integration in other AI systems" (Art 3(66)). The Regulation explicitly contemplates a downstream system, yours, built on an upstream model, someone else's — each a distinct system, each with its own provider.

Now put that next to the marking duty. Article 50(2) names the obligation-bearer, and it is not the model trainer and not the deployer:

"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."

The recital that settles the argument

If the definitions felt like lawyering, the Regulation's own recital removes the doubt. Recital 133 — the interpretive note behind Article 50(2) — says the marking can be implemented at the model level or the system level, and describes upstream model marking as a convenience for the party actually on the hook:

"The downstream provider of the AI system" is you. The Commission's draft guidelines on Article 50 (published for consultation in 2026, and non-binding) go further in the same direction: legal readers summarise them as putting Article 50 duties at the system layer (borne by the system provider), while the separate model-documentation duties of Article 53 sit at the model layer. On that reading, upstream model providers like the big labs are only encouraged to mark at the model level — they "would not formally fall within Article 50." If the formal duty isn't theirs, whose is it? The downstream system provider's. Yours.

The comfortable counter-argument, taken seriously

Honesty requires stating the other side, because it is not frivolous. Some compliance guides characterise an API integrator as a deployer, with the model vendor as the provider — "the provider is responsible for the model, the deployer is responsible for the application." If that reading held, the 50(2) marking duty would stay upstream. Three things make it a risky place to stand:

  • It only survives if you never ship a distinct system under your own name. A pure, unbranded pass-through that shows raw upstream output under the upstream's brand has a real argument for "deployer." A branded product with your logo on the render does not.
  • It is in tension with Recital 133 and the Commission's system-layer framing, both of which assume the downstream integrator carries the duty.
  • The Act knows how to move provider status explicitly, and it didn't need to here. Article 25 "deems" you a provider if you put your name on a system or substantially modify it — but that mechanism is framed around high-risk systems. Article 50(2) applies to providers of generative systems regardless of risk tier. You don't need Article 25 to be caught; you're caught by being the system's provider in the first place.

The fair summary: for a company shipping its own branded generative product, the "you're the provider" reading is strongly supported by the text, the recital, and the draft guidelines. It is not yet tested by a court, and academics have flagged the API-integration case as a genuine "structural compliance gap" with ambiguity at the edges. Treat it as a live exposure to plan around, not a settled certainty — and get your own counsel to read your specific setup.

Working out which one you are

A rough decision path, to be pressure-tested with a lawyer, not instead of one:

  • Do you put an image/video/audio/text generator in front of users under your own product name? If yes, you are very likely a system provider and the Article 50(2) marking duty is in scope — even though you trained nothing.
  • Do you publish deepfakes, or AI-generated text meant to inform the public on matters of public interest? If yes, you also have deployer disclosure duties under Article 50(4), on top of anything you owe as a provider.
  • Are you a bare, unbranded pass-through adding no distinct system of your own? Then "deployer" is arguable — but confirm it before you rely on it.

If you're a deployer too: Article 50(4)

The deployer duties are a different obligation with a different escape hatch. Deployers must disclose that a deep fake was artificially generated, and must disclose AI-generated text published to inform the public on matters of public interest — unless the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility." That editorial exemption is real, but it is a records exercise: to lean on it you need to be able to show the human review happened — who reviewed, when it was approved, how you label. Those are records Wakemark does not hold for you; keep them.

The clock, and one honest footnote about it

2 Aug 2026

Article 50 transparency obligations start applying, including the 50(2) marking duty for new systems.

2 Dec 2026

Marking deadline for systems already on the market before August — via the Digital Omnibus, adopted June 2026, awaiting publication.

€15M / 3%

Penalty ceiling for an Article 50 breach — €15M or 3% of worldwide annual turnover, whichever is higher (Art 99).

Two footnotes, because the dates get repeated carelessly. First, the 2 December 2026 grace period for pre-existing systems is not in the original Regulation — it comes from the 2026 Digital Omnibus, which the co-legislators adopted in June 2026 but which, at the time of writing, has not yet been published in the Official Journal and so is not yet in force. Treat it as adopted-and-expected, not as settled statute. Second, the €15M/3% ceiling is the middle penalty tier that Article 99 attaches to transparency breaches — not the €35M/7% tier, which is reserved for the prohibited-practices ban in Article 5.

Sources

Links verified 2026-07-10

  1. Regulation (EU) 2024/1689 — Article 3 (definitions 3(1), 3(3), 3(4), 3(66))provider / deployer / AI system / general-purpose AI system
  2. Regulation (EU) 2024/1689 — Article 50(2)the provider marking duty, expressly including general-purpose AI systems
  3. Regulation (EU) 2024/1689 — Recital 133“fulfilment of this obligation by the downstream provider of the AI system”
  4. Regulation (EU) 2024/1689 — Article 25 (provider status shifts)re-badging / substantial modification (high-risk framed)
  5. Regulation (EU) 2024/1689 — Article 99 (penalties)€15M / 3% tier for Article 50 transparency breaches
  6. Covington — takeaways from the Commission's draft Article 50 transparency guidelines (2026)Article 50 attaches at the system layer; model providers only encouraged to mark

Put it into practice

Wakemark is one API above the providers — capability routing, cross-provider failover, byte-exact custody, and an append-only audit ledger under every job.