AI Act Article 50 in force: what to log per generated file

Article 50 applies from 2 August 2026. Keep a per-file record of job id, request id and artifact URL from Sume, and know what the docs leave unsaid on marking.

5 min readSume
All posts

Keep one record per generated file: the Sume job id, the request id, the artifact id and URL, the job's events, and the disclosure text you attached. Article 50 of the AI Act applies from 2 August 2026, and the paragraphs quoted below are about marking and disclosure, not logs, so this is a practical habit and not legal advice. Sume's docs do not describe a machine-readable mark on outputs.

Article facts are from artificialintelligenceact.eu and the Commission's code of practice page (both listed under Sources); Sume facts from Jobs and results and Usage. All read 2026-09-30.

What does Article 50 ask of whom?

Paragraph 2 says providers must ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. Paragraph 4 says deployers must disclose that deepfake content has been artificially generated or manipulated. The Commission's page says the code of practice, published final on 10 June 2026 with about 190 signatories by the end of July, is "an adequate voluntary tool".

What can I record from Sume for each file?

Everything below comes from Sume's own responses, and none of it is a mark inside the media.

Record fields and where they come from (Sume docs linked above, read 2026-09-30)
FieldSource
Job idSubmit response; GET /v1/jobs/:id
Request idError body and response headers
Artifact id and Sume URLresult.artifacts[] on GET /v1/jobs/:id/result
TimelineGET /v1/jobs/:id/events (job.created to job.completed)
Cost rowsGET /v1/usage?job_id=

Should I store the provider URL or the Sume URL?

The Sume URL. Sume's docs say to use the Sume media URLs from the result, and that raw provider URLs are not public API outputs. Store the https://media.sume.com/... URL from the result along with your own content hash of the delivered file.

What do the docs not say?

They do not say whether outputs carry a watermark or C2PA record, so do not assume one; check the delivered file with your own reader, and add your own disclosure where a deployer duty applies. This post is not legal advice; ask a lawyer whether your use is a provider or deployer case.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume