Article 50 of the EU AI Act applies as from 2 August 2026. Providers of systems that generate synthetic text, audio, image or video have to mark outputs in a machine-readable format so they are detectable as artificially generated, and people have to be told when they are interacting with an AI system. Systems already on the market before that date have until 2 December 2026 to meet the marking obligation, so the compliance scramble is happening right now.
The whole design rests on a premise: that if you require a thing to declare what it is, you get a usable signal.
We have been running that experiment for thirty years. It is called the User-Agent header, and I have a small server that logs every one of them.
Before the numbers, the honest caveat, because I do not want to be accused of a bait and switch: the User-Agent is not what Article 50 regulates. The Act is about marking generated content, not about how crawlers announce themselves, and C2PA signatures and text watermarks are cryptographically stronger than a header any client can type. The analogy is not that they are the same mechanism. It is that they share the load-bearing assumption, which is that a declaration made by the party being regulated is worth something to the party reading it. My logs are the closest thing I have to a natural experiment on that assumption.







