On 20 July 2026 the European Commission adopted final guidelines for the transparency obligations under Article 50 of the AI Act. According to the Commission's page on the transparency of AI-generated content, these obligations apply from 2 August 2026. For organisations working with AI this means that demonstrating the origin and use of AI is no longer an optional choice, but a concrete obligation with a fixed end date.
What the guidelines precisely require
The guidelines distinguish between two roles. Providers of generative AI must mark their output with machine-readable markings, so that it is detectable that content has been generated by AI. Deployers, meaning the parties that put AI systems into use, must disclose in defined situations that AI is involved. The guidelines on transparency obligations for providers and deployers describe four disclosure scenarios, including deepfakes and AI-generated text of public interest.
The Commission also indicates that compliance can be demonstrated through a code of conduct or equivalent means. That is relevant: the obligation is not only about adding a label, but about demonstrability. An organisation must be able to show when a user is interacting with AI, when content is AI-generated, and how those signals have been technically recorded.
Transparency demands verification, not just marking
Marking and disclosure establish that something originates from AI. They say nothing about the reliability of the content. For professionals working with confidential information, that is the trickiest part: a text can be correctly marked as AI output and at the same time contain factual errors.
This is where the risk management side comes into play. The AI Risk Management Framework from NIST, in the form of the Generative AI Profile from 2024, describes how organisations can identify, measure and manage risks around generative AI. The framework emphasises that risk management is a structured process and not a one-off check. Transparency obligations and risk management complement each other here: the first makes origin visible, the second provides a structure for safeguarding the quality of output.
Technical detection of unreliable output
Policy and labelling are not sufficient to recognise unreliable output. Technical methods are needed for that. In 2025 NIST published research into hallucination detection in large language models using diversion decoding, which shows that detection of unreliable model output is an active field of technical research.
More recently, in July 2026, a peer-reviewed paper appeared in the ACL Findings on hallucination detection in long texts from LLMs, with a benchmark and an approach based on a hyper-relational knowledge graph. The core of that work is that output validation can be measurably evaluated with research methods, rather than relying solely on informal assessment after the fact. That is important for practice: it suggests that validation can be set up systematically and repeatably.
From separate checks to a verifiable chain
The common thread between the EU guidelines, the NIST framework and the recent detection research is that reliable AI use requires multiple layers. One model that produces an answer is not enough. A chain is needed that marks origin, compares output and makes verification steps visible. It is not one model that decides, but a verifiable process.
For professionals such as lawyers, notaries, occupational physicians, journalists and compliance teams this has direct consequences. They will soon have to be able to show how AI has been deployed and in what way the output has been checked. That calls for ways of working in which verification is not tacked on afterwards, but forms part of the process itself.
Where Vera fits into this picture
I am Vera is not a language model and not a chatbot, but a verification layer for professionals working with confidential information. The console is designed to make verification steps visible: answers from different models can be placed side by side, so that a user can see differences and uncertainties. That can help to spot unreliable output sooner. Vera does not thereby assure that output is correct and does not remove the possibility of hallucinations; the professional final judgement always remains with the user.
In the area of confidentiality, the Semantic Privacy Shield is relevant. Pre-processing and anonymisation take place on EU infrastructure, and the workflow is designed to send only anonymised content to the selected AI models. If a privacy check fails, nothing is forwarded. Documents can be viewed and edited within the same secure environment via Vera Office.
The new transparency rules oblige organisations not only to label, but to deal with AI demonstrably. A way of working in which verification and origin form part of the process fits logically with that. Those who already think about a verifiable chain instead of separate checks will be in a stronger position in August 2026.