On 20 July 2026, the European Commission published its Guidelines on Transparency of AI-Generated Content. These guidelines accompany the transparency obligations under Article 50 of the AI Act, which apply from 2 August 2026. The core: anyone deploying AI must make that recognisable and verifiable at various moments. For professionals working with AI output, output validation thereby shifts from an internal quality question to a demonstrable task.
What the new transparency rules require
The guidelines clarify the transparency obligations under Article 50 of the AI Act. Those obligations apply from 2 August 2026 and include, among other things, a duty to inform during direct interaction with AI, machine-readable marking of AI-generated content, and clear labels for deepfakes and public-interest text. The guidelines also clarify exceptions, scope and how compliance can be demonstrated via the Code of Practice.
The Commission confirms on the AI Act overview page that generative AI output must be identifiable, that certain AI content must be clearly labelled, and that the transparency rules take effect in August 2026. The page links this to the Code of Practice and the transparency guidelines. For organisations, this means that AI interaction and AI-generated content must be markable, labellable and traceable.
Privacy and source control for training and reference data
The transparency requirements do not stand apart from privacy rules. On 8 July 2026, the EDPB published draft guidelines 03/2026 on web scraping in generative AI, with a public consultation running until 30 October 2026. Those guidelines clarify that the GDPR continues to apply to the scraping of personal data, and mention, among other things, legal basis, transparency, data minimisation, a preference for reliable sources, timestamping and validation of data before use in training.
These points bear directly on output validation: if training or reference data may contain personal data, source control and traceability become part of a verifiable chain. Source control beforehand and the validation of data are thus not only a privacy requirement, but also a basis for verifiable output afterwards.
Output validation as a multi-step process
Recent academic work shows that output validation works better as a process than as a single score. The paper PROcess-Based BEnchmark for Hallucination Detection introduces PROBE, a process-based benchmark that breaks hallucination detection down into claim decomposition, evidence finding, evidence evaluation and hallucination localisation. The authors show that current LLMs struggle with evidence finding and that process-based evaluation is more transparent and more diagnosis-friendly than a single score.
For long, complex texts a broader view is needed. The paper Hallucination Detection in Long-Form Text Generated by LLMs presents LHD and HRKG-HD for long, factually interwoven text and shows that relational, knowledge-graph-based reasoning can improve hallucination detection in long answers. That supports the claim that long, complex outputs require a global, dependency-aware check. Together, both papers point to output validation as a multi-step process rather than a single-model or single-metric decision.
What this means in practice
The combination of the Commission guidelines of 20 July 2026, the EDPB guidelines of 8 July 2026 and the two ACL papers from July 2026 points in the same direction: output validation is becoming a verifiable chain of provenance, source control and multi-step validation. Here, it is not a single model that decides, but multiple checks that assess the output together.
A verification layer such as Vera can help here by making verification steps visible and thereby supporting oversight. Pre-processing and anonymisation take place on EU infrastructure; the workflow is designed to send only anonymised content to the selected AI models, and if a privacy check fails, nothing is forwarded. In this way, a structured approach gives more insight into the provenance and substantiation of AI output. The professional final judgement always remains with the user.