AI watermarking and other AI transparency measures are now mandatory under the EU's Artificial Intelligence Act (Act) and apply to anyone who supplies AI systems or AI-generated outputs for use within the EU, even if they are based in New Zealand.1
More broadly, watermarking is now being applied by many AI models to AI-generated outputs worldwide, not just in the EU. This means that New Zealand organisations with no EU connection and outside the scope of the Act may still be producing marked content every day when using AI tools to provide services to customers.
What is AI watermarking?
"AI watermarking" covers a range of techniques for signalling that content has been generated or manipulated by AI. Most are imperceptible by humans without a specialised detection tool. There are two commonly used types, and they are often used together:
- Embedded watermarks: Statistical patterns woven into AI-generated content itself in pixels, audio waveforms or word choices. More resilient than metadata, but still difficult to detect once content has been heavily edited. Detection usually requires a highly specialised tool.
- Provenance metadata: Cryptographically signed metadata recording a file's origin and history. Checkable with a wider range of tools, but easily lost when a file is converted, re-saved or stripped of metadata.
Anthropic already uses both.2
What a watermark can and can't tell you
In many cases, detection requires a compatible tool. For example, Anthropic's publicly available scanner checks files for Claude-generated provenance metadata.3 Anthropic's detection API can further assess the likelihood that text was generated or edited by Claude, but access is currently limited to eligible organisations as required under EU law, including regulators, law enforcement, media, fact-checkers, researchers, educational organisations and EU civil society groups.4
Whilst the signal is useful, a watermark may survive on content a human has substantially rewritten and may attach to human-authored content that was merely proofread, translated or summarised using AI.
Equally, the absence of a watermark doesn't definitively mean that AI has not been used. Marks and metadata can be removed, degraded or lost through ordinary editing and file conversion and AI models not subject to the Act (e.g., those who are not used in the EU) may not necessarily engage in watermarking.
Accordingly, watermarking is a helpful transparency and traceability tool, but not definitive proof of authorship.
Who the obligations fall on
Article 50 of the Act splits the transparency obligations between providers (those who develop and supply AI systems) and deployers (organisations that use them). Many organisations will be both, but AI systems or outputs used exclusively for military, defence, or national security purposes fall outside the scope of the Act.
Providers must:5
- ensure users of systems designed to interact directly with individuals (e.g., chatbots and voice assistants) know they are dealing with an AI system, unless that is already obvious; and
- mark the outputs of systems generating audio, image, video or text so that machines can detect the content as AI-generated or manipulated. For these purposes, marking must be effective, interoperable, robust and reliable, so far as is technically feasible, having regard to the type of content and the cost of implementation (however, this requirement does not apply where the AI system performs only an assistive function or makes only minor alterations to content).
Deployers must:6
- inform individuals who are being exposed to emotion recognition or biometric categorisation systems, and ensure they are handling any personal data in accordance with the GDPR and certain related EU data protection laws in the deployment of those solutions;
- where any image, audio or video content is artificially created or manipulated resulting in a "deep fake", disclose that it has been artificially generated or manipulated (for artistic or similar works, the obligation is limited to disclosing the use of AI-generated or manipulated content in a way that doesn't interfere with the display or enjoyment of the work); and
- disclose AI-generated or AI-manipulated text published to inform the public on matters of public interest, unless the content has been subject to human review or editorial control and a person holds editorial responsibility for the publication.
The information must be provided clearly and upon first interaction with the content or system, and exceptions apply to obligations of both providers and deployers in relation to certain law enforcement activities.
Timing, penalties and the Commission's guidance
Breach of the Act can attract administrative fines of up to the greater of €15 million or three per cent of total worldwide annual turnover.7
The obligations came into effect on 2 August 2026, but providers of generative AI systems already available in the EU prior to that date have until 2 December 2026 to comply with the machine-readable marking and detection requirement.
Content both generated and published before 2 August 2026 need not be marked retrospectively, but content generated before that date and published after it is caught.
The European Commission has issued guidelines on Article 50, as well as the Code of Practice on Transparency of AI-Generated Content.8 The Code is voluntary and has been confirmed as adequate to demonstrate compliance with the marking obligations. If a provider or deployer follows the Code's measures, they can point to that compliance as evidence that they meet the relevant Act transparency obligations. Accordingly, for providers in-scope of the Act, signing is worth consideration.
What New Zealand organisations should do
Three steps:
- Assess reach: The trigger is supply into the EU market or EU-based use of your AI outputs, not where your organisation is based. Consider whether you may be caught.
- Identify your role: Determine whether you are a provider under the Act, a deployer, or both, and determine your obligations under the Act.
- Make it operational: Update AI use policies, publication workflows, customer disclosures and supplier contracts so that any required marking and disclosure actually happens in practice.
If you are in-scope of the Act and relying on an AI vendor's model to generate content, you may also be relying on that vendor's marking to ensure compliance with the Act. In this case, your contracts should allocate responsibility accordingly.
Wider implications for AI detection
Irrespective of whether the Act applies to you directly, if you are using a commercial model in-scope of the Act to provide services to others, you may well already be generating marked content identifiable as AI output. On the other hand, organisations in receipt of content, may now also be able to check whether that content has been developed with the involvement of AI.
Marks are not definitive and should be treated with caution. But New Zealand organisations should decide now on their position regarding disclosure of AI use to clients, and ensure any use complies with local law and client terms, rather than waiting until a mark is detected.
These are among the first AI-specific obligations with practical consequences for a broad range of organisations using generative AI, and the EU standard is likely to influence practice well beyond Europe.
We will continue to monitor developments in the EU and in New Zealand. If you would like to discuss how these requirements apply to your organisation, or to review your AI use policies and supplier or customer arrangements, please get in touch with one of our experts listed below.