IT Governance

Solutions

Watermark Management System

Marking, detection and labelling as a working process - so people can tell when content is machine-made.

Generative systems produce new content every day. Readers, customers and staff need a fair chance to know when what they are looking at was made or altered by a machine. That is the point of transparency rules such as Article 50 of the EU AI Act. Similar expectations are appearing in other markets as well.

A one-off technical setting will not keep up with that. Outputs change. Models change. The record of how content was marked has to move with them.

The Watermark Management System is the working process for that record. It helps providers and deployers mark outputs, label them where people will see them, keep the evidence in one place, and show how the work is maintained over time.

What Article 50 Is Asking For

In the Union, the main transparency duties for generative content sit in Article 50:

  • Providers mark AI-generated outputs in a machine-readable way so they can be detected as artificially generated.
  • Deployers disclose deep fakes and certain AI-generated text published as information for the public.
  • The information is given clearly, at the point of first interaction or exposure.
  • The Code of Practice on transparency of AI-generated content turns those duties into practical commitments and measures.

Organisations outside the EU that place systems on the Union market, or that publish content there, often work to the same pattern. The system is built so that work can be reused if other jurisdictions ask for similar marking and labelling.

What the System Is For

It treats transparency as an ordinary part of how the organisation runs generative systems - not as a separate project that ends when the first watermark is switched on.

For providers

  • A place to plan and record multi-layered marking - metadata and watermarking together where that is the approach
  • A simple structure for detection tools: what is available, who can use them, how results are kept
  • A record of how marking and detection are performing over time
  • Evidence packs that can be handed over when an authority or a customer asks how content is marked

For deployers

  • A record of visible labelling, including use of the EU disclosure icon where that applies
  • Space for human review and editorial policy
  • A trace of when and how disclosure was applied

What You Can Do with It

Keep the decisions in one place. Policies, approvals and evidence for marking and labelling sit in a single record, with versions, so the current picture is easy to find.

Separate provider and deployer work. The two roles are not the same. The system gives each its own path so teams are not filling in the wrong file.

Support the technical layer. Machine-readable marks, signed metadata and imperceptible watermarks can all be documented. Detection results and basic quality checks - whether the mark is effective, reliable, robust and usable across tools - can be kept alongside the method.

Follow the system through its life. Register the system, set the scope, run the marks, watch performance, and keep the trail from obligation to evidence. The same record can sit next to risk, change and post-market work if those already exist.

Produce a pack when asked. Structured evidence can be generated when a market surveillance authority, a customer or an internal audit needs it. Two ways of working are available: a lighter profile that concentrates on showing the transparency work, and a fuller profile that sits inside an existing quality management system.

How It Maps to the Code of Practice

The platform follows the Commitments and Measures in the Code of Practice on Transparency of AI-Generated Content. As that Code and the related guidance move, the record can move with them.

Code area What the system holds
Section 1 - Providers Marking methods, detection tools, quality checks, interoperability notes, cooperation records
Section 2 - Deployers Visible labelling, review policy, internal process, disclosure trail
Measure 4.1 - Compliance process Versioned process, examples, audit trail
Measure 4.2 - Testing and verification Test notes, performance watch, follow-up actions
Measure 4.4 - Authority cooperation Prepared packs and a documented way to respond

How the Work Usually Runs

1. Registration and scope. Record the system and the features that matter for transparency. Decide whether the organisation is acting as provider, deployer, or both. Set what needs to be marked, detected or labelled.

2. Set the record up. Put the methods, policies and internal process on file. Decide how monitoring and evidence will be collected.

3. Operate and watch. Run the marking and detection. Keep an eye on how they perform. Keep the link between the duty, the measure and the evidence.

4. Evidence when it is needed. Produce a signed pack. Answer a request. Show that the work is current.

Who It Helps

Compliance and legal - a single file for marking and labelling, ready when someone asks how disclosure is done.

Product and engineering - a clear place to record the technical method and to see what still needs to be described.

Leadership - a straightforward picture of how the organisation handles AI-generated content.

Start with the lighter profile if you want the transparency record in place first. Move to the integrated profile if the work should sit inside an existing quality management system, with change control and related governance already attached.

Pair It with Runtime Governance

Marking is one half of the picture. Seeing unmarked or altered content in use, and knowing who generated what, sits with the AI Log Analyzer. Both use the same AI system inventory.

If you would like to see how this would sit with your generative systems, we can walk through it.