What an Article 50 audit actually asks for, based on the first enforcement letters

Three market surveillance authorities have started writing to obligated organisations. The letters are shorter than expected and ask for two things: a coverage figure per channel, and the evidence behind one specific published asset.

MVMarijke VisserCompliance research2 September 202612 min read

The first letters went out in the last week of August. They are one page long. That brevity is the interesting part: an authority that asks for everything is easy to satisfy badly, and an authority that asks for two specific things is not.

What follows is a reading of three letters, shared with us by the organisations that received them, with identifying detail removed at their request. None of this is legal advice, and none of it is a promise about how any particular authority will behave next.

1 · A coverage figure, per channel, per month

Every letter asked for the same first item: the share of AI-generated output that carried a machine-readable mark, broken down by publication channel and by calendar month. Not an average across the organisation. Per channel.

This is harder than it sounds for a simple reason. Most organisations know what their generator produced. Fewer know what their channels published. The gap between those two numbers is where every uncomfortable conversation lives: the social scheduler that strips metadata, the partner feed that re-encodes, the intern who exported a screenshot.

The number they want is not a compliance score. It is a starting point for asking what happened to the missing percent.

An answer of 100% invites more scrutiny than an answer of 94% with a named list of exceptions. One of the three organisations reported 99.8% and was asked to substantiate it; the one that reported 91% with a breakdown by cause was not.

2 · The evidence behind one specific asset

The second item was a URL. One published asset, chosen by the authority, with a request for the provenance record behind it: who signed it, when, with what identity, and what the signature covers.

This is where a ledger stops being an engineering nicety. If your answer is a screenshot of an internal dashboard, you are asking the authority to trust your dashboard. If your answer is a signed manifest plus a ledger entry with a checkpoint that predates the request, you are not asking them to trust anything.

WHAT A COMPLETE ANSWER CONTAINED
  • The C2PA manifest as published, not as generated
  • The signing identity and which trust anchor it resolves to
  • The ledger entry, its sequence number and its checkpoint
  • The watermark detection result, with its confidence value

3 · What was not asked for

No letter asked about model cards, training data or internal AI governance policy. No letter asked for a vendor certification. Two of the three explicitly noted that a self-signed provenance record would be considered, though not as strong evidence.

That last point matters if you are waiting for a qualified provider before you start. Starting with a C2PA trust list identity and upgrading later leaves a coherent trail. Starting with nothing leaves a gap that cannot be filled retroactively.

4 · What to do this month

Measure what your channels actually publish, not what your generator produces. Write down the exceptions with a cause. Then make sure that for any single asset you can produce the four items above without asking a colleague to check something.

If that takes more than an afternoon, the problem is not the regulation.

Provena produces those four items for every asset it signs, per channel and per period.Start free
Article 50EnforcementAuditCoverage
KEEP READINGAll posts