{
  "$schema": "./schema.json",
  "id": "eu-transparency-code",
  "name": {
    "en": "EU Code of Practice on Transparency of AI-Generated Content — AIO formalization",
    "ko": "EU AI 생성 콘텐츠 투명성 실행규약 — AIO 정형화"
  },
  "sourceNorm": {
    "title": "Code of Practice on Transparency of AI-Generated Content — Section 1 (providers of generative AI systems: marking and detection, Article 50(2) and (5) AI Act) and Section 2 (deployers: labelling of deep fakes and AI-generated or manipulated published text, Article 50(4) and (5) AI Act)",
    "publisher": "European Commission — AI Office (drawn up by independent experts chairing two working groups in a multi-stakeholder process; the Commission and the AI Board assessed its adequacy)",
    "version": "Published 10 June 2026; two sections, eight Commitments; Commission opinion on adequacy 8 July 2026 and AI Board adequacy assessment 9 July 2026; unamended as at 14 August 2026",
    "url": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content"
  },
  "vesMapping": [
    {
      "article": "Section 1 (Providers), Commitment 1 · Measure 1.1 (with Sub-measures 1.1.1 and 1.1.2)",
      "summary": "Signatories must implement a marking solution built from at least one machine-readable marking technique which, together with the corresponding detection mechanism, reaches the level of effectiveness, reliability, robustness and interoperability required by Article 50(2) AI Act, and — for as long as no single technique can meet all four requirements — must mark outputs with at least two layers, digitally signed and time-stamped metadata under Sub-measure 1.1.1 and an imperceptible watermark under Sub-measure 1.1.2, with a single layer accepted only for generative systems embedded in closed physical products and for free-form text.",
      "v": [
        "Cor"
      ],
      "e": [
        "Gui",
        "Dat"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "Whether a marking pipeline exists, how many layers it applies and whether the signing keys are handled securely are properties of a build, not of a judgment in a concrete case; no AIO item observes any of them. The Measure expressly allows the marking technique to be implemented upstream at model level or bought from a third party without displacing the Signatory's own responsibility, so a measurement against this entry says nothing about who built the marking. `Dat` is an INFERENCE from the Measure's cross-reference to Commitment 3 rather than from its own words and is carried to the RFC round on that point. The 200-token free-form-text threshold and the closed-product exception in Sub-measure 1.1.2 and Measure 1.1 are engineering scope conditions, not normative directions, and the pack does not code them.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 1, Commitment 1, Measure 1.1, first and second paragraphs",
        "quote": "Signatories will implement a marking solution that consists of at least one machine-readable marking technique […] meets the level of effectiveness, reliability, robustness, and interoperability required by Article 50(2) AI Act and Commitment 3 of the Code. […] Signatories will implement a multi-layered marking approach to ensure that the outputs of their generative AI systems are marked with at least two layers of machine-readable marking […]",
        "rationale": "The operative demand is conformity with a requirement set stated elsewhere and reproduced as a yardstick — 'required by Article 50(2) AI Act and Commitment 3 of the Code' — which is `Cor` read directly off the text. No protected interest is named anywhere in the quoted paragraphs: the recitals of this Section speak of trust in the information ecosystem, but the methodology codes the provision and not the preamble, so `Ses` is not declared here. What discharges the duty in the first instance is a written specification read as issued — the Code's own enumeration of marking techniques and the two-layer rule (`Gui`). `Dat` is declared because the four quality requirements the excerpt names are settled by the measurement regime of Commitment 3 (error rates, accuracy across content length and semantics); the excerpt names Commitment 3 but not the metrics, so this code follows from the provision's structure rather than its words and is flagged INFERENCE. Two source classes are designated. `Gov`: Article 50(2) AI Act is named as the instrument decisive on the substance of the requirement. `Ind`: the Signatory is the party that implements the marking solution and, under Sub-measure 1.1.1, records and signs the metadata. `Pro` is not declared even though marking techniques are standardisation-heavy — this Measure names no standardisation body, in contrast with Measure 3.4 where interoperability standards are discussed and with the GPAI Code's copyright Measure 1.3 where the IETF is named expressly.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 1 (Providers), Measure 1.2, points (a) and (b)",
      "summary": "Signatories must make best efforts to preserve metadata markings: they must retain, and abstain from intentionally altering or removing, existing metadata markings on content used as input and transformed by their AI system — save for good-faith legitimate processing such as security audits and research — and must include in their acceptable use policy, terms and conditions or accompanying documentation a prohibition on the intentional removal of or tampering with metadata markings by deployers or any third party, with an alert in the documentation sufficing for free and open-source releases.",
      "v": [
        "Bed",
        "Cor"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The behavioral limb an item can reach is the exception judgment: whether a particular transformation of incoming metadata is 'good faith, legitimate processing […] necessary to maintain accurate and functional information' or is the intentional stripping the point forbids. The acceptable-use-policy clause and the documentation for open-source releases are organisational artefacts that no item observes. The Measure itself is explicit that point (a) does not make the Signatory responsible for third-party metadata markings or for third parties' compliance with point (b), so nothing here reaches the downstream chain. `Pro` was considered and withheld: 'recognisable as per open standards' names a class of specification but no standardisation body, which is the distinction that earned `Pro` in the GPAI Code's copyright Measure 1.3 and that fails here.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 1, Measure 1.2, points (a) and (b)",
        "quote": "[point a)] Signatories will, to the extent technically feasible and recognisable as per open standards, retain, and abstain from intentionally altering or removing, existing metadata markings, where such content is used as input and subsequently transformed by their AI system into an output. This does not affect good faith, legitimate processing […] [point b)] […] include in the acceptable use policy, terms and conditions or the documentation accompanying their generative AI system a prohibition of the intentional removal of or tampering with metadata markings […]",
        "rationale": "Point (a) asks the Signatory to leave alone a marking that someone else placed and that it is technically able to strip; that is the dependability of a party in a chain that cannot police it (`Bed`), and the same reading was taken for the honouring of rightsholder reservations in the GPAI Code's copyright Measure 1.3. The marking is recognised through a convention external to the Signatory — 'recognisable as per open standards' — and point (b) turns that convention into a stated prohibition, which is rule-conformity in the strict sense (`Cor`). What discharges both points is a document read as written: the open standard that defines what a metadata marking is, and the acceptable use policy or terms and conditions that carry the prohibition (`Gui`). No metric decides either point, so `Dat` is not declared. The only source class the excerpt designates is the Signatory itself as the unilateral author of the acceptable use policy, terms and conditions and accompanying documentation (`Ind`). `Gov` is not declared: neither point cites a legal instrument, and the fact that this Section operates under Article 50(2) AI Act is not carried into an excerpt that does not name it.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 1 (Providers), Measure 1.2, final prohibition",
      "summary": "Signatories must not place or make available on the market, nor promote or advertise the use of, tools whose purpose is to circumvent the machine-readable markings added to AI-generated or manipulated content for transparency.",
      "v": [
        "Ses"
      ],
      "e": [],
      "s": [],
      "status": "draft-unverified",
      "obligationType": "behavioral",
      "note": "The sharpest judgment correlate in this pack, and the closest analogue anywhere in the AIO catalogue to Article 10, second paragraph of the Chinese labelling Measures (pack `cn-ai-labelling`), which forbids providing tools that remove or forge labels. It is a bare prohibition: nothing is documented, logged or built to discharge it. What an item can test is whether help with defeating a transparency marking is refused, and whether the refusal survives a framing in which the removal is presented as a routine technical favour. What no item reaches is the corporate limb — whether a Signatory has in fact withdrawn such a product from its catalogue or stopped advertising it. Both layers other than value are left undeclared: the excerpt designates no evidence class that settles when a tool's 'purpose' is circumvention, and no source class at all. The evidence gap is the same one recorded for intent-based prohibitions in the `tx-traiga` pack.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 1, Measure 1.2, penultimate paragraph",
        "quote": "Furthermore, Signatories will neither place or make available on the market, nor promote or advertise the use of tools whose purpose is to circumvent the machine-readable markings added to the AI-generated or manipulated content for transparency.",
        "rationale": "The prohibition protects the marking regime itself rather than any identified person: what a circumvented marking costs is the reliability of the shared environment in which content is read, which is collective order and infrastructure (`Ses`). That reading is structural — the excerpt names 'transparency' as the purpose of the markings but names no protected interest in terms — so `Ses` is flagged INFERENCE and carried to the RFC round; the parallel provision in the Chinese labelling pack was coded the same way and for the same reason. `Cor` was considered and rejected as vacuous: every provision in a code of practice is a rule its adherents follow, and declaring `Cor` wherever a duty is stated would drain the code of discriminating power. The evidence layer is left empty because the excerpt prescribes no test, metric, adjudicator or documentary standard for the 'purpose' of a tool; an undeclared layer is a scoring exclusion and is the honest signal. The source layer is left empty for the same reason: no authority, instrument or issuer is named anywhere in the sentence.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 1 (Providers), Commitment 2 · Measure 2.1 (with Sub-measures 2.1.1 and 2.1.2)",
      "summary": "Signatories must make available a detection solution — a public specification, a piece of software, or a cloud service reachable from the Union — that lets deployers, users, third-party integrators, end-users exposed to the content and other legitimate parties verify whether content came from their AI system; the solution must be free of charge, with a narrow fee exception for Signatories under 1,000,000 monthly users whose solution incurs substantial operational costs and only above a reasonable request volume, and free and volume-unrestricted at all times for market surveillance and other authorities, law enforcement, media, fact-checkers, trusted flaggers, independent researchers, educational and research institutions and civil society organisations; access must fit the audience that may be exposed to the content, may be restricted only where effective safeguards limit exposure, and detection of free-form-text watermarks may be confined to verified expert users for as long as reliability is low.",
      "v": [
        "Sdt",
        "Unc"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "Standing up and operating a detection service is organisational. The judgment correlate an item can reach is the access decision: whether a requester falls within the classes that must always have free, unrestricted access, whether a restriction is genuinely justified by safeguards against wider exposure, and whether a restriction on free-form-text detection is being kept 'limited in time' as the Sub-measure requires or has quietly become permanent. The always-free list is a striking feature of the Code — it names fact-checkers, trusted flaggers, independent researchers and civil society organisations as parties whose access may not be priced — and none of those classes has a home in the AIO source vocabulary, which is recorded as a vocabulary-gap candidate rather than forced into `Pro` or `New`.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 1, Commitment 2, Measure 2.1, first paragraph, and Sub-measure 2.1.1",
        "quote": "[Measure 2.1] Signatories will make available a detection solution, composed of one or more detection mechanisms, to enable deployers, users of their generative AI system, third-party integrators, end-users exposed to the content, and other legitimate parties (such as competent authorities, independent researchers, civil society and media organisations) to verify whether content has been generated or manipulated by their AI system […] [Sub-measure 2.1.1] Signatories will make the detection solution available free of charge.",
        "rationale": "The purpose clause is the coding: the solution exists 'to enable […] to verify', which puts the means of reaching a conclusion in the hands of the person exposed rather than asking them to accept the provider's word (`Sdt`). Free-of-charge availability extended to end-users, civil society and researchers alike, and — in the sentence the summary records — to authorities, media and fact-checkers without volume limits, is protection distributed to whoever is affected rather than to a defined customer class (`Unc`). What is decisive on the question the solution answers is the detector's output, a machine measurement carrying an error rate (`Dat`), and one of the three permitted forms of the solution is 'a public, ideally standardised, specification', a written specification read as issued (`Gui`). On sources, only `Ind` is declared: the Signatory builds and operates the detection solution. `Gov` is deliberately withheld even though competent authorities are named twice — in this Measure they are beneficiaries of access, and under the convention settled in Wave 2 and extended in Wave 3 a party named as recipient or beneficiary does not thereby become a source whose position is trusted. `Pro` is withheld for the same reason: independent researchers, fact-checkers and trusted flaggers appear as parties who must be let in, not as authorities the provision defers to.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 1 (Providers), Measure 2.3",
      "summary": "Signatories must present detection results in a way that is clear and easily comprehensible to the natural persons exposed to the content who want to verify its origin, must indicate whether a result rests on a metadata marking, a watermark, forensic detection or another technique so far as technically feasible, must incorporate additional information carried in the marking, and must make the human interfaces that present results accessible to persons with disabilities in compliance with Union accessibility law, in particular Directive (EU) 2019/882 and Directive (EU) 2016/2102.",
      "v": [
        "Sdt",
        "Hum",
        "Unc"
      ],
      "e": [
        "Dat",
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "This is the Article 50(5) limb of Section 1 and the entry with the most direct judgment correlate on the provider side: what to say to a person who has just run a detection, how much confidence to attach to it, and whether to disclose that the answer rests on a technique the Code itself describes as less reliable. Building an accessible interface is organisational and no item observes it. The Measure's tiered-access advice — avoid overwhelming a lay end-user with detailed results — is framed as encouragement and is therefore not coded, but it is the sentence an item writer should read first. ETSI EN 301 549 and WCAG 2.1 are named in the Measure, but only inside an 'encouraged' sentence, so no source class is declared for the bodies behind them; under the Code's own reading of its modal verbs, 'encouraged' marks a measure that is not legally required.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 1, Measure 2.3, first, second and fourth paragraphs",
        "quote": "Signatories will ensure that the detection results provided by their detection solution are presented in a way that is clear and easily comprehensible to natural persons exposed to the content […] and who want to verify its origin. Signatories will ensure that detection results indicate whether they are based on a metadata marking, a watermark marking, forensic detection or other techniques, to the extent technically feasible. […] Signatories will ensure that human interfaces used to present detection results are accessible to persons with disabilities in compliance with applicable accessibility requirements under Union law, in particular those laid down in Directive (EU) 2019/882 […]",
        "rationale": "The addressee of the whole Measure is the person who 'want[s] to verify its origin', and what is owed to that person is a result they can understand and act on themselves (`Sdt`). The second sentence is the unusual one: the result must carry the class of evidence it rests on, which is a requirement to state the basis and therefore the limits of one's own claim — the same structure that earned `Hum` at Measure 7.2 of the GPAI Code, and here it is reinforced by the Measure's own caution that detailed results can confuse a lay reader (`Hum`). Extending comprehensibility to persons with disabilities under named accessibility law is protection stated for everyone exposed, not for a defined customer group (`Unc`). What is decisive is the detection output itself, a measured signal (`Dat`), presented in conformity with accessibility requirements read as written (`Gui`). Two source classes are designated: Directive (EU) 2019/882 and Directive (EU) 2016/2102 are named as the instruments decisive on the accessibility limb (`Gov`), and the Signatory composes and presents the result (`Ind`). `Pro` is withheld — ETSI and W3C appear only in the Measure's 'encouraged' sentence, which the Code defines as not legally required.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 2 (Deployers), Commitment 1 · Measure 1.1",
      "summary": "Deployer Signatories must ensure consistent and effective disclosure of the artificial origin of deep fakes and of AI-generated or manipulated text published on matters of public interest, implemented through the EU icon in Annex 1 of the Code or through an equivalent icon or label meeting the Code's design and placement specifications; the design specifications require the capitalised acronym 'AI' as the main visual element where visual disclosure is possible and a short audible disclaimer at the beginning of the content where it is not, and require the Signatory to take account of the diversity of the exposed audience — including AI and digital literacy, language proficiency, and vulnerable categories such as children and the elderly — and of the sensitivity of the context.",
      "v": [
        "Sdt",
        "Unc"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The behavioral limb is the disclosure judgment on a concrete piece of content: whether this output is a deep fake or published text within Article 50(4) at all, and whether the label as placed is in fact clear and distinguishable to the audience that will see it. The organisational limb sits next door in Measure 2.1, which is not mapped in this pack and is covered in the management-system guide. The Code is explicit that labelling does not exempt a deployer from other Union or Member State law, including consent of depicted persons and rightsholders; a measurement against this entry bears on none of that. The EU icon in Annex 1 is referred to by name only; the pack does not reproduce it, and the Code states that the icons may be used without attribution to the Commission or the AI Office.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 2, Commitment 1, first and second paragraphs, and Measure 1.1, penultimate paragraph of the design specifications",
        "quote": "[Commitment 1] To fulfil their obligations under Article 50(4) and (5) AI Act, Signatories commit to ensure consistent and effective disclosure of the artificial origin of deep fakes or published text. Signatories commit to implement such disclosure through the available EU icon provided in Annex 1 of the Code or through an equivalent icon or label that complies with the design and placement specifications […] [Measure 1.1] When applying the design specifications of this measure, Signatories will consider the potentially diverse composition of the audience exposed to the content (including diverging levels of AI and digital literacy […] and vulnerable user categories such as children and the elderly) […]",
        "rationale": "Disclosure of artificial origin exists so that the person exposed can weigh what they are looking at for themselves; the Section's own objective clause frames it as informing decision-making rather than vouching for the content, and the operative commitment is to make that origin legible (`Sdt`). The design paragraph extends the standard to the whole audience and names vulnerable categories expressly, which is equal protection stated in the text rather than inferred (`Unc`). What discharges the commitment is a prescribed visual form — the Annex icon or an equivalent meeting written design and placement specifications — which is `Gui` in its strict sense; nothing measured or argued is decisive. Two source classes are designated. `Gov`: Article 50(4) and (5) AI Act are named as the obligations the commitment fulfils and are decisive on what must be disclosed. `Ind`: where the Signatory does not take the EU icon it authors its own equivalent label, which makes it the author of the operative artefact. The fact that the icon is supplied by the AI Office inside this very Code is not carried into the source axis — a self-reference by the instrument being formalized does not earn `Gov`, which is the rule settled on the `tx-traiga` pack.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 2 (Deployers), Measure 1.2 (with Sub-measures 1.2.1 and 1.2.2)",
      "summary": "Deployer Signatories must place the icon or equivalent label so that it is recognised immediately without user interaction or sustained attention, remains visible long enough to be noticed, is embedded in the content unless an equivalent alternative such as an interface overlay is used, and is clearly perceivable and distinguishable at the latest at the time of first exposure; for video the label must appear at the beginning and, where possible, at intervals and after interruptions; for published text it goes above or near the headline or in the colophon, with a contextual notice permitted for very short outputs; where visual disclosure is impossible an audible disclaimer is required at the latest at first exposure, supplemented at intervals for long-form or live audio.",
      "v": [
        "Sdt",
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "Placement is where a labelling regime is usually defeated in practice, and the Measure legislates against the two common defeats: a label that requires the reader to go looking for it, and a label that survives only in the original upload. The judgment correlate is per item of content — where does this label go so that this audience sees it before it matters — and it is testable. What no item reaches is whether the deployer's publishing pipeline actually applies the placement rule at scale, or whether downstream platforms preserve it; the Measure itself only encourages cooperation with distributors on that point, and encouragement is not a duty under the Code's own reading of its modal verbs.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 2, Measure 1.2, chapeau, and Sub-measure 1.2.1, points (a) and (d)",
        "quote": "[Measure 1.2] To meet the legal requirements of labelling in a clear and distinguishable manner at the latest at the time of first exposure under Article 50(5) AI Act […] Signatories will apply the placement specifications described in this measure. […] [Sub-measure 1.2.1] a) Considering the content format and dissemination context, the icon or equivalent label will be placed in an appropriate and perceivable manner that ensures immediate recognition by natural persons without requiring user (inter)action or sustained attention.",
        "rationale": "Point (a) is written from the position of the person who will encounter the content: recognition must be immediate and must not depend on the reader doing anything, which protects that person's capacity to judge what they are seeing before they act on it (`Sdt`). The chapeau fixes the moment at which the duty falls due — labelling in a clear and distinguishable manner at the latest at the time of first exposure — which makes it an obligation owed to an identified counterparty against a deadline (`Bed`); the same structure was coded `Bed` at Measure 1.2 of the GPAI Code, and Sub-measure 1.2.1, point (d) repeats the timing requirement for the label itself. What discharges the duty is the Code's written placement specification applied to the content format at hand (`Gui`). Two source classes are designated: Article 50(5) AI Act, named in the chapeau as the legal requirement decisive on the manner and timing of labelling (`Gov`), and the Signatory, which performs the placement determination for each item of content (`Ind`). No professional or standards body is named anywhere in the Measure, so `Pro` is not declared.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 2 (Deployers), Commitment 2 · Measure 2.3",
      "summary": "Deployer Signatories must support the implementation of the design and placement specifications through internal review and external feedback, must review cases reported in a substantiated manner as mislabelled or incorrectly labelled and take measures to remedy non-compliance with Article 50(4) and (5) without undue delay, and must cooperate with competent authorities in accordance with applicable Union and national law; providing flagging channels for individuals and third parties such as trusted flaggers, researchers, academics and fact-checkers is encouraged rather than required.",
      "v": [
        "Bed",
        "Cor"
      ],
      "e": [
        "Cas"
      ],
      "s": [
        "Gov"
      ],
      "status": "draft-unverified",
      "obligationType": "mixed",
      "note": "The behavioral limb is the disposal judgment on a single report: whether the report is 'substantiated', whether the label really is missing or wrong, and what 'without undue delay' means for this piece of content in this distribution context. The intake channel, the internal review function and the record of what was fixed are organisational and are covered in the management-system guide. Note the asymmetry the Code chose: reviewing and remedying a substantiated report is a duty, but providing the channel through which anyone could report is only encouraged — an operator that runs no flagging channel at all can still be within the letter of this Measure. `Ind` is not declared: the Signatory here corrects its own earlier output rather than authoring anything that governs the question.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 2, Commitment 2, Measure 2.3, first and last paragraphs",
        "quote": "Signatories will support the effective implementation of the design and placement specifications through internal review and external feedback. […] Signatories will review cases that have been reported in a substantiated manner as mislabelled or incorrectly labelled and take measures to remedy cases of non-compliance with Article 50(4) and (5) without undue delay. Signatories will cooperate with competent authorities in accordance with applicable Union and national laws (e.g., national market surveillance authorities).",
        "rationale": "Acting on a report from outside, promptly, and putting right what was wrong is the conduct of a party that can be relied on by those affected by its content (`Bed`); the remedy is defined by reference to 'non-compliance with Article 50(4) and (5)', which makes conformity with a stated rule the operative standard (`Cor`). The unit of decision is the individual reported case, examined against comparable ones — a structured look at particular instances rather than a metric or a guideline (`Cas`); `Tri` was considered for the reporter's account and withheld, because the Measure does not require the reporter to be someone who was themselves exposed, and the classes of reporter it names appear only in an 'encouraged' sentence. `Gov` is declared on the strength of 'applicable Union and national laws', which the excerpt names as decisive on the cooperation duty; the market surveillance authorities themselves appear as the counterparty to that cooperation, and being a counterparty or a recipient would not on its own have earned the code.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 2 (Deployers), Commitment 3",
      "summary": "Where a deep fake forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, deployer Signatories must disclose it in a way that does not hamper the display or enjoyment of the work, including its normal exploitation and use, and that maintains the work's utility and quality: using an icon or equivalent label following the Measure 1.1 design specifications, placed appropriately to the type of work and the context in which it is presented, clear, distinguishable and accessible to all natural persons at the latest at first exposure, and perceivable long enough to be noticed — with adjacent or interface-level placement permitted for digital and interactive presentation and point-of-entry, ticket or packaging disclosure for exhibitions, cinemas and physical carriers.",
      "v": [
        "Sdt",
        "Unc",
        "Hed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "behavioral",
      "note": "The only entry in this pack whose entire demand is discharged by a decision about one concrete piece of content: is this work evidently artistic, creative, satirical, fictional or analogous, and where does the disclosure go so that the audience is informed without the work being spoiled. Commitment 3 requires no document, process, channel or infrastructure of any kind. It is also the entry where the Code asks for a trade-off rather than a rule, which makes it the first candidate for item-bank authoring and the one where item writers must test both directions of error — a label so discreet it is not a disclosure, and a label so intrusive that the exception in Article 50(4), third sentence, is defeated. `Hed` is an unusual code and is flagged for the RFC round; the value the provision protects on the other side of the trade-off — artistic and creative expression as such — has no carrier in the AIO value vocabulary at all, which is recorded as a vocabulary-gap candidate.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 2, Commitment 3, first paragraph and point (b)",
        "quote": "In accordance with Article 50(4) AI Act, Signatories commit to implement measures to disclose deep fakes that form part of evidently artistic, creative, satirical, fictional or analogous work or programmes in a way that does not hamper the display or enjoyment of the work […] while maintaining the utility and quality of the work. […] ensure such disclosure and placement are clear, distinguishable, and accessible to all natural persons, and provided at the latest at the time of first exposure to the content containing the deep fake […]",
        "rationale": "Two interests are named in the same sentence and the provision requires both to survive. The disclosure limb informs the person exposed so that they can place what they are seeing (`Sdt`), and point (b) extends that to 'all natural persons' with accessibility stated in terms (`Unc`). The limiting interest is named in the text as the 'enjoyment of the work', which in the AIO value vocabulary is pleasure and gratification in the experience itself (`Hed`); the code is declared because the provision expects that interest to prevail against a disclosure design that would override it, not because enjoyment outranks disclosure. This is the first appearance of `Hed` in any AIO pack and it is flagged for the RFC round, together with the observation that the neighbouring interest the sentence also protects — the integrity and normal exploitation of a creative work — has no code available at all. What discharges the duty is the written design specification of Measure 1.1 applied to the type of work (`Gui`). `Gov` is declared because the first words of the Commitment name Article 50(4) AI Act, whose third sentence is the substantive source of the artistic-works regime; `Ind` because the placement appropriate to the work is the Signatory's own determination.",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    },
    {
      "article": "Section 2 (Deployers), Commitment 4",
      "summary": "Media service providers within the meaning of Article 2(2) of Regulation (EU) 2024/1083 that are already subject to editorial standards may rely on their existing review and editorial procedures for the Article 50(4), second subparagraph exception; every other Signatory must establish, adapt or maintain policies for human review or editorial control before publication and ensure that a natural or legal person holds editorial responsibility, the policy identifying that person by name, role and contact details and giving an overview of the organisational measures and human resources allocated, with those contact details published where they are not already public — while individual instances of review need not be documented, and media freedom, editorial independence and the protection of journalistic source information are unaffected.",
      "v": [
        "Bed"
      ],
      "e": [
        "Gui"
      ],
      "s": [
        "Gov",
        "Ind"
      ],
      "status": "draft-unverified",
      "obligationType": "organizational",
      "note": "A policy, a named accountable person and a published contact point: nothing here is discharged by a judgment in a concrete case, and the Commitment says in terms that individual instances of human review need not be documented. The provision that matters most to an operator is the one it points at rather than states — Article 50(4), second subparagraph, under which AI-generated published text that has undergone human review and editorial control, with a person holding editorial responsibility, falls outside the disclosure duty altogether. Whether a given review was real enough to carry that exception is exactly the judgment this Commitment declines to specify. The closing sentence preserves media freedom, editorial independence and journalistic source protection against the Commitment itself; that pattern — an interest expressly preserved against the obligation — has now been recorded in four packs and remains without a home in the value vocabulary.",
      "provenance": {
        "sourceUrl": "https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content",
        "retrievalUrl": "https://ec.europa.eu/newsroom/dae/redirection/document/129555",
        "article": "Section 2, Commitment 4, second paragraph, point (a), and closing sentence",
        "quote": "All other Signatories, including those without such review or editorial procedures, commit to establish, adapt, or maintain appropriate policies for human review or editorial control prior to publication and that a natural or legal person holds editorial responsibility for the publication. […] The identification of the natural or legal person with editorial responsibility (name, role and contact details); […] The implementation of this Commitment shall in no way affect media freedom, editorial independence and protection of journalistic source information.",
        "rationale": "The point of the Commitment is that somebody answers for what was published: a named person holds editorial responsibility and their contact details are published 'to ensure accountability', which is dependability in the strict sense — being the member of the chain that can be held to what it put out (`Bed`). No other interest is named on the operative side; `Ses` was considered for the integrity of public information and rejected as belonging to the Section's recitals rather than to this Commitment. What discharges the duty is a written internal policy containing a prescribed list of elements (`Gui`); the Commitment expressly declines to require per-instance records, so no case-based or documentary evidence about individual publications is decisive. Two source classes are designated: Article 50(4), second subparagraph AI Act and Regulation (EU) 2024/1083, which between them decide who may rely on existing editorial procedures (`Gov`), and the Signatory, which authors the policy and designates the responsible person (`Ind`).",
        "retrievedAt": "2026-08-14",
        "verifiedBy": "seed formalization (single pass; dual verification pending)"
      }
    }
  ],
  "itemBankRef": {
    "publicSet": null,
    "privateSet": null
  },
  "version": "0.1",
  "status": "draft-unverified",
  "updatedAt": "2026-08-14",
  "measurementScope": "AIO items measure model judgment alignment with the normative direction of each mapped Commitment or Measure — for example whether a request to defeat a transparency marking is refused, whether a detection result is reported with the basis and the confidence it actually carries, and whether an AI-generated satirical work is disclosed without the disclosure being made unfindable. They do not assess whether a provider has built a marking pipeline, operates a detection service, tested it against the Code's quality requirements or implemented an interoperability solution; nor whether a deployer has an internal compliance process, an awareness programme, a flagging channel or an editorial-responsibility policy. Those are management-system duties that no item-based measurement observes. Nothing in a measurement against this pack bears on whether an organisation has signed the Code, adheres to it, or complies with Article 50 of Regulation (EU) 2024/1689; AIO is not a party to the Code and has no role in the Commission's or the AI Board's assessment of it.",
  "notes": [
    "draft-unverified, and it stays there until a second independent formalization is run. Every entry carries a verbatim excerpt of the official text and a rationale argued from it, but this is a single seed pass (execution plan §5.3.5.5): agreement between two independent passes is what makes a formalization evidence, and there has been only one. Human review is also pending. Certificates issued against this pack, if any, carry a draft-basis notice.",
    "Primary source and quote verification method. The Code was downloaded on 2026-08-14 as a single 38-page PDF from the European Commission newsroom endpoint linked from its official landing page — https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content, document https://ec.europa.eu/newsroom/dae/redirection/document/129555, 1,213,943 bytes, PDF creation timestamp 2026-06-10. Three independent text extractions were made locally — poppler `pdftotext` in raw mode, poppler `pdftotext -layout`, and pypdf — and every quoted fragment was checked as a substring of all three. Thirty fragments were checked — the twenty-five that make up the ten `provenance.quote` fields, plus five sentences quoted in these notes for the status and scope statements: 30/30 matched in both poppler extractions under whitespace-and-punctuation normalisation, and 30/30 matched in the pypdf extraction, of which 25 matched with whitespace collapsed to single spaces and 5 required whitespace to be removed entirely. The six are an extraction artefact and not a textual difference: pypdf inserts a space at a line-break hyphenation ('multi- layered') and at a page boundary. Two further normalisations are recorded because they were necessary and because they cut in opposite directions. (a) Punctuation: pypdf preserves the document's curly quotation marks and en dashes, poppler renders them as backticks, straight apostrophes or replacement characters; the quotes in this pack are stored in the pypdf reading, which is the one that matches the PDF's own character stream. (b) Pagination: lines consisting only of a page number were removed from the corpora before matching, because a page number that falls in the middle of a sentence is not part of the sentence. No commentary, summary, mirror or law-firm note was used as a source for any quote. Where a quote spans more than one paragraph or Measure, a bracketed citation such as [Measure 1.1] precedes the excerpt; everything outside brackets is verbatim. Quote length: the ten excerpts total 5,358 characters, average 536 and longest 713, which is above the 400-character convention. The reason is structural rather than careless — a Measure in this Code typically states the duty in one paragraph and the condition that makes it operative in another, and cutting the second limb would misstate the first. The convention exists to keep licence exposure low, and here the Commission's reuse policy places the text under CC BY 4.0, so the constraint that binds is accuracy rather than length. Every excerpt is nonetheless confined to the operative sentences of the Measure it cites; no recital, glossary entry, annex or example is quoted anywhere in this pack.",
    "Legal status — stated precisely, and not more strongly than the instruments allow. The Code is voluntary to sign, and the obligations it implements are not. Article 50(2), (4) and (5) of Regulation (EU) 2024/1689 apply from 2 August 2026 to providers and deployers within their scope whether or not those parties have signed. The Code's own objective clauses put its status in the same terms in both Sections: it serves 'as a guiding document for demonstrating compliance with the obligations provided for in Article 50(2) and (5) AI Act, while recognising that adherence to the Code does not constitute conclusive evidence of compliance with these obligations'. Section 2 repeats the formula for Article 50(4) and (5). Adherence is therefore a route to demonstrating compliance that competent market surveillance authorities can assess consistently; it is not a presumption of conformity, which Regulation (EU) 2024/1689 reserves to harmonised standards, and the Code says so of itself. The Code also fixes its own modal vocabulary, which this pack follows: 'will' marks a mandatory measure that must be met to be compliant with the cited Article 50 paragraphs and whose compliance market surveillance authorities will monitor; 'encouraged' and 'may' mark measures that are 'not legally required and are purely voluntary'. No provision drawn from an 'encouraged' or 'may' sentence is coded in this pack, and where such a sentence was the only textual hook for a code, the code was withheld and the fact recorded in the entry.",
    "Currency, and the amendment that did not happen. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (the Digital Omnibus on AI), was verified against the Official Journal text on 2026-08-14 through the EU Publications Office Cellar (celex 32026R1744, expression manifestation L_202601744.ENG.xhtml, retrieved via publications.europa.eu because eur-lex.europa.eu answered the direct request with a bot-mitigation challenge). Three findings matter here. (1) The application date of Article 50 was NOT moved: the Omnibus amends Article 113, third paragraph, points (a) and (c) and adds a point (d), deferring the high-risk regime of Chapter III, Sections 1–3 to 2 December 2027 and 2 August 2028 and bringing Articles 102 to 110 forward to 27 July 2026, but it leaves Chapter IV, in which Article 50 sits, on the Regulation's general date of 2 August 2026. (2) The substantive transparency duties in Article 50(2), (4) and (5) were not amended at all; the only change to Article 50 replaces paragraph 7, removing the requirement that a code of practice for these obligations be approved by an implementing act and leaving the Commission to assess adequacy in accordance with the Article 56(6) procedure, with an implementing act reserved for the case where a code is deemed inadequate. The Omnibus recital states the reason in terms — codes of practice under Article 50(7) 'have limited legal effect, and in particular do not grant a presumption of conformity'. (3) A four-month transitional was added as a new Article 111(4): providers of AI systems generating synthetic audio, image, video or text content 'that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026'. That carve-out is about legacy systems and about paragraph (2) only; it does not touch the deployer duties in Article 50(4) that Section 2 of the Code implements. The Omnibus entered into force on the third day following its publication in the Official Journal.",
    "Publication, adequacy and signatory context, as verified on 2026-08-14 against the Commission's own pages. The Code was published on 10 June 2026 in two Sections. The Commission concluded on 8 July 2026 that the Code adequately covers the obligations provided for in Article 50(2), (4) and (5) AI Act and facilitates their effective implementation, and the AI Board adopted its adequacy assessment on 9 July 2026. Signing is by Section: the Commission's news item of 31 July 2026 records about 190 organisations signed in total, 82 to Section 1 and 152 to Section 2 — the two figures exceed the total because an organisation may sign both — and names Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia among Section 1 signatories and Bulgari, Fastweb, Getty Images, Iberdrola, Lenovo and Lufthansa among Section 2 signatories. The list is updated on an ongoing basis; anyone relying on it should re-check the Commission page rather than this note. Non-signature is not non-compliance: the obligations bind irrespective of adherence, and a party that does not sign must demonstrate compliance by other adequate means. This pack takes no position on whether any signatory in fact implements the Code, and being named above is not evidence that it does.",
    "Do not confuse the Code with the Commission's Article 50 guidelines. A separate instrument — the Commission's Guidelines on transparency obligations for providers and deployers of certain AI systems, whose Commission page was last updated 6 August 2026 — interprets Article 50 as a whole, including the paragraphs this Code does not touch (Article 50(1) on AI interaction disclosure and Article 50(3) on emotion recognition and biometric categorisation). The guidelines are not formalized in this pack, are not quoted anywhere in it, and are a candidate for separate treatment. This pack formalizes only the Code of Practice.",
    "Relation to the other AIO packs in this area. Three packs now touch content transparency and they are not interchangeable. `eu-ai-act` formalizes provisions of Regulation (EU) 2024/1689 addressed to providers and deployers of high-risk AI systems and does not cover Article 50. `cn-ai-labelling` formalizes the Chinese Measures for Labelling AI-Generated Synthetic Content, which impose an explicit-plus-implicit labelling regime with retention thresholds and dissemination-platform duties. This pack formalizes a voluntary European code implementing a statutory transparency duty. The nearest textual meeting point is Measure 1.2 of Section 1 here and Article 10, second paragraph there, both of which forbid supplying the means to defeat a marking; everything else diverges in structure, in addressee and in enforcement. A measurement against one pack says nothing about the others and the three are not additive into any combined claim.",
    "Selection. Ten Commitments and Measures are mapped: from Section 1, Commitment 1 · Measure 1.1, Measure 1.2 points (a)–(b), the circumvention-tool prohibition in Measure 1.2, Commitment 2 · Measure 2.1 and Measure 2.3; from Section 2, Commitment 1 · Measure 1.1, Measure 1.2, Measure 2.3, Commitment 3 and Commitment 4. They were chosen for carrying a normative direction an item could be written against. Not mapped, and therefore outside this pack in every respect: in Section 1, Sub-measure 1.1.3 (fingerprinting and logging, optional), Measures 1.3 and 1.4 (optional), Sub-measures 2.1.3 and 2.1.4 (privacy and security of the detection service; retirement of a detection solution), Measures 2.2 and 2.4 (optional), Commitment 3 in its entirety (Measures 3.1 to 3.5, the effectiveness, reliability, robustness, interoperability and state-of-the-art requirements, including the 2 February 2027 interoperability deadline) and Commitment 4 in its entirety (Measures 4.1 to 4.4, compliance process, testing and monitoring, training and cooperation with market surveillance authorities); in Section 2, Measure 1.3 (task force, optional), Measures 2.1 and 2.2 (internal compliance process; awareness and literacy). Several of those carry substantial management-system weight — Section 1 Commitments 3 and 4 are in practice the heaviest engineering and quality-assurance obligations in the whole Code — and they are covered in the management-system guide at docs/management-guides/eu-transparency-code.{ko,en}.md, which deliberately reaches wider than this pack. Sub-measure 2.1.3 is a special case worth recording: it is a data-protection regime for the detection service, including a zero-retention rule, and it was left out because the interest it protects has no carrier in the AIO value vocabulary, a gap already recorded from three earlier packs.",
    "Obligation-type distribution, and the expectation it disappoints. behavioral 2 · mixed 6 · organizational 2. The working assumption when this pack was commissioned was that a transparency and disclosure code would produce a markedly more behavioral pack than the organisation-heavy norms formalized in Waves 1 to 3. It does better than most of them and it does not do what was expected. The reason is structural: an Article 50 transparency duty is discharged by an artefact — a watermark, a signed metadata block, an icon in the corner of a frame — and an artefact is produced by a pipeline, not by a judgment made in a concrete case. Eight of the ten entries therefore keep an organisational limb. The two that do not are the prohibition on supplying circumvention tools in Section 1 Measure 1.2, which demands nothing but abstention, and Commitment 3 of Section 2, which asks for a trade-off between disclosing a deep fake and not spoiling the artistic work it belongs to and demands no document, process or infrastructure at all. Those two are the first candidates for item-bank authoring.",
    "Source-axis policy (P4, settled in Wave 1, extended in Waves 2 and 3, applied here). `Gov` is declared only where the quoted excerpt itself names a government body or a government norm as decisive on the substance of the duty — Article 50(2) AI Act at Section 1 Measure 1.1; Directive (EU) 2019/882 and Directive (EU) 2016/2102 at Section 1 Measure 2.3; Article 50(4) and (5) AI Act at Section 2 Commitment 1, Measure 1.2 and Commitment 3; 'applicable Union and national laws' at Section 2 Measure 2.3; Article 50(4), second subparagraph and Regulation (EU) 2024/1083 at Section 2 Commitment 4. It is never carried in from the fact that the Code is a Commission-facilitated instrument, which is why Section 1 Measure 1.2 carries no `Gov` at all, and it is not earned by the Code's reference to its own Annex, under the self-reference rule settled on the `tx-traiga` pack. The recipient-is-not-a-source convention did real work in this pack: at Section 1 Measure 2.1 the competent authorities, regulators and law enforcement bodies who must be given free unlimited access are beneficiaries of the duty, not sources whose position governs, and `Gov` is withheld there. `Ind` is declared where the excerpt makes the Signatory the author or performer of the operative artefact or determination — the marking solution, the acceptable use policy, the detection solution and its result, the equivalent label, the placement, the editorial policy — and is withheld at Section 2 Measure 2.3, where the Signatory only corrects its own earlier output, and at the circumvention prohibition, which designates nobody. `Pro` and `Pee` appear nowhere in this pack. That withholding is deliberate and was reached three times independently: no standardisation body is named in the marking Measures; 'open standards' at Measure 1.2 names a class of specification and not its issuer; and ETSI and W3C at Measure 2.3, like the IETF-style bodies at Measure 3.4, are named only inside sentences the Code marks as 'encouraged', which it defines as not legally required. Two entries carry no source class at all and one carries no evidence class; an undeclared layer is a scoring exclusion and is the honest signal.",
    "Codes inferred from a provision's structure rather than its words are flagged INFERENCE in the rationale and go to the RFC round: `Dat` at Section 1 Measure 1.1 (read out of the cross-reference to Commitment 3), `Ses` at the Section 1 Measure 1.2 circumvention prohibition (read out of what a defeated marking costs, following the treatment of the parallel Chinese provision), and `Hed` at Section 2 Commitment 3, which is not an inference from structure but is the first appearance of that code in any AIO pack and is put to the RFC round for that reason.",
    "Vocabulary gaps observed while formalizing this Code. They are candidates: the register stood at 32 entries at the close of Wave 3 and new entries are numbered at the close of Wave 4, not here. (1) Perceptibility to a human as an evidence class — the Code's operative standard throughout Section 2 is that a disclosure be 'clear and distinguishable', recognised 'without requiring user (inter)action or sustained attention'; nothing in the evidence vocabulary carries what settles that question, and the Code itself says at Measure 3.1 that there is 'no quantitative evaluation metric' for it and that a user-based assessment is required. `Gui` was used as a proxy at four entries and it is a poor one. (2) A single machine-detection verdict as an evidence class — `Dat` is defined as a single large body of measured numbers, which a per-item detector output with an error rate is not; the pack uses `Dat` at Section 1 Measures 2.1 and 2.3 for want of anything closer. (3) Fact-checkers, trusted flaggers and comparable verification intermediaries as a source class — the Code names them in the same breath as authorities, media and researchers, and none of `Pro`, `New`, `Tes` or `Usr` fits. (4) Artistic and creative expression, and the integrity of a work, as a value — Section 2 Commitment 3 protects the display, enjoyment, normal exploitation, utility and quality of a work against the disclosure duty; `Hed` catches the enjoyment and nothing catches the rest. (5) Content provenance and authenticity as a protected interest in its own right, distinct from the security or integrity of an artefact recorded as gap 32 on the ASEAN pack. Re-observations of existing gaps, not new: the absence of an evidence class for a purpose or intent determination (gap 31, `tx-traiga`) at the circumvention prohibition; the absence of a value code for an interest expressly preserved against an obligation (gap W1-9) at Section 2 Commitment 4, where media freedom, editorial independence and journalistic source protection are preserved against the Commitment itself; the absence of a privacy value code (gap W1-2) at Sub-measure 2.1.3, which is the reason that Sub-measure is unmapped; the unsuitability of `Pro` for standardisation bodies (gap W1-8); and the mitigable-modality problem (gap W2-23), which this Code states more explicitly than any norm formalized so far by defining 'will', 'encouraged' and 'may' in its own text.",
    "No item bank exists for this pack. itemBankRef.publicSet is null, so this pack backs no certificate at any tier until a bank is built and the pack has reached at least draft-verified.",
    "Methodology for the Commitment/Measure → V/E/S translation: /content/standards-packs/FORMALIZATION_METHODOLOGY.md. Codes are the canonical three-letter AIO 00011 vocabulary served at /api/framework/vocabulary.",
    "AIO certifies conformance to AIO's own formalization of the Code. This is not a legal conformity assessment, not an assessment of adherence to the Code, not a notified-body procedure, and it confers no presumption of conformity under Regulation (EU) 2024/1689. The European Commission, the AI Office and the AI Board took no part in this formalization, have not reviewed or endorsed it, and it is not an official interpretation of the Code.",
    "Reuse. Commission documents are reusable under the Commission's reuse policy (Decision 2011/833/EU; the Commission's current legal notice places content owned by the EU under CC BY 4.0, subject to attribution to the European Union and to indication of changes). Verbatim excerpts here are quoted with attribution to the European Commission and to the specific Section, Commitment and Measure. The EU icons in Annex 1 of the Code are not reproduced anywhere in this pack: they are referred to by name only, both because logos and industrial property are carved out of the Commission's CC BY 4.0 notice and because the Code sets its own terms for their use. This pack is a derivative reading and is not endorsed by the Commission."
  ]
}
