EU AI Act · Article 50 in force · marking deadline 2 December 2026
EU AI Act · Article 50(2) · AI generators

Does DALL·E / GPT-4o Images (OpenAI) mark its images as AI-generated?

In force since 2 Aug 2026Fines up to €15M / 3% turnoverLast reviewed August 2026

OpenAI's image tools, DALL·E 3 and GPT-4o/GPT-image's native generation inside ChatGPT and the API, are among the most widely used AI image generators for everything from marketing assets to blog illustrations. OpenAI has invested specifically in machine-readable provenance: images from ChatGPT, Codex, and the API carry both C2PA metadata and a SynthID watermark, and OpenAI now also applies C2PA to Sora-generated video. For an Article 50(2) compliance check, that means OpenAI's own output starts well-marked, the real question for a site owner is whether that marking survives everything that happens to the image between generation and publication.

Article 50(2) of the EU AI Act requires AI-generated or AI-edited audio, image, video, and text to be marked in a machine-readable format so it's detectable as artificially generated, via C2PA Content Credentials or IPTC provenance metadata, embedded in the file itself. This is a provider-side duty on the generative system, but it fails quietly in practice: content that leaves a generator marked routinely arrives on a published page unmarked, stripped somewhere in the ordinary pipeline of editing, compressing, and publishing.

Two separate duties, don't conflate them. Article 50(2)'s machine-readable marking is invisible, in the file itself, and largely a provider/tooling question. Article 50(4) separately requires a visible label on deepfakes and AI-generated text published to inform the public, a fallback that doesn't depend on whether machine-readable marking survived. Where you can't confirm marking, visible labeling is the simpler, more reliable compliance path.

Does DALL·E / GPT-4o Images (OpenAI) mark its output by default?

As of this review, OpenAI embeds both signals by default: a cryptographically signed C2PA manifest attached to the image (declaring the model used, DALL·E 3, GPT image, or Sora, generation date, a hash of the original, and OpenAI's producer signature) and a SynthID watermark, developed with Google DeepMind, embedded directly into the pixel data rather than as removable metadata. SynthID is specifically engineered to survive common transformations, moderate cropping, rotation, JPEG compression, and many filters, where a metadata-only signal would be dropped. OpenAI also publishes a public verification tool at openai.com/verify that checks an uploaded image for either signal.

What strips the marking before it reaches your published page

How to verify before you publish

Keep proof either way. Whether or not machine-readable marking survives to your published page, keep a record of what you checked and when: a screenshot from a verification tool, or your visible-label copy, so you can show the diligence, not just assert it.

The realistic compliance gap

OpenAI's own output is genuinely well-marked by industry standards, the compliance gap is almost entirely downstream, in the ordinary publishing pipeline: CMS uploads, image CDNs, social re-sharing, and third-party editing tools that weren't built with C2PA in mind. A site that generates a compliant image and then runs it through a standard image-optimization step before publishing can end up with an unmarked file despite starting from a well-marked one.

Note: AI-generator provenance practices change quickly and can vary by product tier, export path, or recent platform update. This page describes DALL·E / GPT-4o Images (OpenAI)'s marking behavior as understood as of August 2026; verify against DALL·E / GPT-4o Images (OpenAI)'s current official documentation and check your own specific output before publishing.

Common questions

If OpenAI already marks its images, do we still need to do anything for Article 50(2)?

Check what happens to the image after generation, not just at the moment it's created. If your CMS, CDN, or editing workflow strips the C2PA manifest (common with image optimizers) before the image reaches your published page, the marking OpenAI attached never makes it to your visitors, verify the actual published file, not the original download.

Does the SynthID watermark mean we don't need to worry about C2PA getting stripped?

SynthID is more resistant to common transformations than C2PA metadata, but it's a different kind of signal, it's designed to be detectable by tools that know to look for it, not necessarily to satisfy Article 50(2)'s 'machine-readable' marking requirement on its own in every context. Treat the two as complementary: C2PA for structured, standards-based provenance data, SynthID as a more resilient backup signal, and verify both where you can.

Check what's on your site. DisclosureProof samples the media on your homepage and checks it for machine-readable AI-content marking, with timestamped evidence either way. Run the free scan →