EU AI Act · Article 50 in force · marking deadline 2 December 2026
EU AI Act · Article 50(2) · AI generators

Does Stable Diffusion (Stability AI) mark its images as AI-generated?

In force since 2 Aug 2026Fines up to €15M / 3% turnoverLast reviewed August 2026

Stable Diffusion is unusual in this comparison because it isn't one product, it's an open-weight model that's deployed through Stability AI's own hosted Stable Image platform, through countless third-party interfaces (ComfyUI, Automatic1111, InvokeAI, and others), and through self-hosted local installations. That structure means "does Stable Diffusion mark its output" doesn't have one answer: it depends entirely on which specific tool generated the image, not on the underlying model.

Article 50(2) of the EU AI Act requires AI-generated or AI-edited audio, image, video, and text to be marked in a machine-readable format so it's detectable as artificially generated, via C2PA Content Credentials or IPTC provenance metadata, embedded in the file itself. This is a provider-side duty on the generative system, but it fails quietly in practice: content that leaves a generator marked routinely arrives on a published page unmarked, stripped somewhere in the ordinary pipeline of editing, compressing, and publishing.

Two separate duties, don't conflate them. Article 50(2)'s machine-readable marking is invisible, in the file itself, and largely a provider/tooling question. Article 50(4) separately requires a visible label on deepfakes and AI-generated text published to inform the public, a fallback that doesn't depend on whether machine-readable marking survived. Where you can't confirm marking, visible labeling is the simpler, more reliable compliance path.

Does Stable Diffusion (Stability AI) mark its output by default?

Stability AI's own hosted Stable Image platform has added C2PA support and is listed among major providers (alongside Google, Adobe, OpenAI, Microsoft, and Meta) embedding Content Credentials as of March 2026. But the open-source model weights and base code do not embed C2PA manifests by default, and the most popular third-party interfaces for running Stable Diffusion, ComfyUI, Automatic1111, InvokeAI, do not add C2PA credentials by default either, even though they technically could be configured to.

What strips the marking before it reaches your published page

How to verify before you publish

Keep proof either way. Whether or not machine-readable marking survives to your published page, keep a record of what you checked and when: a screenshot from a verification tool, or your visible-label copy, so you can show the diligence, not just assert it.

The realistic compliance gap

Stable Diffusion is likely the highest-risk generator in this entire comparison for Article 50(2) purposes, precisely because of its fragmented tooling ecosystem, unlike a single controlled SaaS product, there's no one place to check or one setting to enable. A marketing team that doesn't know or track which specific Stable-Diffusion-based tool produced a given image has no reliable way to know its marking status without checking the file directly.

Note: AI-generator provenance practices change quickly and can vary by product tier, export path, or recent platform update. This page describes Stable Diffusion (Stability AI)'s marking behavior as understood as of August 2026; verify against Stable Diffusion (Stability AI)'s current official documentation and check your own specific output before publishing.

Common questions

We use a third-party app that's 'powered by Stable Diffusion', does it have C2PA marking?

Don't assume so. C2PA support depends on the specific tool, not the underlying model, Stability AI's own hosted platform supports it, but most third-party apps and interfaces built on the open-weight model do not add it by default. Check the specific tool's own documentation, and verify actual output files with a C2PA checker rather than relying on the fact that it's "Stable Diffusion" under the hood.

Our design team uses a self-hosted Stable Diffusion setup (ComfyUI/Automatic1111), what's the simplest fix?

The most reliable approach for self-hosted setups is to skip relying on machine-readable marking entirely and use Article 50(4)'s visible-labeling path instead, add a clear, honest "AI-generated" label or caption to published images, since that doesn't depend on your specific tooling having implemented C2PA.

Check what's on your site. DisclosureProof samples the media on your homepage and checks it for machine-readable AI-content marking, with timestamped evidence either way. Run the free scan →