Binding law — in force
Do not strip the marks on AI output, disable the provider's marking, or remove a deepfake disclosure (Greece, Law 5321/2026 Art. 23)
Since 2026-07-20, Greek Law 5321/2026 Art. 23 makes it an offence, punishable by imprisonment and a fine unless another provision punishes the act more severely, for anyone to remove the machine-readable marks on the output of AI systems that generate synthetic content, or to obstruct the proper working of the provider's technical solutions for that marking, as AI Act Art. 50(2) requires them, or to remove or obstruct the deployer's disclosure under Art. 50(4) that content is a deepfake or has been artificially generated or manipulated. Detect code that strips metadata, C2PA manifests or watermarks from AI-generated media, switches off a generator's watermarking, or removes an 'AI-generated' disclosure.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.4
- Lane
- Binding law — in force In force: applies since 20 Jul 2026
- Official source
- Law 5321/2026, Art. 23 (removing the machine-readable marks of AI Act Art. 50(2) or the deployer's deepfake disclosure of Art. 50(4) is an offence) · captured 3 Oct 2026 · anchor hash (SHA-256)
567c708e495a…· 2 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.9.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
3 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Re-encoding (Pillow save, cv2.imwrite, sharp, ffmpeg transcodes) can drop an embedded C2PA manifest with no explicit strip call; confirm with a round-trip test on a marked sample
- Metadata dropped by an image CDN or transcoder configured outside the repository
- Removing only private EXIF fields (GPS, device) while the C2PA manifest and watermark survive, or re-signing the manifest after an edit, is not removal of the mark; confirm what the call removes.
5 more known limits in the data release.
Who it applies to
- Duty falls on: any person
- Any person, in Greece, who removes the machine-readable marks on synthetic output of AI systems or obstructs the provider's marking solutions (AI Act Art. 50(2)), or removes or obstructs a deployer's deepfake or artificial-content disclosure (Art. 50(4)): an offence under Greek criminal law, in force since 2026-07-20. The marks it protects are those AI Act Art. 50(2) and (4) require (see the eu-ai-act pack for when those duties apply). Whether only intentional removal is punishable, whether re-encoding that drops a mark is 'removal', how the offence reaches acts outside Greece, and whether Art. 23 bites before Art. 50 applies are questions for counsel (review flag).
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Keep the marks: process AI output so its C2PA manifest, provenance metadata and watermark survive, never switch off the generator's marking, and never strip an 'AI-generated' disclosure.
In every path that takes AI-generated media from the generator (images.generate, a diffusers pipeline, Imagen, a TTS or voice-clone call) to storage or publication, remove the calls that drop marks: ffmpeg -map_metadata -1, ImageMagick -strip, exiftool -all=, piexif.remove(, strip_metadata=True, remove_watermark( or remove_c2pa(. Where metadata must be reduced for privacy, remove only the named private fields and keep or re-sign the C2PA manifest (c2pa.Builder / c2patool) after editing. Leave the provider's marking on: no add_watermarker=False or pipe.watermark = None in diffusers, no add_watermark=False for Imagen. Edit and export code carries the deepfake or 'AI-generated' disclosure through; nothing removes or hides it. A test reads the mark back (c2pa.Reader, the watermark decoder) from a processed sample.
Where it goes: 9 AI output handling, 1 application source code, 12 repository artifacts.
What this provision adds:
- Never remove the machine-readable marks on AI-generated output or obstruct the provider's marking (AI Act Art. 50(2)), nor remove or obstruct a deployer's deepfake disclosure (Art. 50(4)); in Greece each is an offence punishable by imprisonment and a fine.
Example (diffusers + ffmpeg post-processing), before:
pipe = StableDiffusionXLPipeline.from_pretrained(MODEL_ID, add_watermarker=False)
image = pipe(prompt).images[0]
image.save(tmp_path)
subprocess.run(['ffmpeg', '-i', tmp_path, '-map_metadata', '-1', out_path])After:
pipe = StableDiffusionXLPipeline.from_pretrained(MODEL_ID) # keeps the invisible watermarker
image = pipe(prompt).images[0]
image.save(tmp_path)
sign_c2pa(tmp_path, out_path, digital_source_type='trainedAlgorithmicMedia') # our helper around c2pa.Builder.sign
assert read_c2pa(out_path) # round-trip check: the mark survivesControl: Machine-readable marking or deepfake disclosure on AI output removed or disabled. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Rule id gr-law-5321.no-removal-of-ai-output-marking · review status: primary source derived