Inspect the file that actually shipped, not the master it came from: read the mark embedded at generation, re-test it after delivery, and hold the asset for the editor who releases it.
An asset is generated, and Article 50 of the AI Act has applied since 2 August 2026.
02
A synthetic spokesperson ships, and the deep-fake limb of Art. 50(4) lands on a deployer.
Reason
03
A voice is cloned, and Art. 3(60) asks whether it resembles an existing person.
04
A master is resized for a placement, and the manifest can leave the file without a warning.
05
A file is transcoded for an ad server, and the mark either survives that pass or it does not.
Decide
06
An asset lands in the CMS, and re-encoding on ingestion is where marks go missing most quietly.
07
A format is derived for a feed, and platform re-compression is tested rather than assumed.
Out
08
An asset is archived, and Art. 50 lays no record-keeping duty on a deployer.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
The agent records what was generated, embeds or verifies the mark your policy specifies, and re-tests the delivered file. A named editor releases the asset.
Example workflow
One asset, generation to release
AgentHuman
1Asset evidence receivedGeneration logs, tool manifests, DAM renditions or delivery-pipeline captures
2Asset context assembledThe asset, the tool that made it, the paragraph it answers to and the day it was generated
3Provenance evidence draftedThe asset, its marks, the renditions derived from it and completeness
4Controls appliedMark-presence checks, survival re-tests, deep-fake checks and completeness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is released at any of them — the agent is testing, and the legal lane opens at the completeness gate.
5DecisionSplits at the completeness gate
Evidence sufficient
Goes to the releasing editor to approve.
Anything thin
Adds a legal counsel read first.
Legal review
The asset is held with its marks, its renditions and the tool that generated it.
Release · Append evidence · Send to legal review
Released — by a named editor▼
6Asset and rendition records updatedOnly where write access and records policy allow it
7Outcome evaluatedMark survival, register coverage, reviewer corrections and what the read found
Corrections
Each legal correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Releasing an asset for publication.
Deciding a deep fake needs no disclosure.
Settling deployer or provider under Art. 3(3).
Signing the Code of Practice on Transparency.
Automation boundaryAgent acts unaided
✓Record what generated the asset and the tool version behind it.
✓Embed or verify whichever mark your own marking policy specifies.
✓Re-test the file the pipeline actually ships.
✓Flag the rendition that generated marked and reached.
Nothing is released or disclosed except by a named person, inside the agreed boundaries.
Judging whether an Art. 50(4) exemption applies.
Telling a market surveillance authority anything.
Setting the marking policy an asset is held to.
Changes to masters, renditions or delivery records.
Example output
One asset, annotated
Our campaign copy generation agent drafts headlines and body copy against the brief, the brand voice and the approved claims library; this page is about the file — what is embedded in it, and whether it is still there after delivery.
Register entry · single assetIllustrative example
Asset
Recorded as
Mark
Evidence of record
Confidence
Held for
Synthetic spokesperson, Art. 50(4)
Generated marked, re-tested after delivery
Deep fake
Delivery re-test, 3 August 2026
Held unreleased
The releasing editor, by name
As receivedTaken from the generation log and the delivered rendition — it reaches as far as those sources do.
What the record holdsGeneration logEmbedded markDelivered rendition
Why no release hereWhether a deep fake may ship is an Art. 50(4) call, not a model output.
ActionReleaseAppend evidenceSend to legal review
What the score decidesBelow the configured threshold an asset picks up a legal read before the editor sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every assetFrom the tool that made it
03Evidence
Where the evidence is used
Our advertising pages answer to a client who booked the media; this one answers to the brand legal and privacy functions that live with the asset afterwards.
01Approved path
The mark has to survive
A mark present at generation and absent in the delivered creative is a failure no copy review can detect, which is why the re-test runs at the end of the pipeline.
02Human review
What was checked, and not found
The enacting provision of Regulation (EU) 2026/1744 behind the 2 December 2026 marking transitional was not located in the operative text, the OJ publication and entry-into-force dates of the AI Act were not verified against primary text, no harmonised standard or implementing act on marking formats was found in force, and no signatory count for the Code of Practice on Transparency of AI-generated Content is published.
04Build an evidence trail
The asset, the mark embedded in it and the editor who released it stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Generation tools and modelsImage, video and voice tools Generation logs and manifests
Asset managementDAM · CMS renditions Master and derivative records
Delivery and distributionAd server · social platforms Delivered file captures
Agent
Content generation provenance
Reads the assets Tests the marks Holds for the editor
Records and case systemsLegal tooling · ticketing Disclosure and review records
Integration availability depends on the client's existing systems and API access.
Agent controls
Six presses between the model and the editor
Six presses run in sequence, the last the heaviest. Whatever comes out whole is drawn in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeNarrow the agent to evidence assembly when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt and marking rules; Regulation (EU) 2026/1744, in force 27 July 2026, defers Chapter III high-risk duties alone and left Article 50 where it stood.Track
L4TraceabilityRecord each asset, the mark behind it, the renditions drawn from it and every read of the file.Record
L3Editor releaseHold the asset for a named editor; the hold governs release, not whether an Art. 50(4) disclosure was owed on it.Gate
L2Marking guardrailsTest each asset against the marking policy you configure; recital 133 lists watermarks, metadata identifications, cryptographic provenance and fingerprints, and mandates no single format.Restrict
L1Confidence thresholdsRoute a thin asset to a legal read first; Art. 50(1) and Art. 50(2) bind providers, and reading either onto a deployer is the common error.Require review
Model coreEvidence assembled — the asset, its marks, the renditions and completeness
L1 – L2Test whether an asset may ship
L3Puts the release in a person's hands
L4 – L5Keep the asset and the mark behind it
L6Withholds the release when signals degrade
How Nestack evaluates it
Evaluate the whole assembly — not only the register entry that comes out.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the record an authority reads
Depth of coverage ▼
E1Final-output evaluationDid the entry record what the asset actually carries?
E2Step-level evaluationDid the agent read the right asset, the right rendition and the live delivery path?
E3Tool evaluationDid it read and write the correct asset record and the correct mark?
E4Confidence calibrationDo low-confidence assets actually attract more legal corrections?
E5Slice evaluationHow does performance change across specific asset types?
E6Business outcomeHow many assets needed a correction before the editor released?
Floor — the register the brand answers for
Failure modes
Where each failure originates in the agent
Seven failure modes, each named at the stage where it first appears.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
KV-03
Stale rendition read
The rendition read is not the one now being served.
Stage gathersThe assets, the tools, the marks and the renditions
02 · Reasoning2 modes
KV-04
Mark asserted, not tested
A mark is recorded present without a re-test.
KV-06
Provider duty read onto us
Art. 50(2) marking is worked as our own duty.
Stage proposesThe assets, their marks and completeness
03 · Tool / write2 modes
KV-02
Thin asset passed forward
An asset moves on without the legal read.
KV-05
Bound to the wrong master
A mark is filed against the wrong asset.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
KV-01
Released, evidence unrecorded
The record shows a release but not what supported it.
Stage returnsThe record an editor releases and an authority reads
05 · Change / Version1 mode
KV-07
Silent marking regression
A pipeline change strips the mark, not the record.
Stage tracksModel, prompt, marking rules and asset fields
Sev-1 · a deep fake shipped undisclosedSev-2 · wrong mark reaches the registerSev-3 · source degrades, asset held back
A type-level mark-survival figure can read clean while synthetic video and voice carry most of the rework. Nestack reports the correction rate by asset type, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Synthetic video and voice
11.4%
3.7×
Review
Social-derived formats
8.1%
2.6×
Review
Display and banner renditions
5.1%
1.6×
Watch
Photography and stills
2.3%
0.7×
Normal
Bar: correction-rate lift vs. photography baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What a stripped mark costs
A cycle shuts when the stripped manifest is a regression case. That suite is what the next asset released is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on synthetic video and voice.
02Diagnose
The mark that was in the master and gone from the file the ad server delivered is read back until one cause remains.
03Improve
The change ships numbered, and the assets that forced it ride with it.
04Verify
Nothing releases while one touched asset case is still red.
05Learn
It is retained for good, and the marking rules are amended in that same commit.
Learn → DetectThe return edge. The next release is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, provenance assembly, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Mark-survival discovery and automation-boundary work.
02Generation, DAM and delivery sources.
03Asset-to-paragraph and mark-coverage rule mapping.
04Asset and rendition ingestion.
05Asset, mark and record binding.
06Completeness scoring and review routing.
07Editor release workflow.
08Ad-server and CMS integration.
09Provenance and survival cases.
10Guardrails and release controls.
11Asset-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne asset type, one quarterProductionProduction release workflowAdvancedMultiple brands / markets
Introduced at Pilot
Provenance assembly to your assets✓✓✓
Releasing editor control✓✓✓
Generated-asset baseline✓✓✓
Introduced at Production
Reporting by asset type—✓✓
Release workflow in your systems—✓✓
Approved write-back—✓✓
Delivery-pipeline integration—✓✓
Introduced at Advanced
Multi-brand estates——✓
Cross-market evidence packs——✓
Large asset libraries——✓
Multi-format marking controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, asset volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your assets and the tools that generate them→Asset inventory mapping and mark captureWeek 1
02Representative masters, renditions and delivered files→Record binding, marking logic and the survival baselineWeek 2
03Your marking policy and the formats it names→Asset mapping, mark binding and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Generation, DAM and delivery-source assessment, then integration setupWeek 2
05Assets you would not want traced→Survival cases and failure-mode testingWeek 4
06What no provenance mark may establish→Completeness scoring, review routing, guardrails and release controlsWeek 3
07A named editor to release the asset→Release workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Every band below is worked time and not drawn space, and so the fifth of them has to carry a pair.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Content workflow discovery, asset mapping and the automation boundaryW2Source integration and the mark-survival baselineW3Provenance assembly, marking logic and release controlsW4Evaluation suite, survival cases and failure-mode testingW5Delivery integration, pilot assets and targeted correctionsW6One publishing quarter run under the content lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for. The fifth holds a pair because the work does.
At the end of W6Validation closes on live releases, and Agent Care picks up the watch.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Marketing AI agent
Build a provenance agent around the rendition that left your master marked and reached the ad server bare.
Show us one asset and the file your ad server delivered. Not a copy review. A file test, run at the far end of the pipeline, on the rendition that shipped. Art. 50 lays no record-keeping duty on deployers, so the register is voluntary evidence built against Art. 99 exposure.