The first question is what the content does

People often ask whether making a deepfake is illegal. That is too broad to produce a useful answer. Was it used to steal money, impersonate an employee, interfere with an election, create intimate imagery without consent or make a false claim about a person? Existing fraud, privacy, defamation and consumer laws may matter even if they never mention the word deepfake.

Context changes the analysis. A labeled parody, a visual-effects demo and a fake emergency call may use similar technology while creating very different risks. Country, audience, intent and the people depicted all matter.

What the EU AI Act adds

The EU AI Act defines a deep fake broadly as AI-generated or manipulated image, audio or video content that resembles real people, objects, places, entities or events and would falsely appear authentic. Article 50 sets transparency duties around systems that generate or manipulate this kind of content.

There is additional context for artistic, creative, satirical and fictional works rather than a single identical label for every use. The exact obligations and timing should be checked against the official regulation. A short article - especially this one - is not legal advice for a specific campaign or product.

A label does not solve consent

Disclosure is important, but it is not a universal permission slip. A clear AI label does not automatically resolve the use of somebody's likeness, the source of training material, a misleading commercial claim or the handling of private data. On the other hand, using software does not by itself make an artwork unlawful.

For a business, the sensible approach is to review the whole route from source material to publication: performer consent, model and tool terms, claims made to the audience, labels, records and complaint handling. Adding a tiny 'AI' note at the end cannot repair a process that was irresponsible from the start.

Platforms can say no before a court does

Social networks, advertising services and payment providers enforce their own rules. They may reject or remove media that no court has ruled illegal, and those policies can change much faster than legislation. Check the current rules of every channel involved in distribution.

Keep original media, consent records and editing history. Content Credentials may help document part of the production trail, but internal records are still necessary when a platform, regulator or affected person asks what happened.

A workable minimum policy

Clearly disclose realistic synthetic media, obtain appropriate permission for likeness and voice, ban deceptive identity and financial uses, retain production records and provide a route for complaints. Escalate political, intimate, high-reach or otherwise high-risk work to qualified counsel in the relevant jurisdiction.

Rules and enforcement keep moving. Check official sources at the time you publish rather than assuming a policy written last year still covers the launch in front of you.

Automated results require source and context review.

Continue with independent verification.

Check disputed media
Sources

Primary reading

We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 2 September 2026.