EU AI Act Deepfake Labels: What Article 50 Requires Now
Since 2 August 2026, a hidden technical marker and a visible disclosure have been two different jobs. Knowing which one is yours is the useful place to start.
The transparency rules are now in application
Article 50 of the EU AI Act became applicable on 2 August 2026. It covers several kinds of transparency, but two are especially relevant to synthetic media: providers of generative AI systems must make certain outputs machine-readable and detectable as artificial, while deployers must disclose deepfakes to the people exposed to them.
Those duties are related, not interchangeable. A production tool may embed provenance or another machine-readable signal in a file. The organization that publishes a realistic synthetic video may still need a disclosure a person can actually perceive. Conversely, adding the words ‘AI generated’ to a post does not complete a system provider’s technical marking work.
This guide is a practical reading of the official text and the European Commission’s July 2026 guidelines. It is not legal advice for a particular product, campaign or jurisdiction, and Article 50 does not replace privacy, consumer, intellectual-property, election, fraud or platform rules that may also apply.
First decide whether you are a provider, a deployer or both
A provider develops an AI system or has one developed and places it on the market or puts it into service under its name or trade mark. A deployer uses an AI system under its authority. The Act’s deployer definition excludes a natural person using AI in a purely personal, non-professional activity.
A model company offering a video-generation system is likely looking at the provider obligation. A marketing agency using that system for a client campaign is looking at the deployer obligation. A company that develops its own generator and then publishes its output can occupy both roles. Labelling policy should therefore begin with a simple map of who supplies the system, who makes the content and who exposes the audience to it.
Do not assume that buying a tool transfers every duty to its vendor. The provider controls system-level marking; the deployer controls the publication context, the audience-facing disclosure and the records explaining what was released.
What counts as a deepfake for this rule
The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. That is wider than a face swap. A synthetic voice, a fabricated scene of a real place or a convincing fake event may qualify.
Not every use of AI in a media workflow is automatically a deepfake. Article 50(2) also recognizes system-level exceptions where AI only performs an assistive function for standard editing or does not substantially alter the input or its meaning. The Commission guidelines provide examples of what is in and out of scope. Teams still need to look at the finished content: a harmless color correction and a generated statement placed in a real person’s mouth are not the same operation.
The useful test is not whether a particular model was used. Ask what the audience sees or hears, what real person, place, object or event it resembles, and whether it could falsely appear authentic or truthful.
Machine-readable marking and human disclosure are separate layers
Under Article 50(2), providers of systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as technically feasible, taking account of the medium, cost and state of the art.
Under Article 50(4), deployers of a system that generates or manipulates a deepfake must disclose that the content is artificially generated or manipulated. Article 50(5) says the information must be clear and distinguishable, accessible, and provided no later than the first interaction or exposure.
A metadata field that only specialist software can read is not, by itself, a clear disclosure to the viewer. A visible caption with no durable technical signal does not satisfy the provider’s separate marking duty. A sensible workflow preserves the provider’s embedded signal and adds an audience-facing label that survives the way the content will actually be displayed, downloaded and reshared.
- Provider layer: machine-readable marking and detectability
- Deployer layer: a clear disclosure to the exposed person
- Timing: no later than first interaction or exposure
- Accessibility: the disclosure must be perceivable and understandable
Put the disclosure where the audience meets the content
The Commission’s optional EU icons offer one practical pattern. Its guidance says an icon should be clearly perceivable and distinguishable at first exposure, avoid intervening overlays and remain visible when content is reshared or downloaded. Plain-language text beside an icon can improve understanding; the icon page notes that user testing performed better when the symbol was accompanied by a label.
Treat a label hidden in a profile biography, terms page or click-through menu with caution. It may never reach somebody watching an embedded clip. For video, the disclosure may need to be in the frame and available to assistive technology. For audio, it needs an audible or otherwise accessible equivalent. For an image, the surrounding interface matters, but the disclosure should not vanish when the file leaves that interface.
The EU icons are optional. Their use does not establish compliance by itself, and organizations may use other measures. Whatever format is chosen, preserve evidence of the label text, position, timing, accessibility and behavior after common export and sharing steps.
Creative and satirical works still have a disclosure rule
Where deepfake content forms part of an evidently artistic, creative, satirical, fictional or analogous work or program, Article 50 does not simply erase transparency. It limits the obligation to disclosure in an appropriate manner that does not hamper display or enjoyment of the work.
That allows context-sensitive placement. A cinema drama need not place a warning over an actor’s face throughout every generated scene, but the production still needs an appropriate way to disclose the existence of generated or manipulated content. A satirical post should not rely on the creator’s assumption that every viewer will recognize the joke after it has been clipped and reposted.
‘Creative’ should not become a default checkbox for advertising, impersonation or public-information work. Record why the exception was considered, what disclosure was chosen and how it remains available to the audience without spoiling the work.
Public-interest text follows a narrower rule
Article 50(4) also covers AI-generated or manipulated text published to inform the public on matters of public interest. The official guidance distinguishes this from the deepfake rule for image, audio and video. The text duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
A quick read-through is not a magic phrase. An editorial process should identify who checked factual claims, sources, quotations and material changes, who had authority to reject the text and who accepts responsibility for publication. Keep that record with the content version that was actually released.
The exception is specific to the public-interest text limb. Human review does not automatically remove the separate duty to disclose an image, audio clip or video that constitutes a deepfake.
The code is voluntary; the legal obligations are not
The Code of Practice on Transparency of AI-Generated Content gives providers and deployers a common implementation framework. Section 1 addresses provider marking and detection. Section 2 addresses deployer labels for deepfakes and certain public-interest text. The Commission and AI Board have assessed the code as an adequate voluntary route for demonstrating compliance.
An organization does not breach the Act merely by declining to sign the code. It must still comply with Article 50 and be prepared to demonstrate that its alternative measures are adequate. That makes a documented gap analysis useful even for non-signatories: compare current product and publishing controls with the code, then record equivalent controls and the evidence behind them.
Commission materials describe a limited transition to 2 December 2026 for the provider marking and detection duty in Article 50(2) for certain systems placed on the market before 2 August. This is not a blanket delay for all Article 50 duties, and it does not turn off the deployer’s deepfake disclosure obligation. Check the current official guidance against the facts and launch date of the system involved.
A practical publication checklist
Build the check into release, not into crisis response. The person approving publication should be able to see the source files, system used, provider marking, audience-facing label, intended channels and any exception being relied on. Test the real exported asset in the real interface, including a download or reshare path.
A label does not make harmful conduct lawful or a false claim true. Consent, likeness, copyright, consumer protection, defamation, election rules and platform policies may still block publication. Keep a complaint and correction route, especially when the content resembles a real person or event.
- Map provider and deployer roles for the exact workflow
- Decide whether the output is a deepfake under the statutory definition
- Preserve machine-readable marks through export and transcoding
- Add a clear, accessible disclosure at first exposure
- Test downloads, embeds, crops and platform reshares
- Document creative or editorial exceptions instead of assuming them
- Retain approvals, source records and the released version
- Recheck the Commission guidance when the system or format changes
Continue with independent verification.
Check disputed mediaPrimary reading
We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 17 August 2026.
- AI Act Service Desk: Article 50 official text and explanation
- European Commission: Article 50 transparency guidelines (July 2026)
- European Commission: Code of Practice on Transparency of AI-Generated Content
- European Commission: EU icons for labelling AI-generated content
- European Commission: Article 50 questions and answers
- Regulation (EU) 2024/1689, official text