Labelling deepfakes and synthetic media: what the EU AI Act requires from your organization

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

An AI-generated video of your CEO announcing a product launch. A voice clone of an actor in your radio ad. A campaign image placing a familiar face in a new setting. From 2 August 2026, Article 50 of the EU AI Act requires organizations using this kind of content to disclose that it was artificially generated or manipulated. This labelling obligation rests with the deployer, the organization publishing the content, and not only with the maker of the AI tool. This article covers when content falls under the deepfake provision, what exactly you must do, and where the exceptions sit.

First, the division of roles: marking versus labelling

Article 50 contains two obligations that often get mixed up. Providers of generative AI systems must mark their output in a machine-readable way, for example with C2PA metadata or watermarks. That is a technical duty on the tool builder's side, and for systems on the market before 2 August 2026 the Digital Omnibus postpones it to 2 December 2026. Deployers publishing deepfakes must additionally disclose themselves that the content is artificial. That second duty has not been postponed and is what this article is about. As a publishing organization you cannot rely on the tool's marking being enough: the disclosure towards your audience is your responsibility.

When is content a deepfake in the legal sense?

The AI Act defines a deepfake in Article 3(60) as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events, and would falsely appear to a person to be authentic or truthful. Two elements carry that definition: the resemblance to something existing and the potential to mislead.

This means that by no means all AI content is a deepfake. An illustration of a non-existent person next to a blog article does not resemble anyone who exists. A clearly stylized animation does not come across as authentic. But a photorealistic image of an existing office building with more solar panels than it has, a voice clone of a recognizable speaker, or a video putting words in someone's mouth does qualify. There are plenty of borderline cases, and a practical rule of thumb applies there: if you have to explain why something is not a deepfake, labelling is the easier route.

What exactly must you do?

Deployers must disclose under Article 50(4) that the content was artificially generated or manipulated. The law does not prescribe how. The disclosure must be clear and distinguishable and made at the latest at the first exposure to the content (Article 50(5)). In practice we see three forms that work: a visible caption or overlay for images and video ("this image was generated with AI"), a spoken or displayed announcement at the start of audio and video, and a statement directly next to the content on the publication page. A reference buried in your terms and conditions does not suffice: the viewer must encounter the disclosure where they encounter the content.

A separate provision applies to AI-generated text. If you publish AI-generated text to inform the public on matters of public interest, you must disclose it, unless a human has carried out editorial control and a person or organization bears editorial responsibility. For most corporate content, such as a knowledge base article reviewed by an employee and published under the organization's responsibility, that exception provides room. For automatically published news items without human control it does not.

The exception for art, satire and fiction

For content that is part of an evidently artistic, creative, satirical or fictional work, a softened obligation applies: you must disclose the existence of the generated or manipulated content in a way that does not hamper the display or enjoyment of the work. A film production therefore does not need a warning across the screen; a mention in an appropriate place, such as the credits or programme information, suffices. For marketing content this exception is rarely usable: a campaign video is not satire, even when it is meant to be funny.

Common mistakes

The same misconceptions keep returning in the projects we support. The first: "our AI tool already watermarks the output, so we do not need to do anything". The provider's marking and the deployer's disclosure are two separate obligations; the second remains yours. The second misconception: "we mention AI use in our privacy statement". The disclosure must sit with the content, not in a document nobody reads next to the video. The third: only involving the marketing department. HR (recruitment videos), internal communications (a generated message from the board) and sales (personalized video pitches) also publish synthetic media, often without compliance knowing.

Practical anchoring

The labelling duty can be anchored without heavy processes. Start with an inventory of where in the organization synthetic media are created and published, including the tools used. Define a standard label per content type, so creators do not have to improvise per item. Include the label in the existing content review, in the same place where brand guidelines and rights are checked today. And record what was published with which label, so you can show how you fulfil the obligation when questions come. Organizations with an ISO 42001 management system attach this to their AI inventory and usage policy; the internal audit then periodically checks whether labels are applied in practice.

Supervision and fines

Violating the transparency obligations can lead, under Article 99(4)(g), to a fine of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs, including start-ups, Article 99(6) caps the fine at the lower of the two amounts. Enforcement rests with the national market surveillance authorities. Beyond the fine, the reputational risk weighs heavily: an unlabelled deepfake going viral is a bigger problem than any fine that may follow. The obligation applies from 2 August 2026. Whoever walks through their content processes now has it arranged before it becomes an issue.

Source: this article is based on Regulation (EU) 2024/1689 (the AI Act), in particular Article 3(60), Article 50(2), (4) and (5), and Article 99(4)(g). The full legal text is available at https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Frequently asked questions

When does AI content qualify as a deepfake under the EU AI Act?+

When it is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events, and would falsely appear authentic to a person. An illustration of a non-existent person does not qualify; a voice clone of a recognizable speaker does.

Who must label a deepfake: the AI tool builder or the publishing organization?+

Both, but with different obligations. The provider of the generative system must mark the output in a machine-readable way. The deployer publishing the content must additionally disclose that it is artificial. That second duty cannot be shifted to the tool.

Has the deepfake labelling obligation been postponed by the Digital Omnibus?+

No. The postponement to 2 December 2026 only covers the machine-readable marking duty of providers, and only for systems on the market before 2 August 2026. The deployer's disclosure duty applies from 2 August 2026.

Does AI-generated text need labelling too?+

Only when it is published to inform the public on matters of public interest, and there is no human editorial control with editorial responsibility. An article reviewed by an employee and published under the organization's responsibility falls outside the disclosure duty.

What should the label look like?+

The law does not prescribe a form, but the disclosure must be clear and made at the latest at the first exposure. Workable forms are a caption or overlay for images, an announcement at the start of audio or video, and a statement directly next to the content. A sentence in your terms and conditions is not enough.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us