Deepfake Labeling: Obligations Under the EU AI Act 2026
Last updated on August 10, 2026 at 14:23 PM.Deepfake labelling refers to the legal obligation to declare AI-generated or AI-manipulated video, audio and image content as synthetic. The legal basis is Article 50 of the AI Act (EU AI Act), binding from 2 August 2026. Companies with high video-content volumes must label deepfakes, AI avatars and synthetic voices in a machine-readable format and visibly for users – non-compliance carries fines of up to EUR 15 million or 3% of global annual turnover. This article provides the legal definitions, specific labelling requirements, wording examples and the operational compliance steps content teams need now.

What is a deepfake under the AI Act?
Under Art. 3(60) of the AI Act, a deepfake is image, audio or video content generated or manipulated by an AI system that resembles real persons, places or events and could falsely appear to be authentic. The definition draws a clear line: obviously fictional content – a comic character, a fantasy landscape – is not covered. The decisive criterion is the potential for confusion with reality. For companies deploying AI avatars in explainer videos or synthetic voices for podcasts, this boundary is operationally relevant because it determines whether a labelling obligation applies or not.
Labelling is one half of the task; the internal governance behind it is the other. Companies producing AI-generated video content rely on tools whose data flows are rarely fully transparent to anyone – and that is precisely where the risk emerges that no one wants to own later. How to place AI deployment on a GDPR-compliant footing through audits, clear policies and secured integrations is outlined on the AI Governance and Compliance page from Crispy Content®. The underlying principle is the same as with deepfake labelling: a promise to users and regulators can only be kept if the processes behind it are documented and audited.
Deepfake vs. synthetic content – the distinction
Synthetic content is the umbrella term: any output generated by an AI system, whether text, image, audio or video. A deepfake is a subset – deceptively realistic and referencing real-world subjects. The distinction is not an academic exercise; it determines the scope of obligations. Art. 50(2) of the AI Act addresses synthetic content in general with a machine-readable marking requirement. Art. 50(4) tightens the rules for deepfakes: here, visible disclosure to the end user is added. AI avatars and synthetic voices fall under both categories as soon as they appear photorealistic or imitate existing persons.
Which content falls under the deepfake provision?
The regulation covers four core categories directly relevant to corporate communications:
- AI-generated videos featuring real persons: A training video in which a CEO "speaks" via AI, even though the recording is synthetic, meets the provision.
- Synthetic voices imitating existing speakers: Voice cloning of a brand ambassador for an advertising spot falls under the deepfake definition.
- Photorealistic AI images of real scenarios: An AI-generated product photo simulating a real factory floor is subject to labelling.
- AI avatars as human representatives: As soon as an avatar is designed so that an average viewer could mistake it for a real person, Art. 50(4) applies.
Article 50 AI Act: The transparency obligations in detail
Art. 50 distinguishes four sets of obligations: interactive AI systems (para. 1), synthetic content in general (para. 2), deepfakes in the narrow sense (para. 4, variant 1) and publicly relevant AI-generated text (para. 4, variant 2). For companies with video production, paragraphs 2 and 4 are the operationally decisive provisions. The obligations address two different parties – providers and deployers – each with their own requirements regarding technology and visibility.
Obligations for providers – machine-readable labelling
Providers of AI systems that generate synthetic content must mark their outputs as artificially generated in a machine-readable format. The technical solution must meet four criteria: effective, interoperable, robust and reliable. In practice, this means deploying standards such as C2PA Content Credentials or digital watermarks that survive compression, format conversion or screenshots. The European Commission explicitly references C2PA as the benchmark standard in the Code of Practice. Providers distributing video-generation tools or voice-cloning software bear this obligation regardless of how their customers use the outputs.
Obligations for deployers – visible disclosure to users
Deployers – companies that use AI tools and publish their outputs – must disclose deepfakes to the end user. The timing is clearly defined: no later than first perception of the content. The format must be clear, unambiguous and accessible. A hidden metadata entry alone is not sufficient for deployers; the label must be recognisable to the average user without technical aids. Anyone embedding an AI-generated video on a corporate website therefore needs both the machine-readable marking (supplied by the provider or added independently) and a visible on-screen notice.
Table: Provider vs. deployer obligations under Art. 50 AI Act
| Criterion | Provider (para. 2) | Deployer (para. 4) |
|---|---|---|
| Obligation | Machine-readable marking in the file format | Visible disclosure to end users |
| Addressee of the label | Downstream deployers and systems | End users and the public |
| Technical example | C2PA metadata during video generation | On-screen text "AI-generated content" on website |
Deploying AI avatars compliantly: Requirements for virtual presenters
An AI avatar can be deployed compliantly when three conditions are met simultaneously: labelling occurs before or at the first interaction, the avatar cannot be confused with a real person, and the technical marking is embedded in the file format. If any one of these three components is missing, a compliance risk arises. The control question every content team must answer before publication: Would an average viewer mistake this avatar for a real human?
When does an AI avatar qualify as a deepfake?
Classification follows a tiered model. If the avatar is modelled on a real person – such as the CEO or a well-known industry expert – the deepfake labelling obligation under Art. 50(4) applies without question. If the avatar is fictional but photorealistic, a grey area exists: the regulation refers to content that "could falsely appear to be authentic". In practice, labelling is advisable here because the risk of a regulatory classification as a deepfake far outweighs the effort of labelling. Stylised, obviously artificial avatars – for example with exaggerated proportions or comic aesthetics – do not fall under the provision.
Wording examples for AI avatar labelling
Three formats cover the most common use cases:
- Video intro: "The person in this video is an AI-generated avatar."
- Website overlay: "This presenter is entirely AI-generated."
- Metadata tag: C2PA Content Credential with the field
ai_generated: trueand identification of the generation system used.
The wording must be factual and unambiguous. Euphemisms such as "digitally assisted" or "virtually enhanced" do not meet the clarity requirement.
Labelling synthetic voices: Audio deepfakes in corporate communications
Synthetic voices – AI-generated speech outputs that imitate human voices or create entirely new ones – are subject to the labelling obligation under Art. 50(2) (providers) and Art. 50(4) (deployers) as soon as they are used in publicly accessible media. The obligation applies regardless of whether the voice imitates an existing person or uses a purely synthetic voice profile. The decisive factor is whether a listener could mistake the voice for a human one.
Deepfake audio: Legal requirements for podcasts, advertising and hotlines
Requirements vary by use case:
- Podcast with synthetic voice: An audible notice at the beginning of each episode plus labelling in the RSS feed metadata. The notice must precede the substantive content, not appear in the outro.
- Telephone hotline with AI voice: Art. 50(1) additionally applies here – the user must be informed before the conversation begins that they are interacting with an AI system.
- Advertising with a cloned celebrity voice: Dual obligation – deepfake labelling under Art. 50(4) and personality-rights consent from the affected person under national law.
Table: Deepfake threat landscape for enterprises
| Metric | Value | Source |
|---|---|---|
| Documented deepfake fraud cases 2025 (damages) | > USD 1.28 bn | Resemble AI Deepfake Threat Report 2025 |
| Organisations hit by at least one deepfake attack (2024/25) | 62% | Gartner Cybersecurity Leader Survey 2025 |
| Projected deepfake detection market volume 2026 | USD 15.7 bn | Liminal / Deloitte TMT Predictions 2025 |
Deepfake compliance: Fines, exemptions and documentation obligations
Violations of the transparency obligations under Art. 50 AI Act are sanctioned under Art. 99(4) with fines of up to EUR 15 million or 3% of global annual turnover – whichever is higher. The sanction level is thus on par with GDPR fines for serious infringements. Exemptions exist but are narrowly defined: they apply to artistic, satirical or fictional content and to content under documented editorial responsibility.
When does the labelling obligation not apply?
The regulation defines three exemptions:
- Obviously artistic, satirical or fictional works: A feature film with AI-generated special effects is not subject to the obligation, provided the fictional nature is recognisable to the audience.
- AI as an auxiliary function without material alteration: Spell-checking, automatic colour correction or noise reduction do not produce output requiring labelling.
- Editorial control with documented assumption of responsibility: For AI-generated texts, the obligation does not apply if a natural person assumes editorial responsibility and this is documented.
The exemptions are to be interpreted restrictively. "We editorially approved the video" is not sufficient – the documentation must demonstrate who performed which substantive review and when.
Documentation and internal processes for deepfake compliance
Compliance without process is coincidence. Three elements form the minimum:
- Central AI register: Every content system generating synthetic outputs is recorded with its purpose, output type and labelling status.
- Defined roles: An AI compliance lead within the content team decides on labelling obligations and verifies technical implementation before publication.
- Audit trail: For every unlabelled piece of content, documentation must record why an exemption applies – with reference to the specific exemption provision.
Table: Fine tiers under Art. 99 AI Act
| Infringement category | Maximum fine | Turnover reference |
|---|---|---|
| Prohibited AI practices (Art. 5) | EUR 35 million | 7% |
| High-risk obligations (Chapter III) | EUR 15 million | 3% |
| Transparency obligations (Art. 50) | EUR 15 million | 3% |
Deepfakes and reputation: Why reputation-sensitive industries are disproportionately affected
Industries with high public visibility face disproportionate risk from unlabelled or maliciously deployed deepfakes. 42.5% of all AI-powered fraud attempts target the financial sector. The risk is twofold: on one hand, third parties can weaponise deepfakes against a company – for example, a fabricated CEO statement that moves share prices. On the other hand, reputational damage arises when a company itself publishes synthetic content without labelling it and this becomes public.
68% of consumers fear deception through synthetic content. Proactive labelling is therefore not a pure compliance exercise but a trust signal. Transparently disclosing that an explainer video uses an AI avatar demonstrates control over one's own communications. Concealing it and getting caught demonstrates the opposite. The calculation is straightforward: the reputational damage from a public labelling violation exceeds the cost of implementation by orders of magnitude.
Table: Risk profile by industry
| Industry | Typical deepfake risk | Video-content volume |
|---|---|---|
| Financial services | CEO fraud, fabricated analyst statements | High (webinars, explainer videos) |
| Pharma / Healthcare | Fabricated study results, fake testimonials | Medium to high |
| Automotive / Luxury | Manipulated product presentations | Very high (campaigns, social media) |
Deepfake labelling for video-heavy companies: Implementing compliance in practice
Companies with high video-content volumes – 50 videos per quarter and above – need standardised workflows that embed labelling at the production stage. Retrofitting labels only at distribution creates error sources, duplication of effort and gaps. The production process itself must include the labelling step, just as an approval process includes the review step.
Technical implementation: Watermarks, metadata, overlay
Three layers of labelling work in concert:
- Machine-readable: C2PA Content Credentials are embedded in the file during video generation. They contain information about the AI system used, the time of creation and the content type.
- Visible: An on-screen text notice at the beginning of the video or a persistent overlay in the corner. The notice must remain on screen for at least three seconds and appear in a font size legible on the smallest common playback device.
- Audio: An audible notice before the substantive content begins plus a metadata tag in the audio stream.
Wording examples for different formats
- Video: "This video contains AI-generated content."
- Social media post with AI image: "Image created with the assistance of AI."
- Podcast: "Notice: This voice was synthetically generated."
The wording is deliberately short and factual. It describes the situation without editorialising. Creative paraphrases such as "created with digital magic" fail the unambiguity requirement.
Worked example: A company produces 200 videos per quarter. With EUR 50 million in annual turnover, the maximum fine exposure is EUR 1.5 million (3%). Implementing a C2PA workflow costs EUR 15,000–40,000 one-off plus EUR 2,000–5,000 per month for tooling. This yields an ROI on the compliance investment of 37× to 100× relative to the fine exposure. The numbers do not argue for waiting.
Table: Labelling formats at a glance
| Format | Machine-readable | User-visible | Suitable for |
|---|---|---|---|
| C2PA Content Credentials | Yes | No (only with tool support) | Video, image, audio |
| Visual overlay / watermark | No | Yes | Video, image |
| Audible notice | No | Yes | Audio, podcast |
| Metadata tag (EXIF/XMP) | Yes | No | Image, video |
Deepfake regulation 2026 and beyond: Trends and developments
The EU Code of Practice on Transparency of AI-Generated Content will specify the implementation of Art. 50 from 2026 onwards. The European AI Office is coordinating the drafting with input from providers, deployers and civil society. The Code of Practice is formally voluntary – but those who follow it can demonstrate in enforcement proceedings that their implementation reflects the state of the art. Those who ignore it bear the burden of proof themselves.
Four developments are emerging:
- Code of Practice as de facto standard: What begins as a voluntary instrument becomes the benchmark through regulatory practice. Comparable to GDPR certification, which is formally voluntary but practically expected.
- Deepfake detection as a cybersecurity discipline: The market for detection tools is growing at 42% annually. Companies will integrate deepfake detection into their security stacks, not just their content workflows.
- Tightening rules for real-time deepfakes: Live streaming and video conferencing with synthetic participants are the next regulatory focus. Technical labelling in real time remains unsolved – further regulation will follow.
- Convergence with the DSA and national media laws: The Digital Services Act already obliges platforms to label AI-generated content. The AI Act supplements this obligation on the generator and deployer side. National media laws will follow.
A documented deepfake compliance strategy protects both reputation and budget. Companies that prefer not to build the implementation in-house can develop it with a specialist communications agency such as Crispy Content®.
Table: AI Act timeline – relevant deadlines
| Date | Obligation | Affected parties |
|---|---|---|
| 2 February 2025 | Prohibited AI practices (Art. 5) | All |
| 2 August 2025 | GPAI model obligations (Chapter V) | Providers of foundation models |
| 2 August 2026 | Transparency obligations (Art. 50) | Providers + deployers of AI systems |
Deepfake labelling as a strategic obligation for video-content companies
The deepfake labelling obligation under Art. 50 AI Act is not a legal formality but an operational intervention in content production and distribution. The mechanics are clear: machine-readable marking plus visible disclosure, documented in an internal register, owned by a defined role. Companies with high video-content volumes that implement standardised processes now avoid fines of up to EUR 15 million, protect their brand reputation and position themselves as trustworthy to stakeholders. Methods deliver guarantees – here too.
Sources
European Parliament / Council of the EU (2024): Regulation (EU) 2024/1689 (AI Act), Article 50 – Transparency obligations for providers and deployers of certain AI systems. URL: https://artificialintelligenceact.eu/de/article/50/ (accessed 20 July 2026).
European Commission (2026): Code of Practice on Transparency of AI-Generated Content. URL: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content (accessed 20 July 2026).
HÄRTING Rechtsanwälte (2025): Transparenzpflichten in der KI-Verordnung (Art. 50): KI-Inhalte richtig kennzeichnen. URL: https://haerting.de/wissen/transparenzpflichten-in-der-ki-verordnung/ (accessed 20 July 2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.