EU AI Act Deepfake Rules: What You Must Do Now (Live Since August 2, 2026)
As of August 2, 2026, the EU AI Act deepfake rules are no longer a forecast: they start being enforceable law. From that date, businesses that use generative AI to create or publish realistic synthetic media for an EU audience must disclose it, and the companies that build generative systems must mark their outputs so machines can detect them. The May 2026 Digital Omnibus moved other AI Act deadlines. It did not move this one. Here is exactly what deployers and providers must do, who is exempt, and what non-compliance costs.
- What Changed on August 2, 2026
- Deployer Duties: Label Your Deepfakes (Article 50(4))
- Provider Duties: Machine-Readable Marking (Article 50(2))
- The Code of Practice, EU Labeling Icons, and Signatories
- Penalties for Breaking the Deepfake Rules
- Who Is Exempt From the EU AI Act Deepfake Rules
- Deepfake Compliance Checklist
- How the EU Rules Compare Globally
- Where Detection Fits
- FAQ
- Conclusion: The Rules Are Live

Disclaimer: This article is general legal information, not legal advice. Last reviewed: August 30, 2026, against the official EU sources cited below. How the rules apply depends on your role, your content, and your facts. If you operate in or sell into the EU, consult a qualified lawyer.
The question every compliance, marketing, and trust team is asking right now is simple: what do we actually have to do before August 2, 2026? The answer depends on whether you use generative AI (a deployer) or build it (a provider), and most organizations that publish AI content are deployers. This guide leads with the deployer duties, then covers providers, the new Code of Practice and EU labeling icons, penalties, and exemptions.
Quick answer: From August 2, 2026, anyone using AI to create or publish a deepfake in the EU must clearly disclose that it is artificially generated or manipulated, and providers of generative AI systems must mark outputs in a machine-readable, detectable way. Breaches can draw fines of up to 15,000,000 EUR or 3% of worldwide turnover.
What Changed on August 2, 2026
The transparency obligations in Article 50 of the AI Act become applicable on 2 August 2026. That is the date the deepfake disclosure duty, the AI-text disclosure duty, the chatbot disclosure duty, and the synthetic-content marking duty all take legal effect, per the application schedule in Regulation (EU) 2024/1689 on EUR-Lex.
One point of confusion is worth killing immediately. The Digital Omnibus package, politically agreed in May 2026, postponed the AI Act's high-risk system deadlines. It did not delay Article 50. The only Article 50 relief in the Omnibus is narrow: generative AI systems already on the market before 2 August 2026 get until 2 December 2026 to meet the machine-readable marking duty in Article 50(2). Every other Article 50 obligation, including the deployer duty to label deepfakes, applies from 2 August 2026.
| Milestone | Date | Status |
|---|---|---|
| AI Act entry into force | 1 August 2024 | In force |
| Prohibited practices apply | 2 February 2025 | In force |
| GPAI model obligations apply | 2 August 2025 | In force |
| Draft Commission guidelines on Article 50 scope | 8 May 2026 | Published (final due before 2 August 2026) |
| Final Code of Practice on Transparency of AI-Generated Content | 10 June 2026 | Published |
| Initial Code of Practice signatory list | 22 July 2026 | Deadline |
| Article 50 transparency obligations apply | 2 August 2026 | Upcoming |
| Marking grace period ends for generative systems already on the market | 2 December 2026 | Upcoming |
| High-risk system obligations | Postponed by the May 2026 Digital Omnibus | Rescheduled |
Deployer Duties: Label Your Deepfakes (Article 50(4))
If your organization uses an AI system to generate or manipulate content, you are a deployer, and Article 50(4) is your obligation. It requires you to disclose that deepfake content has been artificially generated or manipulated.
How the Act Defines a Deepfake
Article 3(60) of the Regulation defines a deep fake as AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful, per the official text on EUR-Lex. Three things matter: the content is made or altered by AI, it resembles something real, and an ordinary viewer could take it for genuine. For a general primer on the technology, see our explainer on what a deepfake is.
The Disclosure Itself
The duty applies even when there is no intent to deceive. The test is whether the content as a whole would falsely appear authentic, not what the maker meant by it. In practice, deployers meet the duty with a clear, visible label: an on-screen tag, a caption, an overlay, or a stated disclosure, provided at the latest when a person is first exposed to the content. The EU has published official labeling icons that deployers may use (see the Code of Practice section below).
For evidently artistic, creative, satirical, fictional, or analogous work, Article 50(4) applies a lighter regime: the existence of the generated or manipulated content still has to be disclosed, but in a way that does not hamper the display or enjoyment of the work. That is a lighter placement rule, not an exemption. More on this in the exemptions section.
AI-Generated Text
Deployers also carry a disclosure duty for AI-generated or manipulated text published to inform the public on matters of public interest. There is an exception where the text has undergone human review or editorial control and a person or organization holds editorial responsibility for publication. The final Code of Practice covers labeling of AI text in its deployer section.
Provider Duties: Machine-Readable Marking (Article 50(2))
If you build or supply an AI system that generates synthetic audio, image, video, or text, Article 50(2) requires you to ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This is the invisible layer of the regime: watermarks, signed metadata, and content provenance credentials that machines can read even when a human sees no label.
The Act asks that marking solutions be effective, interoperable, robust, and reliable as far as technically feasible, taking the state of the art into account. The Code of Practice's provider section details accepted marking and detection techniques.
The one deadline nuance: under the May 2026 Digital Omnibus agreement, generative AI systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with this marking duty. New systems entering the market from 2 August 2026 must comply immediately, and the deployer labeling duty is not deferred for anyone.
The Code of Practice, EU Labeling Icons, and Signatories
On 10 June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content. It is the practical playbook for Article 50 and has two sections:
- Providers: how to mark synthetic outputs and make them detectable under Article 50(2).
- Deployers: how to label deepfakes and AI-generated text under Article 50(4).
The Commission and the AI Board issued an opinion confirming the Code as an adequate voluntary tool for demonstrating compliance with the Article 50 obligations. Signing is voluntary, but signatories get a recognized route to showing they meet the rules; the initial signatory list closes on 22 July 2026.
Alongside the Code, the EU published official icons for labeling AI-generated content that deployers may use to satisfy the visible-disclosure duty in a consistent, recognizable way. Using the EU icons is optional, but they are the closest thing to a safe-harbor label design that currently exists.
Also in flight: the Commission's guidelines on the scope of Article 50, which interpret terms like deep fake and evidently artistic. A draft was published on 8 May 2026, and the final version is due before 2 August 2026. Check the final guidelines before locking your compliance approach.
Penalties for Breaking the Deepfake Rules
Article 99(4) sets the penalty for breaching the Article 50 transparency obligations: administrative fines of up to 15,000,000 EUR or, for companies, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, per the regulation text on EUR-Lex.
Two points keep this in perspective. First, for small and medium-sized enterprises, including start-ups, the fine is capped at the lower of the percentage or the fixed amount, not the higher. Second, the transparency duties sit in a middle penalty tier; the Act's heaviest fines, up to 35,000,000 EUR or 7% of turnover, are reserved for prohibited practices, not labeling failures. Enforcement practice is brand new, so we make no predictions about how national authorities will apply these figures.
Who Is Exempt From the EU AI Act Deepfake Rules
Fewer people than the headlines suggest. The main carve-outs and nuances:
- Art, satire, parody, and fiction: a lighter disclosure regime, not an exemption. The synthetic nature still has to be disclosed, but the disclosure can be placed so it does not spoil the work. A parody video can carry its label in the description rather than stamped across the frame.
- Purely personal, non-professional use: the AI Act's scope excludes natural persons using AI in a purely personal, non-professional activity. The nuance is publication: editing a photo for your own album is one thing; publishing realistic synthetic media to an audience can make you a deployer. If you are publishing, assume the rules can reach you.
- Editorially reviewed AI text: AI-assisted text escapes the text-disclosure duty where it has undergone human review or editorial control and someone holds editorial responsibility for publication.
- Clearly unrealistic content: content that no ordinary person would take for authentic, such as obvious fantasy scenes, generally falls outside the deep fake definition in the first place.
The boundaries of evidently artistic and of the personal-use exclusion are exactly what the Commission's final Article 50 guidelines are expected to sharpen before 2 August 2026, so treat edge cases as open until then.
Deepfake Compliance Checklist
A practical sequence for teams that publish or process AI-generated content for EU audiences:
Map your role
Determine whether you are a provider, a deployer, or both, for each AI system you build or use. Most businesses using generative AI tools are deployers.
Document your generative AI systems
Inventory every tool that generates or manipulates image, audio, video, or text in your workflows, and note which outputs reach EU audiences.
Label deepfakes visibly
Add a clear disclosure at or before first exposure for any realistic synthetic media you publish. Consider the official EU labeling icons for consistency.
Keep marking metadata intact
Do not strip watermarks, provenance credentials, or signed metadata in your editing, compression, or publishing pipeline. Provider-side marks only work if deployers preserve them.
Verify content you receive and publish
Labels only cover the compliant. Screen inbound and user-submitted media so you are not amplifying unlabeled synthetic content.
Track the final guidance
The Commission's final Article 50 guidelines land before 2 August 2026, and the Code of Practice will evolve. Assign someone to re-check quarterly.
How the EU Rules Compare Globally
The EU is not alone; it is joining a fast-forming global norm of labeling synthetic content, though each regime cuts differently.
| Jurisdiction | In effect | Core duty |
|---|---|---|
| EU (AI Act Article 50) | 2 August 2026 | Deployers label deepfakes and AI text; providers mark outputs machine-readably |
| China (CAC labeling rules) | 1 September 2025 | Explicit and implicit labels on publicly distributed AI-generated content |
| United States (TAKE IT DOWN Act) | Enforced since 19 May 2026 (FTC) | Platforms must remove non-consensual intimate imagery, including AI-generated, within 48 hours |
| India (IT Rules amendment) | 20 February 2026 | Mandatory labeling of synthetic content on intermediaries |
Note the structural difference: the EU and China impose a general transparency duty on synthetic content, while US federal law targets specific harms and leaves no general labeling duty, layered over a patchwork of state statutes. For the US picture, see our guides on whether deepfakes are illegal and deepfake laws by state. A single piece of content can trigger EU disclosure duties and US harm-based liability at the same time.
Where Detection Fits
Be clear about what Article 50 does and does not do. It makes providers mark synthetic content and deployers label it. It does not make anyone verify media, and no detection tool makes you Article 50 compliant on its own. Compliance is labeling your own output and preserving marks; that part is on you.
Detection matters for the other side of the equation: the content you receive. Disclosure rules bind the compliant, and bad actors do not label, and watermarks get stripped. Newsrooms, platforms, and businesses that publish or act on third-party media still have to answer "is this real" for files that arrive with no marks at all. That is where verification tools fit into an Article 50 era workflow: as the check on inbound media that labeling regimes assume but cannot enforce. Our guide to how deepfake detection works covers the methods in depth.
DeepfakeDetector.ai returns a whole-file verdict of Authentic, Likely Synthetic, or Inconclusive, paired with a TrustScore from 0 to 100, across image, video, and audio. It is a verification signal for your review process, not a compliance certificate.
FAQ
Does the EU AI Act ban deepfakes?
No. The Act does not prohibit deepfakes; it requires that they be disclosed as artificially generated or manipulated under the Article 50 transparency rules in force since 2 August 2026.
Did the Digital Omnibus delay the deepfake rules?
No. The May 2026 Digital Omnibus agreement postponed high-risk deadlines but did not delay Article 50. The one carve-out: generative systems already on the market before 2 August 2026 get until 2 December 2026 to meet the machine-readable marking duty in Article 50(2).
Who must label deepfakes under the AI Act?
Deployers who use AI to create or publish deepfakes must provide a visible disclosure, and providers of generating systems must mark synthetic outputs in a machine-readable, detectable way.
Are memes and parody exempt from the AI Act deepfake rules?
Not fully. Evidently artistic, satirical, or fictional work gets a lighter disclosure obligation that should not spoil the work, but the content still has to be disclosed as synthetic.
What is the penalty for not labeling a deepfake?
Breaching the Article 50 transparency duties can draw administrative fines of up to 15,000,000 EUR or up to 3% of worldwide annual turnover, whichever is higher, under Article 99(4).
Does the EU AI Act apply to US companies?
Yes, if the output reaches people in the EU. The Act applies to providers and deployers outside the EU when their AI system's output is used in the EU market.
Conclusion: The Rules Are Live
The EU AI Act deepfake rules apply from 2 August 2026, and the Digital Omnibus did not move them. Deployers label deepfakes and AI text visibly, providers mark outputs machine-readably (with a grace period to 2 December 2026 only for systems already on the market), the Code of Practice and EU icons give both sides a recognized playbook, and Article 99(4) backs it all with fines of up to 15,000,000 EUR or 3% of turnover. The remaining moving part is the Commission's final Article 50 guidelines, due before the deadline, so keep your edge cases flexible and your review date in the calendar.
This article is general information, not legal advice. Last reviewed July 14, 2026; provisions and dates cited were verified against EUR-Lex and the European Commission at that date. Scheduled for re-review by October 2026.