BINAIBINAI

EU AI Act Content Labelling: Deepfake and AI Rules

· 10 min read · BINAI Editorial Team

What does the EU AI Act say about labelling AI-generated content?

The EU AI Act requires two things for AI-generated content: AI tools must mark their output in a machine-readable way, and anyone who publishes a deepfake in a professional context must clearly tell people it is artificial. Both duties sit in Article 50 of the AI Act and have applied since 2 August 2026, with a short grace period for marking that ends on 2 December 2026.

For a small business or creator, the practical question is narrower than it sounds. You are not required to stamp "AI" on every image you make. You are required to disclose realistic synthetic content that could fool people into thinking it is real, and the tools you use are required to embed hidden signals that help platforms detect AI output. This guide explains who has to do what, as of October 2026, and how the EU's voluntary code of practice fits in. For the wider picture of copyright, ads and likeness rights, see our guide to whether AI-generated content is legal.

Who has to do what under Article 50?

The AI Act splits duties between "providers" and "deployers". A provider is the company that develops an AI system and puts it on the market under its own name, such as a video model maker. A deployer is a person or organisation that uses an AI system under its own authority, except for purely personal, non-professional use.

If you run a shop, an agency or a monetised channel and you publish AI content, you are almost always a deployer. Here is how Article 50 divides the work:

Duty Who What it means in practice
Tell people they are talking to an AI (50(1)) Providers of chatbots and interactive AI A chatbot must say it is an AI unless that is obvious
Machine-readable marking (50(2)) Providers of generative AI Audio, image, video and text output carries a detectable mark, such as a watermark or metadata
Disclose deepfakes (50(4)) Deployers Your realistic AI content showing real-looking people, places or events must be disclosed
Label AI text on public-interest matters (50(4)) Deployers AI text published to inform the public needs a label unless a human reviewed it and someone holds editorial responsibility

Article 50(5) adds that the information must be given "in a clear and distinguishable manner" at the latest at the first interaction or exposure, and must meet accessibility requirements.

What counts as a deepfake under the AI Act?

A deepfake, in the AI Act's definition, is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The test is realism plus the risk of being mistaken for the real thing.

Some examples help:

  • A realistic AI video of a "customer" talking about your product is likely a deepfake.
  • A photo of your real product edited so it looks bigger or shinier than it is falls in the same zone.
  • A cloned voice of a real person saying something they never said clearly qualifies.
  • A flat cartoon explainer or an obviously fantastical scene is generally not a deepfake, because no one would take it as authentic.

The Commission's final guidelines on Article 50, published on 20 July 2026, go further on advertising. According to a summary by law firm Faegre Drinker, the guidelines list AI-generated marketing content that makes products appear different from reality, digital replicas of real persons and de-aging of actors as deepfakes that require disclosure. That matters for anyone making AI UGC-style ads or product videos.

Is there an exception for creative or artistic content?

Yes, but it is a softer label rather than no label. When a deepfake is part of an evidently artistic, creative, satirical, fictional or similar work, the disclosure obligation is limited to revealing that generated or manipulated content exists "in an appropriate manner that does not hamper the display or enjoyment of the work".

In practice, a short film, a music video or a parody can carry a discreet disclosure, for example in the opening or closing credits, instead of a permanent badge on screen. According to the same Faegre Drinker summary, the guidelines treat this exception narrowly for advertising: most ad examples still need a standard disclosure, and only genuinely "creative" advertising may use the lighter form.

When do the Article 50 rules apply after the Digital Omnibus?

The rules apply from 2 August 2026. The Digital Omnibus on AI, an amending regulation adopted by the Council on 29 June 2026 and in force since 27 July 2026, changed several AI Act deadlines but left the Article 50 duties essentially in place.

Here is the timeline as of October 2026:

  1. 2 August 2026: all Article 50 duties apply, including deployers' deepfake labelling and providers' marking for new systems.
  2. 2 December 2026: end of the grace period for machine-readable marking by generative AI systems that were already on the market before 2 August 2026. The Commission's quick-facts page describes this as a "grace period for marking obligation until December 2026".
  3. 2 December 2026: a new prohibition added by the Omnibus also applies, banning AI systems used to generate non-consensual intimate content of real people and child sexual abuse material.
  4. 2 December 2027 and 2 August 2028: the postponed dates for high-risk AI rules. These do not affect content labelling.

The Commission's original Omnibus proposal had suggested a longer marking grace period; the final text settled on 2 December 2026. That extra time only concerns providers' marking of output from existing tools. It does not delay your duty to disclose deepfakes.

On content made before 2 August 2026, the Commission's quick-facts page says there is "no mandatory retroactive labelling but encouraged".

What is the EU code of practice on marking and labelling AI content?

The Code of Practice on Transparency of AI-generated Content is a voluntary rulebook that shows providers and deployers how to meet Article 50(2) and 50(4). The Commission published the final version on 10 June 2026. It was drafted by six independent experts with input from more than 180 stakeholders.

The code has two sections:

  • Section 1, providers: how to mark AI-generated or manipulated audio, images, video and text in a machine-readable way so it can be detected.
  • Section 2, deployers: how to clearly label deepfakes and AI-generated text published on matters of public interest without human review or editorial control.

The EU has also created a set of icons that deployers may use to label AI-generated content. The Commission's quick-facts page refers to three optional EU icons. According to the Faegre Drinker summary, the code points deployers to the standard icon placed at first exposure for images and video, and to a spoken or written disclaimer for audio-only formats where a visual label is impractical.

What is the status of the code as of October 2026?

As of October 2026, the code is final, assessed as adequate and widely signed:

  • Adequacy: the Commission and the AI Board confirmed in July 2026 that the code is an adequate voluntary tool to demonstrate compliance. Businesses that sign and follow it can rely on it to show they meet the relevant Article 50 duties.
  • Signatories: the Commission reported on 31 July 2026 that about 190 organisations had signed. Provider signatories include Anthropic, Google, Meta, Microsoft, Mistral, OpenAI and Synthesia; deployer signatories include Getty Images, Lenovo and Lufthansa. About half of the signatories are small, recent companies.
  • Guidelines: the Commission's guidelines on Article 50, published on 20 July 2026, clarify scope and definitions and complement the code.
  • Next steps: signatory task forces were announced from September 2026 to share practices on marking and labelling.

Signing is open to providers and deployers covered by Article 50(2) or 50(4), and a senior executive with binding authority must sign the form. Signing is optional; the legal duties apply either way.

Does the AI Act apply to my business if I am outside the EU?

It can. Article 2 extends the AI Act to providers and deployers located outside the EU "where the output produced by the AI system is used in the Union". If you are a US or UK business running realistic AI ads aimed at EU customers, treat the deepfake labelling rule as applying to those ads.

The Act does not cover people using AI for purely personal, non-professional purposes. A private person posting an AI meme from their personal account is outside the deployer duties; a business account promoting products is not.

How do I label AI content to comply with Article 50?

You do not need a lawyer to set up a sensible routine. These steps follow the structure of Article 50 and the code:

  1. Sort your content. For each piece, ask whether it is realistic and could be taken as real footage, a real voice or a real photo. If yes, treat it as a deepfake. If it is clearly stylised, a label is generally not legally required.
  2. Label at first exposure. Put the disclosure where people see it first: on the image or in the first seconds of the video, not only in a caption people may never expand. The EU icons are an option.
  3. Use the platform tools too. YouTube, TikTok, Instagram and Facebook all have AI labels. Using them helps with both the law and platform rules; see how to disclose AI content on each platform.
  4. Keep the hidden marks. Do not strip watermarks or metadata that your AI tool adds. They are part of how the system is meant to work, and platforms read them.
  5. Check AI text on public topics. If you publish AI-written news-style text, have a person review it and take editorial responsibility, or label it.
  6. Never use a label to excuse a false claim. A label tells people the content is synthetic; it does not make a misleading ad lawful. Consumer-protection rules still apply.

When you make realistic scenes or swap faces in a tool like BINAI's Character swap, plan the disclosure before you publish rather than after a complaint.

What happens if you do not label a deepfake?

Each EU country appoints market surveillance authorities to enforce the AI Act. Breaches of the Article 50 transparency duties can lead to fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs, including start-ups, the cap is whichever of the two is lower, and the Commission notes that proportionality applies.

Beyond fines, missing labels can break platform rules. YouTube, TikTok and Meta can add their own labels, remove content or apply penalties when creators fail to disclose realistic AI media.

How do the EU rules compare with the US and UK?

The EU is the only one of the three with a general legal duty to label deepfakes. In the US, there is no federal AI labelling law; the Federal Trade Commission instead applies its rules against deceptive advertising and fake reviews. In the UK, the advertising regulator says there is no blanket legal requirement to disclose AI in ads, but an ad must not mislead. Our article on FTC rules for AI ads, endorsements and reviews covers both.

If you make explainer videos, note that stylised animation is usually outside the deepfake definition, while realistic recreations of real events are not. Our guide to animated explainer videos with AI explains how to plan scenes with that in mind.

This article is general information, not legal advice; for a specific case talk to a lawyer in your country.

Check before you post with BINAI

BINAI makes images, videos and music that stay editable piece by piece, and its check before posting looks for content that breaks a platform rule or uses material without permission. It lowers the risk, but labelling decisions under the AI Act remain yours. Try it at app.binai.it.

Sources

Frequently asked questions

When did the EU AI Act labelling rules start to apply?

The Article 50 transparency duties apply from 2 August 2026. The Digital Omnibus on AI did not postpone them. It only gave providers of generative AI systems already on the market before 2 August 2026 extra time, until 2 December 2026, to add machine-readable marking to their outputs.

Do I have to label every AI image I post in the EU?

No. The labelling duty for businesses covers deepfakes, meaning realistic AI content that resembles real people, places, objects or events and could pass as authentic, plus AI text on matters of public interest without human editorial control. Obviously artificial content, such as a cartoon, generally is not a deepfake.

Is the EU code of practice on AI content labelling mandatory?

No, it is voluntary. The Commission and the AI Board assessed it as adequate in July 2026, so signatories can use it to show they comply with Article 50. Businesses that do not sign still have to meet the legal obligations in some other way.

Does the AI Act apply to businesses outside the EU?

Yes, it can. Article 2 extends the Act to providers and deployers located outside the EU when the output of their AI system is used in the Union. A US shop running deepfake-style ads aimed at EU customers should assume the labelling rules apply to those ads.

What are the fines for breaking Article 50?

Breaches of the Article 50 transparency duties can lead to fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For small and medium-sized businesses the lower of the two amounts applies. National market surveillance authorities enforce the rules.