EU AI Act Article 50: Deepfake Labelling Obligations Explained
Article 50 of the EU AI Act sets transparency obligations for AI systems that interact with people or generate content, requiring machine-readable marking of synthetic media and clear disclosure of deepfakes. The obligations apply from 2 August 2026, with a limited deferral to 2 December 2026 for certain generative systems already on the market. Penalties reach EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
The rules are now live. What follows is what they actually require.
Key takeaways
- Article 50 covers four situations: direct interaction with a person, AI-generated content, emotion recognition and biometric categorisation, and deepfakes and AI-generated text on matters of public interest.
- Obligations split between providers (mark the output) and deployers (disclose the use).
- Deepfake disclosure applies regardless of intent to deceive.
- Compliance is expected to be multi-layered: machine-readable marking plus visible disclosure, not one or the other.
- The Commission's guidelines and an accompanying code of practice complete the guidance framework.
The four triggers
| Trigger | Who is obliged | What is required |
|---|---|---|
| A person interacts directly with an AI system | Provider | The person must be informed they are interacting with AI, unless it is obvious from context |
| An AI system generates synthetic audio, image, video or text | Provider | Output marked in a machine-readable format and detectable as artificially generated |
| Emotion recognition or biometric categorisation is used | Deployer | Exposed individuals must be informed of the system's operation |
| Content is a deepfake, or AI-generated text published on matters of public interest | Deployer | Disclosure that the content is artificially generated or manipulated |
The most common compliance failure will be at the boundary between rows two and four. A provider marks the output cryptographically. A deployer publishes it. The marking satisfies the provider's obligation and does nothing for the deployer's, because a machine-readable watermark is not a disclosure to a human reader. Both obligations must be discharged.
What "multi-layered" means in practice
Guidance published in mid-2026 signalled that a layered approach is the working standard. In practice that means three layers, each doing something the others cannot.
- Embedded marking. Watermarks, cryptographic signatures or provenance metadata travelling with the file. Machine-readable, survives redistribution to varying degrees, invisible to the reader.
- Visible disclosure. A label a human actually sees, at the point of consumption. Not buried in terms of service, not in a footer, not only in metadata.
- Organisational process. Internal procedures, staff literacy, review mechanisms and feedback paths. Deployers are expected to have a process, not just a label.
The third layer is where most organisations are least prepared, and it is explicitly named. Article 50 compliance is not purely a technical control. It requires demonstrable process.
The provenance problem underneath
Content marking answers "was this generated by AI." It does not answer the question that usually matters more: who published this, and are they who they claim to be.
A labelled deepfake is still a deepfake. Disclosure lets an informed reader discount it. It does not help a person deciding whether the video call they are on is with their actual colleague, or whether the account posting an announcement genuinely represents the organisation named.
Content provenance and identity provenance are two halves of the same problem and they are being solved on separate timetables. Article 50 addresses the first. The second sits with identity infrastructure.
The pairing that closes the gap is straightforward to state: a piece of content carries a provenance marker indicating how it was produced, and a verifiable credential indicating who published it. The reader can then evaluate both the artefact and the source. Neither signal is sufficient alone.
AIR Identity addresses the second half. Publishers, platforms and organisations can establish verifiable identity for the entities behind content, with zero-knowledge verification so the assertion is confirmed without exposing underlying data. For publishers and communities, where impersonation directly damages the asset being monetised, source verification is a commercial control as much as a compliance one.
Practical steps for organisations in scope
Determine whether you are a provider, a deployer, or both. Many organisations are both, for different systems, and the obligations differ. Map this before designing controls.
Audit every user-facing AI touchpoint. Chat interfaces, support automation, generated imagery, synthetic voice, AI-assisted editorial. Each is a potential Article 50 trigger.
Check that disclosure is actually visible. A machine-readable mark is not a disclosure to a human. If a reasonable reader would not notice the label, it is unlikely to satisfy the obligation.
Document the process, not just the output. Review mechanisms, staff literacy measures and feedback paths are named expectations. They need to exist and be evidenced.
Treat the December 2026 deferral as narrow. It applies to certain generative systems already on the market. It is not a general extension.
Frequently asked questions
When does EU AI Act Article 50 apply?
Article 50 transparency obligations apply from 2 August 2026. A limited deferral to 2 December 2026 exists for certain generative AI systems already placed on the market before the application date.
What are the penalties for breaching Article 50?
Infringements of the transparency obligations can attract fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.
Do deepfake rules apply without intent to deceive?
Yes. The disclosure obligation attaches to the nature of the content, not to the purpose behind it. Satire, entertainment and artistic uses are still in scope, though the form the disclosure takes may be adapted where it would otherwise undermine the work.
What counts as a deepfake under the AI Act?
AI-generated or AI-manipulated image, audio or video content that resembles real persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
Does Article 50 apply to organisations outside the EU?
Yes, where the AI system is placed on the EU market or its output is used in the EU. Establishment outside the Union does not remove the obligation.
Related reading
- Proof of human: bot detection at the login layer
- Government digital credentials in 2026
- Why biometrics alone are no longer enough
More from AIR: AIR Identity, publisher monetisation, or browse the full AIR blog.
Working on content authenticity and source verification together? See how AIR Identity establishes verifiable identity for the entities behind content, or talk to our team.




.png)