News

EU AI Act Article 50: Deepfake Labelling Obligations Explained

Moca Network
August 23, 2026

Article 50 of the EU AI Act sets transparency obligations for AI systems that interact with people or generate content, requiring machine-readable marking of synthetic media and clear disclosure of deepfakes. The obligations apply from 2 August 2026, with a limited deferral to 2 December 2026 for certain generative systems already on the market. Penalties reach EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.

The rules are now live. What follows is what they actually require.

Key takeaways

  • Article 50 covers four situations: direct interaction with a person, AI-generated content, emotion recognition and biometric categorisation, and deepfakes and AI-generated text on matters of public interest.
  • Obligations split between providers (mark the output) and deployers (disclose the use).
  • Deepfake disclosure applies regardless of intent to deceive.
  • Compliance is expected to be multi-layered: machine-readable marking plus visible disclosure, not one or the other.
  • The Commission's guidelines and an accompanying code of practice complete the guidance framework.

The four triggers

TriggerWho is obligedWhat is required
A person interacts directly with an AI systemProviderThe person must be informed they are interacting with AI, unless it is obvious from context
An AI system generates synthetic audio, image, video or textProviderOutput marked in a machine-readable format and detectable as artificially generated
Emotion recognition or biometric categorisation is usedDeployerExposed individuals must be informed of the system's operation
Content is a deepfake, or AI-generated text published on matters of public interestDeployerDisclosure that the content is artificially generated or manipulated

The most common compliance failure will be at the boundary between rows two and four. A provider marks the output cryptographically. A deployer publishes it. The marking satisfies the provider's obligation and does nothing for the deployer's, because a machine-readable watermark is not a disclosure to a human reader. Both obligations must be discharged.

What "multi-layered" means in practice

Guidance published in mid-2026 signalled that a layered approach is the working standard. In practice that means three layers, each doing something the others cannot.

  1. Embedded marking. Watermarks, cryptographic signatures or provenance metadata travelling with the file. Machine-readable, survives redistribution to varying degrees, invisible to the reader.
  2. Visible disclosure. A label a human actually sees, at the point of consumption. Not buried in terms of service, not in a footer, not only in metadata.
  3. Organisational process. Internal procedures, staff literacy, review mechanisms and feedback paths. Deployers are expected to have a process, not just a label.

The third layer is where most organisations are least prepared, and it is explicitly named. Article 50 compliance is not purely a technical control. It requires demonstrable process.

The provenance problem underneath

Content marking answers "was this generated by AI." It does not answer the question that usually matters more: who published this, and are they who they claim to be.

A labelled deepfake is still a deepfake. Disclosure lets an informed reader discount it. It does not help a person deciding whether the video call they are on is with their actual colleague, or whether the account posting an announcement genuinely represents the organisation named.

Content provenance and identity provenance are two halves of the same problem and they are being solved on separate timetables. Article 50 addresses the first. The second sits with identity infrastructure.

The pairing that closes the gap is straightforward to state: a piece of content carries a provenance marker indicating how it was produced, and a verifiable credential indicating who published it. The reader can then evaluate both the artefact and the source. Neither signal is sufficient alone.

AIR Identity addresses the second half. Publishers, platforms and organisations can establish verifiable identity for the entities behind content, with zero-knowledge verification so the assertion is confirmed without exposing underlying data. For publishers and communities, where impersonation directly damages the asset being monetised, source verification is a commercial control as much as a compliance one.

Practical steps for organisations in scope

Determine whether you are a provider, a deployer, or both. Many organisations are both, for different systems, and the obligations differ. Map this before designing controls.

Audit every user-facing AI touchpoint. Chat interfaces, support automation, generated imagery, synthetic voice, AI-assisted editorial. Each is a potential Article 50 trigger.

Check that disclosure is actually visible. A machine-readable mark is not a disclosure to a human. If a reasonable reader would not notice the label, it is unlikely to satisfy the obligation.

Document the process, not just the output. Review mechanisms, staff literacy measures and feedback paths are named expectations. They need to exist and be evidenced.

Treat the December 2026 deferral as narrow. It applies to certain generative systems already on the market. It is not a general extension.

Frequently asked questions

When does EU AI Act Article 50 apply?

Article 50 transparency obligations apply from 2 August 2026. A limited deferral to 2 December 2026 exists for certain generative AI systems already placed on the market before the application date.

What are the penalties for breaching Article 50?

Infringements of the transparency obligations can attract fines of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher.

Do deepfake rules apply without intent to deceive?

Yes. The disclosure obligation attaches to the nature of the content, not to the purpose behind it. Satire, entertainment and artistic uses are still in scope, though the form the disclosure takes may be adapted where it would otherwise undermine the work.

What counts as a deepfake under the AI Act?

AI-generated or AI-manipulated image, audio or video content that resembles real persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

Does Article 50 apply to organisations outside the EU?

Yes, where the AI system is placed on the EU market or its output is used in the EU. Establishment outside the Union does not remove the obligation.

Related reading

More from AIR: AIR Identity, publisher monetisation, or browse the full AIR blog.

Working on content authenticity and source verification together? See how AIR Identity establishes verifiable identity for the entities behind content, or talk to our team.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Proof of Human: Why Bot Detection Moved to the Login Layer in 2026
Governments are now procuring technology to block automated agentic AI at sign-in. Proof of human has become an authentication requirement, not a research topic.
News
Age Assurance Accuracy Standards: The 2026 Benchmarks Explained
Age assurance now has measurable accuracy targets: a 10% under-18 false-positive ceiling for 16-17 year olds and 3% for 13-15. What the benchmarks mean for platforms.
News
Government Digital Credentials in 2026: Birth Records, ID Cards and Wallets
The first US digital birth credential, a new European biometric ID card and a merged national identity app all landed in one week. What state issuance means for platforms.