Updated on 10 July 2026

Deepfake Labeling: Obligations Under EU AI Act Art. 50(4)

Updated: July 21, 2026

A deceptively realistic video of a politician, a cloned voice in a commercial, a photorealistic photo of a real person in a situation that never happened: content like this falls under the term "deepfake," and starting August 2, 2026, a legal deepfake labeling requirement applies to it under Art. 50(4) of the EU AI Act. Whoever uses and publishes a deepfake must disclose, from this deadline onward, that the content was artificially generated or manipulated. This article explains what legally counts as a deepfake, who the disclosure obligation affects, what exemptions exist for art and satire, how to cleanly separate harmless AI editing from a deepfake requiring labeling, and how to label it correctly within minutes.

Key Takeaways

  • Deepfake labeling is mandatory from August 2, 2026 (Art. 50(4) EU AI Act), 24 months after entry into force on August 1, 2024.
  • Responsible for visible disclosure is the deployer, meaning companies, agencies, marketing teams, and media outlets that publish the deepfake.
  • A deepfake only exists where there is a link to reality (real person, real place, real event) and potential for deception. Not every AI image is a deepfake.
  • Art, satire, and fiction enjoy a lighter standard, disclosure must not disturb the enjoyment of the work, but it is never fully waived.
  • Violations can be penalized with up to 15 million euros or 3 % of global annual turnover.
  • The core deadline of August 2, 2026 stays in place. Only the machine readable marking under paragraph 2, for systems provided before this date, was provisionally postponed to December 2, 2026 by the Digital Omnibus, the visible deepfake labeling under paragraph 4 was not.

Table of Contents

  1. What is a deepfake within the meaning of the AI Act?
  2. Is every AI image a deepfake?
  3. Distinction: harmless AI editing vs. deepfake
  4. Who does the deepfake labeling requirement affect?
  5. Exemption for art, satire, and editorial cases
  6. How and where disclosure must take place
  7. Risks and fines
  8. Guide: labeling correctly in 5 steps
  9. FAQ

What is a deepfake within the meaning of the AI Act?

The AI Act defines a deepfake as AI generated or AI manipulated image, audio, or video content that resembles existing people, objects, places, institutions, or events and would falsely appear to a person to be authentic or truthful. This definition sits at the center of every deepfake labeling decision and separates content requiring labeling from uncritical content.

Two characteristics are decisive:

  • A link to reality: the content depicts something that exists, or appears to, a real person, a real event, a real place.
  • Potential for deception: an average viewer could mistake the content for authentic.

A deepfake is therefore not limited to the classic "face swap video." Three practical examples illustrate the range:

  • Audio deepfake: a voice created with a voice cloning tool has a real CEO say sentences in a commercial that he never spoke.
  • Image deepfake: a generator photorealistically places a well known person at an event they never attended.
  • Video deepfake: an interview is altered by AI so that the person shown makes different statements than in the original.

All three meet the criteria of a link to reality and potential for deception, and therefore trigger the disclosure obligation under Art. 50(4).

Is every AI image a deepfake?

No. That is the most common misunderstanding. Not every AI generated image is automatically a deepfake, and conversely, not every AI image triggers the same labeling requirement as a deepfake.

The AI Act distinguishes two levels of transparency in Art. 50 EU AI Act, which must be kept cleanly apart:

  1. Provider level (Art. 50(2)): whoever provides an AI system that produces synthetic image, audio, video, or text content must mark these outputs in a machine readable way and identify them as artificially generated. The solutions must be "effective, interoperable, robust and reliable," "as far as this is technically possible," which covers machine readable methods like the C2PA standard, IPTC fields, and watermarks. This is aimed at the makers of the generators.
  2. Deployer level (Art. 50(4)): whoever uses and publishes a deepfake must disclose that the content was artificially generated or manipulated, visibly and recognizably for humans.

An AI image is therefore a labeling required deepfake at the deployer level when it meets the link to reality and potential for deception criteria. An obviously artificial fantasy motif, a recognizable illustration, or an abstract pattern with no link to a real person is AI generated but not a deepfake in the narrower sense. For general labeling of still images, see our guide to labeling AI images; for moving content, see labeling AI video. How the two roles interact in detail is explained in the overview of provider and deployer obligations.

Distinction: harmless AI editing vs. deepfake

Where does permissible retouching end and where does a deepfake begin? Art. 50(4) explicitly exempts edits where the AI system only performs a supporting, standard function or does not substantially alter the input data. The following overview classifies typical cases.

Case Deepfake labeling required? Classification
Skin retouching, color correction, exposure, cropping No Standard editing, no substantial manipulation
Removing a distracting object in the background Usually no Minor, no pretense of reality
AI face swap with a real person Yes Classic deepfake
Real person photorealistically placed into a fabricated scene Yes Potential for deception present
Cloned voice of a real person Yes Audio deepfake
AI video with real but altered statements Yes Video deepfake
Fully invented, non real "AI person" (photorealistic) Case by case No link to reality to an existing person, but possibly general AI transparency applies
Recognizable drawing, comic, stylized image No No pretense of reality

The rule of thumb: as soon as your editing can lead a viewer to believe something is real that did not actually happen, we are talking about a deepfake with a disclosure obligation. This line depends on judgment in individual cases, when in doubt, label it.

Edge case, e commerce and marketing: an AI cut out and color corrected product photo remains permissible standard editing. If you instead show a real testimonial customer in an AI generated usage scene that never took place, the case tips toward a deepfake. What this means for shop owners and advertisers is covered in more depth in the articles on AI labeling in e commerce and marketing and AI advertising on Meta and Instagram Ads.

Who does the deepfake labeling requirement affect? (Deployer, paragraph 4)

The addressee of Art. 50(4) is the deployer, meaning whoever actually uses and publishes the deepfake. In practice, these are companies, agencies, media outlets, marketing departments, and self employed people who use AI tools to create and distribute content.

So if you produce a deepfake with an image, video, or audio generator and publish it on your website, on social media, or in a campaign, you are the deployer and therefore required to label it, regardless of the fact that the maker of the generator must in turn apply the machine readable marking under paragraph 2. The basis for this division of roles comes from the official EU Commission guidelines on transparency obligations.

The following table summarizes the two levels of responsibility:

Criterion Provider (paragraph 2) Deployer (paragraph 4)
Who? Maker of the generator Whoever publishes the deepfake
Obligation Machine readable marking Visible disclosure
Tool IPTC/XMP, C2PA, watermark Recognizable label on the content
Deadline August 2, 2026 (legacy systems: December 2, 2026) August 2, 2026
Typical audience AI tool providers D2C, e commerce, marketing, editorial teams

Deepfake exemption for art, satire, and editorial cases

Art. 50(4) provides for a lighter standard for certain constellations. If a deepfake is recognizably part of an artistic, creative, satirical, fictional, or analogous work, the obligation is limited to disclosing the existence of generated or manipulated content in a way that does not impair the display or enjoyment of the work.

In practice, that means: a satire show, a recognizably fictional film, or an art project does not have to destroy the illusion with an intrusive permanent label. A subtle notice, for example in the credits, in a caption, or in the description, can be sufficient.

This deepfake exemption for art and satire is, however, not a blank check:

  • It only applies if the artistic or satirical character is actually recognizable.
  • Disclosure is not fully waived, it is only required to be less prominent.
  • A deceptively realistic depiction of a real person merely labeled as "satire" does not fall under the relief.

For AI generated text on matters of public interest (for example news or political information), a separate disclosure obligation under paragraph 4 also applies, unless a human editorial review with acceptance of responsibility has taken place. The article on labeling AI text from ChatGPT & co. shows how to correctly label such text.

How and where disclosure must take place

Labeling must occur clearly, distinctly, and accessibly, at the latest at the moment of first interaction or perception. A hidden notice in the legal notice or the footer is not enough, the labeling belongs on or immediately with the content itself.

Solid deepfake labeling ideally consists of two components:

  1. A visible label directly on the content, for example the notice "AI generated" or "modified with AI." The EU Commission provides an official but optional set of EU icons for AI content for this purpose (variants: "basic," "fully AI generated," "partially AI modified"; as SVG and PNG). Technical details can be found in the official overview of EU icons for labeling AI generated content.
  2. A machine readable marking in the metadata (IPTC/XMP, optionally C2PA or an invisible watermark), so platforms and verification tools can automatically recognize the content as AI generated.

Wording like "illustrative image" or "digital art" is not sufficient for a deepfake disclosure, because it does not clearly name the artificial generation. The labeling must make the circumstance of AI generation or manipulation explicit and understandable.

Risks and fines for missing deepfake labeling

Whoever violates the disclosure obligation risks consequences at several levels:

  • Fines under the AI Act: violations of the transparency obligations under Art. 50 can be penalized with fines of up to 15 million euros or 3 % of global annual turnover (whichever amount is higher). The higher fine brackets of the AI Act are reserved exclusively for prohibited practices under Art. 5, not for labeling. Details on deadlines and sanctions are gathered in the article on AI Act deadlines and fines.
  • Cease and desist letters and competition law: missing labeling can be challenged as a competition law violation. What you then face is covered under AI labeling: fines and warning letters.
  • Personality and copyright rights: deepfakes of real people also touch, independent of the AI Act, the right to one's own image and one's own words. This can add injunctive relief and damages claims from the affected person.

For a full overview of all obligations, we also recommend the AI labeling requirement under the EU AI Act as well as the practical AI labeling checklist.

Guide: labeling correctly in 5 steps

  1. Deepfake assessment: first clarify whether the content meets the link to reality and potential for deception criteria. Only then does paragraph 4 apply. When in doubt, use the distinction table above.
  2. Determine your role: are you publishing the content yourself? Then you are the deployer and responsible for visible disclosure.
  3. Set a visible label: place a clear, humanly recognizable EU icon or a plain text notice directly on the image or video, not only in the footer.
  4. Mark it machine readable: write IPTC/XMP metadata and optionally a watermark into the file, so platforms also automatically recognize the AI origin.
  5. Document your proof: secure tamper resistant proof (e.g. a checksum and timestamp) so you can prove, if a dispute arises, that and when you labeled correctly.

With the free web tool KI-Kennzeichnung from Scalemaker, you handle steps 3 through 5 in one pass: a visible EU label by drag and drop onto an image or video, machine readable metadata (IPTC/XMP, C2PA) including an optional watermark, a verification feature for existing files, and a compliance register with a SHA-256 checksum and CSV export as proof. For large volumes, the batch feature processes up to 50 files as a ZIP, and a REST API integrates the labeling directly into your workflows.

Frequently asked questions about deepfake labeling (FAQ)

What is a deepfake within the meaning of the AI Act? A deepfake is AI generated or AI manipulated image, audio, or video content that resembles real people, places, or events and could falsely appear to be authentic. The link to reality and the potential for deception are decisive.

Is every AI image a deepfake and therefore subject to labeling? No. Only AI content with a link to reality and potential for deception counts as a deepfake under Art. 50(4). Obviously artificial illustrations or abstract motifs with no link to real people do not fall under it, though they may be subject to general AI transparency.

From when does the deepfake labeling requirement apply? The transparency and disclosure obligations under Art. 50 EU AI Act apply from August 2, 2026 (24 months after the regulation entered into force on August 1, 2024). The visible deployer labeling under paragraph 4 is not postponed; only the machine readable marking under paragraph 2, for systems provided before this date, was provisionally postponed to December 2, 2026 by the Digital Omnibus. The official EU timeline for implementation documents the schedule.

Who has to label the deepfake, the provider or the deployer? The deployer, who uses and publishes the deepfake, is responsible for visible disclosure. The provider of the generator must additionally apply the machine readable marking under paragraph 2.

Does an exemption apply for art and satire? Yes. For recognizably artistic, satirical, or fictional works, a lighter standard applies: disclosure must occur in a way that does not impair the enjoyment of the work, for example as a subtle notice in the credits or the description. Labeling is, however, never fully waived.

Do I have to label retouched photos as a deepfake? Minor edits like color correction, exposure, or skin retouching are not deepfakes. Only once the manipulation could lead viewers to mistake something non real for real does the disclosure obligation arise.

How must the labeling look and where do I place it? It must be clear, distinct, accessible, and recognizable at the latest upon first perception, directly on the content, not in the footer or legal notice. A visible label (e.g. an EU icon) plus machine readable metadata is recommended.

Is the notice "illustrative image" or "digital art" enough? No. Such wording does not clearly name the artificial generation. The labeling must explicitly clarify that the content is AI generated or AI manipulated.

How high is the fine for missing deepfake labeling? Violations of the transparency obligations under Art. 50 can be penalized with up to 15 million euros or 3 % of global annual turnover. The higher fine bracket of the AI Act applies only to prohibited practices under Art. 5, not to labeling.

Do I have to label deepfakes created before August 2, 2026? For visible disclosure under paragraph 4, the deadline of August 2, 2026 applies to publication. If you continue to publicly distribute legacy content, you should label it. For the machine readable marking by providers of older systems, the extended deadline until December 2, 2026 applies.

Sources


This article reflects the status as of July 21, 2026, and does not constitute legal advice. For your specific case, please consult a lawyer.

Read more