{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"deepfakes-under-the-eu-ai-act","title":"Deepfakes under the EU AI Act: the rule that applies now","body":"The European Union now has a live disclosure rule for deepfakes. Since **2 August 2026**, a company, public body, campaign, studio or individual using an AI system to generate or manipulate realistic image, audio or video must disclose that the content was artificially generated or manipulated. The duty falls on the **deployer**—the party using the system—not only on the company that built the model. A separate provider duty requires machine-readable marking at the point of generation.\n\nThis page turns Article 50 of Regulation (EU) 2024/1689 into an operating test. It is a practical resource, not legal advice. The legal text, the Commission’s final July 2026 guidelines and the Commission’s own implementation materials remain controlling.\n\n> **The short rule**\n>\n> If AI-generated or AI-manipulated image, audio or video resembles a real person, object, place, entity or event and could falsely appear authentic or truthful, treat it as a deepfake. Preserve the provider’s machine-readable mark. Add a clear human-visible disclosure no later than first exposure. Keep the record that proves both layers travelled with the asset.\n\n[[embed:source:s1]]\n\n## A deepfake is defined by deceptive resemblance, not by quality\n\nArticle 3(60) defines a deepfake as AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Four questions do the work:\n\n| Question | If yes | If no |\n|---|---|---|\n| Was image, audio or video generated or manipulated by an AI system? | Continue | Article 50(4)’s deepfake branch does not apply |\n| Does it resemble an existing person, object, place, entity or event? | Continue | It may be synthetic content, but not a deepfake under this definition |\n| Could it falsely appear authentic or truthful to a person? | Continue | The statutory definition may not be met |\n| Is the party publishing, distributing or otherwise using it the deployer? | The deployer disclosure duty attaches | Identify who actually deploys the system and content |\n\nPhotorealism is evidence, not the test. A crude voice clone may qualify if it plausibly resembles a real speaker. A beautiful fictional landscape may fall outside the deepfake definition if it resembles no existing place or event. A manipulated image of a real factory, product or document can qualify even when no human face appears.\n\n[[embed:source:s2]]\n\n## Two disclosures travel through the same content supply chain\n\nArticle 50 creates two distinct duties that should be designed as one chain.\n\n| Layer | Responsible party | Required result | Deadline |\n|---|---|---|---|\n| Article 50(2) | Provider of the generative AI system, including a general-purpose system | Output is marked in a machine-readable format and detectable as artificially generated or manipulated; the solution must be effective, interoperable, robust and reliable as far as technically feasible | At generation/export |\n| Article 50(4)–(5) | Deployer using the AI system and exposing the content | People receive a clear, distinguishable disclosure that the content was artificially generated or manipulated | No later than first exposure |\n\nA caption alone is not the provider mark. Embedded provenance alone is not the deployer disclosure. A robust implementation carries both.\n\nThe Commission’s final July 2026 guidance says providers and deployers may use the voluntary Code of Practice to demonstrate compliance. A party that does not sign the Code must be able to demonstrate an alternative, equivalently adequate means for the marking and labelling obligations.\n\n[[embed:source:s3]]\n\n## The disclosure has to arrive before the deception can do its work\n\nArticle 50(5) supplies the timing and presentation standard: the information must be clear and distinguishable, provided no later than the first interaction or exposure, and comply with applicable accessibility requirements.\n\nThat produces concrete design consequences:\n\n- A label hidden at the end of a caption is vulnerable because the first exposure already occurred.\n- A disclosure only inside metadata does not inform a person who cannot see the metadata.\n- A watermark too faint to distinguish at the rendered size does not meet a clear-and-distinguishable standard merely because it exists in the source file.\n- A spoken deepfake needs an accessible disclosure appropriate to audio; text-only labelling may not reach the audience exposed through sound.\n- A video repost workflow must preserve or recreate the disclosure when platforms strip the original caption or metadata.\n\nThe Commission has released optional EU icons for labelling AI-generated content. They can support recognition, but an icon does not excuse an implementation that leaves the audience unable to understand what was generated or manipulated.\n\n[[embed:source:s4]]\n\n## Art, satire and fiction get a narrower manner of disclosure, not a blank exemption\n\nWhere the content is part of an evidently artistic, creative, satirical, fictional or analogous work or programme, Article 50(4) limits the obligation to disclosure of the existence of the generated or manipulated content in an appropriate manner that does not hamper display or enjoyment.\n\nThe word **evidently** matters. The safer operating assumption is not “art means exempt.” It is:\n\n1. Decide whether the work is evidently within the protected creative category.\n2. Preserve the fact of disclosure.\n3. Choose a manner proportionate to the work that does not destroy its display or enjoyment.\n4. Keep the reasoning and rendered exhibit showing why the chosen placement remained clear.\n\nThe separate law-enforcement exception is narrow: use authorised by law to detect, prevent, investigate or prosecute criminal offences. It is not a general public-sector exemption.\n\n## A six-record compliance packet\n\nThe best evidence is produced during the content workflow, not assembled after a complaint. Keep one packet per asset or campaign:\n\n| Record | What it proves |\n|---|---|\n| 1. Source asset hash | Which exact file was assessed and published |\n| 2. Generation or edit receipt | Which AI system and operation created or changed it |\n| 3. Provider-mark inspection | Which machine-readable mark was present after export |\n| 4. Transformation log | Whether editing, transcoding, screenshotting or platform upload stripped or altered the mark |\n| 5. First-exposure captures | The disclosure as actually rendered on every distribution surface |\n| 6. Classification memorandum | Why the content was or was not treated as a deepfake; which exception or creative treatment was applied |\n\nA policy without the rendered captures does not prove disclosure. A screenshot without the source hash does not prove which asset it covers. The packet binds the duty, the file and the human exposure into one reviewable object.\n\n## The pre-publication test\n\nRun this before every release:\n\n```text\nASSET_ID: <stable id and SHA-256>\nAI_OPERATION: <generated | manipulated | standard edit only>\nREAL-WORLD_RESEMBLANCE: <person | object | place | entity | event | none>\nFALSE_AUTHENTICITY_RISK: <yes | no, with one-sentence basis>\nPROVIDER_MARK_PRESENT_AFTER_EXPORT: <yes | no | unknown>\nDEPLOYER_LABEL_AT_FIRST_EXPOSURE: <exact wording and placement>\nACCESSIBILITY_CHECK: <visual | audio | captions | screen-reader>\nCREATIVE_WORK_TREATMENT: <not invoked | invoked, with basis>\nTRANSFORMATION_TEST: <mark and label survived each downstream surface>\nREVIEWER_AND_DATE: <name, authority, timestamp>\n```\n\nAny `unknown` is an unresolved control, not a pass. Any downstream surface that strips the provider mark or the human-facing label needs a compensating publication step before release.\n\n## The rule reaches businesses outside Europe\n\nThe AI Act’s territorial scope is not limited to companies incorporated in the Union. A provider or deployer outside the EU can be in scope where the output produced by the AI system is used in the Union. The exact scope analysis remains fact-specific, but “the model and publisher are abroad” is not a classification rule.\n\nNon-compliance with Article 50 can attract administrative fines up to **€15 million or 3% of total worldwide annual turnover**, whichever is higher for an undertaking, subject to the Regulation’s penalty rules and proportionality provisions. The Commission identifies national market-surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor for EU institutions as enforcement actors.\n\n[[embed:source:s5]]\n\n## The useful question is not whether a label exists\n\nA regulator, auditor or court will be able to ask a harder sequence:\n\n- Was this exact asset a deepfake under Article 3(60)?\n- Which party was provider, which was deployer, and where did each duty attach?\n- Did the machine-readable mark survive the complete distribution chain?\n- What did a person actually see or hear at first exposure?\n- Was the disclosure accessible in that medium?\n- If the creative-work treatment was used, why was the work evidently within it and why was the chosen disclosure appropriate?\n- Can the operator reproduce the answer from records made before the dispute?\n\nThat is the standard this page is built to make executable.\n\n## A free public-interest audit\n\nThe **Object Invocation Protocol** will run a documented Article 50 gap analysis without charge for a legislator, regulator, civil-society organisation, company or private party willing to provide a bounded public artifact and the facts necessary to assess it. The output can include:\n\n- the provider/deployer role map;\n- the deepfake and synthetic-content classification;\n- the first-exposure and accessibility test;\n- the missing-evidence register;\n- a proposed compliance record and remediation schematic;\n- independent model findings bound to the same source record, with disagreement preserved rather than hidden.\n\nSend the artifact or public URL to **build@miscsubjects.com** with the jurisdiction and intended use. The analysis, its sources and its limits will be returned as a reviewable record. No finding is represented as a regulator’s determination or legal advice.\n\n## Continue the EU AI Act series\n\n[[embed:three-models-deliberate-one-statutory-question]]\n\nThe companion pages cover machine-readable marking under Article 50(2), the complete Act, and the Article 6 high-risk classification decision tree. This page will be revised when the Commission, AI Board, market-surveillance authorities or courts materially change the operational answer.","register":"essay","hero":"https://miscsubjects.com/img/gen/codex-eu-ai-deepfake-article50-2026.png?v=1","hero_brief":"A forensic media examination table with one portrait split between authentic photograph and synthetic deepfake reconstruction, inspected under an EU-blue evidence light; restrained European editorial photography.","editorial_review":{"headline_subject":"The live EU AI Act rule for deepfakes and the records needed to prove compliance","hero_subject":"A forensic analyst compares an authentic portrait with its synthetic reconstruction","visual_action":"The gloved analyst inspects the seam between authentic and synthetic halves under a blue evidence light","rationale":"The article is about distinguishing and disclosing synthetic likeness; the image renders the exact evidentiary task without generic AI imagery.","inspected":true,"inspection_note":"Inspected the 1536×1024 render: the split portrait is immediate at card scale, the authentic and synthetic halves are materially distinct, the analyst’s hands and loupe establish examination, and there is no readable text or decorative robot imagery.","hero_brief":"A forensic media examination table with one portrait split between authentic photograph and synthetic deepfake reconstruction, inspected under an EU-blue evidence light; restrained European editorial photography."},"tags":["canonical","eu-ai-act","article-50","deepfakes","compliance","ongoing"],"category":"canon","style":{},"claims":[{"id":"c1","text":"Article 50(4) requires deployers of AI systems generating or manipulating deepfake image, audio or video to disclose that the content was artificially generated or manipulated.","section":"Two disclosures travel through the same content supply chain","tier":"primary-law","source_ids":["s1","s2"]},{"id":"c2","text":"Article 3(60) defines a deepfake by AI generation or manipulation, resemblance to an existing person, object, place, entity or event, and false appearance of authenticity or truthfulness.","section":"A deepfake is defined by deceptive resemblance, not by quality","tier":"primary-law","source_ids":["s1"]},{"id":"c3","text":"Provider machine-readable marking and deployer human-facing disclosure are distinct Article 50 duties and a robust supply chain must preserve both.","section":"Two disclosures travel through the same content supply chain","tier":"derived","source_ids":["s1","s3"]},{"id":"c4","text":"Article 50 information must be clear, distinguishable, accessible and supplied no later than first interaction or exposure.","section":"The disclosure has to arrive before the deception can do its work","tier":"primary-law","source_ids":["s1","s2"]},{"id":"c5","text":"The artistic, creative, satirical and fictional treatment narrows the manner of disclosure but does not erase disclosure of the generated or manipulated content.","section":"Art, satire and fiction get a narrower manner of disclosure, not a blank exemption","tier":"primary-law","source_ids":["s1"]},{"id":"c6","text":"The Commission states that Article 50 transparency duties apply from 2 August 2026 and that pre-existing systems and content may receive specific transitional treatment.","section":"The short rule","tier":"official-guidance","source_ids":["s2","s3","s4"]},{"id":"c7","text":"Article 50 non-compliance can fall within the penalty tier up to €15 million or 3% of worldwide annual turnover for undertakings.","section":"The rule reaches businesses outside Europe","tier":"primary-law","source_ids":["s1","s5"]},{"id":"c8","text":"A compliance packet should bind the exact asset, AI operation, provider mark, transformation chain, first-exposure disclosure and classification rationale before publication.","section":"A six-record compliance packet","tier":"method","source_ids":["s1","s3"]},{"id":"c9","text":"The final Article 50 guidelines do not eliminate fact-specific uncertainty about particular label placement, the limited creative-work treatment, national enforcement practice or equivalent alternative compliance measures.","section":"The disclosure has to arrive before the deception can do its work","tier":"boundary","source_ids":["s1","s2","s3"]},{"id":"c10","text":"This article is an operational guide, not a regulatory determination or legal advice; a defensible assessment still requires the exact asset, render, workflow, audience and disclosure evidence.","section":"A six-record compliance packet","tier":"limitation","source_ids":["s1","s2"]}],"sources":[{"id":"s1","type":"reference","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng","title":"Regulation (EU) 2024/1689 — Articles 3(60), 50 and 99","summary":"Binding text defining deepfakes, separating provider marking from deployer disclosure, setting timing/accessibility, exceptions and penalties.","publisher":"EUR-Lex","claim_ids":["c1","c2","c3","c4","c5","c7","c9","c10"]},{"id":"s2","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","title":"Guidelines on transparency obligations for providers and deployers of certain AI systems","summary":"Final Commission Article 50 guidelines published 20 July 2026; the operative interpretation used by authorities and operators.","publisher":"European Commission","claim_ids":["c1","c4","c6","c9","c10"]},{"id":"s3","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/faqs/code-practice-transparency-ai-generated-content","title":"Code of Practice on Transparency of AI-Generated Content","summary":"Official implementation route for marking, detection and labelling; voluntary adherence and alternative-equivalence posture.","publisher":"European Commission","claim_ids":["c3","c6","c8","c9"]},{"id":"s4","type":"reference","url":"https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems","title":"Quick Facts: Transparency rules for AI systems","summary":"Official operational summary covering content, exceptions, application dates, icons, enforcement and transition rules.","publisher":"European Commission","claim_ids":["c4","c6"]},{"id":"s5","type":"reference","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99","title":"Article 99: Penalties","summary":"Accessible article-level presentation of the penalty framework; primary citation remains EUR-Lex.","publisher":"EU AI Act Service Desk","claim_ids":["c7"]}],"prov":{"model":"unattributed","action":"write"}}