imadethisup.org Retain →
LAW · 2026-08-29

Synthetic media disclosure obligations now in force

Article 50 of the EU AI Act requires providers and deployers of AI-generated content to mark outputs and disclose whether content is artificially generated or manipulated.

What Article 50 requires

Article 50 of the EU AI Act took effect on 2 August 2026 [1]. The provision imposes transparency obligations on two groups: providers of AI systems and deployers, the organizations and individuals who use those systems to create or distribute synthetic content [1].

Providers, the organizations that build and release AI systems, must ensure that any system generating synthetic audio, image, video, or text marks its outputs in a machine-readable format that is detectable as artificially generated or manipulated [1]. Machine-readable means technically parseable, not merely human-visible labeling. A deployer or third party should be able to detect the synthetic origin programmatically.

Deployers have separate obligations. When they release synthetic media to the public, they must disclose the artificial origin of the content. The specific requirements depend on the type of content and its purpose [1].

Technical marking requirements for providers of AI systems

Providers must make their marking solutions "effective, interoperable, robust and reliable as far as this is technically feasible" [1]. The regulation explicitly recognizes practical constraints. When assessing feasibility, providers may consider the costs of implementation and the "generally acknowledged state of the art," including relevant technical standards [1]. Different content types, such as video versus text, may justify different approaches.

Important exemptions apply. Systems performing only assistive editing functions, like grammar correction, color correction, or exposure adjustment, are exempt from marking requirements [1]. Systems that do not substantially alter the semantic meaning of the input data are also exempt [1]. Uses authorized by law for detecting, preventing, investigating, or prosecuting criminal offences are exempt [1].

A gap remains. The regulation does not specify which technical standards, file formats, or metadata schemes satisfy the machine-readable format requirement. No implementing technical specification has been confirmed. Organizations deploying synthetic-media systems operate with compliance uncertainty on this point.

Deepfake disclosure

A deepfake, synthetically generated or manipulated image, audio, or video, is subject to an explicit disclosure rule [1]. Deployers of such systems must disclose to the public that the content has been artificially generated or manipulated [1].

This obligation does not apply where the use is authorized by law for law enforcement purposes [1]. It also does not apply to artistic, creative, satirical, fictional, or analogous works [1]. For such creative content, the transparency obligation is not eliminated but rather narrowed; deployers must disclose that the content was generated or manipulated, but only in an appropriate manner that does not hamper the display or enjoyment of the work [1].

AI-generated text for public interest reporting

Article 50 also regulates text. Deployers of AI systems that generate or manipulate text for publication with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated [1].

A significant exemption exists, and it depends on editorial practice. Deployers need not disclose AI-generated text if the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication [1]. This exemption is conditional on a practice, not on a technology. It requires three things: human review or editorial control, together with a named person or legal person holding editorial responsibility. An organization that automates content creation and removes human editorial oversight loses the exemption; the disclosure duty applies to that AI-generated content again [1].

Law enforcement uses are exempt [1].

The conjunction matters here and is easy to misread. The exemption applies where the content has undergone a process of human review or editorial control, and where a natural or legal person holds editorial responsibility for the publication [1]. It is a disjunction inside a conjunction: one of review or editorial control, plus someone who owns the result. A publisher that keeps neither review nor editorial control, or that can point to no person or legal person carrying editorial responsibility, is outside the exemption and owes the disclosure.

What Article 50 leaves unsettled: marking standards and enforcement

As checked on 30 August 2026, no enforcement action has been initiated since Article 50 took effect on 2 August 2026. No precedent exists yet for how regulators will interpret or enforce the transparency obligations. This is a claim with a short shelf life; check it again before relying on it.

The technical scope of "machine-readable format" has not been defined by implementing regulation. The European Commission published a voluntary Code of Practice on Marking and Labelling of AI-generated Content [2], and an AI Act Service Desk provides guidance [2]. Whether the Code of Practice has binding legal effect or definitively answers what marking standards are required remains uncertain.

What the disclosure duty means for counsel, newsrooms, and security teams

For lawyers and compliance officers: your clients deploying synthetic-media systems face new legal obligations with undefined technical scope. You need to advise them on what Article 50 requires while acknowledging the gap in technical specifications.

For journalists and news organizations: Article 50(4) creates a new obligation on you. When you publish AI-generated or AI-manipulated text about matters of public interest, you must disclose it, unless your organization maintains human editorial review and responsibility. If you shift to fully automated content creation, the exemption disappears. The disclosure duty applies.

For security professionals: these obligations matter because breaches of the law become part of threat assessment, incident response, and digital forensics work.

For individuals affected by synthetic media: Article 50 creates legal obligations for transparency when synthetic media is released. Enforcement has not begun, but the legal foundation now exists.


Related reading

Sources

  1. [1]
    European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 50 and Article 113. Official Journal, 12 July 2024.eur-lex.europa.eu
  2. [2]
    European Commission. Regulatory framework for AI.digital-strategy.ec.europa.eu
Questions

Common questions on this topic

When did the EU AI Act deepfake disclosure obligations start to apply?

Article 113 of Regulation (EU) 2024/1689 sets 2 August 2026 as the general application date, and Article 50 is not among the provisions that applied earlier. The Regulation itself was published in the Official Journal on 12 July 2024, so the law existed for two years before these particular duties took effect.

Does the EU AI Act require AI-generated text to be labelled?

Article 50(4) requires deployers to disclose that text has been artificially generated or manipulated where it is published to inform the public on matters of public interest. The obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

Are artistic or satirical deepfakes exempt from disclosure?

Not exempt, but the duty is narrower. Article 50(4) provides that where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the transparency obligation is limited to disclosing the existence of the generated or manipulated content in a manner that does not hamper the display or enjoyment of the work.