ENFORCEMENT: AUGUST 2, 2026

EU AI Act Article 50(4): Deepfake & AI-Generated Content Disclosure — Complete Compliance Guide 2026

Article 50(4) targets the most publicly visible form of AI transparency: the obligation to label deepfakes and AI-generated text that informs the public on matters of public interest. With enforcement beginning August 2, 2026, every media company, marketing agency, content creator, and news organisation that uses AI to generate or manipulate visual, audio, or textual content must understand when disclosure is required, what format it must take, and which exemptions apply. This guide covers the three deepfake criteria, the artistic exemption, the editorial review standard for AI-generated text, and a concrete implementation path.

2. What Is a Deepfake — The Three Criteria

Article 3(60) provides the legal definition. A piece of content qualifies as a deepfake only when all three criteria are met simultaneously:

The Three Deepfake Criteria (All Must Be Met)

1
AI generation or manipulation. The content was generated or manipulated by an AI system. This includes both fully synthetic content (AI-generated from scratch) and AI-manipulated content (real content altered by AI — face-swapping, voice cloning, lip-syncing, scene manipulation).
2
Resemblance to reality. The content resembles existing persons, objects, places, entities, or events. A purely abstract AI-generated image that does not depict any recognisable real-world element does not meet this criterion.
3
False appearance of authenticity. The content would falsely appear to a person to be authentic or truthful. A clearly stylised illustration, an obvious cartoon, or content with visible AI artefacts that a reasonable person would recognise as synthetic does not meet this criterion. The standard is the perception of a "reasonably well-informed, observant and circumspect" person.

Applying the criteria in practice

Content ExampleCriterion 1Criterion 2Criterion 3Deepfake?
AI-generated video of a CEO making a statement they never made Yes Yes (real person) Yes (appears authentic) Yes — disclosure required
AI face-swap of a politician onto another body Yes Yes (real person) Yes (appears authentic) Yes — disclosure required
AI-generated photorealistic landscape of a real city Yes Yes (real place) Yes (appears authentic) Yes — disclosure required
AI-generated abstract art with no real-world reference Yes No N/A No — not a deepfake
AI-generated cartoon caricature of a politician Yes Yes (real person) No (obviously a caricature) No — not a deepfake (plus artistic exemption)
Voice clone of a real person reading a script Yes Yes (real person's voice) Yes (sounds authentic) Yes — disclosure required
AI upscaling of a low-resolution photo Yes (AI manipulation) Yes (real scene) Generally no (enhancing, not fabricating) Usually no — but depends on extent of alteration
AI background removal and replacement in a product photo Yes Possibly (real product) Depends on context Grey area — assess case by case

3. Content Types Covered

Article 50(4) covers four content types, but applies different rules to each:

Content TypeDeepfake Disclosure (Subparagraph 1)Public Interest Text Disclosure (Subparagraph 2)Exemptions
Image (photos, illustrations, graphics) Required if three criteria met N/A Artistic/satirical; law enforcement
Audio (voice, music, sound effects) Required if three criteria met N/A Artistic/satirical; law enforcement
Video (live action, animation, composites) Required if three criteria met N/A Artistic/satirical; law enforcement
Text N/A (text cannot be a "deepfake" under Art. 3(60)) Required if published to inform public on matters of public interest Human editorial review; law enforcement
Text Is Different
AI-generated text is explicitly excluded from the deepfake definition — the Article 3(60) definition covers only image, audio, and video. Text has its own separate regime under Article 50(4) second subparagraph, with different scope (limited to public interest matters) and different exemptions (editorial review rather than artistic expression). This distinction matters: an AI-generated product description is not a deepfake and does not require Article 50(4) disclosure if it is not published for public interest purposes.

4. Who Must Comply — Deployer Obligation

Like Article 50(3), the disclosure obligation falls on deployers — the organisations or individuals that use an AI system to generate or manipulate content and then distribute that content. In practice, this means:

ActorArticle 50(4) ObligationExamples
Content creator using AI tools Must disclose if output meets deepfake criteria or is public interest text Marketing agency using AI image generators; journalist using AI writing tools; social media creator using face-swap apps
Publisher distributing AI content Must disclose if publishing AI-generated content meeting the criteria News outlet publishing AI-assisted articles; media company distributing AI-generated video
Platform hosting user-generated AI content Facilitating role — may bear obligations under DSA; not directly a "deployer" unless the platform itself generates the content Social media platform where users upload deepfakes — DSA obligations apply; platform's own AI-generated content requires disclosure
AI tool provider Article 50(2) obligation to embed machine-readable marking — separate from deployer's Article 50(4) disclosure Companies building image generators, voice synthesisers, video AI tools
The Provider-Deployer Handshake
Article 50(2) requires providers to mark AI-generated content with machine-readable metadata at the point of creation. Article 50(4) requires deployers to disclose the AI nature to the public at the point of distribution. These are complementary: the provider embeds the technical marking, the deployer ensures human-perceptible disclosure. If you use an AI tool that does not embed metadata (non-compliant provider), your Article 50(4) disclosure obligation as a deployer still applies — you cannot rely on the provider's failure to excuse your own non-compliance.

5. AI-Generated Text and the Public Interest Test

The second subparagraph of Article 50(4) creates a narrower obligation for AI-generated text than for deepfakes. Disclosure is required only when two conditions are both met:

ConditionWhat It MeansExamples That QualifyExamples That Do Not
AI-generated or AI-manipulated text The text was substantially produced or altered by an AI system — not merely spell-checked or grammar-corrected Article drafted by ChatGPT; report generated by Claude; analysis written by Gemini Human-written text run through a spell-checker; text with AI-suggested synonyms; auto-correct
Published to inform the public on matters of public interest The text addresses topics of societal concern and is made publicly available with the purpose of informing readers News articles; public policy analysis; election coverage; public health guidance; scientific commentary; government communications; consumer safety alerts Product descriptions; marketing copy; creative fiction; internal memos; personal emails; customer service templates; advertising copy

Borderline cases

ContentPublic Interest?Reasoning
AI-generated blog post about EU AI Act compliance Likely yes Regulation is a matter of public interest; the post informs the public about legal obligations
AI-generated company sustainability report (public) Likely yes ESG and environmental impact are matters of public interest; public availability indicates informing purpose
AI-generated product review on a retail website Possibly Consumer protection is public interest; depends on whether the review genuinely informs or is marketing
AI-generated recipe article Generally no Not typically a matter of public interest unless it relates to food safety or public health
AI-generated financial market commentary Likely yes Financial markets affect the public; market commentary informs investors and consumers
AI-generated social media post about a political candidate Yes Election-related content is quintessentially public interest

6. The Editorial Review Exemption

AI-generated text published on matters of public interest does not require disclosure if two conditions are met: (1) the content has undergone "a process of human review or editorial control," and (2) a natural or legal person "holds editorial responsibility for the publication of the content." Both must be satisfied — editorial responsibility alone, without genuine review, is not sufficient.

What constitutes genuine editorial review

ActionGenuine Review?Reasoning
Editor reads the full text, checks facts against primary sources, corrects errors, and approves for publication Yes Substantive engagement with content; editorial accountability is real
Editor reads the text, assesses tone and accuracy, makes minor revisions, signs off with name on byline Yes Genuine engagement and personal accountability
Editor glances at the headline and first paragraph, clicks "publish" No Superficial check does not constitute genuine review
Automated grammar/plagiarism check followed by auto-publish No No human review occurred — automated tools are not editorial control
Editor reviews AI output, makes substantial revisions, adds original reporting Yes The human contribution transforms the output; editor bears genuine responsibility
Publisher claims editorial responsibility in their terms of service but has no editorial staff No Claiming responsibility without exercising it does not satisfy the requirement
Document Your Editorial Process
If you rely on the editorial review exemption, you must be able to demonstrate that genuine review occurred. Maintain records: who reviewed the content, when, what changes were made, what sources were checked, and who bears editorial responsibility. In the event of a regulatory inquiry, "we have editors" is not sufficient — you must show that the specific content was reviewed.

The editorial responsibility requirement

The exemption requires that "a natural or legal person holds editorial responsibility for the publication." This means a named individual or organisation must accept accountability for the content's accuracy, fairness, and compliance. This is modelled on the concept of editorial responsibility in media law. A news outlet with an editor-in-chief who signs off on AI-assisted articles satisfies this requirement. An anonymous content farm that bulk-publishes AI text without any named editorial figure does not.

7. Artistic, Satirical & Creative Exemption

The deepfake disclosure obligation is modified — not eliminated — for content that forms part of an "evidently creative, satirical, artistic or fictional cinematographic or analogous work." This exemption recognises that deepfake technology has legitimate creative applications: films using de-ageing technology, satirical videos, artistic installations, and entertainment.

What the exemption changes

The exemption does not remove the disclosure obligation entirely. Instead, it limits the obligation: disclosure of the AI-generated or AI-manipulated nature must still be made, but "in an appropriate manner that does not hamper the display or enjoyment of the work." This means:

Without ExemptionWith Artistic Exemption
On-screen label visible during playback Credit in end titles or accompanying description is sufficient
Persistent watermark on image Caption, gallery description, or metadata disclosure is sufficient
Audio announcement at start of recording Liner notes, show description, or platform metadata is sufficient

When the exemption applies

ContentArtistic Exemption?Reasoning
Feature film using AI de-ageing on an actor Yes Evidently creative cinematographic work
Satirical video imitating a politician's voice for comedy Yes Evidently satirical — context makes the creative purpose clear
Art exhibition using AI-generated photorealistic portraits Yes Evidently artistic — gallery context signals creative purpose
Music video with AI-generated visual effects Yes Analogous to cinematographic work
Marketing video using AI face-swap to show a celebrity "endorsing" a product No Commercial advertising, not creative/satirical/artistic work
Political campaign video using AI to depict an opponent No Political messaging, not artistic or satirical — full disclosure required
Video game with AI-generated cutscenes featuring real-world settings Yes Interactive entertainment is an analogous creative work
"Evidently" Is Key
The exemption applies to evidently creative, satirical, or artistic work — the creative nature must be apparent from the context. A deepfake video posted on a news platform without context might not be "evidently" satirical, even if the creator intended satire. The surrounding context — platform, framing, description, metadata — must make the creative purpose clear.

8. Disclosure Format and Technical Implementation

Article 50(4) requires disclosure to be made "at the latest at the time of first distribution or publication" in a manner that is "clear and distinguishable" and, where technically feasible, "machine-readable." The Code of Practice on AI Transparency (finalised June 10, 2026) provides operational guidance on implementation.

Dual-layer disclosure model

Best practice — and what the Code of Practice recommends — is a dual-layer approach: a human-perceptible label visible to viewers, plus machine-readable metadata embedded in the file.

Content TypeHuman-Perceptible LabelMachine-Readable Metadata
Image (JPEG, PNG, WebP) Visible watermark, caption, or border label: "AI-generated image" or "This image was created with AI" C2PA content credentials embedded in file; EXIF/XMP metadata field indicating AI generation; IPTC "digitalSourceType" field
Video (MP4, WebM) On-screen label at start and/or end: "This video contains AI-generated content"; persistent subtle watermark during playback C2PA content credentials; container-level metadata; chapter markers indicating AI-manipulated segments
Audio (MP3, WAV, podcast) Spoken announcement at start: "This audio contains AI-generated voice content"; show notes disclosure C2PA content credentials; ID3/Vorbis comment tags indicating AI generation; RSS feed-level disclosure for podcasts
Text (HTML, PDF, article) Visible label before or at the start: "This article was generated with AI assistance" or "AI-generated content" HTML meta tag; Schema.org CreativeWork with "isBasedOn" or custom AI disclosure property; PDF metadata

C2PA integration

The Coalition for Content Provenance and Authenticity (C2PA) standard is the most mature framework for machine-readable content credentials. C2PA embeds a cryptographically signed manifest in the file that records the content's origin, creation method, and any modifications. For Article 50(4) compliance, C2PA credentials should indicate:

C2PA FieldValue for AI-Generated Content
c2pa.action "c2pa.created" (fully AI-generated) or "c2pa.edited" (AI-manipulated)
c2pa.softwareAgent Name and version of the AI tool used
dc:description "AI-generated content" or "AI-manipulated content"
stds:digitalSourceType "trainedAlgorithmicMedia" (IPTC standard value)
Watermarking Grace Period
The EU Omnibus Regulation (signed July 8, 2026) provides a 4-month grace period specifically for watermarking — until December 2, 2026. This applies to the provider's obligation to embed machine-readable markings under Article 50(2). However, the deployer's obligation to provide human-perceptible disclosure under Article 50(4) has no grace period — it takes effect on August 2, 2026 as scheduled. Deployers cannot wait for providers to implement watermarking before disclosing.

9. Pass/Fail Compliance Scenarios

COMPLIANT — NEWS OUTLET WITH EDITORIAL REVIEW

Scenario: A newspaper uses AI to generate a first draft of a financial market summary. A senior editor reviews the draft against primary sources (exchange data, company filings, central bank statements), corrects two factual errors, adds context from an analyst interview, and publishes under the editor's byline with the newspaper named as editorially responsible.

Why it passes: The editorial review exemption applies — genuine substantive review occurred, errors were corrected, original reporting was added, and a named individual and organisation hold editorial responsibility. No AI disclosure label is required, though many outlets choose to add one voluntarily for reader trust.

NON-COMPLIANT — AUTOMATED NEWS AGGREGATOR

Scenario: A website uses AI to rewrite press releases and wire stories into "original" news articles about public health developments. The articles are auto-published without human review. The website's footer states: "All content is editorially managed by [Company Name]."

Why it fails: No genuine human review occurred — auto-publishing with a corporate claim of editorial management does not satisfy the exemption. Public health is clearly a matter of public interest. The AI-generated text requires disclosure.

COMPLIANT — DEEPFAKE IN FILM WITH CREDIT

Scenario: A feature film uses AI de-ageing technology on an actor for flashback scenes. The end credits include: "Visual effects include AI-assisted de-ageing of [Actor Name] by [VFX Studio]." The film's promotional materials mention the technology. C2PA metadata is embedded in the digital distribution file.

Why it passes: The artistic exemption applies — the disclosure is provided "in an appropriate manner that does not hamper the display or enjoyment of the work" via end credits and metadata. No on-screen label during the scene is required.

NON-COMPLIANT — UNLABELLED MARKETING DEEPFAKE

Scenario: A brand creates a marketing video using AI to generate a photorealistic scene of a celebrity appearing to use their product. The celebrity did not agree to the depiction. No label or disclosure is included.

Why it fails: All three deepfake criteria are met (AI-generated, resembles a real person, appears authentic). The artistic exemption does not apply — this is commercial advertising, not creative or satirical work. Disclosure is required. Additionally, this may violate personality rights and the prohibition on non-consensual intimate AI content under the Omnibus amendment to Article 5.

COMPLIANT — AI-GENERATED PRODUCT PHOTO BACKGROUND

Scenario: An e-commerce company uses AI to replace product photo backgrounds with clean studio settings. The product itself is real and unmodified. No disclosure label is applied.

Why it passes: While the background is AI-manipulated, the content does not falsely appear to depict a real scene that a reasonable person would mistake for authentic — product photography with studio backgrounds is an industry convention. Criterion 3 (false appearance of authenticity) is likely not met. This is a grey area where documented risk assessment strengthens the compliance position.

NON-COMPLIANT — AI-GENERATED ELECTION CONTENT WITHOUT LABEL

Scenario: A political advocacy group uses AI to generate an article analysing a candidate's policy positions and publishes it on their website during an election campaign. No AI disclosure is included and no human editor reviewed the article.

Why it fails: Election content is quintessentially public interest. AI-generated text published to inform the public on election matters requires disclosure unless genuine editorial review occurred. Neither condition for exemption is met.

COMPLIANT — SATIRICAL DEEPFAKE WITH CONTEXT

Scenario: A comedy show creates a sketch using AI to generate a clearly labelled parody of a political debate. The video is posted on social media with the caption: "Parody — AI-generated satire. Not real." The sketch is obviously comedic in tone.

Why it passes: The artistic/satirical exemption applies. The disclosure is provided in a manner that does not hamper enjoyment (caption, not an intrusive on-screen label during playback). The evidently satirical context is clear from the platform, framing, and description.

10. Platform and Social Media Considerations

Article 50(4) places the disclosure obligation on deployers — the individuals or organisations that create and distribute the content. Platforms that host user-generated content are not directly "deployers" of the deepfakes their users upload. However, platforms have parallel obligations under the Digital Services Act (DSA) and may face indirect liability:

Platform RoleAI Act ObligationDSA Obligation
Hosting AI content uploaded by users Not directly a deployer; no Article 50(4) obligation on the platform for user content Must act on notifications about illegal content (Art. 16 DSA); very large platforms must mitigate systemic risks including deepfakes (Art. 34-35 DSA)
Providing AI generation tools to users Provider under Article 50(2) — must embed machine-readable marking; users are deployers under Article 50(4) Must offer clear terms of service covering AI content policies
Generating AI content with its own tools for its own publication Both provider (Art. 50(2)) and deployer (Art. 50(4)) — full obligations Full DSA hosting and potentially VLOP obligations
Practical Advice for Social Media Users
If you create AI-generated or AI-manipulated content that meets the deepfake criteria and post it on social media, you are the deployer. The platform's labelling tools (if available) can help you comply, but the legal obligation is yours. Use available platform AI content labels, add disclosure text in captions, and consider embedding C2PA metadata before uploading. If the platform strips metadata during upload, the caption-level disclosure becomes your primary compliance mechanism.

11. Implementation Checklist

Article 50(4) Compliance Checklist — Before August 2, 2026

1. Content audit. Identify every channel where your organisation publishes content (website, social media, email newsletters, press releases, reports, marketing materials). Flag all content produced or manipulated using AI tools.
2. Deepfake assessment. For each AI-generated or AI-manipulated image, audio, or video, apply the three criteria: (1) AI generation/manipulation, (2) resemblance to reality, (3) false appearance of authenticity. Document your assessment for each content type.
3. Public interest text identification. Identify any AI-generated text published to inform the public on matters of public interest. Assess whether the editorial review exemption applies — document the review process if claiming exemption.
4. Disclosure label design. Create standardised disclosure labels for each content type: visible watermarks or captions for images, on-screen labels for video, spoken announcements for audio, text labels for articles. Ensure labels are "clear and distinguishable" — not hidden, not in microscopic text, not in secondary languages only.
5. Machine-readable metadata. Implement C2PA content credentials or equivalent metadata in all AI-generated content files. Verify metadata survives compression, format conversion, and platform upload processes. Where platforms strip metadata, rely on human-perceptible labels as primary disclosure.
6. Editorial review process. If publishing AI-generated text on public interest matters and claiming the editorial review exemption, formalise your review process: designated reviewers with named accountability, fact-checking protocol against primary sources, documented sign-off, and retained records.
7. Artistic exemption documentation. If creating deepfake content for creative, satirical, or artistic purposes, document the creative intent and ensure the context makes the creative nature evident. Implement disclosure in a manner that does not hamper enjoyment — credits, captions, or metadata rather than intrusive on-screen labels.
8. Staff training. Train content creators, editors, marketing teams, and social media managers on Article 50(4) requirements. Ensure everyone who uses AI tools to create content understands when disclosure is required and how to implement it.
9. Platform tool adoption. Activate AI content labelling features on all social media platforms where you publish. Use platform-provided AI content tags, labels, or metadata fields in addition to your own disclosure mechanisms.
10. Evidence archive. Maintain a compliance archive: screenshots of labelled content, copies of metadata-embedded files, editorial review records, deepfake assessment documentation, and staff training records. This archive is your primary defence in the event of regulatory inquiry.

12. Penalties

Up to €15,000,000 or 3% of worldwide turnover
For failure to comply with Article 50(4) transparency obligations
(whichever is higher; for SMEs and startups, the lower amount applies)

The penalties apply to each non-compliant deployment or publication. A media company that systematically publishes unlabelled deepfakes across multiple channels could face separate enforcement actions for each channel. Penalties are determined by national market surveillance authorities, taking into account the nature, gravity, and duration of the infringement, the number of persons affected, the level of damage suffered, and whether the infringement was intentional.

Reputational Risk Exceeds Financial Penalty
For most organisations, the reputational damage from being caught distributing unlabelled deepfakes or undisclosed AI-generated public interest content will exceed the regulatory fine. In a trust economy, transparency is a competitive advantage. Organisations that proactively label AI content build credibility; those caught hiding it face lasting brand damage.

13. Frequently Asked Questions

Does Article 50(4) apply to AI-generated email marketing?

Generally no — email marketing copy is commercial content, not content published to inform the public on matters of public interest. The deepfake provisions could apply if the email contains AI-generated images or video that meet the three criteria (resembles reality and appears authentic), but most marketing emails would not trigger Article 50(4). However, if a company sends an AI-generated email newsletter that includes public interest content (market analysis, regulatory updates, policy commentary), the text disclosure obligation could apply.

If I use AI to translate an article into another language, is the translation AI-generated text?

Translation is a grey area. If the original article was human-written and the AI only translates it, the substantive content is human-originated. However, if the translation is published to inform the public on matters of public interest, a cautious approach would be to note that AI translation was used — particularly if the translation has not been reviewed by a human fluent in the target language. The editorial review exemption could apply if a bilingual editor verifies the translation.

What about AI-assisted code generation — is published code "text" requiring disclosure?

Software source code is not "published with the purpose of informing the public on matters of public interest" in the ordinary sense. Code published in open-source repositories, technical documentation, or developer guides is not typically covered by Article 50(4). However, if AI-generated code is included in a published article or report about public interest topics (for example, a cybersecurity analysis), the surrounding text would need to comply if it is AI-generated.

Can I rely on the provider's machine-readable marking as my disclosure?

No. Machine-readable metadata (Article 50(2) — provider obligation) and human-perceptible disclosure (Article 50(4) — deployer obligation) are complementary, not alternatives. A viewer who encounters a deepfake image on a website cannot read C2PA metadata — they need a visible label. Machine-readable marking enables detection tools and platform verification; human-perceptible disclosure informs the individual viewer.

What if I purchase stock AI-generated images from a commercial library?

If you use AI-generated stock images in a publication, you are the deployer. Apply the three deepfake criteria: if the image is a generic illustration that does not resemble any real person, place, or event, it likely does not qualify as a deepfake (criterion 2 not met). If it is a photorealistic image of a recognisable location or person, disclosure may be required. The stock library (provider) should indicate whether images are AI-generated; as a deployer, you should verify this and apply disclosure where needed.

Takayuki Sawai
Gyoseishoshi (行政書士)  |  20+ years in government licensing administration  |  AI compliance researcher covering 14 countries
Full profile & credentials →

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Article 50(4), Article 3(60), Article 99
  2. Recital 134 of Regulation (EU) 2024/1689 — artistic and creative exemption guidance
  3. European AI Office, Code of Practice on AI Transparency, finalised June 10, 2026
  4. EU Omnibus Regulation on AI, signed July 8, 2026 — 4-month watermarking grace period for Article 50(2); Article 50(4) deployer obligations unchanged
  5. Coalition for Content Provenance and Authenticity (C2PA), Technical Specification v2.1, 2026
  6. IPTC Digital Source Type vocabulary — NewsCodes for AI-generated content classification
  7. Regulation (EU) 2022/2065 (Digital Services Act), Articles 16, 34-35 — platform obligations for deepfake content
  8. European Commission, Draft Guidelines on Article 50 transparency obligations, March 2026