From this Sunday, AI companies will be subject to new obligations under the EU's AI Act requiring them to make deepfakes and other AI-generated content clearly recognisable as artificial. Brussels has put the machinery in place, and now the companies that profit from synthetic media have to stamp their output with labels and machine-readable markings, at least on paper.
Brussels Writes the Rules
The European Commission developed a voluntary code of practice as a framework for how companies should disclose the artificial origin of synthetic content through machine-readable markings and visible labels for deepfakes. The language is bureaucratic, the effect is political. The Brussels apparatus is trying to manage a technology it helped normalise through sweeping rules adopted two years ago, while creating a dedicated AI Office to oversee implementation.
The rules are stricter for deepfakes, described as realistic AI-generated or AI-manipulated images, audio or videos that imitate a real person's appearance, voice or actions in a way that could lead people to believe they said or did something that never happened. Brussels said not all synthetic content is deceptive, and content created for clearly artistic, creative, satirical or fictional purposes generally falls outside the disclosure requirements. So the line between manipulation and acceptable fabrication gets drawn by regulators, while the platforms keep moving the material.
The code of practice also addresses the associated detection mechanism and requires collaboration among AI companies, social media platforms, civil society organisations and fact-checkers. That’s the familiar governance ritual: the state sets the framework, corporations keep the infrastructure, and a layer of approved intermediaries is asked to clean up the mess. The rules apply to both the companies developing the technology and those using AI in a professional capacity, while personal uses are excluded from the scope.
A Moving Target for the Platforms
Major AI companies like OpenAI and Google have broadly backed transparency requirements by signing the Commission's code of practice, while warning that detection and marking technologies remain a moving target. That’s the neat trick. The companies sign up to the principle, then explain why the tools don’t quite work yet. Compliance becomes a performance, not a guarantee.
There is currently no single industry-wide solution. Companies are experimenting with watermarking, metadata and content provenance systems that don't always work together or talk to each other. Experts warned that watermarks can be removed, altered or lost when content is edited, compressed or shared across platforms, and researchers argued that no single technology will be enough. The Commission’s technical study concluded that a combination of solutions is more powerful than any single measure and that a best practice is to implement multiple layers of marking and detection for AI-generated content.
That’s the architecture of digital control in miniature: multiple layers, multiple actors, multiple checkpoints, and still no certainty that the thing can be contained once it’s loose. The system wants traceability after the fact, not restraint before the damage.
Synthetic Media, Real Damage
The article cited examples that show why the issue matters. In 2023, an AI-generated image of Pope Francis wearing a fashionable white puffer jacket went viral. In 2024, AI-generated explicit images targeting Taylor Swift spread online without her consent. In 2022, a fake video showed Ukrainian President Volodymyr Zelenskyy telling soldiers to surrender shortly after Russia launched its full-scale invasion of Ukraine.
Those examples are doing a lot of work for the regulators. They show how synthetic media can be used to humiliate, deceive and manipulate at speed, across platforms that are built to reward circulation over verification. The Commission’s answer is disclosure, detection and coordination. The companies’ answer is to sign the code, warn that the technology keeps shifting, and carry on.
What’s left is a regime of labels, watermarks and provenance systems that may or may not survive compression, editing or reposting. The EU calls it oversight. The platforms call it innovation. Ordinary people get the fallout, and then the fact-checkers are asked to mop up the floor.