
From this Sunday, AI companies operating in the European Union will face new obligations under the bloc's AI Act requiring them to make deepfakes and other AI-generated content clearly recognisable as artificial. The European Commission developed a voluntary code of practice as a framework for how companies should disclose the artificial origin of synthetic content through machine-readable markings and visible labels for deepfakes.
The rules are stricter for deepfakes, described as realistic AI-generated or AI-manipulated images, audio or videos that imitate a real person's appearance, voice or actions in a way that could lead people to believe they said or did something that never happened. Brussels said not all synthetic content is deceptive, and content created for clearly artistic, creative, satirical or fictional purposes generally falls outside the disclosure requirements.
The Technical Reality
There's currently no single industry-wide solution. Companies are experimenting with watermarking, metadata and content provenance systems that don't always work together or talk to each other. Experts warned that watermarks can be removed, altered or lost when content is edited, compressed or shared across platforms. Researchers argued that no single technology will be enough.
The European Commission's technical study concluded that a combination of solutions is more powerful than any single measure and that a best practice is to implement multiple layers of marking and detection for AI-generated content. Major AI companies like OpenAI and Google have broadly backed transparency requirements by signing the Commission's code of practice, while warning that detection and marking technologies remain a moving target.
What's Required
The code of practice also addresses the associated detection mechanism and requires collaboration among AI companies, social media platforms, civil society organisations and fact-checkers. The rules apply to both the companies developing the technology and those using AI in a professional capacity, while personal uses are excluded from the scope.
The EU adopted sweeping rules to regulate artificial intelligence two years ago and created a dedicated AI Office to oversee implementation. The new obligations come as synthetic media has already caused real-world harm. A 2023 AI-generated image of Pope Francis wearing a fashionable white puffer jacket went viral. AI-generated explicit images targeting Taylor Swift spread online without her consent in 2024. A fake video showed Ukrainian President Volodymyr Zelenskyy telling soldiers to surrender shortly after Russia launched its full-scale invasion of Ukraine in 2022.
Why This Matters:
The EU's deepfake labeling requirements reveal a familiar pattern: Brussels moves first on digital regulation, but the technical infrastructure to enforce it lags behind. Companies are being asked to implement marking systems that experts acknowledge can be easily circumvented. The requirement for collaboration among AI firms, platforms, civil society and fact-checkers creates a complex web of dependencies that may slow detection rather than accelerate it. Member states will bear the cost of enforcement through their national authorities, while the effectiveness of the regime depends on technologies that don't yet reliably work across platforms. The code is voluntary, which raises questions about compliance and competitive disadvantage for firms that invest heavily in labeling versus those that don't. Europe's first-mover advantage in AI regulation risks becoming a competitiveness burden if the US and China don't impose similar costs on their tech sectors.