ISHIGHRISK AI
Analysis

Labelling deepfakes under Article 50(4)

Article 50(4) puts the deepfake labelling duty on the deployer, not the tool vendor, and the artistic carve-out is narrower than agencies assume.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 50(4) puts the deepfake disclosure duty on the deployer, so for commercial content it lands on the marketing team, the agency or the publisher, not on the tool vendor. The vendor owes the Article 50(2) machine-readable marking instead, which is built for detectors and does nothing for a person watching a video, so satisfying one duty leaves the other open. Not every AI image is a deepfake: Article 3(60) needs both resemblance to something that exists and content that would falsely appear authentic, which is why a photorealistic street scene qualifies and a stylised illustration usually does not. The artistic, creative, satirical and fictional carve-out limits the form of the disclosure so it does not hamper enjoyment of the work, it does not remove it. The duty applies from 2 August 2026, and the penalty tier is 15,000,000 euro or 3 percent of worldwide turnover.

The duty lands on the deployer

If an agency generates a video of a recognisable person and a brand publishes it, the labelling duty belongs to the agency and the brand, not to the company that built the generator. Article 50(4) binds deployers, the parties that use an AI system under their own authority in a professional capacity, and for commercial synthetic media that is the marketing team, the production partner or the publisher.

The vendor owes a different thing. Its duty under Article 50(2) is to mark output in a machine-readable format, discharged inside the file and aimed at detection tooling. Nothing about it produces a sentence the audience can read. Article 50 is where the roles reverse, as the provider and deployer page sets out: 50(1) and 50(2) are provider duties, 50(3) and 50(4) are deployer duties.

The date makes this a decision for this week. Article 50(4) applies from 2 August 2026, days away. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved several deadlines, including the high-risk regime and the 50(2) marking date for systems already on the market. It did not move 50(4), so anything scheduled to publish in August is in scope on the day it goes live. The page on what lands on 2 August 2026 sets out the rest of that date.

Where an agency operates the tool and a client publishes the output, the regulation does not allocate between them. Settle in the contract who does the labelling and who checks it, but treat that as an allocation of work and cost. An indemnity does not move a statutory duty off the party that owes it.

What counts as a deepfake, and what does not

The definition sits in Article 3(60): AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Two conditions, both required.

  1. Resemblance to something that exists. Not only faces. The text names objects, places, entities and events, so a synthetic shot of a real building or a real protest is caught with nobody in frame.
  2. It would falsely appear authentic or truthful. The content has to be capable of being taken for the real thing by a person looking at it.

The second condition is why "we used AI, therefore we label" overshoots. A flat vector illustration, a stylised render, a plainly impossible scene: none would be mistaken for a record of something that happened, so none is a deepfake, however synthetic. The first condition is why the duty reaches further than teams expect in the other direction, because a photorealistic image of a high street that never looked like that meets both tests with nobody in the frame. Note the scope too: Article 3(60) covers image, audio and video only, and text falls to the second limb of Article 50(4).

The hard case is the fully synthetic person.A generated model corresponding to no real individual fails the resemblance limb on the face of the text. Two things still bite. The provider's Article 50(2) marking duty turns on synthetic output rather than on resemblance, so it is unaffected. And the setting can supply the resemblance the face does not: place that invented model at a real, identifiable event and the composite is arguably back inside Article 3(60).

Marking is for machines, disclosure is for people

The most common failure is a team that has done one duty and believes it has done both. The provider must mark synthetic audio, image, video or text in a machine-readable format detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, robust and reliable as far as technically feasible. Provenance manifests and invisible watermarks live here. The voluntary Code of Practice on transparency of AI-generated content, published in final form on 10 June 2026, is the likely de facto route to showing this was done properly, and it asks for at least two layers of marking where one technique cannot meet the four statutory criteria. Art 50(2)

The deployer must disclose to the people who see the content. That disclosure is human-visible by definition, and no watermark satisfies it, because a person scrolling a feed cannot run a detector. Art 50(4)

The exceptions do not cross over either. Article 50(2) excepts systems performing an assistive function for standard editing, or not substantially altering the input data or the semantics thereof, and that exception is drafted for the marking duty alone. If a tool is lawfully unmarked on that basis and the output still resembles a real person or place and would appear authentic, the deployer discloses anyway.

2 Aug 2026Article 50(1), 50(3) and 50(4) apply. Article 50(2) marking applies for systems placed on the market on or after that date.
2 Dec 2026Article 50(2) marking applies for generative systems placed on the EU market before 2 August 2026, a transitional period of four months under recital 38 of Regulation (EU) 2026/1744.

The gap between those dates produces a result that reads as a contradiction and is not one. Between 2 August and 2 December 2026 you can lawfully deploy a generative tool whose output carries no machine-readable mark, and still owe the full human-visible disclosure on the content you publish with it. The grace period is the provider's, not yours.

ContentProvider marking, Art 50(2)Deployer disclosure, Art 50(4)
Synthetic video of a named executive reading a scriptYesYes, both limbs of Art 3(60) are met
Cloned voice of a real person in a radio spotYesYes, audio is inside Art 3(60)
Photorealistic image of a real place that never looked that wayYesYes, places count, no person needed
Stylised illustration or obviously synthetic renderYesUsually no, it would not appear authentic
AI-drafted news piece on a matter of public interestYes, text is inside 50(2)Yes, unless the editorial exception is met
AI-drafted product description or internal memoYes, text is inside 50(2)No, not published to inform the public
Crop, colour correction or noise reduction on a real photographExcepted as assistive standard editingNo, the photograph is authentic

The carve-outs, and how far they actually go

Article 50(4) carries a carve-out for creative work and an exception for text. Both are read too generously.

The creative carve-out limits the form. Where the content is evidently artistic, creative, satirical or fictional, or analogous, the disclosure is limited to a form that does not hamper the display or enjoyment of the work. The obligation is narrowed in its manner, not switched off. A film or a piece of satire still discloses, it simply does not have to burn a banner across the face of the work: end credits, a caption in the description or an unobtrusive corner mark all respect the limit.

The word carrying the weight is "evidently", judged from the side of the audience rather than from the brief. A commercial with a comic tone is not evidently satire. If a reasonable viewer could take the content as a record of something that happened, the carve-out is the wrong thing to rely on.

The text limb is narrower than it looks, and its exception is stricter. The second limb of Article 50(4) reaches AI-generated or manipulated text published with the purpose of informing the public on matters of public interest. Both filters have to be passed before the duty exists at all, and most commercial copy passes neither: a landing page sells rather than informs, and a product range is not a matter of public interest. Coverage of an election, a public health question or a planning decision is.

Where the limb does bite, the disclosure falls away only if the content underwent a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Both are required. A rubber stamp does not satisfy the first, because the text asks for a process of review or control rather than an approval event, and a workflow where nobody can be named as answering for the output does not satisfy the second. If you rely on this exception, record who holds editorial responsibility, in advance, by name or by role.

Where the label goes, surface by surface

Article 50(5) sets the manner for both 50(1) and 50(4): the information must be provided clearly and distinguishably at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements. First exposure is the whole test, so the question on every surface is where exposure actually begins for the person.

  • Social video.Exposure begins on autoplay in the feed, muted, with the caption truncated after a line, so a caption-only disclosure arrives after first exposure and often never. Put a legible label in the first frames and keep it on screen. The platform's AI-content flag is worth setting too, but it renders in the platform's own interface and generally does not survive a download and a reshare, so treat it as a supplement.
  • Display advertising. Exposure is the impression, not the click, so a note on the landing page is too late. The disclosure has to sit inside the creative and stay legible at the smallest placement it gets trafficked to. A label readable in the master file and illegible at 300 by 250 has not been provided clearly and distinguishably.
  • Synthetic voiceover. On an audio-only surface it has to be audible, at the start, before the content it qualifies. On a video with a cloned voice, on-screen text does not reach a listener with the screen off and a spoken line does not reach a deaf viewer, so carry it in both channels.
  • Articles and long-form pages. Put it with the byline or beside the asset it describes, not in a page footer. Where a synthetic image or clip is embedded, the caption and the alt text should carry the same words, because accessibility is part of the Article 50(5) duty and a label that exists only as pixels reaches no screen-reader user.

The regulation prescribes no wording. It fixes only what has to be conveyed, that the content has been artificially generated or manipulated, and short and specific works: "AI-generated video", "This voice is synthetic". "Enhanced with AI" is weaker, because a viewer can read it as describing a tool used on real footage rather than as saying the footage is not real.

Penalties, and the harder line above Article 50

Article 50 breaches sit in the middle Article 99 tier: 15,000,000 euro or 3 percent of total worldwide annual turnover, whichever is higher. Under Art 99(6) SMEs and start-ups pay the lower of the two instead. The penalty provisions have been enforceable since 2 August 2025, so the tier is in place before the duty attaches, and the penalties page has all three.

The AI Office begins enforcing from 2 August 2026, and national market surveillance authorities designated under Article 70 handle most of the rest. Designation has been uneven: member states had to name their national competent authorities by 2 August 2025 and only 8 of the 27 did so on time, which the national authorities tracker keeps current. Expect inconsistent early enforcement, not an absence of it.

One category is not a labelling problem at all. From 2 December 2026 the Digital Omnibus adds a ninth prohibited practice under Article 5, covering AI used to generate child sexual abuse material or non-consensual intimate imagery, binding providers and deployers alike. That is the top tier, 35,000,000 euro or 7 percent of worldwide turnover, and no disclosure cures it. Consent and subject-matter checks belong upstream, in the production process.

Four things worth doing before 2 August 2026:

  1. Inventory the synthetic assets already scheduled or in market. An asset built in June and still running in August is in scope on the application date.
  2. Run each one through the two limbs of Article 3(60) and record the answer. "No existing person, place or event is resembled" is a defensible finding when it is written down at the time.
  3. Ask each generative vendor in writing what it marks, in what format and from what date, and whether it treats itself as inside the 2 December 2026 transitional period. The answer changes your evidence position, not your duty.
  4. Fix the placement per surface against the first-exposure test, then check it at the smallest rendered size, with sound off and with a screen reader. The remaining limbs are mapped on the Article 50 transparency page.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Who is responsible for labelling a deepfake, the AI tool or the company using it?

The company using it. Article 50(4) binds the deployer, the party that uses an AI system under its own authority in a professional capacity, so for commercial content that is the marketing team, the production agency or the publisher. The tool vendor owes a separate duty under Article 50(2) to mark output in a machine-readable format, and that duty is discharged inside the file rather than on the screen. Buying a tool that marks its output correctly does not give the deployer a compliant, human-visible disclosure.

Do I have to label every AI-generated image in an ad?

No. The Article 50(4) disclosure duty attaches to a deepfake, defined in Article 3(60) as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. Both conditions have to be met, so a plainly synthetic illustration or a stylised render is usually outside the definition because nobody would take it for a real photograph. A photorealistic image of a real place or a real person is inside it, whether or not the deception was intended.

Is a watermark enough to comply with Article 50(4)?

Not on its own. An invisible watermark or an embedded provenance manifest goes to the Article 50(2) marking duty, which is machine-readable by design and aimed at detection tools rather than at the audience. Article 50(4) requires the deployer to disclose to the people who see the content, and Article 50(5) requires that information to be clear and distinguishable at the latest at the time of first exposure. A viewer scrolling a feed cannot read a watermark, so the two duties have to be satisfied separately.

Does the artistic or satirical exception mean no label is needed?

No. Where the content forms part of an evidently artistic, creative, satirical or fictional work, Article 50(4) limits the disclosure to a form that does not hamper the display or enjoyment of the work. It limits the form, not the existence of the duty, so a credit line, a caption or an unobtrusive mark still has to appear somewhere. The word doing the work is "evidently", which is judged from the side of the audience: a commercial with a comic tone is not evidently satire.

Do we have to disclose AI-written articles?

Only where the text is published to inform the public on matters of public interest, which is the second limb of Article 50(4). A product page or a marketing landing page usually falls outside it. Where the limb does bite, the disclosure falls away if the content underwent a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Both conditions are needed, so a nominal approval click with nobody accountable for the output does not qualify.

What is the fine for not labelling a deepfake?

Article 50 breaches sit in the middle Article 99 tier: 15,000,000 euro or 3 percent of total worldwide annual turnover, whichever is higher. Under Article 99(6) SMEs and start-ups pay the lower of the two instead. The penalty provisions have been enforceable since 2 August 2025, so the tier is already live and attaches to the Article 50(4) duty from the day that duty applies, 2 August 2026.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.