Definition

Deepfake Disclosure (EU AI Act)

The deepfake disclosure rule is Article 50(4) of the EU AI Act: it requires deployers of AI systems that generate or manipulate image, audio, or video content into a "deepfake" to disclose that the content is artificially generated or manipulated. It's a narrower, deployer-facing obligation, distinct from the general content-marking duty on providers in Article 50(2). This page is general information about the requirement, not legal advice.

Who it applies to, and what counts as a deepfake

The obligation falls on deployers — the organizations or people putting a deepfake-generating AI system to use — rather than on the underlying model's provider. Under the Act, a deepfake is AI-generated or AI-manipulated image, audio, or video content that resembles existing people, objects, places, or events in a way that would falsely appear authentic or truthful to a reasonable person. A related clause in the same paragraph covers deployers of systems that generate text published to inform the public on matters of public interest, requiring similar disclosure that the text is artificially generated.

Exceptions

Disclosure isn't required for AI systems authorized by law for detecting, preventing, investigating, or prosecuting criminal offenses. Content that is evidently artistic, creative, satirical, fictional, or part of an analogous work faces a lighter version of the obligation — the deployer only needs to disclose that generated or manipulated content exists in a way that doesn't hamper the display or enjoyment of the work, rather than a full disclosure. Human-reviewed content published under editorial responsibility carries its own carve-out under the related public-interest-text clause.

Source: Regulation (EU) 2024/1689, Article 50

FAQ

Is deepfake disclosure the same as the general AI content-marking rule?

No. Article 50(2) requires providers of systems that generate synthetic audio, image, video, or text to make outputs machine-readably marked and detectable at the point of generation. Article 50(4)'s deepfake disclosure rule is a separate, deployer-facing duty to actually disclose to the audience that specific deepfake content is artificially generated or manipulated.

Do satirical or artistic deepfakes need to be disclosed?

Yes, but with lighter requirements. Content that is evidently artistic, creative, satirical, or fictional still needs some disclosure that generated or manipulated content exists, just presented in a way that doesn't interfere with the work itself.

How does machine-readable provenance help with deepfake disclosure?

A cryptographically signed provenance record, carried through a watermark or embedded manifest, gives deployers and platforms a reliable, automatable signal that content was AI-generated — supporting the kind of disclosure Article 50(4) calls for. It doesn't substitute for the deployer's own disclosure obligation, which is a legal responsibility, not a technical one.