DECODING: Europe forces tech companies to label deepfakes
Since Sunday, July 26, 2026 , the European Union's AI Act requires companies deploying artificial intelligence to make deepfakes and other synthetic content identifiable as artificially generated, a requirement Euronews…
- Since Sunday, July 26, 2026 , the European Union's AI Act requires companies deploying artificial intelligence to make deepfakes and other synthetic content identifiable as artificially generated, a requirement Euronews…
- Since Sunday, July 26, 2026 , the European Union's AI Act requires companies deploying artificial intelligence to make deepfakes and other synthetic content identifiable as artificially generated, a requirement Euronews describes as the "first transparency regime in the world" applied to synthetic media at this scale.
- A law that forces a machine to admit what it made is not censorship; it is the bare minimum owed to anyone who might be fooled by it.
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Since Sunday, July 26, 2026, the European Union's AI Act requires companies deploying artificial intelligence to make deepfakes and other synthetic content identifiable as artificially generated, a requirement Euronews describes as the "first transparency regime in the world" applied to synthetic media at this scale. A law that forces a machine to admit what it made is not censorship; it is the bare minimum owed to anyone who might be fooled by it.
The obligation applies to companies operating generative AI systems available in the European Union, including major American providers such as Anthropic, which develops Claude, and OpenAI, which develops ChatGPT. This European requirement contrasts with the more fragmented approach taken across the Atlantic, where individual American states, such as Minnesota, are legislating separately rather than through a single federal framework.
This decoding draws on Euronews' July 28, 2026 analysis, on the European Commission's official guidelines on transparency for AI-generated content, and on parallel American reporting from Reuters, CNBC, the Epoch Times, and the Guardian regarding comparable disputes over AI-generated content in the United States. It separates the binding legal obligation now in force from the voluntary code of practice that remains, at this stage, a recommendation rather than a rule.
What the AI Act's new obligation actually requires
A rule that took effect on a Sunday, with little fanfare
The transparency obligation for deepfakes under the AI Act took effect around July 26, 2026, a Sunday, without the kind of major public rollout campaign that often accompanies significant new digital regulations in the European Union. This quiet entry into force does not diminish the rule's binding legal weight for every company operating within its scope. A law does not need fanfare to bind.
The absence of major publicity around the effective date could partly reflect the technical, rather than symbolic, nature of the obligation: unlike a headline-grabbing fine or ban, a labeling requirement operates mostly behind the scenes, in the code and interfaces of the affected AI systems rather than in a public spectacle.
What counts as a deepfake under the new European definition
The AI Act defines a deepfake as realistic AI-generated or AI-manipulated image, audio, or video content that imitates the appearance, voice, or actions of a real, existing person in a way that would falsely lead someone to believe that person actually said or did something they did not. This definition centers on realism and false attribution rather than on the mere use of artificial intelligence itself.
This precise definition matters because it draws a clear boundary: a synthetic image is not automatically a deepfake under this rule simply because AI produced it; the content must also convincingly imitate a real person in a manner likely to mislead an ordinary viewer about what that person actually did or said.
What escapes this new obligation
Artistic, creative, and satirical works generally exempt
The AI Act's transparency requirement generally exempts artistic, creative, and satirical uses of AI-generated content from the same labeling obligation imposed on other synthetic media, recognizing that these forms of expression rely, by their very nature, on audiences understanding the depicted scenario is not a literal factual claim. A satirical cartoon and a fabricated video of a real crime are not made from the same intention, and the law finally treats them differently.
This exemption requires, in practice, some interpretation of context and intent, a task that could prove more difficult in borderline cases where the line between legitimate satire and content that might genuinely mislead an unsuspecting viewer is not immediately obvious to an automated content-labeling system.
Personal, non-commercial uses also left outside the rule
Content generated for purely personal use, without commercial distribution or public broadcast intent, similarly falls outside the scope of this new transparency obligation under the AI Act, a carve-out that avoids imposing labeling requirements on private, non-public uses of generative AI tools by individual users.
This personal-use exemption still leaves open the question of what happens once such content, initially created for private purposes, is later shared more broadly or goes viral beyond its original intended audience, a gray zone the source material consulted for this decoding does not explicitly resolve.
The voluntary code of practice, a second, softer layer
Machine-readable watermarking as the Commission's preferred tool
The European Commission has developed a voluntary code of practice that recommends combining machine-readable watermarking embedded directly in the content's underlying data with visible labels shown to the end viewer, a dual-layer approach meant to catch both automated systems and human viewers. A watermark only a machine can read protects the platform; a label a human can see protects the person watching.
Machine-readable watermarking allows automated systems, including social media platforms and search engines, to detect and flag AI-generated content even when a human viewer might not immediately notice a visible label, adding a layer of technical detection beyond what the human eye alone could catch.
A recommendation, not yet a binding requirement
This code of practice remains, crucially, voluntary rather than legally binding, which distinguishes it clearly from the mandatory labeling obligation that took effect on July 26 under the AI Act itself. Companies can choose to follow the Commission's recommended watermarking approach, or they can opt for other technical methods to fulfill the underlying binding transparency obligation.
This distinction between the binding legal requirement to label deepfakes and the voluntary recommendation on exactly how to implement that labeling gives companies some technical flexibility, while still holding them accountable for the underlying transparency outcome the AI Act demands.
Why the Commission itself admits the limits of watermarking
A published technical study acknowledging real weaknesses
The European Commission's own technical study concludes that combining multiple detection and labeling solutions produces a more robust result than relying on any single method alone, an admission that no individual technique, including watermarking, is sufficient by itself to guarantee reliable identification of deepfakes at scale. A regulator that publishes its own doubts about its preferred tool is being more honest than most companies ever are about their products.
This official acknowledgment of watermarking's limits, coming directly from the body responsible for designing the underlying policy, lends credibility to independent expert concerns about the technique's practical reliability outside a controlled testing environment.
What experts warn about watermarks being removed or altered
Independent experts warn that watermarks embedded in AI-generated content can be removed, altered, or lost during routine processes such as file compression, format conversion, or simple re-uploading to different platforms, meaning a technically watermarked piece of content might arrive at its final viewer with no trace of that original marking left intact.
This vulnerability to accidental or deliberate removal represents one of the central technical challenges facing any regulatory approach built around watermarking as a primary detection mechanism, a challenge the Commission's own study does not claim to have fully resolved at this stage.
Which companies fall under this new obligation
Major US AI providers directly affected
The AI Act's transparency requirement applies to generative AI providers offering their services within the European Union, which directly includes major American companies such as Anthropic, developer of Claude, and OpenAI, developer of ChatGPT, regardless of these companies' headquarters location outside European territory. A European rule that reaches an American company's product shows exactly how market access, not geography, now defines who must comply.
This extraterritorial reach of European digital regulation is not new; it follows a pattern already established with other EU rules such as the General Data Protection Regulation, where the decisive factor is whether a company serves European users, not where that company happens to be legally based.
What compliance will concretely require from these providers
For companies like Anthropic and OpenAI, compliance with this new obligation will likely require technical adjustments to how their systems flag or embed markers in generated image, audio, and video outputs specifically for users accessing these services from within the European Union, a jurisdiction-specific technical requirement that adds complexity to global product deployment.
No source consulted for this decoding details the exact technical mechanisms Anthropic or OpenAI have specifically adopted to meet this European requirement, an absence of company-specific detail that should be flagged rather than filled with unverified assumptions about their respective compliance approaches.
The contrast with the fragmented American approach
Minnesota's law as a case study in a different model
The parallel case of Minnesota's law banning AI "nudification" tools, set to take effect on August 1, 2026 with fines of up to 500,000 dollars per violation, illustrates a fundamentally different regulatory model than the European approach: a single American state legislating on a narrow category of harmful AI-generated content, rather than a continent-wide framework covering the broader category of deepfakes overall. One law for twenty-seven countries against fifty separate laws for one country says something about which model scales.
According to CNBC and the Epoch Times, xAI, operating as SpaceXAI, has already sued Minnesota Attorney General Keith Ellison over this specific law, arguing its language is too vague, an early legal challenge that illustrates the litigation risk inherent in the fragmented, state-by-state American legislative model.
Why a unified European framework avoids some of these battles
The AI Act's continent-wide scope means a company cannot simply avoid European transparency obligations by operating from a different EU member state, unlike the American situation where a company might, in theory, face different legal exposure depending on which individual state's specific law is at issue in a given dispute.
This structural difference does not mean the European model is free of legal challenges of its own; it means the battleground shifts from disputes between a company and fifty separate American state legislatures to a smaller number of disputes over the AI Act's interpretation before European courts and regulators.
The Jess Asato case as a real-world test of these gaps
A UK lawsuit outside the EU framework, but relevant to it
The lawsuit filed by British Member of Parliament Jess Asato against xAI before the High Court of London on July 28, 2026, alleging that Grok generated non-consensual sexualized images and an alleged video of extreme severity, falls outside the EU's AI Act since the United Kingdom is no longer a member state, yet it illustrates precisely the kind of harm transparency labeling alone cannot fully prevent. A label that says "this is fake" does nothing to stop the fake from being generated in the first place.
More analysis
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
This distinction matters for understanding the limits of the European transparency approach: labeling deepfakes as artificial helps viewers avoid being deceived about authenticity, but it does not, by itself, prevent the underlying generation of non-consensual or harmful content in the first place, a separate and arguably more urgent regulatory question.
What this reveals about the different harms regulators are targeting
The European transparency regime and the type of harm alleged in the Jess Asato case address two distinct problems: one concerns the public's ability to recognize synthetic content as such, the other concerns whether such content should be generated at all when it depicts a real, non-consenting person in a degrading or harmful manner.
Understanding this distinction helps explain why the EU's labeling requirement and Minnesota's generation ban represent complementary rather than competing regulatory strategies, each targeting a different point in the lifecycle of harmful AI-generated content, from creation to distribution to viewer perception.
What labeling can and cannot accomplish
Transparency addresses deception, not necessarily harm
A labeling requirement, however well implemented, primarily addresses the problem of deception, ensuring viewers are not misled into believing fabricated content is authentic, but it does not, on its own, address the separate harm caused when AI-generated content depicts a real, identifiable, non-consenting person in a sexualized or degrading manner, even when clearly labeled as artificial. Knowing a fake image is fake does not undo the harm to the real person it depicts.
This distinction explains why some observers argue that transparency labeling, while a useful and necessary tool, cannot substitute for separate rules governing the underlying generation of certain categories of harmful content, a gap the AI Act's labeling requirement alone does not claim to close.
What happens when labels are ignored or bypassed
No source consulted for this decoding specifies the concrete enforcement mechanism the European Union will use against companies that fail to properly label deepfakes under this new obligation, nor the specific fine amounts applicable in cases of non-compliance, in contrast to the precisely stated 500,000-dollar-per-violation penalty specified in Minnesota's separate law.
This absence of a clearly stated fine amount in the source material available for this decoding should be flagged as a genuine information gap, rather than interpreted as evidence that the European obligation carries no meaningful enforcement consequence for non-compliant companies.
The technical challenge of detecting deepfakes at scale
A rapidly evolving technology outpacing detection tools
Generative AI models capable of producing increasingly realistic synthetic images, audio, and video continue to improve at a pace that regularly challenges the reliability of existing detection tools, creating an ongoing technical race between generation capability and detection capability that regulatory frameworks must constantly adapt to. A detection tool built for today's deepfakes is already behind tomorrow's.
This technological race dynamic partly explains why the European Commission's own study recommends combining multiple detection methods rather than relying on a single technique: no single approach can be expected to remain reliably effective as the underlying generative technology continues to evolve rapidly.
Why combining methods still leaves gaps
Even a combined approach using both machine-readable watermarking and visible labeling cannot guarantee complete detection coverage, particularly for content deliberately stripped of its markers by a bad-faith actor specifically seeking to circumvent the labeling requirement altogether, a scenario the Commission's study appears to acknowledge as a genuine limitation rather than a solved problem.
This persistent gap between the regulatory ambition of universal deepfake labeling and the practical technical reality of imperfect detection tools illustrates the broader challenge facing any government attempting to regulate a rapidly evolving technology through rules that risk becoming outdated before they are even fully implemented.
On the same topic
ESSAY: Fourth Heat Wave — Europe Enters the Age…
On July 28, 2026, the New York Times reports that the…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
What this means for ordinary internet users
A label is only useful if a viewer actually sees it
The practical value of this new transparency obligation for ordinary internet users depends heavily on how visibly and clearly platforms actually display the required labels, since a technically compliant but easily overlooked label provides little real protection against being misled by convincingly realistic deepfake content. A compliant label buried in a settings menu protects a company's legal position more than it protects a viewer's judgment.
No source consulted specifies detailed design requirements for how visible or prominent these labels must be on the interfaces of platforms distributing AI-generated content, leaving considerable practical discretion to individual companies in how they choose to implement this aspect of the underlying European obligation.
What users should still watch for despite the new rule
Despite this new labeling requirement, internet users navigating content originating from outside the European Union's jurisdiction, or content that has been altered after its original creation to strip identifying markers, should not assume that every piece of synthetic media they encounter will necessarily carry a visible or accurate label under this new rule.
This persistent need for individual vigilance, even after a binding transparency law takes effect, reflects the broader reality that regulation alone rarely eliminates the underlying risk of deception entirely, particularly across a global internet where content routinely crosses jurisdictional boundaries within seconds.
What this decoding reveals about global AI governance
Three different countries, three different regulatory philosophies
Comparing the European Union's unified transparency mandate, Minnesota's narrower state-level generation ban, and the United Kingdom's reliance on existing privacy and data protection law in the Jess Asato case reveals three genuinely distinct regulatory philosophies operating simultaneously on the same underlying global technology. The same generative model faces three different legal regimes depending only on which border the resulting content happens to cross.
This regulatory fragmentation across jurisdictions creates genuine compliance complexity for global AI companies like Anthropic, OpenAI, and xAI, which must simultaneously satisfy a continent-wide labeling mandate, a narrower American state-level generation ban, and traditional privacy doctrines being newly applied to an entirely new category of AI-generated harm.
Why this fragmentation may eventually push toward convergence
Historical precedent from other digital regulation debates, notably data privacy following the European Union's General Data Protection Regulation, suggests that companies facing this kind of regulatory fragmentation sometimes choose to apply the strictest available standard globally, for reasons of practical engineering simplicity rather than genuine legal obligation. Companies rarely build two products when building the stricter one everywhere is cheaper than building two.
Should this pattern repeat with deepfake transparency requirements, the European Union's binding labeling mandate could end up shaping global product design well beyond its own legal jurisdiction, a possibility this decoding flags as plausible without treating it as an already confirmed outcome.
What remains unresolved after this rule's entry into force
No confirmed enforcement action yet reported
Discover
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
No source consulted for this decoding reports a first confirmed enforcement action taken by European regulators against a specific company for failing to comply with this new deepfake labeling obligation since its entry into force around July 26, 2026, a genuine information gap given how recently the rule took effect. A rule without a first enforcement case is still, for now, only a promise on paper.
This absence of a reported enforcement precedent should be understood as reflecting the rule's recency rather than as evidence of either full industry compliance or, conversely, regulatory inaction, a distinction this decoding prefers to state explicitly rather than assume in either direction.
Whether the voluntary code will eventually become mandatory
No source consulted specifies whether the European Commission intends to eventually convert its currently voluntary code of practice on watermarking into a binding technical standard, a step that would remove companies' current flexibility in choosing their own preferred method for meeting the underlying transparency obligation.
This remains, at this stage, an open regulatory question rather than an announced policy direction, and this decoding treats it as such, flagging the possibility without presenting it as an already decided or even clearly anticipated next step by European regulators.
Why this rule matters beyond the technology sector alone
A response to a broader crisis of trust in digital content
This new transparency obligation responds to a broader societal concern that extends well beyond the technology sector alone: as AI-generated content becomes increasingly difficult to distinguish from authentic material, the basic ability of ordinary citizens to trust what they see and hear online comes under growing pressure, a concern that touches journalism, elections, and everyday personal interactions alike. A society that can no longer tell the real from the synthetic loses something no single law can fully restore.
This broader stake explains why the European Union chose to act through a binding, continent-wide legal obligation rather than leaving the matter entirely to individual companies' internal content policies, a choice that treats synthetic media transparency as a matter of public interest rather than purely private commercial discretion.
What this case teaches about regulating fast-moving technology
The gap between the Commission's own acknowledged technical limitations and the binding legal obligation now in force illustrates a recurring pattern in technology regulation: governments often must legislate before the underlying technical solutions are fully mature, accepting an imperfect present remedy over an indefinitely delayed perfect one.
This pattern, visible here in the EU's approach to deepfake labeling, will likely repeat itself across other emerging artificial intelligence governance questions in the coming years, as regulators worldwide continue grappling with technologies that evolve faster than the legislative processes meant to govern them.
What this decoding establishes with certainty: since July 26, 2026, the European Union's AI Act legally requires companies to label deepfakes, a binding obligation the Commission pairs with a voluntary, technically imperfect watermarking recommendation it does not claim fully solves the underlying detection challenge. A label is a beginning, never an ending; the machines that generate the fake keep running long after the sticker is applied.
What remains unresolved is whether this transparency mandate will be enforced with real consequence, and whether it will do anything to prevent the kind of harm alleged in cases like Jess Asato's against xAI, where the problem was never a lack of a label, but the underlying generation of harmful content itself.
Signed Maxime Marquette, columnist
Columnist's Transparency box
Editorial positioning
This decoding is written from an acknowledged angle favoring binding transparency regulation of AI-generated content over purely voluntary industry self-governance, while explicitly acknowledging the technical limits of watermarking that the European Commission itself has documented. No company named in this text is accused of current non-compliance.
Methodology and sources
This text relies on Euronews' July 28, 2026 analysis and on the European Commission's official transparency guidelines as primary sources for the AI Act's requirements. Reuters, CNBC, the Epoch Times, and the Guardian were used as secondary sources for the comparative American context.
Nature of the analysis
This text distinguishes between the binding legal obligation that took effect on July 26, 2026, and the voluntary code of practice on watermarking, which remains a recommendation. Enforcement outcomes and company-specific compliance measures are flagged as unreported rather than assumed.
Sources
Primary sources
Secondary sources
Get the tech columns
AI, platforms, digital power: the next analyses straight to your inbox.
Cite this article
Maxime Marquette (2026). DECODING: Europe forces tech companies to label deepfakes. MadMax. https://mad-max.co/en/article/decoding-europe-forces-tech-companies-to-label-deepfakes
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.