In my previous blog, I already touched on this: the Digital Omnibus for AI has shifted quite a few things around, but the transparency obligations in Article 50 of the AI Act came into effect on August 2nd as planned. Since last Sunday, that is now a reality. In preparation, the European Commission also published the final guidelines on this article on July 20th, a solid 50-plus pages of interpretation we will need to work with for the time being.
Time to briefly run through the four transparency obligations, with particular attention to the deepfake requirement. That one is broader than you might initially think.
Article 50 contains four separate transparency obligations, primarily designed to prevent people from being confused about whether something originates from a human or from AI. I prefer to call them 'confusion-prevention duties'. Most of these fall on providers; one rests with deployers.
Providers of AI systems intended to interact directly with people (think chatbots, voice assistants, AI agents, but also automated scanning gates) must design those systems so that users immediately know they are dealing with an AI. This obligation only lapses when it is genuinely obvious, and that exception should be interpreted strictly according to the guidelines. A generic disclaimer tucked into the terms of service will not suffice; the notice must be contextual and appear at the moment of first interaction, for example through a disclaimer or a clear opening message: "Hello, I'm ICTRechtBot; I'm not a human!".
Providers of generative AI systems (including GPAI) must mark their output in a machine-readable format, and that marking must also be detectable. Think watermarks, metadata, or cryptographic provenance methods. The guidelines make clear that both elements, marking and detectability, must be arranged cumulatively. Simply applying a watermark is not enough if there is no accompanying detection tool.
Deployers of these systems must inform the individuals concerned that they are being exposed to such a system. Do not forget, incidentally, that the use of emotion recognition in the workplace or in education is prohibited outright under Article 5. So the transparency obligation does not automatically make use lawful.
Deployers must disclose when image, audio, or video content is a deepfake, and when published text on matters of public interest has been AI-generated or manipulated. For text, an important exception applies: if the content has undergone human editorial review and someone bears editorial responsibility, disclosure is not required.
It is tempting to think of "deepfake" in terms of the classic examples: a politician saying something they never said, or a celebrity placed in a compromising situation. But the definition in the AI Act is considerably broader: it covers AI-generated or manipulated image, audio, or video material that resembles existing persons, objects, places, entities, or events and could falsely appear to be authentic or truthful.
The guidelines flesh out that definition substantially. A few points that stand out:
It does not have to involve people: AI-generated images of existing buildings, products, places, or events can also be deepfakes. A product photo in an advertisement that does not accurately represent the product therefore falls within scope in principle.
Fictional but realistic scenes also count: the subject does not need to actually exist; it is enough that it could plausibly exist. An AI-generated image of a non-existent person who nonetheless looks realistic can be a deepfake. Only clearly fantastical content (dragons, elephants, driving cars) falls outside scope.
The intention to deceive is not required. The test is an objective assessment of whether the content could come across as authentic or truthful to the expected audience. Anyone who underestimates their audience remains obliged to label. And certainly do not overestimate your audience either.
Advertising and corporate content are also covered. The guidelines explicitly cite AI-generated advertisements featuring synthetic influencers, CEO video messages using AI avatars, and AI-manipulated product images as examples of deepfakes. That is more relevant to many marketing departments than they probably realise.
For manifestly artistic, creative, satirical, or fictional works, a lighter regime applies: disclosure is still required, but it should not get in the way of enjoying the work. A subtle mention in the end credits may suffice. However, the guidelines interpret "manifestly" strictly. A commercial spot with a fictional setting, for instance, does not automatically fall under this exception if its commercial nature predominates.
There are two things I want to briefly highlight.
First: the information must be provided clearly and distinguishably, at the latest upon first interaction or exposure. Hiding it in the general terms and conditions or behind a series of menu options is expressly insufficient. And for vulnerable groups such as children, the elderly, or people with disabilities, the communication must be adapted accordingly.
Second: for providers of generative AI systems that were already on the market before 2 August 2026, the Omnibus grants a transitional period until 2 December 2026 for the marking and detectability obligation under paragraph 2. The other obligations, such as deepfake labelling and disclosure upon direct interaction, however apply immediately.
While the high-risk obligations have been granted a few more years of delay, Article 50 is now actually in force. For many organisations, this means concretely: equip chatbots with a disclaimer, mark generative output in a machine-readable way, and (often underestimated) label marketing and communications materials containing AI-generated imagery as deepfakes. Anyone who reads the definition strictly and consults the guidelines will quickly discover that the scope is broader than it intuitively feels.
Reason enough to take a tour of your own organisation and map out where AI content is being generated, shared, or published. Because the obligations are here, and so are the fines: up to 15 million euros or 3% of annual worldwide turnover.
Want to stay up to date with the latest developments in AI? Sign up for our AI newsletter.