04/08/26
|

AI Act Compliance for Content Teams: Deepfakes, Disclosure, Deadlines

A practical guide to EU AI Act obligations for anyone producing or publishing content with AI — labeling, workflow, vendor responsibility, and copyright.

Author: Karol Tomaszewski, CEO & Founder, VCreatives

Status as of June 2026 — following the Digital Omnibus political agreement (May 7, 2026) and the final Code of Practice on Transparency of AI-Generated Content (June 10, 2026). Last updated: [add publication date].

TL;DR

The EU AI Act applies to anyone producing or publishing AI-generated content, such as chatbots, virtual assistants, or synthetic audio or video, reaching audiences in the EU, regardless of where the company is based.

August 2, 2026 is the date that matters most for content teams: disclosure obligations for chatbots and labeling obligations for deepfakes become enforceable under the EU AI Act’s risk-based framework.

December 2, 2026 is the deadline for AI tool providers to implement machine-readable marking on generative systems already on the market before August. The Code of Practice, drawn up by independent experts convened by the AI Office, sets out how.

Content and marketing agencies are typically deployers, not providers — most obligations are about labeling and vendor due diligence, not building compliant AI systems from scratch. Human oversight and full technical documentation are mainly concerns for high-risk AI systems (think critical infrastructure or employment screening), not for a typical content workflow.

Penalties for non-compliance can reach fines of up to

What Article 50 Actually Requires

Most content teams don’t need to worry about the AI Act’s high-risk system rules. Those apply to things like employment screening, credit scoring, and law enforcement tools. What content and creative teams do need to worry about is Article 50 — the transparency obligations.

Article 50 covers four situations: informing people they’re talking to a chatbot, labeling deepfakes, marking AI-generated audio/image/video/text as synthetic in a machine-readable way, and disclosing when someone has been exposed to emotion recognition or biometric categorization. For a content or marketing team, the first two are the ones that come up constantly.

A deepfake, under the Act’s own definition, is AI-generated or AI-manipulated image, audio, or video content that resembles existing people, objects, places, or events in a way that could pass as authentic. That definition, not the presence of a “chatbot” or “campaign,” is what triggers the labeling obligation.

The Two Dates That Matter: August 2 and December 2, 2026

August 2, 2026 is the date the core of Article 50 becomes enforceable: chatbot disclosure and deepfake/synthetic-content labeling by whoever publishes the content. This date has not moved, even after the Digital Omnibus negotiations.

December 2, 2026 is a narrower, provider-side deadline. Generative AI systems that were already on the market before August 2 get a transitional window to implement machine-readable watermarking under Article 50(2). The same date also brings a new prohibition on AI tools used to generate non-consensual intimate imagery (“nudifiers”) and CSAM.

Both dates come from the Digital Omnibus, the EU’s simplification package. On May 7, 2026, the Council and Parliament reached a provisional political agreement that pushed back the compliance deadlines for high-risk AI systems (to December 2027 and August 2028, depending on category) while leaving the Article 50 transparency timeline essentially untouched. Formal adoption and publication in the Official Journal were expected before August 2026 — worth double-checking the current status before you publish, since the agreement was still provisional as of mid-June.

What Counts as a Deepfake, and What Doesn’t

This is the part that trips up production teams the most. There’s no single technology that satisfies Article 50 on its own — the Commission’s Code of Practice explicitly rejects the idea that one marking method covers effectiveness, interoperability, robustness, and reliability at once. In practice, compliant systems combine watermarking, metadata, and detection capability.

The Code distinguishes between content that’s fully AI-generated and content that’s merely AI-assisted. A spot where the background and a secondary character are entirely synthetic needs a visible, persistent “AI” label for the full duration of the exposure — not a flash at the end. A shot filmed conventionally where AI only adjusted lighting or removed a stray object sits closer to the “assisted” category and carries a lighter labeling burden.

Until an official EU icon exists, the Code allows a temporary solution: the word “AI” (or its local equivalent), visible and legible for the entire time the content is shown. That’s the practical bar to hit right now for video and static content.

There’s a narrow carve-out for content that’s clearly creative, satirical, or fictional — disclosure still has to happen, just in a form that doesn’t undercut the work. This exception does not extend to deepfakes designed to pass as real statements or news content.

The operating question isn’t “is this an ad?” It’s “could an average viewer mistake this for something authentic?” That’s what decides whether a label is required, whether the content runs as a paid ad or an organic post.

Who’s Responsible: Provider vs. Deployer

The Act splits responsibility between the provider — the company that builds and places an AI model on the market — and the deployer, the one that uses that model or tool. Agencies and studios are almost always deployers: they use someone else’s generative tools rather than build their own models.

That role determines the scope of liability. The technical burden — embedding a machine-readable watermark into generated output — sits with the tool provider. Deployers are largely off the hook for watermarking engineering; their job is the visible side: labeling deepfakes and, where it comes up, AI-generated text on matters of public interest.

There’s a line past which a deployer becomes a provider in its own right: if you substantially modify or fine-tune a model — for general-purpose models, the threshold is roughly one-third of the compute used to train the original — you inherit provider obligations for that modification. Most agency work never gets close to this line, but it’s worth knowing before anyone on the team starts serious fine-tuning.

The operational takeaway: since watermarking is the provider’s job, you need contractual assurance that they’re actually doing it. For every generative tool in your pipeline, check: does it embed a machine-readable mark compliant with Article 50(2)? What rights do you have over generated output? Where is data stored? Can you opt out of having your content used for further training? Is there a data processing agreement? That’s the minimum vendor review for compliance.

Copyright and Training Data: The Opt-Out You Should Know About

The Digital Omnibus didn’t touch Article 53 or the general-purpose AI model regime. What did change is timing: obligations for those models have applied since August 2025, but the AI Office’s real enforcement powers only start on August 2, 2026 — meaning the actual penalty risk for copyright violations only becomes concrete now.

Model providers carry two obligations relevant to copyright: a policy respecting rights holders’ reservations (i.e., honoring a creator’s decision to exclude their content from training), and a sufficiently detailed public summary of the training data used, per the AI Office’s template.

The opt-out mechanism comes from the EU’s Copyright in the Digital Single Market Directive (2019/790), Article 4(3). By default, the directive permits text and data mining, including for model training. But rights holders can reserve their rights — opt out — and for material published online, that reservation has to be machine-readable: via robots.txt, file-level metadata, HTTP headers, or a dedicated rights-reservation protocol.

Article 53(1)(c) of the AI Act requires general-purpose model providers to implement a policy that identifies and honors these reservations using state-of-the-art technology. Crucially, this obligation is extraterritorial — any provider placing a model on the EU market must respect EU rights reservations regardless of where training took place, closing the door on training outside Europe to sidestep opt-out.

For an agency, opt-out cuts two ways. As a rights holder — of your own portfolio, photography, projects — you can reserve those materials against training use, via metadata or a robots.txt rule on your own domain. As a tool user, you should favor providers whose policy genuinely honors these reservations, since that reduces the risk that a model was trained on content acquired against the wishes of its creators. It’s worth remembering this is an opt-out regime, not opt-in: silence defaults to permission.

How Meta and China Are Already Enforcing This

Two questions come up constantly: how are the big platforms handling this, and is this purely an EU thing? On the second point: no. Similar rules are emerging in parallel around the world, and Meta illustrates the tension between industry and regulators well.

Meta plays two roles here. As a model provider (the Llama family), it’s the only major player that declined to sign the GPAI Code of Practice in July 2025, arguing it overreached the AI Act’s scope — while Anthropic, OpenAI, Google, Microsoft, Mistral, and Amazon all signed. The result was the opposite of what Meta likely intended: its models now face closer scrutiny from the EU’s AI Office, and the Act’s obligations apply regardless.

The second role matters directly to agencies, because we publish on Meta’s platforms. Since 2024, Facebook and Instagram read C2PA metadata and automatically attach an “AI Info” label to content that carries it. The problem: metadata-based detection doesn’t distinguish substantial generation from light assistance — it can label a real product photo the same way it labels a fully generated image, and content flagged as misleading can see its reach reduced. Since May 2026, Instagram has also added a separate “AI Creator” account label for creators who mostly publish AI content.

China went furthest, earliest. Since September 1, 2025, AI-generated content labeling measures plus a national standard have applied there. The model is two-layered: an explicit label — a visible “AI” mark — for content that could mislead, and a hidden metadata label with provider name and content ID for all AI content regardless of misleading potential. Platforms like WeChat, Douyin, and Weibo act as enforcers and require creators to declare AI content. Crucially, these rules apply extraterritorially, so a campaign aimed at the Chinese market with AI graphics needs labeling at the source.

Two distinct logics sit side by side: the EU takes a rights-based approach — machine watermark on the provider side, visible deepfake label on the publisher side. China takes a state-control model — explicit and hidden labeling applied broadly, with the platform as enforcer. Together they show that AI content transparency is a global direction, not a regional quirk.

Ads vs. Organic Content: Same Rules Apply

A common misunderstanding worth clearing up: the AI Act doesn’t distinguish between advertising and organic content. What triggers the obligation isn’t whether something is a paid ad — it’s the nature of the content itself: is it synthetic image, video, audio, or text, is it a deepfake. The same generative graphic requires identical treatment whether it runs as an organic post or a paid spot.

“Ad-ness” enters the picture through other regimes, not Article 50 — consumer protection law, unfair commercial practices rules, and platform policy. Meta requires AI disclosure in ads and bans deepfake ads outright, with extra rigor for political and social ads. The audience matters too: the threshold for “misleading” is assessed against the real audience, and it drops if that audience includes vulnerable groups like children — no bad intent needs to be shown.

In practice: don’t ask “is this an ad?” Ask “could an average viewer take this for something authentic?” That second question decides whether labeling is required.

Packshots: The Textbook Gray Zone

There’s no dedicated rule for packshots, but Commission guidance offers a simple heuristic: stylized content or content with minor technical correction sits outside the regime; photorealistic content or content with substantial intervention sits inside it. Light AI assistance doesn’t turn a packshot into a deepfake and doesn’t require a visible label: color correction, noise reduction, lighting adjustment, upscaling, compression, or cleaning up a real product’s background all count as AI-assisted. Substantial intervention does require labeling: object removal, face swaps, colorization, a generative background, a product placed in a fully generated scene, or a generated model holding the product. Some situations — stock retouching, background swaps, face cropping — remain a genuine gray zone that supervisory practice will clarify from August 2026 onward.

The double risk with packshots: legally, you risk under-labeling substantial generation, but on platforms you risk the opposite — over-labeling. Meta, reading leftover C2PA metadata that tools like Photoshop or Firefly leave behind, can attach “AI Info” to a genuinely real product photo, reducing its reach. The practical rule: preserve provenance where a label is genuinely needed, and strip it when the photo is real and the edit is minimal.

Compliance Checklist: What to Do Before August and Before December

By August 2, 2026 (your role as publisher):

  • Build content-AI labeling into your video and static production workflow — clear ownership of who adds the label, at what stage, and in what form.
  • Set a labeling standard: a visible “AI” mark for the full duration of exposure, with a ready-made template for spots and posts.
  • If chatbots or virtual assistants are customer-facing, add a clear disclosure that the user is talking to AI, no later than the first interaction.
  • Classify your content into fully generated versus merely assisted, since they carry different obligations.
  • Run a short team training — the AI literacy obligation applies to everyone working with these tools, not just the technical team.

By December 2, 2026 (your role as a tool and process owner):

  • Audit your generative tools and confirm the provider embeds a machine-readable mark.
  • Clean up vendor contracts: watermarking compliance, rights to output, training opt-out, data processing agreements.
  • Take a firm stance on the new prohibition — no tool or workflow in your production can be used to generate non-consensual intimate content.
  • Update your AI tool inventory along with a risk classification for each one.

FAQ

What is the EU AI Act, and who does it apply to?

The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive law regulating artificial intelligence, built around a risk-based framework. It applies horizontally to anyone building, deploying, or using an AI system, regardless of sector or where the company is based, if the content or system reaches people in the EU — covering both private companies and public bodies, and enforced through different market surveillance authorities across member states, coordinated by the AI Office.

Does a content or marketing agency need to comply with the AI Act?

Yes, if it creates or publishes content using AI tools, for example generative image or video tools, chatbots, or virtual assistants. Most of that work falls under transparency obligations (labeling content), not the high-risk category that requires human oversight, full technical documentation, and certification.

When do the AI Act’s content rules take effect in 2026?

August 2, 2026 is the key date — disclosure for chatbots and labeling for deepfakes and synthetic content become enforceable. December 2, 2026 brings machine-readable marking for generative tools already on the market, plus a new ban on non-consensual intimate content generation. EU legislative bodies reached a provisional political agreement on these dates on May 7, 2026, and the Code of Practice that operationalizes them was published June 10, 2026.

How should AI-generated content be labeled?

Fully AI-generated content is required to carry a visible “AI” label for the entire duration it’s shown. Merely AI-assisted content (light retouching, lighting correction) falls under a lighter regime. The Code of Practice promotes shared, open standards so that providers of generative AI systems and deployers can share practices instead of building incompatible labeling systems from scratch. The test: could an average viewer mistake it for authentic content?

Who’s responsible for labeling — the agency or the AI tool provider?

Agencies are typically deployers, not providers. The technical burden of machine-readable marking sits with the tool provider, set up according to the Code of Practice drawn up by independent experts in AI governance and data governance appointed by the AI Office. The agency is responsible for visibly labeling published content and should have contractual confirmation that its vendor embeds a compliant mark on each AI output.

What are the penalties for non-compliance?

Penalties for AI Act violations are tiered by obligation type, reaching fines of up to several million euros or a percentage of global annual turnover, whichever is higher, for the most serious breaches. Given that different sources cite different percentages for different obligation categories, confirm the exact applicable tier with legal counsel before publishing a specific figure.

Sources