The EU AI Act’s transparency rules entered into force in August 2024. However, its rules on AI-generated content took effect on 2 August 2026. This requires organisations targeting EU audiences to label AI-generated content. Providers (the companies building AI tools) must embed a machine-readable watermark in outputs (although there is a grace period until 2 December 20206 for generative AI systems already on the market). Deployers (organisations publishing AI-generated content) must give audiences a clear, human-perceptible disclosure, such as a visible label, on-screen text, or an audio cue, at the point of first exposure to the AI-generated content. This could be a “Made by AI” label. They can be fined up to Euro 15 million, or 3% of their global revenue, for Article 50 transparency breaches. Prohibited AI practices carry a steeper penalty of up to Euro 35 million.
The rules don’t apply to personal use, and it remains allowed to post artistic, satirical, or creative AI content online, though it’s probably best to include a “made by AI” label. There are further exceptions: you don’t need to flag that you’ve used AI for standard photo edits, such as removing a background or correcting red-eye caused by a flash. You can also still run an AI grammar check on a document or colour-correct a video.
But organisations will need to alert users if they’ve used AI to insert new people into a photo, made “substantial” changes to their faces, or mimicked someone’s speech to say something they never actually said. The deepfake test isn’t about intent. Content must be labelled even if there was no intention to deceive and it depicts a fictitious rather than a real person, as long as it looks realistic. It isn’t a defence for the Comms Team to say “We didn’t mean to mislead”.
The new law’s ultimate aim is to increase trust in what we read and see online. Deepfakes can show politicians saying things they never said, helping them win or lose an election. Two days before voting in Slovakia’s September 2023 parliamentary election, an AI-generated audio clip circulated on social media purporting to show opposition leader Michal Šimečka discussing how to rig the election with a journalist. It surfaced during the country’s legally mandated pre-election silence period, when campaigning and rebuttals were restricted, making it almost impossible to debunk in time. His party lost narrowly. Other examples include a January 2024 robocall that cloned Joe Biden’s voice to discourage New Hampshire primary voters, and AI-manipulated audio and video targeting candidates in Pakistan and Bangladesh’s 2024 elections. These cases are exactly why the EU built Article 50 around deepfakes on matters of public interest, including politics and the democratic process.
A European Barometer survey published in February 2026 found that 69% of Europeans are “highly worried” about disinformation and false or misleading information, with a further 19% “moderately worried”. That adds up to 88%!
Although we think we can spot AI content, it is not so easy. “Human or Not” is a social Turing game in which you chat with a stranger for two minutes and try to decide whether you’re talking to a real person or an AI. Try it at https://humanornot.so.
On another Veriff site, there are 12 videos and photos that you need to decide whether they are real or fake: https://storage.googleapis.com/veriff-deepfakes-quiz-cbs/index.html.
BBC Bitesize, primarily aimed at young people, has “AI or Real” quizzes at https://www.bbc.co.uk/bitesize/articles/zqnwxg8.
How did you do?
The new law may help stem the flood of AI slop. However, and it is a big however, the legislation applies only to EU countries. The UK has no bill for a horizontal AI Act equivalent to the EU’s. A House of Commons Library briefing from June 2026 confirms there’s no AI bill before Parliament, and the previous private member’s Artificial Intelligence (Regulation) Bill fell in April 2026 without reaching a second reading. The UK government’s stated approach is “context-specific and sector-by-sector”, with oversight through existing regulators such as the ICO, Ofcom, FCA, and CMA, rather than a single statute. That said, the UK isn’t ignoring deepfakes entirely, just tackling a narrower slice. Since February 2026, Section 138 of the Data (Use and Access) Act 2025 has made it a criminal offence to create, or even request, non-consensual AI-generated intimate images, working alongside the Online Safety Act’s existing ban on sharing such content. There’s no equivalent labelling mandate for political deepfakes or general AI-generated content, though. The UK government has set up a working group looking at AI content labelling but has explicitly stopped short of proposing a statutory labelling regime. For UK-only audiences, that means the “Made by AI” obligation genuinely doesn’t apply, unfortunately. But any UK organisations targeting EU audiences still need to comply with the EU AI Act. Brexit doesn’t insulate you!
[Image of the scales of justice from Unsplash+]



Leave a comment