As of Sunday, companies developing or deploying generative AI systems within the European Union must comply with new transparency obligations under the bloc's AI Act. The rules, adopted two years ago and overseen by the EU's dedicated AI Office in Brussels, require providers of tools like Anthropic's Claude and OpenAI's ChatGPT to ensure that artificially generated or manipulated content is clearly identifiable as synthetic.
The provisions are particularly stringent for deepfakes — realistic AI-generated or altered images, audio, or video that imitate a real person's appearance, voice, or actions in a way that could deceive viewers into believing something never happened. The aim is to help citizens distinguish genuine information from fabricated material in an era of increasingly convincing synthetic media.
Not all synthetic content is deceptive
Brussels acknowledges that AI-generated material can serve legitimate creative, artistic, satirical, or fictional purposes. A well-known example from 2023 involved an AI-generated image of Pope Francis wearing a white puffer jacket, which went viral but was widely understood as a joke. Similarly, content created for clearly artistic or satirical contexts generally falls outside the deepfake disclosure requirements.
However, the same technology can be weaponised. In 2024, explicit AI-generated images of pop star Taylor Swift circulated online without her consent, reigniting debates about the risks of synthetic media. Deepfakes have also been used for political manipulation: in 2022, shortly after Russia launched its full-scale invasion of Ukraine, a fake video showed President Volodymyr Zelenskyy urging soldiers to surrender. It was quickly debunked, but it demonstrated how synthetic media could be exploited in wartime. More recently, an AI-generated image falsely showed President Macron kneeling before the Thai king, and other fakes sought to claim the Kyiv Monastery attack was staged.
How the rules are supposed to work
The European Commission developed a voluntary code of practice that outlines how companies should disclose the artificial origin of synthetic content. This includes both machine-readable markings — such as watermarks or metadata — and visible labels for deepfakes. The idea is straightforward: people should know when they are looking at AI-generated or AI-altered content. The rules apply to developers of AI systems and to professional users, while personal uses are exempt.
The code also addresses detection mechanisms, requiring collaboration among AI companies, social media platforms, civil society organisations, and fact-checkers. Major players like OpenAI and Google have broadly backed the transparency requirements and signed the code. Yet they have also warned that detection and marking technologies remain a moving target.
Technical and jurisdictional gaps
Enforcement faces several hurdles. First, the EU can regulate companies operating in or targeting the European market, but online content does not stop at borders. A deepfake created outside Europe can reach millions of European users within minutes. Second, there is currently no single industry-wide solution for marking and detection. Companies are experimenting with different approaches — watermarking, metadata, content provenance systems — that often do not interoperate.
Third, digital traces are fragile. Watermarks can be removed, altered, or lost when content is edited, compressed, or shared across platforms. Tracing the full history of an AI-generated image through multiple edits is extremely difficult. Researchers argue that no single technology will suffice; a multilayer approach combining several methods is likely necessary. The European Commission's own technical study concluded that "a combination of solutions is more powerful than any single measure."
The broader challenge is keeping pace with rapid advances in generative AI. As synthetic content becomes harder to distinguish from reality, the EU's pioneering regulatory framework may need constant updating. For now, the bloc is taking a leading role in tackling one of the defining challenges of the AI era — but whether the rules will prove effective in practice remains an open question.


