DeepFake Check
Back to Blog
DeepFakeCheck Team 5 min read

The EU AI Act's Deepfake Rules Arrive August 2, 2026: What Changes, What Was Delayed, and Why You Still Need Detection

TL;DR — Five Things to Know

  • 1. From August 2, 2026, anyone in the EU who publishes a deepfake — an AI-generated or manipulated image, audio or video that looks real — must disclose that it's artificial (EU AI Act, Article 50(4)).
  • 2. Fines are real: up to €15 million or 3% of worldwide annual turnover (whichever is higher; for SMEs, whichever is lower), enforceable from the same date.
  • 3. One duty was partially delayed: the requirement for AI tools to embed machine-readable markers in generated content (Article 50(2)) applies immediately to tools launched on or after August 2, 2026 — but tools already on the market before that date have a grace period until December 2, 2026.
  • 4. The law does not retro-label anything: content generated before August 2 needs no label, and scammers won't label anything at all.
  • 5. So a missing label proves nothing. Disclosure rules help honest publishers; catching dishonest ones still requires verification habits and detection tools.

What actually takes effect on August 2, 2026

The EU AI Act's transparency chapter (Article 50) becomes applicable. In plain terms, four duties start:

  • Chatbots must reveal they're AI when people interact with them, unless it's already obvious.
  • AI tools must mark their outputs in a machine-readable way so that other software can detect the content is synthetic (with the partial delay explained below).
  • Emotion recognition and biometric categorisation systems must inform the people exposed to them.
  • Deepfakes must be disclosed by whoever publishes them. This is the one that matters most for readers of this site: if a company, creator or organisation deploys AI-generated or manipulated image, audio or video that resembles real people, places or events, it must state the content is artificial. AI-written text on matters of public interest needs disclosure too, unless a human editor takes responsibility for it.

The rules apply to content published from August 2 onward, regardless of when the AI system that made it was released. There is a lighter regime for evidently artistic, satirical or fictional works — a brief, non-intrusive notice is enough there — but no total exemption.

What was delayed — and for whom

In May 2026, EU lawmakers agreed on a package of amendments (the "Digital Omnibus") that softened one specific piece: the machine-readable marking duty for AI providers under Article 50(2).

The nuance matters and is widely misreported:

  • AI tools launched on or after August 2, 2026: must embed machine-readable marks in their outputs from day one. No grace period.
  • AI tools already on the market before August 2, 2026: get until December 2, 2026 to comply.

Everything else — including the deepfake disclosure duty for publishers — stays on the August 2 schedule. December 2, 2026 is also when the EU's new prohibition on generating non-consensual intimate imagery kicks in.

What counts as a "deepfake" under the law

The Act defines a deepfake as AI-generated or manipulated image, audio or video that resembles existing persons, objects, places, entities or events and would falsely appear authentic. Two details from the European Commission's 2026 draft guidance are worth knowing:

  • Intent to deceive is not required. A face swap made "just for fun" still falls under the disclosure duty if it looks real.
  • Clearly impossible content is excluded. A video of a dragon or a person flying unaided isn't a deepfake in the legal sense — it can't falsely appear authentic.

Why none of this protects you from scams

Here is the uncomfortable part. Labeling rules bind the people willing to follow rules:

  • Scammers won't disclose. The investment-fraud ring running a fake celebrity endorsement is already committing fraud; a transparency fine changes nothing about their behaviour.
  • A missing label doesn't mean "real". Content made before August 2 needs no label. Content made outside the EU may carry none. Treating unlabeled content as authentic is exactly the wrong lesson to draw.
  • Enforcement takes time. National authorities receive their powers on August 2; investigations and fines will follow months later.

The practical conclusion: the label tells you about the publisher's honesty, not the content's authenticity. For anything that matters — a payment request on a video call, a viral clip, a job interview — verification is still on you. Manual checks help (we cover the jawline, blink and profile-turn signs in our face swap detection guide), and running the file through a video detector or image detector gives you evidence rather than a guess.

If you run a business, do these three things now

  • 1. Inventory where your teams publish AI-generated media. Marketing visuals, AI avatars in videos, synthetic voiceovers — if any of it could be mistaken for real, plan the disclosure now.
  • 2. Check your vendors' marking support. If you generate content with third-party AI tools, ask whether their outputs carry machine-readable marks — new tools must do this from August 2, existing ones by December 2.
  • 3. Harden your inbound verification. The law regulates what honest actors publish; it does nothing about the deepfake candidate in your hiring pipeline or the cloned voice calling your finance team. Detection and callback procedures remain your job. (Our guide to spotting deepfakes in video calls covers the tests that still break real-time face swaps.)

This article is general information, not legal advice. For compliance decisions, consult counsel familiar with the EU AI Act.

Suspect an image might be AI-generated?

Use our advanced deepfake detection tool to analyze images with high precision.

Analyze Image Now