Skip to main content

Digital Blog of the Agency

Blog Numerique de l'agence
AI Act européen et deepfakes : quelles responsabilités pour les entreprises à partir du 2 août 2026 ?

European AI Act and deepfakes: what responsibilities will businesses have from 2 August 2026?

Creating an image with artificial intelligence, modifying a person's voice, generating a realistic video or publishing a text assisted by ChatGPT are now part of the daily routine for many businesses.

These technologies offer considerable possibilities for communication, advertising, SEO, social media, and content creation. However, they can also be used to deceive consumers, impersonate individuals, or depict an entirely artificial scene as a real event.

To address these risks, the European Union adopted the European regulation on artificial intelligence, commonly known as the AI Act or European AI regulation.

The regulation came into effect on 1st August 2024. Its main transparency obligations concerning AI-generated or manipulated content become applicable from 2nd August 2026.

For companies, communication agencies, website creators, media outlets, influencers, and brands, this evolution poses a very concrete question:

When should it be disclosed that content has been created or modified by artificial intelligence?

What is the European AI Act?

The AI Act is the European regulation 2024/1689 establishing harmonised rules concerning the use and marketing of artificial intelligence systems.

Its goal is to foster trustworthy artificial intelligence while protecting health, safety, fundamental rights, democracy, and the rule of law against potentially negative effects of certain AI systems.

The regulation is based on a risk-based approach. Not all uses of artificial intelligence are therefore subject to the same obligations.

A spell check conducted with AI, generating a decorative background, or using a chatbot does not necessarily pose the same level of risk as a fake video showing a public figure making statements they never made.

The European Union particularly distinguishes:

  • prohibited artificial intelligence practices;
  • AI systems considered high-risk;
  • systems subject to specific transparency obligations;
  • systems presenting minimal or limited risk.

Deepfakes primarily fall under the transparency obligations provided by Article 50 of the AI Act.

What is a deepfake according to European law?

Commonly, a deepfake often refers to a highly realistic fake video showing someone saying or doing something they never actually said or did.

The European legal definition, however, is broader.

The AI Act defines a deepfake, officially termed "hypertrucage" in the French version of the regulation, as an image or audio or video content generated or manipulated by artificial intelligence, resembling existing people, objects, places, entities, or events and likely to be mistakenly perceived as authentic or true.

A deepfake does not concern solely the face of a famous person.

It can also involve:

  • an artificial voice mimicking a leader's;
  • a photograph of a product deceptively modified;
  • a fake image depicting a real place;
  • a video reconstructing an event that never occurred;
  • a fake customer testimonial generated by artificial intelligence;
  • a person artificially integrated into a real photograph;
  • an empty apartment artificially furnished and presented as genuinely fitted out;
  • a face replaced with someone else's.

Are all AI-generated contents deepfakes?

No. This is a crucial distinction.

An abstract illustration, an imaginary landscape, or a completely fictitious mascot does not necessarily constitute a deepfake.

To fall within the European definition of a deepfake, the content must resemble an existing person, object, place, entity, or event and be capable of being mistakenly taken for authentic content.

A clearly fantastic image or an evidently artificial illustration presents a lower risk of confusion.

However, a fake photograph of an actually existing restaurant, a voice imitating a leader, or a fake video testimonial presented as authentic may fall under this definition.

What are the primary risks associated with deepfakes?

The rapid development of artificial intelligence tools makes artificial content increasingly difficult to distinguish from authentic content.

The European regulation identifies risks including misinformation, mass manipulation, fraud, identity theft, and consumer deception.

The risk of deceiving the consumer

A company might use artificial intelligence to enhance a photograph, add a decorative element, or simulate a future plan.

This usage becomes problematic when the consumer might believe the image faithfully represents reality.

For example, a real estate agency that artificially adds a pool to a property, without specifying it is a projection, risks creating a misleading representation of the offered property.

Similarly, a restaurant publishing dishes entirely generated by AI that do not match those actually served can mislead its customers.

The risk of identity theft

AI systems can increasingly realistically replicate a person's face, voice, or expressions.

A fake video might thus give the impression that a leader endorses an investment, validates a payment, or supports a product.

Impersonation can be used against a public figure, but also against a business leader, employee, client, or individual.

The risk of financial fraud

An artificial voice mimicking a leader might be used to request an urgent transfer from an employee.

A fake video could also be used to promote an investment, a cryptocurrency, a product, or a service that was never endorsed by the portrayed person.

The presence of a realistic image, voice, or video increases the apparent credibility of the fraud.

The reputational risk

A deepfake can attribute statements, actions, or behaviours to someone that do not belong to them.

Even when it is later proven that the content is false, its dissemination can cause lasting harm to a person's or a company's reputation.

The risk of misinformation

Deepfakes can depict false events, fake statements, or doctored evidence.

The danger lies not only in the technical quality of the content. It also comes from its rapid dissemination on social networks, private messaging, and video platforms.

The risk of losing trust

As deepfakes become more common, internet users may end up doubting all images, videos, and recordings they view.

This loss of trust thus does not affect only fake content. It can also reduce the credibility of perfectly authentic content.

Who is responsible according to the AI Act?

The AI Act primarily distinguishes the provider of the AI system and the deploying party.

The provider is the entity that develops or commissions the development of an AI system and markets or offers it under its own name or brand.

The deploying party is the business, organisation, or professional person that uses the AI system under its own authority. Strictly personal and non-professional use is excluded from this definition regarding the obligations applicable to deploying parties.

The responsibility of the AI tool provider

The provider of a system capable of generating images, text, audio, or video must ensure that the produced content can be identified as being generated or manipulated by artificial intelligence.

The marking must be done in a machine-readable format. The technical solution must be as effective, interoperable, robust, and reliable as technology allows.

This obligation may particularly concern technical mechanisms of traceability, provenance, or detection integrated into the content.

It does not apply the same way when artificial intelligence merely assists with a standard modification or when the modification does not substantially change the data or their meaning.

The responsibility of the company publishing the content

A company using an artificial intelligence tool in its activity is generally considered a deployer under the AI Act.

The fact that the image or video was created with a tool provided by another entity does not remove its own responsibility.

When a deployer publishes an image, video, or audio content constituting a deepfake, they must indicate that the content was generated or manipulated by artificial intelligence.

In practice, this obligation may concern:

  • a brand publishing an AI-created advertisement;
  • a communication agency preparing a visual for a client;
  • a company posting a video on its social networks;
  • a website using an image that might be confused with a real photograph;
  • a media outlet broadcasting manipulated audiovisual content;
  • a professional using the artificial voice or face of a person.

The responsibility of the client and the agency

In a relationship between an agency and its client, the division of tasks must be clearly defined.

The agency may be tasked with creating the content, advising the client, and adding the necessary mentions. The client may be responsible for validating the content and deciding on its publication.

However, a simple contractual transfer of responsibility does not guarantee that an authority will consider only one party to be accountable.

Depending on the actual role played by each participant, multiple actors in the chain may need to demonstrate that they have fulfilled their respective obligations.

It is therefore wise to include in contracts:

  • who supplies the images, videos, and texts;
  • who decides to use artificial intelligence;
  • who checks the rights to the original content;
  • who validates the realistic or fictitious nature of the content;
  • who adds the transparency label;
  • who retains proof of validation;
  • who assumes editorial responsibility for the publication.

How to indicate that an image or video was created by AI?

Article 50 requires that the information be presented clearly, recognisably, and accessibly.

The user must be able to understand that they are viewing content that is artificially generated or manipulated.

The European Commission specifies that the label should be visible upon first exposure to the content, should not be obscured by another element, and should remain visible when the content is downloaded or reshared.

Simple phrases may be used, such as:

  • “Image generated by artificial intelligence”;
  • “Image partially modified by AI”;
  • “Visual content created with artificial intelligence”;
  • “Video generated or manipulated by AI”;
  • “Voice generated by artificial intelligence”;
  • “Virtual staging created with AI”.

The label must correspond to the reality of the content. It is better to distinguish fully generated content from real content that is partially modified.

Does the law mandate a minimum size of 10 pixels or 10 points?

No, the AI Act does not establish a general rule requiring a font size of 10 pixels or 10 points for all AI-generated content.

The regulation requires clear, recognisable, accessible information that is appropriate for the context.

European recommendations indicate that the icon or label should be of a clearly visible size, but do not create a universal size suitable for a poster, photograph, vertical video, blog post, or social media publication.

A label written in 10 pixels could indeed be too small on some screens and therefore not meet the visibility requirement.

The best approach is to ensure that the label:

  • is easily readable on both computer and mobile;
  • provides sufficient contrast with the background;
  • is not hidden in the terms and conditions;
  • is visible before users perceive the content as an actual representation;
  • remains understandable without specific technical knowledge.

Are European icons mandatory?

The European Commission has created several icons intended to make identifying AI-generated or modified content easier.

These icons can distinguish fully AI-generated content from content that is only partially modified.

Their use is optional. However, the obligation to inform the public, when applicable, is mandatory.

Using the European icon alone does not automatically ensure compliance. The deployer remains responsible for the clarity and effectiveness of the information provided.

Does a simple image retouch require disclosure?

Not necessarily.

A brightness adjustment, cropping, noise reduction, format adaptation, or minor technical correction does not automatically transform a photograph into a deepfake.

The regulation provides an exception for standard modification assistance functions and for transformations that do not substantially alter the original data or their meaning.

The key question is:

Could the modification wrongly lead someone to believe that a person, object, place, or real event is authentically represented?

If the answer is yes, a transparency label becomes highly recommended and may be legally obligatory.

Practical examples for websites and social networks

Example 1: enhancing the lighting of a photograph

A company uses AI to adjust the lighting and sharpness of a real photograph.

If the depicted content is not substantially modified, it generally does not count as a deepfake.

Example 2: adding furniture to an empty apartment

A real estate agency uses AI to virtually furnish an empty apartment.

The image might be mistaken for a real photograph of the property. A label like “Virtual staging created by artificial intelligence” should be clearly displayed.

Example 3: creating the portrait of a fake client

A company publishes the generated portrait of a fictitious person next to a fake testimonial presented as authentic.

This practice poses a high risk of consumer deception. Simply adding a label “created with AI” does not necessarily make a misleading commercial presentation acceptable.

Example 4: depicting a future real estate project

An AI-generated image shows the future appearance of a building.

The publication should specify that it is a rendering, visualisation, or non-contractual image created with artificial intelligence.

Example 5: having an executive speak with a synthetic voice

A video uses an executive’s artificial face or voice to present a company.

The public should be clearly informed that the voice, image, or video was generated or manipulated by AI. The permission of the concerned individual must also be considered in light of other applicable rules.

Example 6: using an evidently imaginary illustration

A company publishes a futuristic city or a non-existent creature.

If no one could reasonably mistake the image for a real place, person, or event, it does not necessarily constitute a deepfake under the AI Act.

What rules apply to texts generated by AI?

The AI Act does not include a general obligation to disclose every sentence produced with the help of artificial intelligence.

Article 50 particularly targets texts generated or manipulated by AI that are published to inform the public on matters of public interest.

In such cases, the artificial origin must be disclosed, except when the content has undergone genuine human review or editorial control and a physical or legal person assumes editorial responsibility for the publication.

This distinction is crucial for companies using artificial intelligence to draft blog articles.

Using AI as an assistive tool does not necessarily mean a label must be placed on every article, provided that a human responsible:

  • verifies the information;
  • corrects errors;
  • checks sources;
  • adapts the text to the business;
  • validates the publication;
  • assumes editorial responsibility for the content.

Automatically publishing a news item or public interest content without human oversight, on the other hand, presents a risk of non-compliance.

Are artistic and satirical works exempt?

Manifestly artistic, creative, satirical, fictional, or similar works benefit from an adaptation of the transparency obligation.

This does not necessarily mean they can be published without any information whatsoever.

The disclosure can be made in a manner that does not interfere with the display or enjoyment of the work. It may, depending on the context, appear in a credit, description, caption, or information associated with the content.

The goal is to preserve artistic freedom while preventing a realistic work from being presented as an authentic document.

Is the consent of the person represented sufficient?

The consent of the person represented is important, but it does not automatically replace the obligation to inform the public.

A person can permit the use of their face or voice while allowing internet users to believe the video is authentic.

When the content matches the definition of a deepfake, therefore, its artificial origin must be disclosed, even when the use of the image has been authorised.

Does the label “generated by AI” make all content legal?

No.

The labelling meets a transparency obligation. It does not automatically transform illicit, defamatory, fraudulent, or misleading content into legal content.

The AI Act operates alongside other European and national regulations, notably those concerning consumer protection, product safety, personal data, intellectual property, and commercial practices. The regulation specifically states that it does not prejudice other European rules regarding consumer protection.

A company must therefore verify both:

  • the transparency regarding the use of AI;
  • the rights to the images and original content;
  • the authorisation of represented individuals;
  • the protection of personal data;
  • the absence of misleading commercial presentation;
  • the truthfulness of advertising claims;
  • the respect for copyright and personality rights.

What sanctions are provided?

Failure to comply with the transparency obligations provided by Article 50 can be sanctioned by an administrative fine of up to 15 million euros or, for a company, up to 3% of its total annual global turnover for the preceding financial year.

The regulation specifies that the higher amount is retained for companies other than SMEs. For SMEs, including start-ups, the lower threshold is applied.

The actual amount will depend on factors including:

  • the nature of the infringement;
  • its severity and duration;
  • the number of people affected;
  • the level of harm;
  • whether it was intentional or negligent;
  • the measures taken to prevent or mitigate the damage;
  • the company's cooperation with authorities.

Sanctions must remain effective, proportionate and dissuasive.

How to prepare your company for the application of the AI Act?

Compliance cannot be limited to adding a sentence under a few images.

A company must implement a genuine management method for content generated or handled by artificial intelligence.

1. Inventory AI tools used

The company must identify the tools used by its teams, agencies, service providers, and subcontractors.

This can include:

  • image generators;
  • writing assistants;
  • translation tools;
  • voice generators;
  • video editing software;
  • chatbots;
  • photo retouching and enhancement tools.

2. Classify content according to its risk level

A spellcheck does not pose the same risk as a fake video testimonial.

Content can be classified according to several criteria:

  • manifestly fictitious content;
  • real content slightly corrected;
  • substantially modified real content;
  • entirely generated content that could be mistaken for real;
  • content depicting an identifiable person;
  • content used for commercial or informational purposes.

3. Implement human validation

Before publication, an identified person must verify:

  • the origin of the content;
  • the level of modification;
  • the risk of confusion;
  • the need for a disclaimer;
  • rights and permissions;
  • the accuracy of the associated message.

4. Create label templates

The company should prepare several disclaimers tailored to its uses:

  • image fully generated by AI;
  • image partially modified by AI;
  • virtual adjustment;
  • synthetic voice;
  • fictitious reconstruction;
  • non-contractual illustration;
  • content reviewed and validated by a human supervisor.

5. Maintain traceability

It is wise to keep:

  • the original content;
  • the modified content;
  • the name of the tool used;
  • the creation date;
  • the main instructions given to the tool;
  • the identity of the person who verified the content;
  • the validated version;
  • proof of permission from represented individuals.

6. Train employees

The AI Act also requires providers and deployers to take measures to ensure a sufficient understanding of artificial intelligence among those who use these systems on their behalf.

An internal charter thus does not suffice if employees cannot recognise a deepfake or determine when a disclaimer is needed.

CKom Valencia's recommendations for its clients

At CKom Valencia, we consider that artificial intelligence should be used as a tool for creation, translation, SEO, and enhancing user experience, without misleading the internet user.

For websites, blog posts and social networks, we recommend following three simple principles:

  1. Never present an artificial scene as real if it can influence a client's decision.
  2. Clearly inform the internet user when realistic content has been generated or substantially manipulated by AI.
  3. Maintain human validation and editorial responsibility over the texts and content published.

Artificial intelligence can be used to create an illustration, translate an article, enhance a photograph, or optimise content for SEO.

But the company must always be able to answer four questions:

  • What part of the content is real?
  • What part has been generated or modified?
  • Can the public be misled?
  • Who verified and validated the publication?

FAQ on the AI Act and deepfakes

When do obligations regarding deepfakes become applicable?

The transparency obligations outlined in Article 50 of the AI Act become applicable from 2 August 2026.

Do I have to flag all images created by artificial intelligence?

No. The obligation specifically targets images, videos and audio content constituting deepfakes, meaning content resembling existing people, objects, places, or events that could be mistaken for authentic.

Must an entirely fictitious image be labelled?

Not necessarily under the rule concerning deepfakes. If the image is manifestly imaginary and cannot be mistaken for an authentic representation of a person, place, or real event, it may not necessarily meet the definition of a deepfake.

Is a photograph retouched with AI a deepfake?

Not automatically. A minor technical retouch usually does not suffice. However, a substantial modification that alters the represented reality and can mislead internet users may fall under Article 50.

Must the mention be in a font size of 10 pixels?

No. The regulation does not prescribe a universal size of 10 pixels or points. It requires the information to be clear, recognisable, and accessible. A size of 10 pixels might even be inadequate on some media.

Are the European Union icons mandatory?

No. Their use is optional. However, the transparency obligation remains applicable when the content falls within the scope of Article 50.

Does a blog post written with AI need to be flagged?

Not systematically. For texts intended to inform the public on matters of public interest, the obligation does not apply when the content has undergone human review or editorial oversight and a physical or legal person assumes editorial responsibility for its publication.

Must a satirical work contain a mention?

The obligation is adjusted for manifestly artistic, creative, satirical, or fictional works. Disclosure may be executed in a manner that does not interfere with the presentation or appreciation of the work.

Who should add the mention: the agency or the client?

This depends on the actual role of each party and the contract concluded. The agency might create and prepare the mention, while the client may validate and publish the content. It is advisable to clearly define this responsibility in contracts and validation procedures.

Does adding a mention protect against all liability?

No. A transparency label does not legitimise fraudulent, misleading, defamatory content or content published without the necessary permissions.

What are the penalties for non-compliance?

Infringements of the transparency obligations of Article 50 can lead to a fine of up to 15 million euros or 3% of the total annual global turnover of a company, as stipulated by the regulation.

Conclusion: using artificial intelligence without deceiving the internet user

The AI Act does not prohibit the creation of images, videos, texts, or audio content with artificial intelligence.

It primarily imposes a transparency rule when artificial content might be confused with reality.

From 2 August 2026, companies must be able to identify the relevant content, label it correctly, maintain traceability, and train those who use artificial intelligence tools.

The best approach is not to systematically add a mention to every piece of content. It is to understand the level of transformation performed and the risk of misleading the user.

Artificial intelligence can enhance creation and improve communication. It must never prevent the public from clearly distinguishing between authentic information and artificial representation.

This content provides general information on the AI Act and does not constitute legal advice tailored to a specific situation. Companies facing sensitive cases should have their practices reviewed by a legal professional.

Blog

©

Website and ecommerce creation in Valencia.
Powered by ckomvalencia.com.