News·6 min read

The EU Can Now Fine AI Companies €15 Million for Skipping a Deepfake Label

Quick answer ✦As of August 2, 2026, the EU's AI Act Article 50 requires AI chatbots to disclose they're AI, deepfakes to be clearly labeled, and AI-generated images, audio and video to carry a machine-readable mark. It applies to any provider whose AI output reaches an EU user, regardless of where the company is based, and non-compliance can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher. Generative AI systems already on the market before August 2 get until December 2, 2026 to add the machine-readable marks specifically.

Aug 2, 2026

when Article 50 obligations took effect

the European Commission began enforcing it that day, per its official announcement

€15M or 3%

maximum fine for non-compliance

whichever figure is higher, of global annual turnover, under Article 99

Dec 2, 2026

grace period for existing systems' machine-readable marks

per the Commission's transparency quick facts page

There was no press conference for this the way there was for the AI Act itself back in 2024. Article 50 just quietly became enforceable, and it changes what a normal person sees when they interact with AI, not just what a company has to file in a compliance report.

What the law actually requires

  • Chatbots must say they're AI. Any interactive AI system has to disclose that upfront, at the latest by your first interaction with it, unless it's obvious from context that you're talking to a machine.
  • Deepfakes need a label. AI-generated or AI-edited images, audio, or video that resemble real people, places, or events have to be clearly marked as artificial or manipulated.
  • AI content needs a machine-readable mark. Generative systems have to embed a technical signal, metadata, watermark, or similar, so the content can be identified as AI-made by detection tools, not just a human reader.

Who actually has to comply

This is not an EU-companies-only rule. Article 50 applies to any provider whose AI system is placed on the EU market or whose output is used by someone in the EU, regardless of where the company is incorporated or where its servers sit. That covers OpenAI, Google, Anthropic, Meta and every other major AI company the moment an EU user opens their product, the same extraterritorial logic that made GDPR a global standard rather than a European one.

The obvious weak point

A machine-readable mark is not the same as a permanent one. Re-encode a video, screenshot an image, or run text through a paraphraser, and a lot of these signals degrade or disappear entirely, which is exactly why the EU's own Code of Practice on AI-generated content pushes providers toward layering several methods (metadata, invisible watermarking, and logging) rather than betting on any single one. Even that combination doesn't survive every path content actually travels: a repost, a re-upload, a re-compress by whatever platform it lands on.

How the EU's approach compares to the US

EU (Article 50)United States
Federal chatbot disclosure lawYes, since Aug 2, 2026No federal equivalent
Federal deepfake labeling lawYes, since Aug 2, 2026No federal equivalent
State-level deepfake lawsN/A (EU-wide)A growing patchwork, mostly around elections and explicit imagery
Maximum penalty€15M or 3% of global turnoverVaries by state; no uniform federal fine

Several US states already regulate AI-generated election content or non-consensual explicit deepfakes specifically, tracked in detail by policy groups like MultiState, but nothing at the federal level requires the broad, platform-agnostic labeling Article 50 now mandates across the EU.

What to actually watch for

Over the next few months, expect small AI disclosure labels to start showing up more consistently on chatbots, image generators, and video tools used by EU-based companies, and for that labeling behavior to often ship globally rather than being geofenced, since building two versions of a product is usually more expensive than building one. Whether the machine-readable marks survive a trip through a random social platform's re-encoding pipeline is the real test of whether this law does anything beyond the disclosure text you can already see.

Does Article 50 apply to me if I'm not in the EU?

The obligation falls on the AI provider, not the user, but it applies to any provider whose AI system is placed on the EU market or whose output reaches an EU user, so companies serving EU customers have to comply regardless of where they're based.

What counts as a deepfake under the law?

AI-generated or AI-manipulated image, audio, or video content that resembles a real person, object, place, or event, and could mislead someone into thinking it's authentic.

Will I start seeing 'AI-generated' labels on ChatGPT or Gemini?

You should, if you're interacting from the EU. Chatbots must disclose they're AI at the outset, and AI-generated media from these platforms is required to carry a machine-readable mark going forward.

What happens to a company that doesn't comply?

EU regulators can fine it up to €15 million or 3% of its worldwide annual turnover, whichever is higher, under Article 99 of the AI Act.

Does a watermark actually stop deepfakes from spreading?

Not by itself. Machine-readable marks and metadata are easy to strip by re-encoding, screenshotting, or re-uploading content through a platform that recompresses it, which is why the EU's own guidance recommends combining several detection methods rather than relying on one.

Try the tools ✦

Free browser tools that never upload your files.

Open Tools