Navigating the deep fake labelling requirements under Article 50(4)(1) AI Act
The AI Omnibus gave many businesses reason to breathe a sigh of relief: the application of the AI Act’s core high-risk requirements has been postponed. But AI compliance is not on hold. Particularly, the labelling obligations in Article 50(4) deserve special attention for many businesses.
How will the AI Act affect your use of Gen AI in marketing?
Generative AI has moved into everyday business communication. Marketing teams, communications departments and external agencies increasingly rely on AI tools when producing or adapting, for example, campaign visuals, product videos, website images or social media assets. Given the scale at which these tools are used nowadays, the publication of AI-generated content has become a routine part of business operations.
Yet, from 02 August 2026, organisations can no longer focus solely on creativity and efficiency. Where AI-generated or AI-manipulated content qualifies as a “deep fake” under the AI Act, specific labelling requirements apply. This makes transparency compliance an important consideration for day-to-day marketing and communications activities. Against this backdrop, this article explores the scope of Article 50(4)(1) AI Act and outlines when AI-generated or manipulated content used in retail and marketing contexts requires a disclosure.
The AI Act’s deep fake definition: Beyond impersonation?
Much turns on how the term “deep fake” is understood. It is commonly associated with a specific type of content: a manipulated video, image or voice recording that makes a real person appear to say or do something they did not actually say or do. For many, the term immediately brings to mind sophisticated cyber-attacks, such as the attempted impersonation of Ferrari’s CEO, which was fortunately detected in time before causing significant damage.
The wording of the AI Act, however, is less straightforward. It defines “deep fake” as AI generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
There is currently considerable uncertainty regarding the scope of this definition, particularly as regards to what resembling “existing” persons, objects or other subjects means.
A textual interpretation suggests that the relevant content must resemble a real and specifically identifiable person, object, place, or other existing subject matter. Accordingly, only content that replicates an existing person, such as a well-known musician or famous athlete, would qualify as a deep fake. By contrast, an image depicting a synthetic performer on a concert stage or player on the football pitch, without resembling any existing person, would fall outside the scope of the definition.
The EU Commission’s guidelines on the implementation of the transparency obligations (“Guidelines”), however, favour a materially broader interpretation. According to the Guidelines, three cumulative criteria must be satisfied: (1) a high level of similarity between the AI-generated or manipulated content and the subject being simulated; (2) that simulated subject must exist, be capable of plausibly existing or be something that could plausibly have existed in reality; and (3) the content must have the potential to deceive or mislead a person regarding its authenticity or truthfulness. The last criterion is context-specific and depends on factors such as level of resemblance, the message conveyed, the intended and foreseeable deployment context and audience expectations. According to the Commission’s interpretation, a photorealistic image depicting a synthetic performer on a concert stage or player on a football pitch, may therefore constitute a deep fake even though it does not resemble any specifically identifiable real person. Only clearly unrealistic and physically impossible content, such as unaided flying humans, falls outside of the scope.
How does the difference look like in an example?
Based on the Guidelines, the following AI-generated image constitutes a deep fake. It presents a photorealistic picture of a “corporate event” that, in reality, never occurred. If published on the website, viewers could mistakenly assume that the event actually took place.

On the other hand, the image below, in which the presenter is talking towards a crowd of animals, can be detected as non-realistic scenario very easily. It therefore does not constitute a deep fake, even under the Commission’s broad interpretation.

Affected organisations: Who has to comply?
The labelling obligation for deep fakes applies to deployers of AI systems. “Deployer” means any natural or legal person using an AI system under its authority and in the course of a professional activity. For example, if an organisation uses a third-party AI image generator to create a synthetic image for a marketing campaign, the organisation qualifies as a deployer and must comply with the labelling obligation where relevant conditions are met.
The labelling obligations in Article 50(4) AI Act apply to deployers established or located in the EU. They further apply to deployers outside the EU where the AI output is used in the EU, for example where the deployer publishes or authorises the distribution of deep fakes that are accessible in the EU. On the other hand, where AI-generated content reaches EU audiences through unforeseeable channels that are outside the deployer's control, the obligations are not applicable.
Why is it particularly relevant for advertisement and marketing?
Among the various use cases, marketing and advertising activities deserve particular attention. The broad range of AI tools nowadays available enables organisations to generate entirely new content or alter existing material with minimal effort. While the AI Act provides for limited relief from the labelling obligation for deep fakes forming part of evidently artistic, creative, satirical, or fictional work, the Guidelines indicate that this carve-out does not extend to a number of common marketing and advertising use cases.
Deep fake labelling may therefore be required in the following situations:
AI-generated virtual models:
- A fashion house replaces its photoshoot models with a fully AI-generated "virtual model" wearing its new collection across e-commerce product pages and advertisements.
- A smartphone manufacturer creates an AI-generated "tech reviewer" who appears in an unboxing-style video on the company's own YouTube channel and paid social ads, demonstrating the device's camera and features as though conducting an independent, authentic review.
AI-modified real-life models:
- A cosmetics brand takes genuine "before and after" photos and uses AI to visibly smooth skin texture and reduce visible signs of ageing beyond the product's actual effect, then publishes the images while indicating that they depict authentic and unretouched results.
- A fashion retailer uses AI to insert a well-known actress's likeness into a red-carpet-style video wearing the retailer's dress, a look she never actually wore.
AI-generated or modified products:
- An online fashion retailer uses AI to generate product photos of a knit sweater showing a denser weave, richer colour saturation, and smoother drape than the actual garment shipped to customers, across its e-commerce shop and marketplace listings.
- A footwear brand uses AI to alter the colourway or material finish of a sneaker in its new advertisement campaign (e.g., rendering suede as glossier leather) so the shoe appears more premium than the physical retail item.
Conversely, the following uses are, as a general rule, unlikely to constitute deep fakes:
AI-generated background:
- A fashion retailer photographs a real jacket on a real model and uses AI to place the pair against a generated "Parisian street" backdrop for its website banner and social advertisements, without altering the jacket or the model themselves.
- A sportswear brand photographs a real pair of trainers and uses AI to place them against a generated stadium or running-track backdrop for a digital advertisement, while leaving the trainers unchanged.
Adjustments with AI:
- A fashion brand uses AI to apply colour and light corrections to a dress photo and to extend the studio backdrop behind a real model for aesthetic framing on its product listing page, without altering the dress or the model.
- A car manufacturer films a real vehicle being driven on a public road for a promotional video published on its website, and uses AI to digitally remove a pedestrian who wandered into the background of the shot while separately reducing ambient traffic noise in the audio track, without altering the vehicle itself or the substance of what is shown or said.
How do you need to label relevant content?
Article 50(5) AI Act merely states that information must be clear and distinguishable, provided no later than the first interaction or exposure, and compliant with applicable accessibility requirements. Even from these high-level requirements, it becomes clear that a label or notice appearing solely in a website footer or terms and conditions is insufficient. But how should the required disclosure be presented in practice?
Practical implementation guidance can be derived from the EU Commission’s Code of Practice on Transparency of AI-Generated Content (“Code of Practice”). While the Code of Practice is voluntary and legally binding only for entities that sign up to it, its practical significance extends beyond its formal signatories. Market surveillance authorities are likely to view the Code of Practice as the benchmark for assessing compliance. This is also implied by the Guidelines indicating that organisations choosing not to adhere to the Code of Practice, or that implement alternative measures, are expected to demonstrate how their approach ensures compliance, i.e., achieves the same level of transparency.
The Code of Practice envisages the use of publicly available EU icons as the primary means of disclosure:
While the icon displaying the capitalised acronym “AI” is considered mandatory, the addition of “GENERATED” or “MODIFIED” remains optional and is recommended only. Alternatively, deployers can also use an equivalent icon or label that complies with the design and placement specifications of the Code of Practice.
Turning to the Code’s placement requirements, the icon or equivalent label must be immediately recognisable to natural persons without requiring any user interaction or sustained attention. It must remain visible for a sufficient period to be noticed under normal exposure conditions and be clearly perceivable and distinguishable no later than a natural person’s first exposure to the deep fake. The disclosure should, as a general rule, be embedded directly within the content. The aim is to ensure that the icon or equivalent label remains attached to the deep fake even throughout subsequent sharing. An overlay designed to appear as part of the content itself (e.g., a user interface overlay that appears to natural persons to form part of the content itself) is permissible only as an equivalent alternative to direct embedding and must comply with the same placement principles. As overlays, however, may not survive downloads or screenshots, deployers must make best efforts to ensure that the disclosure is retained when the content is shared or redistributed by others.
The appropriate form, placement and timing of the disclosure, however, depend on the output format of the deep fake:
- Static picture: Place a clearly visible icon or equivalent label inside the image, in a clearly visible position such as the top-right corner, so it is apparent on first viewing.
- Video content: Display the icon at the beginning and, where possible, at regular intervals, and at least after interruptions such as advertising breaks. Continuous display throughout the deep fake segment is recommended. An audible statement alone cannot replace visual disclosure where visual labelling is possible.
- Audio content: Start audio-only content with a short audible disclaimer in plain language, stating its artificial origin. For long-form audio sequences, repeat reminders at suitable intervals and after interruptions. Where a screen is available, add a visual icon.
What are enforcement risks?
Non-compliance with Article 50 AI Act may result in administrative fines of up to EUR 15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
From a practical perspective, the more immediate risk stems from private enforcement rather than regulatory action. This is because the labelling obligations under Article 50(4) AI Act are likely to be viewed as market conduct rules within the meaning of Section 3(a) German Unfair Competition Act (Gesetz gegen den unlauteren Wettbewerb – UWG). As a result, a failure to comply with the labelling requirements may result in unfair competition claims, including warning letters and cease-and-desist actions brought by competitors or consumer interest groups.
Finally, it should be noted that the use of deep fakes portraying real and existing persons without their consent may also result in liability for violations of personality rights.
What are next steps to take?
Businesses should use the remaining period before 2 August 2026 to build Article 50(4)(1) AI Act into their publication processes. The relevant workflows will often sit outside legal teams, such as marketing, communications, digital or product teams. Businesses should therefore raise awareness of the new requirements within those teams and ensure that employees involved in content creation and publication are able to identify potential deep fakes before content is released. They should also keep records of the labelling method selected and the relevant approval decisions to demonstrate compliance if challenged.
Reading list:
Regulatory guidance:
EU Commission, The Code of Practice on Transparency of AI-Generated Content, https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content#1720699867912-0
EU Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
AI and marketing:
McKinsey & Company, From campaigns to continuous growth: AI capabilities shaping marketing, https://www.mckinsey.com/capabilities/growth-marketing-and-sales/our-insights/from-campaigns-to-continuous-growth-ai-capabilities-shaping-marketing
Financial Times, ‘Sometimes reality is not enough’: fashion brands turn to AI, https://www.ft.com/content/af2752e8-d409-40d4-b415-820df0fbedf9
Statista, Artificial Intelligence (AI) use in marketing – statistics & facts, https://www.statista.com/topics/5017/ai-use-in-marketing/?srsltid=AfmBOop-b3x6oLYz5UIxIE1dPwHbgnad86lDtesZOPgn06HYAO8F1gM9#topicOverview
Deepfakes and cybersecurity:
Bloomberg Law, Ferrari Narrowly Dodges Deepfake Scam Simulating Deal-Hungry CEO, https://news.bloomberglaw.com/privacy-and-data-security/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo