Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · August 18, 2026

Europe's deepfake rule is now in force, and it lands on the tool, not the fraud

Article 50 of the EU AI Act applies from 2 August 2026: generative tools must mark their output, deployers must disclose deepfakes, fines reach EUR 15m or 3%. Identity checks stay off the high-risk list.

By DiditUpdated
Didit Blog card on a soft blue gradient: 'Europe's deepfake rule is now in force, and it lands on the tool, not the fraud', with a large sparkle line icon.

Article 50 of the EU AI Act applies from 2 August 2026. Providers of generative systems must mark their output in a machine-readable way; anyone deploying a deepfake must say so. The fraudster pointing one at a bank ignores both duties, and the regulation is written in the knowledge that they will.

The short version

  • Regulation (EU) 2024/1689, the AI Act, applies from 2 August 2026. Article 50 requires AI systems that generate audio, image, video or text to mark their output in a machine-readable format so that it can be detected as artificially generated.
  • Anyone deploying a deepfake must disclose that the content is artificial. Article 3(60) defines a deep fake as AI content resembling real people, places or events that "would falsely appear to a person to be authentic or truthful".
  • Breaching Article 50 carries fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Systems already on the market before 2 August have until 2 December 2026 to meet the marking duty.
  • The same Act's high-risk list expressly excludes 1:1 biometric verification, the check that confirms a person is who they claim to be. The tool that attacks the identity check is regulated; the check itself is left alone to work.

Deepfakes are now a standing entry in regulators' fraud assessments

On 30 July 2026 the Gambling Commission of Great Britain published a risk assessment that names deepfake videos and face swaps among the methods used to get past identity checks, and scores identity-document risk at the top of its scale. A deepfake is AI-generated video, audio or imagery that convincingly imitates a real person.

That assessment is one instance of a wider pattern. A check built to compare a face to a document assumes the face on camera belongs to a live person. Generative models broke that assumption, and broke it cheaply: the tooling that produces a film effect can produce a synthetic customer, and the check cannot tell the difference by looking.

The European Union's answer arrived inside its general artificial intelligence law rather than in a fraud statute. Regulation (EU) 2024/1689, the AI Act, is the first comprehensive AI law from a major regulator. Most of its weight falls on high-risk systems: medical devices, hiring tools, credit scoring. It also carries a set of transparency duties, in Article 50, aimed at the ordinary generative tools everyone now uses. Those duties applied from 2 August 2026.

The design choice worth noticing is where the duty sits. The Act does not ban deepfakes. It requires the tool to mark what it makes and the user to disclose what they deploy. The European Commission's stated reason is a right to know, put on the record by the Commissioner responsible when the supporting Code of Practice was published on 10 June 2026.

Europeans have a right to know whether what they see, hear or read has been made or altered by AI, especially when such content can shape public debate. Transparency is how we protect trust.

Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, European Commission. Statement of 10 June 2026

Article 50 splits the work: providers mark, deployers disclose

Article 50 of Regulation (EU) 2024/1689 places two main duties on two different actors. A provider, the firm that builds or supplies a generative AI system, must ensure its outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". A deployer, whoever uses the system, must disclose a deepfake as artificial.

The provider duty is the infrastructural one. Marking has to be built into the system itself, and the Act asks that the technical solutions be "effective, interoperable, robust and reliable as far as this is technically feasible". Machine-readable is the operative phrase: the mark is meant for software, so that other systems can detect synthetic content without a human squinting at it. The Act does not prescribe a technology. Watermarking and provenance metadata are the two candidates that industry standards work has converged on.

The deployer duty is the visible one. Whoever publishes a deepfake must say the content is artificial, "at the latest at the time of the first interaction or exposure". Two further duties complete the set. Systems that talk to people, such as chatbots, must identify themselves as AI unless that is obvious, and firms running emotion recognition or biometric categorisation on people must tell them.

Each duty carries exceptions, and they repay reading. Marking is not required where the AI performs "an assistive function for standard editing", so a photo touch-up is not a deepfake. Uses authorised by law to detect or investigate crime are exempt across the board. Art gets unusual care: where a deepfake is part of an "evidently artistic, creative, satirical, fictional or analogous" work, disclosure need only happen in a way "that does not hamper the display or enjoyment of the work". AI-written text on matters of public interest must be disclosed unless a human editor has reviewed it and someone holds editorial responsibility.

The price of non-compliance is set at Article 99(4): fines up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. That is the Act's middle tier, below the EUR 35 million and 7% reserved for prohibited practices and above the 1% tier for supplying misleading information. Enforcement sits with national market surveillance authorities, the member-state bodies that police product rules.

The Act arrives in stages, and 2 August 2026 was the main one

Article 113 of Regulation (EU) 2024/1689 staggers the law's arrival. Bans on prohibited AI practices applied from 2 February 2025; obligations for general-purpose AI models from 2 August 2025. The regulation as a whole, Article 50 included, applies from 2 August 2026. One category of high-risk duty follows on 2 August 2027.

One transitional matters for the marking duty specifically. Under the European Commission's guidance, a generative system already placed on the market before 2 August 2026 has until 2 December 2026 to meet the machine-readable marking requirement, and content generated before 2 August needs no retroactive label. The disclosure duties on deployers carry no such grace. They run from 2 August.

The supporting texts landed just ahead of the deadline. The Commission published the voluntary Code of Practice on marking and labelling AI-generated content on 10 June 2026; signing it is one way to demonstrate compliance, though "alternative equivalently adequate means" remain open. Commission guidelines that clarify scope and give practical examples accompany it.

DateRuleStatus
1 Aug 2024The AI Act enters into force — Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, in force on the twentieth day after.Passed
2 Feb 2025Prohibited practices banned — Chapters I and II apply: social scoring, certain manipulation and scraping practices.Passed
2 Aug 2025General-purpose AI model duties — Chapter V applies to providers of general-purpose models placed on the market from this date.Passed
10 Jun 2026Code of Practice published — Voluntary code on marking and labelling AI-generated content; Commission press release IP/26/1328.Passed
2 Aug 2026Article 50 applies — The regulation as a whole applies. Marking, deepfake disclosure, chatbot identification and emotion-recognition notice duties are live. Fines to EUR 15m or 3%.In force
2 Dec 2026Marking grace period ends — Systems placed on the market before 2 August 2026 must meet the machine-readable marking duty, per Commission guidance.Ahead
2 Aug 2027Article 6(1) high-risk duties apply — The final tranche: high-risk classification for products under existing EU safety legislation.Ahead

The same Act declines to call identity verification high-risk

Annex III of Regulation (EU) 2024/1689 lists remote biometric identification among high-risk AI uses, then draws a boundary. The listing "shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be". A 1:1 identity check is not on the high-risk list.

The distinction the drafters made is between searching and confirming. A remote biometric identification system scans faces against a database to find out who someone is, typically without their involvement. That is high-risk, with the full apparatus of conformity assessment that follows. A biometric verification check answers a narrower question: is this person the one this passport, this account, this claim belongs to? The person presents themselves and asserts an identity; the system confirms or declines it. That sits outside the entry.

The boundary is a scope line, not an exemption from law. A verification provider still answers to the rest of the Act where it applies, to data protection law, and to the sector rules of every customer it serves. And the Act keeps two neighbouring uses firmly on the high-risk list, emotion recognition and biometric categorisation by sensitive attributes, both of which also carry Article 50 disclosure duties when deployed.

Read together with the labelling duties, the Act's map of the identity check is symmetrical. The generative tool that can fabricate a face must mark its output. The verification tool that confirms a face is left off the high-risk list to do its work. The document the deepfake attacks and the check that reads it are both, in the Act's scheme, infrastructure worth keeping legible. Europe's other new identity rulebook makes the same bet from the opposite direction: the anti-money laundering regulation accepts a document or an electronic identity as alternative routes to verification and declines to rank them.

A labelling duty binds the compliant, and that is the open question it carries

Article 50, in force since 2 August 2026, does not stop a fraudster generating a deepfake. A person using synthetic video to defraud a bank was already committing offences and will not honour a labelling duty. What the rule builds is provenance infrastructure, carried by the compliant majority of tools.

Regulators have used that structure before: put the obligation where compliance can actually be obtained, so that the absence of the expected signal becomes informative. If mainstream generative systems mark their output machine-readably, unmarked synthetic content becomes the anomaly, and software on the receiving end has something to test for. The Gambling Commission's assessment of AI on both sides of the identity check described the attacking side; Article 50 is the first attempt to make that side announce itself.

For a compliance or fraud team the consequences are concrete but, for now, modest. The marks are meant for machines, so verification pipelines gain a new signal to read once the standards work settles; the Code of Practice is where that convergence is happening. Firms that deploy generative AI in customer communication carry disclosure duties of their own from 2 August. And the identity checks themselves keep working exactly as before, because the labelling regime assumes the attacker who matters most will not label.

The proportionality question underneath is the standing one, in a new costume. The duty falls on every compliant provider and deployer in the Union; the harm is done by actors who will ignore it. Whether provenance infrastructure justifies that distribution of effort is a question the Act's own carve-outs acknowledge without resolving, and the first enforcement decisions under Article 99(4) will show how national authorities weigh it. None exist yet. The rule is eight days old.

Key takeaways

The duties are live.

Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026: machine-readable marking for providers, deepfake disclosure for deployers, chatbot identification, and notice for emotion recognition.

One grace period exists.

Systems on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty, per Commission guidance. Disclosure duties carry no grace.

The fine tier is 15 million or 3%.

Article 99(4) sets the ceiling for transparency breaches at EUR 15 million or 3% of worldwide turnover, whichever is higher, enforced by national market surveillance authorities.

Verification is not on the high-risk list.

Annex III excludes 1:1 biometric verification, the check that confirms a claimed identity, from the remote biometric identification entry. Emotion recognition stays on the list.

The rule builds a signal, not a shield.

Fraudsters will not label their deepfakes. The value, if it comes, is that marked mainstream output makes the unmarked kind stand out to machines that check.

Where Didit fits: identity checks under deepfake pressure

Article 50's duties fall on providers and deployers of generative AI systems. Running a KYC (know your customer) check is a different role, and buying verification does not make anyone compliant with the AI Act. If your firm deploys generative tools in customer communication, the disclosure duties above are yours to meet. What a verification pipeline addresses is the other side of the problem this post describes: the synthetic customer arriving at onboarding.

The modules map onto the attack. Passive Liveness at $0.10 per check tests that a live person, not a replayed or generated video, is in front of the camera. Face Match (1:1) at $0.05 per check is precisely the confirmation Annex III describes: it compares the live capture against the document portrait to confirm the person is who they claim to be. ID Verification at $0.15 per check reads and validates the document itself, and where the document carries a chip, NFC Reading at $0.15 per check pulls cryptographically signed data that a screen-presented fake cannot supply. Current prices are on the pricing page.

What stays with you is the judgement the Act deliberately leaves in place. Your risk assessment decides which checks a customer sees, and your processes decide what happens when one fails. No vendor's module reads the Article 50 machine-readable marks yet, because the technical standards are still converging. When they settle, marked content becomes one more signal a pipeline can test. Until then, liveness and chip data are the working defences.

Frequently asked questions

When did the EU AI Act's deepfake labelling rules take effect?

2 August 2026. Article 113 of Regulation (EU) 2024/1689 states that the regulation applies from that date, and Article 50's transparency obligations apply with it. One transitional exists: under the European Commission's guidance, systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty.

What does the AI Act define as a deep fake?

Article 3(60) of Regulation (EU) 2024/1689 defines a deep fake as "AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".

What are the penalties for breaking Article 50 of the AI Act?

Under Article 99(4) of Regulation (EU) 2024/1689, non-compliance with Article 50's transparency obligations carries administrative fines of up to EUR 15 million or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Does the AI Act treat identity verification as high-risk AI?

Not one-to-one verification. Annex III lists remote biometric identification systems as high-risk but states this "shall not include AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be". Emotion recognition systems are on the high-risk list.

Is the Code of Practice on labelling AI content mandatory?

No. The European Commission published the Code of Practice on marking and labelling AI-generated content on 10 June 2026 as a voluntary tool. Signing it is one way to demonstrate compliance with Article 50's marking and labelling obligations; providers may instead use alternative equivalently adequate means.

Related reading

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence — European Parliament and Council · EUR-Lex · Articles 3(60), 50, 99, 113 and Annex III · applies from 2 August 2026
  2. Commission publishes Code of Practice on marking and labelling AI-generated content — European Commission press release IP/26/1328 · 10 June 2026 · source of the Virkkunen statement
  3. Guidelines on transparency obligations for providers and deployers of certain AI systems — European Commission · policy page updated 6 August 2026
  4. Transparency obligations under Article 50 of the AI Act — European Commission FAQ · source for the 2 December 2026 transitional and enforcement allocation
  5. Code of Practice on Transparency of AI-generated Content — European Commission · voluntary compliance route for the marking and labelling duties

Who wrote this

Tuan Nguyen — Growth · Didit

Writes about identity verification, fraud and compliance at Didit.

Last reviewed 10 Aug 2026 against the sources above

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page