A person is holding a smartphone; a hologram of an AI input field displaying the terms ‘Prompt’ and ‘generate’

Deepfake or Just AI-Generated? Understanding Disclosure Rules

Since the boom in AI-generated content, many marketing and communication departments like the idea of saving the effort of finding the perfect stock image and creating one themselves instead. Need an image of a family lying happily on a couch? With a good prompt, they can get exactly what they need in five minutes.

That raises a question: is that happy family on the sofa a “deepfake”? And if so, must it be labelled as such?

Most of us think of deepfakes as fake videos of politicians and celebrities in deceptive situations. However, with the AI Act and the Commission's Guidelines on its transparency obligations, it is worth understanding the legal standing on this topic.

Two Roles, Two Sets of Obligations

The AI Act assigns different responsibilities to two different actors.

A provider is the company that develops an AI system (or has it developed) and offers it under its own name. This would be the company behind the image generator. Providers must embed a machine-readable mark (such as a watermark, metadata or a fingerprint) in the images their system produces and make them detectable as AI-generated. Their obligation is broad: it covers almost every synthetic image the system generates, regardless of its content. The main exceptions are standard editing, such as minor cropping or color correction, and edits that do not substantially change the original.

A deployer is anyone who uses an AI system under their authority in a professional context. This would be a company whose marketing department uses an image generator for its next campaign, or whose HR department uses one for its internal communications. Deployers must add labels that people can see or hear. This obligation is narrower than the providers' because it only arises when the resulting image is a deepfake. And deployers cannot rely on the provider's invisible watermark to meet it, as those are two separate obligations.

The difference can be summarised as: providers mark for machines, while deployers label for people.

What Counts as a Deepfake?

Article 3 para. 60 of the AI Act defines a deepfake as “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”.

The Commission has broken down this definition in several criteria, all of which must be met. In plain terms, you can check them with four questions.

  1. Did AI create the image, or change it substantially?

An image fully generated from a prompt meets this condition. So does an existing photo that AI has changed in a meaningful way, for example by swapping a face or adding a person. Minor touch-ups, such as colour correction, will usually not be enough. 

Context matters: an edit that is harmless in a product advert can change the meaning of a news photograph.

  1. Does it resemble a person, object, place, animal or event?

The definition covers persons, objects (buildings, artworks, consumer goods), places, “entities” (which the Guidelines read as animals and other living beings) and events (scenes and situations). The resemblance must be appreciable, meaning a high degree of similarity.

This means that abstract content, such as a swirl of colours, a geometric pattern or a texture, cannot be a deepfake.

  1. Is it realistic?

The subject does not have to exist in real life. According to the Guidelines, it is enough that the image resembles someone or something that “exists, can plausibly exist or could have plausibly existed”. 

The clearly unrealistic falls outside the definition. That means images that defy the laws of nature, such as the Commission's examples of a sphinx flying over the Eiffel Tower or mice arguing about cheese.

This is where the marketing team in the example above should pay attention: the realistic picture of the family on the sofa that we mentioned at the beginning of this article could trigger a labelling obligation, even if the family is fictitious. However, not every photorealistic AI-generated image automatically requires disclosure, since the next point is also required.

  1. Could someone in your likely audience take it as genuine?

We need to ask ourselves whether the image will be taken as authentic or truthful.  

Think about everyone who may realistically see the image. If the image could mislead a part of your viewers, that may be enough. At the same time, you only need to consider your foreseeable audience. An image in a corporate newsletter does not have to be assessed as if the whole internet will see it.

An image is only a deepfake if the answer to all four questions is yes. If any one of them is a no, the AI Act does not require a label.

How to Label Properly

Article 50 para. 5 requires the disclosure to be clear and distinguishable. It must also come no later than the moment someone first sees the content. In practice, that means:

  • Visible without tools: People must be able to see the label without inspecting metadata or using a detection app.
  • On or next to the image: The label must be noticeable and shown with the image itself, for example on it or directly beside it. 
  • Every image, every viewer: The obligation applies to each image and to each person who sees it, not only the first.
  • Accessible: Where accessibility rules apply to your website or service, the disclosure must meet them too.
  • Built to survive distribution: If your images travel through partners or other channels, take proportionate steps so that the label is still shown when the audience sees the image.
  • Does not require the word “deepfake”: The deployer only needs to say that the content has been artificially generated or manipulated. 

A Label Does Not Guarantee Lawfulness

Labelling a deepfake does not by itself make it lawful:

  • If the image depicts an identifiable living person, the GDPR applies: you need a legal basis and you must inform the person concerned, among all other data protection obligations. 
  • Personality rights still apply, such as the right to one's own image, and so do copyright and trademark law.
  • A misleading product image remains misleading advertising under consumer protection law, label or no label.
  • Some content is unlawful whatever the label says, such as non-consensual intimate images or child sexual abuse material.

A Practical Checklist for Deployers

  • Find out where AI images are made. Look at marketing, HR, communications, sales and anyone else who produces content.
  • Train your people on labeling obligations. AI literacy is already a legal requirement under Article 4 of the AI Act, and knowing what must be labeled belongs in that training for the people who create and publish images.
  • Choose a standard label and a standard placement, so that teams do not improvise.
  • Apply the criteria to each type of image.

Author’s Thoughts

In some respects, there is a tension between the Commission's Guidelines and the AI Act itself. The Act speaks of content that resembles “existing” persons, objects or places. The Guidelines stretch “existing” to cover anything that “can plausibly exist or could have plausibly existed”. On that reading, a photorealistic stock-style image of people who never existed can potentially qualify as a deepfake.

It is worth asking what this achieves in ordinary marketing. Advertising photography has always been staged. The smiling family on the sofa was never a family, their happiness was faked, and nobody reasonably believed that they loved the product. Companies did not have to disclose that the people were actors because viewers generally understood the image for what it was: an illustration, not a documentary record of a real family or event.

The Guidelines themselves say that the audience's expectations and the context in which the content is shown matter. If viewers understand an image as illustrative advertising rather than as evidence of a real person or event, it is difficult to see what they are being misled about in any meaningful sense. However, that does not make the assessment easy and it’s bound to come with innumerable gray areas that are likely to keep lawyers and courts busy in the years to come. 

The Guidelines are non-binding, and the Commission itself describes them as a first interpretation, to be revisited as practical experience develops and the Court of Justice provides further guidance. Until then, organizations should document the reasoning behind decisions in gray areas, particularly where they decide not to label, to demonstrate a considered approach rather than a neglectful omission.

If you are unsure whether the images your organisation produces cross the deepfake line, it is worth getting a professional opinion. FIRST PRIVACY and the companies of the DSN GROUP are happy to help.



No comments


« Previous post