Deepfake Disclosure Rules: EU AI Act and US States
Agencies using synthetic images, video, or audio face two different compliance problems. The European Union has a cross-sector transparency rule for certain AI systems and deepfakes. The United States still relies on a mix of federal law, state statutes, sector rules, platform policies, and claims such as deception, publicity-rights violations, or fraud.
Those systems should not be reduced to “put an AI label on every image.” The legal result depends on what the content depicts, how realistic it is, where it appears, who created or deployed it, and whether it could mislead the audience. This guide provides an operational starting point for agencies, not legal advice.
The EU AI Act rule for deepfakes
Article 50 of the EU AI Act separates obligations for providers from obligations for deployers. Providers of systems that generate synthetic audio, images, video, or text must support machine-readable marking and detection of generated or manipulated output. A deployer that uses an AI system to create or manipulate image, audio, or video constituting a deepfake must disclose that the content was artificially generated or manipulated.
The Article 50 transparency obligations apply from 2 August 2026. The European Commission's Article 50 guidance explains that disclosure for a deepfake must be clear and perceptible to a person. Embedded machine-readable information alone does not satisfy the deployer's visible disclosure duty.
Not every AI-assisted edit is automatically a deepfake. The regulation focuses on generated or manipulated content that resembles existing people, objects, places, entities, or events and would falsely appear authentic or truthful. Routine corrections such as exposure or noise reduction require a different analysis from fabricating a person, product event, or testimonial.
Creative, satirical, artistic, or fictional works receive tailored treatment. Disclosure is still relevant, but it may be made in an appropriate way that does not prevent normal display or enjoyment of the work. Agencies should not interpret that flexibility as a blanket exemption.
Why US state laws do not create one labeling rule
The United States does not have one state-level rule that can be copied into every campaign. State laws target different harms and actors. Common categories include:
- deceptive election communications and candidate deepfakes;
- non-consensual intimate imagery and impersonation;
- synthetic performers, voice, and digital replicas;
- consumer interactions with generative AI;
- high-risk automated decisions involving employment, housing, credit, insurance, education, or essential services.
A product-background edit may fall outside a political deepfake statute. A synthetic endorsement using a real person's likeness may trigger several legal theories even if the file contains an AI label. Disclosure is one control, not a universal safe harbor.
California: election deepfakes are a specific category
California's AB 2655 addresses materially deceptive election content and imposes duties on defined large online platforms during specified periods around elections. The statute distinguishes removal from labeling, defines covered election communications, and includes exceptions for satire, parody, and qualifying news uses.
That is not the same as a general rule requiring every agency-created commercial image to carry an AI disclaimer. It is also important to check current litigation and enforceability before relying on a summary. Teams working on political campaigns should review the chaptered California text and obtain advice for the specific communication, timing, platform, and audience.
Colorado: high-risk AI systems are not a media-labeling law
Colorado's Consumer Protections for Artificial Intelligence law focuses on algorithmic discrimination in high-risk systems used to make or substantially influence consequential decisions. The legislature later moved the relevant effective date to 30 June 2026.
For an agency, the distinction is practical. Generating a campaign background is not automatically the same activity as deploying a high-risk system that influences an employment or housing decision. If an agency builds personalization, lead scoring, eligibility, or targeting systems, the legal analysis may extend beyond the creative asset. The official Colorado legislative summary should be read together with the underlying statute and current regulator guidance.
Build an asset-level compliance record
An agency needs to answer basic questions after the campaign has shipped. Which source files were used? Did the workflow generate or merely enhance the image? Was a real person or protected product claim depicted? Which human approved the result? Where was the final asset published?
Create a record for each accepted asset containing:
- the original file and final derivative;
- client, campaign, territory, channel, and publication date;
- tool and workflow version;
- a short description of generated or materially altered elements;
- licenses, releases, and approval status;
- the required disclosure text and where it appears;
- a stable identifier connecting the file with the campaign record.
This record is more useful than a folder named “AI images.” It supports legal review, client questions, corrections, and later changes in disclosure requirements.
Use two layers of transparency
Human-readable disclosure and machine-readable provenance solve different problems. A visible or audible notice informs the audience at the point of exposure. Provenance metadata can describe origin and edits to compatible tools and platforms.
Do not assume metadata will survive every export, screenshot, messaging app, or content-management system. Test the complete publishing path. If a visible disclosure is legally required, provenance metadata should support it rather than replace it. The guide to C2PA and Content Credentials explains the role and limits of signed provenance records.
A pre-publication checklist for agencies
- Classify the edit. Record whether the asset was corrected, enhanced, composited, or substantially generated.
- Identify people and claims. Check likeness rights, consent, testimonials, product performance, and implied real events.
- Map territories and channels. A global campaign may need different treatment in the EU, US states, and individual platforms.
- Choose disclosure placement. Define wording, size, duration, language, and proximity to the content.
- Preserve provenance. Keep originals, generation records, approvals, and any machine-readable credentials.
- Review platform rules. Ad networks and social platforms may impose requirements beyond legislation.
- Escalate sensitive work. Political content, realistic impersonation, health claims, financial claims, and content involving minors deserve legal review.
Using image tools within a controlled workflow
Deep-Image.ai tools can sit inside a documented production process. Teams can use the AI Generator for new creative material and the API for automated processing. The agency remains responsible for the brief, source rights, review, disclosure decision, and final publication.
Separate low-risk corrections from synthetic content that changes meaning. An exposure adjustment or background cleanup should not be logged as if it were a fabricated spokesperson. Conversely, a photorealistic generated person should not be described as routine retouching.
The bottom line
The EU and US approaches cannot be compressed into one AI-labeling rule. Article 50 creates defined transparency duties that begin applying on 2 August 2026. US state laws remain purpose-specific and may target elections, impersonation, consumer interactions, or high-risk decisions rather than every generated commercial image.
A durable agency process classifies the edit, checks the territory and use case, preserves evidence, and selects both visible disclosure and provenance controls where appropriate. Recheck the official text before launch, because statutes, guidance, litigation, and platform rules can change faster than a campaign template.