News

The EU’s AI Labeling Rules Are in Force, but Synthetic Media Remains Hard to Trace

The European Union has reached an important point in its attempt to regulate artificial intelligence. After two years of legislative deadlines, industry consultations, and arguments over whether Europe was moving too quickly or too slowly, parts of the EU AI Act are no longer theoretical.

As of August 2, companies operating in the European market must comply with new transparency requirements covering chatbots, deepfakes, and certain other AI-generated material. The European Commission has also expanded its enforcement operation in Brussels, adding staff and establishing new mechanisms for reporting suspected violations.

The goal is simple: people should know when they are interacting with AI or viewing machine-generated content. But accomplishing that goal will be anything but simple.

The new rules attempt to create a chain of accountability stretching from the company that develops an AI system to the business or organization that publishes its output. They also depend on technical markers that can be lost when a file is edited, converted, or passed through platforms that do not preserve its provenance.

The EU is not simply telling companies to put an “AI-generated” sticker on synthetic media. It is trying to make artificial content traceable across an internet that was never designed to preserve that kind of information.

A Label for the Synthetic World
Article 50 of the AI Act establishes several transparency obligations. Providers must generally tell people when they are interacting directly with an AI system, unless that interaction is already obvious. They must also design generative systems to place machine-readable markings in synthetic or manipulated audio, images, video, and text.

Organizations using AI professionally face a related set of responsibilities. They must disclose when they publish deepfakes, use certain emotion-recognition or biometric-categorization systems, or publish AI-generated text about matters of public interest without human editorial review.

The rules distinguish between a provider, which develops or supplies an AI system, and a deployer, which uses it professionally. A model developer may be responsible for embedding provenance information in an image, while a political campaign or media organization publishing that image could be responsible for making the disclosure visible to the audience.

Personal and nonprofessional uses are generally excluded. Artistic, fictional, and satirical works receive more limited disclosure requirements, although the precise treatment depends on how the content is presented.

That division of responsibility is important. Synthetic content usually does not travel directly from an AI model to an audience. It may pass through an application, an advertising platform, and a social network before anyone sees it. The EU’s approach recognizes that disclosure can fail at any point in that chain.

It also means that compliance is not solely an OpenAI, Google, or Anthropic problem. Software companies incorporating their models, publishers using generative tools, and other professional users may acquire obligations of their own.

Enforcement, With Some Qualifications
The European AI Office will oversee parts of the system, particularly when a company provides both a general-purpose model and an AI system built on it. National market-surveillance authorities will handle much of the remaining enforcement. AI used by EU institutions falls under the European Data Protection Supervisor.

The AI Office’s authority is therefore important but not universal. Enforcement will be distributed across European institutions and national regulators, depending on the system and the industry in which it is deployed.

The Associated Press reported that the Brussels operation is adding 38 employees, along with confidential reporting and whistleblower tools. Regulators are expected to examine risks that extend beyond misleading media, including models that could support cyberattacks or produce illegal content.

Companies that violate the transparency requirements could face fines of up to €15 million or 3 percent of worldwide annual revenue, depending on the offense and the size of the company.

But August 2 was not a single switch that activated the entire AI Act. Systems introduced after that date must comply with the Article 50 requirements. Systems already on the market receive a limited transition period until December 2 for the machine-readable marking and detection requirement. Content created before August 2 does not have to be labeled retroactively.

Other major provisions remain further away. Rules covering stand-alone high-risk AI systems have been delayed until December 2027. Requirements for high-risk systems embedded in regulated products are scheduled for August 2028. The EU has also adopted a prohibition targeting systems used to generate nonconsensual sexual deepfakes or AI-generated child sexual abuse material, which is due to apply in December.

The result is a regulatory rollout with several clocks running at once. Transparency rules are arriving now, while some of the law’s most demanding requirements have been pushed into the future.

The Weakest Link Is the File
The policy rests on two kinds of disclosure. One is intended for people, such as a visible label attached to a deepfake. The other is intended for machines, allowing software to inspect a file and determine whether it was generated or altered using AI.

Technical approaches include embedded metadata and invisible watermarks. Standards such as C2PA can record a file’s origin and editing history in cryptographically signed metadata. Watermarks can place a less visible signal directly inside the content.

Neither approach is foolproof.

Metadata may disappear when an image is uploaded to an incompatible platform or converted into another format. Taking a screenshot can remove the original C2PA record entirely. Invisible watermarks may survive some transformations, but they can be weakened by cropping, compression, or deliberate manipulation.

OpenAI, which uses both C2PA metadata and Google DeepMind’s SynthID watermarking in its generated images, acknowledges that an absent signal does not prove an image is authentic. Metadata can be stripped, and watermarks can be degraded. Its verification system can indicate that an image came from OpenAI’s tools, but it cannot establish that the image is accurate or being presented in its original context.

That distinction matters. Provenance can help answer, “Where did this file come from?” It cannot necessarily answer, “Should I believe what this file appears to show?”

A genuine photograph can be paired with a false caption. A synthetic image can depict something that really happened. An authentic recording can be selectively edited. Labels provide context, but they do not eliminate the need for verification or editorial judgment.

The Risk of Label Fatigue
The law faces a second problem that is more human than technical. A warning loses value when it appears everywhere.

Industry critics contend that an overly broad interpretation of “deepfake” could result in labels being attached to routine advertising images, entertainment, and other material that was never intended to deceive. If consumers encounter AI disclosures as frequently as cookie banners, they may learn to ignore them.

The European Commission has developed optional standardized icons and a voluntary Code of Practice to encourage consistent implementation. The code covers technical marking, detection, and visible labeling, giving companies a common route for demonstrating compliance. Signing it does not conclusively prove that a company has met the law, but it can simplify how regulators evaluate its practices.

Consistency will be critical. A label that means one thing on a social platform and something different in an advertisement will create confusion rather than clarity. A marker that disappears when content moves between services will leave investigators with gaps precisely where provenance matters most.

Europe’s Rules Will Not Stay in Europe
The AI Act applies beyond companies headquartered inside the EU. A U.S. developer offering an AI system in Europe can fall within its scope, as can a company whose system produces output used in the European market.

That reach gives the law the potential to produce another version of what became known as The Brussels Effect. When a market as large as the EU establishes product requirements, multinational companies often apply those requirements more broadly rather than maintaining separate systems for every country.

AI labels could follow that pattern. A model provider that builds machine-readable provenance into its European output may find it simpler to include the same capability worldwide. Social platforms could make European disclosure icons part of their global interface. Enterprise buyers outside Europe may begin demanding the same records from vendors because the infrastructure already exists.

That does not mean the EU’s system will become a universal standard. U.S. policymakers remain more skeptical of broad technology regulation, and governments disagree about where transparency ends and compelled speech begins. Open-weight models also make comprehensive enforcement difficult because people can run or modify them outside the provider’s hosted service.

Still, the EU has done something no voluntary industry pledge could accomplish. It has made transparency a legal obligation rather than a product option.

The real test will not be whether compliant AI tools can attach labels under controlled conditions. Most large developers can do that. The test will be whether those signals remain intact as content crosses applications, platforms, and borders.

Europe has created a legal expectation that synthetic media should carry its history with it. Now the technology has to catch up.

About the Author

John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS.  He can be reached at [email protected].

Featured