Article 50(4) of the EU AI Act (Regulation (EU) 2024/1689) requires deployers to disclose when image, audio or video content is a deepfake, and when text has been artificially generated or manipulated for publication on matters of public interest. Two carve-outs sit inside that duty — a lighter disclosure for content that is “evidently” artistic, creative, satirical or fictional, and no disclosure at all for text that passed through genuine editorial control. Both sound generous on a first read. Neither is as wide as it looks, and the European Commission’s draft guidelines, published 8 May 2026, spend more time narrowing them than most summaries let on.
Which content counts as a deepfake under Article 50(4)?
The duty sits with the deployer, not the provider — whoever publishes or puts the content in front of people, not whoever generated it. It applies to AI-generated or manipulated image, audio or video content that constitutes a deepfake under Article 3(60): content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic or truthful.
The Commission’s draft guidelines read that definition wider than most people assume. Three clarifications matter:
- Intent is irrelevant. Whether the content falsely appears authentic doesn’t depend on whether the deployer meant to deceive anyone. An absence of fraudulent intent doesn’t defeat the labelling duty.
- “Existing” is read broadly. A realistic synthetic depiction of a fictitious but natural-looking person can still be a deepfake, even where no identifiable real person is implicated — it’s enough that the subject resembles someone or something that could exist, or could once have existed.
- Not every edit counts. Routine adjustments — lighting, colour correction, noise reduction, sound cleanup — normally don’t turn content into a deepfake, because they don’t meaningfully affect how truthful it appears. More substantial changes that alter meaning or context, such as edits to a photograph used in journalism, can. The guidelines treat this as a case-by-case judgment rather than a bright line.
The artistic, creative, satirical and fictional carve-out
Where a deepfake forms part of a work or programme that is artistic, creative, satirical, fictional or similar in nature, Article 50(4) is satisfied by a lighter disclosure: making known that the content exists in generated or manipulated form, in a way that doesn’t hamper the display or enjoyment of the work — a credit rather than an overlay stamped across the frame.
The word doing the real work in that sentence is one most summaries drop. The original text requires the work to be evidently artistic, creative, satirical or fictional — not arguably, not defensibly, but obviously so. That’s not loose paraphrasing: it’s the actual qualifier in the operative text, and the Commission’s draft guidelines lean on it directly, treating it as a threshold the content has to clear plainly rather than a label a deployer can assert after the fact.
That threshold has teeth, and the clearest illustration is political satire — the case that looks safest on paper. A deepfake of a real politician, shared on social media to mock a decision they made, looks like a textbook fit for the satirical carve-out. Commentary on the draft guidelines gives exactly this example and reaches the opposite conclusion: the exception doesn’t apply, because the same content also touches public discourse on a matter of public interest. Satire and public-interest commentary aren’t mutually exclusive categories under Article 50(4) — they can describe the same clip, and where they do, the more consequential reading controls, not the more convenient one.
The Code of Practice on Transparency of AI-Generated Content addresses this carve-out too, in the section covering deployer labelling of deepfakes and public-interest text. It’s a voluntary compliance tool, not a substitute for reading the exception correctly — signing it demonstrates a method, it doesn’t relax the “evidently” test underneath.
The text carve-out and its two cumulative conditions
Article 50(4)’s second limb catches AI-generated or manipulated text published to inform the public on matters of public interest. It doesn’t catch text that isn’t public-interest text in the first place — an AI-drafted product description or an internal memo was never in scope, carve-out or not.
For the text that is in scope, disclosure drops away entirely, but only where two conditions are both met: the content has undergone a process of human review or editorial control, and a natural or legal person holds editorial responsibility for publishing it. Both, not either. A generative system that drafts news summaries with nobody reviewing them, and nobody named as accountable for what goes out, gets neither condition and has to label every piece.
“Editorial control” is doing more work here than a quick skim suggests. The guidelines and the underlying text point toward an actual review process tied to an identifiable person or role who could be held to account for the publication — not a general policy that content is “monitored,” and not a single glance before hitting publish. A newsroom with a named editor who reviews AI-assisted copy before it runs has a real claim to both conditions. A platform that auto-publishes AI summaries with a disclaimer buried in the terms of service has neither.
Why “obvious” means something narrower here than in Article 50(1)
Article 50(1)’s chatbot-disclosure exception and Article 50(4)’s deepfake exception both turn on how a reasonable person would perceive the content — but they’re not the same reasonable person, and the draft guidelines are explicit about the gap.
Article 50(1) asks whether it would be obvious to a reasonably well-informed, observant and circumspect member of the system’s target audience that they’re dealing with AI. Article 50(4)’s deepfake assessment asks something broader: it has to account for the actual, potentially more varied audience the content is likely to reach, including foreseeable exposure to children, older people, or audiences with less digital or AI literacy than the primary audience the deployer had in mind. A deployer who tests disclosure against their core audience’s media literacy and stops there has answered the wrong question if the content is likely to circulate further than that audience — which most social content is.
The EU icon and the taxonomy nobody has finished building
The Code of Practice’s Section 2 covers Article 50(4) and 50(5) labelling specifically, distinct from the Section 1 marking obligations under Article 50(2). Alongside it, the Commission has floated a standardised visual label for AI-generated content — an “AI” mark, localised as “KI” in German or “IA” in French — together with a taxonomy that would distinguish “fully AI-generated” content from “AI-assisted” content and attach different disclosure requirements to each. Neither the icon nor the taxonomy is settled law; both are proposals moving alongside the Code rather than requirements written into Article 50 itself. Whether to sign the Code at all is a separate decision with its own trade-offs, worth working through on its own terms.
What’s left over
The law enforcement exception applies here as it does throughout Article 50: use authorised by law to detect, prevent, investigate or prosecute criminal offences falls outside the disclosure duty. Open-source licensing doesn’t help elsewhere — Article 2(12) exempts free and open-source AI systems from large parts of the Act, but the exemption specifically carves out Article 50, so a deepfake or text-generation system released under an open licence is fully subject to the labelling duties described here. And none of this shifted in the Digital Omnibus reshuffle: Article 50(4) applies from 2 August 2026 regardless of what happened to the high-risk timeline.
Frequently asked questions
Does a satirical deepfake of a real politician escape labelling?
Not reliably. If the content also bears on public discourse about that person’s decisions or conduct, it’s simultaneously public-interest content, and the guidelines’ worked example treats that overlap as defeating the satire carve-out rather than being resolved in the deployer’s favour. Political content aimed at a real, identifiable person is the case to assume you can’t rely on the exception, not the case to assume you can.
Does someone glancing at AI output before publishing count as editorial control?
That’s a thin claim to either condition. The stronger reading requires an actual review process and a person who holds editorial responsibility for the publication — not evidence that a human technically looked at the text. If you can’t name who is accountable for what goes out, you likely don’t meet the second condition regardless of the first.
Does an AI-written product description count as a matter of public interest?
No. The text limb of Article 50(4) only reaches content published to inform the public on matters of public interest — news, safety information, and similar categories. Commercial copy was never in scope, so the editorial-control carve-out is irrelevant to it; there was never a disclosure duty to carve out of.
Do you need both a visible label and machine-readable metadata?
Generally yes, and they’re not substitutes. Article 50(2) machine-readable marking is a provider duty attached to the output itself; Article 50(4) labelling is a deployer duty attached to how the content is published or presented to people. A provider marking its model’s output doesn’t relieve the deployer of disclosing a deepfake to its actual audience.
Who has the labelling duty — the agency that made the content or the client that published it?
Article 50(4) attaches to the deployer — whoever puts the content in front of the public — not necessarily whoever operated the generative tool. An agency producing a deepfake on a client’s behalf isn’t automatically who Article 50(4) is speaking to if the client is the one publishing it; that allocation is worth fixing in the contract rather than assuming.
