AI disclosure · EU · updated
Article 50(4): deepfakes and AI-generated text on matters of public interest
Since 2 August 2026, anyone using an AI system professionally to make a deepfake has to say so. The AI Act says: “Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.” (AI Act, Art. 50(4), first subparagraph, applies from 2 August 2026). A second duty covers text published to inform the public on matters of public interest. Both sit with the deployer, and neither was deferred to 2 December 2026.
What counts as a deep fake
“‘deep fake’ means AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful;”
“Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations set out in this paragraph are limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.”
AI-generated text on matters of public interest
“Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated.”
“This obligation shall not apply where the use is authorised by law to detect, prevent, investigate or prosecute criminal offences or where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content.”
When and how
“The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure.”
Section 2 of the code of practice sets out how signatories design and place labels, and its Annex I offers an optional EU icon in three variants that deployers may use.
What the checker can and cannot see here
A visible label is a design question this tool does not judge. What it can read is the machine-readable side: whether the file you publish still carries the generator's C2PA manifest and digital source type, which Article 50(2) puts on the provider and which a label can sit beside.
$ npx --allow-git=root github:agentwares/agent-disclosure output published-image.jpgRun it on the file as you publish it, after your own editing and export: some tools strip the metadata a generator wrote.
Fines
“Non-compliance with any of the following provisions related to operators or notified bodies, other than those laid down in Articles 5, shall be subject to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher: … (g) transparency obligations for providers and deployers pursuant to Article 50.”
A signed readiness report
The free checks print everything they find. The Article 50 readiness report ($49, one-time, no account) is the same checks for up to 10 URLs and 25 artefacts, dated and hash-signed, as PDF and JSON, to keep or hand over.
Keep a dated record of every check, and of every disclosure and marking you ship
okgate keeps every tool call your agents make in a hash-chained audit log with daily Merkle roots on a public page: 90 days on Pro ($99/month), 365 days with a compliance export on Team ($299/month).
A record of your disclosure and marking checks, kept the same way, is not built yet. I want that record