Why EU AI Act Compliance Is No Longer Optional
Businesses across Europe and beyond are being urged to accelerate their EU AI Act compliance preparations, particularly around two rapidly approaching obligations: the mandatory labelling of AI-generated content and the disclosure of deepfake or synthetic media. Legal experts and regulators are warning that many organisations — from startups to multinationals — remain underprepared for rules that carry significant enforcement consequences. For developers shipping AI-powered products into the EU market, privacy professionals advising clients, and IT decision-makers evaluating technology stacks, the time to act is now.
The EU AI Act, which entered into force in August 2024, is widely regarded as the world's most comprehensive AI regulatory framework. It establishes a risk-tiered system covering everything from prohibited AI applications to transparency requirements for general-purpose AI systems. Among its most practically immediate provisions are those governing the labelling of AI-generated outputs — text, images, audio, and video — and the explicit identification of deepfake content. These requirements sit under the Act's transparency obligations and apply broadly across sectors, making them relevant to virtually any business that deploys or integrates generative AI tools. According to legal analysis published by Pinsent Masons, the obligations are closer than many compliance teams assume.

What the AI Output and Deepfake Labelling Rules Actually Require
The EU AI Act's transparency requirements are split across several articles, but the most immediately actionable relate to AI systems that interact with humans, generate synthetic content, or produce media that could be mistaken for real-world outputs. Specifically, the Act requires that:
- AI-generated or AI-manipulated content — including images, audio, and video — must be labelled in a machine-readable format and, where technically feasible, marked in a way visible to end users.
- Deepfakes — defined as AI-generated or manipulated media depicting real persons, places, or events in ways that could falsely appear genuine — must be explicitly disclosed as artificial. There are limited exceptions for clearly artistic, satirical, or fictional contexts, but these are narrow and must be evidenced.
- AI-generated text published at scale for the purpose of informing the public on matters of general interest must also be labelled as AI-produced.
- Providers of general-purpose AI (GPAI) models, such as large language models embedded in downstream products, carry additional documentation and transparency obligations under the Act's GPAI-specific provisions.
The practical implications are significant. A media company using AI to generate video content, a marketing agency deploying AI tools for customer-facing copy, or a SaaS platform offering AI-generated avatars all fall squarely within scope. Importantly, the obligations fall not just on AI developers but on deployers — the businesses and individuals that integrate and use AI systems in their operations. This distinction is critical for IT decision-makers and procurement teams evaluating third-party AI tools: deployer liability cannot be outsourced simply by pointing to a vendor's terms of service.
"Organisations that treat AI Act compliance as a future problem are already behind. The labelling provisions, in particular, require technical implementation decisions that take time to build into products and workflows — and the deadlines are firm."
— AI regulatory counsel, European technology law firmThe EU AI Act Timeline: When Do Deepfake and Labelling Rules Apply?
The EU AI Act operates on a staggered implementation timeline, which has led some businesses to underestimate the urgency of specific provisions. Understanding which rules apply when is essential for prioritising compliance work.
| Provision | Applicability Date | Who Is Affected |
|---|---|---|
| Prohibited AI practices banned | February 2025 | All AI providers and deployers |
| GPAI model obligations | August 2025 | Providers of general-purpose AI models |
| Transparency & labelling obligations (incl. deepfakes) | August 2026 | Deployers and providers of AI-generated content systems |
| High-risk AI system rules | August 2026 | Providers and deployers in regulated sectors |
| Full Act enforcement | August 2027 | All regulated AI actors |
While transparency and labelling obligations formally apply from August 2026, legal experts emphasise that building the technical infrastructure — watermarking pipelines, metadata tagging systems, content management workflows — takes substantially longer than many teams anticipate. Companies that begin compliance planning now will be able to implement, test, and iterate; those that wait will face compressed timelines and higher implementation costs. The European AI Office, established under the Act to oversee GPAI model regulation, has also signalled that it will be active in guidance development well before enforcement deadlines arrive, as reported by Euractiv.
How to Actually Implement AI Content Labelling: Technical Approaches
For developers and technical teams, the EU AI Act's labelling requirements translate into a concrete set of engineering decisions. The Act does not mandate a specific technical standard for labelling, which gives organisations flexibility but also requires them to make defensible choices. Several approaches are emerging as industry norms:
Digital watermarking involves embedding invisible signals into AI-generated images, audio, or video at the point of generation. Providers like Google (via its SynthID technology) and Adobe (through its Content Authenticity Initiative) have pioneered watermarking approaches that survive moderate compression and editing. The challenge is robustness: determined actors can attempt to strip watermarks, and the Act does not specify minimum robustness thresholds.
Metadata tagging using standards such as C2PA (Coalition for Content Provenance and Authenticity) allows AI-generated content to carry cryptographically signed provenance information. The C2PA standard, backed by Adobe, Microsoft, Sony, and others, is gaining traction as a technically rigorous approach to AI content labelling, as documented in the C2PA specification. For enterprise IT teams, integrating C2PA into content pipelines is increasingly a practical option.
User-interface disclosure — explicitly informing end users when content is AI-generated through labels, banners, or UI elements — is the most straightforward approach for many deployers and is required independently of technical watermarking. This is particularly relevant for chatbots, AI writing assistants, and synthetic media platforms.

For deepfake-specific obligations, the bar is higher. The Act requires not just machine-readable disclosure but consumer-facing notification that the depicted person, place, or event has been artificially generated or manipulated. Businesses operating in entertainment, advertising, or media production that use AI-generated likenesses of real individuals must pay particular attention — these obligations intersect with GDPR's biometric data provisions, creating a dual compliance burden. A detailed overview of GDPR's interaction with AI-generated biometric content has been published by the European Data Protection Board.
What Are the Penalties for Non-Compliance With EU AI Act Labelling Rules?
The EU AI Act's enforcement regime is structured to deter non-compliance through substantial fines. For violations of the transparency and labelling obligations — which sit in the mid-tier of the Act's risk hierarchy — penalties can reach up to €15 million or 3% of global annual turnover, whichever is higher. For smaller businesses and startups, proportionality provisions apply, but the exposure is still material.
National market surveillance authorities in each EU member state will be the primary enforcement bodies, with the European AI Office assuming oversight of GPAI model compliance. The patchwork of national regulators — each with different resourcing levels and enforcement priorities — introduces some uncertainty, but it also means businesses with EU operations spanning multiple member states need to think about compliance at a pan-European level. This is especially pertinent given that GDPR enforcement has demonstrated that EU data regulators are willing to impose landmark fines on major technology platforms, as extensively covered by Reuters.
Practical Steps Businesses Should Take Now to Prepare
Legal advisors and compliance professionals consistently recommend a structured, phased approach to EU AI Act compliance. For businesses that have not yet started, the following steps represent the minimum viable compliance preparation for the labelling and deepfake provisions: