EU AI Act: Enterprise Compliance Guide (2027)

The EU AI Act is the world’s first regulation on Artificial intelligence.

It regulates Developers, Deployers, and Enterprise Businesses who produce, publish, or manage AI systems/tools.

The goal is the protect people from unsafe AI.

The EU AI Act synthetic media compliance has three main ideas that help you to find other requirements much more manageable:

  1. Label it
  2. Disclose it
  3. Prove it

According to Article 50 of the EU AI Act, the transparency obligation for synthetic media will come into force on 2 August 2026, and Systems placed on the market before 2 August will have until 2 December.

The clock is ticking, and we’re here to tell you all about it.

This blog translates the EU AI Act process into dates, responsibilities, and an actionable checklist for you. 


Key Takeaways

  • Transparency obligations (Article 50) will apply from 2nd August 2026, which include AI-interaction & deepfake disclosure and synthetic content marketing.

  • This section states that the providers of the generative AI need to provide the synthetic output of the generative AI in a machine-readable and detectable format. (Article 50(2))

  • Even without the intent to deceive, deployers must label the deepfakes (Article 50 (4)).

  • Penalties are upto €15 million or 3% of the annual turnover, whichever is higher, across the globe. (in case of transparency violation)

  • A company does not need to be based in the European Union to be subject to the EU AI Act. If people based in the EU use their output, the company has to comply.


What Article 50 Actually Requires for Synthetic Media

The EU AI Act contains transparency obligations for AI systems that interact with users and those that create content under Article 50.

For synthetic media, there are two main roles. 

Generative AI outputs (synthetic audio, image, video and text) must be labeled in a machine-readable format as artificial or altered (Article 50(2)).

AI Detection AI Detection

Never Worry About AI Fraud Again. TruthScan Can Help You:

  • Detect AI generated images, text, voice, and video.
  • Avoid major AI driven fraud.
  • Protect your most sensitive enterprise assets.
Try for FREE

Deployers who use AI to create deepfakes or AI-generated text on matters of public interest must disclose that the content was generated or manipulated using AI (Article 50(4)). 

This article also requires that people be informed when they’re communicating with an AI system, such as a chatbot. The basic idea behind this is honesty, whether for good or for bad, the disclosure must be plain and obvious.

The Timeline: What Is Due in 2026 and 2027

Here is what applies and when:

  • 2 August 2026: Article 50 transparency obligations come into force. This involves deepfake disclosures, disclosures for chatbots and AI interactions, and synthetic content marking. See the implementation timeline.
  • 2 December 2026: A special grace period for AI-based synthetic content providers to label systems on the market before 2 August 2026.
  • 2 August 2028: The high-risk AI rules for systems embedded in regulated products (Annex I) are deferred from 2 August 2027 to 2 August 2028 under the Digital Omnibus. 
  • The deadline for stand-alone high-risk AI systems (Annex III) has been extended from 2 August 2026 to 2 December 2027.

Despite these extensions, organizations should still treat 2027 as an internal readiness target for synthetic media compliance.

This ensures that 2027 will be a wise choice for compliance, not just because of the postponed deadlines, but because it guarantees that the necessary steps are being taken. 

Delaying synthetic media compliance runs the risk of racing against time to complete compliance tasks and vendor procurement simultaneously. 

Who Is Liable: Provider vs Deployer

Your duties vary according to the system in which you operate and many companies might perform both roles. The Act specifies the duties between providers and deployers, so it is important to note your role in each system.

For example, a marketing team could both deploy a licensed image model and provide an in-house-developed chatbot. 

If you build or fine-tune a generative system

If you are a provider, you have the responsibility set out by the Article 50(2) to mark and make identifiable the output of your system, irrespective of its content form (whether audio, image, video or textual).

Small and medium-sized AI providers may find themselves categorized as fine-tuning an existing model for the specific purpose of creating branded media. 

If you use AI to create content (marketing, comms, media)

If you’re a deployer, you will be obligated to disclose deepfakes and make it clear the content is AI-generated in accordance with Article 50(4).

Even in cases where there is no actual attempt to deceive, the rule applies: If it’s a marketing video, voiceover, or synthetic talking person, there should be a clear disclosure for the viewer. 

If you operate outside the EU

These requirements may still apply to you if you’re Non-EU. 

The providers and deployers of the AI whose output is used in the EU must comply even when they are not EU providers or deployers, as specified in Article 2. 

Global content operations must accept these rules, even if the company is based in the USA or Asia and targets EU audiences. 

Penalties and Enforcement

The second level of penalty under the AI Act is for violations of Article 50. They may face administrative fines of up to €15 million or 3% of their annual global turnover, whichever is greater (Article 99). 

National authorities will be responsible for enforcement, in coordination with the EU AI Office. Fines are not automatic; that is, consideration will be given to proportionality, nature of the breach, length of the breach, and cooperation. 

The cap is lower for smaller companies, and start-up businesses and SMEs are capped at the lower end of the fixed sum or percentage range. The fine is the tip of the iceberg. 

The examples involving banks and fintechs show how devastating the consequences can be: if a synthetic asset is mislabeled or goes undetected, it can cause substantial financial losses for a bank or fintech well before the regulator gets involved.

The Enterprise Compliance Checklist

Follow this checklist to make the rules a reality. This provides the practical core of EU AI Act synthetic media compliance, with each step representing one of the above duties. 

  • Identify all AI systems currently in use and categorize them as provider and/or deployer duties, as mentioned in Article 50. 
  •  Enable machine-readable markings for synthetic outputs in all formats (Audio, Image, Video, Text).
  • Make a ‘clear and distinguishable’ disclosure of deepfakes or chatbots. Include Article 50 obligations in vendor contracts well before the 2 August 2026 deadline and identify each of the specific obligations on either side.
  • Create a detection and verification layer to identify synthetic vs authentic content if necessary. When you’re still weighing your options, start with how to choose an AI image detector at enterprise scale, as the accuracy may differ from one to another.
  • Follow the EU Code of Practice, then log your decisions for audit purposes.
EU AI Act Synthetic Media Compliance Checklist

Where Detection and Verification Fit

The first half of Article 50 is about marking your own synthetic content. In addition, enterprises must verify and detect synthetic media both inbound and outbound: the deepfakes that enter your systems and the AI-generated content you publish. 

Stripping watermarks and metadata is quite common, so the second layer that checks the content is important. This is reflected for the first time in practice during onboarding.

In fact, Fintechs already fighting deepfake onboarding fraud are effectively running an inbound Article 50 check before the regulation requires against the same type of undisclosed synthetic content that the article addresses: a face-swapped ID or a selfie of the same individual. 

Frequently Asked Questions

When do the EU AI Act synthetic-media rules apply?

On 2 August 2026, the Article 50 transparency requirements will take effect. Article 50(2) provides for a specific provider-marking transition until 2 December 2026 for existing systems, and high-risk AI regulations incorporated into regulated products (Annex I) have been deferred from 2 August 2027 to 2 August 2028.

Do the rules apply to companies outside the EU?

The provider and deployer of the AI system must comply, regardless of whether they are based in the EU, as long as the output is used in the EU (Article 2). Content operators based in the US/Asia that serve EU audiences are facing the compliance challenge.

What are the penalties for non-compliance?

The consequence may be up to €15 million or 3% of the company’s global turnover, whichever is higher, subject to national enforcement and proportionality (Article 99). The lower amount will be offered to start-ups and SMEs.

Final Thoughts

The deadlines are rapidly approaching. 

Whether you become a provider, a deployer, or both, you will be responsible for certain tasks, and your location outside the EU won’t get you off the hook. 

In 2027, companies can avoid the rush and reputation damage by incorporating marking, disclosure, and detection into their processes.

To enable detection and validation of synthetic media within an Article 50 framework, explore TruthScan.

Copyright © 2025 TruthScan. All Rights Reserved