A rule with a penalty attached and a promise a company makes are different kinds of things. One of them survives the quarter it becomes inconvenient.
On the second of August, Europe started enforcing the first kind.
What the rule actually says
It is Article 50 of the EU AI Act, and it covers three things.
If you open a chat window and the thing answering you is AI, it has to tell you. Not in a settings menu. Not in terms you scrolled past to click accept. No later than your first message.
If an image, a video, a voice clip, or a block of text was generated by a machine, it has to carry a marker in the file saying so. Machine readable, so a platform can find it even when a person cannot see it.
And if a video puts words in a real person’s mouth, it has to be labeled a fake.
The rule follows the person being messaged, not the company doing the messaging. If your chatbot talks to somebody in Europe, it applies to you, whether you are sitting in Dublin or in Delaware.
The timing is the part that protects you
Knowing you are talking to a machine is not trivia. It is the piece of information you need in order to decide whether to keep going.
You may be perfectly comfortable letting a bot handle a delayed package. You may not be comfortable letting one handle a diagnosis, a debt, or a call about your child’s school. Those are different conversations and they deserve different decisions.
You cannot make that decision about something you did not know you were inside of. A disclosure that arrives afterward is not consent. It is a receipt.
A convincing fake now costs about a dollar
In January 2024 somebody sent a robocall to New Hampshire voters in Joe Biden’s voice, telling them to stay home. It cost about one dollar to produce and took under twenty minutes. Software that does the same job sells on the dark web starting around twenty dollars.
Think about what a price does. When a forgery costs a hundred thousand dollars, only a few operations can afford one, and afterward you can usually work out who paid. At a dollar, anybody can, as often as they like, and there is no money trail to follow because there is no money.
The largest category of misuse is not politics either. Scams account for roughly 27 percent of tracked deepfake incidents, ahead of fabricated statements and well ahead of election content. The FBI broke out AI-enabled fraud as its own category for the first time last year and counted 893 million dollars in losses. Somebody calls your mother in your voice, and your mother is not going to ask for identification.
The benefit and the damage do not travel at the same speed
I use these tools every day and my work depends on them. The benefits are real and I am not going to pretend otherwise.
But the benefits arrive gradually and spread thin. A lot of people each get a little more done, over months, and most of it is invisible. Damage arrives all at once and lands on one person, or one election. One clip, one afternoon, and it is on four million phones before the person in it has finished breakfast.
Same technology. Completely different clock.
In Sudan, the fakes are already deciding what people believe
A fabricated image of a university in flames went around Facebook, blamed on the army, amplified by political leaders. A synthetic recording of a military commander apparently ordering civilians killed reached 230,000 views and was shared by politicians before anyone took it down. An AI campaign brought Omar al-Bashir back to life on TikTok and pulled hundreds of thousands of views.
Verification there is people running reverse image searches by hand, because the free detection tools return false positives often enough to be useless and there is nothing better on offer.
The one advantage they have is accidental. Voice models are still clumsy with Sudanese dialects, so the fakes come out slightly wrong to a local ear. Everybody working on this knows that advantage has an expiration date.
Then real things stop being able to prove themselves
Once people know convincing fakes exist, genuine evidence stops working. A politician caught on tape says the tape is AI. A leaked document is dismissed as a fabrication. Researchers call this the liar’s dividend, and the ugly thing about it is that it does not require a single successful deepfake. It only requires people to know the technology is out there.
Which is the strongest argument for labeling I have come across. A label does not stop a liar. It gives an honest person a way to prove they are honest.
In the United States, your protection depends on your zip code
There is no federal AI law.
What exists instead is five states with comprehensive AI acts either in force now or arriving in 2027, and more than forty narrower laws scattered across the rest, covering deepfakes, hiring, and chatbots one slice at a time.
Twenty-nine states have election deepfake laws in effect. California and Hawaii passed theirs and had them permanently blocked in court.
So the same fabricated video of the same candidate can be illegal in one state, protected speech across the border, and unaddressed two states over. The video does not stop at the state line. Your protection does.
Europe was not first. China was.
Since September 2025, Chinese law has required AI content to be labeled across text, image, audio, and video. A visible mark on chatbots, synthetic voices, and face swaps. A hidden watermark in the file itself where a visible mark is not required. Platforms are required to police it, and penalties run up to suspended business licenses.
Whatever you think of the government that wrote it, the rule is broader than Europe’s and it landed a year earlier.
After those two it thins out fast. Brazil has a bill in progress that includes a right to understand automated decisions. India has no dedicated AI legislation yet. Most of Africa has no national strategy at all, and the countries that do have one are short of the institutions to enforce it.
The places least able to check are getting the same flood
The numbers underneath explain why this is not going to even out on its own.
High income countries produce 87 percent of notable AI models and take 91 percent of AI startup funding. Low income countries hold one tenth of one percent of the world’s data center capacity.
Detection is built where the models are built, and it is trained on the languages those builders speak. Research on spotting misinformation is overwhelmingly English. Accuracy drops sharply outside the well resourced languages, which is most of them.
So the fakes are generated in one place and land in another, and the second place has no tool that works on its own language. Sudan gets reverse image searches, done by hand.
Some companies moved on their own. Not all of them, and not evenly.
There has been real progress and it deserves credit.
The C2PA provenance standard is past 6,000 members. OpenAI joined its steering committee in May and now embeds Google’s SynthID watermark in the images ChatGPT produces. Meta reads those credentials on upload and shows an AI Info label. YouTube labels automatically, whether the creator declares it or not.
The problem is that it is uneven in a way that teaches people the wrong lesson. Photographers found that a light Adobe retouch was enough to get a portrait flagged on Instagram while heavier synthetic work went through clean. When a platform labels some things and not others, people learn that no label means human, and that is exactly backwards.
There is also the obvious hole. Free tools exist, one command, that strip SynthID and C2PA metadata off an image entirely.
Voluntary disclosure sets the floor at whatever the least careful company decides to do. The person building something designed to deceive is not the person volunteering.
So what actually helps
Detection is losing this fight and it will keep losing, because the fakes improve faster than the detectors and always will.
What is left is disclosure, done by everybody honest, every time, until the absence of a label finally means something. That is not a technology problem. It is a rule problem, and rules are written by governments or they are not written at all.
Europe wrote one for 450 million people. China wrote a stricter one first, for 1.4 billion. In the United States it depends which state you woke up in.
In Sudan it depends on whether the voice model has learned the dialect yet.
Forward → Upward ↑ Onward ↗︎
Mstimaj
Sources and Further Reading
- EU AI Act, Article 50, the transparency obligations that became enforceable on 2 August 2026.
- Measures for Labeling of AI-Generated Synthetic Content, China, in force since 1 September 2025.
- Bird & Bird: how China’s labelling rules compare to the EU AI Act.
- Axios: Voters face uneven AI deepfake protections, source of the twenty-nine states figure and the enjoined California and Hawaii laws.
- King & Spalding: new state AI laws effective January 2026, on the wider state patchwork.
- African Arguments: The deepfake is a powerful weapon in the war in Sudan, source of the Sudan incidents and the dialect limitation.
- Monolingual and Multilingual Misinformation Detection for Low-Resource Languages: A Comprehensive Survey, on how badly detection performs outside English.
- Seeing Isn’t Believing: Addressing the Societal Impact of Deepfakes in Low-Tech Environments.
- C2PA, Coalition for Content Provenance and Authenticity, the provenance standard and its membership.
- Deepfake statistics roundup, collecting the Resemble AI incident split and the cost of the New Hampshire robocall.
- Tony Blair Institute: AI regulation in the Global South, on enforcement capacity and the model production and data centre figures.
Join the Conversation
Share your thoughts and connect with other readers