Deepfakes on Your Own Website: Why the Operator Is Liable — Not the Creator
Art. 50(4) EU AI Act places the responsibility for deepfakes on the user — that is, the website operator. What counts as a deepfake, where they can appear unnoticed, and how you can fulfil your obligation.
If there is one provision in the EU AI Act that website operators should take seriously, it is this: Art. 50(4). It requires that deepfakes be disclosed as artificially generated or manipulated — and it places this obligation on the person using the content. Not on the AI tool. Not on the agency. On you.
What Actually Counts as a Deepfake
The term is broader than headlines suggest. It refers to image, audio, and video content that resembles real people, objects, places, or events and could falsely appear to be genuine. This includes the obvious cases — a politician saying things they never said. But it also covers less dramatic examples: the AI-generated testimonial video with a photorealistic face, the synthetic voice in an explainer video, the team photo that has been animated afterwards.
How Deepfakes Can Appear Unnoticed on Websites
- Video agencies use AI avatars to save on production costs — and deliver the result without any indication.
- Marketing teams use tools that turn a photo into a talking video.
- Stock platforms are increasingly offering photorealistic AI portraits that are indistinguishable from real photographs.
Ignorance Is No Excuse
The obligation is linked to use, not to knowledge. That is precisely why taking stock is the crucial first step: you can only disclose what you are aware of.
Fulfilling the Obligation — Without Ruining the Video
Disclosure does not mean placing a red warning banner over the video. A permanently visible, discreet notice — such as a small label in the corner of the player — serves the purpose and preserves the production. What matters is permanence: a notice that disappears after three seconds does not count.
And as with all articles in this series: technical guidance, not legal advice. Whether a specific piece of content crosses the threshold to being a deepfake is, in case of doubt, a matter for your lawyer.
Free audit
What is actually on your website?
Enter your domain, wait less than a minute — you will see which content shows traces of AI generation. No registration required.
Read more
Art. 50 EU AI Act: Who Must Label AI Content — and What This Means in Practice
The practical guide to labelling obligations: affected content, the operator’s role, and the most common misconceptions.
How to Detect AI-Generated Content — and Why No Single Detector Is Sufficient
Why metadata provides the strongest evidence, classifiers can be misleading — and why, ultimately, a human should make the final decision.
EU AI Act: The 10-Point Checklist for Your Website
From inventory to monitoring: the ten questions every website operator should now be able to answer.
Labelling AI Images: What Is Mandatory, What Is Sensible — and How to Do It Properly
The honest answer to the most common question — and three design rules to ensure your labelling doesn’t look like a warning sign.
C2PA, Metadata, Watermarks: How Machine-Readable AI Labelling Really Works
A look inside the file rather than at the image: the standards that make origin verifiable — clearly explained.
Stock Photos and AI: Why Almost Every Website Contains Unlabelled AI Content
You have never knowingly used AI? Your website probably has — in ways no one expects.