Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU opens industry talks on labelling AI deepfakes before 2026 deadline

Brussels begins eight months of negotiations on a voluntary code of practice, but tech groups warn the timeline is unrealistic and technical solutions remain immature.

By , Technology Editor

Published

8 min read

The European Commission sits down with technology industry representatives in Brussels on Wednesday for the first of what will be eight months of negotiations on how to label artificial intelligence-generated content online. The meeting launches a process that must produce a voluntary code of practice by June next year, months before the EU's AI Act makes transparency requirements legally binding in August 2026.

A regulatory deadline that cannot move

The AI Act, agreed in 2024 after three years of legislative wrangling, sets out broad transparency obligations. Providers of general-purpose AI models must ensure that synthetic text, images, audio and video are marked in a machine-readable format and that users are informed when they are interacting with an AI system. Those rules apply from 2 August 2026. The Commission's AI Office, created to oversee implementation, has decided that a co-regulatory code of practice, negotiated with industry but approved by the Commission, is the most practical way to translate the law's principles into technical specifications companies can actually follow.

The timeline is aggressive. According to an October presentation from the AI Office seen by this publication, a first draft of the code is due in December, a second in March, and a final version in June. That leaves barely two months for the Commission to assess the code and publish it in the Official Journal before the August deadline. Industry groups argue that the schedule ignores the complexity of the technical challenge.

Industry warns against prescriptive technical mandates

Digital Europe, which represents many of the largest technology companies operating in Europe, and the Information Technology Industry Council (ITI) are among the lobby groups attending Wednesday's session. Their message is consistent: the science of labelling AI output is still evolving, and locking in a single approach now would be premature. Marco Leto Barone, policy director of ITI Europe, said marking techniques are still nascent and have limitations, arguing that the industry should be able to use and mix different solutions to comply with the law.

That position reflects a deeper anxiety. The AI Act's transparency requirements are only one part of a much larger compliance burden landing in 2026. Separate rules for high-risk AI systems, covering areas such as recruitment, credit scoring and critical infrastructure, also take effect in August, but the technical standards needed to demonstrate conformity are not yet finished. The Commission has acknowledged concerns about industry readiness for both sets of obligations.

Watermarks, metadata and the arms race to remove them

Several major AI developers are already experimenting with labelling. OpenAI's video generator Sora 2 adds a visible watermark to every clip it produces. Google, Microsoft, Meta and OpenAI have jointly backed the Coalition for Content Provenance and Authenticity (C2PA), which has developed a cryptographic standard for embedding origin information, including whether content is AI-generated, into file metadata. The idea is that platforms and browsers can read the metadata and surface a label automatically.

The approach has limits. Watermarks can be cropped, blurred or stripped by re-encoding. Metadata is routinely stripped when files are uploaded to social platforms or shared through messaging apps. Within weeks of Sora 2's release, websites appeared offering tools to remove its visible watermark. Researchers have demonstrated that invisible watermarks embedded in pixel values can survive some transformations but fail against others, particularly screen recording and lossy compression. No single technique has proven robust across the full distribution chain from model output to end-user view.

Election campaigns expose the enforcement gap

The political urgency behind the labelling push is clear. Two recent European election campaigns, including the Dutch general election, saw a surge in AI-generated visuals. Simon Kruschinski, a researcher on political campaigning at the University of Mainz, examined the Dutch campaign and found that the majority of AI-generated posts carried no disclaimer. He described the situation as both a transparency issue and a regulation issue. The finding suggests that voluntary commitments by model providers are not reaching the political actors and content farms actually deploying the technology.

The Commission's code of practice will need to address the full supply chain: model providers, application developers, platforms that host content, and the distributors who strip metadata. That is a far wider set of actors than the companies currently sitting around the table in Brussels. Digital Europe's membership skews toward large American platforms and model builders; European start-ups, open-source developers and the long tail of content creators are largely absent from the formal negotiation.

Google asks for a six-month grace period

In a recent submission to an EU consultation, Google argued that the labelling and transparency rules should become applicable no sooner than six months after the code of practice is finalised. The company warned that an inflexible approach could worsen users' experience online due to excessive and frequently ignored alerts and labels. The request is effectively a bid to push the practical compliance date from August 2026 to early 2027, assuming the code lands on schedule in June.

The Commission has not publicly responded to that request. Legal experts note that the AI Act's entry-into-force dates are set in the regulation itself and cannot be changed by a code of practice. What the code can do is define what constitutes compliance, potentially giving companies a safe harbour if they follow its specifications even before the legal deadline. Whether that safe harbour extends to a grace period is a question the Commission will have to answer.

The standards gap for high-risk systems

While the labelling code dominates attention this week, the parallel track for high-risk AI systems is running into similar problems. The AI Act requires providers of high-risk systems to comply with harmonised technical standards developed by European standardisation bodies CEN and CENELEC. Those standards cover risk management, data governance, transparency, human oversight and cybersecurity. As of November 2025, none of the sector-specific standards have been published. The Commission has the power to adopt common specifications as a fallback, but that would bypass the industry-led standardisation process and invite legal challenges.

The two tracks are connected. A company deploying a generative AI model for a high-risk use case, such as drafting medical reports or evaluating loan applications, must satisfy both the transparency requirements for AI-generated content and the full high-risk conformity assessment. If the standards are not ready, the company cannot complete the assessment. The Commission has hinted that it may need to delay enforcement for high-risk systems, but no formal decision has been taken.

What the code must resolve

The negotiations starting Wednesday will need to settle at least four contested questions. First, what counts as a label: visible watermark, invisible watermark, C2PA metadata, a combination, or something else? Second, who is responsible for applying it, the model provider, the application layer, the platform, or all three? Third, how should the label survive distribution: must platforms preserve metadata, and must they add their own label if the original is missing? Fourth, what constitutes a proportionate exception for low-risk uses such as AI-assisted spell-check or background blur in video calls?

The Commission's AI Office has signalled it wants the code to be technology-neutral, focusing on outcomes rather than mandating specific tools. That principle is easier to state than to operationalise. If the code accepts multiple labelling methods, platforms need a way to detect and display them consistently. If it mandates one method, it risks locking in a standard that the research community has not yet validated at scale.

Sources

  1. POLITICO

    politico.eu · 2025-11-04

People mentioned

  • Marco Leto Barone

    Policy director, Information Technology Industry Council Europe

  • Simon Kruschinski

    Researcher on political campaigning, University of Mainz

Organisations

European Commission · Digital Europe · Information Technology Industry Council · Coalition for Content Provenance and Authenticity · OpenAI · Microsoft

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.