Creative Rights & AI Policy

Europe’s New Deepfake Rule Owes You Nothing

It took effect on August 2 and requires a label for the audience. China wrote the label and the permission into one regulation three and a half years ago.


Key Takeaways

  • The obligation is disclosure, owed to viewers and listeners. The person whose likeness was used gets no notice, no right to object, and nothing to enforce.
  • Consent doesn’t change anything. Under the Act’s own definition, a licensed, paid, contractually clean voice clone is still a deepfake and still has to be labeled.
  • China required all three, on January 10, 2023. One regulation: a technical mark, a conspicuous label, and separate consent from the person whose face or voice is edited.
  • European law does make them ask before training. Regulators have taken the position that GDPR can treat a cloned voice as biometric data. That permission covers the input and travels with nobody.
  • The lightest duty of all applies to music. The Commission’s guidelines put songs in the category with the softened requirement.

We’re taking a hop, skip, and a jump over the pond for this one, because as of August 2, Europe has decided that listeners should know when a voice was generated by AI. The EU’s AI Act reached Article 50, and the requirement went live across twenty-seven countries.

Here’s what the Article does. Say DJ Joe clones your voice, slaps it on a house track, and releases it in Berlin. DJ Joe has to tell their listeners the audio was artificially generated or manipulated.1 If he doesn’t, our favorite house DJ faces penalties of up to fifteen million euros or three percent of worldwide annual turnover. And yes, that can still apply if DJ Joe made the whole thing from his studio here in Wisconsin.

Now for the kicker. Article 50 never makes DJ Joe tell you, and it never makes DJ Joe ask. You’d learn your voice was in it the way the listeners do, from a label written for them.

A little housekeeping on how Article 50 works, because Europe has split this job in two.

The companies making the AI systems, called providers under the Act, have to mark their output in a machine-readable format. Think metadata: something another piece of software can find, but you probably won’t.

Then there are deployers, the people actually putting the content in front of you. They have a separate job. If what they’re publishing is a deepfake, they have to label it so the audience knows.

The Commission’s July 20 guidelines are explicit about keeping those two duties separate. Deployers “cannot rely on the machine-readable marking embedded in the content by the provider,” because a mark buried in the file doesn’t do much good for the person watching or listening to it.2

And that tells us what Article 50 is trying to solve. It wants the audience to know when what they’re hearing was made by a machine, which is something a mark inside a file will never accomplish.

Fair enough. But notice who we’re still talking about: the listener. Whether the person whose voice was cloned ever said yes is a different question entirely.

Consent isn’t part of the test

Here’s where DJ Joe gets interesting.

The Act defines a deepfake as generated content that “resembles existing persons” and “would falsely appear to a person to be authentic or truthful.”3 Consent doesn’t appear anywhere in that sentence.

DJ Joe could call you first, negotiate a license, pay you handsomely, and send flowers when the track hits a million streams. It’s still a deepfake under Article 50, and it still gets a label.

Or DJ Joe could scrape every recording you’ve ever put online, clone your voice without asking, and release the exact same track. Same deepfake. Same label.

Article 50 doesn’t distinguish between the two because permission was never part of the test. The only question it asks is whether the audience could mistake generated content for the real thing.

Those are two different questions. Europe built a disclosure rule to answer one of them.

Europe does make them ask, just not about this

Now, the lawyers in the room are already objecting, and they’re right. Europe does have a law that makes DJ Joe ask.

That law is the General Data Protection Regulation, or GDPR, Europe’s sweeping privacy law governing how companies and organizations collect, use, store, and otherwise process people’s personal data. It’s been in force since 2018, and you’ve probably encountered it whether you knew its name or not.

Under the GDPR, voice data used to identify or reproduce a person can be treated as biometric personal data. European regulators have taken the position that processing someone’s recordings to reproduce their voice can trigger the GDPR’s heightened protections, including its rules around consent.4 So Article 50’s silence doesn’t mean DJ Joe is free to scrape your recordings and feed them into a voice model.

But that solves a different part of the problem.

GDPR consent governs what happens on the way into the machine. It’s permission to process your data, given to a company and recorded somewhere in its compliance file. It doesn’t travel with the song that comes out the other end.

Article 50, meanwhile, governs the thing that came out. It tells DJ Joe what he owes the people listening to it.

So Europe has an answer for whether your recordings could go into the machine, and another for what the audience needs to know about what came out.

What’s missing is the agreement connecting the two.

China wrote both duties into one regulation

Meanwhile, China had already answered both questions.

On January 10, 2023, three and a half years before Article 50 applied, China’s deep-synthesis rules took effect. The regulation has the very government-issued name Provisions on the Administration of Deep Synthesis Internet Information Services, but what it covers should be recognizable by now.

Start with Article 16. It requires deep-synthesis providers to put a technical mark on content generated or edited using their services, one that doesn’t interfere with the user’s experience.

Then Article 17 adds the label people can actually see. When generated content might confuse or mislead the public, the provider has to conspicuously identify it as synthetic. Voice synthesis and voice imitation are specifically on the list.5

Sound familiar? China had the two pieces we just walked through in Article 50: a technical mark in the file and a disclosure for the audience. Except China had them in 2023.

And then it makes someone ask.

Article 14 covers services that edit biometric information “such as faces and voices.” When they do, the provider has to prompt its user to notify the person whose face or voice is being edited and obtain their separate consent.

The technical mark, the label, the permission. Same regulation, 2023.

Now, three pretty important asterisks before we crown China the champion of digital likeness rights. First, this doesn’t hand the person being cloned a shiny new right to sue. The obligation runs through the service provider, which has to prompt its user to notify that person and obtain consent. Second, the whole system operates inside a real-name identity regime that Europe hasn’t adopted, and probably wouldn’t want to. Third, China wasn’t inventing consent from scratch here. The rule builds on its existing data-protection framework.

So no, I’m not suggesting Brussels should have copied and pasted China’s homework. But the comparison matters for a different reason. The regulatory choices were already sitting next to each other in 2023: mark the file, tell the audience, ask the person.

China did all three. Europe did the first two. Whatever the gap in Article 50 is, the question had already been asked and answered.

The softest duty lands on music

There’s one more wrinkle in Article 50, and this one should bother any of us who make things for a living. DJ Joe’s house track gets special treatment.

Article 50 has a lighter disclosure rule for deepfakes that form part of an “evidently artistic, creative, satirical, fictional or analogous work.” Instead of the ordinary disclosure requirement, the publisher only has to disclose that generated or manipulated content is present, and can do it in a way that doesn’t hamper the enjoyment or display of the work.

And music is named in that category outright. The Commission’s guidelines put it first: artistic works are “works that have been created for the purpose of art, including music, cinematographic works, and visual arts.” They go further and give an example of a work that qualifies: AI-generated music in any genre resembling the individual style of an existing artist. That isn’t quite DJ Joe’s track, since resembling a style isn’t the same as cloning a voice, but it’s the same neighborhood, and the Commission put it there on purpose.6

To be clear, this isn’t a free pass. The guidelines say these works “are not excluded from the transparency obligation.” DJ Joe still has to disclose the AI-origin of the content. He just gets more flexibility in how he does it.

The guidelines also say the lighter regime can’t be used as cover. Relying on it “cannot be a justification for failing to respect” someone’s rights under EU intellectual property or data protection law. That’s true, and it’s also the point. Whatever protection is left standing lives in other law, not in the rule that was supposed to be about telling people what happened.

There’s a perfectly understandable reason for that. Europe doesn’t want a transparency rule trampling all over artistic expression in the process. A disclosure shouldn’t ruin the movie, cover the painting, or interrupt the song it’s trying to label.

But look at what happens when the artistic expression being protected belongs to DJ Joe, and the voice inside it belongs to you. The same carve-out designed to keep a disclosure from interfering with his art makes the duty more flexible on a record you never agreed to sing on.

What this leaves us

Bring DJ Joe back home to Wisconsin, and things get stranger.

Our right of publicity sits at s. 995.50, discussed here before. Enacted in 1977, it covers your name, portrait, and picture. It never mentions your voice, and the right ends when you do.7 The federal NO FAKES Act cleared Senate Judiciary on a unanimous voice vote in June and has gone nowhere since.

So a working musician here ends up in an odd position. If DJ Joe clones her voice in Wisconsin and releases the track in Berlin, European law requires a disclosure to listeners thousands of miles away, while Wisconsin’s right of publicity has nothing to say about her voice. The disclosure arrived before the consent did.

One disclosure, and it points forward. I’m inside the class this affects. I also think this gap can be closed, and the next briefing is where I make that case. Worth knowing when you’re reading a diagnosis from someone who already has a remedy in mind.

The more interesting problem is what none of these systems records. Article 50 records what the audience needs to know about a file. GDPR records whether your data could be processed. Provenance standards like C2PA record what happened to the file along the way. Our right of publicity, where it applies, records whether someone had the right to use your identity. None of them records the agreement itself.

Did you agree to the clone for this song, or every song? For a year, or forever? Could DJ Joe license it to somebody else, or train another model on it? Can you change your mind? What happens to the voice when you die?

Every one of those is a question about what one person gave another person permission to do. That’s the document we end up fighting over, and it’s the one nobody has built yet.

For the state-level picture behind this, see my briefings at mjsterling.org.

Notes & sources

  1. Regulation (EU) 2024/1689, Article 50(4), first subparagraph: “Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.” Article 50 has applied since August 2, 2026. A limited grace period for marking obligations on pre-existing systems runs to December 2, 2026.
  2. European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50, C(2026) 5054 final, Brussels, July 20, 2026, para. 117. The full sentence: “deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2) AI Act, since those markings are not immediately clear and distinguishable for the natural persons exposed to the deep fake content.”
  3. Art. 3(60): “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.” Whether a track openly marketed as an AI production meets the “falsely appear” test is untested, and practitioners treat it as case-specific.
  4. EDPB Guidelines 02/2021 on virtual voice assistants, which treat voice data as inherently biometric; positions of the CNIL and the Belgian Data Protection Authority on voice processed to identify or reproduce a speaker. Whether voice cloning clears Art. 9 is unsettled: GDPR Art. 4(14) ties biometric data to processing “which allow or confirm the unique identification” of a person, and cloning processes a voice to reproduce it rather than to identify anyone. These are regulator positions, not holdings.
  5. Provisions on the Administration of Deep Synthesis Internet Information Services, effective January 10, 2023, Arts. 14, 16 and 17. Translation by China Law Translate, corroborated against the Digital Policy Alert raw text. Art. 16: providers “shall adopt technical measures to add a mark to content generated or edited by their users without interfering with the use.” Art. 17 names “speech generation services such as voice synthesis and imitations.” Art. 14: “Where deep synthesis service providers and technical supports provide functions for editing biometric information such as faces and voices, they shall prompt the users of the deep synthesis service to notify the individuals whose personal information is being edited and obtain their independent consent in accordance with law.” Note that China places all three duties on the service provider, where the EU splits marking and disclosure between provider and deployer.
  6. Guidelines C(2026) 5054 final, paras. 119-124. Para. 120 defines artistic works as “works that have been created for the purpose of art, including music, cinematographic works, and visual arts.” Para. 124 lists as a qualifying example “AI-generated music in any kind of genre resembling the individual style of existing artists,” and states that reliance on the attenuated obligation “cannot be a justification for failing to respect the fundamental rights of individuals or rightsholders under Union law on intellectual property or Union data protection law.” Para. 122 excludes content “whose nature is exclusively informative or commercial and is recognisable as such,” giving news reporting as the example; on the commercial limb see also Zahed Ashkara, “AI voice clones under Article 50: consent settles the rights, not the transparency,” praxikon.com, August 13, 2026.
  7. Wis. Stat. s. 995.50(2)(b). See Briefing 003 for the full treatment, including why the statute has moved twice in forty-nine years.

About the author

MJ Sterling writes on law, policy, and technology, with attention to digital assets, financial infrastructure, and intellectual property. Read more.

Briefings and essays, in your inbox.

New policy briefings, analysis, and commentary. Sent occasionally, never noise.