The EU's deepfake labeling law is live — and fraudsters aren't complying

Facial recognition scan with biometric grid overlay representing AI deepfake detection and identity verification

On August 2, 2026, a new legal requirement quietly took effect across the European Union: AI-generated and manipulated content, including deepfake audio and video, must now be clearly and visibly labeled. It is one of the most ambitious attempts yet to bring transparency to synthetic media. It is also, for fraud teams, almost beside the point. The criminal who cloned a finance director's voice to authorize a €3 million wire transfer was never going to check a compliance box first.

What just changed under the EU AI Act

The new rules come from Article 50 of the EU AI Act, the bloc's transparency provision covering AI-generated content. As of this month, providers and deployers of AI systems operating in the EU must mark synthetic audio, image, video, and text in a machine-readable format that enables detection, and deepfakes shown to the public must carry a clear, visible label (artificialintelligenceact.eu). Regulators expect penalties for non-compliance to reach €15 million or 3% of global annual turnover, whichever is higher (Bratby Law).

Roughly 190 organizations had already signed the EU's voluntary Code of Practice on labeling AI content by the end of July, ahead of the rules becoming legally binding (Euronews). That's a meaningful show of intent from legitimate AI vendors and platforms. It is also, by definition, a list that will never include a fraud ring.

Why labeling won't stop the fraud that matters

Content labeling is built for a specific problem: helping the public tell real media from synthetic media on platforms that choose to comply. It does very little against the fraud scenarios banks, telecoms, and law enforcement actually deal with, for a simple reason — compliance is voluntary in exactly the cases where it matters least.

  • Fraudsters don't publish through regulated channels. A cloned voice used to impersonate a CEO on a live phone call, or a synthetic video injected into a KYC onboarding flow, never passes through a platform that would apply — or enforce — a label.
  • Voice cloning needs almost nothing to work. Convincing voice clones can now be produced from as little as three seconds of audio, and packaged fraud kits combining cloned voice, fake video, and phishing infrastructure have been advertised for as little as $60 a month.
  • Labels can be stripped or never applied. Watermarking standards remain fragmented across vendors, and there is no mechanism forcing a bad actor's tools to embed one in the first place.

The result is a rule that raises the floor for responsible AI platforms while leaving the ceiling on fraud largely untouched. That gap is precisely where incidents like the $35 million Hong Kong bank fraud and the €3 million voice-cloned executive scam at an Indian SaaS company keep happening — no label was ever going to intervene in either call.

The compliance ripple effect for banks and telecoms

Even though Article 50 targets AI providers rather than fraud victims, it still changes the operating environment for regulated institutions. Banks, telecoms, and HR platforms operating in the EU now need to document how they distinguish labeled, disclosed synthetic content from undisclosed, malicious synthetic content in their own risk assessments — and that distinction has to be made technically, not just procedurally, since fraud will arrive unlabeled by design.

A parallel worth watching

The EU's approach sits alongside separate momentum in the United States, where lawmakers have pushed AI fraud accountability legislation targeting voice-cloning scams directly. Together, the two tracks signal the same conclusion from regulators on both sides of the Atlantic: disclosure requirements and fraud liability rules are arriving faster than most institutions' detection capabilities.

What actually stops the fraud a label can't

If labeling only works when bad actors cooperate, the practical defense has to sit somewhere labeling can't reach: at the point of the call, the video interview, or the onboarding session itself. That means:

  • Real-time audio and video analysis that flags synthetic speech and injected or manipulated video during a live interaction, not after the fact.
  • Voice-to-face verification that confirms identity without depending on a database the fraudster could have already compromised.
  • Continuous, not one-time, verification across a call or session, since a clone convincing enough to pass an opening security question can still be caught mid-conversation.

Regulation like Article 50 is a useful signal — it shows that governments now treat synthetic media as a systemic risk, not a novelty. But for the institutions actually exposed to deepfake fraud, the label was never going to be the safeguard. Detection has to be.

Corsound AI helps banks, telecoms, and identity platforms catch synthetic voices and manipulated video in real time, before a label — or its absence — ever enters the picture. See how Deepfake Detect works, or explore our approach for banking and finance teams.

Photo: cottonbro studio / Pexels

See Corsound AI Voice Intelligence In Action
Thank you.
Your submission has been received.
Oops! Something went wrong while submitting the form.