The European Union is beginning to enforce AI transparency obligations that require public-facing AI systems to disclose when users are interacting with AI and require providers of tools that generate or manipulate synthetic image, audio, video, and text to make those outputs identifiable as AI-generated or AI-altered. The rules apply to deepfakes and other synthetic media, call for both visible disclosures and technical markers such as watermarks or embedded metadata, and set a later compliance deadline for existing systems. Exemptions cover some personal-use, artistic, satirical, fictional, law-enforcement, and human-edited text scenarios, though disclosure may still be required depending on context.
The rollout is accelerating industry efforts around content provenance and watermarking. Google backed the EU AI Act transparency code of practice and pointed to its SynthID watermarking system and work on the C2PA standard, while also warning that overlapping labeling mandates could create confusion and hurt competitiveness. Reporting on SynthID said Google’s AI tools have already produced more than 100 billion images and videos and that partners including OpenAI, NVIDIA, Apple, ElevenLabs, Kakao, and others are testing interoperable labeling approaches, even as researchers note that metadata-based labeling can be stripped and watermarking alone is unlikely to solve misinformation at internet scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The European Commission released a first list of more than 180 organizations that signed the voluntary Code of Practice on transparency of AI-generated content. The list was presented as a way for providers to document compliance, even though the underlying Article 50 transparency obligations are mandatory regardless of signature.
Google published a policy statement announcing support for the EU AI Act Code of Practice on transparency of AI-generated content. The company linked the move to its work on C2PA, SynthID, and industry partnerships on interoperable watermarking.
The European Union launched a new enforcement team in Brussels to oversee compliance with the AI Act as the regulation comes into force. The European Commission expanded its AI Office by 38 staff and added reporting and whistleblower tools, while retaining authority to investigate AI companies and sanction violators.
The European Union's next AI Act phase begins on August 2, 2026, requiring public-facing AI systems to disclose when users are interacting with AI and requiring synthetic media outputs to be identifiable as AI-generated or AI-manipulated. The rules cover images, audio, video, text, and deepfakes, with some exemptions for editorial, artistic, satirical, fictional, and certain law-enforcement uses.
Ars Technica reported Google's announcement that its tools have been used to create more than 100 billion AI images and videos. The article also noted expanded partnerships around SynthID adoption.
Google said its support for the EU AI Act transparency code builds on its earlier signing of the GPAI Code of Practice. No specific date for that earlier signing is provided in the references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcesecurityweek.com
Open sourceghacks.net
Open sourcearstechnica.com
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.