Reputation · 14 August 2026

Since 2 August 2026, a deepfake used in a professional setting must be labelled visibly. This is no longer a communications recommendation. It is Article 50 of the AI Act. For an SME, the word “deepfake” still evokes a political video or a CEO fraud. The text, for its part, also covers the generated voice-over for a local ad, the synthetic face on a landing page, the demonstration video that is too smooth. The risk is not only the fine (up to €15 million or 3% of worldwide turnover on the transparency strand). It is a customer who discovers that “the testimonial” was not a person, and who does not come back.

What the visible label covers

Article 50 distinguishes several layers. Synthetic content (audio, image, video, text) must carry a machine-readable marking. Systems already placed on the market before 2 August 2026 have until 2 December 2026 for that machine-readable marking (Article 50(2)). Deepfakes in professional use must be labelled visibly from 2 August. AI-generated text of public interest, if it has had only limited human review, must indicate the use of AI.

Visible means perceptible by a human under normal viewing conditions. C2PA metadata, an invisible watermark (Anthropic has announced a text watermark in Claude from 2 August; the detector is not public) or SynthID on image and audio (OpenAI / DeepMind) help machine tracing. They do not replace the caption, overlay or credits the customer can read.

Professional use: as soon as the content serves your activity (sales, recruitment, press relations, customer training, company social network), you are no longer in private leisure. A VSE that posts on LinkedIn is in that frame.

Where an SME gets burned, in practice

First case: the commercial visual that simulates reality. Flat, guest room, renovated façade, machined part, restaurant dish. If the image is not a photo of the property or the service, and it can pass for one, the label is required. A hotel agent that sends that image in reply to “do you have a photo of room 12?” makes the problem worse: the customer believes they hold proof.

Second case: voice and face. A vocal clone of the director for a welcome message, an avatar of an “adviser”, a generated testimonial video. Even if the intent is to lighten production, the public hears a person. Without a clear mention, you expose the company to a loss of trust, and the director to an impersonation whose circulation they will no longer control.

Third case: the deepfake of which you are the victim, not the author. A fake call from the manager, a fake voice invoice, a fake story. The AI Act does not stop the attack. It obliges those who produce professionally to mark. For you, the job is AI cybersecurity: call procedure, confirmation channel, awareness in accounts. A cybersecurity audit that ignores voice fraud is no longer up to date.

Six actions to protect reputation, not only the file

  • Inventory content that simulates a real person or place. Live campaigns, website, Google Business, brochures, agents’ automatic messages.
  • Set a binary rule. Either it is an identified real recording, or it is generated or heavily synthetic and labelled next to the media. No third way of “we’ll see if someone complains”.
  • Ban fake testimonials. No customer avatar, no generated “Marie, 42”. The marketing gain is small. The reputational cost is high.
  • Protect the director’s identity. Limit unnecessary public voice clips. Agree a call password for transfers. Tell the team that the manager’s voice can be cloned.
  • Schedule machine-readable marking. Ask your tools and agencies for C2PA or equivalent. For systems predating 2 August 2026, the 2 December 2026 deadline is not an excuse for the visible label.
  • Train those who publish. Article 4 (literacy) has applied to deployers since 2 February 2025. The community manager is a de facto deployer as soon as they put AI content online under your name.

What the regulation does not ask of you

It does not ask you to stop all synthetic imagery. It does not ask for an “AI” banner on every sentence reviewed by a human. It does not turn a light lighting retouch into a deepfake. Stay proportionate: the spirit of the text is to stop a professional passing a fabrication off as reality. Prohibited practices (manipulation, and so on) fall under another cap, already applicable (up to €35 million or 7% of worldwide turnover). A misleading fake testimonial is not only a forgotten label. It is a problem of commercial loyalty, AI Act or not.

The AI Office may investigate providers of general-purpose models since 2 August 2026. Your risk, in an SME, will more often run through a customer or a local paper than through a European investigation. Reputation does not wait for the regulator.

Cybernecs framing

We help VSEs and SMEs connect agents, content and security: what the agent is allowed to send, what must carry a mention. Patrick Dajan Mouelle, director of Cybernecs, refuses campaigns of the “you won’t see the difference” type. If you cannot see the difference, the label is there to restore it.

For a review of your content, go through the contact page. Compliance as of 2 August is read on your pages, not in a provider press release.

Sources: Artificial Intelligence Regulation (AI Act), Touteleurope, L’Express, Anthropic and OpenAI / DeepMind communications (SynthID), C2PA.

Post a comment

Your email address will not be published.

Articles de la même catégorie