New rules on the labelling of AI-generated content have taken effect across the European Union, offering fresh hope in the fight against deepfakes and the online flood of synthetic junk.
The rules kicked in on August 2 as part of the EU Artificial Intelligence Act. They apply to AI systems or content that finds its way into the EU.
Under Article 50, systems must explicitly tell users when they are interacting with AI and must stamp any generative AI outputs — whether text, imagery or audio — with a machine-readable digital watermark.
People who use AI must also clearly label any "deepfakes" they create so that audiences can easily spot synthetic or manipulated content.
Importantly, the deepfakes rule only applies for content created as part of a person's job, leaving personal use unchecked.
The EU regime nonetheless far outstrips what's being done in Australia.
Dr Michael Davis, who leads the information integrity research program at the UTS Centre for Media Transition, told The Repost that Australia had "not taken any steps" towards mandatory labelling rules.
However, it was "quite possible" we might benefit from Europe's actions, he said, noting that the EU's cookie law had "driven adoption of detailed consent pop-ups when we visit many websites, even outside the EU".
More generally, the extent to which AI disclosures may prevent people from being misled remains an open question.
Studies have shown that AI labels make people more sceptical of articles and less willing to share them, and that information cues added to deepfake videos make people less susceptible to their claims.
Other studies suggest labels may do little to affect an article's persuasiveness. One recent experiment found that people still relied on the information they were given by a deepfake video even after being told it was an AI fiction.
An article in The Conversation has also warned that AI labelling could create a "boomerang effect" where audiences mistakenly assume that content without a label must be real. It's something to bear in mind given the efforts already underway to remove labels and watermarks.
Regardless, there is strong public demand for transparency in AI use, and as some have argued, the usefulness of disclosure labels is likely to be affected by how and where the labels appear, and what details they offer.
Already more than 190 organisations have signed a voluntary code designed to ensure compliance with the EU law, among them Google, Meta, Microsoft, OpenAI and Anthropic.
The new regime has been welcomed by fact-checking and verification experts as a major step in the right direction — though not without its shortcomings.
In a statement, the human rights group WITNESS said the labels mandated by the code were insufficiently detailed. To be "genuinely useful, a label needs to carry… a record of where a piece of content came from and what has been done to it, and not just a flag that says 'made by AI'," it said.
Also worth noting is that the transparency rules centre on the creation of content, not the sharing of it, with social media platforms merely encouraged to preserve labelling from other AI systems and to help users detect content.
The good news is that the major platforms are already using various methods to find and flag AI content [$]. But even though "detection solutions" must be made available by AI companies to help third parties to read their watermarks, there is no guarantee that social media platforms will integrate detection tools for every type of identifier.
(Many platforms look for standardised C2PA metadata to identify AI content, but this is often stripped when images are edited or uploaded.)
All of which is to say, the job of checking for embedded watermarks may still fall to individual users, leaving a potential gap to be exploited by bad actors.
Social media platforms are also subject to the EU's Digital Services Act (DSA), which establishes various transparency and accountability obligations related to misinformation and manipulative content.
As Dr Davis points out, those obligations include conducting risk assessments and establishing measures to mitigate the risks identified. Measures could include deepfake labelling or takedowns, though neither is mandatory, except when it comes to removing illegal content.
"Since the DSA employs a systemic, risk-based approach, the obligations are general and don't specify the exact action that must be taken," he said.