Deepfakes face strict disclosure rules. AI-generated or manipulated content that resembles real people must be labelled. Failure to label is directly punishable. Synthetic content at scale also triggers GPAI transparency obligations.
The EU AI Act reaches any company whose AI output is used in the European Union — regardless of where the company is based. If your product has EU users or clients, the rules apply to you. The first question is always the same: which risk tier does your system fall into, and what duties come with that tier?
The Act sorts AI into four tiers: prohibited (banned outright), high-risk (heavy duties), limited-risk (transparency only), and minimal-risk (no mandatory duties). Most software starts in limited or minimal risk. The expensive surprises live in high-risk and prohibited — which is exactly why scanning early matters.
See your score in 2 minutes. No signup, no code stored.
Scan Your Codebase Now