AI LAW RADAR · Daily Last verified 23 Sep 2026

Topic dossier

Deepfake & synthetic-media labelling laws

Where AI-generated images, video, audio and text must be disclosed, watermarked or removed — the binding rules and the proposals. 27 obligations across 13 jurisdictions — 18 in force. Next dated deadline: 1 Oct 2026.

A fast-moving cluster of laws now requires AI-generated and manipulated media to be labelled, watermarked or disclosed. They divide into two families: provenance rules that mark content at creation — a visible label plus embedded metadata or a watermark — and platform duties to take down non-consensual or deceptive synthetic media. The obligations below are the instruments AI Law Radar tracks under this theme, each linked to its primary source and dated to its last check.

The Register

27 obligations · 13 jurisdictions

China 2

China Binding

Deep Synthesis Provisions

Binds Deep-synthesis service providers, technical supporters, and users. Conspicuous labelling and consent for synthetic media / deepfakes.

Stated maximum penalty — Rectification, suspension, criminal referral

In force · 10 Jan 2023 checked 4 Sep 2026 CAC Deep Synthesis Provisions ↗ high confidence
China Binding

AI-content labelling (+ GB 45438-2025)

Binds AI-content service & propagation platforms, app stores, and users. Explicit (visible) and implicit (metadata/watermark) labels on AI-generated content.

Stated maximum penalty — CAC administrative penalties

In force · 1 Sep 2025 checked 4 Sep 2026 CAC AI-Labelling Measures ↗ high confidence

European Union 2

EU Comprehensive

Article 50 transparency & deepfake labelling

Binds Providers & deployers of interactive, synthetic-content or biometric AI. Disclosure of AI interaction; marking of AI-generated content.

In force 2 August 2026. Commission adopted Guidelines on Transparency Obligations under Art. 50 on 20 July 2026, C(2026) 5054 final (https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) (soft law, interpretive guidance on chatbots, deepfakes, emotion recognition, AI-generated text). No enforcement actions by national authorities reported as of 2026-08-09; first enforcement expected Q4 2026 as national market surveillance authorities build capacity (10 of 27 member states advanced implementation). Note: marking/watermarking of systems already on market before 2 Aug 2026 deferred to 2 Dec 2026 per Reg. (EU) 2026/1744.

Stated maximum penalty — Up to 3% turnover or €15M

In force · 2 Aug 2026 checked 10 Sep 2026 EU AI Act ↗ high confidence
EU Comprehensive

Art. 50(2) marking retrofit — synthetic-content systems placed on the market before 2 Aug 2026

Binds Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content placed on the EU market before 2 August 2026. Four-month transitional period: providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the EU market before 2 Aug 2026 have until 2 Dec 2026 to implement the Art. 50(2) machine-readable marking of synthetic output.

Added by the Digital Omnibus on AI, Regulation (EU) 2026/1744, Article 1(39)(b), which adds a new paragraph 4 to Article 111 of Regulation (EU) 2024/1689 (OJ L, 24.7.2026). Recital (38) describes it as a transitional period of four months for providers who had already placed their systems on the market. Distinct from the Article 50 transparency entry, which binds from 2 Aug 2026, and from the new Article 5 CSAM/NCII prohibitions, which share the 2 Dec 2026 date but sit in the higher Article 99(3) penalty tier.

Stated maximum penalty — Up to 3% turnover or €15M

Applies 2 Dec 2026 checked 22 Sep 2026 EU AI Act Art. 111(4) (Digital Omnibus) ↗ high confidence

Gabon 2

Gabon Binding

Ordonnance n° 0011/PR/2026 Chapitre VII (arts. 32-34) — deepfake prohibitions, a 24-hour AI-content takedown right, and the audit of AI detection and marking systems

Binds Art. 2 scope: the ordonnance applies to every user, editor or host of online social networks and digital platforms as soon as the content diffused is accessible on, or produces its effects on, Gabonese territory, and it also covers the treatment of any offer of publicly accessible online communication goods or services, whether free or for consideration. Art. 32's prohibitions attach to the content itself «indépendamment de leur lieu de création», so they reach content generated abroad; art. 41 gives the référé judge express extraterritorial competence. Art. 33's twenty-four-hour takedown duty binds the éditeur and the hébergeur as defined in art. 3 — respectively the person who by an active role and moderation power controls and implements diffusion, and the person who supplies the technical means of storage and public availability of third-party content. Art. 34's audit power reaches any social network or platform on which AI detection and marking systems are deployed. No size, turnover or user-number threshold appears anywhere in the ordonnance. Impact tier: all entities.. Chapitre VII of Ordonnance n° 0011/PR/2026 du 26 février 2026 portant réglementation de l'usage des réseaux sociaux et des plateformes numériques — «De la régulation des contenus générés par intelligence artificielle» — is Gabon's first AI-specific binding rule, and it consists of exactly three articles. Art. 32 prohibits on national territory, «indépendamment de leur lieu de création», four classes of AI-generated content: hypertrucages realistically depicting an identifiable natural person in sexual situations without their express consent; hypertrucages of a public or private figure attributing to them false statements or conduct of a nature to cause serious harm to public order, national security or the dignity of persons; the representation of sexual situations involving minors, whatever the technical modality; and imitation of the visual or sound identity of a Gabonese State institution for disinformation purposes. Its closing paragraph makes content falling under those prohibitions liable to «la saisine immédiate du juge des référés». Art. 33 gives any identifiable natural person represented in AI-generated content published on a social network or digital platform without their consent a droit de signalement: the right to seise the editor or host to remove the illicit content within a maximum of twenty-four hours from the report, and, on refusal or inaction within that period, to go directly to the Haute Autorité de la Communication or the competent courts. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public, on its own initiative, commission an independent technical audit of the AI-content detection and marking systems deployed on a social network or platform. Two provisions outside the chapter carry the AI rule further. Art. 42, in the référé numérique procedure created by arts. 39 to 44, lists among the provisional measures the juge des référés may order «l'apposition forcée d'un marquage d'origine sur un contenu généré par intelligence artificielle» — a court-ordered origin marking, alongside temporary suspension of an account or content, targeted de-referencing and publication of a correction; art. 41 gives that judge expressly territorial and extraterritorial competence and requires a ruling «d'heure à heure». Art. 52 supplies the one AI-specific criminal aggravator in the ordonnance: identity usurpation via a social network or platform is punished by five years' imprisonment and a fine of up to 20,000,000 FCFA, but where the same offences are committed «par le biais d'une intelligence artificielle» the penalty rises to ten years' imprisonment and a fine of up to 50,000,000 FCFA. The definitions article, art. 3, defines Contenu généré par intelligence artificielle as any text, image, video, audio or synthetic content created or substantially modified by an automated algorithmic system; Hypertrucage ou deepfake as image, audio or video content generated or manipulated by an artificial intelligence resembling existing persons, objects, places, entities or events and which would falsely appear authentic or truthful to a person; Intelligence Artificielle as a logical and automated process generally resting on an algorithm able to carry out well-defined tasks — the same formula as the Loi n° 025/2023 definition; and Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system. The general labelling duty that gives that last definition its operative effect is not here: it sits in art. 53, in the transitional chapter, and is deferred — tracked separately as ga-ord0011-2026-art53-marquage.

Corrected 1 September 2026 against the primary gazette text, which had not been read when this row was first written on the same date; the original row rested on secondary legal commentary and was wrong in two respects that mattered. First, it recorded a labelling duty for AI-generated content as in force from 8 April 2026. The ordonnance contains no labelling duty in Chapitre VII at all: the marking obligation is in art. 53, in Chapitre XI «Des dispositions transitoires, diverses et finales», and it is expressly subject to a twelve-month period running from publication, so it does not bite until April 2027. That limb has been split out into ga-ord0011-2026-art53-marquage at lifecycle dateset. Second, the original row carried «fines up to 50,000,000 FCFA» as the penalty, taken from press reporting. Chapitre X, arts. 45 to 52, is the penal chapter, and none of arts. 45, 46, 47, 48, 50 or 51 attaches to arts. 32, 33 or 34: they punish, respectively, failure to publish mandatory identity information, an host's failure to give the editor identification means, failure to insert a right of reply within forty-eight hours, failure in the duty to combat the diffusion of illicit content, obstruction of the Haute Autorité de la Communication, and phishing. The 5,000,000 to 50,000,000 FCFA band the press attributed to the AI rules is the band of arts. 45, 46 and 48. The only penalty in the ordonnance that is AI-specific on its face is the final paragraph of art. 52, recorded in the penalty field here. There is no criminal penalty attached to art. 32 itself; its enforcement route is the référé numérique of arts. 39 to 44, which is a provisional-measures procedure, and art. 43 provides that any measure the référé judge orders expires automatically if no proceedings on the merits are commenced within one month of the seisin. Structure confirmed against the text: 55 articles in 11 chapters, signed at Libreville 26 February 2026 by the President of the Republic and countersigned by the Ministers of the Digital Economy, Defence, Communication and Media, the Interior and Justice. Art. 55 is a bare abrogation-of-contrary-provisions, registration and publication clause with no deferred commencement, so arts. 32 to 34, 39 to 44 and 52 took effect on publication. The date recorded is the opening date of the gazette issue in which the ordonnance was published, Journal Officiel de la République Gabonaise n° 110 covering 8 to 15 April 2026; the issue is dated as a week rather than as a day, so the true publication date lies between 8 and 15 April 2026, and confidence is set to medium on that account alone — every other statement in this row is read directly off the gazette text at pages 135 to 141. On sourcing: the official gazette host journal-officiel.ga carries the landing page for this instrument at https://journal-officiel.ga/22404-0011-pr-2026-/ but its port 443 timed out on every attempt this session, as it did when the Loi n° 025/2023 row was first written. The source_url therefore points at a complete scan of Journal Officiel n° 110 itself — every page carries the gazette's own running head «JOURNAL OFFICIEL DE LA REPUBLIQUE GABONAISE — 8 AU 15 AVRIL 2026 — N° 110» and its own pagination — rather than at a landing page that cannot be opened. Note one scanning artefact in the gazette itself: the AI aggravator paragraph of art. 52 prints the currency as «FCEA», a typographic error for FCFA, which is the unit used in every other penal article of the same chapter. Two companion ordonnances of the same date in the same issue, 0012/PR/2026 amending the Code de la Communication and 0013/PR/2026 on the Haute Autorité de la Communication, are not separately tracked: neither carries an AI-specific rule. Distinct from, and additional to, the automated-decision rule of the data-protection statute at Loi n° 025/2023 art. 77 — see ga-loi0252023-art77. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.

Stated maximum penalty — No penal article of the ordonnance attaches to arts. 32, 33 or 34. Enforcement of the art. 32 prohibitions runs through the référé numérique of arts. 39 to 44: the juge des référés, seised by the Ministère Public, the Haute Autorité de la Communication or any person justifying an interest to act, rules «d'heure à heure» with territorial and extraterritorial competence and may order temporary suspension of an account or of a content, targeted de-referencing, publication of a correction, and forced application of an origin marking on AI-generated content; where a viral content causes manifestly serious disturbance, art. 44 adds temporary traffic slowing in identified zones, restriction of specific functionalities and temporary suspension of access to a platform, for a maximum of seventy-two hours. Art. 43 makes every such measure temporary and expires it automatically if no proceedings on the merits begin within one month of the seisin. The single AI-specific criminal penalty is the final paragraph of art. 52: where identity usurpation by means of a social network or digital platform — usurping a third party's identity or using data identifying them, so as to disturb their tranquillity or that of others, harm their honour, standing or interests, or with intent to commit, aid or encourage an illegal activity constituting a délit or a crime, which the preceding paragraph punishes with five years' imprisonment and a fine of up to 20,000,000 FCFA — is committed «par le biais d'une intelligence artificielle», the penalty is ten years' imprisonment and a fine of up to 50,000,000 FCFA. Breach of the art. 33 twenty-four-hour takedown duty is reachable in practice only through art. 48, the general duty of editors and hosts to combat the diffusion of illicit content, punished by one year's imprisonment and a fine of 5,000,000 to 50,000,000 FCFA or one of those penalties only — art. 3 defines contenu illicite as content harming human dignity, privacy, honour, bonnes mœurs or administrative security, which the art. 32 categories will usually satisfy, but the ordonnance does not make that link expressly.

In force · 8 Apr 2026 checked 21 Sep 2026 Ordonnance 0011/PR/2026 arts. 32-34 ↗ medium confidence
Gabon Binding

Ordonnance n° 0011/PR/2026 art. 53 — AI-content detection tooling, visible and permanent origin marking, and metadata handover, due twelve months after publication

Binds «Tout éditeur de réseau social ou de plateforme numérique» — the éditeur only, not the hébergeur, on the art. 3 definitions: the éditeur is the natural or legal person who, by an active role and a power of moderation, controls and implements the diffusion of communications, publications or information on a communication service, social network or online digital platform. Combined with the art. 2 scope, the duty reaches any such editor whose diffused content is accessible on, or produces its effects on, Gabonese territory, with no size, turnover or user-number threshold and no domestic establishment requirement. Impact tier: all entities.. Art. 53 is the opening article of Chapitre XI, «Des dispositions transitoires, diverses et finales», and it is where the operative AI-content labelling duty of the Gabonese ordonnance actually sits. Every editor of a social network or digital platform is required, within a period of twelve months from the publication of the ordonnance, to do four things. To implement effective technical age-verification mechanisms on every new registration. To deploy automatic detection tools for AI-generated content published or shared on its services, according to technical standards set by the texts in force — standards that art. 54 leaves to implementing regulations and that had not been issued as at 1 September 2026. To apply a visible, clear and permanent marking to any content identified as generated or substantially modified by an artificial-intelligence system, accessible to the user without any additional action on their part. And to preserve, and to transmit to the Haute Autorité de la Communication within eight days, the origin metadata of AI-generated content that is the subject of a judicial or administrative investigation. Read with art. 3, which defines Marquage d'origine as a technical process allowing persistent and verifiable identification that a content was generated or modified by an artificial-intelligence system, the third indent is a synthetic-content labelling mandate of the same family as EU AI Act art. 50, but placed on the platform rather than on the generator, and framed as a detection-and-marking duty rather than a provider disclosure. The second indent is unusual in a comparative view: it requires platforms to run AI-content detection, not merely to pass through a label the generator applied. Art. 34, in the AI chapter, presupposes this article by giving the Haute Autorité de la Communication and the Ministère Public power to commission an independent technical audit of «les systèmes de détection et de marquage des contenus générés par intelligence artificielle» deployed on a platform.

Split out of ga-ord0011-2026-ai-content on 1 September 2026 once the primary gazette text was read. The original single row recorded the labelling duty as in force from publication; it is not. Art. 53 opens the transitional chapter and gives «un délai de douze mois à compter de la publication de la présente ordonnance». Applying the commencement method: this is a direct offset from publication, not a named day and not an elapsed-term formula, so it is computed rather than looked up. The one uncertainty is the base date. Journal Officiel de la République Gabonaise n° 110 is dated as a week, «8 au 15 avril 2026», printed on the running head of every page, and not as a single day; Gabonese press reporting of the publication settles on 8 April. The date recorded here is therefore the earliest date on which the twelve-month period can expire, 8 April 2027, and the outer bound is 15 April 2027. Confidence is medium for that reason and for that reason only. Three further points on the shape of this deadline. It is a compliance deadline running against the editor, not a commencement date for the article: the ordonnance itself has been in force since publication, and art. 55 defers nothing. The second indent is conditioned on technical standards «définis par les dispositions des textes en vigueur», and art. 54 provides that regulatory texts determine as needed the provisions necessary for application of the ordonnance; no such text had been published as at 1 September 2026, so the detection-standard limb has no content yet and the deadline may in practice be reached with the standard still unissued. That is a watch item, not a reason to move the date. And the first indent, age verification, is not an AI duty at all; it is recorded here because it shares the article and the same twelve-month clock, and because art. 3 sets the digital age of majority at sixteen. Source: the same scan of Journal Officiel n° 110 used for the Chapitre VII row, art. 53 at page 141 of the issue; the official host journal-officiel.ga timed out on port 443 throughout this session. Source moved 16 September 2026 off directinfosgabon.com (a Gabonese news site) onto the Journal Officiel's own host: the live page at https://journal-officiel.ga/22404-0011-pr-2026-/ still times out on port 443 from this egress, as it has every session since this row was written, so the citation is the Internet Archive's capture of that same official page — https://web.archive.org/web/20260611101549/https://journal-officiel.ga/22404-0011-pr-2026-/ — the CAR/Senegal/São Tomé remedy. The archived page is the gazette's own HTML rendering of Ordonnance n° 0011/PR/2026, not a scan, and its full text of arts. 32-34, 42, 45-53 and the signature block (Libreville, 26 February 2026, Brice Clotaire Oligui Nguema, countersigned by the Ministers of Digital Economy, Defence, Communications, Interior and Justice) was re-read end to end against this row and against ga-ord0011-2026-art53-marquage; every fact, including the «FCEA» typo for FCFA in art. 52's AI aggravator, matches verbatim. No substantive change.

Stated maximum penalty — None stated. Art. 53 carries no penalty of its own, and Chapitre X, the penal chapter at arts. 45 to 52, does not reference it: arts. 45 and 46 punish identity-information failures, art. 47 the right of reply, art. 48 the general duty to combat illicit content, art. 50 obstruction of the Haute Autorité de la Communication, and arts. 51 and 52 phishing and identity usurpation. Because the ordonnance predates any implementing text under art. 54, there is at present no stated sanction for an editor that reaches April 2027 without detection tooling or origin marking in place. Two indirect routes exist. Art. 34 lets the Haute Autorité de la Communication or the Ministère Public commission an independent technical audit of the detection and marking systems on its own initiative, and art. 50 punishes obstruction of the Authority — refusing to communicate useful information or documents to its members or authorised agents, concealing or destroying them, or supplying information not conforming to the records — with one year's imprisonment and a fine of 2,000,000 to 20,000,000 FCFA or one of those penalties only, which is the sanction an editor would face for stonewalling such an audit rather than for failing the underlying duty. Separately art. 42 lets the juge des référés order forced application of an origin marking on a given AI-generated content, which is a per-content remedy and not a sanction for breach of art. 53.

Applies 8 Apr 2027 checked 21 Sep 2026 Ordonnance 0011/PR/2026 art. 53 ↗ medium confidence

India 1

India Binding

IT Rules — synthetic-content (deepfake) labelling

Binds Intermediaries, significant social-media intermediaries (5M+ users), GenAI tool providers. Mandatory labels on AI-generated (SGI) content; 3-hour government-ordered takedown; significant-platform traceability.

Stated maximum penalty — Loss of safe harbour; IT Act offences

In force · 10 Feb 2026 checked 17 Sep 2026 IT Rules 2026 amendments (SGI) ↗ high confidence

Japan 1

Japan Comprehensive

Japan Election AI Labelling & Platform Obligations (2026 Amendment)

Binds All internet users (duty not to spread false election information); candidates and campaign organisations (AI labelling obligation); large-scale platform operators (X, YouTube, Meta) operating in Japan. AI-generated election content must display an 'AI作成' label; large social media platforms must implement harm-mitigation measures and publish annual reports covering election misinformation. Applies from March 2027.

Passed the House of Councillors July 13, 2026; promulgated July 17, 2026 as Law No. 58 of Reiwa 8 (令和8年法律第58号). Amends the Public Offices Election Law and the Platform Countermeasures Act (情プラ法). Enforcement March 1, 2027 ahead of April 2027 unified local elections. No new criminal penalties for platform duties (political compromise). AI-generated content that could be mistaken for authentic footage must display 'AI作成' label; clearly identifiable illustrations/animation are exempt.

Stated maximum penalty — No new criminal penalties created; existing election law criminal provisions (Art. 235-2) continue to apply to candidates

Applies 1 Mar 2027 checked 20 Sep 2026 Election SNS Regulation Law (Law No. 58/2026, Amendment) ↗ high confidence

Kyrgyzstan 1

Kyrgyzstan Binding

Digital Code art. 197 - tell consumers they are talking to an AI, tell people they are being emotion- or biometrically classified, and label deepfakes

Binds Owners and users of AI systems that interact with natural persons as consumers (part 1); users of emotion-recognition and biometric-classification systems (part 2); users of AI systems for deepfakes (part 4). Danger tier is irrelevant here - a minimal-danger chatbot owes part 1 - and there is no size, sector or nationality threshold. Part 1's register limb additionally reaches the sectoral regulator of the national ecosystem, which must publish the same information on its own site.. Art. 197 is Kyrgyzstan's transparency article and, unlike the rest of Chapter 23, it applies to AI systems at any danger level. Part 1 obliges owners and users who design, develop or apply AI systems in order to interact with natural persons as consumers to inform those consumers of the fact that they are interacting with an AI system, except where it is obvious from the circumstances; it further declares information about the use of AI systems within digital-environment legal relations to be publicly accessible information, which must be posted in accessible and intelligible form both on the sites of the users of those systems and on the site of the sectoral regulator of the national ecosystem - a disclosure register duty that goes beyond the EU AI Act art. 50 equivalent. Part 2 requires users of systems intended for emotion recognition or for the classification of natural persons by biometric characteristics to inform the persons concerned that such a system is being applied to them; Kyrgyzstan regulates these by notification rather than banning them in workplaces and education as the EU does. Part 4 requires users of AI systems for deepfakes to disclose the artificial origin or alteration of the material. Part 3 disapplies parts 1 and 2 - not part 4 - for functions where informing would frustrate lawful use for defence, national security, or public order in the detection, prevention and investigation of crime and criminal prosecution; part 5 disapplies part 4 for lawful use protecting those same goods or in exercise of the freedom of scientific, technical and artistic creativity, teaching and learning, which is a notably wide carve-out from deepfake labelling. Part 6 conditions every one of those exceptions on necessary measures having been taken to protect the affected human and civil rights and freedoms.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. Art. 197 needs no implementing act and none has been issued: the duties are self-executing on the text, and neither Resolution No. 770 nor Order No. 1181-т touches transparency. What has NOT been located is any published register on the site of the sectoral regulator of the national ecosystem under part 1, which the article requires; that is recorded as an open follow-up rather than asserted either way.

Stated maximum penalty — Nothing. There is no administrative offence for failing to disclose AI interaction, for applying emotion recognition or biometric classification without notifying the person, or for publishing an unlabelled deepfake. Art. 228-10 of the Code of Offences, the only AI-specific offence, covers the art. 192(2) targeted-unlawful-harm prohibition alone (200 расчетных показателей for natural persons, 650 for legal persons, at 100 som per показатель). Kyrgyzstan therefore sits at the opposite end from Kazakhstan on this one point: Kazakhstan's KoAP art. 641-1 does penalise failure to inform users about misleading synthetic outputs, at 15 to 100 MRP, while Kyrgyzstan's identical duty carries no fine at all.

In force · 6 Feb 2026 checked 5 Sep 2026 KG Digital Code art. 197 ↗ high confidence

South Korea 1

S. Korea Comprehensive

AI Basic Act — transparency & labelling

Binds AI business operators offering AI products/services in Korea (extraterritorial). Pre-notify users that a service uses AI; label generative and realistic synthetic outputs.

MSIT enforcement grace period of AT LEAST one year from 22 Jan 2026 before administrative fines are imposed — confirmed in an MSIT primary release (English press release on the AI Basic Act Enforcement Decree legislative notice, 12 Nov 2025: https://www.msit.go.kr/eng/bbs/view.do?sCode=eng&mPid=2&mId=4&bbsSeqNo=42&nttSeqNo=1191). That release states MSIT "will implement a grace period of at least one year before administrative fines are imposed" and that "efforts are currently underway to gather opinions to finalize the detailed operation plan and duration of this grace period" — so ~22 Jan 2027 is a FLOOR, not a confirmed end date, and the release states no exception or carve-out to the grace period. The 22 Jan 2026 in-force date is separately primary-sourced (law.go.kr).

Stated maximum penalty — Admin fine up to ₩30M

In force · 22 Jan 2026 checked 23 Sep 2026 AI Basic Act ↗ high confidence

Kazakhstan 1

Kazakhstan Binding

AI Law art. 21 — tell users AI was involved, and machine-readably mark every synthetic output you distribute

Binds Art. 21(1) is expressed impersonally and attaches to whoever produces or supplies goods, works or services using AI systems, so it reaches commercial and public suppliers alike with no size or sector threshold. Arts. 21(2), (3) and (5) place the marking, informing and output-conformity duties on собственники и (или) владельцы of the AI systems concerned — owners and holders — again without threshold. The administrative offence backing the synthetic-output limb is graded by business size, from natural person through small, medium and large business entities.. Art. 21 of Law No. 230-VIII carries Kazakhstan's transparency and synthetic-media rules, and unlike the labelling provisions in Russia's 243-FZ it is a genuine duty rather than an entitlement. Art. 21(1) requires that users be informed that goods, works and services are produced or supplied using AI systems — a broad, unthresholded disclosure obligation attached to the commercial offering itself, not merely to generated content. Art. 21(2) then provides that dissemination of synthetic results of AI activity is permitted only on condition that they are marked in machine-readable form AND accompanied by a visual or other form of warning that the user can actually perceive without methods that impede such perception — a dual-layer requirement, machine-readable plus human-perceptible, with an express anti-obfuscation limb. Art. 21(3) places responsibility for informing users about synthetic outputs on the owners or holders of the systems, and art. 21(5) makes the owner and (or) holder responsible for ensuring that the outputs of AI systems conform to the requirements of Kazakh legislation generally. Art. 21(4) is the signpost that matters for automated decision-making: requirements for taking decisions on the basis of exclusively automated processing of personal data are set by the personal-data legislation, i.e. art. 19-1 of Law No. 94-V, tracked separately at kz-pd-art19-1. Art. 22 supports art. 21 by mandating machine-readable forms that allow conditions to be recognised automatically and unambiguously by AI systems and other data-processing means, with the procedure for developing, applying and distributing them to be determined by the authorised body — so the technical standard for the art. 21(2) marking is delegated and not yet fixed on the face of the statute.

In force since 18 January 2026. Art. 31 commences the Law «по истечении шестидесяти календарных дней после дня его первого официального опубликования», with no article carved out. The А́ділет record card gives first official publication as the newspapers «Егемен Қазақстан» No. 222 (31202) and «Казахстанская правда» No. 222 (30600), both of 18 November 2025, with the Reference Control Bank of NPA in electronic form following on 20 November 2025. The sixty days run from 19 November 2025 and expire at the end of 17 January 2026, so the Law entered into force on 18 January 2026. А́ділет serves the text as «Обновленный» (consolidated and current), database state 19 August 2026, and flags the only pending change — Law No. 326-VIII of 24 June 2026 — as a future «Примечание ИЗПИ» note rather than as applied text. Note that the machine-readable marking standard contemplated by arts. 21(2) and 22(3) is to be determined by the authorised body and no such act has been identified as at 21 August 2026, so the form of compliant marking is not yet fixed even though the duty itself is in force.

Stated maximum penalty — KoAP art. 641-1(1)(1) penalises the failure by owners or holders of AI systems to inform users about synthetic results of the system's activity that are capable of misleading them, where the act or omission carries no indicia of a criminal offence. First offence: 15 MRP for natural persons, 20 MRP for small business entities and non-commercial organisations, 30 MRP for medium business entities, 100 MRP for large business entities. Repeat within a year of a penalty being imposed: 30, 50, 70 and 200 MRP respectively, together with suspension or prohibition of the operation of the AI system. Two limits are worth stating precisely. The offence is drafted around informing about synthetic outputs «которые могут ввести их в заблуждение» — capable of misleading — so it is narrower than art. 21(2), which conditions dissemination of ALL synthetic results on marking; and it does not reach the art. 21(1) duty to disclose that goods, works or services are produced using AI at all. Cases are decided by the authorised body in the field of artificial intelligence under KoAP art. 692-3. Amounts are stated in the mесячный расчетный показатель (MRP, monthly calculation index), the statutory unit the Code uses; the tenge value of one MRP is reset every year by the republican budget law, so the MRP figures rather than a converted tenge sum are the stable statement of the penalty.

In force · 18 Jan 2026 checked 5 Sep 2026 KZ AI Law art. 21 ↗ high confidence

Mexico 1

Mexico Binding

LFT/LFDA reform — AI use of performers

Binds Employers / producers using performers’ voice or image via AI; performer contracts. Prior written consent + remuneration to clone or simulate a performer’s voice or image.

Published in the DOF 14 May 2026; in force 15 May 2026.

Stated maximum penalty — Civil/authorial + labour liability

In force · 15 May 2026 checked 15 Sep 2026 LFT/LFDA reform (DOF 14 May 2026) ↗ high confidence

Russia 1

Russia Binding

243-FZ art. 9 — platforms above 500,000 daily users enable an AI label; nobody is made to apply one

Binds Owners of sites, site pages, information systems and computer programs meeting all of the art. 9(3) limbs at once: intended for or used by users to supply or distribute information via personal pages the users create; carrying information in the state language of the Russian Federation, in the state languages of republics within it, or in other languages of the peoples of Russia, on which advertising aimed at attracting the attention of consumers located in Russia may be distributed; and accessed within twenty-four hours by more than 500,000 internet users located in Russia. That is a large-platform threshold, so the practical population is a short list of user-generated-content services. Art. 9(1) and (2) address the person applying the model and the person providing the ability to apply it, but neither is placed under a duty by them.. Russia's first AI statute stops short of an AI-content labelling mandate, and the gap between what art. 9 says and what it is widely reported to say is the point of this entry. Art. 9(1) provides that a person who applies a large foundational model to create informational material in audio and (or) visual form «обеспечивается возможность размещения информационного предупреждения» — is provided with the possibility of placing an informational warning about the use of AI technologies. That is an entitlement, not a duty, and art. 9(2) confirms the reading by leaving the format, content and manner of placing the warning to be fixed by agreement between the person applying the model and the person providing the ability to apply it, which is not how a statutory labelling obligation is drafted. The single hard duty in the article is art. 9(3), and it falls on the platform rather than on the creator: the owner of a site or page of a site on the internet, or of an information system, or of a computer program that is intended for or used by its users to supply and (or) distribute information through personal pages they create, on which advertising directed at consumers located in Russia may be distributed, and access to which within twenty-four hours exceeds five hundred thousand internet users located in Russia, has to ensure that users distributing information created with large foundational models on their personal pages have the possibility of placing an informational warning about that use. The obligation is therefore to build and offer the labelling affordance, not to label, not to detect AI-generated material, and not to take anything down. Compare the EU AI Act art. 50 machine-readable marking duty on the generating provider and the deployer's disclosure duty, or the Chinese labelling measures, both of which put the duty on the party that makes or publishes the content: Russia's rule leaves the decision to label with the user and makes the large platform supply the button.

Art. 9 is one of the articles art. 13(2) defers: the Law enters into force on 1 September 2026 under art. 13(1), but arts. 8, 9 and 10, along with art. 5(2) points 3 to 5 and art. 6 parts 2 to 5, take effect on 1 March 2027. The platform enablement duty therefore does not bite on the commencement date that most accounts of the Law report. Adopted by the State Duma on 8 July 2026, approved by the Federation Council on 17 July 2026, officially published 26 July 2026 as number 0001202607260003 on the official legal-information portal, and carried at Собрание законодательства РФ 2026 No. 30 item 4089 and in «Российская газета» of 31 July 2026. The official register records the Law as not yet in force with a single original redaction commencing 1 September 2026.

Stated maximum penalty — None is stated in the Law. Art. 11 refers offenders to «законодательство Российской Федерации» generally, and as at 21 August 2026 no article of the Code of Administrative Offences is addressed to large foundational AI models or to the art. 9(3) enablement duty, so no figure can be stated. The separate marking rules that apply to advertising and to information intermediaries are outside this entry.

Applies 1 Mar 2027 checked 20 Sep 2026 243-FZ art. 9 ↗ high confidence

United Kingdom 2

UK Binding

UK DUAA 2025 s.138 — Non-consensual deepfake creation/request offences

Binds Any person in the UK who creates or requests creation of a non-consensual intimate deepfake image. Section 138 of the Data (Use and Access) Act 2025 inserts ss.66E–66H into the Sexual Offences Act 2003, criminalising the creation of non-consensual 'purported intimate images' (deepfakes) and the act of requesting such creation, even if the image is never distributed.

In force February 6, 2026 per SI 2026/31 (Commencement No. 5 Regulations 2026). Distinct from Crime and Policing Act 2026 (ss.66I–66L) which targets tool suppliers; this section targets end-users who create or request deepfakes.

Stated maximum penalty — Unlimited fine and/or summary imprisonment (Sexual Offences Act 2003)

In force · 6 Feb 2026 checked 7 Sep 2026 DUAA 2025, s.138 / Sexual Offences Act 2003 ss.66E–66H ↗ high confidence
UK Binding

Crime and Policing Act 2026 — AI-generated CSAM and deepfake offences

Binds Individual developers, distributors, and corporate bodies (criminal offences); Ofcom-regulated platforms (OSA priority-content duty). Criminalises making, adapting, possessing, supplying, or offering to supply AI models optimised to generate CSAM (up to 5 years imprisonment). Separately criminalises AI “nudification” tools/deepfake intimate image generators. Upgrades AI-generated intimate image creation to priority offences under the Online Safety Act; Ofcom-regulated platforms must prevent and remove such content (up to £3M penalty for non-compliance).

Royal Assent: 29 April 2026 (2026 c.20). Section 99 (purported intimate image generators) commenced 29 June 2026 via UKSI 2026/689 (Commencement No. 1) reg. 2(i). The CSAM image-generator offences (ss.72-74) are NOT yet in force — legislation.gov.uk marks them "Prospective" (s.72 not in force at Royal Assent, see s.255(1)), pending a further commencement instrument.

Stated maximum penalty — 5 years imprisonment (CSA/deepfake AI generator offences, once commenced); £3M Ofcom fine (platform intimate image duty)

In force · 29 Jun 2026 checked 20 Sep 2026 Crime and Policing Act 2026 ↗ medium confidence

United States 11

US · Federal Binding

TAKE IT DOWN Act

Binds Anyone publishing non-consensual intimate imagery; covered online platforms (notice-and-removal). Bans non-consensual intimate imagery incl. AI deepfakes; covered platforms must remove within 48h (notice-and-removal duty live 19 May 2026).

Stated maximum penalty — FTC enforcement; criminal penalties

In force · 19 May 2025 checked 2 Sep 2026 TAKE IT DOWN Act (PL 119-12) ↗ high confidence
US · NY Binding

New York Deceased Performer Digital Replica Consent Law (S.8391 / Ch. 616)

Binds Any person or entity using a deceased NY-domiciled performer's AI-generated digital replica in covered audiovisual, recorded, or live musical works without written consent from rights holders. Requires prior written consent from heirs, executors, or assigns before using a deceased New York-domiciled performer's or personality's AI-generated digital replica in audiovisual works, sound recordings, or live musical performances. Amends NY Civil Rights Law §50-f to introduce an AI-specific 'digital replica' definition (highly realistic, readily identifiable, computer-generated representation) and removes the prior 'likely to deceive' threshold. Covers 40 years post-mortem. Private right of action: statutory damages ≥$2,000 or actual damages plus profits and punitive damages.

Stated maximum penalty — ≥$2,000 statutory damages or actual damages + profits + punitive damages (private right of action)

In force · 11 Dec 2025 checked 15 Sep 2026 S.8391 / A.8882 / Ch. 616 (2025) ↗ high confidence
US · NY Binding

New York Synthetic Performer Disclosure Law (S.8420-A / Ch. 617)

Binds Persons, firms, or corporations engaged in commerce who produce or create advertisements using synthetic performers with actual knowledge of their use in New York. Requires conspicuous disclosure when AI-generated synthetic performers (digitally created human assets not recognizable as any identifiable real person) appear in advertisements in any medium — newspapers, magazines, radio, TV, streaming, billboards, and transit. Advertisers must have actual knowledge of synthetic performer use. Exempts expressive works, audio-only ads, and language-translation uses.

Stated maximum penalty — $1,000 first violation; $5,000 subsequent violations (civil penalties)

In force · 9 Jun 2026 checked 15 Sep 2026 S.8420-A / Ch. 617 (2025) ↗ high confidence
US · WA Binding

Washington Forged Digital Likeness Protection Act (SB 5886 / Ch.69)

Binds Any person creating, distributing, or facilitating AI-generated/manipulated likenesses of Washington residents. Prohibits creating or using AI-generated forged digital likenesses without consent; amends WA Personality Rights Act.

Stated maximum penalty — $3,000/violation + noneconomic damages; private right of action

In force · 11 Jun 2026 checked 15 Sep 2026 SB 5886 / Ch.69 ↗ high confidence
US · HI Binding

Hawaii Deepfake Protection & Synthetic Performer Disclosure Act (HB 2137 / Act 247)

Binds Anyone who knowingly publishes realistic AI-generated imitations of identifiable persons without consent; advertisers using synthetic performers in a materially deceptive manner. Two-part law: (1) prohibits publishing unauthorized AI-generated realistic imitations of identifiable persons for use in advertising, fraud, harassment, defamation, or election interference — victims may sue for up to $25,000 per piece or actual damages; (2) requires conspicuous disclosure when synthetic performers (AI-fabricated human assets not recognizable as any real individual) appear in advertising in a materially deceptive manner.

Stated maximum penalty — Up to $25,000 per piece of content or actual damages, plus punitive damages and attorneys fees (Part I — private civil action + AG); $1,000 first violation / $5,000 subsequent violations (Part II — AG enforcement)

In force · 14 Jul 2026 checked 15 Sep 2026 HB 2137 / Act 247 ↗ high confidence
US · CA Binding

California AI Transparency Act (SB 942)

Binds Covered GenAI providers with >1M monthly users accessible in California. AI-detection tool + content provenance for >1M-user providers.

Operative 2 August 2026 under Bus. & Prof. Code s 22757.6 as amended by AB 853, which pushed the original 1 January 2026 start date back. Covers the s 22757.3 covered-provider duties: a free public AI-detection tool, latent disclosures in AI-generated image, video and audio output, and an optional manifest disclosure. A covered provider is one whose GenAI system has over 1,000,000 monthly visitors or users and is publicly accessible within California (s 22757.1(d)). AB 853's later tranches are tracked as us-ca-ab853 (1 January 2027) and us-ca-ab853-capture-device (1 January 2028).

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

In force · 2 Aug 2026 checked 15 Sep 2026 SB 942 (amd. AB 853) ↗ high confidence
US · CT Binding

Connecticut PA 26-15 (SB 5) tranche 1 — subscription AI, frontier models, synthetic content, state agencies

Binds Subscription-based AI providers, frontier developers, generative AI providers with >1,000,000 monthly users publicly accessible for personal use, and CT state agencies. Subscription-based AI providers give consumer disclosures; frontier developers publish safety frameworks; large generative providers embed provenance data; state agencies gated on OPM/DAS AI policies.

Public Act No. 26-15, signed by the Governor 27 May 2026. This row carries the 1 Oct 2026 tranche: s 2 (frontier developer duties), s 15 (covered provider provenance/detectability of synthetic digital content, >1,000,000 monthly users), s 38 (state agency AI use and procurement). Public Act No. 26-100 (companion HB 5222, signed 2 June 2026) s 67 repealed PA 26-15 s 1 effective from passage and replaced the subscription-based provider disclosure duty with a narrower rule at PA 26-100 s 46, still effective 1 Oct 2026 and still applying to subscription-based providers of generative AI systems with >1,000,000 monthly users publicly accessible for personal use, enforced solely by the AG under CUTPA. The Act's later tranches are carried as separate rows: AI companions 1 Jan 2027 (us-ct-sb5-companion), automated employment-related decision technology 1 Oct 2027 (us-ct-sb5-aedt), covered-platform minors 1 Jan 2028 (us-ct-sb5-minors). Sections 17, 18, 31 (AI Academy, working group, higher-education alliance) took effect 1 Jul 2026 but create state-programme duties only, not private-sector obligations. Bill status page: https://www.cga.ct.gov/asp/cgabillstatus/cgabillstatus.asp?selBillType=Bill&bill_num=SB5&which_year=2026

Stated maximum penalty — CT Attorney General — unfair or deceptive trade practice under Conn. Gen. Stat. s 42-110b(a)

Applies 1 Oct 2026 checked 22 Sep 2026 CT PA 26-15 (SB 5) ↗ high confidence
US · MD Binding

Maryland Deepfake Identity Fraud (SB 8 / Ch. 445)

Binds Any person who uses AI or deepfake representations with fraudulent intent to harm, harass, intimidate, or threaten individuals in Maryland. Criminalises creation and distribution of AI/deepfake representations used for identity fraud; expands existing identity-fraud statute.

Signed May 12, 2026 by Governor Wes Moore; effective October 1, 2026.

Stated maximum penalty — Up to 5 years imprisonment and/or $10,000 fine (single victim); up to 10 years and/or $15,000 (two or more victims)

Applies 1 Oct 2026 checked 22 Sep 2026 MD SB 8 / Ch. 445 ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 large online platform & GenAI hosting platform duties

Binds Large online platforms (public-facing social media, file-sharing, mass messaging or stand-alone search) exceeding 2,000,000 unique monthly users over the preceding 12 months; and GenAI hosting platforms offering model weights or source code for download. Large online platforms must detect, display and preserve content provenance data; GenAI hosting platforms may not offer models that omit AI disclosures.

AB 853 (approved by the Governor 13 October 2025) adds three tranches to the California AI Transparency Act. The covered-provider regime under Bus. & Prof. Code s 22757.3 became operative 2 August 2026 and is tracked separately as us-ca-sb942. This entry covers the second tranche: s 22757.3.1 (large online platform provenance detection, a provenance user interface, user inspection/download, and a bar on knowingly stripping provenance data or digital signatures) and s 22757.3.2 (GenAI hosting platforms may not knowingly make available a GenAI system that omits s 22757.3 disclosures). Both carry an express operative date of 1 January 2027 (s 22757.3.1(c), s 22757.3.2(b)). The capture-device manufacturer tranche starts 1 January 2028 and is tracked as us-ca-ab853-capture-device. Threshold correction 2026-08-12: the large online platform test is 2,000,000 unique monthly users (s 22757.1(h)(1)), not the 1,000,000 figure that governs covered providers; broadband internet access service and telecommunications service are excluded. Note a drafting inconsistency in the enacted text: s 22757.3.2 uses 'GenAI system hosting platform' while the defined term at s 22757.1(g) is 'GenAI hosting platform'.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2027 checked 20 Sep 2026 AB 853 (amds. SB 942) ↗ high confidence
US · WA Binding

Washington AI Content Disclosure Act (HB 1170 / Ch.167)

Binds AI content creators and operators serving Washington users. Operators/creators must inform users when content is developed or modified through AI.

Signed 2026-03-24; codified as Chapter 167, Laws of 2026. Enforced exclusively by the WA Attorney General under the Consumer Protection Act (ch. 19.86 RCW).

Stated maximum penalty — Civil penalty up to $100,000 per covered provider (WA Consumer Protection Act, ch. 19.86 RCW; AG enforcement only)

Applies 1 Feb 2027 checked 20 Sep 2026 HB 1170 / Ch.167 ↗ high confidence
US · CA Binding

California AI Transparency Act — AB 853 capture device latent disclosures

Binds Capture device manufacturers, for any capture device first produced for sale in California on or after 1 January 2028 (cameras, mobile phones with built-in cameras or microphones, voice recorders); no user threshold applies. Camera, phone and recorder makers must offer, and switch on by default, latent provenance disclosures in captured content.

Bus. & Prof. Code s 22757.3.3, added by AB 853 (approved 13 October 2025). A capture device manufacturer must (1) give the user the option to include a latent disclosure in content captured by the device and (2) embed latent disclosures by default, in each case only to the extent technically feasible and consistent with widely adopted specifications from an established standards-setting body. The duty attaches to devices first produced for sale in the state on or after 1 January 2028, and s 22757.3.3(c) sets the same operative date. Unlike the covered-provider (1,000,000 monthly users) and large online platform (2,000,000 unique monthly users) tranches, this one has no size threshold: s 22757.1(c)(1) defines a capture device manufacturer simply as a person who produces a capture device for sale in the state. Added 2026-08-12 to close a coverage gap; the 2028 date previously appeared in no entry.

Stated maximum penalty — $5,000 per violation; each day a discrete violation (Bus. & Prof. Code s 22757.4)

Applies 1 Jan 2028 checked 15 Sep 2026 AB 853 (amds. SB 942) ↗ high confidence

Vietnam 1

Vietnam Comprehensive

AI-content labelling & interaction disclosure

Binds Providers / deployers of generative AI and user-facing AI systems. Machine-readable labels on AI media; disclose when users interact with AI; deceptive deepfakes banned.

Stated maximum penalty — Admin fines (decree-set)

In force · 1 Mar 2026 checked 18 Sep 2026 Law 134/2025/QH15 ↗ high confidence

Questions & answers

From the data

Do AI-generated images and video have to be labelled?

It depends where the content is seen. The EU AI Act (Article 50), China’s labelling rules, South Korea’s AI Basic Act, Vietnam’s Law on AI and India’s IT Rules all require AI-generated or synthetic media to be disclosed or marked; the exact form — a visible label, embedded metadata, or a watermark — varies by instrument. Each row above links to the controlling text.

What does the EU AI Act say about deepfakes?

Article 50 requires providers and deployers to disclose AI interaction and to mark AI-generated or manipulated audio, image, video and text — including deepfakes — in a machine-readable way. Its transparency obligations are dated 2 August 2026.

Are deepfakes illegal?

Most jurisdictions do not ban synthetic media outright; they require it to be labelled and forbid specific harmful uses. Non-consensual intimate imagery is the clearest exception — the US TAKE IT DOWN Act and the EU’s new Article 5 prohibition target it directly.

Which jurisdictions does AI Law Radar track for deepfakes & content labelling?

We currently track deepfakes & content labelling obligations across 13 jurisdictions: China, European Union, Gabon, India, Japan, Kyrgyzstan, South Korea, Kazakhstan, Mexico, Russia, United Kingdom, United States and Vietnam. Each is dated and linked to its primary source on this page.