EU AI Act Code of Practice on Transparency: What All Screen Content Makers Need to Know

If you’re a production company, VFX studio, distributor, or any other party involved in producing screen content that flows into the EU, this note sets out the critical elements of the EU’s Code of Practice on the Transparency of AI-Generated Content (“the Code”), plus AIMICI’s five-step action plan for getting ready.

 

Why It Matters

Section 2 of the Code places disclosure obligations on the deployer of an AI system. This is the person or organisation actually using the AI system to generate or manipulate content, as opposed to the company that built the underlying model. Specifically, the Code applies to deployers who produce or manipulate deepfakes, or who publish AI-generated text to “inform the public on matters of public interest.”

If you’re based in the UK, this is still worth your attention, for two separate reasons.

First, on jurisdiction: the Code isn’t legally enforceable against you if you’re a UK company; the AI Act is an EU instrument, and the UK isn’t bound by it. But that doesn’t make it irrelevant. If your content is distributed into, or made accessible in, the EU, the Code is on track to become a practical distribution standard regardless of whose law you sit under. EU broadcasters, platforms and distributors are likely to expect the disclosures the Code describes as a condition of taking your content, whether or not you’re under a domestic legal duty to provide them.

Second, on who in the chain actually carries the obligation: it sits with the deployer ie whoever is actually operating the AI system to generate or manipulate the content, not with whoever commissioned or owns the finished work. So if you’re the VFX studio or post house running the AI tooling, the obligation is yours even though a producer, broadcaster or studio commissioned the piece and owns the output. Being a hired contractor doesn’t shift the obligation up the chain to the commissioning party.

This matters because realistic AI-generated content is becoming difficult to distinguish from authentic material. The Code treats disclosure as a basic safeguard for trust: audiences should be told when something they’re watching, reading or listening to has an artificial or AI-manipulated origin. Audience research on this is fairly consistent. People are usually less bothered by the technology itself than by not being told about it.

 

What Counts as a “Deepfake”

Under Article 3(60) of the AI Act, a deepfake is AI-generated or AI-manipulated image, audio or video content that resembles a real person, object, place, entity or event, and that would falsely appear to a person to be authentic or truthful.

Three things all have to be true at once for content to count:

  1. Resemblance – a high degree of similarity between the content and the thing it depicts.
  2. An existing subject – the person, object, place, entity or event resembled has to exist, plausibly exist, or plausibly have existed.
  3. False appearance of authenticity – the content has to be capable of deceiving or misleading someone about whether it’s real.

On that third point, the European Commission’s guidance says deployers can weigh: how close the resemblance is, the substantive message of the content, the context it’s being deployed in, and what the intended audience would reasonably expect. 

In practice, this is why AI-generated backgrounds, VFX, and standard post-production touch-ups in a normal film or TV production aren’t likely to trip the definition – audiences don’t expect them to be “real” in the first place. Bear this in mind when scoping your own risk assessments: not every use of AI on a production is a deepfake, and treating it as though it is will just create noise around the disclosures that actually matter.

 

What the Code Requires

Section 2 creates two core disclosure duties, covering two categories of output:

  • Deepfakes – as defined above, subject to disclosure requirements.
  • Published text – AI-generated or AI-manipulated text published to inform the public on matters of public interest must be disclosed, unless it has gone through human review and a named natural person holds editorial responsibility for it.
 

The Code also proposes standard EU “icons”: one for wholly AI-generated content, and a different one for AI-manipulated content. This is to give audiences a consistent visual cue regardless of which platform or producer they’re dealing with.

Two nuances worth flagging:

  • Creative, artistic, satirical and fictional works get a lighter touch, not an exemption. For evidently fictional, satirical or analogous work, disclosure is still required, but it only has to be given in a way that doesn’t get in the way of the audience enjoying the work – it doesn’t need a warning slapped over every scene.
  • A machine-readable watermark from the AI tool provider is not enough on its own. Article 50(2) requires AI providers to embed machine-readable markers in their output, but that’s a separate obligation from yours as the deployer. Your disclosure to audiences must be clear, understandable, and perceivable on its own terms – you can’t simply point to the provider’s embedded metadata and call it done.

 

Where and When Disclosure Must Appear

For visual deepfakes, the label or icon needs to be immediately perceivable without the viewer having to do anything. It must be visible no later than first exposure, i.e. at the point of consumption.

For video specifically, the label should appear at the start and, where possible, at intervals across the running time. This matters for anything that might get clipped, screenshotted or shared out of its original context. A label buried only in the opening titles won’t travel with a 15-second clip on social media.

 

The Bigger Picture: A New Credits Roll

Zooming out, the direction of travel is consistent across the Code and the wider regulatory conversation: AI-generated content is expected to become traceable. Carrying metadata, digital signatures, watermarks or provenance records that let its origin be verified long after it leaves the system that made it.

Today, productions credit directors, editors, cinematographers, VFX artists and sound designers as a matter of course. It’s a reasonable bet that AI systems used, the model versions involved, and the pipeline an asset went through will need similar record-keeping. Not necessarily on screen, but somewhere in the production’s own documentation. Detection is becoming as important as generation here too: as synthetic media gets more convincing, broadcasters and distributors handling third-party or user-generated footage (archive material, citizen journalism, remote news gathering) will increasingly need ways to verify authenticity.

 

A Related Development: Hollywood’s Own AI Classification Effort

Worth being aware of, even though it sits outside the Code itself: Hollywood’s own internal AI conversation is moving in a similar direction, for a different reason. Recent industry talks hosted at AFI, involving figures including Kathleen Kennedy, Christopher Nolan, DGA AI Committee co-chair Jon Avnet, and filmmaker Bryn Mooser, have converged on the idea that “AI not/used” as a factual label won’t work. Specifically, the AI term covers everything from noise reduction tools that have quietly existed in post-production software for years, through to fully generative content, and that ambiguity is already causing friction in contract negotiations, credit disputes and guild discussions.

The framework reportedly taking shape, provisionally called Human Generative Workflows (HGW), sorts AI use into three tiers: utility techniques and embedded AI (copyrightable), human-generative workflows where a human retains authorial control (also copyrightable), and fully machine-generative output (not copyrightable).

It’s worth being precise about how this relates or contradicts with the Code.  HGW answers a different legal question – authorship and copyright, relevant to credits and contracts  – and is not focussed on audience disclosure. The two don’t conflict, and one doesn’t replace the other. A shot could easily be a “Human Generative Workflow” for copyright and credit purposes, and still separately trigger an EU disclosure duty if it meets the deepfake test above. 

What the two efforts do share is the same underlying instinct: moving past a flat “was AI used, yes or no” toward tracking where in the process AI was used and how much human control was retained. If you’re logging that detail for your AI Content Register anyway, capturing it in a form that could also support an authorship classification like HGW costs you little extra.

 

Our Proposed Solution: A Composite “Responsible AI” Mark

Given how much both frameworks above depend on the same underlying data, where AI was used, and how much control a human retained, it’s tempting to propose one “Responsible AI” mark that speaks to both the EU’s disclosure concerns and Hollywood’s authorship concerns at once. 

Separate signals may confuse what’s legally required against what’s simply good industry practice, and it risks putting a governance badge designed for one regime on content, for example routine noise reduction, that may never needed audience disclosure in the first place.

A composite mark avoids that problem. Picture a mark with independently legible facets sitting under one recognisable “Responsible AI” badge. This would be closer to a nutrition label carrying or representing some key information, rather than a single health warning (used/not used) badge.

The catch is that the industry is still up in the air on what “good” looks like. Whilst significant, HGW is a provisional proposal out of informal talks. The Code will be tested in time and is already facing changes.

We are already building a prototype of the composite mark’s architecture, and trialling it alongside real productions to capture critical industry requirements (eg. AI competency, AI risks, and EU-compliant disclosure requirements), reserving facets once the industry actually agrees on a classification framework. That keeps the mark useful today and ready to absorb tomorrow’s settled standard.

 

Here’s how to Prepare Now – AIMICI’s Five-Step Action Plan

  1. Maintain an AI Content Register. Log the AI tools used across a production, how you’re keeping a human in the loop over inputs and outputs, the use case, a risk rating, and, as above, where in the process the tool was used and how much creative control stayed with a human.
  2. Separate creative AI from documentary/news AI. Sci-fi VFX doesn’t need the same scrutiny as AI-generated archive footage or synthetic news content. Keep the two streams distinct in your logging so governance effort goes where the actual disclosure risk sits.
  3. Update your workflows end to end. Start with your internal AI policy and make sure it covers the full pipeline,  from AI-assisted storyboarding through to digital doubles,  not just the most visible use cases.
  4. Build an AI Disclosure Pack. A single evidence pack for commissioners, insurers and unions that sets out your responsible-AI position in one place: copyright provenance, approved tools, training-data risk, and identification of any synthetic performers.
  5. Build provenance into your production materials. Rather than one blanket AI statement, seek to tag high-risk shots individually so your disclosures are machine-readable and traceable, not just a line in the small print.

 

Bottom Line

This is about answering three questions on demand: where did this content come from, how was it made, and can you prove it? Getting your documentation habits in order now, in a way that’s flexible enough to survive the industry’s own evolving thinking on AI classification, is the practical way to stay ahead of both the EU’s requirements and wherever Hollywood’s own framework lands.

Share the Post:

Explore more insights