Skip to main content

ECB's Halloween deadline: Europe gets serious about AI deepfakes

Ilustrační obrázek
A bank director's voice on the phone, calmly approving a transfer. A job candidate on a video call, friendly and professional. A famous face recommending an investment. All three can now be faked convincingly enough to cost organisations real money — and Europe is no longer relying on goodwill. With the EU AI Act's relevant transparency obligations applying from 2 August 2026, and the European Central Bank asking significant institutions under its supervision to submit AI-related cybersecurity action plans by 31 October, AI safety has moved from a discussion topic to a resilience priority.
The shift is visible in documented incidents rather than in a single statistic. The FBI's 2024 Internet Crime Report describes the use of artificial intelligence in fraud, including synthetic voices and images. Deepfake scams have moved beyond cheap celebrity hoaxes: fake chief financial officer voices authorising wire transfers, synthetic job applicants passing video interviews, and AI-generated investment pitches that resemble real news broadcasts are all scenarios security teams now have to consider. Financial institutions and identity providers are watching hiring, onboarding and payment flows closely.

Brussels has stopped relying on promises

For two years, European companies could treat AI safety as a discussion topic. The general-purpose AI transition period, with its voluntary codes of practice, was designed to give developers room to prepare. That period has now moved into binding implementation for several provisions of the EU AI Act policy framework. In particular, the Act's transparency obligations for certain AI-generated or manipulated content apply from 2 August 2026, and the EU AI Office is responsible for supervising the rules. Non-compliance can lead to administrative fines under the AI Act, but the provisions do not all become enforceable in a single step. The practical consequence for deepfakes is that Article 50 of the AI Act transparency obligations may apply to certain machine-generated or manipulated content. Providers of systems that generate or manipulate content have their own marking and disclosure responsibilities, while deployers may face disclosure duties in particular circumstances when they publish or otherwise make such content available in the EU. The scope depends on the specific use and content type; not every generated or manipulated item is treated identically, and there is no automatic identical duty for every organisation. Similarly, GDPR rules on biometric data affect how deepfake detection tools can be used. An identity verification vendor in Prague or a bank in Frankfurt may need a lawful basis before running candidates through a face-screening model, and data-protection assessments may be necessary. Because the rules depend on context, organisations should obtain specialist legal advice before designing these systems. The FBI's Internet Crime Complaint Center provides a named, primary account of how criminals are using generative AI in impersonation and other fraud. That evidence helps explain why companies are reassessing verification processes, even though it does not by itself show that every organisation is buying detection software.

Banks face a concrete deadline

The clearest sign that supervisors are building resilience comes from the European Central Bank. In its published supervisory priorities, the ECB has asked significant institutions supervised by the ECB to submit AI-related cybersecurity action plans by 31 October 2026. The plans concern the institutions covered by that supervisory request. The ECB describes the exercise as resilience-building rather than a new compliance mandate, and the deadline is not a universal banking deadline or a general EU compliance target. It is a supervisory mapping and readiness exercise for the significant institutions concerned. Banking matters because it has been among the first sectors to see real losses from voice cloning and face-swapping. Voice cloning has been used in attempted executive impersonation, and real-time face-swapping in video meetings means visual checks alone are no longer reliable.

From pilot testing to production systems

The regulatory shift is also influencing procurement discussions. Some financial institutions and identity verification providers publicly describe moving from small pilots toward real-time detection in automated workflows, although the extent of that move is difficult to measure across the market. A loan application involving a video selfie may now run through a liveness check and a face-forgery screen before a human reviews it; similar tools can be used for remote onboarding, payment approvals and high-value transaction verification. The broader workplace picture has changed too. The European Commission's Apply AI Strategy and the Cloud and AI Development Act are intended to speed up AI adoption across member states. As more EU organisations use AI tools in everyday workflows, deepfake protection is no longer a niche concern for security teams — it also lands on the desks of HR staff, marketers and executive assistants.

What the detection tools actually do now

No single tool catches everything, but the technology is developing on several fronts. Research into watermarking and provenance methods for AI-generated content aims to make synthetic documents traceable, which can help when a fake contract or a fabricated email is the attack vector. Some AI developers also publish safety-testing summaries showing that rare unintended actions by AI agents are still possible, which is why safety work cannot stop. On the defensive side, cybersecurity firms have begun offering specialised deepfake simulation software that lets companies test their own staff against realistic AI-generated attacks — the digital equivalent of fire drills. None of these measures is perfect. The honest summary: detection tools are useful enough to deploy, too weak to rely on alone, and their performance remains uneven across media types and attack scenarios. That is exactly why regulators are pairing technology requirements with human processes — disclosure duties, response plans and audit trails.

Where European organisations stand this week

For most European organisations, three questions determine whether they are ready. First, is there a verified channel for high-value instructions — a callback protocol, a second person to confirm large transfers? Second, do your hiring processes use an identity verification provider that actively screens for synthetic media, and does that provider meet relevant EU transparency and data-protection requirements? Third, if your organisation publishes content in the EU, can it meet the Article 50 disclosure obligations that apply to its specific use cases, taking into account whether it is acting as a provider or a deployer? The tools exist, but they are not a substitute for independent verification, and Europe now has something the market needed most: clearer rules and a supervisory request for the significant institutions covered by it. The 31 October ECB submission date applies to significant institutions supervised by the ECB, not to every bank or organisation in Europe. The signal reaches every organisation that handles payments, hires remotely or publishes content, but the legal duties depend on the activity. Deepfake risk is no longer hypothetical — it is a line item.

Is it legal in the EU to run deepfake detection on job candidates?

The answer depends on the specific case. GDPR rules may restrict the processing of biometric data, and the AI Act can add transparency and risk-management duties depending on the system. Whether a particular detection product may be used in recruitment depends on the legal basis, the safeguards in place and the relevant EU jurisdiction. Employers should obtain specialist legal advice before deploying it.

Our company is not a bank. Do the new rules affect us?

The ECB action-plan request is aimed at significant institutions supervised by the ECB, not at every company or every bank in Europe. The EU AI Act, however, applies to many organisations providing or deploying AI systems in the EU, including deepfake detection and content-generation tools. Article 50 transparency may apply to certain manipulated media, but the requirements depend on the context and on whether the organisation is acting as a provider or a deployer. If you publish AI-generated media or use AI in hiring, it is worth checking your obligations now.

Can an ordinary person still spot a deepfake?

Sometimes — watch for unnatural blinking, audio glitches, inconsistent lighting — but the latest models are too good for visual checks alone. For anything important, verification through an independent channel, such as a known phone number or a second person, remains the most reliable defence.

Discussion

No comments yet — be the first to share your thoughts.
X

Don't miss out!

Subscribe for the latest news and updates.