There isn't a single "deepfakes problem" from a regulatory standpoint — there are at least two, and every country is solving them differently: specifically harmful content (non-consensual, fraud, election disinformation), and general commercial use of synthetic media that needs transparency.
Most deepfake laws fall into two categories: those targeting specifically harmful content (non-consensual intimate images, political disinformation, identity fraud), and those targeting general commercial and institutional uses of synthetic media, requiring labeling, consent mechanisms, and transparency disclosure when AI generates content about real people.
The EU AI Act is the broadest deepfake regulatory framework currently in force, with Article 50 requiring transparency obligations for AI systems that generate synthetic media, including the duty to disclose when content is AI-generated. Transparency rules for those deploying AI-generated content became applicable as of August 2026 — the very Claude watermark we covered is a direct response to this obligation.
China operates the most prescriptive deepfake labeling regime as of 2026: it requires consent to train AI on a person's likeness, mandatory watermarking, and real identity verification. New Chinese regulations require labels and encrypted watermarks embedded in deepfakes, and any software capable of removing those watermarks was directly banned.
Some countries go beyond the floor set by the EU AI Act — Italy's AI Law (132/2025) adds specific criminalization of deepfakes with harsher penalties than the European baseline, showing that "complying with the EU AI Act" doesn't always mean having complied with a specific member state's stricter national law.
The US still has no federal AI law as of mid-2026, with compliance exposure spread across sector regulators, state laws, and common-law negligence claims. Enforcement is concentrating state by state — Texas, New York, and Colorado, along with South Korea and India, are already applying their own rules even ahead of the August deadline for the EU and California.
Beyond the legal differences, C2PA (the content-provenance standard used by the Claude watermark) is functioning as the technical convergence point between major platforms and binding laws — a company that implements C2PA correctly is, in practice, taking a step toward compliance in nearly every relevant jurisdiction at once, without needing a different watermarking solution per country.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel