Can You Trust the Person on the Screen? Europe’s New Rules for AI Impersonation

Europe's new AI transparency rules highlight the urgent need for users to verify digital identities and understand that familiar faces are no longer proof of authenticity.

By Safegram Editorial TeamPublished Updated · 🇮🇪 English
A woman in Dublin looking warily at a man on a video call

A familiar face, a convincing voice and a polished video are no longer proof that the person on screen is real. As Europe’s AI transparency rules take effect and Ireland strengthens online-safety enforcement, the practical question for ordinary users is becoming urgent: what evidence should you trust before you send money, disclose information or believe a digital identity?

Key takeaways

  • EU AI Act transparency obligations under Article 50 have applied since 2 August 2026, including rules covering deepfakes, certain AI-generated public-interest content and interactions with AI systems.
  • Labelling helps, but it cannot replace user verification: deceptive content can be copied, stripped of context or distributed by criminals who ignore the rules.
  • In Ireland, online scams should be reported to An Garda Síochána; platforms also have DSA notice-and-action mechanisms for reporting illegal content.
  • A face, voice, follower count or blue-style badge should never be treated as sufficient proof of identity on its own.
  • The safest response to an unexpected request for money, credentials or sensitive information is to verify the person through a separate trusted channel.

The internet’s old trust signals are getting weaker

For years, people learned a simple set of digital instincts. Look for the familiar face. Listen for the familiar voice. Check the profile photograph. See whether the account looks established. Watch the video and decide whether it feels authentic.

Generative AI has weakened every one of those signals.

Synthetic video can reproduce a person’s appearance. Voice cloning can imitate speech. AI-generated images can create people who never existed. A convincing profile can be assembled from stolen or fabricated material. None of this means that every unusual video is fake. It means visual familiarity is no longer enough to establish identity.

That changes the meaning of trust online. The important question is shifting from “Does this look real?” to “What independent evidence tells me this is real?”

Europe’s AI transparency rules are now live

The EU AI Act attempts to make synthetic media easier to recognise. Article 50 transparency obligations have applied since 2 August 2026.

European Commission guidance identifies four broad transparency situations. People must be informed when they are interacting with certain AI systems. Providers also face requirements around machine-readable marking of AI-generated or manipulated content. Deployers face disclosure obligations for deepfakes and for certain AI-generated or manipulated text published to inform the public on matters of public interest, subject to the Act’s scope and exceptions.

The European Commission has also published a Code of Practice on marking and labelling AI-generated content. The Code is voluntary, but it is designed to help providers and deployers comply with the binding transparency obligations in the AI Act.

That is an important distinction: the legal transparency obligations are not the same thing as the voluntary Code that helps organisations implement them.

Why an AI label cannot solve impersonation by itself

A visible disclosure can help an honest publisher tell an audience that media has been generated or manipulated. Machine-readable provenance can help technical systems identify synthetic material.

But criminals do not become trustworthy because a regulation exists.

A fraudster may deliberately omit a disclosure. A labelled clip can be copied, cropped or reposted without its original context. A genuine video can also be placed beside a false claim. And a scam does not need a technically perfect deepfake if urgency, fear or authority persuades the victim to act before checking.

This is why AI transparency and identity verification solve different problems.

Transparency asks: was this content generated or manipulated using AI?

Verification asks: is the person, business or account actually who it claims to be?

A safer internet needs both.

The verification habit everyone should learn

When a digital interaction suddenly becomes consequential, change channels before acting.

If a family member appears to send an urgent voice message asking for money, call the number you already know. If a business changes bank details by email or messaging, verify the change using a previously established contact route. If an investment promoter, seller or creator asks you to move the conversation or payment outside a trusted service, treat that as a reason for extra verification, not convenience.

The principle is simple: do not use the suspicious interaction itself as the only method of proving that the interaction is genuine.

This is especially important when the request involves money, passwords, one-time codes, bank details, identity documents, intimate images or pressure to act immediately.

What to do if you encounter a suspected scam in Ireland

An Garda Síochána advises people who believe they have been victims of an online scam or fraud to report it to their local Garda station and to use the reporting service of the website or forum where the scam occurred. Garda guidance also recommends retaining relevant evidence such as emails, account details and copies of advertisements or online posts.

The EU Digital Services Act adds another route. Online platforms in the EU must provide a notice-and-action mechanism that users can use to report illegal content. The European Commission says these mechanisms should be simple enough to use without technical or legal expertise.

In Ireland, Coimisiún na Meán is the Digital Services Coordinator. Its Online Safety Framework covers platform duties under the DSA and other Irish and EU online-safety rules.

Reporting matters for two reasons. It can help an individual case, and it can expose patterns that platforms and authorities may need to address systemically.

Do not confuse verification with surveillance

One risk in responding to AI impersonation is overcorrecting.

If every online interaction required every person to reveal a passport, home address or full legal identity to every service, the cure would create its own privacy and cybersecurity problems.

Good verification should be proportionate to the risk. A marketplace may need confidence that a seller is genuine. An age-restricted service may need to know that a threshold has been met. A payment provider may have legal identity requirements. But the public profile or counterparty does not necessarily need access to all of the underlying personal data used to establish that trust.

Ireland’s Government Digital Wallet project reflects this broader privacy principle. Government material says the wallet is being designed so users remain in control of what they share and only the details needed for a service are disclosed.

The direction matters: prove the relevant fact without exposing more information than necessary.

What this means for Safegram — live, developing and planned

Safegram’s wider product direction is based on making trust more explicit rather than asking users to infer it from appearances alone.

Live or already implemented Safegram functionality includes verification layers for users and businesses, privacy-oriented social and marketplace functionality, Safegram Exchange, creator/business tools and encrypted communication features in the current product direction. Exact availability can vary by build, account type and rollout stage.

Safegram is also developing or staging additional trust and safety functionality, including stronger teen/family protections, age-aware account separation and safety notifications. These elements should not be described as universally live until they are confirmed in the production build.

Planned or integration-dependent functionality should be labelled accordingly. Safegram should not claim that government-wallet verification, EU AI-content provenance infrastructure, universal deepfake detection or any regulator-backed identity credential is live unless that specific integration has actually been implemented and verified.

The useful design principle is simpler and already relevant: a trust mark should represent a verification process, not popularity. Verification should make impersonation harder while minimising unnecessary disclosure of personal information.

Verification is becoming part of media literacy

Media literacy used to focus heavily on sources: who published this, what evidence supports it, and is another credible source reporting the same thing?

AI adds another layer: who is the person speaking, and can their identity be independently established?

Ireland is investing in that wider resilience. Coimisiún na Meán opened 2026 funding calls for media-literacy and counter-disinformation projects, noting that €1.1 million was allocated in Budget 2026 to support implementation of the National Counter Disinformation Strategy through initiatives including research, media literacy and fact-checking.

The most valuable skill may not be learning to visually “spot a deepfake”. Detection techniques will change as generation improves. The more durable skill is learning when an interaction becomes high-risk and knowing how to verify it independently.

The future of trust is evidence, not appearance

The internet is not becoming unusable because AI can generate convincing media. But some shortcuts we used to rely on are becoming unreliable.

A familiar face is evidence, but not proof. A familiar voice is evidence, but not proof. A polished profile is evidence, but not proof. Even an AI label answers only one question about how content was made.

Trust increasingly has to come from multiple signals: provenance, independent verification, platform safeguards, transaction protections, reporting systems and human judgement.

The safest digital communities will not be the ones where nobody can create synthetic media. They will be the ones where pretending to be somebody else is difficult, consequential actions require stronger evidence, and users know how to stop and verify before they act.

Frequently asked questions

Are AI deepfakes illegal in the EU?

Not automatically. The legality depends on the context, content and use. The AI Act introduces transparency obligations for deepfakes, while other laws can apply where synthetic media is used for fraud, harassment, non-consensual intimate imagery, defamation or other unlawful conduct.

Do AI-generated videos have to be labelled in Europe?

Article 50 of the EU AI Act creates transparency obligations for specified AI-generated or manipulated content, including deepfakes, subject to its scope and exceptions. The rules have applied since 2 August 2026.

Does an AI label prove a video is safe or truthful?

No. A label can indicate that AI was involved in creating or manipulating content. It does not prove that the claim being made is accurate, lawful or trustworthy.

How can I verify someone who contacts me online?

Use a separate trusted channel. Call a number you already have, visit the organisation’s official site independently, or confirm through an established contact rather than links or details supplied in the suspicious message.

What should I do if I have been scammed online in Ireland?

An Garda Síochána advises victims to report online scams or fraud to their local Garda station and to the platform where the incident occurred, while preserving relevant evidence.

Can I report scam content directly to a platform?

Yes. Under the Digital Services Act, online platforms in the EU must provide a notice-and-action mechanism for reporting illegal content.

Does Safegram detect every deepfake?

Safegram should not make that claim. Its trust direction emphasises verified participation and safer interactions, but universal deepfake detection should only be described as live if a specific production capability has been implemented and validated.

Is verification the same as publishing someone’s identity?

No. Good verification can establish a relevant fact or level of trust without publicly exposing all of the underlying personal information used in the verification process.

Source references

  1. European Commission, “Quick Facts: Transparency rules for AI systems”, Article 50 transparency obligations applicable from 2 August 2026.

  2. European Commission, “Code of Practice on Transparency of AI-generated Content”, current guidance supporting Article 50 compliance.

  3. European Commission, “Commission publishes Code of Practice on marking and labelling AI-generated content”, 10 June 2026.

  4. An Garda Síochána, “Cyber Crime Awareness”, guidance on reporting online scams and preserving evidence.

  5. European Commission, “Fighting online scams with the DSA”, notice-and-action guidance.

  6. Coimisiún na Meán, “Digital Services Act”, Ireland’s Digital Services Coordinator and platform obligations.

  7. Coimisiún na Meán, “Media Literacy & Countering Disinformation Micro Funds”, 3 September 2026.

  8. Government of Ireland, “Minister Chambers launches public consultation and testing phase for Ireland’s new Government Digital Wallet”, 2026.

More from Safegram

Try Safegram

Privacy-first social and a verified marketplace, built in Dublin.