INDUSTRY
The AI-voice disclosure era started on a Sunday
7 min read
On 2 August 2026 the EU AI Act’s Article 50 became applicable: voice agents must say they are AI, synthetic audio must carry a machine-readable mark, deepfakes must be labelled. The vendors raced the deadline and the watermarks have honest limits — but the question the law still doesn’t answer is consent. That one, Blab answered on day one.
Article 50 of the EU AI Act became applicable on Sunday, 2 August 2026. If you build or deploy voice AI that reaches the EU market, three duties are now live: a voice agent has to disclose that it is AI, synthetic audio has to carry a machine-readable mark, and a cloned real person has to be labelled as such. Breaching them can cost up to €15 million or 3% of worldwide turnover. The Commission spent the preceding week making clear this is not a paper deadline: on 31 July it announced that enforcement starts on the 2nd — the AI Office for general-purpose models, national market-surveillance authorities for the rest — and opened a complaints channel and a whistleblower tool. On the Sunday itself it published a short note titled “Safer and more transparent AI”. The disclosure era did not arrive with a bang; it arrived with a news item, on a weekend.
The deadline landed exactly as designed
When we wrote about this date in June, one question was still open: the Digital Omnibus — the package postponing the Act’s high-risk obligations — had a political agreement but no legal text, and its deferrals would only count if it reached the Official Journal in time. It did, with six days to spare. Regulation (EU) 2026/1744 was adopted on 8 July, published on 24 July and entered into force on 27 July. The postponements are now law: high-risk systems under Annex III move to 2 December 2027, AI embedded in regulated products to 2 August 2028, and the new prohibitions on nudifier and CSAM-generating systems land on 2 December 2026. And the point we kept insisting on held: 2 August itself never moved. Transparency, and the power to fine for its absence, arrived on schedule.
Read the marking “delay” closely — it is narrower than it sounds
Much of the coverage says machine-readable marking was pushed to December. That is only a quarter true. What the Omnibus actually wrote into the Act is a transition for legacy systems: generative systems placed on the market before 2 August 2026 get four months, until 2 December 2026, to comply with the marking duty in Article 50(2). A system placed on the market from 2 August onwards owes the mark from day one. And the other two voice duties were never deferred at all: agent disclosure under 50(1) and deepfake labelling under 50(4) apply to everyone as of Sunday. The Commission’s guidelines, finalised on 20 July, add the practical detail for voice: nothing generated before 2 August needs relabelling, because the date of generation governs; a listener who joins mid-stream still has to learn they are hearing AI, so disclosure should recur rather than play once at the top; and an AI agent must disclose both that it is artificial and on whose behalf it is acting.
July was a race to the wire
The vendors saw this coming and moved in almost weekly steps. On 25 June, ElevenLabs began embedding Google DeepMind’s SynthID watermark into its text-to-speech output and shipped a free detector for its own audio. On 8–9 July the Commission and the AI Board assessed the Code of Practice on Transparency of AI-generated Content as an adequate way to comply; by 31 July it counted roughly 190 signatories — Anthropic, Google, Meta, Microsoft and OpenAI among them, alongside voice companies like Resemble and Synthesia. On 29 July Google shipped Lyria 3.5 with SynthID on every generated track. And on 31 July, two days before the deadline, OpenAI extended SynthID watermarking to voice audio generated with GPT-Live. Microsoft, for its part, keeps personal-voice synthesis behind a limited-access gate: a recorded consent statement from the voice’s owner, and an automatic watermark on the output. What none of this produced is a single standard. Article 50(2) is deliberately technology-neutral, so the marking layer is a market still being negotiated in public — now on the regulator’s clock.
What a watermark can and cannot do
It is worth being honest about the limits, because the law now leans on this layer. Today’s detectors are per-ecosystem: ElevenLabs’ tool answers “was this made by ElevenLabs?”, OpenAI’s verifier looks for OpenAI’s signals. “No signal found” therefore does not mean a clip is human — it may come from another generator, or the mark may be gone. Provenance metadata such as C2PA Content Credentials does not survive re-encoding or a screen recording on its own, which is why the spec treats watermarks as “soft bindings” that can re-attach stripped credentials. And in June 2026, researchers demonstrated adaptive attacks that drove audio-watermark detection below 10% while keeping the audio clean. None of this makes marking pointless — it makes it what it is: a transparency layer for the honest majority, not a fraud shield. The fraud numbers insist on the distinction. The FBI’s 2025 internet-crime report, published in April, broke out AI-enabled fraud as a category for the first time — 22,364 complaints and $893 million in reported losses — while CrowdStrike counted voice-phishing attacks up 442% through 2024 and Pindrop logged a 1,300% surge in deepfake calls into contact centres.
No universal “is this AI?” oracle exists.
Disclosure is not consent
There is a second gap the Sunday did not close. Article 50 answers “is this synthetic?” — it does not ask “did the person whose voice this is agree?”. That question belongs to likeness law, and it is still a patchwork: Tennessee’s ELVIS Act, in force since mid-2024, was the first statute to put a person’s voice under the right of publicity; the US NO FAKES Act cleared the Senate Judiciary Committee on 18 June 2026 but is not law; Denmark’s bill giving people copyright-style rights over digital imitations of their voice and likeness was slowed by a snap election and is still pending. The EU itself has no union-wide right to your own voice — only a declaration by culture ministers that citizens “must be protected against digital replicas of their personal characteristics without consent”. In other words: the disclosure layer arrived on Sunday. The consent layer is still being legislated, jurisdiction by jurisdiction.
Where Blab stands
Blab is our voice studio, the surface of our own in-house TTS family — sub-second streaming speech, dubbing that preserves the original soundtrack, 40+ languages and sixty-four voices, wired into a REST API, a TypeScript SDK and MCP for production use. On the question the new rules answer, our position is simple: disclosure duties are duties, and the marking layer will keep evolving as the standards race settles. But on the question the rules still do not answer, Blab never waited for legislation: cloning a voice in Blab requires the consent of the person being cloned — it always has. “Voices so real, we require consent” is not a compliance slogan; it is the product’s oldest rule, adopted because the synthesis got good enough to demand it. A mark tells the listener what the audio is. Consent settles what it was allowed to become in the first place — and no watermark can retrofit that.
The label answers “is this voice synthetic?”. Consent answers “whose voice was it to synthesize?”. The law now requires the first. We started with the second.
For European teams the practical reading is this. The GDPR did not move on Sunday — a real person’s voice was personal data before Article 50 and remains so after it, and that layer still governs whose voice you may process at all. What changed is that transparency now has teeth of its own: fines up to €15 million or 3% of turnover, a complaints channel any citizen can use, and a whistleblower tool — even if capacity is uneven, with only eight member states having designated their market-surveillance contact point at the European Parliament’s last count in March. Do not calibrate to the slowest regulator. Build the disclosure in, keep a record of what you generated and when, and treat consent as the layer the law has not caught up to yet. Blab, from Arpanet BV, was engineered for the GDPR from its first line. Contact us and we will scope it with you.