AI Avatars and the EU AI Act: What Organisations Need to Prepare

Article 50 changes more than the disclosure line. It changes how organisations need to manage reusable digital identities.

AI avatars and the EU AI Act: a presenter and her digital likeness connected to multilingual videos, training and online channels, with permission, disclosure and control.

Olena Soinikova Research & field notes

Article 50 of the EU AI Act has applied since 2 August 2026. For organisations producing AI video, one consequence is immediate: some decisions that used to sit entirely inside a communications workflow now have a compliance dimension.

The visible part is disclosure. The more interesting part is what happens behind it.

 

I work with AI content production across NGOs, EU-funded projects and SMEs through Soinikova Digital, with a team of four AI content creators. The production logic has changed quite quickly. An avatar created for one video rarely has to remain one video. The same digital presenter can return in another language, appear in social media edits and later be considered for training or an interactive service.

 

At that point, the organisation is managing a reusable digital identity.

 

This is where Article 50 becomes more useful as an operational signal than as another regulation to summarise.

The AI Act regulates the output, not the word “avatar”

There is no separate legal category for an “AI avatar” in the AI Act.

For organisations publishing avatar video, the relevant analysis can instead lead to the definition of a deepfake in Article 3(60). The definition covers AI-generated or manipulated image, audio or video that resembles an existing person, object, place, entity or event and can falsely appear authentic or truthful.

Comparison of a synthetic presenter, a real-person digital avatar and an AI-dubbed speaker. Assessment considers what was generated, resemblance and audience interpretation.

That produces quite different situations inside the same production software.

 

A clearly synthetic presenter may sit differently from a digital version of a real director delivering a script that the director never recorded. Voice cloning matters because audio is covered by the definition. AI dubbing can create a more difficult case when the original speaker appears to deliver words or speak a language that was generated later.

 

I find this distinction more useful than asking whether AI was involved. In most contemporary production workflows, that question tells very little.

 

What matters is what was generated, who or what it resembles and how the audience is likely to understand what it sees.

A compliant platform does not settle the publication decision

Article 50 divides responsibility between different actors.

Under Article 50(2), providers of generative AI systems have obligations concerning machine-readable marking and the detectability of synthetic outputs. Article 50(4) creates a different obligation for deployers where image, audio or video constitutes a deepfake: the artificial generation or manipulation has to be disclosed. Article 50(5) sets requirements around how and when that information reaches people.

For a communications team, the practical distinction is straightforward. A technical marker embedded by a platform and a disclosure understood by the audience perform different jobs.

This becomes less tidy once a real production process is involved.

A script may be approved inside an NGO. An external creator generates the video. Somebody else produces a translated version. The communications manager publishes it, and three weeks later a consortium partner cuts 20 seconds from the original and uploads the extract to another social channel.

There is no single “AI compliance button” travelling through that chain.

 

The organisation therefore needs to know where its own responsibility begins and what happens to the relevant disclosure when content moves.

Two transparency roles connected to one AI-generated video: provider machine-readable marking and detectability, and deployer disclosure understood by the audience.

Consent belongs to another layer of the system

A real person’s avatar introduces a second issue that is easy to merge with transparency.

 

An employee, trainer or external expert may have agreed to the creation of an avatar. That permission can matter for GDPR, contractual arrangements and national rules concerning image and voice rights. It does not remove the Article 50 analysis.

 

Consent is absent from the Article 3(60) definition of a deepfake. Article 50(4) does not contain a general exemption for an avatar created with the represented person’s agreement.

 

Operationally, I separate these questions.

One concerns the organisation’s permission to create and use a digital representation. The other concerns what an audience needs to know when it encounters the resulting material.

 

The separation becomes important when the first production brief changes.

 

A person may approve an English training video. Six months later, the organisation wants a Greek version, a fundraising edit and several short videos for social media. Technically, producing them may take very little effort. The original permission may tell the organisation considerably less about whether those uses were actually authorised.

 

This is one reason AI avatars should stop being treated as ordinary media files once they become reusable.

The difficult part appears after the first video

Consider a project that records an expert speaking in English.

 

Later, AI is used to create a Danish version. The translated voice is synthetic and the lip movements are adjusted to make the delivery appear natural. The Danish video is then shortened for social media and distributed through project partners.

 

Several decisions now sit inside what initially looked like localisation.

 

The organisation needs a basis for using the person’s likeness and voice in the translated version. It also needs to examine the final output: if the expert appears to have personally recorded the Danish statement, the deepfake definition becomes relevant.

 

Distribution creates another problem.

A disclosure placed next to the original video on a project website may disappear when a partner downloads the file. A social platform can separate the video from its original description. An edit can remove the opening seconds where information was presented.

 

The published version is therefore what matters operationally, rather than the master file sitting in a project folder.

 

I see a broader pattern here from EU project delivery. Systems are often designed around the moment something is produced, while responsibility continues after the deliverable has left the original workflow. AI-generated identities make that weakness unusually visible.

Governance starts before generation

The AI Act does not require organisations to create an “avatar register”, maintain a particular script approval process or adopt a specific takedown procedure.

 

I would still want those questions settled before an organisation begins producing a large volume of content with the same digital identity.

 

Someone needs authority to approve the use of that identity. The scope of permission needs to be recoverable later rather than living in an email nobody can find. Scripts and translations need an approval path appropriate to the context. Access to the avatar account matters because possession of that access may effectively allow a person to generate new statements in somebody else’s face and voice.

 

Then comes publication and, eventually, withdrawal.

This is organisational governance rather than a hidden paragraph of Article 50. Keeping that distinction is important. The Regulation sets legal obligations; organisations still have to design the process that allows people to meet them consistently.

 

That process becomes more significant as avatars move beyond prerecorded media.

An interactive virtual receptionist, tutor or information assistant can bring Article 50(1) into the analysis because systems designed for direct interaction with natural persons carry their own transparency requirements.

 

A communications asset can therefore become part of service delivery surprisingly quickly.

What NGOs should pay particular attention to

For NGOs and EU-funded projects, I would pay particular attention to the gap between the original reason an avatar was created and everything that happens to it afterwards.

 

Project content travels.

A video commissioned for one work package can later appear on the organisation’s website and social media, be translated under another activity and circulate through consortium partners. The funding period can end while the content remains online. The person represented in it may have left the organisation long before the last copy disappears.

 

For a staff avatar, the first practical issue is scope. The organisation needs to know which uses were authorised: project context, channels, languages, duration and the kinds of statements the avatar may deliver. A reusable synthetic identity creates a very different permission problem from conventional permission to publish one recorded interview.

 

I would be considerably more cautious when the avatar represents a beneficiary, volunteer or project participant.

 

This matters particularly in programmes involving children, refugees, people with disabilities or other potentially vulnerable participants. The AI Act research does not provide one universal rule covering those cases. GDPR, contractual arrangements and applicable national image or voice rights may require a separate assessment. Operationally, consent to appear in conventional project media should not be stretched into an assumption that an organisation may create a reusable synthetic version of that person.

 

Multilingual production deserves its own control point. Translation changes words; AI dubbing can also change the apparent act of speaking. A participant who recorded one statement in one language may later appear to deliver a translated statement personally. That is precisely where script approval, translation review and the deepfake assessment start touching each other.

 

Social media creates a more mundane problem: disclosure has to survive distribution. If a project partner republishes or edits a video, the organisation needs a process that accounts for what the audience of that version actually receives.

 

And there needs to be a way out.

Projects close. Staff change. Permissions can change. Incorrect translations are discovered after publication. Access to production platforms moves between employees and contractors.

 

Article 50 does not prescribe the internal procedure for those events. An NGO using reusable avatars still needs to decide who can stop further production, who controls the account and what happens to existing content when continued use of the digital identity is no longer appropriate.

 

This is the part I would address before scaling AI avatar production across projects.

 

The immediate regulatory task is to understand when Article 50 applies and what disclosure is required. The organisational task goes further: the NGO needs to retain control over the identity it has made reproducible.

AI production has made it possible to create another version of a speaker, in another language, for another channel, without recording that person again.

The infrastructure around that capability now matters as much as the production itself.

Sources and practical resources

EU AI Act — consolidated version, EUR-Lex
Основной текст Regulation (EU) 2024/1689. Для статьи особенно важны Article 3(60) и Article 50.
EU AI Act — consolidated text on EUR-Lex

 

European Commission — Guidelines on Article 50 transparency obligations
Практическая интерпретация требований к providers и deployers, включая deepfakes и AI-generated content.
Article 50 Guidelines — European Commission

 

European Commission — Article 50 FAQ
Один из наиболее удобных официальных ресурсов для практических вопросов о disclosure, deepfakes, machine-readable marking и распределении ответственности.
Transparency obligations under Article 50 — FAQ

 

European Commission / AI Office — Code of Practice on Transparency of AI-Generated Content
Добровольный практический инструмент для выполнения transparency obligations. Это не замена требованиям Regulation.
Code of Practice on Transparency of AI-Generated Content

 

Regulation (EU) 2026/1744 — EUR-Lex
Нужен для проверки изменений 2026 года, включая переходное положение по Article 50(2).
Regulation (EU) 2026/1744 — EUR-Lex

 

GDPR — Regulation (EU) 2016/679, EUR-Lex
Отдельный правовой слой, который следует проверять при использовании изображения, голоса и других персональных данных человека для создания avatar.
GDPR — official text on EUR-Lex

--- From insight to implementation

Treat the avatar as a reusable identity, not a one-off video file.

Define permission, approval, disclosure, access and withdrawal before multilingual production begins.

--- New thinking

Latest insights

View all insights
EU Projects & Innovation

I use a free EU database to read commercial intentions before they become commercial announcements.

Olena Soinikova · August 24, 2026

EU Projects & Innovation

While everyone else waits for the official call to open, the real game is already visible in draft Work Programmes, CORDIS consortium graphs and TED velocity spikes.

Olena Soinikova · August 10, 2026

AI & Content Systems

Why Artificial Intelligence Is More Than Just a Toy — and How We Can Teach Our Children to Use It Wisely.

Olena Soinikova · Jube 06, 2026