What happened
Italy's data protection authority (Garante per la Protezione dei Dati Personali) issued provvedimento n. 577 (adopted 23 July 2026, published/press-released 7 August 2026) ordering broadcaster R.T.I. (Mediaset) to stop processing La7 news director Enrico Mentana's image and voice in AI-generated deepfake segments aired on satirical show Striscia la Notizia. The Garante found on-screen AI disclaimers insufficiently clear/visible for inattentive viewers, applying GDPR Articles 5, 6 and 25 (lawfulness, fairness, transparency, data protection by design) rather than the EU AI Act's Article 50 transparency rules (which R.T.I. argued only applied from 2 August 2026). The order imposes a processing ban under GDPR Article 58(2)(f), a formal warning under Article 58(2)(b), and a compliance-reporting duty within 30 days — but no fine, given the novelty of the legal question.
Why it matters
This is one of the first European enforcement actions applying GDPR principles (rather than the newly-applicable AI Act) to deepfake/synthetic-media use of a real, identifiable person, explicitly rejecting the argument that satire or an on-screen AI label absolves broadcasters of a lawful basis and design obligations. It signals that AI Act Article 50 labelling is necessary but not sufficient — deployers of synthetic media depicting real people still need an independent GDPR lawful basis, and disclosure must be actually noticeable to inattentive viewers. Any organization producing AI-voice/face content of identifiable individuals (marketing, satire, dubbing) in the EU faces exposure under this same GDPR theory regardless of AI Act applicability dates.
Action needed
R.T.I. must report compliance measures within 30 days of notification; broadcasters, marketers, and platforms using AI-generated voice/likeness of real people in the EU should review lawful-basis and disclosure-visibility practices now, independent of AI Act Article 50 timelines.