EU Parliament Committee Bans Deepfake Fraud and Cuts AI Act Machinery Overlap in Two Amendments
The European Parliament’s Internal Market and Consumer Protection Committee approved two amendments to the EU AI Act that extend its prohibited practices and reduce compliance friction for manufacturers. Both changes address implementation problems that emerged after the Act’s initial passage in March 2024.
Amendment 1: Deepfake Fraud Now Explicitly Banned
The AI Act already prohibits systems that deploy subliminal manipulation or exploit psychological vulnerabilities. The committee vote extends prohibited practices to include synthetic media specifically used to deceive individuals into financial transactions, legal commitments, or other consequential decisions — without their knowledge of the content’s artificial origin.
The addition closes a gap that critics had flagged since enforcement began: the original prohibited practices list targeted manipulation at the level of cognitive vulnerability, but said nothing explicit about synthetic video or audio used as the deceptive mechanism in fraud. Deepfake-enabled financial fraud has accelerated since the Act’s passage, with cases involving synthetic executive impersonation in wire transfer authorisation and synthetic contract negotiations entering European courts.
The new prohibition applies to the creation of such content, not merely its deployment. AI systems designed to generate synthetic media for deceptive financial or legal purposes will require conformity assessment under the high-risk framework — or face outright prohibition if the intent is manipulation.
Amendment 2: Machinery Regulation Exemption
Manufacturers of industrial equipment incorporating AI components faced dual compliance under the original framework. An AI system embedded in factory robotics required conformity assessment under both the AI Act (for the AI component) and the Machinery Regulation (for the physical equipment). The practical effect was duplicated paperwork, duplicated assessments, and confusion about which requirements superseded in cases of conflict.
The amendment establishes that AI systems embedded in machinery certified under the Machinery Regulation are exempt from separate AI Act conformity procedures, provided they meet equivalent safety standards. The equivalence standard is the operative constraint — regulators will need to specify what “equivalent” means before the exemption is operationally useful.
For manufacturers in automotive, aerospace, food processing, and industrial robotics — where AI-enabled equipment must comply with multiple vertical regulations — the exemption reduces overhead without changing the underlying safety obligations.
Scope and Limitations
The amendments preserve the AI Act’s risk-based architecture. High-risk systems still require conformity assessments. Transparency obligations for general-purpose AI models remain. The European AI Office retains enforcement authority. These are calibrations, not structural changes.
Financial services companies operating across both domains — trading algorithms under financial services law, customer-facing chatbots potentially under AI Act general-purpose model rules — see no relief. The machinery exemption is specific to physical equipment that falls under the Machinery Regulation, not a general principle that sectoral regulation displaces AI Act obligations.
The deepfake provisions create new documentation requirements for any system capable of generating synthetic content, even where the intent is legitimate. Creative and media applications will need clear internal policies on what constitutes “purpose to deceive” under the new language.
Timeline and Next Steps
Committee approval requires full Parliament and Council adoption before becoming law. Given committee-level consensus, passage is expected. Member states then transpose into national law, with implementation varying across 27 jurisdictions.
The prohibition on banned practices — including the new deepfake restrictions — takes effect six months after entry into force. The European AI Office has signalled additional technical guidance on authentication standards for synthetic content disclosure before that deadline.
Implementation clock:
- Banned practices (including deepfake fraud prohibition): 6 months after entry into force
- General-purpose AI model obligations: 12 months
- Full high-risk system requirements: 24 months
Full enforcement of the original AI Act framework is approximately 16 weeks away for general-purpose models. The deepfake amendment, once formally adopted, adds to that wave.