Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

To what extent are the transparency obligations of Art. 50(2) and (4) of the AI Act capable of combating violations of privacy and data protection rights by nonconsensual pornographic deepfakes?

Christiansen, Sophie Charlotte LU (2026) JAEM01 20261
Department of Law
Faculty of Law
Abstract
This thesis examines whether the AI Act and the transparency obligations of
its Art. 50(2) and (4) are adequate to effectively address violations of the
fundamental rights to privacy and data protection by nonconsensual
pornographic deepfakes.

To this end, the thesis first demonstrates how nonconsensual pornographic
deepfakes infringe the rights to privacy and data protection as enshrined in
Art. 7 and 8 of the Charter of Fundamental Rights of the European Union and
Art. 8 of the European Convention of Human Rights. Currently, deepfakes
are predominantly used for pornographic content involving women and
children. Such content constitutes a serious violation of the affected
individuals’ rights to privacy and data protection as... (More)
This thesis examines whether the AI Act and the transparency obligations of
its Art. 50(2) and (4) are adequate to effectively address violations of the
fundamental rights to privacy and data protection by nonconsensual
pornographic deepfakes.

To this end, the thesis first demonstrates how nonconsensual pornographic
deepfakes infringe the rights to privacy and data protection as enshrined in
Art. 7 and 8 of the Charter of Fundamental Rights of the European Union and
Art. 8 of the European Convention of Human Rights. Currently, deepfakes
are predominantly used for pornographic content involving women and
children. Such content constitutes a serious violation of the affected
individuals’ rights to privacy and data protection as it infringes on their
personal integrity, identity and autonomy. The thesis also considers the
inherently misogynistic nature of such conduct. After briefly outlining the
existing legal remedies available to address these harms and finding that they
are not sufficient to safeguard victims of nonconsensual pornography, it
provides an overview of the regulatory framework established by the EU AI
Act. The only provision in the AI Act that covers pornographic deepfakes is
a transparency obligation. From 2 August 2026, Art. 50 of the Act will require
that AI-generated content be labelled as such. The thesis then offers an in-
depth analysis of Article 50(2) and (4) AI Act using a legal doctrinal method.
It is found that the provision has several shortcomings and that its wording
allows for legal ambiguity making its implementation vague and its
effectiveness questionable. Additionally, significant enforcement challenges
are to be expected.

Finally, the thesis evaluates the limitations of the transparency obligations in
addressing violations of privacy and data protection rights. It is found that
transparency is neither capable of protecting against nonconsensual
pornographic deepfakes nor was this the legislative intention. The thesis
concludes that transparency requirements alone are inadequate to prevent or
mitigate the harms caused by such deepfakes. Moreover, the current
regulatory framework leaves significant loopholes and legal uncertainties
unresolved. It is insufficient to effectively address violations of fundamental
rights, particularly the right to privacy and data protection. Against this
background, the EU’s planned prohibition of AI systems designed to generate
pornographic deepfakes, applying from December 2026, represents an
important and necessary step. (Less)
Please use this url to cite or link to this publication:
author
Christiansen, Sophie Charlotte LU
supervisor
organization
course
JAEM01 20261
year
type
H1 - Master's Degree (One Year)
subject
keywords
AI, Artificial Intelligence, AI Act, Transparency, Pornographic Deepfakes, Privacy, Data Protection, Fundamental Rights
language
English
id
9230755
date added to LUP
2026-06-04 11:39:15
date last changed
2026-06-04 11:39:15
@misc{9230755,
  abstract     = {{This thesis examines whether the AI Act and the transparency obligations of
its Art. 50(2) and (4) are adequate to effectively address violations of the
fundamental rights to privacy and data protection by nonconsensual
pornographic deepfakes.

To this end, the thesis first demonstrates how nonconsensual pornographic
deepfakes infringe the rights to privacy and data protection as enshrined in
Art. 7 and 8 of the Charter of Fundamental Rights of the European Union and
Art. 8 of the European Convention of Human Rights. Currently, deepfakes
are predominantly used for pornographic content involving women and
children. Such content constitutes a serious violation of the affected
individuals’ rights to privacy and data protection as it infringes on their
personal integrity, identity and autonomy. The thesis also considers the
inherently misogynistic nature of such conduct. After briefly outlining the
existing legal remedies available to address these harms and finding that they
are not sufficient to safeguard victims of nonconsensual pornography, it
provides an overview of the regulatory framework established by the EU AI
Act. The only provision in the AI Act that covers pornographic deepfakes is
a transparency obligation. From 2 August 2026, Art. 50 of the Act will require
that AI-generated content be labelled as such. The thesis then offers an in-
depth analysis of Article 50(2) and (4) AI Act using a legal doctrinal method.
It is found that the provision has several shortcomings and that its wording
allows for legal ambiguity making its implementation vague and its
effectiveness questionable. Additionally, significant enforcement challenges
are to be expected.

Finally, the thesis evaluates the limitations of the transparency obligations in
addressing violations of privacy and data protection rights. It is found that
transparency is neither capable of protecting against nonconsensual
pornographic deepfakes nor was this the legislative intention. The thesis
concludes that transparency requirements alone are inadequate to prevent or
mitigate the harms caused by such deepfakes. Moreover, the current
regulatory framework leaves significant loopholes and legal uncertainties
unresolved. It is insufficient to effectively address violations of fundamental
rights, particularly the right to privacy and data protection. Against this
background, the EU’s planned prohibition of AI systems designed to generate
pornographic deepfakes, applying from December 2026, represents an
important and necessary step.}},
  author       = {{Christiansen, Sophie Charlotte}},
  language     = {{eng}},
  note         = {{Student Paper}},
  title        = {{To what extent are the transparency obligations of Art. 50(2) and (4) of the AI Act capable of combating violations of privacy and data protection rights by nonconsensual pornographic deepfakes?}},
  year         = {{2026}},
}