Wait, What Are We Legislating?

The EU is spearheading two of the most ambitious pieces of tech regulation to date. Do any of us understand what’s in it?

Sarah Delporte, Program Manager at the Idiap Research Institute, Geneva, absolutely does. In this immersive conversation, she takes us through the frameworks and nuances of this crucial regulatory moment. 

The views expressed are solely those of the interviewee and do not in any way reflect the position of the Idiap Research institute.

PUBLISHED 5 JULY 2026
BY: Sarah Delporte

AI-generated content has become a catch-all term covering everything from hyper-realistic deepfakes of public figures to what some call “AI slop” – surreal, cartoonish content that floods feeds without being remotely realistic. Why does that distinction actually matter for how regulation is designed? 

It matters enormously, and I think it’s one of the most overlooked problems in how we’re approaching these contents. The instinct in regulation has been to focus on realism: the closer something looks to an authentic video of a real person saying something they never said, the more dangerous it is, and therefore the more it should be regulated. That logic makes intuitive sense. But the problem is that online content ecosystems don’t operate that logic at all. 

What travels on social media isn’t necessarily what looks real, it’s what triggers an emotional response. Cartoonish, surreal, obviously AI-generated content can spread just as fast as a convincing deepfake, and it can embed messages about gender roles, about who belongs in public life, or about “what women are for,” in a far less visible way. When something looks absurd, our critical filters lower. We share it because it’s funny, or weird. We don’t interrogate it the way we might interrogate a realistic video. 

So the distinction matters because most current and proposed regulation is built around how realistic content appears, whereas the actual harm does not follow that boundary. You can cause real damage through content that looks like a cartoon, like normalizing misogynistic ideas, reinforcing stereotypes, or shaping how young people understand gender. And that category of harm is not well captured by the regulatory framework as it currently exists. 

The EU AI Act and the Digital Services Act are two of the most ambitious pieces of tech regulation in the world, and they’re often mentioned in the same breath, but they actually do quite different things. Can you explain in simple terms what each framework targets and where we are in 2026? 

They really are quite different instruments. 

The AI Act, which formally entered into force in August 2024, is essentially a product regulation: it governs the development and deployment of AI systems themselves, classified by risk level. At the top are “prohibited practices:” systems you simply cannot deploy in the EU, which would infringe on fundamental rights, like real-time biometric surveillance in public spaces or social scoring. Followed by “high-risk systems:” AI used in hiring, in law enforcement, or in credit scoring, which face significant obligations around transparency, documentation, and human oversight. And then of lesser concern are “limited” and “minimal risk” systems, which mostly cover everyday applications such as chatbots, recommendation systems, and spam filters, which are subject only to light transparency obligations or no specific regulatory requirements at all. 

For the purposes of our conversation, the most relevant provision is Article 50, which introduces transparency obligations for AI-generated content, including deepfakes. Those obligations will become enforceable in August 2026. What that means in practice is that systems generating or manipulating synthetic content (images, audio, video) will be required to mark their outputs in a machine-readable format so that the artificial nature of the content can be detected. A draft Code of Practice on how to implement those labelling requirements was published in December 2025 and is expected to be finalised by June 2026, just before the obligations kick in. 

The DSA is a completely different logic. It’s not about regulating AI systems, it’s about regulating  platforms. Specifically, in relation to the content that circulates on them and the systemic risks their design creates. It’s a tiered framework: the heaviest obligations fall on “very large online platforms,” aka those with more than 45 million monthly users in the EU (e.g., Instagram, YouTube, TikTok, Amazon), and they include things like algorithmic transparency, risk assessments, access to data for researchers, and a prohibition on profiling-based advertising targeting children. The DSA has been fully applicable since February 2024 and, in December 2025, we saw its first major enforcement decision: a €120 million fine against X for breaching transparency requirements.  

Where we are in 2026 is an interesting moment. The frameworks are in place. The question is whether they work in the way they were intended… and for whom. 

There’s a fascinating and underreported tension between the two frameworks: the AI Act is built around risk levels and content realism, while the DSA focuses on systemic platform risks and illegal content. Where do those two logics pull in different directions – and what falls through the gap between them? 

Indeed, the AI Act and the DSA were designed to be complementary, but they rely on different logics, and that creates a gap with real consequences. 

The AI Act, as I mentioned, is primarily a product regulation based on risk classification. Its transparency obligations for synthetic content depend on whether something is “realistically” generated or manipulated. In other terms, whether it could deceive someone into thinking it’s authentic. That's a sensible starting point, but it means the framework is oriented toward individual pieces of content and individual systems. 

The DSA, by contrast, is systemic. It’s asking: What are the structural risks that this platform’s design creates for society? Its provisions on risk assessment, algorithm transparency, and data access for researchers are about understanding and mitigating harm at scale. But the DSA doesn’t directly regulate the creation or labelling of AI-generated content, that’s the AI Act's territory. 

So the gap is this: content can be harmful, widely shared, and disproportionately affect certain groups  – women, for instance – without clearly falling under either framework. AI-generated content that isn’t an obvious “deepfake” may not trigger the AI Act’s transparency rules. And the DSA relies on platforms  to assess and report risks, which means its effectiveness depends heavily on what data they share and what regulators decide to investigate.  

In practice, this leaves out a whole category of content: for example, cartoon-style or obviously artificial videos that still promote misogynistic ideas, or content that nudges algorithmic recommendations toward gender-stereotyped material. 

The way content spreads online makes this even harder to address. By the time something has been reshared across platforms, often without context, information about where it came from is usually lost, and once those signals are stripped away, the AI Act’s transparency requirements become hard to enforce. 

Limits of Regulation and Gendered Harm 

The AI Act’s labelling requirements don’t fully apply until August 2026, and even then, they apply primarily to lawful deepfakes. Content that’s already illegal – non-consensual intimate images, defamation – is handled under other laws. Does that distinction hold up in practice, or does it create a dangerous grey zone? 

It doesn’t hold up particularly well in practice, and I think it’s important to be honest about that. On paper, the legal framework makes sense: the AI Act deals with transparency for lawful AI-generated content, while illegal content is addressed through national criminal law, data protection rules, and the Digital Services Act. Under the DSA, platforms are required to put in place mechanisms to report and remove illegal content quickly. The idea is simple: different rules apply to different harms. 

But in reality, those harms can be combined. So for someone who has had a sexualised deepfake created and shared without their consent, the different legal layers that apply do little to help them in practice. The content doesn’t come with a label explaining which legal category it falls into. Platforms operate across multiple jurisdictions, with different rules. And the harm happens immediately. In fact, the harm is the sharing itself. By the time legal remedies become available, the content has often already spread. 

There’s a specific issue here that I think is particularly concerning: by limiting its transparency obligations to lawful deepfakes, the AI Act risks creating the impression that there is a clear category of acceptable synthetic imagery of people, content that simply needs to be labelled, and that can be separated from harmful cases. And even where labelling requirements apply, they don’t address how content spreads, they don’t prevent reposting, and they don’t offer victims meaningful recourse.

Enforcement across borders remains a structural problem. A deepfake created outside the EU, shared by someone in the US, reposted endlessly without context – at what point does regulation have any grip on that content? 

Well, the short version is: regulation has some grip, but less than these frameworks imply. 

The AI Act applies extraterritorially to some extent: it covers AI systems whose outputs are used in the EU, regardless of where they are developed. So in theory, a deepfake generator based in the US whose outputs circulate in the EU is within scope. But in practice, enforcement against a non-EU entity depends on market access leverage, on international cooperation, and on the platform layer, which is where the DSA becomes relevant. 

What the DSA can do is require very large online platforms (VLOPs) operating in the EU to put in place mechanisms to report and remove illegal content, to assess systemic risks on their platforms and to  make their moderation practices more transparent. That gives regulators a lever over the platform that distributes it. One practical tool under the DSA is the “trusted flaggers” mechanism, where organisations with recognised expertise can report illegal content, and their reports are given priority by platforms. 

But reposting is a genuinely structural problem that neither framework solves. Content that is removed  from one platform can be reposted elsewhere, stripped of context or metadata, and recirculated. Detection tools exist but are imperfect and expensive. And the DSA’s enforcement capacity, especially in a geopolitically fragmented environment, is not unlimited. 

You draw attention to AI-generated content that appears playful or absurd – surreal videos, cartoonish imagery – but which can embed misogynistic or masculinist messages in less visible ways. Why is that category of content particularly dangerous, and why is it the hardest for regulation to reach? 

Because it’s designed, intentionally or not, to bypass the mechanisms we have for identifying and challenging harmful ideas. 

When something looks like a threat, we recognise it as a threat. When something looks like a joke, or a meme, or a weird AI video of a cartoon cat with man-like features explaining why women belong in the home, our guard is different. Format shapes meaning. Tone shapes reception. A misogynistic argument delivered through an absurdist AI video reaches a completely different audience than the same argument delivered as a manifesto. And it often reaches them more effectively. 

What makes this category particularly difficult for regulation is precisely the fluidity we discussed earlier: there’s no realism threshold to cross, no legal category of “harmful-but-not-illegal misogynistic cartoon content.” It floats freely. The DSA’s systemic risk provisions are probably the most relevant part of the framework in this context. Platforms are supposed to assess the risks that their recommendation algorithms create for gender equality, for example. But it’s not always clear what those risk assessments should look like in practice. Enforcement also happens mainly at the platform level. And the business models of those platforms can themselves encourage the creation of content that degrades or sexualises women, since they often generate high levels of engagement and are therefore financially rewarding. 

There’s also a temporal problem. Regulation acts on categories that have been identified as harmful. But the content ecosystem moves faster than that categorisation process. By the time we’ve identified a  genre of harmful content and worked out which legal provision applies, it’s already been repackaged into something new. 

Young people are perhaps the most exposed to this content and the least equipped to interrogate it. What concerns you most about how AI-generated media is shaping younger audiences, and how does gender figure into that? 

What concerns me most is the normalisation dynamic. The way that repeated exposure to a particular representation of the world shapes what feels normal, without anyone consciously deciding that it should. 

Research on online misogyny and young people already shows something troubling: in the UK, nearly  70% of boys aged 11 to 14 have encountered misogynistic content online. That content doesn’t arrive labelled as misogyny. Studies show that young men often encounter extreme material through entirely unrelated searches, and research suggests that repeated exposure to misogynistic content can reinforce or normalise sexist attitudes. Overall, AI-generated content accelerates that dynamic because the production barrier has essentially collapsed. The volume is higher, and the targeting is easier.  

The gender dimension is dual. Boys are absorbing messages about what masculinity requires and the role women supposedly have. Girls, meanwhile, are internalising what the world apparently thinks about their bodies, their presence in public life, and their credibility. That’s happening in the same content environment, on the same platforms, amplified by the same recommendation systems. 

Women in public life – politicians, journalists, activists – are disproportionately targeted by manipulated content. What does that do to democratic participation over time? And is existing regulation even designed with that specific harm in mind? 

The data on this is striking and should be far more central to public conversation. A December 2024 study by the American Sunlight Project found more than 35,000 mentions of non-consensual intimate imagery depicting 26 members of the US Congress, 25 of them women, and one man. That’s not a marginal problem. The research on deepfakes and elections more broadly consistently shows that women in politics are disproportionately targeted with fabricated pornographic content specifically designed to discredit, humiliate, and, ultimately, deter their participation. 

The democratic harm is structural, not just individual. When a woman politician is targeted by a deepfake campaign, the most visible effect is reputational damage. But there are broader consequences as well: it can deter her from continuing in public life, discourage others from entering politics, and reinforce the idea that women’s presence in public life comes at a cost. Research published in peer-reviewed journals increasingly shows that deepfakes targeting women in public life undermine what political scientists call  “empowered inclusion,” being the ability not just to participate in democratic processes, but to do so on terms that allow meaningful contribution. 

The DSA’s systemic risk framework must assess risks to democratic processes and fundamental rights. But the specific intersection of synthetic content, gender, and political participation is not explicitly addressed in either the AI Act or the DSA. What we have are general provisions that need to be interpreted to cover this harm, rather than rules designed around it. 

WHAT’s MISSING

If legislation alone cannot solve this, what does a genuinely comprehensive response look like? What roles do platform design choices, media literacy, and friction before sharing all play – and who  should be driving that agenda? 

I think we need to think of it as a three layers problem, and legislation is only well-suited to one of them. 

The first layer is what law can do: set minimum standards, create liability where harm occurs, mandate  transparency, and give people who are harmed meaningful routes to redress. That work matters and needs to be done well. But law operates after the fact, it moves slowly, and it depends on enforcement  capacity that is always going to be stretched. 

The second layer is how platforms are designed. Platforms constantly make choices that affect what people see and how quickly content spreads. For example, small changes like adding a short pause before sharing, or asking users if they have read a piece of content before sharing it, have been shown to reduce the spread of false information. Clearer labels that people, and not just machines, can easily understand would also help. Platforms also decide what their recommendation systems promote. Prioritising synthetic content over authentic content is not inevitable. It is a choice. The challenge is that many of the changes that would reduce harm also reduce engagement, and engagement is what drives revenue. So we need a combination of regulatory push and market incentive redesign.

The third layer, and the one that I think gets both the least attention and potentially has the most long-term impact, is media literacy. Not the “spot the deepfake” version of media literacy, which is increasingly unreliable as the technology improves, but something deeper: understanding the content ecosystem, understanding why content is shown to you, understanding that the emotional response you’re having to a piece of content may be exactly what it was engineered to produce. That kind of critical literacy needs to start young and needs to be embedded in education systems. 

As for who should drive this, I would say that there cannot be a single driver. The most durable responses are, I believe, through coalitions: civil society identifying and naming the problem, researchers providing the evidence base, regulators creating accountability frameworks, platforms implementing them under pressure, and educators equipping people to navigate the environment. What's missing right now is the coordination between those layers – and often the participation of women’s organisations in the design of those systems from the beginning, rather than being consulted at the end. 

You've highlighted figures like Joy Buolamwini, Virginia Dignum, and Gabriela Ramos as women actively shaping AI governance. Margrethe Vestager also championed the digital regulatory agenda at the highest level. What do these figures have in common, and why does it matter that women hold these positions? 

What strikes me about all of them is that they came to AI governance from somewhere else. They come from poetry and code, from philosophy, from international development, from competition law, and  that outsider perspective turned out to be exactly what was needed. 

Joy Buolamwini’s work is a good example. She showed that facial recognition systems performed much worse on certain groups, particularly dark-skinned women. An issue she identified in part through her own experience using these systems. Her lived experience and rigorous research methodology made the work undeniable, and pushed major companies like IBM, Microsoft, or Amazon to rethink their systems. 

Virginia Dignum brings a philosophical and ethical framing to AI governance that keeps asking the question that technical communities often skip: What is this for, and who does it serve? And Gabriela Ramos, through UNESCO’s work on AI ethics, has been insisting that international AI governance has to account for the full range of human societies, not just the countries and companies that happen to be building the systems. 

What they share is a refusal to treat AI as a neutral technical domain. They understand – and have spent careers arguing – that the design choices made at the beginning are political choices, and that if you don’t have diverse people in the room when those choices are made, you will systematically build in the blind  spots of whoever is in the room. 

Why does it matter that women hold these positions specifically? Because the harms we’ve been discussing, the deepfakes, the misogynistic content, the way synthetic media is being used to push  women out of public life… these are not harms that tend to get identified as urgent by people who are not experiencing them. Representation isn’t just a fairness argument. It’s an effectiveness argument. The problems you don’t see are the problems you don’t solve, right?

What I wish more people understood is that we are still, genuinely, at the beginning. The systems being built now, the norms being established now, the regulatory frameworks being cemented now, these are foundational. The decisions made in the next five years about how AI-generated content is governed, what counts as harm, who can challenge it, and whose experiences are treated as evidence, these will shape the information environment for a generation. That should feel like urgency, but it should also feel like agency. We have not yet missed the window. 

What concerns me is the pace asymmetry. The technology scales faster than the governance can. A piece of harmful synthetic content can reach millions of people in hours; the regulatory response to the category of harm it represents takes years. That gap is real, and I don’t think we should minimise it. 

But what gives me hope is precisely the kind of initiative that Godmothers represents: the insistence that these conversations happen in public, with diverse voices, before the architecture is locked in. It gives me hope that the regulatory frameworks we’re discussing, however imperfect, exist at all. Five years ago, the idea that the EU would have a comprehensive AI Act with specific transparency obligations for synthetic content would have seemed optimistic. It’s now law. That matters. 

I also find hope in the researchers and advocates who are doing painstaking work to document the harm,  build the evidence base, and show that this is not just a technical issue, but one that also requires social, legal, and design responses. The women doing that work often do it with fewer resources and less institutional support than their male counterparts. But they do it. And increasingly, people are listening. 

Finally — what are you reading right now? 

I’ve been reading Asma Mhalla’s Technopolitique and Cyberpunk, which I find great for challenging your thinking, even if I’d keep a bit of distance from the more alarmist tone. I’d also recommend Carissa Véliz’s work, which offers a very clear and accessible way of thinking about data, privacy, and the ethical questions surrounding them in everyday life. 

And to stay in the spirit of our discussion, two Instagram accounts I like following are @ninon.ia_officiel for AI news and practical insights, and @yasware_ for online privacy and what’s actually happening to your data. 

At the same time, I think it’s important to remember that AI and technology overall are and can truly be a source for good, and it’s really up to us to keep questioning how we build and use them.

Sarah Delporte, Program Manager at the Idiap Research Institute, Switzerland. The views expressed are solely those of the interviewee and do not in any way reflect the position of the Idiap Research Institute.

Sources 

EU AI Act (Regulation (EU) 2024/1689)

EU AI Act timeline

Draft Code of Practice on AI-generated content transparency

X fine

DSA timeline
DSA timeline

DSA overview

DSA systemic risk framework

DSA Transparency limitation

Gaps in EU AI Act article 50

DSA and illegal content

DSA extraterritorial reach

AI Act extraterritorial scope

Algorithm normalisation of toxicity

UK statistics on boys and misogynistic content online
(citing Vodafone 2024 data) 

Academic research on algorithm-driven normalisation for young people

Social media algorithms amplify misogynistic content to teens

American Sunlight Project / The Markup study on deepfakes targeting Congresswomen

Deepfakes and democratic participation research

Women politicians and deepfakes

Algorithmic Justice League