90970

Immagine creata con IAAI-generated image

A satirical deepfake is still data processing: the Garante, the Mentana case and disclaimers that fall short

The Italian data protection authority, the Garante per la protezione dei dati personali, has issued a warning to R.T.I. Reti Televisive Italiane, the broadcaster behind the show Striscia la Notizia, over segments in which the image and voice of journalist Enrico Mentana had been manipulated using artificial intelligence. The decision, adopted on 23 July 2026 and announced in the press release of 7 August, does more than state that a satirical deepfake can harm the rights of the person portrayed. It makes a sharper point, and a more useful one for anyone producing synthetic content: satire does not switch off the data protection regulation, and flagging that a video is fake is not enough if the warning does not reach the viewer.

The case

The proceedings began with the complaint lodged by Enrico Mentana under Article 77 of the Regulation. In the contested segments his real image, filmed in the studio from which he anchors an evening news programme, was reused to have him deliver, through AI-generated dubbing, statements he never made, following a script written by the show’s authors. As the decision notes, the clips also carried the logo of the very newscast he directs, to make the staging more convincing, and were then distributed on the programme’s website, on its social channels and on the Mediaset Infinity platform. The complainant asked for the images to be erased and objected that a great many people had believed those statements to be authentic.

The defence: licence and the right to satire

The broadcaster replied that the audiovisual clips had been licensed from La7, that the only step it had taken was dubbing Mentana with a voice other than his own, and that all of this fell within the right to satire, exercised by a programme that is notoriously sarcastic. It added that it had labelled titles and segments with warnings about the artificial nature of the videos, though it considered them unnecessary, and it invoked the European regulation on artificial intelligence to observe that deepfakes are not, in themselves, a prohibited practice: information obligations rest on those who create them, are reduced where the content is part of a manifestly satirical work, and in any event, R.T.I. itself pointed out, only became applicable from 2 August 2026. In substance, the defence placed the matter squarely within satire and treated the label as proof of its own diligence.

Why satire is not an exemption

The Garante brought the processing within the exercise of freedom of expression, governed by Articles 136 to 139 of the Italian Code, among whose forms the right to satire also falls. That, however, does not confer immunity. Those provisions confirm that processing is lawful even without the data subject’s consent on one precise condition: that it respects the rights, fundamental freedoms and dignity of the persons concerned. Satire enjoys wider limits than news reporting or criticism, because it lives on paradox and hyperbole, but for that very reason its nature must remain perceptible. Here, the authority observes, the journalist’s real image was used, placed in his own television studio, with an alteration carried out “by means such as not to make the existence of that alteration clearly perceptible”, and with statements that “appear, on an immediate viewing, truthful” because they lack the degree of exaggeration that would reveal them as fake. The real context makes the processing particularly insidious for personal identity and amplifies its capacity to spread disinformation, as confirmed by the many mocking messages the complainant received on social media.

Disclaimers that do not reach the viewer

This is the operative core of the decision. The Garante does not fault the absence of warnings, but their inadequacy. The processing, it reads, was not accompanied “by the use of sufficiently clear disclaimers, at least with regard to the technological knowledge of an average or otherwise inattentive public”. The very features of the videos, apt to make them seem truthful, would have required more explicit communications, made more evident at the various moments of broadcast, so as to reach even the less attentive users or those who joined the programme once it had already started. It is not enough, in other words, for the information to exist: it has to be built to reach the person watching. On that basis the authority found a breach of Article 5 of the Regulation, on the principles of lawfulness, fairness and transparency, and of Article 25, on data protection by design and by default, for the failure to adopt adequate technical and organisational measures.

The measures

The penalty is not financial. Since this is a legal question marked by novelty, arising from the use of recently introduced technological tools within artistic expression, the Garante considered a warning under Article 58(2)(b) of the Regulation to be proportionate. It also ordered, under letter (f) of the same article, a ban on further processing of the complainant’s data in the manner complained of, save for retention for any judicial needs, and recorded the measures in the authority’s internal register. R.T.I. must report within thirty days on the steps taken to comply. The authority finally recalls that failure to observe the ban may expose the company to the criminal penalty under Article 170 of the Code and to the administrative fine under Article 83(5)(e) of the Regulation: the warning closes these proceedings, not the wider matter.

The GDPR before the AI Act, and alongside it

The conduct predates 2 August 2026, the date on which the transparency obligations of Article 50 of Regulation (EU) 2024/1689 became applicable, as seen in relation to AI content transparency after 2 August. R.T.I. itself made the point in its defence. That Article 50 was later touched by the Digital Omnibus on AI, published on 8 July 2026 as Regulation (EU) 2026/1744: the act rewrote its paragraph 7 on codes of practice and introduced a four-month transitional period, until 2 December 2026, for the marking obligation of paragraph 2 on systems already placed on the market, but it did not touch the duty, on those who disseminate a deepfake, to make it recognisable, which remains applicable from 2 August 2026. But data protection was not waiting for that deadline: Regulation (EU) 2016/679 already governed that processing, and continued to do so. The two regimes, moreover, converge. The AI Act obligation for deepfakes is to disclose that the content has been artificially generated or manipulated; where the video forms part of a manifestly satirical work the obligation shrinks to merely indicating the existence of such content, but in an appropriate form, which is precisely the point the Garante raised when it found the warnings insufficiently clear. The same need, to make synthetic content recognisable, runs through the machine-readable marking of AI-generated content, while the logic of protection by design, invoked here through Article 25, is the same that surfaced on minors, platforms and default design.

For anyone deploying artificial intelligence on the image and voice of real people, entertainment included, the message is clear. The label is not compliance: the processing must be fair and protective by design, and the warning about the artificial nature of the content has to be designed to reach the average viewer, not the already informed one. Satire remains a broad right, but it is exercised with respect for the dignity of the person portrayed. R.T.I. has thirty days to report to the Garante on the steps it has taken.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article