What the Garante decided
On 23 July 2026, Italy's data protection authority, the Garante, adopted a decision against broadcaster R.T.I. S.p.A. over AI-manipulated segments of the satirical programme Striscia la Notizia. It announced the decision by press release on 7 August. The segments used Enrico Mentana's image and voice to put statements in his mouth that he never made, and placed him in a studio setting. According to the Garante's decision (registry no. 577), R.T.I. breached Article 5 of the GDPR (lawfulness, fairness, transparency) and Article 25 (data protection by design and by default).
The remedies were a formal warning (ammonimento) under Article 58(2)(b) and a ban on further processing of Mentana's data in the contested manner under Article 58(2)(f). R.T.I. may keep the material only for judicial needs. No fine was imposed. The Garante's press release says the videos' realism, combined with warnings about their artificial origin that were not "clear, evident and comprehensible", could lead viewers to believe the content was authentic. The videos were also distributed on social networks.
The strongest case for the regulator
The case for intervention deserves a fair hearing. A deepfake of a working journalist, set in his real newsroom and speaking invented words, is different from a caricature. Mentana's professional credibility depends on people believing that what he says is what he says. If a viewer scrolling past a clipped social post cannot tell that the words are synthetic, the harm is real, and it is unrelated to whether the joke was funny. The Garante's own reasoning reflects this. According to the decision, it accepted that satire is a protected form of expression and is not bound by a truth requirement. It found the problem in the execution: the altered image looked credible rather than obviously exaggerated, and the disclaimers would not reach "inattentive users or those joining mid-program".
Why the narrow reading is the right one
From a pro-speech, pro-innovation view, the decision's most important feature is what it did not do. The Garante did not hold that satirical deepfakes are unlawful. The ANSA report quotes the authority saying that deepfakes, even satirical ones, must respect dignity and the principles of lawfulness, fairness and transparency. Yet the operative finding concerns labelling quality and design. It does not concern subject matter or the target's status. That is a proportionate approach: it leaves the satirist free to mock and asks only that the audience not be deceived about what is synthetic.
The remedy also matches the fault. A warning plus a bar on repeating the specific method is far less blunt than a fine or a ban on AI in comedy. The Garante also recognised, per the decision, that Article 85 of the GDPR, which requires Member States to reconcile data protection with freedom of expression and journalistic, artistic or literary expression, applies to satire. Treating that provision as a balancing test rather than a blanket exemption is what a rights-respecting regulator should do.
Where the risks lie
The weaknesses are in the standard, not the outcome. Three concerns stand out.
- Vague standard of "clear enough". Broadcasters are told a disclaimer must be visible "at all broadcast moments" for viewers who join mid-programme. That is a workable rule for a linear TV show. It is far harder for clips that are cut, re-uploaded and stripped of context on platforms R.T.I. does not control. Liability that follows content beyond the publisher's reach can push cautious producers away from AI-assisted comedy altogether.
- Data protection as a speech regulator. Article 25 is a privacy-engineering provision. Using it to judge whether a satirical label is prominent enough stretches a data protection tool into content regulation. Data protection authorities have real expertise on personal data. They have less on comedic form, and the risk of inconsistent national outcomes grows if each authority sets its own label standard.
- Overlap with AI transparency rules. The EU AI Act's Article 50(4) already addresses deepfake disclosure. It says that where content is part of an evidently artistic, creative, satirical or fictional work, the disclosure duty is limited to disclosing the existence of the manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. The Garante's demand for constant, highly visible labels sits in some tension with that lighter-touch wording. Producers now face two possible yardsticks for the same video.
What proportionate enforcement looks like
The Mentana case can be a useful precedent if it is read narrowly. Three practices would keep it that way.
- Publish concrete label guidance. Regulators should say what a compliant disclosure looks like for broadcast, short video and social formats, so that broadcasters do not have to guess after the fact.
- Coordinate on one standard. The European Data Protection Board and the AI Act authorities should align on how the GDPR's fairness principle and the AI Act's satire carve-out fit together, rather than leaving producers to satisfy whichever is stricter.
- Keep remedies graduated. Warnings and targeted bans, as used here, should remain the default for good-faith media outlets. Fines are better held back for deception aimed at harming the person depicted.
The underlying point is simple. Synthetic media that impersonates a real journalist in his real workplace creates a genuine risk of confusion, and a label that viewers cannot see does not solve it. But the answer is better disclosure, not less satire. The Garante chose the narrow path this time, and the test will be whether it and its peers keep to it as more AI-generated comedy reaches European screens.