ElevenLabs and the EU AI Act
US-based company specialised in AI voice generation: text-to-speech, voice cloning and dubbing via API and apps.
What the Act means when you deploy ElevenLabs
ElevenLabs is a specialised voice-AI vendor rather than a general-purpose model provider, so the Act conversation centres on your deployment: synthetic voice is squarely in the transparency rules — people must not be misled into thinking they hear a real human where disclosure is required, and cloned voices of real people raise consent and deepfake-marking duties. Voice data can also be biometric-adjacent, so pair the Act review with a GDPR one.
Questions to send ElevenLabs
Copy these into your supplier questionnaire. Answers in writing beat answers on a call — your Article 26 file needs evidence, not recollection.
- Q1
What consent and verification does your voice-cloning flow require, and what audit trail do we get for each cloned voice?
- Q2
Do generated audio files support watermarking or detection mechanisms we can rely on for disclosure duties?
- Q3
Where is our audio and text data processed and stored, and what are the retention defaults?
- Q4
Is our data used to train your models, and how do we opt out contractually?
Documents to request for your file
- Instructions for use / product documentation for the exact service and version you deploy
- Identification of the underlying model(s) and their provider, plus the documentation passed through to you
- Data processing agreement, sub-processor list and processing locations
- Security documentation: certifications, retention defaults and access controls
- Written statement on whether your inputs and outputs are used for training, and how to opt out
- Licence terms for the exact version you deploy, including commercial-use conditions
Which of these you can actually obtain depends on your contract and tier — treat the list as a checklist to work through with the vendor, not as an entitlement.
Articles to have on the table
- Art. 26Deployer obligations
If you use this vendor's technology professionally in a high-risk context, you must follow the instructions for use, assign competent human oversight, keep logs and monitor operation.
- Art. 25When you become the provider
Putting your own name on the system, changing its intended purpose or substantially modifying it moves you from deployer to provider — with Article 16 obligations attached.
- Art. 50Transparency towards people
Where people interact with an AI system, or where content is AI-generated or manipulated, disclosure and — in defined cases — machine-readable marking are required. This duty sits with you, not the vendor.
Most buyers of AI land in the deployer role. Read the full deployer obligations under Article 26 — or the overview of all operator roles if you are not sure which one you hold.
Go to the source
Verify everything on this page with ElevenLabs directly. Public pages change; profiles do not update themselves.
Important: what this page is not
This profile is based on publicly available information about ElevenLabs and describes only who they are and what they offer. It makes no assessment of ElevenLabs’s compliance, contains no rating or certification claim, and is not endorsed by or affiliated with ElevenLabs.
EU AI Act obligations depend on how you deploy this vendor's technology and on your role (provider, deployer, importer, distributor). Verify every fact and commitment directly with the vendor before relying on it — this profile is a starting point, not legal advice.
Nothing here is legal advice. Confirm the facts with the vendor and your own counsel before you rely on them.
Run the free 2-minute checker — deterministic classification, no sign-up.