Deepfakes, a rapidly evolving form of synthetic media, have exposed regulatory uncertainty of the EU’s AI framework. While the GDPR considers deepfakes as personal data, the AI Act mostly classifies them as limited-risk systems with minimal transparency and labelling obligations. Through a doctrinal legal analysis, this paper demonstrates how conflicting regulatory approaches contribute to an “accountability vacuum”, enabling private actors to evade responsibility for the malicious use of deepfakes. In this context, we argue for reclassifying deepfakes as high-risk systems under the AI Act, which would prompt stricter transparency, oversight, and auditing requirements. We also suggest ex-ante, mid-course and ex-post mechanisms to address enforcement gaps. Finally, this article proposes a multi-stakeholder approach to strengthen the frameworks for AI accountability within the EU.