EU AI Act Transparency Rules: What Marketing Teams Must Label, and What the UK Requires Instead
- Article 50 of the EU AI Act became applicable on 2 August 2026. It is now live, and it reaches ordinary marketing work.
- Marketing teams are deployers, not providers. Two of the four duties are yours, and they are the two nobody has built a process for.
- The test is not "did AI touch this". It is whether the output is a deepfake: something that resembles a real or plausibly real person, object, place or event and could be taken as authentic.
- Marketing will rarely shelter under the artistic and satirical carve-out. Where content mixes creative and commercial purposes, the prevailing purpose decides, and commercial content does not get the lighter treatment.
- The UK has no equivalent rule. The ASA has said so plainly. UK teams are still caught whenever the output is used in the Union.
- Penalties run to 15 million euros or 3% of worldwide turnover, whichever is higher.
On Sunday, a rule that most marketing teams have never read started to apply to almost everything they make.
Article 50 of the EU AI Act is the transparency chapter. It is short, it is unglamorous, and it has been sitting in the diary since 2024. It became applicable on 2 August 2026, and it does something the previous decade of AI commentary never managed: it puts a legal duty on the person pressing generate, not just on the company that built the model.
Most of the coverage I have read this week has been written by lawyers for lawyers. It explains the structure of the Article beautifully and tells you almost nothing about whether the hero image on your autumn campaign needs a label. So this is the marketing version. What the rules actually say, what they mean for the assets you produce every week, where the exemptions genuinely apply, and what the UK does instead.
What changed on 2 August 2026
The AI Act is Regulation (EU) 2024/1689. It came into force in August 2024 and has been arriving in stages ever since. Article 50, the transparency article, was always scheduled for 2 August 2026, and it arrived on time.
That last part matters, because a lot of people assumed it would slip. In November 2025 the Commission proposed a simplification package, and it passed: Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026 and entered into force on 27 July, six days before Article 50 applied. It delayed the high-risk regime. It did not delay transparency.
What it did add is a four-month runway on one narrow point: providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty. That is a concession to the toolmakers. The duties that fall on you as a deployer applied in full on the day.
Alongside the Article itself, three official documents landed in the weeks before the deadline, and they are the ones worth actually reading:
- The Commission's Guidelines on the transparency obligations (C(2026) 5054 final, 20 July 2026). Non-binding, but this is how the Commission says it reads the law, and it works through examples.
- The Code of Practice on Transparency of AI-generated Content (10 June 2026). Voluntary. Section 1 is for providers, Section 2 is for deployers, which means it is written partly for you.
- The EU icons for labelling AI-generated content (20 July 2026). Free to use, no attribution required, and optional.
By 31 July, around 190 organisations had signed the Code. On the provider side that includes Anthropic, Google, Meta, Microsoft, Mistral, OpenAI, Black Forest Labs and Synthesia. On the deployer side, the side that matters for this article, the signatories include Getty Images, Lufthansa, Bulgari, Lenovo, Iberdrola and Fastweb (European Commission, 31 July 2026). Brands are already signing up to label their own output. That is a competitive signal as much as a legal one.
Provider or deployer? Get this right first
Almost every mistake I have seen this week starts here. The Act splits the world into providers and deployers, and it hands them different duties.
- A provider develops an AI system and places it on the market. Your image generator, your copy tool, the AI features inside your CMS.
- A deployer uses an AI system under its own authority. That is you, your team, your agency.
You can become a provider without meaning to, which is worth knowing: if you build a tool on top of a model and put your own name on it, or substantially modify a system and market it, you may cross the line. But for the overwhelming majority of marketing work, you are a deployer using someone else's system.
Two of the four duties belong to the tool you bought. Which is exactly why you cannot assume they have been done.
The four duties, in plain English
People must know they are talking to a machine
AI systems intended to interact directly with people have to be built so that those people are informed they are dealing with an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person.
AI output must be machine-readably marked
Providers of systems generating synthetic audio, image, video or text must mark the outputs in a machine-readable format so they are detectable as artificially generated or manipulated. Recital 133 lists the sorts of techniques contemplated: watermarks, metadata identifiers, cryptographic provenance methods, logging and fingerprinting.
Tell people when you are reading their emotions
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them, and process the personal data lawfully.
Label deepfakes, and label AI text on matters of public interest
Two limbs. First: deployers generating or manipulating image, audio or video content constituting a deepfake must disclose that it has been artificially generated or manipulated. Second: deployers publishing AI-generated or manipulated text to inform the public on matters of public interest must disclose that, unless the text has undergone human review or editorial control and someone holds editorial responsibility for it.
One point of timing that is easy to miss, from Article 50(5): the information has to be given in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and it has to meet accessibility requirements. A disclosure buried in the third paragraph of a landing page does not rescue an ad that ran on Instagram.
Does this asset need a label? The actual test
Here is the single most useful thing in this article, and the thing most commentary gets wrong. The question is not "did AI touch this". Almost everything touches AI now. The question under Article 50(4) is whether the output is a deepfake, and that has a specific meaning.
The Commission's guidelines set out three cumulative criteria. The content has to resemble something closely; that something has to exist or plausibly exist; and it has to carry a false appearance of being authentic. All three, or it is not a deepfake.
Then there is the carve-out everyone in advertising immediately reaches for. Article 50(4) says that where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is limited to disclosing that such content exists, in a way that does not hamper the display or enjoyment of the work. Note that this is a lighter form of disclosure, not an exemption.
And it is largely closed to you. The Commission's guidelines address content that mixes purposes directly: where deepfake content combines the characteristics of an artistic, creative, satirical or fictional work with other purposes such as commercial or informative ones, the prevailing purpose is what counts, and where content is primarily commercial in nature the limited disclosure regime does not apply.
An advert does not become a work of art because it is beautifully made. Marketing is primarily commercial, so marketing gets the full disclosure.
Sixteen real scenarios, with a verdict on each
This is the table I would put on the wall. It is my reading applied to the work marketing teams actually produce, and the borderline ones are flagged as borderline rather than smoothed over.
| What you made | Label? | Why |
|---|---|---|
| AI-generated photo of your actual product, styled to look like a real photograph | Yes | Resembles a real, existing object and reads as an authentic photograph. This is the classic case, and it is also where consumer law bites hardest. |
| AI-generated background behind a real product shot | Usually no | The product itself is real and unaltered. If the background materially changes what the product appears to be or do, reconsider. |
| AI-generated model wearing your clothing | Yes | A plausibly real person, presented as authentic. Also raises a fit and representation question that sits outside this Article. |
| Invented brand mascot, obviously not real | No | Nothing existing is being resembled. Not a deepfake. |
| Abstract or pattern-based AI artwork for a banner | No | No resemblance to anything existing, no false appearance of authenticity. |
| AI voice clone of your real CEO for a video | Yes | Audio deepfake of an existing person. Get their written consent too; that is a separate issue. |
| Synthetic presenter reading a script, invented face | Likely yes | Plausibly a real person even if nobody in particular. The false appearance of a genuine human presenter is the point of using one. |
| Fully AI-generated influencer promoting a real product | Yes | Reads as a real person endorsing something. Under UK rules this also runs into the testimonial and endorsement provisions. |
| AI upscaling or denoising a real photograph | No | The photograph remains an authentic depiction, so no deepfake arises. The separate marking duty in Article 50(2) belongs to the tool provider. |
| AI removing a stray object from a real photograph | Usually no | Conventional retouching territory. The further you go from tidying, the closer you get to a label. |
| AI changing the season, weather or time of day in a real location shot | Borderline | Depends on whether it misrepresents the place or the offer. A hotel in permanent sunshine is a consumer law problem before it is an AI one. |
| Blog post drafted by AI, edited and signed off by a named person | No | Human review and editorial responsibility. Note this only matters at all if the text informs the public on a matter of public interest. |
| Ordinary product page copy generated by AI | No | Not a matter of public interest. Accuracy rules still apply in full. |
| AI-written thought leadership on health, finance, environment or public policy, published unedited | Yes | Text informing the public on a matter of public interest with no meaningful human review. |
| Customer service chatbot on your site | Yes | Article 50(1). The duty is the provider's, but the exposure is yours. |
| AI-generated stock-style imagery of anonymous people in an office | Likely yes | Plausibly real people presented as authentic. The fact that nobody can name them does not help. |
Scroll the table sideways to see the reasoning column.
If you take one pattern from that table: the label follows realism, not effort. A wholly AI-generated fantasy scene may need nothing. A single AI-swapped face in an otherwise real photograph needs a label.
Channel by channel: where this actually lands
Legal texts are organised by legal structure. Marketing teams are organised by channel. Here is the translation.
- Paid social and display. The highest-volume risk, because this is where AI-generated imagery has spread fastest and where variants get produced in bulk. If your creative automation stack generates hundreds of variants, the disclosure decision has to be made at the template level, not per asset. Nobody is reviewing 400 assets by hand.
- Influencer and creator work. Two questions now, not one. Is it disclosed as advertising, and is the person real? A synthetic creator promoting your product needs disclosing on both counts, and your creator contracts should say what the creator may do with AI on your brand's behalf.
- Product imagery and packaging. The single sharpest area, because it is where an AI image can misrepresent the actual thing you are selling. This is also where EU and UK law converge: an AI product shot that flatters beyond reality is a misleading commercial practice in the UK regardless of any labelling question.
- Video and audio. Voice cloning, dubbing and synthetic presenters all engage Article 50(4) once a real or plausibly real person is involved. AI-assisted colour grading and audio cleanup do not.
- Email and web copy. Mostly outside Article 50(4), because most marketing copy is not text informing the public on a matter of public interest. Do not read that as permission to publish unedited copy; it just means the exposure sits in consumer law rather than here.
- Conversational and chat. Article 50(1). Say it is a bot, at the start, in language a customer will read.
- PR and corporate communications. The one people miss. Statements on environmental performance, financial results, health claims or policy positions can be text on a matter of public interest. The saving grace is meaningful human review, which most PR content has anyway. Make sure it is documented.
How to label: the three EU icons
On 20 July 2026 the Commission published an official icon set, and the European Parliament has been promoting it to a general audience. It is genuinely useful, because it removes the "what should the label look like" argument from your team.
The Commission's own wording is worth quoting exactly, because it is the line people get backwards: "The use of these EU icons is optional, but the labelling requirements under Article 50 AI Act are not." You may design your own label. You may not skip the label.
Three practical rules for applying them:
- Perceivable by a human, at first exposure. The disclosure has to be understandable without any special technical tools. A metadata tag is not a label. Machine-readable marking is a separate duty on a separate party and it does not discharge yours.
- On the asset, not just on the platform. Ticking a platform's "AI-generated" toggle applies that platform's policy. It does not necessarily travel when the same asset appears in an email, on a landing page or in a partner's channel.
- Proportionate, not apologetic. The law asks for clear and distinguishable. It does not ask you to ruin the creative. A small persistent corner label, a first-frame card, or a line at the top of a caption all work.
Four mistakes I keep seeing already
- Labelling everything. Blanket "made with AI" on every asset is not compliance, it is noise, and Ofcom's own research suggests it may cost you: 59% of UK users said they may not trust content with an AI label attached. Over-labelling devalues the label on the content that genuinely needs one.
- Assuming the tool has handled it. Your generator's machine-readable marking, if it exists, satisfies the provider's duty under 50(2). It does nothing for your duty under 50(4). Two different obligations, two different parties.
- Treating "human in the loop" as a rubber stamp. The guidelines are explicit that superficial, formal or procedural checks do not count as human review. A spellcheck and a scan is not editorial control. Someone with relevant knowledge has to be able to approve, alter or reject on substantive grounds, and be responsible for it.
- Thinking a label fixes a misleading claim. It does not, in either jurisdiction. The ASA's example is a good one: a cosmetics image showing results the product cannot achieve is not rescued by an "AI-generated" tag. If the impression is false, labelling the technique does not cure it.
Agency or client: who actually carries this?
This is the question I get asked in every room and the Act does not answer it cleanly. Both parties can be deployers. The agency selects and operates the tools; the client sets the brief, approves the creative and publishes it. In practice you will both have a role, and the Act will not allocate it for you.
So put it in the contract. Four questions, answered in writing before the next campaign:
- Who decides whether an asset is a deepfake for the purposes of Article 50(4)?
- Who applies the label, and at which stage of production?
- Who keeps the record of what was generated, with which tool, and who signed it off?
- Who carries the cost if a regulator disagrees?
Record-keeping is the part everyone skips and the part that saves you. If you cannot reconstruct which assets were AI-generated six months later, you cannot answer a regulator's question, and you cannot fix a problem at scale when one appears. This is a workflow design problem long before it is a legal one, which is why I would build the disclosure decision into the production process itself rather than bolting a review stage onto the end. If you want a structured way to do that, my AI Workflow Design sessions are built around exactly this kind of redesign.
The UK position: no equivalent rule, and no plans for one
Now the comparison, because if you are reading this from London the obvious question is whether any of it is your problem.
As at August 2026, the UK has no statutory requirement to label or disclose AI-generated content in marketing. There is no UK equivalent of Article 50, no duty to tell someone they are talking to an AI, and no machine-readable marking rule. This is not an oversight. It is a settled policy position.
The framework is still the 2023 white paper, A pro-innovation approach to AI regulation, which set five cross-sectoral principles (safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; contestability and redress) and left them deliberately non-statutory, applied by existing regulators within their own remits. No new AI regulator was created. The May 2026 King's Speech contained no AI transparency bill.
The ASA has been unusually direct about what this means for advertising. In guidance published on 29 May 2025, it stated: "There is no blanket legal requirement in the UK to disclose the use of AI in ads."
Instead, the CAP Code is media-neutral, and the ASA applies a two-part test:
- "Is the audience likely to be misled if the use of AI is not disclosed?"
- If so, "is the disclosure clarifying the ad's message or contradicting it?"
That is a completely different intellectual starting point from the EU's. The EU asks what the content is. The UK asks what the content does to the person seeing it. And the ASA's rulings bear this out. I looked through the AI-involving cases: a robot puppy ad upheld in March 2026 for exaggeration and lack of substantiation, an app ad upheld in June 2026 where Google's automated tools generated the assets and the advertiser was still held responsible, an ad in July 2025 for an app that dropped users into a simulated clip with a celebrity, upheld on social responsibility grounds. In every case the ASA upheld on grounds such as misleadingness, substantiation, unauthorised medical claims or social responsibility. In none of them was the breach a failure to say the content was AI.
Three things stop this from being a story about the UK doing nothing.
First, the UK's teeth are sharper where they do bite. The Digital Markets, Competition and Consumers Act 2024 replaced the old unfair trading regulations from 6 April 2025, and it lets the CMA decide that consumer law has been infringed without going to court, with penalties of up to 10% of global turnover. Section 226 catches information which, although true, is presented in a misleading way, and an overall presentation that is likely to deceive. An unlabelled AI product shot that flatters the product is squarely within that. For this kind of breach the UK ceiling is the higher of the two. It is just triggered by deception rather than by silence.
Second, there is a real technical argument on the other side. Ofcom's Deepfake Defences 2 research in July 2025 found that watermarks can be stripped by something as simple as cropping an image, that C2PA provenance metadata is removable, and that while 85% of respondents said it is important for platforms to label AI content, 59% said they may not trust content with an AI label attached. Ofcom published that as a technical toolkit rather than a policy position, and it does not set AI policy. But it does mean the gap between the two jurisdictions is not simply one of ambition.
Third, the industry filled the gap itself. In February 2026 the Advertising Association published a Best Practice Guide for the Responsible Use of Generative AI in Advertising, with eight principles and a risk-based approach to disclosure. Voluntary, but it tells you where the industry expects the line to settle.
The clearest illustration of the divergence is training data. The EU requires general-purpose AI model providers to publish a sufficiently detailed summary of training content, and has done since August 2025. The UK consulted on a comparable duty, was pressed hard on it in the Lords, and in March 2026 concluded in its Report on Copyright and Artificial Intelligence that "a broad copyright exception with opt-out is no longer the government's preferred way forward", proposing to keep monitoring transparency rules elsewhere and develop best practice rather than legislate.
Why UK teams are caught anyway
Here is the part that makes the comparison academic for most people reading this.
Article 2(1)(c) of the AI Act applies the Regulation to "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union."
The UK is a third country. The test is not where you are, or where the tool is, or where the content was made. It is where the output is used. The Commission's guidelines put it about as plainly as you could want:
"A company established in a third country that uses an AI system to generate a deep fake of a celebrity featured in an advertisement displayed in the Union is also a deployer falling within the scope of the AI Act."
So a London agency producing a campaign that runs in Dublin, Berlin or Madrid is in scope. A UK brand whose EU-facing site serves AI-generated imagery is in scope. A UK team creating assets that a client distributes across EU markets is in scope. The guidance does draw a limit around distribution that is genuinely unforeseeable and outside your control, but if you know your work runs in the EU, you cannot rely on that.
So do you run one standard or two?
Every CMO I have discussed this with lands on the same question, and I think the answer is clear.
Run one standard, built to the EU level.
The reasoning is operational rather than legal. Running two content standards means every asset needs a market decision before it needs a creative decision. It means your DAM has to track jurisdiction per asset. It means someone junior, at speed, on a Friday, has to correctly recall which rules apply to a campaign that has just been extended into a new market. The cost of getting that wrong once is larger than the cost of labelling a handful of assets you did not strictly need to label in the UK.
There is a second argument, which is that the tooling is being built to the EU standard anyway. The providers who signed the Code of Practice are embedding marking upstream. Content will arrive at your desk already marked whether or not the UK ever asks for it.
And a third, which is commercial rather than defensive. Deployer-side signatories to the Code already include Getty Images, Lufthansa and Bulgari. Being able to say clearly what in your marketing is synthetic is turning into a trust position, at exactly the moment when consumers are becoming less able to tell.
The duty nobody mentions, which has applied since February 2025
While everyone was watching Article 50, Article 4 has been in force for eighteen months.
It requires providers and deployers to take measures to support the development of AI literacy among their staff and others operating AI on their behalf, taking account of their knowledge, experience and the context of use. The Digital Omnibus softened the wording in July 2026: it now says "support the development of" rather than "ensure a sufficient level of", and adds that the obligation does not require you to guarantee any specific level of literacy in any individual. There is no direct fine attached to Article 4 under Article 99.
I would not treat the softening as permission to ignore it. Look at what Article 50 actually demands of a marketing team day to day. Someone has to decide whether an asset resembles a real person closely enough to be a deepfake. Someone has to judge whether a review was substantive or superficial. Someone has to know that a platform toggle is not a legal disclosure.
None of that is a policy problem. It is a competence problem, distributed across everyone who touches content. You cannot write it into a document and hope. That is the case for AI literacy as an operational requirement rather than a compliance box, and it is what my AI training work is built around. If you want to know where your team currently sits, the free AI Literacy Check takes about five minutes and gives you a level rather than a vibe.
What to do in the next 30 days
- Inventory the AI in your stack. Every tool that generates or materially alters image, audio, video or text. Include the AI features quietly added to tools you already had, which is where most teams find surprises.
- Ask every vendor two questions. Do you mark outputs machine-readably under Article 50(2), and have you signed the Code of Practice on Transparency of AI-generated Content? Put the answers in writing.
- Run the test across last quarter's output. Take fifty recent assets and apply the deepfake test. You are looking for the ratio, not perfection. If it comes back at 3%, this is a light-touch change. If it comes back at 40%, you have a production problem to solve.
- Decide your label. Adopt the EU icons or design your own, then write down where it goes on each format: first frame for video, corner for static, top of caption for social, start of conversation for chat.
- Fix the sign-off point. Name the person who makes the deepfake call and where in the workflow they make it. Before the asset is finished, not after.
- Start the record. A single field in your DAM or project tool recording what was AI-generated, with which tool, and who approved it. Retrofitting this is miserable.
- Update your agency and creator contracts. The four questions in the agency section above.
- Brief the team properly. Not a policy email. A session where people apply the test to your own work and disagree about the borderline cases, because the borderline cases are where the decisions actually get made.
The EU has decided that people are entitled to know when what they are looking at is not real. Whatever you think of the drafting, that instinct is not going to reverse, and a marketing function that can answer the question cleanly will be in a better position than one that cannot.
Questions people actually ask
Not all of it. Under Article 50(4) you must disclose image, audio or video that constitutes a deepfake, meaning it resembles a real or plausibly real person, object, place or event and could be taken as authentic. An AI-generated abstract background, an invented character or an obvious cartoon is not a deepfake and needs no label. Editing that leaves the content an authentic depiction does not create one either.
Yes, in defined circumstances. Article 2(1)(c) applies the Regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union. A UK agency or brand producing AI content that runs to EU audiences is caught as a deployer. The Commission's guidelines give the example of a third-country company generating a deepfake of a celebrity for an advertisement displayed in the Union.
Marketing teams are almost always deployers: you use an AI system under your own authority. The provider is whoever develops the system and places it on the market, such as your image generator or copy tool. The split matters because the chatbot disclosure duty and the machine-readable marking duty fall on the provider, while labelling deepfakes and AI text on matters of public interest falls on you.
Article 99(4) sets fines of up to 15 million euros or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) applies whichever of the two is lower. Enforcement sits mainly with national market surveillance authorities.
No. As at August 2026 there is no UK statute requiring AI content to be labelled in marketing. The ASA has stated that there is no blanket legal requirement in the UK to disclose the use of AI in ads. The CAP Code is media-neutral, so the usual rules on misleading advertising apply whatever the content was made with, and disclosure is needed only where its absence would mislead.
For a deployer, the disclosure has to be perceivable by a person at first exposure, in a clear and distinguishable manner, without needing any technical tools. Machine-readable marking on its own does not satisfy the deployer duty under Article 50(4). The marking obligation under Article 50(2) sits with the provider of the AI system, not with you.
Do not assume so. A platform toggle applies that platform's policy, not your legal duty, and it may not travel with the asset into email, out-of-home, a landing page or a partner's channel. Treat the platform label as a useful signal and keep your own disclosure on the asset itself.
The marking duty in Article 50(2) does not apply where the AI performs an assistive function for standard editing or does not substantially alter the input data or its meaning. Colour correction, denoising and minor retouching sit comfortably inside that. Replacing a face, generating a new scene or changing what a person appears to say does not.
Only a narrow one, and not for you. Regulation (EU) 2026/1744 gives providers of generative AI systems already on the market before 2 August 2026 until 2 December 2026 to comply with the machine-readable marking duty in Article 50(2). The deployer duties in Article 50(3) and 50(4) applied in full from 2 August 2026.
Both can be deployers. The agency chooses and operates the tools; the client sets the brief, approves the creative and publishes it. The Act does not resolve this for you, so it belongs in the contract: who decides whether an asset is a deepfake, who applies the label, who keeps the record, and who carries the cost if it is wrong.
Sources: Regulation (EU) 2024/1689 (EU AI Act), Articles 2, 4, 50 and 99 · Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026 · European Commission, Guidelines on the transparency obligations under Article 50, C(2026) 5054 final, 20 July 2026 · European Commission, Q&A on transparency obligations under Article 50 · Code of Practice on Transparency of AI-generated Content, 10 June 2026 · European Commission, signatories announcement, 31 July 2026 · EU icons for labelling AI-generated content, 20 July 2026 · European Parliament, EU AI Act overview · ASA/CAP, Disclosure of AI in Advertising, 29 May 2025 · ASA, AI and Deepfakes, 11 June 2026 · DSIT, A pro-innovation approach to AI regulation · Digital Markets, Competition and Consumers Act 2024, Part 4 Chapter 1 · CMA207, Unfair commercial practices guidance · Report on Copyright and Artificial Intelligence, March 2026 · Ofcom, Deepfake Defences 2: The Attribution Toolkit, 11 July 2025 · Advertising Association, Best Practice Guide for the Responsible Use of Generative AI in Advertising, February 2026
Compliance is a policy.
Judgement is a skill.
Article 4 has asked you to build AI literacy since February 2025. Article 50 is where it stops being theoretical. I run practical AI training for marketing and communications teams, in London and internationally.