Per the European Commission, the transparency obligations of the EU AI Act — Article 50 — apply from August 2, 2026, including to AI systems already on the market. For anyone producing marketing content at scale, this is the date the AI workflow audit stopped being optional. The Commission has published guidelines on the transparency obligations and is developing a Code of Practice on labeling AI-generated content, but the underlying duties are law now.
The four obligations, translated for marketing
- Chatbots and AI interactions must disclose. An AI brand assistant, AI sales agent or customer-service bot must tell users it is AI — relevant to any conversational marketing deployment in the EU.
- Synthetic content must be machine-marked. Providers of AI systems generating image, audio or video must mark outputs in machine readable form — the upstream duty your tools must satisfy.
- Deepfakes must be visibly labeled. Deployers — that is, brands publishing the content — must disclose AI-generated or manipulated depictions of people, objects, places and events in a way perceptible without technical tools. Think an "AI-generated" label in the asset itself, not buried in metadata.
- Emotion recognition and biometric categorization must be disclosed to the people exposed — relevant to some in-store and attention-measurement technologies.
Who carries the duty: deployers, not just vendors
The part most marketing teams miss is the division of labor. Your AI tool's vendor carries the machine-marking duty as provider. But publication duties — the visible deepfake label, the chatbot disclosure — sit with the deployer: the brand and its agencies. Buying compliant tools does not transfer your labeling obligations. Per Commission guidance, exceptions are narrow, essentially clearly artistic, satirical or fictional works where disclosure must still be made without spoiling the work.
This split creates the classic compliance gap in outsourced production. The brand thinks the agency handled it; the agency thinks the tool handled it; the tool's contract disclaims everything except machine marking. When a regulator asks who failed to label a synthetic spokesperson, the answer is the deployer — the entity whose name is on the campaign. Contractual clarity is therefore not legal polish; it is the difference between owning the duty and knowing who owes it to you.
What "visible" labeling means in practice
The deepfake disclosure standard — perceptible without technical tools — sets a design constraint that most creative pipelines were not built for. Metadata and watermarking satisfy the provider-side machine-marking duty, but they do not satisfy the deployer-side visible-label duty. In practice that means the label has to survive the formats marketing actually ships: cropped social cuts, vertical video, display ads with tight safe zones, and audio where a visual label cannot exist at all.
Teams will have to make choices that creatives will resist: where the label sits, how large it is, whether it appears for the full duration or at minimum at first impression. Regulators have not prescribed pixel sizes, and the Commission's guidance leaves room for proportionality — but the direction of travel is unambiguous. A label that a user can plausibly miss is a label a regulator can plausibly challenge. Building label placements into templates and ad specifications now is far cheaper than re-editing a library of live assets later.
Related stories: Google's Shopping Ads Political Content Rules Tighten: Verification Now Required · UK Ad Spend Beat Its Own Forecast: Q1 2026 Up 9.3% to £11.7 Billion.
The compliance gap in most martech stacks
Practically, the exposure concentrates in three places: AI-generated spokespersons and product imagery published without visible labels; AI-voiced audio and video ads; and stock-style generative assets whose provenance nobody documented. With August 2 reached, each of those is now a compliance question in the EU, enforceable under the AI Act's penalty regime, layered on top of the DSA's existing ad transparency duties.
The undocumented-provenance problem is the hardest of the three, because it is backward-looking. Assets generated over the past two years often carry no record of whether a model produced them, which model, or under whose account. Marketing asset libraries were simply not built to log that. The realistic move is not forensic reconstruction of everything ever shipped, but a documented line drawn in the inventory: assets from a cutoff date forward carry provenance fields; assets before it get risk-ranked by type and reviewed selectively. Regulators respond better to a visible system with a defensible boundary than to silence.
Labeling as a market question, not only a legal one
There is a commercial dimension that pure compliance planning misses. Audiences in the EU are already sensitized to synthetic media, and journalists increasingly check whether campaign imagery is AI-generated. A brand that labels cleanly and early controls that story. A brand that gets caught labeling only under regulatory pressure owns a different one. The disclosure obligation, in other words, can be treated as a tax or as a trust signal — the cost is largely framing.
That logic extends to agencies competing for work. Studios and production partners who have already built labeling, provenance logging and vendor assurances into their pipeline are now selling something with a legal floor under it. Procurement teams shopping on price alone will discover the difference when they ask, in a pitch or an audit, who exactly was the deployer of record.
What to do
Inventory every AI-generated or AI-manipulated asset published in the EU this year, add visible labeling to the pipeline — not per-campaign heroics — and get written assurances from tool vendors about machine-readable marking. The teams that built labeling into their production workflow before the deadline are shipping; the rest are retrofitting under enforcement risk.
The uncomfortable summary: the AI Act did not ban synthetic marketing; it made it auditable. What it ended was the quiet version, where nobody had to say how the asset was made.
For more context, read Google's Shopping Ads Political Content Rules Tighten: Verification Now Required.
For more context, read meta dma compliance.
For more context, read aa warc expenditure report.
