The AI Act's transparency rules have applied since 2 August 2026, and most of what advertisers brace for is not in them. The machine-readable marking duty sits with whoever built the generative tool. What lands on the advertiser is narrower, and on a normal campaign it is a single instrument: a visible label on a deep fake. Here is the test that decides which assets need one, the icon that goes on them, and the four things a label does not buy you.
Who has to mark AI content, and who has to label it
Article 50 of the AI Act splits its duties between two roles, and almost every argument about AI labelling turns out to be an argument about which role you are in. The provider is the company that puts an AI system on the market. The deployer is anyone who uses one in the course of professional activity. A brand, an in-house studio, a media agency and a freelance retoucher are all deployers. Essentially none of them is ever a provider.
The two roles are handed different instruments. Article 50(2) requires synthetic output to be marked in a machine-readable way, which means watermarks, signed metadata and fingerprints, Google's SynthID being the best-known example. That duty is discharged inside the tool, by the company that shipped it. Article 50(4) requires a visible label on deep fakes, and that one belongs to the deployer.
So a deployer does not apply the invisible watermarks, and cannot. The only exposure on the marking side is destroying what the tool already embedded, which is why metadata handling appears later in this piece as a compliance question rather than as housekeeping.
Keeping those two words apart prevents most of the confusion on this subject. A watermark is machine-readable and somebody else's job. A label is human-readable and yours.
Two dates and one number are worth writing down. The obligations have applied since 2 August 2026. Generative systems that were already on the market by then have until 2 December 2026 to meet the machine-readable marking duty, which is a question to put to a vendor rather than one to solve in a studio. Breaches of Article 50 sit under Article 99(4), at up to €15 million or 3% of worldwide annual turnover, whichever is higher.
The three questions that decide whether an asset needs a label
Three questions, and you stop at the first one that resolves.
1) Did a generative AI feature touch this asset at all? Generative fill, expand and remove count, as do voice synthesis, style transfer, text-to-image and text-to-video. Ordinary sliders, presets and non-generative filters do not. If nothing generative touched it, there is nothing to do and nothing to record.
2) Does the result show a real person, product, place or event, in a way a viewer could reasonably take as authentic? "Real" includes plausibly real. An invented person who reads as a photograph of somebody counts. A sphinx flying over the Eiffel Tower does not, and that is close to the example the Commission's own guidance uses.
3) Did AI change what is true about that subject? A face, a voice, a body, the product itself, or an event that did not happen. If AI only touched context, surroundings, light or cleanup, the answer is no.
Three yeses make a deep fake, and a deep fake needs to carry a label.
One procedural rule is worth borrowing whole. When the second and third questions are genuinely close to the line, treat the asset as a deep fake and put the decision in front of whoever owns quality. Ambiguity resolves upward. A label on something that did not strictly need one costs a corner of the frame; a missing label on something that did is the failure the regulation was written about.
Standard editing, a real difference, and a deep fake: the three buckets
Those questions sort every asset into one of three buckets, and only the third carries a legal duty.
Bucket A is standard editing, and it is deliberately generous. The regulation's own exempt list covers edge completion, pixel filling for an aspect-ratio change, background removal where the background was visible in the original, and colour and contrast work. So extending a brick wall that is already in the photograph is bucket A and needs nothing at all. Inventing a wall that was never there, behind a real person, is bucket C.
Bucket B is where AI made a real difference and nothing real is misrepresented. Invented backgrounds, fantasy imagery, characters who are plainly not people, an AI voice for an openly fictional one. There is no labelling duty here. We still tag these files, because in six months somebody will need to know, but that tag is ours and not a disclosure.
Bucket C is the deep fake: a real or plausibly real person, product, place or event, altered or fabricated so that it could pass as authentic. It is the only bucket the labelling duty reaches, and it is the whole job.
Material generated before 2 August 2026 does not need retroactive labelling. Nobody has to go back through the archive.
The EU AI labelling icon, and which variant to use
The Commission publishes the icon set itself. It is free to use, needs no attribution, and has been user-tested across member states, which is a better starting point than a bespoke badge nobody recognises. Three variants ship: AI GENERATED for work that is fully generated, AI MODIFIED for work with real source material that AI meaningfully changed, and a bare AI mark for use with your own wording or an interactive second layer.
The design rules are short. The capitalised acronym AI is the main visual element and stays in English, including in a Finnish or German version of the same campaign. The letters keep equal vertical dimension and their proportions when the mark is resized. Size and colour may adapt to the layout as long as the mark stays legible and recognisable against its background, which is why the set ships in black, white and both of those at 50% transparency. Download it once, keep it with the brand assets, and do not redraw it.
Where the label goes, and how that changes per medium
Placement is where good intentions usually come apart, because a label that technically exists and is never seen satisfies nothing. Three rules hold across every medium:
- Embedded in the asset, not in the caption. It has to survive resharing, download and screenshotting.
- Top right corner is the reference placement. Keep clear space around it and no other overlay competing with it.
- Perceivable without interaction, hovering or sustained attention, at the latest on first exposure.
After that it depends on what the asset is:
| Medium | What to do |
|---|---|
| Still image | Icon top right, embedded in the file |
| Video | Icon at the start, at intervals through the run, and after every break, because clips and screenshots travel. Where only part of the video is a deep fake, carry the icon across that part |
| Audio only | A short spoken disclaimer in plain language at the beginning, in the content's language or in English |
| Audio with a screen | The spoken disclaimer and the icon on screen |
| Video or image with sound | Icon always. Audio disclosure is supplementary and never a replacement |
| Print, out-of-home, packaging | Icon on the artwork. There is no first-exposure moment to defer to |
| Internal-only material | Disclosure may sit in the interface or the room rather than in the asset, as long as people know before they see it |
Where a platform offers its own "AI-generated" switch, use it and the embedded icon. The switch is a courtesy to the platform, and the icon is the compliance measure.
AI-written text is mostly out of scope
Text is where the rules are widely over-read. AI-written text needs a label only when three things hold at once: it is published, it is intended to inform the public, and it concerns a matter of public interest, which means politics, government, justice, fundamental rights, security, health or the environment.
Marketing copy is not a matter of public interest. Most commercial content is simply out of scope, and no amount of AI in the drafting changes that.
Even in scope there is a clean exemption: text that a person has reviewed and takes editorial responsibility for. The condition is that the person is identifiable and their contact details are published. An organisation that already has a human own every published word satisfies this by working normally.
That exemption is why this page carries a byline and a fact-checker at the footer of it, naming the actual model that drafted it and the person who checked it. It is not decoration.
The diagrams on this page are AI-generated too, drawn as vector code by the same model. Run them through the three questions above and the second one fails immediately: none of the three shows a real person, product, place or event, only a schematic panel of boxes, icons and short text illustrating a rule. No label applies to them either.
What an AI label does not buy you
A label makes AI involvement visible. It does not make the content lawful, and four things sit entirely outside it.
- Likeness. Depicting a real person still needs that person's permission, and their biometric data is personal data under separate rules. A label is not consent.
- Intellectual property. Style, characters, trade dress, music. A label is not a licence.
- Advertising law. A product that performs better on screen than it does in reality is misleading whether or not the frame carries an icon.
- The artistic carve-out, which is not for advertising. Article 50(4) softens disclosure for evidently artistic, creative, satirical or fictional work, and the Commission's guidelines read it strictly. Work that is exclusively informative or commercial is excluded, and where a piece mixes an informative and a creative character, the informative character prevails.
The regulator's own examples of what is not artistic are all advertisements: teleshopping-style product demonstrations, synthetic influencers testing a sponsored product. A photoreal render of a building that has not been built, or a lifestyle shot of a product in a room that does not exist, lands in the same place. Cinematic treatment does not make an advertisement a film. Assume standard labelling for commercial work.
Worked examples
The rows marked (EU) come from the Commission's own lists. The rest apply the same test to ordinary studio work.
| Case | Bucket | Why |
|---|---|---|
| Extending a brick wall already in the shot to fill a wider crop | A | Edge completion and aspect-ratio fill are named standard editing |
| Removing a bin from the background of a product shot | A | The background was visible in the original, and the meaning is unchanged |
| Blurring a bystander's face | A | Named standard editing |
| Colour grading a campaign image with an AI tool | A | Cosmetic, no change of meaning |
| Sphinx flying over the Eiffel Tower (EU) | B | Could not plausibly be real |
| Mice arguing about cheese in a cheese advertisement (EU) | B | Openly fictional, so nobody is deceived |
| A fully AI-generated fantasy landscape for a poster | B | Nothing real is depicted |
| An AI voice for an openly fictional character (EU) | B | No deception about who is speaking |
| A real car shown against an AI-generated background (EU) | B | The product itself is untouched and not misrepresented |
| An AI-generated stock-style photo of an invented "customer" | C | It reads as a photograph of a real person |
| Swapping or substantially reshaping a model's face | C | A named semantic change |
| Cloning a client executive's voice for a campaign | C | Realistic speech in a specific person's voice |
| A synthetic avatar of a chief executive thanking staff (EU) | C | A named deep fake example |
| An AI-generated influencer endorsing a real product (EU) | C | Named, and explicitly not artistic |
| A product image that makes the product look better than reality (EU) | C | A named deep fake example |
| Two real athletes composited into a stadium that is not there (EU) | C | A named deep fake example |
| A photoreal render of an unbuilt building, presented as a photograph | C | A plausibly real place, fabricated so it reads as authentic |
| A riot, a crowd or a news-like scene generated whole | C | A plausible event that reads as authentic |
How we handle it
Provenance and labelling are part of the deliverable here, not paperwork bolted on at the end. In the order it actually happens:
Every asset is classified before it leaves. One of the three buckets, decided on the questions above, recorded against the job. Without that record, "did we label that one?" becomes unanswerable a year later, which is the real failure mode on a busy account rather than anybody deciding to hide something.
Filenames carry the bucket. A file AI generated outright and a file AI meaningfully changed get different tags, always as the last element before the extension, so whoever opens it in six months knows which mark it needs. The filename is not a disclosure and we never present it as one: it is stripped on upload and invisible to your audience. It is a production signal, and the label is the compliance measure.
Metadata survives the whole chain. Exports carry their metadata rather than going out as "copyright only". Content Credentials stay switched on wherever a tool offers them, so a Coalition for Content Provenance and Authenticity (C2PA) signature the tool wrote travels with the file. No metadata cleaner, no stripping step, no "optimise for web" pass that quietly discards it. And the inverse, which matters as much: we do not assert human origin on something AI made.
Bucket C leaves already labelled. We do not deliver an unlabelled deep fake with a note asking you to add the icon.
The delivery message names the assets. Which files are AI-generated or AI-modified, that the label must not be cropped out or replaced downstream, and that metadata has to survive your own publishing chain. On recurring work that belongs in the contract instead of in a message every time, which is what the Code of Practice asks deployers to arrange. It is voluntary, and it is also the only EU-recognised way to demonstrate compliance, so we follow it as written.
And the refusal. Asked to take a label off a deep fake, we will not, and we will say so in writing. It is your exposure as much as ours.
All of that fits how we already make content and creative: human-made, AI-accelerated, and labelled honestly.
This is how we read the rules, not legal advice. We make the technical side work and document it so your compliance people have less to do, and we are not your lawyers. A novel case, and anything involving a real person's likeness, belongs with counsel.
Written by Claude (Opus 5), fact-checked by Niklas Rantanen and Google Gemini