On 2 August 2026 a wave of headlines told marketers that from now on they must label everything they create with artificial intelligence as created with AI. That message spread quickly and it isn’t what the EU’s AI Act actually says.
The date is real and it matters, but the AI Act isn’t new legislation that only just landed. The Regulation was adopted back in 2024, and its obligations are being switched on in stages. What arrived on 2 August 2026 is a specific set of transparency rules – those in Article 50 of the regulation – beginning to apply. Actually they’re far more targeted than “label everything.” Most of the AI-assisted work a marketing team does day to day sits outside them.
In this article I aim to help you tell the difference and better understand:
- when an AI-generated asset may actually require disclosure
- what genuinely counts as a “deepfake” and what doesn’t
- why a watermark from your AI tool, invisible to humans, may not be enough on its own
- what the rules mean for chatbots, voicebots, and AI agents in your channels
- which practical checks are worth building into your marketing process
What changed on 2 August 2026?
The AI Act didn’t suddenly switch on this August. It was adopted in 2024, and its requirements apply in phases rather than all at once, which is why different obligations carry different start dates.
💡 What began applying just recently is the set of transparency obligations under Article 50 of the regulation. These are the rules concerned with making it clear, in specific situations, when people are interacting with AI or looking at content that AI generated or manipulated. They’re the part of the Regulation most relevant to marketing and customer communication, which is why they’re the focus here.
Other parts of the AI Act run on their own timelines. For instance, the obligations for high-risk AI systems, for example, apply later. So “the AI Act is now in force” is too broad a statement to act on. What matters for marketers right now is Article 50, and even that applies only in particular cases rather than across the board.
Do you have to label every piece of AI-generated content?
No. Using AI to create an image, a piece of text or another marketing asset does not automatically mean a visible “AI-generated” label is required. Whether disclosure applies depends on the type of content, how it’s used, and whether it could reasonably be perceived as authentic.

That last point is perhaps the most confusing, so it helps to separate two types of content (images, video, and audio, as well as text) that often get lumped together:
- Content generated by or using AI – content created by an AI system from scratch, such as an illustration or a synthetic background or original content modified using AI, for example an edited photo or recording. Generating or using such content by AI system users does not, by itself, trigger a labelling duty, unless it becomes a deepfake.
- Deepfakes – a narrower category: generated or manipulated image, audio or video that resembles a real person, object, place or event in a way that could falsely appear authentic. This is where the absolute disclosure obligation for labelling this kind of visual content actually bites, unless you create this content within the scope of your non-professional activities, with no intention of distribution.
Aside from that, two other cases of disclosure include:
- Machine-readable marking – an invisible technical signal embedded in a file, aimed at systems rather than people. This is the responsibility of the AI tool’s provider, not the marketer using it.
- Human-facing disclosure – a label or notice a person can actually see or hear. This is the kind of disclosure a brand may need to add, and it serves a different purpose from the invisible marking above.
Keeping these apart is essential because the obligations attach to different categories and different parties. Much AI-assisted marketing work is generated or slightly modified content that isn’t pretending to be an authentic depiction of something real and doesn’t require a visible (or audible) AI-generated label at all. The sections that follow work through where the line sits and who’s responsible on each side of it.
Who do the rules target: Provider, deployer or the brand using AI?
Before deciding whether a piece of content needs a label, it helps to know which role you’re playing. Article 50 of the AI Act doesn’t place the same obligations on everyone who touches an AI-generated asset. It distinguishes between the party that makes the AI system available, the party that uses it to produce content, and the layer that simply carries the finished message.
When is a brand a “deployer”?
In broad terms, a deployer is an organisation that uses an AI system under its own authority, for instance, a brand that uses a generative tool to create a campaign visual. That’s the role marketing teams will recognise themselves in.
It’s worth resisting the assumption though that any company touching an AI-generated asset is automatically a deployer in every situation. The role depends on how the AI system is actually used and in what context, as well as what is the AI-generated or modified content used for.
A business that generates and publishes synthetic content is in a very different position from one that simply forwards or displays content someone else produced.
💡 The practical takeaway: identify the specific point in your workflow where an AI system is being used to generate or manipulate content, because that’s where deployer-type responsibilities stemming from the AI Act are most likely to sit.
What if an agency creates the campaign?
Plenty of campaigns are produced externally, which spreads the roles across more than one party. A a setup may look like this:
- a brand commissions the campaign and publishes the result
- an agency operates the AI system to produce the creative
- an AI tool provider supplies the underlying AI system which generates or modifies the content
In a typical setup, three parties are involved in creating AI-assisted content for a brand: the brand itself, the agency, and the provider of the AI tool. It shouldn’t be assumed, however, that each of these parties bears individual responsibility. Ultimately, the content generated or modified by AI is published by the brand. But even so, it shouldn’t be assumed that responsibility rests solely with whoever presses the “publish” button.
Who controls the AI decides who labels
The European Commission’s guidelines on implementing the transparency obligations for certain AI systems contain a good deal of useful direction on who counts as a deployer and, therefore, who the obligations fall on. Much depends on the relationship between the brand and the agency that actually creates the content.
For instance, in interpreting the notion of “exercising control” over an AI system (recall that a deployer is a party using an AI system over which it “exercises control” so if a given party doesn’t exercise control over the AI system that creates the content, it can’t be regarded as a deployer within the meaning of the AI Act, and therefore isn’t subject to the obligation to label deepfake content), the Commission indicates that “control” over an AI system should be understood as taking responsibility for the decision to deploy the system and for the way it is actually used (including the content it generates). This doesn’t necessarily require technical control over how the AI system operates, provided the deployer decides on the purposes and the manner in which the system is used.
So if it’s the brand that decides to use AI systems, or influences which specific system is used or how it’s used, the brand should be regarded as exercising control over that system and as being the deployer.
If, however, the communication between the brand and the agency contains no requirements or guidance regarding the use of AI, and the agency decides on its own to use it, the better view is that the agency is the deployer, and the obligations to appropriately label AI-generated or AI-modified content rest on it.
A similar example appears in the Commission’s guidelines: a company that merely commissions an advertising agency to produce an ad – without making decisions about, or exercising control over, whether and how the agency uses AI in the production process – is not a deployer. There is nothing, however, to prevent the brand from also labelling material created by the agency as AI.
It’s therefore sensible to set the rules for how the agency produces materials deliberately, rather than leaving it to chance. In your internal processes and in the contract with the agency, it’s worth specifying how the agency is to label AI content in order to satisfy the AI Act’s requirements, and establishing a decision-making process around AI – the latter can be pinned down in the creative brief. An absence of provisions on the decision to use AI, or dealing with it only at a very general level, will suggest that the agency is the deployer. The more specifically these matters are regulated, the greater the likelihood that the brand will be the deployer.
Where does your messaging platform sit?
It’s useful to separate three distinct elements:
- an AI system that generates or manipulates the content
- a deployer using that system to create the content
- a technical channel that transmits the AI content to recipients
A communications platform generally belongs to the third layer. Its role is to deliver the message you’ve created across channels, not to generate the creative inside it.
For that reason, the transmission layer shouldn’t automatically be treated as the deployer of the AI system used to produce the content. The obligation to assess and, where needed, disclose sits with the party that actually generated or manipulated the material which usually brings the question back to the brand or its agency, not the pipe the message travels through.

Is an AI-generated image a deepfake? The two-box test
This is the key question here. “Deepfake” has a specific meaning under the EU AI Act, and it’s much narrower than “any image made with AI.” A quick test tells you whether a visual is even in scope of the concept:
- Was the image, audio or video generated or materially manipulated by an AI system?
- Does the content strongly resemble the object being imitated or its characteristic traits?
- Does the content show realistic individuals, objects, or places and events, i.e. such that actually exist or could realistically exist?
- Does the content create a risk that an average recipient mistakes it for an actual recording or an event that actually took place?
If the answer to every question is YES, then you’re dealing with deepfake content, which must be appropriately labelled by the deployer. If any answer is NO, the content isn’t a deepfake, and it’s this group that a large share of everyday marketing materials falls into.

When an AI-generated visual is NOT automatically a deepfake
A lot of AI-assisted creative doesn’t meet the conditions laid out above and therefore isn’t a deepfake at all. For example:
- stylised illustrations
- abstract or clearly artistic creative
- obviously synthetic renders
- artificial hero imagery that isn’t posing as a real photograph
- illustrative product visuals that don’t falsely present themselves as authentic depictions of reality
When it may be a deepfake
The situation changes when content depicts people, objects or events in a photorealistic way, such that it could be taken as an authentic record of reality (this applies both to specific people/places and to fictional figures who look like real people). Cases that may qualify include:
- making a real person appear to say or do something they never did
- cloning a specific person’s voice
- manipulating genuine footage
- fabricating a testimonial attributed to a real person
- depicting a real place or event in a way that falsely appears authentic, for instance, showing something that never actually happened
The common thread is that the material could lead a reasonable viewer to believe it’s an authentic depiction of a real subject. That’s what moves a visual from “generated with AI” into “assess for deepfake disclosure.”
Examples across industries
How this plays out depends on the sector:
- Retail / e-commerce: an AI-generated packshot or a stylised product scene generally won’t be a deepfake – it isn’t creating a false impression that the content showcases a real person or trying to pass off as a fabricated real event.
- Banking / finance: an AI-generated video of a real bank executive saying words they never said is an obvious deepfake, since it depicts an identifiable real person in a way that appears authentic.
- Travel: a photorealistic visualisation of a specific, existing hotel showing a pool or feature that doesn’t exist is a deepfake — the resemblance to the real hotel is obvious, the content depicts something that could readily exist in reality, and it creates a false impression of authenticity and truthfulness,
- Employer branding: a generated, non-existent person used as an illustrative model can most likely be considered a deepfake, although such a person doesn’t physically exist, they look like a real human and create the false impression that this person actually works at the company.
- Customer communications: a photorealistic persona or digital avatar of a consultant (posing as a live human), along with a cloned, realistic voice, falls under the deepfake labelling requirements. If, however, the consultant is clearly presented as a cartoon bot/mascot, that obligation doesn’t arise.
Across all of these, the test introduced earlier is the constant. Run any asset through it before worrying about labels.
If it is a deepfake, what should disclosure look like?
Once content does meet the deepfake criteria, the goal of disclosure is simple: a person should be able to tell that what they’re seeing or hearing was generated or manipulated by AI. How you achieve that can vary by format and context, there isn’t a single label that’s mandatory in every case, but a few principles hold across the board.
Disclosure should be understandable to humans
The point of disclosure is that a real person can recognise and understand it. So it shouldn’t depend only on things people are unlikely to notice such as:
- information buried in terms and conditions or deep within the menu structure
- signals hidden in file metadata
- markers placed outside the creative itself
- anything readable only by automated systems
The aim is for the recipient to grasp the nature of the content at first contact with it – a visible or audible cue tied to the asset, not a note they’d have to go looking for. The disclosure has to be easy to distinguish from other surrounding messaging.
Exactly how that cue looks can depend on the medium so it’s better to think in terms of “would an ordinary viewer notice this?” than to copy one fixed format everywhere.
Disclosure should be made in a clear and distinguishable manner
It must also be easily understandable to the audience, including particular groups such as children or people with disabilities, where they form part of the audience that could foreseeably be exposed to the content or interact with the system.
Disclosure should be made no later than at the moment of the first interaction or first use
The obligation to inform the recipient about a deepfake arises at the point when a person first, in a foreseeable way, comes into contact with the generated content and is able to notice the disclosure.
The deployer can meet this requirement in advance, for example, by placing a notice at the very start of a video. But if there’s a reasonable risk that recipients won’t watch the material from the beginning (for instance, with short reels, live streams, or scrollable content on social media), a disclosure at the outset alone isn’t enough. In such cases, the information should be repeated or maintained throughout the material (for example, as a persistent on-screen marker).
The purpose of the rules, after all, is to ensure real and effective user awareness in a world of increasingly realistic AI content, not merely to formally tick the box in the first second of a recording.
Is an invisible AI watermark enough?
Many AI tools automatically embed an invisible technical marker in the generated file (visible to machines). This marker and the disclosure to the user serve two different functions. The embedded signal is primarily a technical measure sitting with the provider of the AI system, whereas disclosure is information directed at the person consuming the content.

💡 The key message: the fact that a tool added an invisible watermark or AI metadata should not automatically be treated as satisfying every transparency obligation. The two can coexist, but one doesn’t stand in for the other. A marker no one can see doesn’t tell your audience anything.
EU icons for AI-generated content
To make disclosure more consistent, standardised icons have been developed at EU level for signalling AI-generated or manipulated content. They can be a practical way to communicate the nature of a piece of content in a recognisable form across different materials. Learn more about them here.
Two caveats worth keeping in mind here. First, applying an icon isn’t in itself an automatic guarantee of compliance. It’s one component of how you disclose, not a stamp that settles the question. Second, the approach should fit the content and the way it’s presented. An icon that works on a static image may need to be handled differently for audio or video, where a spoken or on-screen cue might be more appropriate.
What about chatbots, text, and other AI content?
Images, as well as audio and visual content, aren’t the whole picture. Article 50 also touches on how you use conversational AI and, in narrower circumstances, AI-generated text, both of which show up across marketing and customer communication.
Chatbots, voicebots, and AI agents
Where an AI system interacts directly with people, users should be informed that they are dealing with AI rather than a human. This obligation rests on the provider of such a system, that is, the party that develops the AI system, or has it developed, and that places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. In customer communication, systems of this kind – chatbots, voicebots and AI agents of all sorts – can appear in a variety of places:
- a chatbot on your website
- an AI support agent inside an app
- automated customer service
- a conversational agent in a messaging channel
- interactions over RCS
- live chat
There’s a sensible limit to this. The disclosure isn’t required where it would already be obvious to a reasonably well-informed, observant and circumspect person in the circumstances that they’re interacting with AI.
💡 The practical read: if there’s any real chance a user would assume they’re talking to a person, make the AI nature clear, ideally at the start of the interaction, where it’s easy to notice. It’s worth vetting AI system providers as to whether their systems meet the information obligations described above, and using only systems that comply with the AI Act’s requirements.
What about AI-written text?
There’s no blanket rule that every piece of text drafted with AI has to be labelled. Using AI to help write:
- a blog post
- a newsletter
- a social post
- an email or SMS
- a product description
does not, on its own, create a labelling obligation.
The obligation to disclose the use of AI applies only to AI-generated or AI-manipulated text published to inform the public on matters of public interest – a situation different from routine marketing content.
For most day-to-day marketing writing, this simply isn’t the provision in play, but it’s worth knowing where the line falls if you publish opinion or informational content on public-interest topics.
What should you do with AI metadata and tool-generated labels?
The basic principle is: “never remove AI markings”, though in particular circumstances it may turn out that this is impossible, or that for other reasons the markings should be modified or removed. The following factors should, however, always be taken into account:
- what markings the tool actually adds
- whether those markings are machine-readable
- whether removing metadata affects the ability to trace the content’s origin
- whether your own situation calls for additional human-facing disclosure on top of whatever the tool embedded
- whether the tool’s own terms impose obligations of their own
💡 The AI Act’s rules and the EU guidelines promote so-called multi-layered protection and prohibit the intentional modification or removal of the technical safeguards added by the AI provider. For that reason, deliberately “cleaning” files of technical metadata before publication creates a direct risk of breaching the transparency requirements. Treat the removal of any technical markers as an exception requiring prior consultation with your legal department.
EU AI Act marketing checklist
A practical way to put all of this into motion, regardless of your sector or which tools you use:
- Inventory your AI tools across marketing, content and customer service, so you know where AI actually enters your workflows.
- Pinpoint where AI generates or materially manipulates image, audio or video and who actually does this – the categories where deepfake questions arise most often.
- Run the four-question test on that content before worrying about labels.
- Don’t assume an invisible watermark satisfies human-facing disclosure – the two serve different purposes.
- Check your chatbot and AI-agent disclosures used by the providers of these systems, so users can tell when they’re interacting with AI.
- Define responsibility and terms of cooperation regarding the use of AI between your brand and any agencies, and if possible, also your AI vendors – ideally in writing.
- Keep documentation of how content is generated, approved and published.
- Escalate ambiguous cases to your legal or compliance team rather than guessing.
Conclusion
The EU AI Act isn’t about a simple “label everything made with AI” rule. The transparency obligations are more targeted than the headlines suggested, and most everyday marketing work sits outside them.
What matters is knowing how to tell the difference, and that comes down to a handful of questions:
- What AI system is being used.
- What type of content it produces.
- Whether that content could reasonably appear authentic.
- Which transparency requirement, if any, applies.
- Who plays which role in the workflow – provider, deployer, content creator or transmission channel.
Work through those in order and most cases resolve quickly, leaving only the genuinely ambiguous ones for a closer look with your legal or compliance team.
As AI becomes part of more customer interactions – from creating content to powering conversational agents – the businesses best placed to adapt are the ones whose communication stays transparent, controlled and consistent across every channel. That’s the real operating principle behind the rules: not less AI, but clearer signals about when and how it’s used. Building that clarity into your processes now means the next phase of the AI Act arrives as a formality rather than a scramble.
This article is provided for general informational purposes and does not constitute legal advice. For more information see the official Article 50 and related documents.
FAQ on the AI Act
No. The fact that an image was generated with AI does not automatically create a visible-labelling obligation. What matters is the nature of the content and whether it could be taken as a deepfake.
As a rule – yes. If a generated figure looks like a real human (is photorealistic), it constitutes a deepfake within the meaning of the AI Act. According to the European Commission’s guidelines, it doesn’t matter that the figure is 100% invented and doesn’t depict a specific, named person. It’s enough that it looks as though it could realistically exist. Such material creates a false impression in the recipient that they’re looking at an authentic photograph or recording of a real person.
Not necessarily. Machine-readable marking and human-facing disclosure do different jobs. An invisible marker aimed at systems doesn’t, on its own, tell a person that content is AI-generated.
Broadly, AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and could falsely appear authentic or truthful.
Not necessarily. There’s no blanket requirement to label text simply because AI helped draft it. Whether any obligation applies depends on the content and the specific Article 50 of the AI Act provision in question.
Not automatically. The roles of AI provider, deployer, content creator and transmission channel need to be assessed separately. The platform that transmits a message is generally distinct from the party that generated the content within it.