Nine days ago, on 2 August 2026, the EU’s AI content disclosure rules switched on. A lot of marketing teams missed it, because they were told the deadline had moved.
Most of it did move. Article 50 did not. If you publish AI-generated content that reaches anyone in the European Union, you now have disclosure duties enforced by national regulators and backed by fines of up to €15 million or 3% of worldwide annual turnover.
On the same day, California’s AI Transparency Act became operative. Two of the world’s largest regulatory blocs turned on AI content rules within hours of each other, built on opposite philosophies. The EU regulates the method. The US regulates the effect.
This is the reference guide. What has to be labelled, who is legally responsible, exactly how labelling is done at a technical level, which channels are in scope, and what happens if you get it wrong. Every claim is linked to a primary source, and where a claim rests only on secondary reporting, I say so.
One position underpins the whole piece, and it is the same one I set out in The Agentic Marketing Manifesto: the work you can prove is the only work that counts. Disclosure law has now made that a legal standard rather than a preference.
Key facts at a glance
| Question | Short answer |
|---|---|
| Is there an EU law requiring AI labels? | Yes. Article 50 of the EU AI Act, applicable since 2 August 2026. |
| Was it delayed by the Digital Omnibus? | Not in substance. The Omnibus moved the high-risk rules to Dec 2027 and Aug 2028. It touched Article 50 only to give legacy systems until 2 Dec 2026 for machine-readable marking. |
| Is there a US federal AI labelling law? | No. The US regulates AI content through deception law (FTC Act §5), narrow federal statutes, and a state patchwork. |
| Who applies the label? | In the EU, the provider applies invisible machine-readable marking. The deployer, meaning you, applies the visible label. |
| What is the maximum EU fine? | €15,000,000 or 3% of global turnover, whichever is higher. |
| Does AI-assisted blog copy need a label? | Usually no, if it is genuinely human-reviewed with someone holding editorial responsibility. That exemption is narrower than most people assume. |
| Do AI images in ads need a label? | In the EU, only if they qualify as a deepfake. In New York, yes if a synthetic performer appears. |
| How many US states regulate election deepfakes? | 31, per Public Citizen’s tracker as of July 2026. |
Part 1. The European Union
The one distinction that decides everything
Almost every misunderstanding about the AI Act comes from skipping this. The Act splits duties between two roles, and marketers and creators are almost always in the second one.
A provider develops an AI system, or has it developed, and places it on the EU market under its own name or trademark. OpenAI, Google, Anthropic, Midjourney, ElevenLabs, Synthesia.
A deployer uses an AI system under its own authority in a professional context. Your agency. Your in-house content team. You, as a creator, when you are operating commercially.
Two clarifications from the Commission’s FAQ that matter operationally. Individual employees acting under a company’s instructions are not separate deployers, the company is. And a company remains the deployer even where contractors or freelancers operate the system on its behalf and under its control. You cannot push the obligation down to a freelancer by hiring one.
| Provider duty | Deployer duty | |
|---|---|---|
| What you do | Embed invisible, machine-readable marking in every output | Apply a visible or audible label to what you publish |
| Where it lives | Inside the file, as metadata plus watermark | On the surface of the content |
| Who sees it | Machines, detection tools, platforms | Humans |
| Can you outsource it? | It is done for you by the model vendor | No. This one is yours. |
The practical consequence: you cannot rely on your AI tool to comply for you. The Commission states plainly that deployers cannot simply rely on the machine-readable marking embedded by the provider to satisfy their own disclosure obligation. The tool handles the machine layer. The human-visible label is your legal obligation and no vendor can discharge it on your behalf.
The five transparency duties in Article 50
Article 50 creates four substantive obligations plus a fifth governing how they are delivered. Only two normally touch content marketing, but agencies increasingly deploy all of these systems.
Article 50(1). Chatbot disclosure (provider duty). People must be told they are interacting with an AI system from the start of the first interaction, in a clear and distinguishable manner, unless it is obvious to a reasonably well-informed, circumspect and observant person. The Commission says this exception should be read restrictively. This covers your website assistant, your AI SDR, your support bot, your conversational booking widget. If you are unsure whether what you have deployed even counts as an AI system for this purpose, the definitional boundaries are worked through in What Is an AI Agent? Anthropic, OpenAI, and LangChain, Compared.
Article 50(2). Machine-readable marking of synthetic output (provider duty). Providers of generative systems must mark synthetic audio, image, video and text so it is machine-detectable. Solutions must be effective, interoperable, robust and reliable as far as technically feasible.
Article 50(3). Emotion recognition and biometric categorisation (deployer duty). If you run emotion detection on webcam footage in a research study, or biometric categorisation in a retail environment, you must inform the people exposed to it, whether the system runs in real time or after the fact. Rare in content marketing, common in adtech and CX research.
Article 50(4). Deepfakes and public-interest text (deployer duty). This is the one that changes how content teams work. Two triggers: you must disclose deepfakes at the latest at the point of first exposure, and you must disclose AI-generated or AI-manipulated text published to inform the public on matters of public interest, unless the text went through human review or editorial control with someone taking editorial responsibility.
Article 50(5). The information under the preceding paragraphs must be provided clearly and distinguishably, at the latest at first exposure, and in line with accessibility requirements. The Code of Practice covers 50(2), (4) and (5) together.
What actually counts as a deepfake
The Commission’s guidance sets three cumulative criteria. All three must be met.
- Resemblance. A high level of similarity between the content and the person, object, place, entity or event it depicts.
- Existence. What it resembles exists, can plausibly exist, or could plausibly have existed.
- False appearance of authenticity. It would falsely appear to a person to be authentic or truthful.
The third criterion is contextual, and this is where the guidance is more forgiving than most summaries suggest. The Commission says you may take into account the level of resemblance, the substantive message, the intended and foreseeable deployment context, and the composition and expectations of the intended audience. If the audience in that context does not expect the content to be authentic, it may not falsely appear to be so.
| Asset | Deepfake? | Why |
|---|---|---|
| AI-generated photorealistic “customer” in a testimonial video | Yes | Resembles a real-seeming person and is presented as authentic |
| AI voice clone of your CEO reading a script | Yes | Resembles an existing person, appears authentic |
| AI product shot of your real product in a real-looking studio | Likely yes | Depicts an existing object in a scene a viewer would read as a photograph |
| Obviously stylised 3D illustration on your blog | No | Fails the false-authenticity test |
| AI-upscaled version of a photo you actually shot | No | Assistive standard editing, not synthetic generation |
| AI-generated abstract background gradient | No | Resembles nothing that exists |
| AI-generated background scene or b-roll with no identifiable people | Context-dependent | The Commission indicates background scenes and special effects in standard production are unlikely to falsely appear authentic. Judge it on audience expectation. |
The working rule I give teams: if a reasonable viewer in that specific placement could mistake it for a photograph or recording of something that happened, label it.
What counts as public-interest text
Three cumulative criteria again. The text must be published, must inform the public, and must concern a matter of public interest. The Commission’s list is broad: politics and democratic processes, public administration and services, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, and economic, financial, political, scientific or cultural developments that may be a relevant subject of public debate.
That last cluster is where content marketers get caught. A B2B article on AI adoption in healthcare, an ESG explainer, a data privacy piece, a market outlook report. Those are arguably economic, scientific or public-health matters.
Here is the exemption that saves most content operations. Published text that has undergone human review or editorial control does not need to be labelled. The Commission defines all three terms tightly:
- Human review means deliberate examination of the substance by one or more natural persons with relevant knowledge and professional judgement on the subject matter.
- Editorial control means authority exercised in practice by a responsible editorial entity to approve, alter or reject the substance on substantive grounds, including fact-checking and assessing source trustworthiness.
- Editorial responsibility means a person holds ultimate legal responsibility over the publication.
- Superficial, purely formal or procedural checks such as spell-checking or grammar correction are explicitly not enough.
So a draft that a named subject-matter editor read, fact-checked, changed and signed off is exempt. A draft that someone skimmed and pushed live is not. If you cannot produce evidence of the review, you do not have the exemption. That evidence requirement is why I now treat editorial logging as a compliance control rather than a nice-to-have, and it is why the systems argument in Agentic Content Strategy: Building Systems, Not Just Assets now has a legal edge to it.
There is a second implication worth naming. The Commission’s definition of human review draws the line at substantive examination by someone with relevant subject-matter judgement, which is exactly the difference between using a model as a collaborator and using it as a typist. I argued that distinction on craft grounds in Using LLMs as Creative Collaborators, Not Just Typists. It now also determines whether you owe a label.
Run every recurring asset type through this once, then encode the answer in your templates.
How disclosure is actually done: the two-layer model
This is the part almost every article skips, so here it is in full.
The Code of Practice on Transparency of AI-generated Content, published on 10 June 2026, is the Commission’s officially blessed route to compliance. It has been assessed as adequate by both the Commission and the AI Board. Roughly 190 organisations had signed by the end of July 2026, ahead of the initial-signatory deadline of 27 July.
Layer 1. Machine-readable marking, the provider’s job
The Code proceeds from the premise that no single marking technique can meet all four Article 50(2) requirements at once, so it requires a multi-layered approach with at least two layers in most cases.
| Technique | What it is | Notes |
|---|---|---|
| Imperceptible watermarking Baseline layer | Statistical signal embedded in pixels, audio waveform or token choices | Required for all AI-generated or manipulated content, including free-form text over 200 tokens. Very short text under 200 tokens is exempt. Must survive compression, cropping, scaling and format conversion. |
| Digitally signed metadata Second layer | Signed, time-stamped, tamper-evident provenance record inside the file | Required as a second layer for formats that support metadata: audio, image, video, containerised text. Providers are encouraged to use open frameworks such as C2PA. |
| Fingerprinting or logging Optional | Hash of the content stored in a registry for later lookup | May supplement the two baseline techniques. Cannot replace them. |
Three specifics worth knowing:
- Providers must make a detection solution available free of charge, with downloadable signed results. Providers with fewer than one million monthly users may charge a limited fee in high-cost cases, and for text watermarks detection may be restricted to verified expert users.
- Providers must implement a watermark-detection interoperability solution by 2 February 2027. The options are a standardised API that routes detection queries, a publicly readable signpost embedded in the content, or participation in a shared consortium solution.
- Signatories must preserve existing markings and must not offer circumvention tools. Apply the same rule inside your own production workflow.
Why C2PA keeps winning. A C2PA manifest is a container of signed assertions covering when content was created, what tool made it, what edits were applied, and whether generative AI contributed. Assertions are hashed and signed with X.509 credentials, so tampering breaks verification. Because most social platforms strip metadata on upload, C2PA also defines soft bindings, meaning invisible watermarks or perceptual fingerprints that let a stripped file be matched back to its cloud-stored credential. That combination is what the spec calls Durable Content Credentials, and it maps closely onto what the Code asks for.
Layer 2. The visible label, your job
Machine-readable marking is invisible. It does nothing for a human scrolling a feed. That is why Article 50(4) requires deployers to apply a label people can actually perceive, understandable without any specific technical tools or dedicated actions.
The Commission published a free set of EU icons on 10 June 2026, in SVG and PNG, in four variants each: black, white, black at 50% transparency and white at 50% transparency. No attribution is required.
| Icon | Use it when |
|---|---|
| Basic icon | AI was involved in producing a deepfake or published text, or you are pairing it with your own custom label text |
| Fully AI-generated | The entire deepfake or text was AI-generated with no human-created elements |
| Partially AI-modified | Pre-existing human content was partially altered with AI |
Using the EU icons is optional. Labelling is not. And the Commission is explicit that using the icons does not establish legal compliance by itself. Deployers remain responsible for ensuring the disclosure meets Article 50. User testing showed performance improved across all measures when the basic icon was paired with accompanying text, so use icon plus words.
Placement rules by format
| Format | Where the label goes |
|---|---|
| Video | At the start, repeated at regular intervals, visible long enough to be read |
| Text | Above the content, or within the opening section |
| Image | Embedded directly into the asset, clearly perceivable at first exposure |
| Audio only | Audible spoken disclaimer at the beginning |
| Artistic, creative, satirical or fictional work | Disclosure still required, but in a manner that does not hamper display or enjoyment of the work. Credits or a hover layer are acceptable. |
Three rules that catch people out:
- The label must be perceivable without user interaction. A disclosure behind a “read more” toggle or buried in a footer does not comply.
- The label must survive resharing and downloading. If your label is a platform-side overlay rather than burned into the asset, it disappears the moment someone saves and re-uploads.
- Machine-readable marking does not substitute for the visible label. Separate obligations, separate parties.
Exemptions, in plain language
| Exemption | Scope |
|---|---|
| Assistive standard editing | AI that does not substantially alter the input data or its semantics: colour correction, denoising, upscaling, background cleanup |
| Obvious AI | Chatbot disclosure not required where it is obvious to a reasonably well-informed person. Read restrictively. |
| Human editorial review | Public-interest text is exempt where a qualified person examined the substance and someone holds editorial responsibility |
| Artistic, creative, satirical, fictional works | Deepfake disclosure still required, placement may be non-obtrusive |
| Out of scope entirely | Short sequences of numbers, symbols or letters. Source code. Machine-to-machine output never exposed to humans. Closed-loop industrial and product development environments, unless it is the final output. |
| Narrow B2B and industrial carve-out | A limited exemption from the Art. 50(2) marking duty for outputs used in business-to-business or industrial contexts, subject to conditions in the Guidelines |
| Content generated before 2 Aug 2026 | No retroactive labelling required, though the Commission encourages it |
The EU compliance calendar
| Date | What happens |
|---|---|
| 1 Aug 2024 | AI Act entered into force |
| 2 Aug 2025 | GPAI model obligations applied |
| 10 Jun 2026 | Code of Practice on Transparency published, alongside the EU icon set |
| 20 Jul 2026 | Final Commission Guidelines on Transparency of AI-Generated Content published, replacing the draft |
| 27 Jul 2026 | AI Omnibus, Regulation (EU) 2026/1744, enters into force |
| 2 Aug 2026 | Article 50 applies. Deployer duties live. Enforcement powers live. |
| 2 Dec 2026 | Grace period ends. Generative systems placed on the market before 2 Aug 2026 must meet Art. 50(2) marking duties. |
| 2 Feb 2027 | Code signatories must have watermark-detection interoperability solutions in place |
| 2 Dec 2027 | Annex III high-risk obligations, postponed by the Omnibus |
| 2 Aug 2028 | Annex I embedded high-risk obligations, postponed |
The Digital Omnibus reached provisional political agreement on 7 May 2026, was approved by the Council on 29 June, published in the Official Journal on 24 July and entered into force on 27 July. It postponed the high-risk classification regime, which was the hardest part to operationalise. It amended Article 50 only to add the four-month grace period for legacy systems, and it added a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and CSAM. Compliance teams that anchored their whole programme to “2 August 2026” and then moved everything when the high-risk deadlines shifted have accidentally abandoned the obligation that actually came due.
Penalties and who enforces
Breaching Article 50 exposes you to fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. The Act instructs authorities to apply proportionality for SMEs and small mid-caps, but the ceiling is real.
Penalties sit in Article 99. Article 50 breaches fall in the mid tier. For context, the top tier for prohibited practices under Article 5 is €35 million or 7%, and the bottom tier, for supplying incorrect or misleading information to authorities, is €7.5 million or 1%.
Enforcement sits mainly with national market surveillance authorities in each member state, not with the Commission. The AI Office has narrow competence, limited to AI systems built on general-purpose AI models where the same entity provides both, or where the system is integrated into a VLOP or VLOSE designated under the DSA. The European Data Protection Supervisor covers EU institutions.
Practical consequence: a pan-European campaign can be challenged by any one of 27 regulators, each with its own enforcement appetite.
Should you sign the Code of Practice?
Signing is voluntary but strategically loaded. Signatories may rely on the Code to demonstrate compliance with Article 50(2), (4) and (5), regardless of where they are established or which authority supervises them, and the Commission has said enforcement for signatories will focus on monitoring adherence to the Code. Non-signatories must demonstrate compliance through alternative adequate means and may face more requests for information.
Signature is open to any provider or deployer of a generative AI system regardless of establishment, which is why non-EU companies signed. The initial signatory list was published before 2 August 2026 and organisations can still join.
Beyond the AI Act: the other EU rules that bite
Political advertising. Regulation (EU) 2024/900 entered full application on 10 October 2025. Political ads must be clearly labelled and must disclose who paid, how much, and which targeting was used, online and offline. Stacked on Article 50, an AI-generated political ad carries two independent labelling duties.
Unfair commercial practices. There is no EU-wide law specifically on AI-retouched marketing imagery. But the Unfair Commercial Practices Directive catches misleading practices generally, and a synthetic image presented as a real product photo or a real customer is a misleading practice whether or not the AI Act applies.
Digital Services Act. Very large platforms carry systemic-risk duties around manipulated media, and the Code of Conduct on Disinformation operates as a DSA co-regulatory instrument. This shapes what platforms make you do, which is often stricter and faster-moving than the law.
National law. This is where it gets uneven, and where a lot of published coverage is wrong.
| Country | Rule | Status | Who it hits |
|---|---|---|---|
| France | Law 2023-451: influencer content with AI-generated faces or bodies must carry “Images virtuelles”. Retouched silhouettes or faces must carry “Images retouchées”. Labels must be clear, legible and identifiable across all formats. | In force since 2023 | Creators and influencers. Breach: up to 1 year and €4,500. Failure to disclose commercial intent at all: up to 2 years and €300,000. |
| Italy | Law 132/2025 creates Art. 612-quater of the Criminal Code: unlawful dissemination of AI-generated or altered content that misleads about authenticity and causes unjust harm. | In force 10 Oct 2025 | Anyone. 1 to 5 years imprisonment. Prosecuted on complaint. |
| Italy | AGCOM influencer guidelines: creators with 500,000+ followers must mark paid collaborations and disclose use of filters and digital alterations. | In force July 2025 | Large creators |
| Denmark | Copyright Act amendment creating a neighbouring right over personal characteristics, appearance and voice, against realistic digital imitation without consent. Protection runs 50 years post-mortem. Caricature, satire, parody and pastiche excluded. | Not yet in force. Entry into force was expected 31 Mar 2026, then delayed around a snap general election. As of the most recent public reporting the draft had not received final parliamentary adoption. | Anyone using someone’s likeness or voice, once adopted |
| Spain | Draft Organic Law on the proper use and governance of AI, adding national penalties for failure to label AI-generated content, with a top tier reported at €35M or 7% turnover. | Still a bill. Approved by the Council of Ministers, in Parliament. | Providers and deployers, once passed |
A great deal of reporting describes Spain’s €35 million fines as current law. They are not. And a great deal of reporting describes Denmark’s likeness right as in force. As far as I can verify, it is not. What binds you in both countries today is the AI Act itself, directly applicable, with the €15M or 3% ceiling. If you find primary-source evidence that either has since been adopted, tell me and I will update this within a day.
Part 2. The United States
There is no federal AI labelling law. That is the headline.
Nothing in US federal law says you must label AI-generated marketing content. The United States regulates the effect, meaning deception, rather than the method. Three federal instruments matter, plus a preemption fight that could reshape everything.
1. FTC Act Section 5, the general deception standard
The FTC’s position is that existing law already covers AI-driven deception. Its Operation AI Comply sweep, launched September 2024, targeted deceptive AI claims and AI-enabled schemes.
For marketers the operative principle is simple. If a synthetic asset creates a false material impression, that a real customer endorsed you, that a real person said something, that a photo depicts a real result, that is deception, label or no label.
2. The Consumer Reviews and Testimonials Rule (16 CFR Part 465)
Effective 21 October 2024. This is the most directly relevant federal rule for content and affiliate marketing. It bans fake and false consumer reviews, consumer testimonials and celebrity testimonials, including AI-generated ones.
The FTC’s own guidance is important for nuance. There is no blanket prohibition on AI-generated avatars in marketing and no general AI disclosure requirement. What is prohibited is misrepresentation, meaning an AI avatar deployed so that consumers reasonably believe a real person or celebrity endorsed the product. A clearly branded synthetic presenter is fine. A synthetic “verified customer” is not.
3. The TAKE IT DOWN Act
FTC enforcement of Section 3 began on 19 May 2026. Covered platforms must provide a clear, plain-language removal process and, on a valid request, remove non-consensual intimate imagery and make reasonable efforts to find and remove known identical copies within 48 hours. The Act expressly covers digital forgeries, meaning intimate images digitally created or altered using software, an app, or artificial intelligence.
Civil penalty exposure is $53,088 per violation. The FTC issued warning letters to major platforms ahead of the deadline.
Coverage is broad: websites, apps, social media, messaging, image and video sharing, and gaming services, plus anything that primarily provides a forum for user-generated content. Nonprofits are not excluded. Email and broadband providers are expressly exempted. This is a platform obligation rather than a marketer obligation, but if you operate a community, a UGC feature or a client portal that accepts uploads, you may be a covered platform.
4. The preemption fight, and the deadlines nobody met
On 11 December 2025 the President signed Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence. It directed the Attorney General to establish a DOJ AI Litigation Task Force within 30 days to challenge state AI laws, largely on Dormant Commerce Clause, preemption and First Amendment grounds. The Task Force was established on 9 January 2026. It also conditioned BEAD broadband funding, roughly $42 billion allocated, on states rolling back AI rules the administration deems onerous, and it directed the FCC to consider a federal AI reporting and disclosure standard that would preempt conflicting state law.
Two weeks after the EO, on 22 December 2025, the FTC reopened and set aside its own 2024 consent order against Rytr, an AI review-generation tool. The Commission concluded the complaint failed to satisfy the FTC Act and that the order unduly burdened AI innovation. Bureau of Consumer Protection Director Christopher Mufarrige framed the reasoning as a rejection of condemning a technology because of how it could potentially be misused.
Then the enforcement machine stalled and moved at the same time.
| Deadline | What was required | What happened |
|---|---|---|
| 10 Jan 2026 | DOJ establishes AI Litigation Task Force | Done. Established 9 January 2026 by internal memorandum. |
| 11 Mar 2026 | Commerce publishes evaluation identifying “onerous” state AI laws for referral | Missed. Not publicly released as of the most recent reporting I could verify. |
| 11 Mar 2026 | Commerce issues BEAD Policy Notice conditioning funding | Missed. |
| 11 Mar 2026 | FTC issues policy statement on FTC Act preemption of state laws requiring alterations to truthful AI outputs | Missed. No statement issued as of the most recent reporting I could verify. |
| April 2026 | Not scheduled | The first real move. xAI sued Colorado on 9 April. DOJ intervened on xAI’s side roughly two weeks later, the first time the federal government sought to invalidate a state AI law in court. On 27 April a federal magistrate stayed enforcement. |
What this means for you. State AI laws remain enforceable today, with the notable exception of Colorado, where enforcement is stayed by court order. The US direction of travel is deregulatory and contested. The EU direction is prescriptive and settled. If you build one compliance system, build it to the EU standard. It is the higher bar and it is the one that is not about to be litigated away.
US state laws, in three tables
Table A. Election and political deepfake laws
Public Citizen’s tracking showed 31 states with enacted election deepfake laws as of July 2026. “Disclaimer” means the law requires a label. “Ban” means it prohibits the content outright.
| State | Type | Instrument | Enacted |
|---|---|---|---|
| Alabama | Ban | — | May 2024 |
| Arizona | Ban | HB 2394; SB 1359 | May 2024 |
| California | Disclaimer | AB 730, AB 972, AB 2355, AB 2839, AB 2655 | 2019–2024 |
| Colorado | Disclaimer | HB 1147 | May 2024 |
| Delaware | Disclaimer | HB 316 HS 1 | Oct 2024 |
| Idaho | Ban | HB 664 | Mar 2024 |
| Indiana | Disclaimer | HB 1133 | Mar 2024 |
| Kentucky | Disclaimer | SB 4 / HB 672 | Mar 2025 |
| Louisiana | Disclaimer | HB 459 | Jun 2026 |
| Maine | Disclaimer | LD 517 | 2026 |
| Maryland | Disclaimer | SB 141 | May 2026, effective 1 Jun 2026 |
| Michigan | Disclaimer | HB 5144 | Nov 2023 |
| Minnesota | Disclaimer | HF 1370; HF 4772 | 2023–2024 |
| Mississippi | Disclaimer | SB 2577 | Apr 2024 |
| Montana | Disclaimer | SB 25 | May 2025 |
| Nevada | Disclaimer | AB 73 | Jun 2025 |
| New Hampshire | Disclaimer | HB 1432; HB 1596 | 2024 |
| New Mexico | Disclaimer | HB 182 | Mar 2024 |
| New York | Mixed | Budget provision; S 9678 | 2024 |
| North Dakota | Disclaimer | HB 1167 | Apr 2025 |
| Oregon | Disclaimer | SB 1571 | Mar 2024 |
| Pennsylvania | Disclaimer | SB 649 | Jul 2025 |
| Rhode Island | Disclaimer | S 816; HB 5872 | Jul 2025 |
| South Dakota | Disclaimer | SB 164 | Mar 2025 |
| Tennessee | Disclaimer | SB 1624 / HB 1513 | 2026 |
| Texas | Ban | SB 751 | Jun 2019 |
| Utah | Disclaimer | SB 131 | Mar 2024 |
| Vermont | Disclaimer | S 23 | 2026 |
| Washington | Disclaimer | SB 5152 | May 2023 |
| Wisconsin | Disclaimer | AB 664 | Mar 2024 |
Compiled from Public Citizen’s tracker, last updated 3 August 2026. The tracker is the live source of truth and moves faster than any article. Verify individual entries before relying on them for a specific campaign.
Three design details worth noting. Colorado and Washington require the disclosure in the content’s metadata, not only as a visible or audible disclaimer, a US requirement that mirrors the EU’s machine-readable layer. Minnesota and Texas prohibit distribution within a defined window before an election rather than merely requiring a label, and Maryland bans them year-round. And two laws have been struck down on First Amendment and Section 230 grounds: California’s AB 2839 was permanently enjoined in August 2025 and Hawaii’s Act 191 followed in January 2026. Broad prohibition models have fared worse in court than disclosure requirements.
Table B. Chatbot and conversational AI disclosure
| State | Instrument | Effective | Requirement | Enforcement |
|---|---|---|---|---|
| California | SB 1001 | 2019 | Clear and conspicuous disclosure where a bot is used with intent to mislead about its artificial identity in a commercial transaction | — |
| California | SB 243, companion chatbots | 1 Jan 2026 | Disclose non-human status to known minors, repeat every three hours with a break reminder, crisis protocols | — |
| New York | GBL Article 47 | 5 Nov 2025 | Clear and conspicuous notice that the user is not speaking with a human, self-harm detection and referral | — |
| Maine | Title 10 §1500-DD | 23 Sep 2025 | Proactive clear and conspicuous disclosure across any trade or commerce where a bot may mislead | No proof of actual harm required |
| New Jersey | Title 56 §56-18-2 | — | Proactive disclosure at start of interaction, limited to sale or advertising of merchandise or real estate | — |
| Utah | AI Policy Act, as amended by SB 226 / SB 332 | 7 May 2025 | Disclose on clear request in consumer transactions, proactively for high-risk interactions and regulated occupations | $2,500 per violation |
| Tennessee | SB 1580 | 1 Jul 2026 | Bots may not present as licensed mental health professionals | — |
| Washington | HB 2225, Chatbot Disclosure Act | 1 Jan 2027 | Session-start disclosure plus reminders every three hours, hourly for minors, outputs must not contradict the disclosure, minor safety protocols | Primarily attorney general |
| Oregon | SB 1546 | 1 Jan 2027 | Disclose AI involvement, automated suicide and self-harm detection with crisis referral, annual filings | Private right of action, $1,000 statutory damages per violation |
| Nebraska | LB 525, Conversational AI Safety Act | 1 Jul 2027 | Disclosure, crisis-response protocols, prohibition on claiming to provide professional mental healthcare | Attorney general |
| Idaho | S 1297, Conversational AI Safety Act | 1 Jul 2027 | Near-identical to the Nebraska model | Attorney general, no private right of action |
| Iowa | SF 2417 | 1 Jul 2027 | Disclosure with the option of a persistent disclaimer | — |
Two design patterns to understand. The Utah model is the most business-friendly and other states are copying it: no proactive disclosure for ordinary consumer interactions, but you must answer honestly if someone asks whether they are talking to a human. Proactive disclosure kicks in only for high-risk interactions, meaning those collecting sensitive financial, health or biometric data and producing personalised recommendations someone might rely on for a significant decision. The Oregon model is the expensive one, because a private right of action with statutory damages turns a compliance gap into class-action exposure without any regulator needing to act.
Table C. Commercial content, advertising and provenance
This is the cluster that most directly governs marketing output.
| State | Instrument | Effective | What it requires | Penalty |
|---|---|---|---|---|
| California | AI Transparency Act, SB 942 as amended by AB 853 | 2 Aug 2026 | GenAI providers with over 1M monthly visitors or users, publicly accessible in California, must offer a user-selectable manifest disclosure and embed latent disclosure metadata in AI-generated image, video and audio, plus a free public detection tool | $5,000 per violation, per day. AG, city attorney or county counsel. No private right of action. Fees to prevailing plaintiff. |
| California | AB 853 platform tier | 1 Jan 2027 | Large online platforms must detect and display provenance data and may not knowingly strip it. Hosting platforms may not offer non-compliant systems. | as above |
| California | AB 853 device tier | 1 Jan 2028 | Capture device manufacturers must offer and default-enable latent disclosures | as above |
| California | AB 2013 | 1 Jan 2026 | GenAI developers must publicly disclose training dataset information | — |
| New York | S.8420-A / A.8887-B → GBL §396-b | 9 Jun 2026 | Conspicuous disclosure when a “synthetic performer” appears in an advertisement, where the person producing or creating it has actual knowledge. Carve-outs: audio-only ads and AI used solely to translate a real performer’s language. | $1,000 first violation, $5,000 subsequent |
| Texas | TRAIGA, HB 149 | 1 Jan 2026 | Disclosure and consent duties with sector-specific requirements, intent-based liability standard | — |
| Colorado | SB 24-205 | 30 Jun 2026, enforcement stayed | Reasonable care against algorithmic discrimination in high-risk systems, plus disclosure duties | Not currently enforced |
| Colorado | SB 26-189, Automated Decision-Making Technology Act | 1 Jan 2027 | Repeals and reenacts SB 24-205 with a narrower notice-based approach | — |
| Utah | SB 149 | 1 May 2024 | Consumer-facing GenAI disclosure for regulated occupations | $2,500 per violation |
A lot of compliance content still lists Colorado’s AI Act as taking effect on 30 June 2026 with live obligations. Here is the actual sequence. xAI filed suit on 9 April 2026 challenging SB 24-205 on First Amendment, Dormant Commerce Clause, equal protection and vagueness grounds. Roughly two weeks later the DOJ intervened on xAI’s side, the first time the federal government has moved to invalidate a state AI law in court. On 27 April a federal magistrate granted a stipulated order under which the Attorney General will not enforce or investigate under the Act pending resolution. On 14 May Governor Polis signed SB 26-189, repealing and reenacting the framework, effective 1 January 2027. So the old Act is technically on the books during a June to December 2026 interim window, and it is not being enforced.
New York’s synthetic performer law deserves special attention from anyone running video ads. The definition is broader than “AI”: a digital asset created, reproduced or modified by computer, using generative AI or a software algorithm, intended to give the impression of an audio, audiovisual or visual performance by a human performer who is not recognisable as any identifiable natural performer. Traditional VFX can qualify. The duty falls on whoever produces or creates the advertisement, which means advertisers and their agencies. The statute does not define “conspicuous,” so the safe read is on-screen, at the start, legible.
Verified against primary statutes and FTC guidance, August 2026.
EU vs US: the structural difference
| EU | US | |
|---|---|---|
| Legal basis | Dedicated statute, AI Act Art. 50 | Deception law plus sectoral plus state patchwork |
| Trigger | The method. Was it AI-generated? | The effect. Is it deceptive? |
| Who is obliged | Providers and deployers | Mostly providers and platforms, advertisers via deception law |
| Machine-readable marking | Mandatory for providers | Only California, and only for large providers |
| Visible label | Mandatory for deepfakes and public-interest text | Narrow cases only: NY synthetic performers, election ads |
| Extraterritorial | Yes, applies where output is used in the Union | No |
| Max exposure | €15M or 3% global turnover | $5,000/day (CA), $53,088/violation (TIDA) |
| Direction of travel | Settled and tightening | Contested and loosening |
The extraterritoriality point is the one US-based readers underestimate. The Commission is explicit that providers established outside the EU are subject to the Act where the output of their AI system is used in the Union. A US agency running a campaign that reaches EU audiences is in scope.
Part 3. How you actually do this
Regulation is one thing. Operations are another. Here is the system.
If you already run agentic workflows in content production, most of this is a logging problem rather than a new build. The draft-never-publish and human-at-the-gate rules in Building Your First Marketing Agent produce exactly the audit trail Article 50(4) asks you to produce. That was a quality decision when I wrote it. It is now a compliance control.
The three-layer disclosure stack. Most teams build layer one by accident and skip layers two and three entirely.
Channel by channel: what to do where
| Channel | EU AI Act position | What to ship |
|---|---|---|
| Blog and long-form | Text exempt if genuinely human-reviewed. Images labelled if deepfake-like. | Editorial review log per post. Label photorealistic AI visuals. Add an AI-use statement near the byline. |
| Newsletter and email | Same as blog | Same as blog. A footer AI-use note is good practice but does not satisfy a deepfake label. |
| Social posts | Deepfake images and video need a label | Burn the label into the creative. Platform-side overlays vanish on reshare. |
| Short-form video | Deepfake rules apply | On-screen label at the start and at intervals, plus the platform’s native AI toggle. |
| AI voiceover and podcast | Voice clone of a real person is a deepfake | Spoken disclaimer at the start. Note in the show description. |
| Synthetic presenter video | Deepfake | On-screen label throughout. In New York this is separately mandatory as a synthetic performer disclosure. |
| Paid social and display | Deepfake rules apply. NY law applies to synthetic performers. | Label inside the creative asset itself, because ad platforms crop and re-render. |
| Website chatbot and AI SDR | Art. 50(1) | Disclosure in the opening message, before the first user input. |
| Case studies and testimonials | FTC Reviews Rule, UCPD | Never synthesise a customer. This is the highest-risk asset class in marketing. |
| Political and issue advocacy | AI Act plus Reg. 2024/900 plus 31 US states | Two or three stacked disclosures. Check the specific state before running. |
One row in that table deserves more than a row. Synthesising a customer testimonial is the single highest-risk thing a marketing team can do with generative AI right now, because it is simultaneously an EU deepfake, an FTC Reviews Rule violation, a UCPD misleading practice, and in New York a synthetic performer disclosure failure. Four regimes, one asset. It is also the clearest case of the pattern I have been tracking under agent-washing: presenting machine output as something it is not, and assuming nobody checks.
Platform policies, which move faster than law
| Platform | Requirement | Consequence |
|---|---|---|
| YouTube | Disclose realistic altered or synthetic content that makes a real person appear to say or do something, alters real footage, or depicts a realistic scene that did not occur. Exempt: non-realistic content, beauty filters, colour adjustment, cloning your own voice, AI scripts and thumbnails. | Label applied by YouTube. Repeated non-disclosure can mean removal or suspension. |
| Meta | “AI info” label applied when Meta detects industry-standard AI indicators or when the uploader self-discloses. Minor edits get the label in the post menu rather than on the surface. | Applied automatically |
| TikTok | AI-generated realistic content must be labelled. TikTok reads C2PA Content Credentials to auto-label and attaches them to content made with its own tools. | Auto-labelling. Removal for undisclosed realistic synthetic media. |
| Reads C2PA Content Credentials and surfaces them on images | Informational label |
The critical gap: most platforms strip or ignore metadata on upload, which is exactly why the C2PA spec pairs hard bindings with soft bindings. Do not assume your provenance survives distribution. Assume it does not, and burn the visible label in.
Copy-paste label wording
Pair each of these with the EU icon where you can, and add alt text.
| Situation | Wording |
|---|---|
| Image or video, fully synthetic | AI-generated image / This video was created with AI. |
| Image or video, partially modified | AI-modified image / Parts of this video were altered using AI. |
| Voice, spoken in the first five seconds | This audio was generated using artificial intelligence. |
| Synthetic presenter | The person shown is AI-generated and is not a real individual. This wording also serves New York’s synthetic performer requirement. |
| Public-interest text without human review | This text was generated using AI and has not been subject to human editorial review. |
| Chatbot opener | Hi. You're chatting with an AI assistant, not a human. |
Who is responsible
| Role | Owns |
|---|---|
| Provider (model vendor) | Machine-readable marking, detection tool, interoperability by Feb 2027 |
| Brand or advertiser (deployer) | The visible label. Editorial review records. Final legal liability. Remains the deployer even where freelancers or contractors run the system on its behalf. |
| Agency | Usually a deployer in its own right for work it publishes. In New York, directly exposed on synthetic performer ads it produces or creates. Allocate this explicitly in contract. |
| Individual creator | A deployer when acting commercially or gaining economic benefit on a regular basis. Purely personal use is outside the Act. In France, directly liable under the influencer law. |
| Platform | Detection, auto-labelling, and from Jan 2027 in California, displaying provenance data and not stripping it |
If you take one contractual action from this article: add an AI disclosure clause to your agency and freelancer agreements specifying who applies labels, who keeps the editorial review record, and who indemnifies whom. Almost no MSA written before 2026 addresses this.
Part 4. The honest caveats
I would rather you cite this article because it is accurate than because it is confident. Five things are genuinely unresolved.
- “Human review” has no bright line. The Commission says substantive examination by a qualified person, not spell-checking. Between those poles sits most real editorial work. Until there is enforcement practice, over-document.
- Detection does not reliably work. Watermark detectors produce false positives and false negatives, and consumer-facing detection tools have shown inconsistent results. The law assumes a level of technical reliability the field has not reached, which is why the Code itself concedes no single technique is sufficient.
- Metadata gets destroyed routinely. Screenshots, re-encodes, platform uploads and format conversions strip C2PA manifests. Soft bindings help. They do not solve it.
- The US may look very different in twelve months. The DOJ Task Force, the funding conditions and the FTC’s changed posture all point the same direction, and Colorado shows the mechanism works. State laws are enforceable now, and may not be later.
- Some of the national-law picture is genuinely unsettled. Denmark and Spain are the clearest cases. I have flagged both rather than reporting expectations as law, and I would rather be corrected than confident.
The compliance checklist
Someone has to own this, and in most organisations nobody currently does. It sits between legal, brand and content ops, which means it falls through. That ownership question is part of a larger one I looked at in The Future of the CMO.
Governance
- Decide whether you are a provider, a deployer, or both, for each system you use
- Assign a named owner for AI disclosure
- Add AI disclosure clauses to agency, freelancer and contractor agreements
Inventory
- List every generative AI tool in the content workflow
- For each, confirm whether it applies C2PA credentials and a watermark, and whether it offers a detection tool
- Confirm whether each vendor signed the EU Code of Practice
Content classification
- Run every recurring asset type through the deepfake three-part test
- Identify which of your content is public-interest text
- Stand up an editorial review log recording reviewer, changes and sign-off
Labelling
- Download the EU icon set and add it to your brand asset library
- Write your standard label strings into the brand guidelines
- Update templates so labels are burned into assets, not added at the platform layer
- Check labels survive resharing and download
Channel
- Add a first-message AI disclosure to every chatbot
- Enable native AI-disclosure toggles on YouTube, TikTok and Meta
- Review paid creative for synthetic performers if you run in New York
- Check state-specific rules before any political or issue-advocacy work
Records
- Keep provenance and review records for the life of the campaign plus the limitation period
- Diary 2 December 2026 and 2 February 2027
FAQ
Do I have to label AI-assisted blog posts in the EU?
Usually not. Article 50(4) only covers text published to inform the public on matters of public interest, and there is an exemption where a qualified person substantively reviewed the content and someone holds editorial responsibility. Keep evidence of that review.
Does an AI-generated image in a blog post need a label?
Only if it qualifies as a deepfake, meaning realistic, resembling something that exists, and capable of being mistaken for authentic by that audience in that context. Abstract or obviously stylised illustration does not.
Who applies the label, my AI tool or me?
Both, at different layers. The tool applies invisible machine-readable marking. You apply the human-visible label. The Commission states directly that deployers cannot rely on the provider’s marking to discharge their own duty.
Is a disclosure in the website footer enough?
No. The label must be perceivable at the point of first exposure without user interaction, on the content itself.
Does the EU AI Act apply to a US company?
Yes, where the AI system’s output is used in the Union. A US agency publishing to EU audiences is in scope.
Is there a US federal law requiring AI content labels?
No. Federal exposure comes through FTC deception law, the Consumer Reviews and Testimonials Rule, and the TAKE IT DOWN Act. Labelling mandates are at state level.
What is the maximum fine?
EU: €15 million or 3% of global annual turnover, whichever is higher. California: $5,000 per violation per day. New York synthetic performer: $1,000 then $5,000. TAKE IT DOWN Act: $53,088 per violation.
Do I need to relabel content published before 2 August 2026?
No. There is no retroactive labelling obligation, though the Commission encourages it where possible.
Was Article 50 delayed by the Digital Omnibus?
No. The Omnibus postponed the high-risk regime to December 2027 and August 2028. Article 50 applied from 2 August 2026 as scheduled. The only Article 50 change was a grace period to 2 December 2026 for the marking duty on systems already on the market.
Is the Colorado AI Act in force?
Technically on the books since 30 June 2026, but enforcement is stayed by federal court order in xAI v. Weiser, and it is repealed and replaced by SB 26-189 on 1 January 2027.
Do satire and parody need labels?
Deepfakes in evidently artistic, creative, satirical or fictional works still require disclosure, but placement may be non-obtrusive so it does not spoil the work. Credits or a hover layer, for example.
Sources
EU primary sources
- Article 50, EU AI Act
- European Commission FAQ on Article 50 transparency obligations
- European Commission Guidelines on Transparency of AI-Generated Content
- Code of Practice on Transparency of AI-generated Content
- European Commission, signing the Code of Practice
- European Commission, Code of Practice signatory numbers
- EU icons for labelling AI-generated content
- Quick facts: transparency rules for AI systems
- EPRS, The Danish approach to copyright and deepfakes
- Légifrance, Article 5, LOI n° 2023-451
EU analysis
- Goodwin, EU AI Act transparency obligations now in force
- Gibson Dunn, EU AI Act Omnibus agreement
- Bird & Bird, the final Transparency Code of Practice
- Gleiss Lutz, the new Code of Practice, impact and options
- Wilson Sonsini, EU Commission publishes AI Transparency Code of Practice
- Reed Smith, the Code of Practice adequacy decision and final Guidelines
- Lewis Silkin, the EU’s new AI labelling rules
- Jones Walker, August 2 still matters
US primary sources
- FTC, Complying With the Take It Down Act
- FTC, Take It Down Act enforcement starts now
- FTC, Commission reopens and sets aside Rytr final order
- FTC, Artificial Intelligence enforcement hub
- California Legislature, AB 853
- New York Senate, S8420-A
- Congressional Research Service, the TAKE IT DOWN Act
- Executive Order 14365
US analysis and trackers
- Public Citizen, tracker on state deepfake election legislation
- Morgan Lewis, new California AI disclosure rules become operative
- Cooley, New York enacts synthetic performer disclosure law
- McDermott, New York’s synthetic performer disclosure law
- Orrick, 2026 state chatbot laws
- Mayer Brown, Oregon and Washington companion chatbot laws
- Jenner & Block, DOJ joins xAI in challenging the Colorado AI Act
- McDermott, Colorado AI law in flux
- Crowell & Moring, SB 26-189 repeals and reenacts the Colorado AI Act
- Sidley, unpacking Executive Order 14365
- Paul Hastings, executive order challenging state AI laws
- Proskauer, what EO 14365 means, including the missed deadlines
Technical standards and platforms
Related reading
- The Agentic Marketing Manifesto
- Agentic AI in Marketing: What’s Real, What’s Agent-Washing, and How to Stay in Control
- What Is an AI Agent? Anthropic, OpenAI, and LangChain, Compared
- Agentic Content Strategy: Building Systems, Not Just Assets
- Building Your First Marketing Agent
- Prompt Engineering for Strategic Marketers
- Marketing Automation vs. Agentic Marketing: The Critical Difference
- Using LLMs as Creative Collaborators, Not Just Typists
- The Future of the CMO: Orchestrating Human and Machine Intelligence
Last updated 11 August 2026. Every claim in this article was checked against a primary source or a named law firm analysis on that date. This is not legal advice. AI disclosure law is moving quickly, particularly in the United States. Verify against primary sources before relying on it for a specific campaign, and tell me if you find something I got wrong.
Written by Tanja Gavrilović. Human-researched, human-edited, AI-assisted in drafting.

