The AI Act arrived in stages, which is why a lot of teams stopped paying attention after the first one. The stage that matters for anybody making advertising is Article 50, and it started applying on 2 August 2026.
It is not a high-risk provision. That is the point people miss. Article 50 applies regardless of whether the underlying system is classified as high-risk, which means a marketing team using an off-the-shelf video model is inside it on the same terms as anybody else.
What the obligation actually is
Article 50 imposes transparency duties on providers and deployers across four categories: systems that interact directly with people, systems that generate synthetic content, emotion recognition and biometric categorisation systems, and systems producing deepfakes.
For advertising, two of those matter. Providers of generative systems must mark outputs in a machine-readable way so they are detectable as artificially generated. Deployers producing deepfakes must disclose that the content has been artificially generated or manipulated.
The manner of disclosure is specified: clear and distinguishable, at the latest at the time of first interaction or exposure, and compliant with accessibility requirements. "At first exposure" rules out a disclosure that appears at the end of a thirty-second spot, and rules out a policy page that nobody visits.
The carve-outs, and why they probably do not help you
Two exceptions exist and both are narrower than they look.
- Evidently artistic, creative, satirical or fictional work, where the disclosure obligation is reduced to revealing the existence of generated content in a manner that does not hamper the display or enjoyment of the work. A stylised brand film may plausibly reach this. A creator-format testimonial does not, because the format’s persuasive power depends on it not being read as fiction.
- AI-generated text on matters of public interest that has undergone human editorial review, with a natural or legal person holding editorial responsibility for publication. This is a publishing carve-out. It does not cover video and it does not cover advertising copy.
The December 2026 grace period, precisely
There is a limited transitional arrangement and it is narrower than most summaries suggest. It applies only to AI systems placed on the market before 2 August 2026, and only in respect of the marking and detection obligation in Article 50(2), the machine-readable marking of outputs. Providers of those systems have until 2 December 2026.
That is a provider concession about watermarking infrastructure. It is not a deferral of the deployer disclosure duty, and it does not give an advertiser until December to start labelling deepfake content.
Territorial reach: why UK and US brands are inside it
The Act follows the output rather than the establishment. Where a system’s output is used in the Union, the obligations attach. For advertising that means a campaign served to audiences in EU member states is in scope irrespective of where the brand, the agency or the studio sits.
For most paid social, EU delivery is the default rather than a decision, and geo-excluding the EU to avoid the obligation is usually a worse commercial trade than complying. So the practical planning assumption for a UK or US advertiser running European paid media is that Article 50 applies.
Penalties
Article 99 sets three tiers. Prohibited practices sit at thirty-five million euro or seven per cent of worldwide annual turnover. Supplying incorrect information sits at seven and a half million or one per cent. The Article 50 transparency duties sit in the middle tier: fifteen million euro or three per cent of worldwide annual turnover, whichever is higher.
What to change this quarter
- Decide disclosure at brief stage, not delivery. Write the labelling decision into the brief alongside the deliverable list, so it is a production constraint rather than a compliance afterthought.
- Put the label on the asset and the provenance in the metadata. The metadata satisfies machine detection. The on-asset label satisfies a human at first exposure, which is what the text actually asks for.
- Ask your model providers, in writing, what marking they apply to outputs and from what date. Their Article 50(2) position determines whether your exports carry machine-readable provenance at all.
- Classify your formats. Wholly synthetic presenters and any manipulated likeness of a real person are deepfake-category and get disclosed without argument. A stylised, obviously-constructed brand film is a judgement call worth documenting.
- Keep the file. Which model, which version, which licence, who signed off, what was disclosed, on which placement. The obligation is provable or it is not satisfied.
None of this is expensive. It is a process change made once, at brief stage, that costs nothing per asset afterwards. The expensive version is the one where a campaign is already live.
UK, EU and platform requirements on one page, arranged by asset type so the decision happens at brief stage. Free, no email gate.
DOWNLOAD THE DISCLOSURE CHECKLIST →