Dark teal cover with a label-and-tag motif and the Good Transformer wordmark, for an article on whether marketers must label AI-generated content.
AI regulationMarketingComplianceLeadership

Do you have to label AI-generated marketing content?

Two AI transparency laws became operative on 2 August. Neither puts a blanket labelling duty on a UK marketing firm, though the European rule can reach particular work. The test worth applying anyway is whether a customer could take the content for something real.

Good Transformer21 min read

Two AI transparency laws became operative on 2 August. Neither creates a blanket duty to label everything a marketing firm makes with AI, and the advertising code here has never had one. The European rule can still reach some of your work, and this piece sets out exactly which.

That sounds like a let-off. It is not. With no rule to follow, the decision is yours, and somebody will make it either way. Either you make it deliberately, or your platform, an awards jury and your client make it for you.

This piece is general information, not legal advice.

What actually changed on 2 August

Two things became operative on the same day and are being reported as one event. They are separate laws with separate targets.

California's AI Transparency Act. An amending Act signed in October 2025 moved the operative date to 2 August 2026. The codified text carries the note "Operative August 2, 2026".

Its duties fall on a "covered provider", defined as a person who "creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users". That means the companies that build the models. Using AI tools does not make an agency a covered provider.

What the Act requires of those companies is worth knowing, because it changes the files you receive. A covered provider must offer users the option of a visible label. It must also embed an invisible record carrying the provider's name, the tool's name and version number, the time and date of creation, and a unique identifier. Both duties cover image, video and audio only. Neither reaches text, although the Act's own definition of a generative system does include it.

The European Union's AI Act. Article 50 of the Regulation applies from 2 August 2026. We checked that against Article 113 in the Official Journal text rather than a summary, because the exceptions are listed article by article. The Regulation "shall apply from 2 August 2026", with named exceptions, and Article 50 is in none of them.

Reports of the rule often miss which paragraph applies to whom. Article 50(2), the duty to mark outputs in a machine-readable format, falls on providers, which again means the labs. The Digital Omnibus on AI, adopted in July, even gave those providers until 2 December 2026 where their systems were already on the market. None of that is your obligation.

The paragraph that can reach a marketing firm is Article 50(4), which binds deployers. A deployer is anyone "using an AI system under its authority". That is you, the moment your team opens an image tool.

Does the European rule reach you?

For a British agency using ordinary AI tools, only one route into the Regulation really matters, and you can settle it in two minutes.

Article 2 sets out who it applies to. It catches three groups: providers who place a system on the European Union market, deployers established or located in the Union, and providers and deployers in a third country "where the output produced by the AI system is used in the Union".

Using ChatGPT is not placing a system on the market, and a firm in Manchester is not established in the Union. So for a British agency it comes down to the third one: is the output used in the Union?

A campaign aimed at an audience in Dublin or Berlin is caught, whoever the client is. Work made here for an audience here is not. Audience is the common case rather than the whole of it, because output used inside an EU client's own organisation counts too. Our earlier piece on the AI Act's scope covers the full version, including recruitment, where the Act imposes much heavier duties.

Say you are in scope. What Article 50(4) asks is narrow. It requires a deployer to disclose image, audio or video content "constituting a deep fake". The Regulation defines a deep fake as content "that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".

The European Commission published its guidelines on Article 50 on 20 July 2026, and they break that definition into four things that must all be true. The resemblance has to be appreciable. The subject has to exist. The subject has to be a person, object, place, entity or event. And the content has to falsely appear authentic or truthful.

The word doing the most work there is "existing", and it is broader than it looks. The Commission says it is enough that the subject resembles something that "exists, can plausibly exist or could have plausibly existed in reality". A synthetic person who never lived still counts. What drops out are subjects that "defy the laws of nature or physics", for which the Commission's own examples are humans flying without mechanical aids, dragons, and elephants driving cars.

Two of its examples are ordinary marketing work. A video "featuring a realistic synthetic influencer testing out a sponsored real product" is a deep fake for this purpose. So is a teleshopping-style video in which simulated people demonstrate a product to persuade viewers to buy it. The Commission lists both as work that does not qualify as creative or fictional, so neither escapes the duty that way.

The rule for text is narrower. It covers text "published with the purpose of informing the public on matters of public interest", and it does not apply where the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication".

Ordinary marketing copy sits outside it. The Commission gives "AI-manipulated text that is part of a company's advertisement or product descriptions" as an example of text the rule does not reach, but it attaches a condition worth reading twice: "not including any claims related to e.g. health, consumer safety or sustainability". An AI-written green claim or health claim is not automatically outside. The human-review exception will usually cover you in any case, and it is worth knowing what the Commission expects of it, because fact-checking the content is "a minimum requirement" of the review.

The advertising code has no AI rule

We searched roughly 300 pages of the CAP Code and the BCAP Code for "artificial intelligence", "AI-generated", "generative", "synthetic" and "deepfake". None of them appears.

That is not an oversight. The Advertising Standards Authority has explained the position in writing, and its reasoning is the most useful thing a marketer can read on this subject. From its May 2025 note on disclosing AI in advertising:

"There is no blanket legal requirement in the UK to disclose the use of AI in ads and there are many schools of thought, around the world, on the suitability and effectiveness of regulators insisting on such disclosure in all circumstances."

It also says what disclosure cannot fix:

"disclosure alone is very unlikely to mitigate the harm caused by a fundamentally misleading message. It would almost certainly be against the rules to make a misleading claim in an ad, either directly or by implication, and then seek to 'disclaim' that message by disclosing that AI was used."

The regulator asks two questions. Is the audience likely to be misled if the use of AI is not disclosed? And if so, is the disclosure clarifying the message or contradicting it?

Its rulings show how that applies. In April 2025 the ASA banned ads for handmade leather boots built around a craftsman called Henry, photographed in his workshop. The ads carried a mock newspaper clipping about his closing-down sale. Henry did not exist and the images were AI-generated.

The rules cited were the ordinary ones: rule 3.1 on misleading advertising and rule 3.7 on substantiation. No labelling rule was cited, because none exists.

The more instructive ruling went the other way. A supplements brand called ShroomIQ did carry an AI disclosure, at the foot of its homepage: "Some images, including product visuals, names and people shown, are AI-generated representations used for illustrative and branding purposes only."

In April 2026 the ASA upheld complaints about those ads. It noted that the disclosure "suggested the individuals shown may not be genuine health professionals", while the ads presented them as exactly that.

The disclaimer did not protect the firm. The ASA read it, and upheld the complaints anyway.

A third ruling matters to agencies. A supplements company was pulled up over a clinical-trial statistic that turned out not to exist. Its explanation was that an agency had used an AI tool to summarise a scientific paper, and the tool had wrongly credited the figure to that paper. The complaint was upheld anyway. The advertiser is responsible for the claim, whoever produced it.

Consumer law reaches the same conclusion in a different way. Sections 226 and 227 of the Digital Markets, Competition and Consumers Act 2024 have been in force since 6 April 2025, and they prohibit misleading actions and misleading omissions.

Section 227 defines the material information you must not omit as "information that the average consumer needs to take an informed transactional decision". There is no duty to label. There is a duty not to leave out what someone needs in order to decide.

Six sources, one test

Six different sources land on the same test, and they did not coordinate. They are the European Union, the Advertising Standards Authority, UK consumer law, the Advertising Association, YouTube and advertisers themselves.

The European Union asks whether content would "falsely appear to a person to be authentic". The Advertising Standards Authority asks whether an audience would be misled without the disclosure. Consumer law asks whether a customer needs the fact to decide.

The Advertising Association's best-practice guide, published in February 2026 with the ASA in the working group, says disclosure "should be determined using a risk-based approach that prioritises prevention of consumer harm". It adds that content "that is obviously fictional, fantastical, or impossible does not typically require AI-specific labelling".

YouTube, which is a company rather than a regulator, requires disclosure when AI is used to "meaningfully alter or generate photorealistic content". It tells creators they need not disclose "someone riding a unicorn through a fantastical world".

And when the World Federation of Advertisers asked 27 multinational brands what should carry a label, 96% said a label belonged on an AI-generated voice that an audience might assume was human. Only 4% said the same of a decorative AI background. That is a small sample, and it records what advertisers think rather than what the public does.

None of the six says label everything. All six say label what a person could take for something real, and you can apply that today without waiting for anyone.

Who does require disclosure?

No UK regulator does. Three other parties do, and each of them can act sooner than any regulator.

The platform you publish on. YouTube requires a creator to tick a disclosure box in three cases: content that "makes a real person appear to say or do something that they didn't say or do", content that "alters footage of a real event or place", and content that "generates a realistic scene that didn't actually occur".

Beauty filters, colour grading and using AI to help write a script do not count. Creators who consistently do not disclose "may be subject to manual application of a label or penalties from YouTube, including removal of content or suspension from the YouTube Partner Program".

The awards you enter. This is where disclosure has become compulsory, with a signature attached. D&AD's 2026 rules require every entrant to "clearly and completely disclose if, how, and to what extent Artificial Intelligence has been used".

That means naming "the tool(s) used, purpose, stage(s) of use, the nature and proportion of any AI-Generated Material in the final work, and the human oversight and editorial controls applied". D&AD reserves the right to ask for "logs, version histories or contributor attestations", and the entry has to carry a validation card digitally signed by the most senior person responsible for the work.

Cannes Lions now carries the same expectation in its rules and eligibility: "You must indicate if AI has been used in the work or the entry materials and for what purpose."

Your client. Client requirements are the ones most likely to catch a small agency, and the easiest to overlook. The twelve industry principles published by the Institute of Practitioners in Advertising with the Incorporated Society of British Advertisers include this:

"Advertisers and agencies should be transparent with each other about their use of AI. Neither should include AI-generated content in materials provided to the other without the other's agreement."

Read that as an agency. It is not about labelling an advert for the public. It says do not hand a client AI-generated material without their agreement. If your client has adopted these principles and you have not mentioned that the concept boards came out of an image tool, you have already broken that principle.

Your label may not survive the upload

Many teams assume the tool's own label travels with the file. It often does not.

Several major generative tools now attach something called Content Credentials to what they produce. This is a small signed record of what made the file, when, and what was done to it. Adobe Firefly adds them automatically to fully generated images, and Microsoft adds them across Designer, Copilot and Paint. Images from ChatGPT carry them, plus an invisible watermark in the pixels.

Midjourney adds nothing at all. Canva has published a rule against removing provenance data, but has not committed to adding any.

The problem is what happens next. Content Credentials are stored in the file's metadata, and metadata is fragile. The Content Authenticity Initiative, which promotes the standard, says so itself: "metadata of any kind can be removed deliberately or accidentally". Its argument for watermarks is that they survive "screenshotting, pictures of pictures, or re-recording of media, which effectively remove secure metadata".

The most common cause is ordinary website software, and it is probably running on your site right now. WordPress strips image metadata when it generates resized copies, and it does so by default. The documented filter "filters whether to strip metadata from images when they're resized", and it defaults to true. The other of WordPress's two image processors strips this data regardless.

Your original upload may keep its credential. The resized copies your pages actually serve will not, unless somebody has changed that default.

Some platforms do read credentials where they survive. LinkedIn displays a Content Credentials icon on signed images and video, including on single-image and video sponsored ads. It says plainly that "it's not yet possible to identify and label all AI-generated and modified content".

This problem is real enough that California has legislated a fix. From 1 January 2027, a large online platform there "shall not, to the extent technically feasible, knowingly strip any system provenance data or digital signature" from content it distributes. It is a genuine improvement, and it is five months away.

The practical consequence for you is simple. Treat a visible label as a decision your team makes, not a setting the software handles.

What disclosure costs, and what being found out costs

Once the label is a decision rather than a setting, the reason teams avoid making it comes into view. The reason is not a legal one. It is that labelling might cost them something. It does, and pretending otherwise would be useless.

A peer-reviewed study published in Organizational Behavior and Human Decision Processes ran thirteen experiments on exactly this. One experiment showed people an advertisement for an investment company. Where the ad disclosed that generative AI had prepared it, trust in the company fell from a mean of 5.08 with no disclosure to 4.18 with it, on a seven-point scale.

Willingness to invest moved the same way. A later experiment found the penalty held whether the disclosure was voluntary or legally required.

The finding has limits. The samples were American, the year was 2025, and the measures were stated attitudes rather than money actually spent.

The same paper tested the other case, in the same set of experiments. Being exposed by a third party for undisclosed AI use damages trust more than disclosing it yourself.

Either way you lose some trust. Disclosing costs less than being found out, and you choose the timing.

Audiences say they want labels, too. When Sprout Social asked 1,000 UK social media users in February 2026 what one thing they wished brands would stop doing, the top answer was posting AI-generated content without labels, at 28%. Second was engagement bait, at 23%.

Two things qualify that number. It was a forced choice from a list of seven. And in the same survey, only 36% had unfollowed anyone over low-effort AI content, half had not, and the rest were unsure. More people say they want labels than have ever acted on it, which is normal, and the direction is still clear.

Write your disclosure position

There are two tools below. The first turns the scope test above into four questions you can answer once and file. The second is the document to adopt.

The scope test, four questions

Answer these once, write the answers down, and revisit them when you take on a client in a new market.

  1. Does any work we make run to an audience inside the European Union?
  2. Is any part of our firm established or located in an EU member state? If the answer to this and to question 1 is no, Article 50 does not apply to you, and what follows is a commercial decision rather than a legal duty.
  3. Do we produce image, audio or video that resembles a real or realistic person, place, product or event, and that would pass for authentic? This is the deep-fake test, and a person who never existed can still meet it. Work that is obviously impossible, of the dragons and flying humans sort, is outside it.
  4. Do we publish AI-written text about matters of public interest, with no human editor holding responsibility for it? For almost all marketing work the answer is no to both parts of that question, though claims about health, consumer safety or sustainability are worth a second look.

If question 1 or 2 is yes and question 3 or 4 is yes, the duty is likely to reach that work. Disclose it, and take proper advice on your own facts. Everything else is your own policy.

The position, ready to adapt

Put this on your website, in your onboarding pack, and in the pitch document. It is written to be given to a client.

How we use AI, and when we tell you

We use generative AI tools in parts of our work, including research, first drafts, image concepts and production. A named person at this firm is responsible for every piece of work we deliver, and that does not change when a tool has been involved.

What we always disclose to you. We tell you about any AI-generated or AI-altered material before you approve it. We will not include AI-generated content in anything we hand you without your agreement.

What we always label to your audience. We label anything a viewer could reasonably take for something real: a synthetic person, a cloned or synthesised voice, a photoreal scene of an event that did not happen, or an altered image of a real person, place or product. Your audience should know when what they are looking at is not a record of something that happened.

What we do not label. We do not label invented backgrounds, textures, or abstract and obviously stylised imagery. We do not label colour, lighting or retouching work. And we do not label research, planning or drafting where a person has written, checked and taken responsibility for the final words.

What we never do. We never publish a claim we cannot evidence, whoever or whatever produced it. We never present an invented testimonial, review or endorsement as genuine, and no label makes that acceptable. We never use a disclaimer to make an otherwise misleading message acceptable.

Who signs it off. [Name, role] approves every disclosure decision and keeps a short record of what was decided and why.

If you or a platform asks. We will tell you which tools were used, at which stage, and what a person did with the output. If a platform or an awards body requires a declaration, we complete it accurately and share it with you.

If you want a visible mark and have no house style for one, the European Commission has published a Code of Practice on transparency of AI-generated content. It comes with an icon anyone may use free of charge: the capitalised letters "AI", optionally with the word "generated" or "modified" beside it.

Signing the Code is voluntary, and about 190 organisations had done so by the end of July, including Getty Images, Lenovo and Lufthansa on the deployer side.

Change two things when you adapt the position. Fill in the name, because a policy with nobody named will not be followed. And keep the record short, because the value is in being able to answer a question in a week's time, not in building an archive.

Where this leaves you

No UK rule requires you to label AI-generated marketing. Three parties who are not regulators can still hold you to it, and one peer-reviewed study found that being exposed by someone else costs more trust than disclosing it yourself.

So write the position down this week, while it is a choice rather than an answer to an awkward email. It makes the next client conversation about your judgement rather than your tools.

If you would find it useful to work through your own version, and to look at where else AI is being used in work that goes to clients, book a session with us. We will start with what your team is actually doing rather than with the rules.

FAQ

Do you legally have to label AI-generated content in the UK?

No. There is no UK statutory AI Act, and neither the CAP Code nor the BCAP Code contains any AI-specific disclosure rule. What does apply is the ordinary prohibition on misleading advertising, and the duty under the Digital Markets, Competition and Consumers Act 2024 not to omit information a customer needs in order to decide.

Does the EU AI Act apply to a UK marketing agency?

It can, on a condition. Article 2 catches a firm outside the Union where the output of its AI system is used in the Union. Work made here for an audience here, and used nowhere in the Union, is outside it. A campaign aimed at an audience in a member state is inside it. Even then, the deployer duty in Article 50(4) covers content that would pass for authentic, not everything made with AI.

Does California's AI Transparency Act affect your agency?

Not directly. Its duties fall on providers of generative AI systems with over a million monthly users, which means the companies that make the tools. It matters to you because it changes what those tools embed in the files you receive.

What should you label?

A synthetic person, a cloned voice, an invented testimonial, or a photoreal scene of an event that did not happen. Invented backgrounds, stylised illustration and ordinary retouching do not need a label.

Sources


This is general information, not legal advice. If a rule here looks like it reaches your firm, take proper advice on your own facts.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading