
Do you have to label AI-generated marketing content?
Two AI transparency laws took effect on 2 August, and neither puts a labelling duty on a marketing firm based in the UK. The test worth applying anyway is whether a customer could take the content for something real.
Two AI transparency laws took effect on 2 August. Neither one puts a labelling duty on a marketing firm based in the UK, and the advertising code here has never had one.
That sounds like a let-off. It is not. With no rule to follow, the decision is yours, and somebody will make it either way. Either you make it deliberately, or your platform, an awards jury and your client make it for you.
This piece is general information, not legal advice.
What actually changed on 2 August
Two things became operative on the same day and are being reported as one event. They are separate laws with separate targets.
California's AI Transparency Act. An amending Act signed in October 2025 moved the operative date to 2 August 2026. The codified text carries the note "Operative August 2, 2026".
Its duties fall on a "covered provider", defined as a person who "creates, codes, or otherwise produces a generative artificial intelligence system that has over 1,000,000 monthly visitors or users". That means the companies that build the models. Using AI tools does not make an agency a covered provider.
What the Act requires of those companies is worth knowing, because it changes the files you receive. A covered provider must offer users the option of a visible label. It must also embed an invisible record carrying the tool's name, its version, the time and date, and an identifier. Both duties cover image, video and audio only. Text is not in the Act at all.
The European Union's AI Act. Article 50 of the Regulation applies from 2 August 2026. We checked that against Article 113 in the Official Journal text rather than a summary, because the exceptions are listed article by article. The Regulation "shall apply from 2 August 2026", with named exceptions, and Article 50 is in none of them.
Reports of the rule often miss which paragraph applies to whom. Article 50(2), the duty to mark outputs in a machine-readable format, falls on providers, which again means the labs. The Digital Omnibus on AI, adopted in July, even gave those providers until 2 December 2026 where their systems were already on the market. None of that is your obligation.
The paragraph that can reach a marketing firm is Article 50(4), which binds deployers. A deployer is anyone "using an AI system under its authority". That is you, the moment your team opens an image tool.
Does the European rule reach you?
The Regulation reaches a British firm in only one situation, and you can settle it in two minutes.
Article 2 sets out who it applies to. It catches three groups: providers who place a system on the European Union market, deployers established or located in the Union, and providers and deployers in a third country "where the output produced by the AI system is used in the Union".
Using ChatGPT is not placing a system on the market, and a firm in Manchester is not established in the Union. So for a British agency it comes down to the third one: is the output used in the Union?
A campaign aimed at an audience in Dublin or Berlin is caught, whoever the client is. Work made here for an audience here is not. That is the whole test. Our earlier piece on the AI Act's scope covers the full version, including recruitment, where the Act imposes much heavier duties.
Say you are in scope. What Article 50(4) asks is narrow. It requires a deployer to disclose image, audio or video content "constituting a deep fake". The Regulation defines a deep fake as content "that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".
Both conditions must be met. A stylised illustration meets neither. A photoreal image of someone who could pass for a real person meets both.
The rule for text is narrower still. It covers text "published with the purpose of informing the public on matters of public interest". It does not apply where the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication". Marketing copy sits outside it twice over. It is not public-interest information, and it has an editor.
The advertising code has no AI rule
We searched roughly 300 pages of the CAP Code and the BCAP Code for "artificial intelligence", "AI-generated", "generative", "synthetic" and "deepfake". None of them appears.
That is not an oversight. The Advertising Standards Authority has explained the position in writing, and its reasoning is the most useful thing a marketer can read on this subject. From its May 2025 note on disclosing AI in advertising:
"There is no blanket legal requirement in the UK to disclose the use of AI in ads and there are many schools of thought, around the world, on the suitability and effectiveness of regulators insisting on such disclosure in all circumstances."
It also says what disclosure cannot fix:
"disclosure alone is very unlikely to mitigate the harm caused by a fundamentally misleading message. It would almost certainly be against the rules to make a misleading claim in an ad, either directly or by implication, and then seek to 'disclaim' that message by disclosing that AI was used."
The regulator asks two questions. Is the audience likely to be misled if the use of AI is not disclosed? And if so, is the disclosure clarifying the message or contradicting it?
Its rulings show how that applies. In April 2025 the ASA banned ads for handmade leather boots built around a craftsman called Henry, photographed in his workshop. The ads carried a mock newspaper clipping about his closing-down sale. Henry did not exist and the images were AI-generated.
The rules cited were the ordinary ones: rule 3.1 on misleading advertising and rule 3.7 on substantiation. No labelling rule was cited, because none exists.
The more instructive ruling went the other way. A supplements brand called ShroomIQ did carry an AI disclosure, at the foot of its homepage: "Some images, including product visuals, names and people shown, are AI-generated representations used for illustrative and branding purposes only."
In April 2026 the ASA used that line against the advertiser. It noted that the disclosure "suggested the individuals shown may not be genuine health professionals", while the ads presented them as exactly that.
The disclaimer did not protect the firm. The ASA used it as evidence against the ads.
A third ruling matters to agencies. A supplements company was pulled up over a clinical-trial statistic that turned out not to exist. Its explanation was that an agency had used an AI tool to summarise a scientific paper, and the tool had wrongly credited the figure to that paper. The complaint was upheld anyway. The advertiser is responsible for the claim, whoever produced it.
Consumer law reaches the same conclusion in a different way. Sections 226 and 227 of the Digital Markets, Competition and Consumers Act 2024 have been in force since 6 April 2025, and they prohibit misleading actions and misleading omissions.
Section 227 defines the material information you must not omit as "information that the average consumer needs to take an informed transactional decision". There is no duty to label. There is a duty not to leave out what someone needs in order to decide.
Six sources, one test
Six different sources land on the same test, and they did not coordinate. They are the European Union, the Advertising Standards Authority, UK consumer law, the Advertising Association, YouTube and advertisers themselves.
The European Union asks whether content would "falsely appear to a person to be authentic". The Advertising Standards Authority asks whether an audience would be misled without the disclosure. Consumer law asks whether a customer needs the fact to decide.
The Advertising Association's best-practice guide, published in February 2026 with the ASA in the working group, says disclosure "should be determined using a risk-based approach that prioritises prevention of consumer harm". It adds that content "that is obviously fictional, fantastical, or impossible does not typically require AI-specific labelling".
YouTube, which is a company rather than a regulator, requires disclosure when AI is used to "meaningfully alter or generate photorealistic content". It tells creators they need not disclose "someone riding a unicorn through a fantastical world".
And when the World Federation of Advertisers asked large advertisers what should carry a label, 96% said a label belonged on an AI-generated voice that an audience might assume was human. Only 4% said the same of a decorative AI background.
None of the six says label everything. All six say label what a person could take for something real, and you can apply that today without waiting for anyone.
Who does require disclosure?
No regulator does. Three other parties do, and each of them can act sooner than any regulator.
The platform you publish on. YouTube requires a creator to tick a disclosure box in three cases: content that "makes a real person appear to say or do something that they didn't say or do", content that "alters footage of a real event or place", and content that "generates a realistic scene that didn't actually occur".
Beauty filters, colour grading and using AI to help write a script do not count. Creators who consistently do not disclose "may be subject to manual application of a label or penalties from YouTube, including removal of content or suspension from the YouTube Partner Program".
The awards you enter. This is where disclosure has become compulsory, with a signature attached. D&AD's 2026 rules require every entrant to "clearly and completely disclose if, how, and to what extent Artificial Intelligence has been used".
That means naming "the tool(s) used, purpose, stage(s) of use, the nature and proportion of any AI-Generated Material in the final work, and the human oversight and editorial controls applied". D&AD reserves the right to ask for "logs, version histories or contributor attestations", and the entry has to carry a validation card digitally signed by the most senior person responsible for the work.
Cannes Lions now carries the same expectation in its rules and eligibility: "You must indicate if AI has been used in the work or the entry materials and for what purpose."
Your client. Client requirements are the ones most likely to catch a small agency, and the easiest to overlook. The twelve industry principles published by the Institute of Practitioners in Advertising with the Incorporated Society of British Advertisers include this:
"Advertisers and agencies should be transparent with each other about their use of AI. Neither should include AI-generated content in materials provided to the other without the other's agreement."
Read that as an agency. It is not about labelling an advert for the public. It says do not hand a client AI-generated material without their agreement. If your client has adopted these principles and you have not mentioned that the concept boards came out of an image tool, you have already broken that principle.
Your label may not survive the upload
Many teams assume the tool's own label travels with the file. It often does not.
Most generative tools now attach something called Content Credentials to what they produce. This is a small signed record of what made the file, when, and what was done to it. Adobe Firefly adds them automatically to fully generated images, and Microsoft adds them across Designer, Copilot and Paint. Images from ChatGPT carry them, plus an invisible watermark in the pixels.
Midjourney adds nothing at all. Canva has published a rule against removing provenance data, but has not committed to adding any.
The problem is what happens next. Content Credentials are stored in the file's metadata, and metadata is fragile. The Content Authenticity Initiative, which promotes the standard, says so itself: "metadata of any kind can be removed deliberately or accidentally". Its argument for watermarks is that they survive "screenshotting, pictures of pictures, or re-recording of media, which effectively remove secure metadata".
The most common cause is ordinary website software, and it is probably running on your site right now. WordPress strips image metadata when it generates resized copies, and it does so by default. The documented filter "filters whether to strip metadata from images when they're resized", and it defaults to true. The other of WordPress's two image processors strips this data regardless.
Your original upload may keep its credential. The versions your pages actually serve will not.
Some platforms do read credentials where they survive. LinkedIn displays a Content Credentials icon on signed images and video, including on single-image and video sponsored ads. It says plainly that "it's not yet possible to identify and label all AI-generated and modified content".
This problem is real enough that California has legislated a fix. From 1 January 2027, a large online platform there "shall not, to the extent technically feasible, knowingly strip any system provenance data or digital signature" from content it distributes. It is a genuine improvement, and it is five months away.
The practical consequence for you is simple. Treat a visible label as a decision your team makes, not a setting the software handles.
What disclosure costs, and what being found out costs
Once the label is a decision rather than a setting, the reason teams avoid making it comes into view. The reason is not a legal one. It is that labelling might cost them something. It does, and pretending otherwise would be useless.
A peer-reviewed study published in Organizational Behavior and Human Decision Processes ran thirteen experiments on exactly this. One experiment showed people an advertisement for an investment company. Where the ad disclosed that generative AI had prepared it, trust in the company fell from a mean of 5.08 with no disclosure to 4.18 with it, on a seven-point scale.
Willingness to invest moved the same way. A later experiment found the penalty held whether the disclosure was voluntary or legally required.
The finding has limits. The samples were American, the year was 2025, and the measures were stated attitudes rather than money actually spent.
The same paper tested the other case, in the same set of experiments. Being exposed by a third party for undisclosed AI use damages trust more than disclosing it yourself.
Either way you lose some trust. Disclosing costs less than being found out, and you choose the timing.
Audiences say they want labels, too. When Sprout Social asked 1,000 UK social media users in February 2026 what one thing they wished brands would stop doing, the top answer was posting AI-generated content without labels, at 28%. Second was engagement bait, at 23%.
Two things qualify that number. It was a forced choice from a list of seven. And in the same survey, only 36% had unfollowed anyone over low-effort AI content, half had not, and the rest were unsure. More people say they want labels than have ever acted on it, which is normal, and the direction is still clear.
Write your disclosure position
There are two tools below. The first turns the scope test above into four questions you can answer once and file. The second is the document to adopt.
The scope test, four questions
Answer these once, write the answers down, and revisit them when you take on a client in a new market.
- Does any work we make run to an audience inside the European Union?
- Is any part of our firm established or located in an EU member state? If the answer to this and to question 1 is no, Article 50 does not apply to you, and what follows is a commercial decision rather than a legal duty.
- Do we produce image, audio or video that resembles a real person, place, product or event, and that would pass for authentic? This is the deep-fake test. Stylised, illustrative and obviously invented work is outside it.
- Do we publish AI-written text about matters of public interest, with no human editor holding responsibility for it? For almost all marketing work the answer is no to both parts of that question.
If question 1 or 2 is yes and question 3 or 4 is yes, the duty is likely to reach that work. Disclose it, and take proper advice on your own facts. Everything else is your own policy.
The position, ready to adapt
Put this on your website, in your onboarding pack, and in the pitch document. It is written to be given to a client.
How we use AI, and when we tell you
We use generative AI tools in parts of our work, including research, first drafts, image concepts and production. A named person at this firm is responsible for every piece of work we deliver, and that does not change when a tool has been involved.
What we always disclose to you. We tell you about any AI-generated or AI-altered material before you approve it. We will not include AI-generated content in anything we hand you without your agreement.
What we always label to your audience. We label anything a viewer could reasonably take for something real: a synthetic person, a cloned or synthesised voice, an invented testimonial or review, a photoreal scene of an event that did not happen, or an altered image of a real person, place or product. You are entitled to know when what you are looking at is not a record of something that happened.
What we do not label. We do not label invented backgrounds, textures, or abstract and obviously stylised imagery. We do not label colour, lighting or retouching work. And we do not label research, planning or drafting where a person has written, checked and taken responsibility for the final words.
What we never do. We never publish a claim we cannot evidence, whoever or whatever produced it. We never use a disclaimer to make an otherwise misleading message acceptable.
Who signs it off. [Name, role] approves every disclosure decision and keeps a short record of what was decided and why.
If you or a platform asks. We will tell you which tools were used, at which stage, and what a person did with the output. If a platform or an awards body requires a declaration, we complete it accurately and share it with you.
If you want a visible mark and have no house style for one, the European Commission has published a Code of Practice on transparency of AI-generated content. It comes with an icon anyone may use free of charge: the capitalised letters "AI", optionally with the word "generated" or "modified" beside it.
Signing the Code is voluntary, and about 190 organisations had done so by the end of July, including Getty Images, Lenovo and Lufthansa on the deployer side.
Change two things when you adapt the position. Fill in the name, because a policy with nobody named will not be followed. And keep the record short, because the value is in being able to answer a question in a week's time, not in building an archive.
Where this leaves you
Nothing in this country requires you to label AI-generated marketing. Three parties who are not regulators can still hold you to it, and one peer-reviewed study found that being exposed by someone else costs more trust than disclosing it yourself.
So write the position down this week, while it is a choice rather than an answer to an awkward email. It makes the next client conversation about your judgement rather than your tools.
If you would find it useful to work through your own version, and to look at where else AI is being used in work that goes to clients, book a session with us. We will start with what your team is actually doing rather than with the rules.
FAQ
Do you legally have to label AI-generated content in the UK?
No. There is no UK statutory AI Act, and neither the CAP Code nor the BCAP Code contains any AI-specific disclosure rule. What does apply is the ordinary prohibition on misleading advertising, and the duty under the Digital Markets, Competition and Consumers Act 2024 not to omit information a customer needs in order to decide.
Does the EU AI Act apply to a UK marketing agency?
It can, on a condition. Article 2 catches a firm outside the Union where the output of its AI system is used in the Union. Work made here for an audience here is outside it. A campaign aimed at an audience in a member state is inside it. Even then, the deployer duty in Article 50(4) covers content that would pass for authentic, not everything made with AI.
Does California's AI Transparency Act affect your agency?
Not directly. Its duties fall on providers of generative AI systems with over a million monthly users, which means the companies that make the tools. It matters to you because it changes what those tools embed in the files you receive.
What should you label?
A synthetic person, a cloned voice, an invented testimonial, or a photoreal scene of an event that did not happen. Invented backgrounds, stylised illustration and ordinary retouching do not need a label.
Sources
- Regulation (EU) 2024/1689, Official Journal text (Articles 2, 3, 50, 113)
- Regulation (EU) 2026/1744, Digital Omnibus on AI
- California Business and Professions Code section 22757.3 and section 22757.3.1
- Advertising Standards Authority, Disclosure of AI in Advertising, May 2025
- Advertising Association, Best Practice Guide for the Responsible Use of Generative AI in Advertising, February 2026
- Institute of Practitioners in Advertising and ISBA, industry principles for generative AI
- Digital Markets, Competition and Consumers Act 2024, section 227
- YouTube, disclosing altered or synthetic content
- D&AD Awards 2026 terms and conditions
- Cannes Lions awards rules and eligibility
- Schilke and Reimann, The transparency dilemma, 2025
- Sprout Social Q1 2026 Pulse Survey, UK data
- World Federation of Advertisers on AI labelling, April 2026
- Content Authenticity Initiative, durable Content Credentials
- European Commission, Code of Practice on transparency of AI-generated content
This is general information, not legal advice. If a rule here looks like it reaches your firm, take proper advice on your own facts.