EU AI Act and AI generated ads: what to do now
The EU AI Act's transparency rules for AI generated ads are live. What changed, what counts as AI creative, and the workflow to run this month.
On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act took effect. If you have searched for what that means for advertising, you will have found a wall of law firm client alerts: thorough, accurate, and written for other lawyers. What has been missing is the version for the people who actually ship the ads.
This is that version. We have checked the legal statements below against the published write-ups from two firms that covered the change, Cooley and Davis+Gilbert, and we only assert what those sources support. The rest of the piece is what we know best: the workflow that makes the obligations manageable, because inventory, review and record keeping are things a production pipeline can simply do for you. This is a workflow guide, not legal advice.
What changed on 2 August 2026
Article 50 of the EU AI Act is the transparency chapter, and its obligations went live on 2 August 2026. Guidance summarised by Cooley makes two framing points worth absorbing before anything else: the obligations apply to in-scope AI systems regardless of when they were placed on the market, and non-compliance can draw fines of up to 15 million euros or 3 per cent of worldwide annual turnover, whichever is higher.
Cooley's summary breaks Article 50 into four disclosure duties, split between providers (those who develop and place an AI system on the market) and deployers (those who use an AI system under their own authority):
- AI systems that interact directly with people, such as chatbots, must disclose that the user is talking to AI, unless it is already obvious.
- Providers of systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and are detectable as AI generated.
- Deployers of emotion recognition or biometric categorisation systems must inform the people affected.
- Deployers must disclose when content is a deepfake, or when AI generated text is published to inform the public on matters of public interest.
For ad teams, the second and fourth are the ones that matter, and the fourth is the one that lands on you rather than on your tooling vendor.
The reach is wider than many teams assume. Both firms' write-ups are clear that the obligations cover companies that place AI systems on the EU market or whose AI outputs are used within the EU. Davis+Gilbert puts it plainly for marketers: a US based advertiser with no offices, employees or physical presence in Europe may still fall within scope if its AI generated content is used in the EU. The question is where the output travels, not where your team sits.
Two supporting documents arrived shortly before the deadline: the European Commission adopted guidelines on the transparency obligations in July 2026, and, as Cooley notes, a voluntary Code of Practice on transparency offers a set of icons for labelling AI generated content, with signatories enjoying a more favourable enforcement posture.
What this touches in ad creative
The word "deepfake" does most of the damage here, because it makes teams picture face-swapped celebrities and conclude the rules are someone else's problem. The Act's definition is much broader. As quoted in Davis+Gilbert's write-up, a deepfake is AI generated or AI manipulated image, audio or video content that "resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".
Read that again with an ad creative hat on. It covers objects, places, entities and events, not just people. Davis+Gilbert notes that this is significantly broader than the American colloquial sense of the word: the test is deceptive realism, not whether a real person has been cloned. Realistic AI depictions of products, locations, animals, events and human avatars are all in the frame.
The advertising examples in the Commission's guidelines, as summarised by Davis+Gilbert, make the application concrete:
- An AI generated image of a product in an advertisement that can affect the audience's perception is the kind of content the disclosure duty targets.
- An AI generated video featuring an AI generated depiction of a celebrity influencer in a promotional context needs disclosure.
- Purely decorative AI generated backgrounds, on the other hand, may be acceptable without disclosure where the real product itself is not misrepresented.
What about content that is obviously stylised, an illustrated mascot or a deliberately surreal composite? The Act does provide lighter treatment for content that is evidently artistic, creative, satirical or fictional. But Davis+Gilbert's read of the guidance should temper any enthusiasm for that route: where content combines commercial and creative characteristics, the commercial character generally prevails, and advertising will rarely qualify for the reduced treatment. The safe planning assumption is that realistic AI imagery in an ad is in scope, and the artistic carve-out is not a strategy.
Text is the narrower story. The Article 50(4) text duty applies to AI generated text published to inform the public on matters of public interest, which most ad copy is not. The interesting part for marketers is the exception both firms highlight: disclosure is not required where AI assisted text has undergone meaningful human review and editorial control, with a person or entity assuming editorial responsibility for it. Cooley's summary phrases it as content that "has undergone substantive human editorial review with a person assuming editorial responsibility". Even where the text duty does not bite, that exception tells you what the whole regime rewards: a named human who actually looked, standing behind the output.
The disclosure mechanics, as the guidance describes them
It helps to keep two layers separate, because they belong to different parties.
The first layer is machine-readable marking, an Article 50(2) obligation on providers of generative AI systems: outputs must carry embedded markings and be detectable as AI generated. If you generate imagery through a mainstream model provider, this layer is largely their engineering problem, not yours. It also carries the only grace period Cooley identifies: providers of generative systems already on the market have until 2 December 2026 to comply with marking and detection, and content generated and published before that date need not be retroactively labelled.
The second layer is the visible disclosure, the Article 50(4) duty on deployers, and this is the one advertisers own. Davis+Gilbert describes a single compliance date with no phase-in: from 2 August 2026, deployers of AI systems that generate or manipulate deepfake content must disclose its artificial nature. Article 50(5), in their summary, sets the manner: disclosures must be provided "in a clear and distinguishable manner", at the latest at the time of first interaction or exposure, and consistent with applicable accessibility requirements. The voluntary Code of Practice icons Cooley mentions are one emerging way to standardise how that looks.
Which seat your organisation occupies, provider or deployer, depends on how you build and buy, and it is exactly the kind of question the firms' memos exist to answer. But for the common case of an ad team generating imagery with AI tools under its own control, the deployer duty for realistic content is the one to plan around.
The workflow answer
Strip the legal language away and the compliance work is three capabilities: know which of your assets are AI generated, put a human decision between generation and the public, and be able to reconstruct both when someone asks. If those live in a spreadsheet and someone's memory, this regulation is a headache. If they are defaults of your pipeline, it is mostly a checklist. Here is how we have built Nubu so they are defaults.
Know which assets are AI generated
Every obligation starts with the same question: which of these five hundred assets did a model make? If your team saves generations to the desktop and uploads them by hand, answering it six months later is archaeology.
In Nubu, provenance is recorded at the moment of creation. When a team generates images or video inside a flow, the outputs land as organisation assets in a dedicated "AI Generated" folder, created automatically the first time it is needed. Each one is auto-tagged with "AI" and "AI Generated", plus the specific model and provider that produced it. And because generation runs on your organisation's own AI keys, the recorded model and provider are the ones you actually used, which is also your pointer to who owes the machine-readable marking layer described above.
The practical effect: "show me every AI generated asset in this quarter's EU campaigns" is a filter, not an investigation. Whatever tooling you use, that is the standard to aim for. Provenance captured at creation time, in a place the whole team can query, never reconstructed from filenames and recollection.
Make human review a posture, not a promise
The verified guidance treats robust human editorial review as the alternative to disclosure for AI assisted text, and the wider transparency conversation keeps returning to the same point: regulators, platforms and audiences all want to know that a person looked before the public did. A review step that can be skipped on a busy week is a promise. A review step the pipeline enforces is a posture.
Nubu's pipeline is approval-shaped end to end. When a flow builds, the resulting creatives land in a review state, and a human approves each one before it can queue for rendering. Nothing renders unreviewed, whether the batch is five creatives or five hundred.
The same posture holds at the far end. When finished creatives are delivered to ad platforms, they land paused: in Meta as paused ads that are never activated automatically, and in Google Ads as paused ads and asset groups that a person reviews and switches on inside the platform. Activation, the moment an ad meets the public, is always a deliberate human act, which is precisely where a disclosure decision belongs.
Nubu's AI assistant works the same way, propose only: it drafts campaigns and flows as cards that a human approves, and it cannot render, publish or spend. That is exactly the human-in-charge posture the transparency conversation rewards, and we have written up how that boundary is enforced in AI proposes, humans approve.
Be able to answer for any ad
The third capability is the one you hope never to need. If a regulator, a platform or a client asks about a specific ad, the questions are predictable: is this AI generated, what went into it, and who signed it off?
In Nubu, every render is traceable by design. Each creative records who created it, which campaign and flow it belongs to, which template it used and which version of that template's files, and exactly which inputs were applied: every text value, every footage assignment, every trim. Renders keep per-attempt logs with timestamps, and failed attempts preserve their error and inputs rather than vanishing. The review conversation lives on the creative itself, as comments with mentions in the drawer, so "who approved this and what did they see" has a written answer months later.
None of this was built for the AI Act specifically. Traceability from input to output is what makes automated creative production trustworthy at all, which is a large part of what creative advertising automation is. The regulation has simply made an old engineering virtue commercially urgent.
A checklist to run this month
You do not need a compliance programme to make meaningful progress in August. You need an afternoon and five decisions.
- Inventory your AI assets. List every AI generated or AI manipulated asset in live and upcoming campaigns that EU audiences can see. If you cannot produce that list with a filter, fix the filing first: one folder, consistent tags, provenance recorded at creation from now on.
- Classify what you found. Split realistic depictions (products, places, people, events that could pass as photographic) from evidently stylised work. Given how narrowly the guidance treats creative exemptions for advertising, default realistic content to "needs disclosure" and treat exceptions as decisions someone senior signs off.
- Decide labelling per placement. For each channel, decide how disclosure appears: the platform's own AI disclosure setting, an on-ad label, or both, and agree the wording once so it stays consistent. Write the per-channel decision down where the delivery team will see it.
- Document the review step. Name who approves AI containing creative before it ships, and make sure the approval lands somewhere permanent, a status change and a comment trail rather than a nod in a stand-up.
- Assign ownership. One named person owns AI transparency, keeps an eye on the guidance as it evolves, and adds the disclosure check to the launch checklist. Loop in your legal team on the finely balanced calls, especially around the realistic-versus-stylised line.
While you are at it, ask your generation providers where they stand on Article 50(2) marking, since the machine-readable layer of the regime rides on them.
Honest limits
A workflow guide owes you clarity about what your tools do not do.
Nubu does not add on-ad labels for you. We record provenance, enforce review and keep the trail, but the decision to disclose, the wording, and the placement of any visible label remain yours, made per market and per channel.
Platform-side AI disclosure settings are also your own step. Meta, for example, operates its own advertiser disclosure options for AI generated or altered content, separate from the AI Act. Nubu delivering your ads paused gives you a natural moment to set those before activation, but it does not set them for you.
And the ground is still moving. The Commission's guidelines were adopted weeks before the deadline, the Code of Practice is voluntary and evolving, and enforcement practice does not exist yet. Keep the primary sources bookmarked: the Commission's guidelines on transparency for AI generated content and its Article 50 FAQ, alongside the firm write-ups this piece drew on from Cooley and Davis+Gilbert.
The teams that will find this regulation boring, in the best sense, are the ones whose pipelines already know which assets are AI generated, already put a human approval before every render, and already keep the record. If you would rather have that as your default than as a discipline, you can try Nubu free and see the whole flow, from tagged AI assets to approved creative to paused delivery, in an afternoon.