The EU AI Act for marketing teams
Since 2 August 2026 the EU asks a plain question of anyone publishing AI-made content to people in the EU: which of this was made with AI, and who stood behind it? Here is what the rules require, in plain words, and where the answers live in Branduals. It is general information, not legal advice.
What changed on 2 August 2026
The EU AI Act's transparency rules, its Article 50, apply since 2 August 2026. For a marketing team they mean two things: some AI-made images, video, audio and text now need a clear label, and a chatbot has to say that it is one.
The Digital Omnibus on AI, in force since 27 July 2026, moved the Act's high-risk rules to 2027 and 2028. It did not move these. The only extra time is for the makers of AI tools, who have until 2 December 2026 to add machine-readable markers to what their tools generate. That duty is theirs, not yours, unless you built the tool yourself.
What the law asks, in plain words
Article 50 sets four duties. Two fall on the companies that build AI tools, the providers, and two on the companies that use them professionally, the deployers. A brand or an agency that decides to use an AI tool for its own content, and controls how it is used, is a deployer.
| Rule | Who | What must happen |
|---|---|---|
| Chatbots and AI assistants | Providers | People are told they are talking to AI from the first message, unless it is obvious. |
| Machine-readable marking | Providers | AI-made images, video, audio and text carry markers that software can detect. |
| Emotion recognition and biometric sorting | Deployers | People exposed to such a system are told. |
| Deepfakes, and AI text on matters of public interest | Deployers | A deepfake is clearly labeled. AI text that informs the public on matters such as health, safety, the environment or the economy is labeled, unless a person reviewed its substance and someone holds editorial responsibility for it. |
The last row is the one that matters for most marketing teams, and two definitions decide most cases.
A deepfake is AI-made or AI-altered image, audio or video that resembles a real or plausible person, object, place, entity or event and would falsely appear authentic or truthful. Context counts: if your audience clearly does not expect the content to be real, it may not be a deepfake. The label has to be visible or audible the first time someone meets the content; a hidden marker from the tool maker is not enough.
Public-interest text is published text meant to inform people about topics such as politics, public health, the environment, consumer safety, or economic and scientific developments. It needs no label if a qualified person reviewed its substance, someone holds editorial responsibility for it, and no AI changed it after that review. A spelling check is not a review.
Which marketing uses need a label?
Most everyday AI use in marketing is unlikely to need a label under the Act. A label is due when the content could make people believe that something made up is real. This table is our reading of the Commission's guidelines, not a quotation of the law: use it as a starting point and confirm your own edge cases with a lawyer.
| Marketing use | A label? | Why |
|---|---|---|
| Retouching, background removal or color correction with an AI tool | Unlikely | Everyday editing that creates no false impression, as long as it does not change how a person or a product really looks. |
| An AI-made or AI-improved product image that makes the product look better than it is | Likely | It can mislead about the real product, which the Commission names as a deepfake. |
| Clearly stylized AI illustration or 3D art | Unlikely | Nobody expects a painting to be a photograph. |
| A photorealistic AI image of a scene, a person or a place that looks like a photo | Likely | It can falsely appear authentic, which is what makes a deepfake. |
| An AI avatar or voice that resembles a real person, or a realistic synthetic person who never existed | Yes | Realistic people count, whether or not they exist. |
| A plainly fantastical ad with nothing realistic in it | No | Not a deepfake at all. |
| A realistic deepfake inside an evidently creative or satirical piece | Yes, lightly | A disclosure is still due, but it can be placed so that it does not spoil the work. |
| A realistic ad that simply sells, such as a synthetic customer or influencer trying a real product | Yes, in full | Selling is not the creative exception. |
| AI-drafted ad copy or a product description | No | Not public-interest text, unless it makes claims about health, consumer safety or sustainability. |
| An AI-drafted article on health, the environment, safety or the economy, reviewed and approved by a qualified editor | No | Human review and editorial responsibility exempt it, as long as nothing was changed by AI afterwards. |
| The same article published without a substantive review | Yes | Public-interest text with no human review. |
| A chatbot or AI assistant on your website | Yes, a disclosure | People must know from the first message that it is AI. If you built or commissioned the assistant under your own name, that duty is yours as its provider, and a line in the terms and conditions is not enough. |
Platform rules can go further. Social networks and ad platforms have their own AI labels, and consumer-protection law already bans misleading ads, so a label can be wise where the Act does not require one.
Who is responsible, and what is at stake
The deployer is whoever uses the AI tool under its own authority: the company that decided to use it and controls how. That is not always the company whose name is on the content. If you brief an agency and leave it to decide whether and how it uses AI, the agency is the deployer for that work; if the agency works under your instructions and your control, you are. Contracts should say who labels what.
Enforcement sits mainly with each EU country's market-surveillance authority. Breaking the transparency rules can cost up to €15 million or 3 % of worldwide annual turnover, whichever is higher; for small and medium companies, and since the Omnibus for small mid-caps, the lower of the two applies. The rules reach beyond the EU: a brand based elsewhere is in scope when its AI-made content is meant for people in the EU. Content made before 2 August 2026 does not need a label after the fact, though the Commission encourages it; text generated earlier but published after that date does.
A checklist for marketing teams
- List every AI tool in use. Image, video, voice and text generators, chatbots, and the AI features inside the tools you already pay for.
- Record AI use per file. For each published image, video or article, note which tool made or changed it and how. You cannot label what you cannot trace. In Branduals this is the Set origin dialog, described below.
- Write a labeling policy. Which cases get a label, the exact wording (“Made with AI”, “AI-generated image”), and where it appears in each format.
- Define human review. Name who reviews public-interest text, what they check (facts and sources at a minimum), how the approval is recorded, and that no AI edit follows the sign-off. Say publicly who holds editorial responsibility.
- Keep the tool makers' markers intact. Do not strip the metadata or watermarks AI tools embed; Branduals reads them when an image is uploaded.
- Update agency and freelancer contracts. Say who the deployer is for each kind of work, require disclosure of AI use on every deliverable, and agree who applies the labels.
- Check your chatbots. Every customer-facing assistant says that it is AI in its first message.
- Support AI literacy. The Act asks providers and deployers to take measures that support it among their staff and the people working on their behalf; short guidance on your policy goes a long way.
- Review every quarter. The Commission's guidelines, the voluntary Code of Practice and the platforms' rules are still evolving.
Where the record lives in Branduals
The hardest step is the second one: knowing, months later, which file was made with AI, what made it, and who signed it off. Here that record sits on the file itself.
| What | Where |
|---|---|
| The origin of a file | Open the file's preview, the Info tab, then Rights & compliance: the Source row holds Set origin, or Edit origin once one is recorded. In Media or Drive, select several files and use Set origin from the toolbar. Pick Human-made, AI-assisted, AI-generated, Stock, Agency, User-generated or Synthesized; for an AI origin add the AI model and the prompt, and Needs AI disclosure switches on by itself. |
| Automatic stamps | An uploaded image that carries a standard AI marker is stamped with its origin, and a file an AI agent writes to with no origin yet is marked AI-assisted, on the first write only. A person's entry always wins over a stamp. |
| Verification | Mark disclosure verified, in the same Rights & compliance section, is something only a person who manages compliance can do, never an agent. |
| The rules | Two check types: AI disclosure, which flags an AI-made file whose disclosure is not verified yet, and AI disclosure in image, which looks for the phrase you require in the image's own text. The suggested rule “AI disclosure on AI-generated assets” adopts the first in one move, under the EU AI Act standard. |
| The counts | Compliance, the Origin tab: how many files need a disclosure, how many are verified, how many are missing. The Brand Hub raises “assets need AI disclosure” as a thing to act on. |
| The label people see | A “Made with AI” chip on shared and public pages and in the file preview, on files whose origin is AI and whose disclosure is required. |
| The report | Compliance, Audit center, the EU AI Act Article 50 report: the score, what was checked, what could not be assessed and why, and the open issues, for the period you pick, as an English HTML file you can download for 30 days. |
| Who did what | Reviews keep who decided what, on which version. The AI activity tab lists what each AI agent did and on whose behalf, and the activity log narrates every change, with “on behalf of” wherever an agent acted for someone. |
| Before it goes out | A campaign post cannot publish while an attached file carries an open blocking issue, and the publish check names the approval and the license too. |
Two limits worth knowing: origin is recorded on files, not on articles or campaign text, and the report lists the issues the checks found rather than every AI-made file; the Origin tab is where you count those. Recording origin, the checks, the Origin tab, the AI activity tab and the reports are on every plan.
Read next: Record origin and rights, Set up your brand rules and Show your audit trail.
This article is general information about the EU AI Act as of September 2026, not legal advice. The Commission's guidelines and the Code of Practice keep evolving, so confirm your own cases with a qualified lawyer. Sources: the European Commission's questions and answers on Article 50 and its guidelines on Article 50 (both July 2026), and Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.