The EU AI Act for Marketing Teams: Article 50 in Force
If a platform automatically labels your AI-generated creative, that does not discharge your own disclosure obligation. The European Commission’s guidance is explicit: platform-side labels may complement an operator’s disclosure but cannot replace it. That single clarification catches a great many marketing teams who assumed the tooling handled it — and the obligations have been in force since 2 August 2026, with penalties reaching €15 million or 3% of total worldwide annual turnover, whichever is higher.
A regulatory analysis from Digital, Ecommerce & Performance Marketing in Europe. Not legal advice — Article 50 involves role-dependent duties and several carve-outs, and you should take advice on your specific systems. Last reviewed August 2026.
1. You are probably in scope
The most common misconception is that the AI Act concerns high-risk systems and large model developers. Article 50 does not work that way. Reported guidance is direct: an organisation with no high-risk AI can still have obligations simply by operating a chatbot or publishing generated content, even when the tools belong to third parties.
| Common marketing activity | Potentially in scope? |
|---|---|
| Website chatbot or AI support agent | Yes — must identify itself as AI |
| Ad creative produced with generative AI | Yes — marking and possible disclosure duties |
| AI-written blog or social copy | Depends on subject matter and editorial control |
| AI-generated product imagery | Marking obligations apply to synthetic content |
| Synthetic voiceover or presenter | Likely a deepfake disclosure question |
| Emotion or sentiment analysis of customers | Yes — individuals must be informed |
Based on reported guidance that a business running a chatbot on its website, producing marketing creative with generative AI, or publishing model-written text has transparency obligations. Whether a specific activity is caught depends on the system, the role and applicable carve-outs — take advice.
The reach is also extraterritorial. Reported analysis confirms the duties apply to businesses wherever established, so a UK or US provider or deployer serving EU users is caught — the same pattern European digital marketing teams already recognise from the GDPR.
2. The four duties under Article 50
| Provision | Duty | Who holds it |
|---|---|---|
| Article 50(1) | Systems interacting directly with people must be designed so people know they are dealing with AI | Provider |
| Article 50(2) | Generative output marked as artificially generated in a machine-readable format | Provider |
| Article 50(3) | Inform individuals exposed to emotion recognition or biometric categorisation | Deployer |
| Article 50(4) | Disclose deepfakes, and AI-generated text published to inform the public on matters of public interest | Deployer |
Sources: Regulation (EU) 2024/1689 Article 50 as described in Commission guidance and legal analyses of 2026. The Commission published draft guidelines on 8 May 2026, ran a targeted consultation which closed on 3 June 2026, and published final guidelines on 20 July 2026.
Note the split. The marking obligation sits with whoever built the tool. The disclosure obligation sits with you, the marketer using it. Buying a compliant tool does not complete your side.
3. Provider or deployer — which are you?
Almost every European performance marketing team is a deployer rather than a provider, and that determines which duties land on you.
| Role | Definition in practice | Typical marketing example |
|---|---|---|
| Provider | Develops the AI system | The vendor supplying your image generator |
| Deployer | Uses the system professionally | Your team producing campaign assets with it |
| Both | Builds and operates its own system | An in-house model or heavily customised agent |
Simplified summary. The distinction carries real consequences: deployer duties under Articles 50(3) and 50(4) cannot be contracted away to a vendor, which is why reported guidance recommends requiring compliance from AI vendors contractually while retaining your own disclosure processes.
4. Platform labels do not discharge your duty
This is the finding most likely to cost a European performance marketing team money, because it contradicts a reasonable assumption.
Commission guidance states that automated AI labels applied by platforms do not relieve the operator of its own disclosure obligation. Platform-side labels may complement, but cannot replace, the operator’s own disclosure.
Source: European Commission guidance on Article 50 transparency obligations, as summarised in 2026 legal analysis. This does not mean every AI-assisted asset requires a visible label — the duty depends on which of the four cases applies. It means you cannot rely on the platform’s automation to satisfy a duty that sits with you.
5. What counts as a deepfake
This is the definition European ecommerce marketing teams need most, because so much product and lifestyle creative now sits near the line. Article 3(60) defines a deepfake as AI-generated or manipulated image, audio or video content resembling existing persons, objects, places, entities or events, which would falsely appear authentic or truthful.
Draft guidance clarified an important limit: clearly fantastical or physically impossible content is treated differently, since a dragon does not falsely appear authentic. The test turns on whether a reasonable viewer might take the content for a real depiction.
| Marketing asset | Likely position |
|---|---|
| Photorealistic AI model wearing your product | Resembles a real person; disclosure question |
| AI-generated version of a real location | Resembles an existing place; disclosure question |
| Obviously fantastical illustration | Not designed to appear authentic |
| Synthetic voice resembling a real presenter | Clear disclosure territory |
| AI-upscaled or retouched real photography | Depends on the degree of manipulation |
| Stylised, plainly illustrative creative | Lower risk |
Assessment based on the Article 3(60) definition and the draft guidelines’ treatment of clearly fantastical or physically impossible content. These are judgement calls at the margin and the fifth row in particular is genuinely uncertain — take advice on borderline assets rather than relying on this table.
6. The date of generation rule
A rare piece of unambiguous good news. Reported guidance confirms that content generated before 2 August 2026 does not require retroactive labelling — the date of generation is what counts.
That gives European ecommerce marketing teams a clean line through the asset library rather than an obligation to audit years of back catalogue. It also creates a practical requirement: you need to know when assets were generated, which means generation dates belong in your asset metadata from now on.
The rule is generous and it has a condition attached. You are only protected by it if you can evidence when something was made.
7. The Code of Practice route
The AI Office developed a Code of Practice on the marking and labelling of AI-generated content, with a first draft published on 17 December 2025, a second in March 2026, and confirmation on 20 July 2026 that the Code of Practice on Transparency of AI-Generated Content was adequate.
| Position | Consequence |
|---|---|
| Adhering to an adequate Code of Practice | A route to demonstrating compliance with Articles 50(2), (4) and (5) |
| Not adhering | Compliance may be demonstrated by alternative means |
| Not adhering, practical effect | Heavier evidentiary burdens and more frequent information requests from market surveillance authorities |
Based on reported analysis of the Code of Practice mechanism. Note the asymmetry: non-adherence is lawful but shifts the burden of proof onto you, which is a meaningful operational cost even where your practices are sound.
8. The timeline, including what may move
| Date | Development |
|---|---|
| 17 December 2025 | First draft Code of Practice on marking and labelling published |
| March 2026 | Second draft published |
| 8 May 2026 | Commission publishes draft Article 50 guidelines — first instrument interpreting it across full scope |
| 3 June 2026 | Targeted consultation closes |
| 20 July 2026 | Final guidelines published; Code of Practice confirmed adequate |
| 2 August 2026 | Article 50 transparency obligations apply |
| 2 December 2026 | Proposed revised deadline for Article 50(2) marking and detection duties under the AI Omnibus — formal adoption pending |
Sources: European Commission publications and 2026 legal analyses. The final row is not settled. The AI Omnibus, on which Parliament and Council reached political agreement, contemplates targeted transitional relief for Article 50(2), with the Council announcing a revised date of 2 December 2026 — but formal adoption remained pending. Do not plan on relief that has not been adopted.
9. What this page does not cover
| Not covered | Why |
|---|---|
| High-risk AI system obligations | Separate and substantial regime |
| General purpose AI model duties | Applies to model providers |
| Whether your specific asset needs a label | Legal determination on the facts |
| Prohibited AI practices | Different provisions entirely |
| Technical marking implementation | Follow the Code of Practice and vendor documentation |
| UK position | No equivalent statute; sector regulators apply existing duties |
Scope statement. On the last row: reported analysis notes the UK has no equivalent statute, but that Ofcom, the ICO and the FCA each apply existing sector duties to the same conduct — so UK teams are not unregulated, merely regulated differently, and remain in scope of the EU rules when serving EU users.
10. The 90-day plan
Indicative sequencing. Unlike most items in this cluster this one is retrospective rather than anticipatory — the obligations commenced on 2 August 2026, so the inventory is establishing where you already stand.
11. Mistakes to avoid
| Mistake | Why it happens | What it costs |
|---|---|---|
| Assuming the AI Act is about high-risk systems | That framing dominated coverage | A chatbot alone puts you in scope |
| Relying on platform auto-labelling | It looks like the problem is solved | Guidance says it cannot replace your disclosure |
| Treating it as a vendor’s problem | The vendor built the tool | Deployer duties cannot be contracted away |
| Planning around the December relief | It has been announced | Formal adoption was still pending |
| No generation dates on assets | Never needed them before | Cannot evidence the pre-August cut-off |
| Assuming non-EU establishment helps | Familiar instinct | Duties reach businesses serving EU users |
| Labelling everything indiscriminately | Caution | The duty centres on four specific cases |
Recurring errors in early AI Act compliance for marketing teams; illustrative and not legal advice.
12. What changes next
The Article 50(2) relief may or may not arrive. The AI Omnibus contemplates transitional relief for marking and detection obligations with a revised date of 2 December 2026 announced by the Council, but formal adoption was pending as at August 2026. Build for the current position.
Enforcement practice is unwritten. The obligations commenced weeks ago, so there is no body of decisions indicating how market surveillance authorities will approach marketing use specifically. That uncertainty argues for documenting your reasoning now rather than after a request arrives.
A standardised EU label is in development. Reported guidance notes work on a standardised label, which would remove some of the current judgement about how disclosure should appear.
Key Takeaways
- Article 50 has applied since 2 August 2026. This is a current obligation, not a future one.
- Platform auto-labels do not discharge your disclosure duty. They complement it; they cannot replace it.
- You do not need high-risk AI to be in scope — a website chatbot or generative campaign creative is enough.
- Deployer duties cannot be contracted to a vendor, though vendor compliance terms are still worth having.
- Penalties reach €15 million or 3% of worldwide turnover, whichever is higher, with the lower figure for SMEs and start-ups.
- Content generated before 2 August 2026 needs no retroactive labelling — but you must be able to evidence the date.
- Code of Practice adherence eases the evidential burden. Non-adherence is lawful but heavier.
Frequently Asked Questions
Does the AI Act apply to ordinary marketing teams?
Frequently yes. Article 50 obligations arise from operating a chatbot, producing creative with generative AI, or publishing model-written text — even when the tools belong to third parties. High-risk classification is a separate question entirely.
Our platform labels AI content automatically. Are we covered?
No. Commission guidance states that automated platform labels do not relieve an operator of its own disclosure obligation, and may complement but not replace it. Your disclosure process remains yours regardless of the tooling.
When did this start?
Article 50 transparency obligations applied from 2 August 2026. Final Commission guidelines were published on 20 July 2026, alongside confirmation that the Code of Practice on Transparency of AI-Generated Content was adequate.
Do we have to label everything made with AI?
Not indiscriminately. The duties centre on four cases: disclosing AI interaction, marking synthetic content in machine-readable form, informing people about emotion recognition or biometric categorisation, and disclosing deepfakes and AI-generated public-interest text.
What about our existing asset library?
Content generated before 2 August 2026 does not require retroactive labelling, since the date of generation is what counts. The practical implication is that you need generation dates recorded in asset metadata to rely on that.
Is AI-generated imagery of a person a deepfake?
Potentially. Article 3(60) covers AI-generated or manipulated image, audio or video resembling existing persons, objects, places, entities or events that would falsely appear authentic. Clearly fantastical or physically impossible content is treated differently.
What are the penalties?
Up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with the lower figure applying to SMEs and start-ups.
Does this reach non-EU businesses?
Yes. The duties apply wherever a business is established, so a UK or US provider or deployer serving EU users is in scope — the familiar extraterritorial pattern from the GDPR.
Should we sign up to the Code of Practice?
It is a commercial judgement. Adherence to an adequate Code offers a route to demonstrating compliance with several provisions, while non-signatories may demonstrate compliance by other means but face heavier evidentiary burdens and more frequent information requests.
Conclusion
The AI Act arrived in marketing without most marketing teams noticing, because the coverage concentrated on high-risk systems and model developers while the provision that actually reaches ordinary work is a transparency rule about chatbots and generated content. It has been in force since the beginning of August, it reaches businesses outside the EU serving EU users, and it carries penalties on the same scale as the privacy regime.
The single detail worth carrying away is the one about platform labels. A great many European digital marketing teams have concluded that because their advertising platform tags AI content automatically, the obligation is handled. The Commission’s guidance says otherwise: those labels complement your disclosure and do not replace it. Map the systems, record when assets were generated, keep the disclosure process on your side of the line, and put the vendor terms in place anyway. None of that is difficult. It is only surprising if you assumed somebody else had done it.
For the practical side of deploying AI in campaigns rather than the compliance side, see AI-powered performance marketing and generative engine optimisation.
Work With Me
If your team produces European campaign creative with generative AI and nobody has mapped which disclosure duties sit with you rather than the vendor, that inventory is a short piece of work with a live deadline behind it.
