Join the membership
Knowledge Hub

Evidence-based thinking for strategic marketers

EU AI Act for Marketers: What You Actually Have to Disclose

ai governance Aug 17, 2026

Last verified 16 August 2026

Most of what marketers have been told they must now do under the EU AI Act is not their obligation. Telling people they are talking to a bot, and putting machine-readable markers in AI-generated content, are duties on the company that makes the AI system. Not on the marketing team using it.

The transparency rules in Article 50 became applicable on 2 August 2026. If you are a marketer, you are a deployer, not a provider, and that word decides which duties are yours.

Here is what lands on a marketing team: a disclosure duty on synthetic likenesses, a much narrower one on text, a training obligation under Article 4 that has been live since February 2025, and one sentence in the Regulation that almost everyone is currently reading backwards.

This is an explainer, not legal advice.

Provider or Deployer Decides Everything

 

A provider develops an AI system and puts it on the market. A deployer uses one under its own authority. Use an off-the-shelf AI assistant, image generator or content tool, and you are a deployer.

Obligation Falls on What it requires
Article 50(1) Interaction disclosure Provider Systems that interact directly with people must be built so users are told they are dealing with an AI system
Article 50(2) Machine-readable marking Provider Outputs of generative systems must be marked in a machine-readable format and detectable as artificially generated
Article 50(3) Emotion recognition and biometric categorisation Deployer Inform people exposed to the system that it is operating
Article 50(4) Deepfakes and public-interest text Deployer Disclose that content has been artificially generated or manipulated
Article 50(5) How you tell people Both Clear and distinguishable, no later than first interaction or exposure, and accessible

Source: European Commission, AI Act Service Desk, Article 50, and the Commission's Quick Facts page on transparency rules.

Run a chatbot on your site using a third-party platform, and the duty to build in the "you are talking to an AI" disclosure sits with that platform. Your job is to confirm they have done it.

The exception to watch: you become a provider by putting your own name or trademark on a system, or by substantially modifying it. A white-labelled assistant branded as yours is a different question from a tool you use as supplied. That is a conversation to have with whoever owns your legal function, and it is the most common way a marketing team walks into obligations it did not expect.

Your Vendors Are Already Doing Their Half, and It Affects You

 

The provider duty stopped being theoretical this month.

In August 2026, Anthropic began applying watermarking to Claude's output and said it was doing so to comply with the EU AI Act, referencing the Article 50(2) Code of Practice on Transparency of AI-Generated Content by name. Text carries a statistical watermark built into word choice, using the SynthID-Text method Google DeepMind open-sourced in October 2024. Files carry C2PA content credentials. Roughly 190 organisations signed the Commission's Code of Practice by the July 2026 deadline, including Anthropic, OpenAI, Google, Meta, Microsoft and Mistral.

Here are some important considerations for a marketing team.

It is global and applied by default. Anthropic said it is watermarking worldwide because it does not yet have a durable way to scope it by region. This is the AI Act reshaping a product for everyone, not just for EU users.

It covers the API, not just the chat app. Output from developer integrations, coding tools and cloud-hosted versions is included. Any assumption that only consumer chat is affected is wrong.

Proofreading can leave a mark on work that is yours. Anthropic's own documentation warns that proofreading, translation, summarising and file conversion may produce a mark even where the ideas and text originated elsewhere. If your agency, your freelancers or your localisation vendor runs your copy through an assistant, the output is marked. Ask them.

Set against that, two things stop this being a crisis. There is no public detection tool yet: Anthropic has said a detection API is coming, not that it exists. And a mark carries far less meaning than people assume. Anthropic's own wording is that detecting a mark "tells you that the content may have been processed by Claude", that it "cannot distinguish 'Claude wrote this' from 'Claude heavily edited this'", and that the absence of a mark "doesn't mean the content wasn't AI-generated or processed".

Text watermarking is also weaker than the coverage suggests, and the reason is worth understanding because it tells you which of your content is actually marked.

The watermark works by nudging word choice, so it needs choices to exist. Anthropic states that where an exact output is required, "where there isn't a choice, and something would be factually wrong or a piece of code would break if a different term was chosen", the watermark is not applied, and that marking is "sparser on factual passages where there are fewer choices". Detection also "doesn't work well on small samples, where there are fewer word choices and thus less information to go on".

Read that against your own content. A long-form blog post or an essay is dense with arbitrary word choices, so it marks heavily. A short ad variant, a subject line, a spec sheet or a tightly factual passage marks lightly or not at all.

Independent research points the same way. Sadasivan and colleagues at the University of Maryland showed in 2023 that recursive paraphrasing substantially degrades detection, and Jovanović, Staab and Vechev at ETH Zurich demonstrated scrubbing and spoofing attacks against schemes of this type at ICML 2024. Anthropic concedes that a complete rewrite where every word is replaced removes the watermark, while light editing probably will not.

Anyone selling you a service that detects your AI content is currently overselling.

The Deepfake Rule Is the One That Reaches Marketing

 

Article 50(4) is the deployer duty most likely to catch a B2B team.

Deployers of a system that generates or manipulates image, audio or video content "constituting a deep fake, shall disclose that the content has been artificially generated or manipulated."

The Commission defines a deep fake through three cumulative criteria: the content resembles existing persons, objects, places, entities or events, and it would falsely appear to a person to be authentic or truthful.

So: a synthetic likeness of something real. A cloned executive voice in a podcast ad. An AI-generated face in a testimonial that resembles a real person. A manipulated video of an event that happened. All in scope.

An invented product visual, a generated abstract background, an illustration of nobody in particular: none of these resemble an existing person or event. Out of scope.

Creative work gets a lighter version. Where content forms part of "an evidently artistic, creative, satirical, fictional or analogous work", the obligation reduces to disclosing that the manipulation exists, "in an appropriate manner that does not hamper the display or enjoyment of the work". You still disclose. You just do not have to run it across the face of the work.

One trap: your vendor's machine-readable marker does not discharge your duty. The Commission requires the deployer's disclosure to be clear and distinguishable to a person. A watermark a human cannot see is not a disclosure to a human.

The Sentence Everyone Is Reading Backwards

 

This is the part of Article 50(4) currently being misunderstood, and getting it right changes how you set up your content operation.

The text limb of 50(4) applies to AI-generated text "published with the purpose of informing the public on matters of public interest". The Commission frames public interest around politics and democratic processes, public administration and services, and the administration of justice and law enforcement.

A product page, a case study, a nurture email, a landing page: none of that is informing the public on a matter of public interest. It is not in scope. Where a marketing team could stray in is content commenting on regulation, public policy, elections or public services. Thought leadership about legislation is a live question in a way that a feature page is not.

Then comes the sentence. The obligation does not apply where the AI-generated content:

"has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content"

Most coverage reads this as a get-out clause: run it past a human, skip the label. That reading fails on the Commission's own qualification, which is that the exemption requires deliberate examination by someone knowledgeable, and a responsible editorial entity with authority to approve, alter or reject. The Commission is explicit that superficial checks do not qualify.

Read it the other way round and it says something more useful. The Regulation is not asking you to label AI. It is asking whether a named human took responsibility for what you published. If someone did, the label becomes unnecessary. If nobody did, no label saves you, because you have a governance problem the disclosure was only ever papering over.

That is a standard, not a loophole. And it is the same standard good publishing operated on before any of this existed: a person with the authority to kill the piece, who owns it once it ships.

Two practical moves follow. Name that person for every content type, not just the regulated ones. And give them real authority to reject, because an approver who cannot say no is not an editorial control, whatever the workflow diagram says.

The Grace Period Is Not the One You Have Been Told About

 

The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, created a four-month transitional period ending 2 December 2026. It covers the Article 50(2) machine-readable marking obligation only, applies to providers only, and only to generative systems already on the market before 2 August 2026. Recital 38 of that Regulation states the purpose plainly: to let providers adapt their practices without disrupting the market.

The deployer duties in 50(3) and 50(4) got no grace period. They applied in full from 2 August 2026.

If you have been told you have until December, check what for. If it is your own deepfake disclosure, that date has passed.

Content generated before 2 August 2026 does not need retroactive labelling, though the Commission encourages voluntary compliance. And the Digital Omnibus did not delay Article 50. It postponed the high-risk regime, to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for those embedded in regulated products. Any coverage describing the Omnibus as proposed or still in negotiation is out of date.

Article 4 Has Required AI Training Since February 2025

 

Article 4 binds providers and deployers, and it has applied since 2 February 2025. It has been landing on marketing teams for eighteen months while everyone watched the Article 50 date.

As adopted, it required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others operating AI systems on their behalf, accounting for their knowledge, experience, training and the context of use.

The Digital Omnibus softened it from a duty of result to a duty of means, applying from 27 July 2026. Organisations now take measures to support the development of AI literacy, and the amended text clarifies there is no requirement to guarantee any specific level in any individual.

Softened, not removed. And unlike Article 50, Article 4 has no "unless it is obvious" test and no editorial exemption.

There is a commercial argument here that is stronger than the compliance one. Marketing is among the heaviest AI-using functions in most organisations, and the Marketing AI Institute's 2025 State of Marketing AI Report, from 1,882 respondents, found 68% functionally lacked company AI training, with 44% reporting none at all. Lack of education and training has been the top adoption barrier in that survey for five consecutive years.

You now have a regulatory reason to fund the thing that was already the biggest constraint on getting value out of the tools.

Yes, This Reaches You Outside the EU

 

Article 2(1)(c) applies the Regulation to providers and deployers established in a third country "where the output produced by the AI system is used in the Union".

The trigger is the output being used in the Union, not where your company sits. An Australian, UK or US business running a campaign served to EU audiences is in scope for that campaign.

For most B2B teams the question is narrow: are we publishing synthetic content resembling real people or events, and is any of it reaching the EU?

What It Costs to Get Wrong

 

Article 99(4)(g) puts Article 50 breaches in the tier attracting administrative fines of up to EUR 15,000,000 or, for an undertaking, 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.

Article 99(6) reverses the test for SMEs and start-ups: whichever is lower.

Enforcement is patchy. Member States had to designate market surveillance authorities by 2 August 2025 and many missed the deadline, so the landscape is still forming. That is a timing question, not a reason to wait. Uneven enforcement is a weak foundation for a brand position, and disclosure is cheap.

The Platform Rules Will Cost You Sooner Than the Regulation

 

Separate from the law, and moving faster: at the end of July 2026 LinkedIn added a "Seems like AI slop" option to the menu on posts and comments, letting members flag content they find recognisably synthetic. Reported consequences are demotion from recommendations and a private notification to the author, rather than removal or a public label. LinkedIn also removed its own "enhance your post" AI rewriting feature and replaced it with a proofreader.

None of this is AI Act compliance. LinkedIn has not invoked the Regulation, and Article 50(2) binds model providers rather than distribution platforms. This is a feed quality decision.

It is also the constraint that bites first. Watermark detection has no public tool and fails on short text. A human reader with a one-click button has neither problem. Your reach is now partly governed by whether real people find your writing recognisably generic, and the penalty is invisible: you quietly stop reaching anyone outside your own network.

Note the strategic signal in the platform deleting its own rewriter. Use AI for research, structure, editing and volume. Keep the specific first-hand detail, the named examples and the real numbers as human input. Generic thought leadership at scale is the thing being demoted.

How to Decide What to Do

 

The Commission finalised a Code of Practice on Transparency of AI-generated Content on 10 June 2026. It is voluntary, has two independently signable sections, one for providers on marking and detection and one for deployers on labelling, and the Commission and AI Board have confirmed it as an adequate voluntary tool for demonstrating compliance. Adherence does not create a presumption of lawfulness.

The Commission has also published optional EU icons for labelling AI-generated content, including "Fully AI-Generated" and "Partially AI-Modified". The icons are optional. The labelling duty is not.

Four decisions, in order

 

1. Sort your AI use into deployer use and provider use. Anything white-labelled or substantially modified needs a closer look. Everything else is deployer use, and the provider duties are your vendor's to evidence. Ask them for that evidence, and ask your agencies what their tools now mark.

2. Audit for synthetic likeness, not for AI use. The question is not whether AI touched something. It is whether the output resembles a real person, place or event closely enough to pass as authentic. That is a far shorter list, and it is the one carrying the duty.

3. Name the human who holds editorial responsibility, and give them the authority to reject. For AI-assisted text that person is the exemption. For everything else they are the reason the work is defensible.

4. Decide your disclosure position deliberately, not minimally. Gartner's January 2026 research found 78% of consumers rate explicit labelling of AI-generated content as very important or the most important factor in maintaining trust, from a survey of 335 US consumers. Labelling is a legal obligation in a narrow set of cases and a trust asset in a much wider one.

The EU AI Act isn't asking marketers to disclose every use of AI.  It's asking organisations to remain accountable for what they publish. That's a good principle whether regulation requires it or not.  AI can help create content.  Responsibility still belongs to people. 

Evidence informs. Judgement decides.

Build the Judgement, Not Just the Checklist

 

Disclosure rules change. The underlying decision does not: what you hand to a machine, what stays with a person who can be held to account, and how you tell the difference.  AI as an assistant is different from AI as a publisher.

That is what the Marketing and AI track develops, starting with Marketing & AI: Foundations. AI arrives as a deliberate layer on top of marketing fundamentals, never as a shortcut around them.

FAQs

 

Do I have to disclose AI-generated content?

Not usually. The EU AI Act does not require marketers to disclose every use of AI. Instead, it focuses on specific situations where people could be misled, such as AI-generated deepfakes or certain AI-generated text published on matters of public interest without meaningful human review. If AI simply helps you draft or edit content that is then reviewed and approved by a human editor, disclosure is generally not required. 

Does ChatGPT content need to be labelled?

Not simply because it was created with ChatGPT. Using ChatGPT to help write a blog post, email or landing page does not automatically trigger a labelling requirement. The key question is whether the content falls within one of the AI Act's transparency obligations. If a human reviews, edits and takes editorial responsibility for the final content, that human oversight is an important exemption for text published on matters of public interest. 

Does the EU AI Act apply outside Europe?

Yes, in some cases. Like the GDPR, parts of the EU AI Act have an extraterritorial effect. If you develop, deploy or make AI systems or AI-generated content available to people in the European Union, the Act may apply even if your business is based elsewhere. Australian, UK and US organisations serving EU customers should understand the rules rather than assuming they only affect European companies. 

Does AI-written content need a disclaimer?

Usually no. Most AI-assisted marketing content does not need a disclaimer simply because AI was involved. The AI Act is designed to promote transparency where people could be deceived, not to require blanket "written with AI" notices on every piece of content. Good editorial review, fact-checking and clear accountability remain more important than generic AI disclaimers.

Sources

  • European Commission, AI Act Service Desk: Article 50 (transparency), Article 2 (scope), Article 4 (AI literacy), Article 99 (penalties), Article 113 (application dates), official version of 13 June 2024
  • European Commission, Transparency obligations under Article 50 AI Act, FAQ
  • European Commission, Quick Facts: Transparency rules for AI systems
  • Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026, in force 27 July 2026, Recital 38
  • Regulation (EU) 2024/1689 (AI Act), EUR-Lex
  • European Commission, Code of Practice on Transparency of AI-generated Content, finalised 10 June 2026; signatory announcement, 31 July 2026
  • European Commission, EU icons for labelling AI-generated content, page updated 10 August 2026
  • Anthropic, How Claude marks AI-generated content and How Claude's text watermarking works, August 2026
  • Google DeepMind, SynthID-Text, open-sourced 23 October 2024, published in Nature
  • Sadasivan, Kumar, Balasubramanian, Wang and Feizi, Can AI-Generated Text be Reliably Detected?, University of Maryland, arXiv 2303.11156, 2023
  • Jovanović, Staab and Vechev, Watermark Stealing in Large Language Models, ETH Zurich SRI Lab, ICML 2024
  • Marketing AI Institute, 2025 State of Marketing AI Report, n=1,882
  • Gartner press release, 15 January 2026, consumer trust and AI content labelling, survey of 335 US consumers, October to November 2025
  • LinkedIn "Seems like AI slop" reporting option, announced by Chief Product Officer Hari Srinivasan, late July 2026, reported by TechCrunch, Fortune, 404 Media and Social Media Today

BACK TO MARKETING ESSAYS

Why fundamentals matter more than ever.

 

A long-form essay every fortnight on B2B marketing and AI. One argument, the evidence named, and the trade-offs shown rather than tidied away.

Subscribe