When must advertisers disclose the use of AI?
23. heinäkuuta 2026
When must advertisers disclose the use of AI?23. heinäkuuta 2026 Navigating the deep fake labelling requirements under Article 50(4)(1) AI ActThe AI Omnibus gave many businesses reason to breathe a sigh of relief: the application of the AI Act’s core high-risk requirements has been postponed. But AI compliance is not on hold. Particularly, the labelling obligations in Article 50(4) deserve special attention for many businesses. How will the AI Act affect your use of Gen AI in marketing?Generative AI has moved into everyday business communication. Marketing teams, communications departments and external agencies increasingly rely on AI tools when producing or adapting, for example, campaign visuals, product videos, website images or social media assets. Given the scale at which these tools are used nowadays, the publication of AI-generated content has become a routine part of business operations. Yet, from 02 August 2026, organisations can no longer focus solely on creativity and efficiency. Where AI-generated or AI-manipulated content qualifies as a “deep fake” under the AI Act, specific labelling requirements apply. This makes transparency compliance an important consideration for day-to-day marketing and communications activities. Against this backdrop, this article explores the scope of Article 50(4)(1) AI Act and outlines when AI-generated or manipulated content used in retail and marketing contexts requires a disclosure. The AI Act’s deep fake definition: Beyond impersonation?Much turns on how the term “deep fake” is understood. It is commonly associated with a specific type of content: a manipulated video, image or voice recording that makes a real person appear to say or do something they did not actually say or do. For many, the term immediately brings to mind sophisticated cyber-attacks, such as the attempted impersonation of Ferrari’s CEO, which was fortunately detected in time before causing significant damage. The wording of the AI Act, however, is less straightforward. It defines “deep fake” as AI generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. There is currently considerable uncertainty regarding the scope of this definition, particularly as regards to what resembling “existing” persons, objects or other subjects means. A textual interpretation suggests that the relevant content must resemble a real and specifically identifiable person, object, place, or other existing subject matter. Accordingly, only content that replicates an existing person, such as a well-known musician or famous athlete, would qualify as a deep fake. By contrast, an image depicting a synthetic performer on a concert stage or player on the football pitch, without resembling any existing person, would fall outside the scope of the definition. The EU Commission’s guidelines on the implementation of the transparency obligations (“Guidelines”), however, favour a materially broader interpretation. According to the Guidelines, three cumulative criteria must be satisfied: (1) a high level of similarity between the AI-generated or manipulated content and the subject being simulated; (2) that simulated subject must exist, be capable of plausibly existing or be something that could plausibly have existed in reality; and (3) the content must have the potential to deceive or mislead a person regarding its authenticity or truthfulness. The last criterion is context-specific and depends on factors such as level of resemblance, the message conveyed, the intended and foreseeable deployment context and audience expectations. According to the Commission’s interpretation, a photorealistic image depicting a synthetic performer on a concert stage or player on a football pitch, may therefore constitute a deep fake even though it does not resemble any specifically identifiable real person. Only clearly unrealistic and physically impossible content, such as unaided flying humans, falls outside of the scope. How does the difference look like in an example?Based on the Guidelines, the following AI-generated image constitutes a deep fake. It presents a photorealistic picture of a “corporate event” that, in reality, never occurred. If published on the website, viewers could mistakenly assume that the event actually took place. On the other hand, the image below, in which the presenter is talking towards a crowd of animals, can be detected as non-realistic scenario very easily. It therefore does not constitute a deep fake, even under the Commission’s broad interpretation. Affected organisations: Who has to comply?The labelling obligation for deep fakes applies to deployers of AI systems. “Deployer” means any natural or legal person using an AI system under its authority and in the course of a professional activity. For example, if an organisation uses a third-party AI image generator to create a synthetic image for a marketing campaign, the organisation qualifies as a deployer and must comply with the labelling obligation where relevant conditions are met. The labelling obligations in Article 50(4) AI Act apply to deployers established or located in the EU. They further apply to deployers outside the EU where the AI output is used in the EU, for example where the deployer publishes or authorises the distribution of deep fakes that are accessible in the EU. On the other hand, where AI-generated content reaches EU audiences through unforeseeable channels that are outside the deployer's control, the obligations are not applicable. Why is it particularly relevant for advertisement and marketing?Among the various use cases, marketing and advertising activities deserve particular attention. The broad range of AI tools nowadays available enables organisations to generate entirely new content or alter existing material with minimal effort. While the AI Act provides for limited relief from the labelling obligation for deep fakes forming part of evidently artistic, creative, satirical, or fictional work, the Guidelines indicate that this carve-out does not extend to a number of common marketing and advertising use cases. Deep fake labelling may therefore be required in the following situations: AI-generated virtual models:
AI-modified real-life models:
AI-generated or modified products:
Conversely, the following uses are, as a general rule, unlikely to constitute deep fakes: AI-generated background:
Adjustments with AI:
How do you need to label relevant content?Article 50(5) AI Act merely states that information must be clear and distinguishable, provided no later than the first interaction or exposure, and compliant with applicable accessibility requirements. Even from these high-level requirements, it becomes clear that a label or notice appearing solely in a website footer or terms and conditions is insufficient. But how should the required disclosure be presented in practice? Practical implementation guidance can be derived from the EU Commission’s Code of Practice on Transparency of AI-Generated Content (“Code of Practice”). While the Code of Practice is voluntary and legally binding only for entities that sign up to it, its practical significance extends beyond its formal signatories. Market surveillance authorities are likely to view the Code of Practice as the benchmark for assessing compliance. This is also implied by the Guidelines indicating that organisations choosing not to adhere to the Code of Practice, or that implement alternative measures, are expected to demonstrate how their approach ensures compliance, i.e., achieves the same level of transparency. The Code of Practice envisages the use of publicly available EU icons as the primary means of disclosure:
While the icon displaying the capitalised acronym “AI” is considered mandatory, the addition of “GENERATED” or “MODIFIED” remains optional and is recommended only. Alternatively, deployers can also use an equivalent icon or label that complies with the design and placement specifications of the Code of Practice. Turning to the Code’s placement requirements, the icon or equivalent label must be immediately recognisable to natural persons without requiring any user interaction or sustained attention. It must remain visible for a sufficient period to be noticed under normal exposure conditions and be clearly perceivable and distinguishable no later than a natural person’s first exposure to the deep fake. The disclosure should, as a general rule, be embedded directly within the content. The aim is to ensure that the icon or equivalent label remains attached to the deep fake even throughout subsequent sharing. An overlay designed to appear as part of the content itself (e.g., a user interface overlay that appears to natural persons to form part of the content itself) is permissible only as an equivalent alternative to direct embedding and must comply with the same placement principles. As overlays, however, may not survive downloads or screenshots, deployers must make best efforts to ensure that the disclosure is retained when the content is shared or redistributed by others. The appropriate form, placement and timing of the disclosure, however, depend on the output format of the deep fake:
What are enforcement risks?Non-compliance with Article 50 AI Act may result in administrative fines of up to EUR 15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. From a practical perspective, the more immediate risk stems from private enforcement rather than regulatory action. This is because the labelling obligations under Article 50(4) AI Act are likely to be viewed as market conduct rules within the meaning of Section 3(a) German Unfair Competition Act (Gesetz gegen den unlauteren Wettbewerb – UWG). As a result, a failure to comply with the labelling requirements may result in unfair competition claims, including warning letters and cease-and-desist actions brought by competitors or consumer interest groups. Finally, it should be noted that the use of deep fakes portraying real and existing persons without their consent may also result in liability for violations of personality rights. What are next steps to take?Businesses should use the remaining period before 2 August 2026 to build Article 50(4)(1) AI Act into their publication processes. The relevant workflows will often sit outside legal teams, such as marketing, communications, digital or product teams. Businesses should therefore raise awareness of the new requirements within those teams and ensure that employees involved in content creation and publication are able to identify potential deep fakes before content is released. They should also keep records of the labelling method selected and the relevant approval decisions to demonstrate compliance if challenged. Reading list:Regulatory guidance: EU Commission, The Code of Practice on Transparency of AI-Generated Content, https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content#1720699867912-0 EU Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems AI and marketing: McKinsey & Company, From campaigns to continuous growth: AI capabilities shaping marketing, https://www.mckinsey.com/capabilities/growth-marketing-and-sales/our-insights/from-campaigns-to-continuous-growth-ai-capabilities-shaping-marketing Financial Times, ‘Sometimes reality is not enough’: fashion brands turn to AI, https://www.ft.com/content/af2752e8-d409-40d4-b415-820df0fbedf9 Statista, Artificial Intelligence (AI) use in marketing – statistics & facts, https://www.statista.com/topics/5017/ai-use-in-marketing/?srsltid=AfmBOop-b3x6oLYz5UIxIE1dPwHbgnad86lDtesZOPgn06HYAO8F1gM9#topicOverview Deepfakes and cybersecurity: Bloomberg Law, Ferrari Narrowly Dodges Deepfake Scam Simulating Deal-Hungry CEO, https://news.bloomberglaw.com/privacy-and-data-security/ferrari-narrowly-dodges-deepfake-scam-simulating-deal-hungry-ceo Uusimmat Artikkelit
Uusimmat Uutiset
Uusimmat Tapahtumat ja koulutukset
legal updates 23. heinäkuuta 2026 AI Governance Bill: Malaysia’s Next Step Towards the First AI Rulebook legal updates 23. heinäkuuta 2026 When must advertisers disclose the use of AI? legal updates 22. heinäkuuta 2026 Commercially Connected shorts - 22 July 2026 legal updates 20. heinäkuuta 2026 Industrials Unpacked #1: Supply Chain Contracts asiakasuutiset 24. heinäkuuta 2026 Advising Johnson Matthey on completion of the sale of its Catalyst Technolo... toimistomme uutiset 10. heinäkuuta 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... asiakasuutiset 10. heinäkuuta 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... asiakasuutiset 09. heinäkuuta 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... etätapahtuma UAE - Employment law in the Dubai International Financial Centre 10. syyskuuta 2026 9.30am - 1.30pm (GMT) Virtual livetapahtuma Managing AI use in the workplace: what every UK HR team needs to know 10. syyskuuta 2026 9.30am - 1.00pm (BST) Lontoo, Yhdistynyt kuningaskunta livetapahtuma Basic foundations of US employment law 17. syyskuuta 2026 9.30am - 4.30pm (GMT) Lontoo, Yhdistynyt kuningaskunta livetapahtuma 2026 BDC Roundtable 23. syyskuuta 2026 Washington DC, Yhdysvallat |