There is a comfortable misconception doing the rounds in marketing teams right now. It goes: the EU delayed the AI Act, so this is a 2027 problem. Half of that is true. The AI Omnibus package did push the high-risk system obligations back, standalone high-risk systems to 2 December 2027 and product-embedded ones to 2 August 2028. What it did not touch is Article 50, the transparency chapter, which applied on schedule from 2 August 2026.

Article 50 is, as it happens, the one part of the Act most marketing teams actually sit inside. The high-risk annexes are about recruitment scoring, credit decisions and biometric identification. Article 50 is about chatbots, synthetic media and AI-written content, which is to say: Tuesday.

Nothing here is legal advice. It is an operational read of a law that your content process now has to live with, and the sort of thing we end up mapping in audits. Take the legal questions to a lawyer.

First, the distinction that clears up most of the confusion

The Act splits duties between providers (whoever builds the AI system or puts it on the EU market under their name) and deployers (whoever uses it under their own authority). Almost every marketing team is a deployer, not a provider. That matters because two of Article 50's four obligations belong to your vendors, and two belong to you.

  • 50(1), your vendor's job. An AI system that interacts with people must make clear that it is an AI. The "unless it's obvious" exception exists but is read narrowly, judged by a reasonably informed, observant average person. If you have built a chat assistant with a human name and a friendly avatar, "obvious" is doing a lot of work you should not rely on.
  • 50(2), your vendor's job. Providers of generative AI must mark synthetic output in a machine-readable format so it can be detected as AI-generated. This is the clause behind the watermarking wave, and there is a grandfathering grace period to 2 December 2026 for systems already on the market. Exemptions cover brief character sequences, source code, machine-to-machine output, and assistive standard editing that does not substantially alter your input.
  • 50(3), your job. If you deploy emotion recognition or biometric categorisation, you must tell the people exposed to it. Rarer in marketing, but not unheard of in retail analytics and ad testing.
  • 50(4), your job, and the big one. Deployers of deepfakes must disclose that the content is artificially generated or manipulated. Deployers publishing AI-generated text on matters of public interest must disclose that too, unless it went through genuine human editorial review.
Machine-readable marking is your supplier's duty. Telling the audience is yours. Do not assume the watermark discharges your obligation, it is not visible to a reader.

"But we're in the UK"

This is the objection we hear most, and it does not hold. The Act reaches providers placing systems on the EU market and deployers whose output is used in the EU, regardless of where the company sits. A campaign built in London or Chicago and served to audiences in Dublin, Berlin or Madrid is in scope. Social makes this sharper still: one central team posts, and the content is viewed and reshared across every market you have a page in. As TEAM LEWIS put it in a good practical primer, location alone is not a reliable way to decide whether the rules matter to you.

The penalty ceiling for Article 50 breaches is €15 million or 3% of global annual turnover, whichever is higher, enforced by national market surveillance authorities. Realistically, a first enforcement wave against a mid-sized brand's Instagram output is unlikely. Being asked about it in a procurement questionnaire, a client's vendor review or a due-diligence pack is close to certain.

The only question that actually decides it

The Act is not asking "did AI touch this?" If it were, every resized banner and tightened headline would need a label, which is absurd and is not what the text says. The operative question is closer to: could a reasonable person mistake this for an unmediated record of reality?

Applied to a real content calendar, that sorts fairly cleanly.

  • Disclose: a photorealistic video of a real executive saying words they never said; a cloned voice presented as a real spokesperson; an AI-generated photograph of an event that did not happen; a materially altered image that changes what appears to have occurred; AI-written public-interest content published without meaningful human review.
  • Almost certainly not: obviously illustrated or fantastical visuals; cropping, resizing and colour correction; removing a small background distraction without changing the meaning; copy drafted with AI and then substantively reviewed and fact-checked by a person; anything used internally for research or early concepts.

Two refinements worth internalising. Context changes the answer: a surreal visual in a playful brand campaign is not documentary evidence, but the same asset framed as a real customer story is a different proposition entirely. And "human review" has a floor: the exemption for AI-generated public-interest text contemplates substantive examination by someone qualified, holding editorial responsibility, not a skim for typos and a publish click.

Where disclosure is required, it has to be clear and distinguishable at first exposure, and understandable without technical tools. Not the eleventh line of a caption. Not a link to a policy page. The European Commission has published optional labels and icons you can model a house standard on, and there are Commission guidelines on the transparency obligations if you want the primary text.

The part nearly everyone has missed

While the industry argues about labels, Article 4 has been in force since 2 February 2025. It requires providers and deployers to ensure a sufficient level of AI literacy among staff who operate these systems on their behalf. There is no certificate to buy and no box to tick, which is precisely why it gets skipped. If your team cannot articulate the difference between AI-assisted and AI-generated work, you have both a compliance gap and, more to the point, a quality control gap.

Six things to put in place, none of which need a project

  • Inventory where AI is actually used. Image generation, voice cloning, synthetic presenters, translation, chat and support bots, AI-assisted public-facing copy, and every tool your agencies and freelancers use on your behalf. Most organisations cannot answer this today, and the answer is usually broader than the marketing director expects.
  • Write one disclosure standard. Decide the wording, the icon, and the placement for each surface: social, web, display, video, audio, email. One decision, made once, beats a judgement call per asset.
  • Record provenance in the approval flow. Which tool, what was generated or altered, who reviewed it, when. This is a metadata field in your DAM or a column in your content calendar, not a new system.
  • Name the owner in contracts. Brand, agency, production partner or platform: someone has to be responsible for spotting the trigger and adding the disclosure. Unassigned duties are unperformed duties, and agency contracts are the obvious place to fix it.
  • Define AI-assisted versus AI-generated in policy. Then apply your editorial review standard to the second category, because that is what the public-interest exemption turns on.
  • When an asset sits on the line, disclose. The reputational cost of an unnecessary label is roughly zero. The cost of the other mistake is not.

Why this is converging with everything else

Read Article 50 next to what is happening on the model side and the direction is obvious. The machine-readable marking duty in 50(2) is why Claude now watermarks the text it generates, worldwide rather than just in Europe, and why the other major labs signed the same voluntary Code of Practice on Transparency of AI-Generated Content. Provenance is becoming a property of the content itself.

So the two halves arrive together: your suppliers are making AI content detectable, and the law is making certain uses declarable. A brand that quietly passes off synthetic media as real is now taking a risk that compounds, because the evidence is being embedded at the point of generation and the disclosure duty is already live.

The upside is genuine, and it is not the compliance. Audiences are getting steadily better at sniffing out synthetic content and steadily more annoyed at being fooled by it. Teams that decide what their disclosure standard is, publish it, and stick to it get to keep experimenting with these tools while looking like the adults in the category. The goal was never to make less with AI. It is to be able to say, out loud, how you made it.

Where we come in

Everything above starts with an inventory nobody has: what AI is in your marketing stack, who is using it, on which public-facing assets, and under whose sign-off. That is exactly the kind of unglamorous mapping our Digital Marketing Strategy Audit does, governance, supplier arrangements and editorial process examined as one system rather than a pile of assets. If your concern is more about how AI systems read and represent your brand out in the world, that is the AI Visibility Audit. And if you simply want a straight answer on where your exposure sits, book a free scoping call and we will walk your stack with you.