VidsFor.me
Menu

Blog · · 7 min read

EU AI Act and AI-Generated Ads: What Article 50 Requires

Article 50 transparency rules for AI-generated video, audio and images in ads, in force since 2 August 2026, plus platform labels and C2PA explained.


title: "EU AI Act and AI-Generated Ads: What Article 50 Requires" description: "Article 50 transparency rules for AI-generated video, audio and images in ads, in force since 2 August 2026, plus platform labels and C2PA explained." date: "2026-09-24" tags: ["eu-ai-act", "compliance", "disclosure", "c2pa"]

Since 2 August 2026, anyone using AI to generate or manipulate realistic video, audio or images and showing them to people in the EU has a legal duty to say so, and that includes advertisers. The rule is Article 50 of the EU AI Act, it survived the Digital Omnibus untouched, and the platforms have been building labelling machinery around it for two years. This post explains what the article requires, who it applies to, how platform labels interact with it, what Content Credentials are, and what to do about it on Monday.

Key takeaways

  • Article 50 of the EU AI Act has applied since 2 August 2026. Deployers of AI systems that produce deepfakes must disclose that the content is AI-generated or manipulated; providers of generative AI must mark outputs in a machine-readable way.
  • Advertisers and agencies are deployers. "We bought the tool" is not a defence.
  • The Digital Omnibus, in force since late July 2026, delayed high-risk obligations to 2027 and 2028 but did not delay Article 50. There is a grace period to 2 December 2026 for the machine-readable marking of systems already on the market before 2 August 2026.
  • Meta, TikTok and YouTube each have their own labelling rules and increasingly read C2PA Content Credentials to label content automatically.
  • Fines can reach 15 million euros or 3 percent of worldwide annual turnover, whichever is higher (as of September 2026).

What Article 50 requires

Article 50 sets out four transparency obligations. Two of them matter for advertising.

Article 50(2), for providers. Providers of AI systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The marking must be "effective, interoperable, robust and reliable" as far as technically feasible. This is the obligation that falls on the model and tool vendors: the video model, the voice model, the image model.

Article 50(4), for deployers. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. The Commission's guidance says this disclosure must be clear and distinguishable and must happen at the point of first exposure at the latest. Where the content is part of an evidently artistic, creative, satirical or fictional work, the obligation is limited to disclosing the existence of generated content in a way that does not hamper the work.

The regulation defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. The Commission's FAQ reads this as three cumulative criteria: resemblance, depicting something that exists, and a false appearance of authenticity.

Apply that to a UGC-style ad. A photorealistic AI creator holding your product in a kitchen and recommending it is designed to look authentic and is squarely inside the definition. A stylised animated mascot probably is not. Real creator footage with AI captions is not a deepfake either, but the same footage dubbed into German with lip re-sync is a manipulated video of a real person and needs a disclosure.

Article 50(4) also covers AI-generated text published on matters of public interest, unless it had human editorial review. Product ad copy is not public-interest information, so this rarely applies to advertisers.

Who it applies to

The AI Act divides the world into providers (who build or substantially modify AI systems) and deployers (who use them under their own authority). An advertiser generating creative with an AI tool is a deployer, and so is the agency doing it for a client. The vendor carries the marking duty; the disclosure duty for a deepfake is on whoever puts the content in front of people.

Territorial scope follows the output, not the company: Article 2 applies the regulation to deployers located in the EU and to providers and deployers anywhere whose system's output is used in the EU. A US brand running AI-generated ads to German audiences is in scope.

On timing: the Digital Omnibus on AI, adopted in June 2026 and in force from 27 July 2026, pushed deadlines for standalone high-risk systems to 2 December 2027 and for high-risk AI in regulated products to 2 August 2028, but left Article 50 where it was. Systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking requirement in Article 50(2); that grace period covers providers' watermarking, not deployers' disclosure. Content published before 2 August 2026 need not be labelled retroactively, though the Commission encourages it.

A Code of Practice on Transparency of AI-Generated Content, assessed as adequate by the Commission and the AI Board, gives signatories a recognised route to compliance. Enforcement sits with national market surveillance authorities; the penalty ceiling is 15 million euros or 3 percent of worldwide annual turnover, with proportionality for SMEs (as of September 2026).

Platform labelling rules

The platforms had their own rules before the AI Act and now sit alongside it. A platform label does not automatically satisfy Article 50, and Article 50 compliance does not exempt you from platform policy. You need both.

Meta (Facebook, Instagram). Meta applies an "AI info" label to ads created or significantly edited with generative AI, visible in the ad's "About this ad" panel and sometimes next to the Sponsored tag. Ads made with Meta's own Advantage+ creative tools are labelled automatically; for third-party AI content, Meta has been running automated detection using industry-standard provenance signals since mid-2026 and applies the label itself when it finds them. Mandatory advertiser self-disclosure applies to social-issue, electoral and political ads, where a missing disclosure can get the ad rejected and the account penalised (as of September 2026).

TikTok. TikTok requires a visible label on AI-generated content that shows realistic-looking people, scenes or audio, and applies the same rule to paid ads and branded content as to organic posts. It has read C2PA Content Credentials at upload since 2024 and labels content automatically when it finds them, alongside invisible watermark detection and its own classifiers (as of September 2026). Unlabelled realistic AI content can be removed.

YouTube (Google). YouTube requires creators and advertisers to disclose "realistic" altered or synthetic content, meaning anything a viewer could mistake for a real person, place or event, and shows a label in the description or, for sensitive topics, on the player. The policy has been in place since March 2024 with enforcement ramping through 2025. Google Ads has its own political-ad synthetic-content disclosure requirement on top.

All three platforms are moving from asking you to disclose toward detecting provenance metadata and labelling for you, which makes the metadata the thing to get right.

What Content Credentials (C2PA) are

C2PA is the Coalition for Content Provenance and Authenticity, an industry standard backed by Adobe, Microsoft, Google, OpenAI, Meta, TikTok and others. Content Credentials are the user-facing name for the C2PA manifest: a cryptographically signed record attached to a media file that says who made it, with what tool, and what was done to it, including whether generative AI was involved.

The credential is embedded in the exported MP4 or image and can be verified with any C2PA-aware viewer. Re-encoding can strip it, which is why the standard also supports fingerprint and watermark lookups and why platforms read it at upload, before transcoding.

For an advertiser, Content Credentials do two jobs. They are the most direct way to meet the "machine-readable" spirit of Article 50(2) in the exported asset, and they are the signal TikTok, Meta and YouTube already read to apply their labels. They do not replace the visible disclosure Article 50(4) requires of deployers; a human watching the ad still needs to be able to tell.

A practical checklist

  1. Inventory the AI in each ad. Generated creator, cloned voice, dubbed and lip-synced footage, generated B-roll, AI-edited product shots. Anything photorealistic that depicts a person, place or event is presumptively a deepfake under the Act.
  2. Add a visible disclosure. A short on-screen label such as "AI-generated" or "Created with AI" in the first frames, plus the platform's disclosure toggle. Visible for the duration is safest for talking-head content.
  3. Embed Content Credentials. Export with a C2PA manifest that records the generative tools used. Check it survives your editing pipeline.
  4. Keep the record. Who consented to a voice or likeness clone, when, for what use, and where the raw prompt and outputs are. The Commission expects deployers to be able to show their labelling practice.
  5. Check claims separately. Disclosure does not fix a false claim. AI creators cannot give testimonials about experiences they did not have, in the EU under consumer law and in the US under the FTC's testimonial rule.
  6. Assign it. One person owns disclosure per campaign and signs off before upload.
  7. Re-check quarterly. Platform policies keep changing.

VidsFor.me was built with this checklist in mind: exports carry an AI disclosure label and Content Credentials, consent records are stored per voice and likeness, the banned-claims checker flags testimonial language on AI creators, and agencies can keep each client's material in a sealed project. The compliance features page covers the details.

This is not legal advice

This article summarises public regulatory text and platform policies as we understand them in September 2026. It is not legal advice, we are not lawyers, and authorities' interpretations are still forming. Have your own counsel review your disclosure practice, particularly in regulated categories or across several jurisdictions.

Prices and third-party facts are as of the publication date and change often; check each provider's page before deciding. Nothing here is legal advice.

Ready to make ads at provider prices?

Join the private beta. Connect your keys, paste a product link, and have finished ads before your next standup.

Request access

Private beta · 14-day Pro trial · bring your own keys

We'll use this to send your invite. Privacy policy.