Labeling AI content made for a client: who has to disclose it

If your studio generated the content, your studio discloses it. The transparency obligations in Article 50 of the EU AI Act have applied since 2 August 2026, and the duty attaches to whoever ran the model rather than to whoever pressed publish. That settles most of the confusion around labeling AI generated content produced on commission. Generative tools already sit inside the production line: surveying around 200 agency decision makers with 4A’s in April 2026, Forrester found that nine in ten US marketing agencies use generative AI.

The duty and the evidence then travel in opposite directions. The duty stays with the producer, while the file goes on to the client, gets recompressed for the web and cropped for a placement, and the marking does not always survive the trip. Months later the agency has to show what it delivered, when, and how it was marked.

Who carries the obligation when a supplier generates the content

The obligation belongs to whoever uses the AI system under their own authority, which in commissioned creative work is normally the agency, the studio or the freelancer who generated the material. The European Commission’s guidelines on Article 50, issued as C(2026) 5054 final on 20 July 2026, name “an advertising company” as a textbook deployer and add that a legal person remains the deployer even when it involves contractors or freelancers in operating the system on its behalf. Individual employees, whether digital animators, web designers or content creators, are not separate deployers. Authority means assuming responsibility for the decision to deploy the system and for the manner of its actual use, including its outputs, and the guidelines specify that this does not require technical control. Handing the file over does not move the duty.

Provider, deployer and those who merely distribute someone else’s content

Three positions have to be kept apart, because only one carries the labeling duty. The provider builds the system and answers for the machine-readable marking of Article 50(2), while the deployer runs it under its own authority and answers for the disclosure duties in Article 50(4), which is where the text of Article 50 and its labeling obligations become an agency’s problem. One duty does not cover the other: under point 117 a deployer cannot lean on the machine-readable marking the provider inserted, because that marking is not clear and distinguishable for the people exposed to the content. Anyone whose role is limited to disseminating content created by others is not a deployer: point 16 names hosting services, online platforms and broadcasters, which are strongly encouraged, not required, to preserve markings applied upstream. The parties most likely to break your label have no duty to keep it.

A client who merely commissions the work is not a deployer

A brand that simply orders a campaign does not take on the disclosure duty. A company that merely commissions an agency to produce an advertisement, without taking decisions and exercising control over whether and how the agency uses AI, is not a deployer. Control is the switch, so a client who specifies a synthetic presenter steps into the role.

One misreading circulates widely in English-language guidance. Article 50(5) is sometimes described as an obligation running from one deployer down the chain to the next, and it is nothing of the sort: paragraph 5 governs when and how the information reaches the persons exposed to the content, no later than first exposure. Your duty arises from being the deployer and is never inherited. Point 13 adds that even a third-country company generating a deepfake for an advertisement shown in the Union is a deployer.

What must be disclosed in advertising work and what must not

Not every asset made with AI needs a label, and the dividing line runs through the concept of a deep fake rather than through the tool that produced it. Article 3(60) of Regulation (EU) 2024/1689 defines a deep fake as AI generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The Commission guidelines break that into four cumulative criteria at point 113: appreciable resemblance, a subject that exists or plausibly exists, one of the listed categories, and a false appearance of authenticity. Under point 114 the assessment is objective, so an intention to deceive is not required. Text follows a separate rule with a narrower scope, which is why one campaign can carry a labeled key visual and unlabeled body copy.

When a campaign falls within the definition of a deepfake

The Commission’s own examples come from advertising. A generated celebrity influencer in a promotional context is a deep fake, as is a realistic synthetic avatar of a CEO, and so is an AI generated image of a product in an advertisement or on packaging that misleads about its appearance, characteristics or use.

The negative examples matter just as much: a real car shown against a generated background stays outside the definition, provided the ad does not mislead about the product. Underneath all of it sits a threshold of relevance. Point 116 treats color correction, background replacement for aesthetic purposes and rescaling for packaging as having only a minor impact on perceived authenticity.

Why the artistic and creative exception does not cover advertising

The exception for evidently artistic, creative, satirical or fictional works does not switch the obligation off but changes the manner of disclosure, and advertising rarely qualifies for it in the first place. Point 122 of the guidelines states that the categories should be interpreted strictly, and puts outside them any content whose nature is exclusively informative or commercial. For mixed cases it sets a closing rule: when a deep fake combines several characters, the informative character should always prevail. The negative examples come from commercial work, including an AI-manipulated video in the style of a teleshopping channel simulating humans advertising a product, and a realistic synthetic influencer testing a sponsored real product with the sole purpose of showing what it does. Where the lighter regime applies, point 123 still requires disclosure in a manner that does not hamper the display or enjoyment of the work.

Text, images and the counter-intuitive rule on promotional copy

Ad copy written with AI is normally outside the text obligation, and the exclusion carries a parenthesis that pulls a good part of advertising back in. The second subparagraph of Article 50(4) covers text published to inform the public on matters of public interest, and point 131 places company advertisements and product descriptions outside it, “not including any claims related to e.g. health, consumer safety or sustainability”. A generated product description is out of scope until it asserts something about wellbeing, safety or the environment.

Where the text obligation does bite, the editorial exception is the way out, and it takes two conditions together: human review or editorial control, plus editorial responsibility held by an identified person. Point 134 then sets the bar for that review, calling it a deliberate examination of the substance by people with relevant knowledge and professional judgment, with fact-checking as the minimum. Superficial checks, an editorial policy that exists only on paper and cursory sign-off are all ruled out. Then comes the sequencing trap: any substantive AI intervention after the review voids the exception, so a last-minute rewrite undoes the sign-off it was supposed to sit under.

Deliverable Under the obligation Why How it is met
Generated background, real product unaltered No Does not mislead about the product Nothing due; keep an internal record
Product shown better than it is Yes Deep fake misleading on appearance Disclosure visible at first exposure
A real testimonial de-aged Yes Point 114 lists de-aging among deep fake markers Disclosure, unless the work is evidently creative
Synthetic voice of a real person Yes Generated audio resembling an existing person Audible disclaimer at the start, per the Code
Promotional copy written with AI As a rule no Advertisements sit outside the published-text rule Assess images and video separately
Health, safety or sustainability claim in generated text Yes The advertising exclusion does not cover them Disclose, or meet the editorial exception
Sponsored editorial on a public-interest matter Yes, unless the exception applies Text published to inform the public Substantive human review plus a named editorial owner

The dates that matter and the misunderstanding about the December deferral

Article 50 has applied since 2 August 2026 under Article 113, and the deferral everyone keeps mentioning does not concern agencies. Regulation (EU) 2026/1744 of 8 July 2026 added a fourth paragraph to Article 111 of the AI Act, giving providers of systems that generate synthetic audio, image, video or text content until 2 December 2026 to comply with Article 50(2). Three limits are built into that sentence: it applies only to providers, only to the machine-readable marking of paragraph 2, and only to systems placed on the market before 2 August 2026. Deepfake labeling under Article 50(4) is untouched, and point 153 confirms that every in-scope system had to comply on 2 August 2026 whatever its date of placement on the market, with no grandfathering anywhere in the transparency obligations that took effect for businesses.

Two further dates get quoted as deadlines and are not. The Code of Practice on transparency for AI generated content, published on 10 June 2026 with around 190 signatories by the end of July, commits providers in its Section 1 to an interoperability solution for detection mechanisms by 2 February 2027: a promise made inside a voluntary instrument, not a statutory term. The guidelines themselves will be formally adopted only once all language versions are available.

Penalties deserve reading twice. Article 99(4)(g) sets fines of up to EUR 15 million or up to 3% of total worldwide annual turnover, whichever is higher, while paragraph 6 reverses the test for SMEs and start-ups, for whom the lower figure applies. None of this closes the gap between having a rule and showing you followed it, which is where transparency law stops.

TrueScreen

TrueScreen

TrueScreen, the forensic acquisition and certification platform

Acquire and certify digital content with legal value, right from the source.

Discover more →

Where the producer’s responsibility ends and the client’s begins

After delivery your responsibility becomes a duty to take proportionate measures, not a duty to control what happens next, and the instruments the guidelines name at point 12 are contractual rather than technical.

Contractual conditions along the distribution chain

Deployers in complex content production and distribution chains should take proportionate measures to ensure the labeling they applied is displayed clearly at first exposure, and point 12 names contractual conditions with distributing partners alongside user experience settings and interfaces. Section 2 of the Code adds that signatories are encouraged to collaborate on a best effort basis with publishers, platforms and retail partners to preserve the label. Neither text asks you to guarantee the result: a nine-person agency cannot police a global rollout, only ask in writing.

What to put in the contract and in the handover to the client

Most of the weight sits in four clauses. The first is an asset-by-asset declaration of which files are synthetic and what marking each carries, since the deepfake test applies per asset and not per campaign. The second is a clause obliging the client and its partners to preserve the label through republication, resizing and reupload. The third is a named editorial owner wherever the editorial exception is relied on, since Section 2 of the Code expects a policy naming that person, with role and contacts. The fourth is a copy of the delivered material that stays intact. An agency can hand over the TrueScreen certification of each original file alongside the assets: it records what was produced and with which marking, whatever happens to the copy after publication. At volume the practical route is integrating certification into production.

How do you prove what was delivered and with which marking?

The obligation is yours, but the proof does not have to rest on your own records. TrueScreen, the Data Authenticity Platform, certifies the file at the moment it is produced and fixes its content, its date and its origin in a package anyone can verify independently, without proprietary software, so what an agency delivered stays demonstrable after the label has been stripped downstream. The certification carries a qualified timestamp and an electronic seal applied through a third-party QTSP integrated via API, which is what makes the handover enforceable rather than merely documented. That is the distance between declaring and demonstrating: a marking travels inside the file and dies with the first recompression, while a certification of the original file is a separate object that survives whatever the client’s systems do to the copy.

The mechanism is ordinary. A visual uploaded to a content management system gets recompressed for the web and the metadata does not survive the pass. Six months later a consumer association challenges the campaign, claiming a depicted environment does not exist. Certifying the file at production time fixes each visual as it left the studio, and the client checks it with the public verification tool.

FAQ: labeling AI content made for a client

If the agency generates the content but the client publishes it, who has to disclose it?
The agency. Under Article 50 of the EU AI Act the duty falls on the deployer, whoever uses the AI system under their own authority, and the Commission’s guidelines of 20 July 2026 name an advertising company as a typical deployer. A client who merely commissions the work is not one.
Is an advertising campaign with an AI generated face a deepfake?
Usually yes. Article 3(60) of Regulation (EU) 2024/1689 defines a deep fake as AI generated or manipulated image, audio or video content resembling existing persons, objects, places or events that would falsely appear authentic. The Commission cites a generated celebrity influencer in a promotional context, and intention to deceive is irrelevant.
Does ad copy written with AI have to be disclosed?
As a rule no. The second subparagraph of Article 50(4) applies to text published to inform the public on matters of public interest, and the Commission’s guidelines place advertisements and product descriptions outside it. The exclusion stops at claims about health, consumer safety or sustainability.
Does the artistic and creative exception apply to advertising?
Rarely. Point 122 of the Commission’s guidelines requires the artistic, creative, satirical and fictional categories to be read strictly and excludes content that is exclusively informative or commercial. Where several characters combine, the informative one prevails, and teleshopping-style videos with simulated humans do not qualify.
What changes on 2 December 2026?
Nothing for agencies. Regulation (EU) 2026/1744 of 8 July 2026 added Article 111(4) to the AI Act, giving providers of generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2) on machine-readable marking. Deployers are not covered.
How do you prove what was delivered if the label is lost?
By certifying the delivered files at production time instead of relying on the marking inside them. Recompression, cropping and reupload strip embedded metadata, so a label alone leaves no evidence once the client’s systems have processed the file. A certification fixing content, date and origin, sealed through a QTSP, survives it.

Certify what you deliver to your client

TrueScreen captures and certifies deliverables at handover, fixing content, date and origin with a qualified timestamp and the electronic seal of a third-party QTSP.

Start now
Request a demo

TrueScreen