Today the European Commission published its final guidelines for Article 50 of the EU AI Act. Thirteen days from now, those rules become legally binding. If you run ads in Europe and you're using AI to generate any part of your creative, you have less than two weeks to figure out what compliance looks like. Most marketing teams haven't started.
[INSIGHT] The EU just set a 200-token watermark threshold for AI-generated text. Anything longer must carry machine-readable marking. Deployers, including advertisers, must add visible labels. Penalties reach 3 percent of worldwide turnover.
Two Rules, Two Different Jobs
Article 50 splits its transparency requirements across two groups, and the distinction determines who has to do what.
The first group is providers. These are the companies building the AI systems. OpenAI, Google, Meta, Anthropic, the platforms that place generative models on the market under their own name. Their job is marking. Every piece of AI-generated audio, image, video, or text must carry a machine-readable signal that identifies it as artificially generated. Think invisible watermarks, digitally signed metadata, detection layers. The marking happens at creation, not at publication.
The second group is deployers. These are the organizations using AI systems under their own authority for professional purposes. Advertisers. Agencies. Media outlets. Publishers. If you take an AI-generated image and put it in a campaign, you're a deployer. Your job is labelling. You must disclose to humans, visibly and clearly, that the content was artificially generated or manipulated.
These two obligations can stack. A provider marks the content. A deployer labels it. If you're an advertiser using an AI tool to generate ad creative and publishing that creative in the EU, you're in the deployer seat. The marking is someone else's problem. The visible label is yours.
The full Code of Practice on Transparency of AI-Generated Content runs through the technical requirements in detail, including the multi-layered marking approach that providers must implement.

[INSIGHT] If you publish AI-generated content in the EU, you're a deployer. The visible label is your responsibility, not your AI vendor's.
The 200-Token Line
The Code of Practice sets a specific technical threshold for text. AI-generated text longer than 200 tokens must be watermarked by the provider. Below that line, it's classified as "very short text" and exempt from the watermarking requirement.
But here's the catch. The exemption only covers marking. If that short text qualifies as a deepfake or addresses matters of public interest, the deployer still has to label it. A 150-token AI-generated product description sitting on an e-commerce page might dodge the watermark requirement. A 150-token AI-generated news summary about a regulatory decision does not dodge the labelling requirement.
The Code acknowledges that text watermarking is less reliable than image or audio watermarking. To compensate, it requires a multi-layered approach for most content. At least two machine-readable marking layers: digitally signed metadata plus an imperceptible watermark. Free-form text gets a single layer because metadata doesn't attach cleanly to text, but providers still have to watermark above the 200-token line.
The threshold will drop as detection methods improve. Today it's 200 tokens. In twelve months, it could be 50. Brands building compliance workflows around the current number should plan for the floor to move.
Advertising Gets No Break
Here's where it gets uncomfortable for marketers.
Article 50 includes an attenuated disclosure regime for deepfakes that are "evidently artistic, creative, satirical, fictional or analogous works." Under this regime, disclosure just has to happen in a way that doesn't hamper enjoyment of the work. Think of a movie poster with a synthetic actor. The label can be subtle.
The guidelines explicitly exclude advertising from this lighter regime. An AI-manipulated video styled like a teleshopping segment, using synthetic humans to persuade viewers to buy a product, does not qualify as artistic or satirical. It gets full disclosure requirements. The label must be clearly perceivable at the time of first exposure.
This means every AI-generated or AI-manipulated ad creative running in the EU needs a visible disclosure. Not buried in a settings menu. Not hidden behind three dots and two taps. Visible at first exposure.
Meta started automatically applying an "AI info label" to ads last month. Google added similar labels. But the EU guidelines are specific about placement. The label must be perceivable where the content is encountered, without requiring the user to click away or dig through menus. Whether Meta's and Google's current label placements satisfy that standard is an open question. The Commission will be the one answering it.
[INSIGHT] Advertising is explicitly excluded from the lighter artistic disclosure regime. AI-generated ad creative gets full mandatory labelling. No exceptions for performance marketing, no carve-outs for product imagery.
The Meta Problem Becomes a Legal Problem
If you've been following how AI is already distorting media buying, the Meta situation will feel familiar. Meta has been auto-enrolling advertisers in AI creative features for months. The results have been chaotic. REI ran an Instagram ad showing a bike with two handlebars. A pajama brand's dress was transformed into a shirt and pants. A women's networking group's ad had men added to it. A bookstore's Valentine's Day campaign came back with garbled text on the products.
Meta's response to advertisers has been consistent: AI can make mistakes, and it's the advertiser's responsibility to review AI outputs. That's a TOS position. Under Article 50, it's about to become a legal position.
If an AI-generated ad creative runs in the EU without proper disclosure, the deployer is liable. That's the advertiser, not Meta. Meta provides the tool. You publish the ad. You carry the labelling obligation. And if the ad contains a synthetic human that constitutes a deepfake, the disclosure requirements get stricter, not lighter.
The agencies handling hundreds of campaigns simultaneously now face a structural problem. They can't manually review every AI-enhanced creative for every market. But the EU just made manual review a legal necessity, not a best practice.
Business Insider's reporting on Meta's AI ad chaos details how even large agencies with dedicated Meta reps are struggling to keep AI features turned off when they shouldn't be on.
What the Penalty Actually Looks Like
Non-compliance with Article 50 can result in administrative fines of up to EUR 15 million or 3 percent of a company's total worldwide annual turnover, whichever is higher.
For a mid-size advertising group with EUR 500 million in revenue, the cap is EUR 15 million. For a global holding company with EUR 5 billion in turnover, it's EUR 150 million. The penalty scales with your business, not with the violation.
Enforcement won't start on August 2. The Commission and national market surveillance authorities need time to build cases. But the first wave of enforcement typically targets visible, high-traffic violations. A major brand running an undisclosed AI-generated campaign in Germany or France is exactly the kind of case that makes a regulator's career.
The parallel to GDPR is intentional. GDPR enforcement started slow, then accelerated sharply after the first few high-profile fines. Brands that treated it as a compliance exercise survived. Brands that waited for enforcement to reach them did not.
The FTC is moving in the same direction on AI transparency, proposing that hiding how an AI system is steered could violate federal law. The EU deadline is just the first to hit.
[INSIGHT] Penalties reach 3 percent of worldwide turnover. For a billion-dollar brand, that's 30 million. The fine scales with your revenue, not your violation.
The Detection Gap
Providers have to offer detection tools, and those tools have to be free. But there's a practical problem that the Code acknowledges without solving.
Text watermarking is less reliable than image or audio watermarking. The 200-token threshold exists because the technology can't reliably watermark shorter passages yet. Even at 200 tokens, the Code notes "lower reliability" compared to other content types.
For advertisers, this creates an awkward dependency. Your compliance depends partly on whether your AI provider's marking actually works. If OpenAI's watermarking fails on a 300-token product description, the deployer still needs to label it. But the deployer may not know the marking failed unless they run detection on their own content, which requires access to the provider's detection tool, which is currently restricted to verified expert users.
The zero-retention rule adds another wrinkle. Content submitted for detection must be deleted immediately after the check. That means no building a library of verified detections. Each audit is a point-in-time snapshot.
Thirteen Days: The Practical Checklist
If you're a marketing leader with EU exposure, here's what needs to happen before August 2.
Audit your AI-generated content in EU markets. Pull every campaign running in EU countries. Flag anything where AI was used to generate or significantly alter creative assets. Images, video, audio, text. If a human didn't create it from scratch, it needs review.
Map your deployer status. If your agency is publishing AI-generated creative on your behalf, clarify who carries the labelling obligation. The guidelines point to the entity publishing the content. If your agency publishes, they may be the deployer. If you publish through your own ad accounts, you are.
Check your providers' detection capabilities. Ask your AI vendors whether they offer detection tools for their generated content. If they don't, document the gap. You'll need that documentation if a regulator asks why you couldn't verify marking.
Build a labelling workflow. Every AI-generated ad creative needs a visible disclosure. Figure out where that label goes in your creative production pipeline. The earlier in the process, the cheaper it is to implement.
Brief your legal team. This is not a marketing-only problem. Your general counsel needs to understand the deployer obligations, the penalty structure, and the interaction with existing consumer protection law in each EU market you operate in.
A German court already ruled that AI-generated content is the platform's responsibility. Article 50 makes AI-generated content the deployer's responsibility too. The liability now flows in both directions.
What Comes After August 2
August 2 is a starting line, not a finish line. The guidelines will evolve as the Commission learns from early enforcement. The 200-token threshold will drop. Detection methods will improve. National regulators in Germany, France, and the Netherlands will set the enforcement tone.
The brands that treat this like GDPR 2.0, building compliance into their creative workflow now, will absorb the cost once and move on. The brands that wait for the first enforcement letter will pay more. They always do.
Watch what happens in the first 90 days. If regulators target a major consumer brand running undisclosed AI creative, the rest of the industry will move overnight. If enforcement stays quiet, the laggards will feel vindicated until the second wave hits harder.
The Meta ad chaos shows the stakes aren't theoretical. AI is already changing your creative without your approval. The EU just made it illegal to pretend it didn't.
