Four AI disclosure rules now apply to advertising. The EU AI Act’s Article 50 has applied since 2 August 2026 and requires machine-readable marking of synthetic image, audio and video. New York requires a conspicuous disclosure when an ad contains a synthetic performer, in force since 9 June 2026. Google Merchant Center requires AI provenance metadata on product images. TikTok labels AI content automatically.
An agency running creative for twelve clients cannot currently say which of those rules applies to which asset. That is the problem this solves.
This covers what each rule actually says, which asset types trigger it, and a decision table you can apply per asset and per market. It is general information, not legal advice.
Key Takeaways
- The trigger is usually a synthetic person, not AI editing. Background replacement, upscaling and colour work are generally treated as assistive editing. A generated human face in an ad is the thing that reliably triggers disclosure.
- The EU AI Act applies now. Article 50’s transparency obligations have applied since 2 August 2026 (artificialintelligenceact.eu, accessed September 2026).
- Non-compliance with Article 50 sits in the second penalty tier: up to EUR 15,000,000 or 3 percent of worldwide annual turnover, whichever is higher (artificialintelligenceact.eu, accessed September 2026).
- Marking is machine-readable, and the obligation falls on the provider. Article 50(2) requires outputs to be “marked in a machine-readable format and detectable as artificially generated or manipulated”. Deployers carry a separate disclosure duty for deepfakes.
- Google requires the metadata and forbids stripping it. Merchant Center policy names the IPTC DigitalSourceType TrainedAlgorithmicMedia tag and prohibits removing it (support.google.com, accessed September 2026).
- New York is the first US state to legislate this for ads. In force 9 June 2026, covering “digitally-created media that appear as a real person” (governor.ny.gov, accessed September 2026).
- Never strip metadata to avoid a label. It breaks a Google policy directly and works against the EU marking obligation.
What does the EU AI Act require for AI-generated ads?
Article 50 splits the duty in two, and which half applies to you depends on whether you build the model or use it. Disclosure is the fourth of the layers an advertiser has to manage, and the only one carrying statutory penalties.
Providers of systems that generate synthetic image, audio, video or text must ensure outputs “are marked in a machine-readable format and detectable as artificially generated or manipulated” (Article 50(2)). The marking has to be “effective, interoperable, robust and reliable as far as this is technically feasible”.
Deployers, which is you, must “disclose that the content has been artificially generated or manipulated” for deepfakes, and for AI-generated text published on matters of public interest (Article 50(4)).
There is a carve-out that covers most retouching work. The marking obligation does not apply where “the AI systems perform an assistive function for standard editing or do not substantially alter the input data”. Removing a background from a real photograph of a real product is assistive editing. Generating a person who does not exist is not.
The transparency obligations have applied since 2 August 2026, per Article 113. Non-compliance falls in the second penalty tier under Article 99: up to EUR 15,000,000 or 3 percent of worldwide annual turnover, whichever is higher. Small and medium enterprises are capped at the lower of the two figures rather than the higher.
What does New York’s synthetic performer law require?
A conspicuous disclosure in any advertisement that includes an AI-generated synthetic performer, defined as “digitally-created media that appear as a real person”.
The law took effect on 9 June 2026, and New York’s own announcement describes it as first in the nation. It requires those who produce or create an advertisement to “identify if it includes AI-generated synthetic performers” (governor.ny.gov, accessed September 2026).
Two practical notes. The statute does not define “conspicuous”, so formatting is currently a judgement call and practice varies by ad format. And reported analysis of the bill describes penalties of $1,000 for a first violation and $5,000 for subsequent ones, plus an exemption for promotional material for expressive works such as films and games. Those specifics come from law firm summaries rather than the announcement text, so confirm them against the statute before relying on them.
The scope point that matters for a small brand: this applies to advertising, and it turns on a synthetic performer. An AI-generated product still with no person in it is outside it. An AI-generated model wearing your garment is inside it.
What does Google require on product images?
Provenance metadata, and it prohibits removing it.
Merchant Center policy states: “All images created using generative AI must contain meta data indicating that the image was AI-generated (for example, the IPTC DigitalSourceType TrainedAlgorithmicMedia metadata tag).” It then states directly: “Don’t remove embedded metadata tags such as the IPTC DigitalSourceType property from images created using generative AI tools” (support.google.com, accessed September 2026).
This is the rule most commonly broken by accident. Metadata is routinely stripped by resizing scripts, image compressors, CMS uploads and export presets. Nobody decides to remove it. A pipeline removes it, silently, between generation and upload.
Two other Merchant Center rules interact with generated imagery. Images must “accurately display the entire product, and include minimal or no product staging”, and any overlay including watermarks, brand names and logos is prohibited unless it is part of the product itself. A generated lifestyle scene that buries the product in styling can fail the staging rule regardless of disclosure.
What do the ad platforms do automatically?
TikTok labels a growing share of AI content without asking you.
TikTok was “the first video sharing platform to implement” C2PA Content Credentials, and it automatically labels AI-generated content “when it’s uploaded from certain other platforms” by reading that embedded metadata. It also attaches Content Credentials to TikTok content, which “will remain on content when downloaded”, and labels anything made with TikTok’s own AI effects. It has required creators to label realistic AI-generated content for over a year (newsroom.tiktok.com, accessed September 2026).
The consequence for planning: on TikTok, disclosure is not fully your decision. If your generator writes Content Credentials, the label can be applied on upload whether or not you selected it. Build the campaign expecting the label rather than hoping to avoid it.
You will find claims that platforms suppress reach on labelled AI content. Treat those carefully. We have not found a platform policy stating it, and the evidence circulating is anecdotal. Plan for the label being visible, and do not plan around a demotion nobody has documented.
Which of your assets actually need a label?
Work asset by asset, not campaign by campaign.
| Asset | Person in it | EU AI Act | New York | Google Shopping |
|---|---|---|---|---|
| Product still, background removed from a real photo | No | Assistive editing carve-out | No | Metadata if generated |
| Fully generated product still, no person | No | Marking on the output | No | Metadata required |
| Generated model wearing your garment | Yes, synthetic | Marking, and disclosure if it reads as a deepfake | Disclosure required | Metadata required |
| Real model, AI retouched | Yes, real | Assistive editing carve-out | Check against the definition | Metadata if generated |
| Generated video ad with a synthetic presenter | Yes, synthetic | Marking plus disclosure | Disclosure required | Not applicable |
| Real footage, AI colour grade or upscale | Yes, real | Assistive editing carve-out | No | Not applicable |
The pattern across all four regimes is the same. A synthetic human is the trigger. Editing a real photograph of a real product is generally not.
How should a small team operate this?
Five habits, none of which need a compliance function.
- Record what made each asset. One column in your asset sheet saying generated, edited or shot. Without it you cannot answer a question about an ad from four months ago, and that is when the question arrives. This belongs alongside where your finished assets live.
- Stop your pipeline stripping metadata. Check what survives resizing and CMS upload. Test one file end to end and inspect it at the other side.
- Label synthetic people by default. The rules converge here, and a default is cheaper to run than a per-asset judgement across twelve clients.
- Decide by market, then apply the strictest rule. If a campaign runs in the EU and New York, you are running to both.
- Keep the tag with the file, not in a spreadsheet. Embedded provenance survives handoffs between people and tools. A spreadsheet does not.
There is a design decision underneath all of this. Assets built from your own product photograph are simpler to disclose than assets invented from a text prompt, because there is usually no synthetic person and the edit is closer to the assistive carve-out. DesignerBox works that way by default: the output derives from the product photo you upload. On-model work does put a synthetic person in the frame, and those are the assets to label. Virtual try-on and AI video start on the Premium plan, $75 a month billed monthly.
The reason to settle this once is that you only want to settle it once. Decide which asset types carry a label, write that decision into the workflow that produces them, and product four hundred comes out labelled the same way as product ten. A rule that lives in a person’s head has to be re-applied per asset. A rule that lives in the run applies itself, which is the only version that survives twelve clients and a drop calendar.
The related question, and the one clients ask next, is what a model release covers when the model is not a real person.
FAQ
Do I have to disclose AI-generated images in ads?
It depends on the asset and the market. Where an ad contains a synthetic person, both the EU AI Act and New York’s synthetic performer law point to disclosure. Where you have edited a real photograph of a real product, the EU rules include a carve-out for assistive editing that does not substantially alter the input. Google separately requires provenance metadata on generated product images regardless of whether a person appears.
When did the EU AI Act transparency rules start applying?
2 August 2026, per Article 113. Article 50 requires providers to mark synthetic outputs in a machine-readable format, and deployers to disclose deepfakes and AI-generated text on matters of public interest.
What is the penalty for failing to disclose AI content in the EU?
Article 50 breaches fall in the second penalty tier of Article 99: up to EUR 15,000,000 or 3 percent of worldwide annual turnover, whichever is higher. Small and medium enterprises are capped at whichever of the two figures is lower rather than higher.
What counts as a synthetic performer in New York?
The state describes it as “digitally-created media that appear as a real person”. The obligation is on those who produce or create an advertisement, and requires a conspicuous disclosure. The statute does not define conspicuous, so formatting practice currently varies.
Does Google require AI labels on product photos?
Google Merchant Center requires generative AI images to carry metadata indicating they were AI-generated, naming the IPTC DigitalSourceType TrainedAlgorithmicMedia tag as the example, and prohibits removing that embedded metadata. This is separate from any visible on-image label, and visible overlays are themselves prohibited in product images.
Does labelling AI content reduce reach?
There is no platform policy we can find that states this. Claims that labelled content is demoted circulate widely and are anecdotal. Plan on the assumption that the label will be visible, particularly on TikTok, where labels can be applied automatically from embedded Content Credentials.
Do I need to label AI-edited photos of real products?
Generally not on the synthetic-person grounds, because the EU carve-out covers systems performing “an assistive function for standard editing” that do not substantially alter the input. Google’s metadata requirement still applies to images created using generative AI, so keep the provenance tag intact even for edits.
Sources
- EU AI Act, Article 50, transparency obligations (artificialintelligenceact.eu, accessed September 2026)
- EU AI Act, Article 99, penalties (artificialintelligenceact.eu, accessed September 2026)
- Google Merchant Center image requirements (support.google.com, accessed September 2026)
- New York State, synthetic performer disclosure law announcement (governor.ny.gov, accessed September 2026)
- TikTok Newsroom, AI transparency and Content Credentials (newsroom.tiktok.com, accessed September 2026)
Regulatory positions verified from primary sources as of September 2026. This is general information, not legal advice. Rules differ by market and change quickly. Confirm the current statute and platform policy for your jurisdiction before publishing a campaign.