A chatbot must say it's a chatbot — clearly, at the outset. Synthetic media (images, video, audio generated by tools like Midjourney, Runway, Adobe Firefly, ElevenLabs, or Synthesia) must be labeled as artificially generated. Deepfakes — AI depictions of real people, places, or events that could look authentic — must be disclosed in clear and distinguishable manner before first interaction or exposure.
The standard is transparency, not perfection. The buyer, viewer, or user should know they're encountering AI before they're deceived by it. The European Commission AI Office enforces this standard as of August 2, 2026.
For Brands: Four Compliance Steps
Step 1: Audit every active campaign right now. Which assets are AI-generated or AI-modified? Product shots created in Midjourney. Backgrounds generated in Runway or Adobe Firefly. Video upscaled or enhanced by AI tools. Audio cloned or synthesized using ElevenLabs or Synthesia. Text drafted by Claude, ChatGPT, or Gemini and minimally edited before publishing.
Document the tool that created each asset. Track the approval chain. Record who reviewed it and signed off as human editor. This documentation is your defense when enforcement comes.
Step 2: Build your disclosure standard NOW. Decide your framework: label in the image? Caption line? Icon? QR code to terms? Whatever you choose must be visible, persistent across platforms, and readable on mobile. Test it on TikTok, Instagram, YouTube, email, and LinkedIn. If it disappears or becomes illegible on mobile, it's not compliant under Article 50 guidance.
Step 3: Label creative going live after August 2. Any asset created or modified after August 2 is subject to disclosure obligations on publication date — now. Don't wait for December 2. Comply from today. Meta, Google, TikTok, and LinkedIn have published their own Article 50 guidelines on their platforms; follow those in addition to your internal standard.
Step 4: Document AI use in investor relations and regulatory filings. California's AI transparency law (effective August 2, 2026 parallel to Article 50) requires disclosure in marketing. If your CFO is filing SEC disclosures on brand strategy, note AI-generated content separately if material to investor thesis.
For Agencies: Four Liability Steps
Your obligations differ from brands. You create or distribute content on behalf of clients. That makes you a deployer — jointly liable with the brand.
Step 1: Document what you created. If you produced an AI-generated asset (even under client direction), you have a record showing creation date, tool used (Midjourney, Adobe Firefly, Runway, etc.), who approved it, and what disclosure framework was applied. If the disclosure fails, the liability doesn't disappear because the client approved it. You created it. Your name is on the work order.
Step 2: Audit your vendor stack immediately — this week. Midjourney, Adobe Firefly, Runway, Sora, ElevenLabs, Synthesia, Create, Pika, Loom, Opus Clip — none of these have published comprehensive Article 50 compliance statements. That's a problem. You're using tools you don't know are compliant, creating assets that may not be, and distributing work that may breach.
Build a vendor evaluation checklist:
- Does the vendor have Article 50 compliance documentation or certification?
- Does the tool generate machine-readable metadata indicating AI creation (C2PA support)?
- Does the vendor support C2PA (Coalition for Content Provenance and Authenticity) watermarking? (Adobe and Microsoft do; Midjourney and Runway do not — yet.)
- What happens if the vendor is sued for non-compliance? Do they carry indemnification for their users?
- For EU work specifically: has the vendor published EU compliance statements or third-party certification?
Vendors that can't answer these clearly should be retired from EU work — or at minimum, flagged with clients as high-risk and requiring manual disclosure overlay.
Step 3: Train your teams on Article 50 by August 31. Your creative team, paid-media team, influencer team, GEO team — everyone creating or distributing content for EU audiences needs to understand Article 50. Not as lawyers. As operators. Create a one-page checklist they run through before assets ship. Template: "Is this asset AI-generated? If yes, has disclosure been embedded and tested on mobile?"
Step 4: Disclose in production, not retrofit. Don't create assets without disclosure, then add labels in post. Build disclosure requirements into your creative brief, production workflow, and final QA. If an asset can't be disclosed cleanly, it shouldn't be created for EU markets. If you're running a TikTok campaign for an EU brand using Midjourney backgrounds, the disclosure goes into the caption at creation time — not added after 100K views.
The EU AI Act applies to U.S. companies whose AI content is used in the EU. Not: companies with European offices. Not: companies selling in EU markets (though that applies too). The trigger is simpler: is your AI work reaching European persons?
If your brand sells globally and an EU customer sees AI-generated product marketing, you're in scope. If your agency runs a campaign targeting European audiences with AI-enhanced creative on Meta or Google, you're in scope. If your GEO work optimizes EU-market queries with AI-generated content for retrieval by ChatGPT, Claude, Gemini, Perplexity, or Google AI Overviews, you're in scope.
The act applies regardless of where you're incorporated or where your data is stored. California's parallel AI transparency law (August 2, 2026) covers U.S. brands and agencies operating domestically, creating a dual-jurisdiction compliance regime for many companies.
Map your EU exposure this week. Which campaigns touch EU audiences? Which client work serves European users? Which internal AI tools produce outputs destined for EU distribution? Which GEO work targets EU search behavior?
For each: document compliance status. Is disclosure live? Is the vendor Article 50 compliant? Who approved the disclosure framework? When was it last audited?
The carve-out that saves you sometimes: AI-generated text (not images, not video — text only) escapes disclosure if it received meaningful human review and editorial control before publishing. A human editor who reviewed, approved, and took accountability for the final output creates a shield. That human must be named, and the edit process must be documented. "Meaningful" is enforcement-ready language. Don't test it. Document heavily. The European Commission's draft guidance (June 2026) suggests senior review with decision authority is the standard.
December 2 Watermarking: Building the C2PA Stack Now
December 2, 2026 is the deadline for machine-readable watermarking — the technical requirement that AI-generated content carries metadata readable by verification tools and platforms.
This is a four-month deferral from August 2 for systems already on the market. New generative AI systems deployed after August 2 must include watermarking from day one. If you're using Midjourney, Runway, or Adobe Firefly for new work starting today, assume watermarking requirements apply immediately.
Don't read December 2 as breathing room. The industry is consolidating around C2PA — the Coalition for Content Provenance and Authenticity standard. Adobe, Microsoft, Google, OpenAI, and Meta are aligning to it. Adopting C2PA now (before December 2) means you're building the stack once, not retrofitting under enforcement pressure in November.
Vendor-specific C2PA status (as of August 8, 2026):
Supporting C2PA: Adobe Firefly (Microsoft partnership), Microsoft Designer (OpenAI alignment), Google Imagine, OpenAI APIs (beta).
Not yet supporting C2PA: Midjourney (signals support coming), Runway (no public timeline), Sora (Microsoft owns, likely by Dec 2), ElevenLabs (audio focus, lower priority), Synthesia (video, in progress).
For Midjourney and Runway users: Those platforms don't natively embed C2PA watermarks. That means you're responsible for marking outputs before they distribute. Build that into your workflow. Write watermarking responsibility into your production briefs. Don't assume the vendor handles it — they don't.
For Adobe Firefly and Microsoft Designer users: Both platforms are moving toward C2PA support. Verify current compliance status with the vendors directly. Don't assume it's there because Microsoft or Adobe are on the C2PA board.
The Liability Stack: Who Pays When Enforcement Finds a Breach
If your agency creates AI content: You're liable for disclosure compliance. If you hand a non-compliant asset to a client, your liability doesn't disappear. You created it. The brand may be liable to consumers; you're liable for creating non-compliant output.
If your client publishes AI content you created without proper disclosure: You share liability. The European Commission can fine the deployer (the brand). But the producer (you) can be held contributory negligent if the breach traces to your work. Indemnification clauses help, but they don't erase your risk exposure. Read your contracts now.
If your vendor's tool is non-compliant: Your outputs from that tool are non-compliant. The vendor's liability doesn't shield you. You created the asset using their tool. You distributed it. You're on the hook. Vendor indemnification is rare and usually limited. Read your vendor agreements now. Midjourney's TOS (last updated June 2026) provides no indemnification for Article 50 breaches.
If a client uses your AI asset for a purpose you didn't anticipate: You may still be liable if the use was foreseeable. A product image generated in Midjourney, disclosed for one campaign, then repurposed for EU social media without disclosure — your liability exposure extends to that secondary use if it was reasonably foreseeable.
The only safe position: Document everything. Disclose proactively. Audit vendors. Train teams. When enforcement comes, enforcement officers will ask: "Did you know your vendor wasn't compliant?" The answer "No" is not a defense. "Yes, and here's what we did about it" is documentation that you exercised reasonable care and are defensible.
Your August-Through-December Compliance Checklist
THIS WEEK (August 8–14):
- Audit all active and planned campaigns for AI-generated or AI-modified assets.
- Document which tools (Midjourney, Runway, Adobe Firefly, etc.) created which assets.
- Test your disclosure labels on mobile across platforms (TikTok, Instagram, YouTube, email, web).
- Identify which assets are non-compliant. Pause them for EU distribution immediately.
- Read your vendor contracts. Do they include Article 50 compliance warranties or indemnification clauses? Flag for legal review if not.
BY AUGUST 31:
- Build a vendor evaluation checklist (questions above). Score each platform you use.
- Train creative, paid-media, influencer, and GEO teams on Article 50 obligations.
- Document the disclosure framework you're using (icon, label, caption line, link). Publish it internally so teams know the standard.
- Establish a QA process: every asset destined for EU audiences must pass a compliance audit before it ships.
- Create a vendor audit report for leadership. Which tools are safe? Which need disclosure wrappers? Which should be retired from EU work?
BY DECEMBER 1:
- Adopt C2PA as your production-side watermarking standard. Integrate it into creative workflows.
- Audit all assets from August 2–December 1 to ensure C2PA compliance or add manual watermarking where needed.
- Document your compliance posture. When enforcement comes, enforcement officers will ask: "What did you do to comply?" Have an answer that shows intent, process, and documentation.
- Brief your board or executive team on Article 50 and California AI Transparency Act compliance status.
The Enforcement Reality: First Fines Land by October
The European Commission AI Office began enforcement August 2. National authorities in EU member states are standing up enforcement units. Fines for Article 50 disclosure violations range from €15 million to 3% of global turnover — whichever is higher. Prohibited practices (AI in high-risk domains like law enforcement or child-facing applications) reach up to €35 million or 7% of turnover.
Enforcement typically follows a pattern: visible large companies first, public examples next, market deterrence through examples. The firms that move now — that document compliance, audit vendors, train teams, build disclosure frameworks — will look reasonable if enforcement reaches them. The firms that don't will look negligent.
The cheapest compliance is the one built before enforcement begins.
Read Alongside This Playbook
Law Firms Own the Answer on EU AI Rules. PR Is Missing. The 5W AI Visibility Index research showing how to win this conversation inside ChatGPT, Claude, Gemini, Perplexity, and Google AI Overviews.
The EU AI Act Extraterritorial Stress Test — Strategic framework for understanding jurisdiction, enforcement scenarios, and communications posture.
The EU AI Act's December 2 Deadline: What Marketers Must Know About AI Content Watermarking — Technical deep-dive on C2PA, watermarking standards, and vendor compliance.
5W AI Visibility Index Audit — Full research at 5wpr.com/research.