What changed on 2 August for AI-generated ad disclosure
Two regulators converged on the same date. On 2 August 2026, the European Union began enforcing the transparency obligations of its Artificial Intelligence Act (EU AI Act), and California's AI Transparency Act became operative on the exact same date. That alignment is not a coincidence of the calendar. It is the moment AI-generated ad disclosure stopped being a brand-safety nicety and became a legal object with a penalty attached.
The European Commission notice, dated 31 July 2026, is blunt about the shape of it. Under Article 50, chatbots must tell people they are AI, deepfakes and AI-altered image, audio, and video must be labelled, and generative systems must mark their outputs so the content can be detected as machine-made. For anyone running Advantage+ images, TikTok Symphony video, Performance Max auto-assets, or any generated-image ad, the second and third items are the ones that land. The synthetic ad is now a disclosure-and-provenance object.
We already published the full obligations overview back in July, before enforcement, as the general marketing map. This piece is narrower and later. It is the enforcement event, the California mirror that landed the same day, and the creative-specific watermarking mechanics an operator has to actually run. Where the earlier post explained the terrain, this one tells you what to do on Monday.
This is an operator's field guide, not legal advice. The bands, roles, and checklist below are our reading of public regulation to help you scope exposure. Confirm your specific obligations with qualified counsel before you rely on them.
Who is actually on the hook
The first mistake most teams make is assuming the obligation sits neatly in one place. It does not. Both regimes split responsibility across the chain, and the split is where the risk hides. Read the roles below as our operator interpretation of how the two laws distribute the duty, then map your own stack onto them.
Provider (the tool maker)
The company that builds the generative model or system. Under Article 50 the provider must mark outputs in a machine-readable format so they are detectable as AI-generated. California's law puts the heaviest load here: covered providers over one million monthly visitors or users must embed a hidden provenance watermark, offer a visible disclosure option, and run a free detection tool.
Deployer (you, running the creative)
The party that puts AI-generated content in front of people. Most advertisers occupy this role. Under Article 50, a deployer who publishes a deepfake or AI-manipulated ad must disclose that it is artificially generated or manipulated, and that duty holds even when the tool did the marking.
Advertiser and agency (the accountable buyer)
Whoever owns the campaign and the brand. The statutes speak in provider and deployer terms, but in practice the advertiser is the entity a regulator, a platform, or a plaintiff will contact. If your agency generated the creative and you ran it, you are both close to the deployer duty. Contracts should say who carries what.
Here is the practical read. If you use a large commercial tool that already marks its output, the provider duty is largely handled upstream, but the disclosure duty on a deepfake or a manipulated image still travels with you as the deployer. If you build creative with a smaller or in-house model that does not mark output, you have inherited a slice of the provider duty too. The comfortable assumption that "the platform handles it" is only half true, and the missing half is the labelling call on your own creative.
What machine-readable provenance means for an ad
Both laws lean on a phrase that sounds abstract until you see it in a file: machine-readable provenance. A visible "AI-generated" sticker is one layer, and it is the layer a human sees. The layer regulators actually care about is the invisible one, a durable, detectable record baked into the media so a machine can confirm how the content was made even after it has been cropped, re-encoded, or reposted.
The dominant standard for this is C2PA, the Coalition for Content Provenance and Authenticity, an open specification for attaching tamper-evident provenance data to a media file. A C2PA-tagged ad carries a small manifest: which tool produced it, whether AI was involved, and when. California's SB 942 describes the same shape in statute, requiring the hidden mark to convey the provider name, the system name and version, a timestamp, and a unique identifier. The EU points at the mechanism without naming a single vendor, leaving the exact technical standard to be settled through the Act's Code of Practice.
The tooling side is already moving toward this, which is the part operators underrate. TikTok's Symphony creative suite, per its own August 2026 product post, attaches AI labels, invisible watermarking, and C2PA Content Credentials to generated output. Meta and other large platforms have been layering similar provenance signals onto generative outputs. The direction of travel is one where the mark rides inside the asset by default. Your job as an operator is not to invent watermarking. It is to stop stripping it out and to know which of your tools do not add it in the first place.
One caution worth stating plainly. Provenance marking is a detectability mechanism, not a compliance certificate. A watermark tells a machine the content is AI-made. It does not, by itself, satisfy the separate human-facing disclosure duty on a deepfake, and it does not decide whether a given ad even needed a label. Those are judgement calls that sit above the plumbing.
The two regimes, side by side
The EU and California landed on the same day and the same core idea, but the mechanics differ in ways that matter for scoping. The table lays out the two so you can see where they overlap and where they diverge. Every figure and date here was confirmed against the primary source.
| Dimension | EU AI Act, Article 50 | California AI Transparency Act (SB 942 / AB 853) |
|---|---|---|
| Trigger | AI content or systems shown to people in the EU; deepfakes and AI-altered media in ads | A generative AI provider with more than one million monthly visitors or users, publicly accessible in California |
| Who carries the duty | Providers of generative systems (marking) and deployers who publish deepfakes (disclosure) | The covered generative AI provider (the tool maker), primarily |
| What mark is required | Machine-readable marking of AI output; a label on deepfakes and manipulated media | Hidden machine-readable provenance watermark carrying provider, system, timestamp, and a unique identifier |
| Visible disclosure | Deepfakes and manipulated content disclosed as artificially generated or manipulated | A visible disclosure option users can choose to attach, plus a free public detection tool |
| Penalty exposure | Up to 15 million euro or 3 percent of worldwide annual turnover (Article 99 mid tier) | Enforcement and civil remedies under the Act; a licence-revocation duty within 96 hours if a licensee disables disclosure |
| Effective date | 2 August 2026; under the EU AI Act's transitional provisions (the AI Omnibus package), systems already on the market are expected to have until 2 December 2026 to comply with the marking requirement, but confirm the enacted text before relying on this date | Operative 2 August 2026, as amended by AB 853 (delayed from 1 January 2026) |
Two things jump out. First, the EU splits the duty between provider and deployer, so an advertiser can be on the hook for disclosure even when the tool did the marking, while California concentrates the heavy load on the tool provider. Second, the penalty picture is asymmetric and easy to overstate. The 15 million euro or 3 percent figure is the EU transparency tier under Article 99. The louder 35 million euro or 7 percent number belongs to prohibited practices under Article 5, a different category that has nothing to do with labelling an ad. Getting that distinction right is the difference between a proportionate response and a panic.
Interactive: does this reach me?
Answer the three toggles below to get a heuristic exposure band and the obligation that most likely attaches. This is an informational scoping aid, not legal advice, and it does not read your account or your creative. It is a heuristic. Confirm your specific position with counsel.
Tick the boxes that apply and this box updates with your heuristic band.
Informational heuristic only. Not legal advice. Confirm obligations with qualified counsel.
If the widget does not load, the static table below carries the same logic. Find the row that matches your answers.
| AI creative? | EU audience? | Large CA-accessible GenAI tool? | Heuristic band | Obligation that likely attaches |
|---|---|---|---|---|
| No | Any | Any | Monitor | No creative-labelling duty today; watch for chatbot disclosure if you deploy AI agents |
| Yes | Yes | Yes | Likely in scope | Deepfake and manipulated-media disclosure plus machine-readable provenance across both regimes |
| Yes | Yes | No | Likely in scope | EU Article 50 disclosure and provenance marking on your AI creative into EU audiences |
| Yes | No | Yes | Partial | California provenance-watermark expectations flow through your tool; verify its disclosure output |
| Yes | No | No | Monitor | Build provenance hygiene now; no in-force EU or California trigger on these answers |
The five-market read
leapbuzz operates across Singapore, Malaysia, Australia, the US, and Canada, so "does this apply to me" rarely has a single-country answer. The honest position in August 2026: the EU and California are the two live, enforceable regimes, and the other markets are signals rather than statutes. That does not make them irrelevant. It makes the EU the standard to build to.
The EU rule reaches by audience. Any advertiser serving impressions into European placements is within the practical scope of Article 50 expectations on our reading, whether that advertiser sits in Kuala Lumpur or Toronto. California is the US bellwether, and its structure, a hidden provenance mark plus a visible disclosure option plus a public detection tool, is the template other US states tend to borrow. AB 853 also staggers later duties, with large online platforms expected to surface provenance from January 2027 and capture-device makers from 2028, so the California surface widens over time rather than freezing. Verify the enacted AB 853 text for the exact platform thresholds and operative dates before calendar-planning around them.
Elsewhere the picture is governance-by-guidance, not hard ad law. Singapore runs AI oversight through the Personal Data Protection Act and its model AI governance framework rather than a synthetic-media ad-labelling statute. Australia and Canada have advanced AI-governance proposals and clear content-authenticity interest, but not an identical in-force rule as of this writing. Malaysia is developing its own AI guidance. The pattern across every one of these regulators favours provenance and disclosure over outright bans, which is why the pragmatic multi-market move is to build to the strictest live standard once and let the rest catch up to a system you already run. We treat this as forward-looking method-level reading, not a claim that these countries have an operative ad-labelling law today.
The Monday checklist
Enough context. Here is what an operator does this week. None of it requires a lawyer to start, though a few items end with one.
- Inventory your AI creative. You cannot label what you have not counted, so start here. List every campaign running AI-generated or AI-altered assets: Advantage+ images, Symphony video, Performance Max auto-assets, synthetic voice, generated stills.
- Map each asset to an audience. Flag anything that serves EU placements and anything produced by a large California-accessible generative tool. Those two flags are your trigger set. Use the self-check above as the first pass.
- Confirm your tools mark their output. Does each generative tool embed provenance such as C2PA Content Credentials and offer a disclosure option? Check. Where a tool does not, you have inherited part of the marking duty yourself.
- Stop stripping provenance. Audit your production and trafficking steps for anything that re-encodes or scrubs metadata and kills the watermark. This is the most common own goal, and it is the cheapest to fix.
- Decide your disclosure standard. One house rule for how deepfakes and manipulated media get labelled. Consistent, not per-campaign improvisation. Write it down.
- Use the marking runway, do not lean on it. Under the EU AI Act's transitional provisions (the AI Omnibus package), systems already on the market are expected to have until 2 December 2026 to comply with the marking requirement, but confirm the enacted text before relying on this date. This is a runway to fix provenance plumbing, not a pass to run unlabelled AI creative into EU audiences through the autumn.
- Put it in contracts, then confirm with counsel. If an agency generates your creative, state who carries the provider and deployer duties. Then have qualified counsel pressure-test your specific exposure before you rely on any of the above.
None of this is exotic once the inventory exists. The teams that struggle are the ones that discover, three campaigns deep, that nobody can say which ads were AI-made or whether the provenance survived trafficking. If AI creative is now a routine part of how you run paid media, this is the operating discipline that keeps it from becoming a liability. We do this build for teams who would rather wire it in once than react to the first regulator letter. Start with our services, and for the wider LLM-and-regulated-data picture see our note on LLM marketing data risks. If you also run AI on Google surfaces, pair this with the Google Ads transparency-labels read and the Meta Advantage+ creative breakdown.
