Strategy

AI-generated ad disclosure: the Aug 2 rules, explained

The Aug 2 enforcement event, not the general overview. Two regimes went live the same day: what changed, who is on the hook, what a C2PA watermark means for an ad, and a Monday checklist across five markets.

Two overlapping jurisdiction arcs bridged by a wavy provenance thread with small nodes and one solid orange node, cream paper, ink line style, no text.

Bottom line

On 2 August 2026, two regulations governing AI-generated content went live the same day on two continents. If you run AI-generated creative, the synthetic ad is now a disclosure-and-provenance object, not a free lunch.

  • EU AI Act Article 50 transparency rules began being enforced 2 August 2026, per the European Commission notice dated 31 July 2026.
  • Deepfakes must be labelled and generative outputs must carry machine-readable provenance marks; a breach sits in the up-to 15 million euro or 3 percent of turnover tier.
  • California's AI Transparency Act (SB 942, as amended by AB 853) became operative the same day, requiring hidden provenance watermarks plus a visible disclosure option.
  • Under the EU AI Act's transitional provisions (the AI Omnibus package), systems already on the market are expected to have until 2 December 2026 to comply with the marking requirement; confirm the enacted text before relying on this date.
  • The reach follows the audience, not the head office, so any advertiser touching EU or California users should run the self-check below.

What changed on 2 August for AI-generated ad disclosure

Two regulators converged on the same date. On 2 August 2026, the European Union began enforcing the transparency obligations of its Artificial Intelligence Act (EU AI Act), and California's AI Transparency Act became operative on the exact same date. That alignment is not a coincidence of the calendar. It is the moment AI-generated ad disclosure stopped being a brand-safety nicety and became a legal object with a penalty attached.

The European Commission notice, dated 31 July 2026, is blunt about the shape of it. Under Article 50, chatbots must tell people they are AI, deepfakes and AI-altered image, audio, and video must be labelled, and generative systems must mark their outputs so the content can be detected as machine-made. For anyone running Advantage+ images, TikTok Symphony video, Performance Max auto-assets, or any generated-image ad, the second and third items are the ones that land. The synthetic ad is now a disclosure-and-provenance object.

We already published the full obligations overview back in July, before enforcement, as the general marketing map. This piece is narrower and later. It is the enforcement event, the California mirror that landed the same day, and the creative-specific watermarking mechanics an operator has to actually run. Where the earlier post explained the terrain, this one tells you what to do on Monday.

Not legal advice

This is an operator's field guide, not legal advice. The bands, roles, and checklist below are our reading of public regulation to help you scope exposure. Confirm your specific obligations with qualified counsel before you rely on them.

Who is actually on the hook

The first mistake most teams make is assuming the obligation sits neatly in one place. It does not. Both regimes split responsibility across the chain, and the split is where the risk hides. Read the roles below as our operator interpretation of how the two laws distribute the duty, then map your own stack onto them.

Provider (the tool maker)

The company that builds the generative model or system. Under Article 50 the provider must mark outputs in a machine-readable format so they are detectable as AI-generated. California's law puts the heaviest load here: covered providers over one million monthly visitors or users must embed a hidden provenance watermark, offer a visible disclosure option, and run a free detection tool.

Deployer (you, running the creative)

The party that puts AI-generated content in front of people. Most advertisers occupy this role. Under Article 50, a deployer who publishes a deepfake or AI-manipulated ad must disclose that it is artificially generated or manipulated, and that duty holds even when the tool did the marking.

Advertiser and agency (the accountable buyer)

Whoever owns the campaign and the brand. The statutes speak in provider and deployer terms, but in practice the advertiser is the entity a regulator, a platform, or a plaintiff will contact. If your agency generated the creative and you ran it, you are both close to the deployer duty. Contracts should say who carries what.

Here is the practical read. If you use a large commercial tool that already marks its output, the provider duty is largely handled upstream, but the disclosure duty on a deepfake or a manipulated image still travels with you as the deployer. If you build creative with a smaller or in-house model that does not mark output, you have inherited a slice of the provider duty too. The comfortable assumption that "the platform handles it" is only half true, and the missing half is the labelling call on your own creative.

What machine-readable provenance means for an ad

Both laws lean on a phrase that sounds abstract until you see it in a file: machine-readable provenance. A visible "AI-generated" sticker is one layer, and it is the layer a human sees. The layer regulators actually care about is the invisible one, a durable, detectable record baked into the media so a machine can confirm how the content was made even after it has been cropped, re-encoded, or reposted.

The dominant standard for this is C2PA, the Coalition for Content Provenance and Authenticity, an open specification for attaching tamper-evident provenance data to a media file. A C2PA-tagged ad carries a small manifest: which tool produced it, whether AI was involved, and when. California's SB 942 describes the same shape in statute, requiring the hidden mark to convey the provider name, the system name and version, a timestamp, and a unique identifier. The EU points at the mechanism without naming a single vendor, leaving the exact technical standard to be settled through the Act's Code of Practice.

The tooling side is already moving toward this, which is the part operators underrate. TikTok's Symphony creative suite, per its own August 2026 product post, attaches AI labels, invisible watermarking, and C2PA Content Credentials to generated output. Meta and other large platforms have been layering similar provenance signals onto generative outputs. The direction of travel is one where the mark rides inside the asset by default. Your job as an operator is not to invent watermarking. It is to stop stripping it out and to know which of your tools do not add it in the first place.

One caution worth stating plainly. Provenance marking is a detectability mechanism, not a compliance certificate. A watermark tells a machine the content is AI-made. It does not, by itself, satisfy the separate human-facing disclosure duty on a deepfake, and it does not decide whether a given ad even needed a label. Those are judgement calls that sit above the plumbing.

The two regimes, side by side

The EU and California landed on the same day and the same core idea, but the mechanics differ in ways that matter for scoping. The table lays out the two so you can see where they overlap and where they diverge. Every figure and date here was confirmed against the primary source.

EU AI Act Article 50 and the California AI Transparency Act, compared. Confirmed against primary sources, August 2026.
Dimension EU AI Act, Article 50 California AI Transparency Act (SB 942 / AB 853)
Trigger AI content or systems shown to people in the EU; deepfakes and AI-altered media in ads A generative AI provider with more than one million monthly visitors or users, publicly accessible in California
Who carries the duty Providers of generative systems (marking) and deployers who publish deepfakes (disclosure) The covered generative AI provider (the tool maker), primarily
What mark is required Machine-readable marking of AI output; a label on deepfakes and manipulated media Hidden machine-readable provenance watermark carrying provider, system, timestamp, and a unique identifier
Visible disclosure Deepfakes and manipulated content disclosed as artificially generated or manipulated A visible disclosure option users can choose to attach, plus a free public detection tool
Penalty exposure Up to 15 million euro or 3 percent of worldwide annual turnover (Article 99 mid tier) Enforcement and civil remedies under the Act; a licence-revocation duty within 96 hours if a licensee disables disclosure
Effective date 2 August 2026; under the EU AI Act's transitional provisions (the AI Omnibus package), systems already on the market are expected to have until 2 December 2026 to comply with the marking requirement, but confirm the enacted text before relying on this date Operative 2 August 2026, as amended by AB 853 (delayed from 1 January 2026)

Two things jump out. First, the EU splits the duty between provider and deployer, so an advertiser can be on the hook for disclosure even when the tool did the marking, while California concentrates the heavy load on the tool provider. Second, the penalty picture is asymmetric and easy to overstate. The 15 million euro or 3 percent figure is the EU transparency tier under Article 99. The louder 35 million euro or 7 percent number belongs to prohibited practices under Article 5, a different category that has nothing to do with labelling an ad. Getting that distinction right is the difference between a proportionate response and a panic.

Interactive: does this reach me?

Answer the three toggles below to get a heuristic exposure band and the obligation that most likely attaches. This is an informational scoping aid, not legal advice, and it does not read your account or your creative. It is a heuristic. Confirm your specific position with counsel.

Answer the toggles

Tick the boxes that apply and this box updates with your heuristic band.

Informational heuristic only. Not legal advice. Confirm obligations with qualified counsel.

If the widget does not load, the static table below carries the same logic. Find the row that matches your answers.

Static fallback for the self-check. AI creative refers to running any AI-generated or AI-altered ad.
AI creative? EU audience? Large CA-accessible GenAI tool? Heuristic band Obligation that likely attaches
No Any Any Monitor No creative-labelling duty today; watch for chatbot disclosure if you deploy AI agents
Yes Yes Yes Likely in scope Deepfake and manipulated-media disclosure plus machine-readable provenance across both regimes
Yes Yes No Likely in scope EU Article 50 disclosure and provenance marking on your AI creative into EU audiences
Yes No Yes Partial California provenance-watermark expectations flow through your tool; verify its disclosure output
Yes No No Monitor Build provenance hygiene now; no in-force EU or California trigger on these answers

The five-market read

leapbuzz operates across Singapore, Malaysia, Australia, the US, and Canada, so "does this apply to me" rarely has a single-country answer. The honest position in August 2026: the EU and California are the two live, enforceable regimes, and the other markets are signals rather than statutes. That does not make them irrelevant. It makes the EU the standard to build to.

The EU rule reaches by audience. Any advertiser serving impressions into European placements is within the practical scope of Article 50 expectations on our reading, whether that advertiser sits in Kuala Lumpur or Toronto. California is the US bellwether, and its structure, a hidden provenance mark plus a visible disclosure option plus a public detection tool, is the template other US states tend to borrow. AB 853 also staggers later duties, with large online platforms expected to surface provenance from January 2027 and capture-device makers from 2028, so the California surface widens over time rather than freezing. Verify the enacted AB 853 text for the exact platform thresholds and operative dates before calendar-planning around them.

Elsewhere the picture is governance-by-guidance, not hard ad law. Singapore runs AI oversight through the Personal Data Protection Act and its model AI governance framework rather than a synthetic-media ad-labelling statute. Australia and Canada have advanced AI-governance proposals and clear content-authenticity interest, but not an identical in-force rule as of this writing. Malaysia is developing its own AI guidance. The pattern across every one of these regulators favours provenance and disclosure over outright bans, which is why the pragmatic multi-market move is to build to the strictest live standard once and let the rest catch up to a system you already run. We treat this as forward-looking method-level reading, not a claim that these countries have an operative ad-labelling law today.

The Monday checklist

Enough context. Here is what an operator does this week. None of it requires a lawyer to start, though a few items end with one.

  1. Inventory your AI creative. You cannot label what you have not counted, so start here. List every campaign running AI-generated or AI-altered assets: Advantage+ images, Symphony video, Performance Max auto-assets, synthetic voice, generated stills.
  2. Map each asset to an audience. Flag anything that serves EU placements and anything produced by a large California-accessible generative tool. Those two flags are your trigger set. Use the self-check above as the first pass.
  3. Confirm your tools mark their output. Does each generative tool embed provenance such as C2PA Content Credentials and offer a disclosure option? Check. Where a tool does not, you have inherited part of the marking duty yourself.
  4. Stop stripping provenance. Audit your production and trafficking steps for anything that re-encodes or scrubs metadata and kills the watermark. This is the most common own goal, and it is the cheapest to fix.
  5. Decide your disclosure standard. One house rule for how deepfakes and manipulated media get labelled. Consistent, not per-campaign improvisation. Write it down.
  6. Use the marking runway, do not lean on it. Under the EU AI Act's transitional provisions (the AI Omnibus package), systems already on the market are expected to have until 2 December 2026 to comply with the marking requirement, but confirm the enacted text before relying on this date. This is a runway to fix provenance plumbing, not a pass to run unlabelled AI creative into EU audiences through the autumn.
  7. Put it in contracts, then confirm with counsel. If an agency generates your creative, state who carries the provider and deployer duties. Then have qualified counsel pressure-test your specific exposure before you rely on any of the above.

None of this is exotic once the inventory exists. The teams that struggle are the ones that discover, three campaigns deep, that nobody can say which ads were AI-made or whether the provenance survived trafficking. If AI creative is now a routine part of how you run paid media, this is the operating discipline that keeps it from becoming a liability. We do this build for teams who would rather wire it in once than react to the first regulator letter. Start with our services, and for the wider LLM-and-regulated-data picture see our note on LLM marketing data risks. If you also run AI on Google surfaces, pair this with the Google Ads transparency-labels read and the Meta Advantage+ creative breakdown.

Frequently asked questions

What is AI-generated ad disclosure?

It is the requirement to signal that an advertisement, or an element of it, was made or altered by artificial intelligence. From 2 August 2026 this stopped being an ethics preference and became law in two large markets at once. Under the European Union Artificial Intelligence Act (EU AI Act) Article 50, deepfakes and AI-manipulated media in ads must be labelled, and providers of generative systems must mark outputs in a machine-readable format. California's AI Transparency Act mirrors the idea with a hidden provenance watermark plus a visible disclosure option. The through-line is provenance: content should carry a durable, detectable signal of how it was made.

Does the EU AI Act reach advertisers outside Europe?

Effectively, yes, through audience reach rather than company address. Article 50 transparency obligations attach to systems and content placed on the European Union market or shown to people in it. If your campaign serves impressions to audiences in the European Union, the deepfake-labelling and provenance-marking expectations follow the content, not your head office. A business in Singapore, Sydney, or San Francisco running AI-generated creative into European placements is in the same practical position as a business in Berlin. This is why we treat any EU audience exposure as the trigger question, not where the advertiser is registered. That said, jurisdictional reach under EU law turns on specific facts, and this is our operator reading, not legal advice. Confirm how Article 50 applies to your specific structure with qualified counsel.

What does Article 50 of the EU AI Act actually require?

Three things, confirmed against the Act text. First, chatbots and interactive AI must tell users they are dealing with AI, at the latest at first interaction. Second, deepfakes and AI-altered image, audio, or video must be disclosed as artificially generated or manipulated. Third, providers of generative AI must mark outputs in a machine-readable format so they can be detected as AI-generated. For advertising, the second and third points are the live ones: a synthetic ad is now a labelled, provenance-carrying object. Technical standards for the marking are still being finalised through the Act's Code of Practice.

What is the penalty for breaching the EU transparency rules?

Under Article 99 of the EU AI Act, a breach of the Article 50 transparency obligations sits in the mid penalty tier: up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. That is a real number, though it is not the top tier. The 35 million euro or 7 percent band is reserved for prohibited AI practices under Article 5, which is a different category from transparency. For small and medium enterprises and start-ups, the Act caps the fine at whichever of the two thresholds is lower. We flag this because the two tiers get conflated in coverage, and the difference is large.

What does California's SB 942 require, and who does it cover?

The California AI Transparency Act, in the form amended by Assembly Bill 853, became operative on 2 August 2026, the same day as the EU rules. It covers a generative AI provider with more than one million monthly visitors or users that is publicly accessible in California. Covered providers must embed a hidden, machine-readable provenance watermark in AI image, video, and audio carrying provider and system details, offer a visible disclosure option users can attach, and run a free public detection tool. The obligation lands on the tool provider, but the labelled output is what flows into your ad account.

What is a C2PA watermark and why does it matter for ads?

C2PA stands for the Coalition for Content Provenance and Authenticity, an open standard for attaching tamper-evident provenance data to a media file. In practice, a C2PA-tagged ad carries a machine-readable record of the tool that made it and whether AI was involved, which detection tools and platforms can read. It matters because both regimes lean on machine-readable provenance rather than only a visible sticker. The platforms are already moving: TikTok's Symphony creative tools attach AI labels, invisible watermarking, and C2PA Content Credentials to generated output. That tooling is the mechanism the law is pointing at.

Is there a grace period before enforcement bites?

Partly. The core Article 50 obligations applied from 2 August 2026. A transitional runway exists for the machine-readable marking requirement on generative systems already on the market before that date: under the EU AI Act's transitional provisions (the AI Omnibus package), those systems are expected to have until 2 December 2026 to comply; confirm the enacted text before relying on this date. This is a runway for the marking mechanism on existing tools, not a general holiday from the labelling duty. Treat it as time to get provenance plumbing in order, not permission to run unlabelled AI creative into European audiences through the autumn.

Do Singapore, Malaysia, Australia, and Canada have the same rules yet?

Not in the same enforceable form as of August 2026, which is exactly why the EU and California moves matter as signals. Singapore governs AI through the Personal Data Protection Act and model AI governance guidance rather than a hard synthetic-media ad-labelling statute. Australia and Canada have advanced AI-governance proposals and content-authenticity interest but not an identical in-force ad rule. The pattern across regulators favours provenance and disclosure over bans. For a five-market operator, the practical move is to build to the strictest live standard, the EU, and let the others catch up to a system you already run.

Related

Work with leapbuzz

The self-check flagged exposure. Want AI-creative disclosure handled before it becomes a fine?

leapbuzz builds AI-native marketing operations for teams across Singapore, Malaysia, Australia, the US, and Canada. We map where your AI creative touches regulated audiences, wire provenance and labelling into the workflow, and keep the paper trail a regulator or CFO can read. This is operating design, not a one-page policy memo.

Talk to us