The CEO of a marketing agency running campaigns for EU audiences should have every AI-made image, video and audio asset checked against the AI Act's deepfake test before release, and labelled if it meets that test, because Article 50 of the AI Act has put that disclosure on the agency using the AI tool since 2 August 2026.
The Commission's AI Act Service Desk says transparency obligations will enter into application and be enforceable from 2 August 2026, with one grace period: providers of AI systems placed on the market before that date have until 2 December 2026 for the marking and detection duty in Article 50(2). That grace period came from the Digital Omnibus on AI, in force since 27 July 2026, which added no other.
A deployer is anyone using an AI system professionally under its authority. The Commission's questions and answers name an advertising company as an example, still the deployer when contractors or freelancers operate the system under its responsibility and control. Its guidelines of 20 July 2026 add that a company that merely commissions an advertising agency, without taking decisions and exercising control over whether and how the agency uses AI, is outside the definition.
The AI vendor carries a separate duty, the machine-readable mark, and the Commission states that deployers cannot simply rely on the machine-readable marking embedded in the content by the provider. The label has to be perceivable by a person without technical tools, at first exposure at the latest.
Under Article 3(60), a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The non-binding guidelines sort advertising both ways: an AI-generated celebrity influencer in an advertising or promotional context counts, as does a product image that can mislead as to the product's actual appearance, characteristics or use, while colour correction and clearly aesthetic background changes in product advertisements likely fall outside. A deepfake in an evidently artistic, creative, satirical, fictional or analogous work needs only a disclosure that does not hamper the display or enjoyment of the work, and advertisements might be regarded as evidently creative or fictional works in certain, specific situations, but not in others, with the categories read strictly.
In month one, the head of production should list every AI tool staff and freelancers use, and every AI-made asset generated since 2 August for EU audiences. In month two, each AI-made asset gets one approval record: the producer notes whether it meets the definition, and why if the lighter creative disclosure is claimed, and the account director signs before release, using the EU's set of icons that deployers of generative AI systems may use to label their AI-generated content or another clear label. In month three, client and media contracts should require partners to keep the label in place where the audience first sees the asset, a contractual measure the guidelines name for complex production and distribution chains. The chief operating officer owns the record.
The check can stop at advertising and product description text without claims on health, consumer safety or sustainability, which the guidelines place outside the text duty, and at content generated before 2 August 2026, which needs no retroactive label, though the Commission encourages one. National market surveillance authorities do most of the enforcing, and the Commission puts fines at up to 15 million euros or 3% of total worldwide turnover for the preceding financial year, whichever is higher, and whichever is lower for small and medium sized and small mid-cap enterprises.