Which AI Disclosure Rules Actually Apply to You?
Most of the AI-disclosure rules brands worry about are addressed to AI providers and platforms, not advertisers. Here is which ones are actually yours, and at which moment each one binds.

This is general information, not legal advice. It describes published platform policies, statutory text and industry guidance verified as of September 2026. Obligations differ by jurisdiction, channel and fact pattern, and they are changing. Consult your own counsel before changing a contract or a workflow.
Between June and September 2026, four separate AI-disclosure regimes came into effect or were published. Most brands have read about all four and concluded they are subject to all four. Most are not.
Two of them are addressed to the companies that build AI systems and the platforms that distribute their output. If you are a consumer brand running creator content, those are not your obligations, and preparing for them is wasted effort. The remaining set is shorter, more specific, and harder to satisfy after the fact, because at least one of them has to be met before a file is uploaded.
The sorting question is: who is each rule addressed to?
Answer that first, and the compliance problem becomes tractable.
The answer capsule
AI-disclosure obligations split by who they bind. The EU AI Act's Article 50(2) marking requirement and California's AI Transparency Act bind AI providers and large platforms, not advertisers.
What binds a brand running creator content is narrower: Amazon's metadata requirement before upload, YouTube's branded-content declaration, New York's synthetic-performer disclosure where the advertiser has actual knowledge, the EU's deepfake disclosure duty on deployers, and the FTC's existing rules on material connections.
Cohley's position: disclosure is an accountability problem, not a labeling problem. A brand cannot disclose what it does not know, and it will not know unless the brief asks, the agreement commits, and the approval verifies. For the separate question of whether to use AI content at all, see AI-generated UGC vs real creators. This article assumes that decision is made and asks how you prove which is which.
Who is each rule addressed to?
Two of the four regimes do not bind advertisers at all.
- EU AI Act Article 50(2) — machine-readable marking of synthetic outputBinding, EUProviders of AI systems: those who develop them and place them on the EU marketNo. This is the AI vendor's obligation
- EU AI Act Article 50(4) — deepfake disclosureBinding, EUDeployers: legal persons using an AI system under their authority. The Commission names an advertising company as an exampleYes, if you operate in the EU
- California AI Transparency Act, as amended by AB 853Binding, CaliforniaProviders of generative AI systems above 1,000,000 monthly users; large online platforms; GenAI hosting platforms; web browsers; capture-device manufacturersNo. Advertisers are not a covered entity
- New York GBL §396-b — synthetic performer disclosureBinding, New YorkThe business that produces or creates the advertisement, where it has actual knowledge
- Amazon's metadata requirementPlatform policy, worldwide storesSellersYes, if you sell on Amazon
- YouTube branded content policyPlatform policyCreators, with consequences reaching the channelIndirectly — the duty sits with your creator
- FTC 16 CFR Part 255Binding, USAdvertisers and endorsersYes — and this is about the commercial relationship, not AI
- IAB AI Transparency & Disclosure Framework V2Voluntary industry guidanceThe advertising ecosystem generallyOnly if you adopt it
Two clarifications this table exists to make.
California's AB 853 is not an advertiser law. It was signed on October 13, 2025 as Chapter 674, amending the California AI Transparency Act originally enacted as SB 942. Its principal effect for present purposes was to move the Act's operative date from January 1, 2026 to August 2, 2026, deliberately aligned with the EU. What it requires is latent and manifest disclosures and a free AI detection tool from covered generative AI providers, and from January 1, 2027, provenance detection and display obligations on large online platforms. A brand running creator content is none of those.
The IAB document is guidance, not law, every time it comes up. The IAB published its AI Transparency & Disclosure Framework V2 on August 18, 2026.
It is worth reading: it takes a risk-based, materiality-driven approach and covers AI-generated and AI-assisted text, imagery, video, audio, synthetic voices, digital twins and AI-powered consumer interactions, with use-case triggers and disclosure principles. It also explicitly tries to balance transparency against disclosure fatigue, which is a more honest framing than most.
None of it is binding.
A note on naming: the document's own title and PDF call it a Framework, while the IAB's URL and site menu call it Standards. Cite it as the Framework.
What actually lands on you
Four obligations, four enforcing parties, three different moments in the production process.
- Amazon listing image, video or A+ ContentA photorealistic AI-generated person appearsThe keyword contains-synthetic-performer written into the file's dc:subject XMP field with an IPTC-compatible metadata editorAmazon, through listing and image policiesBefore upload
- YouTubeBranded content, including content given in exchange for free product or a deferred benefitCreator declares paid promotion in YouTube Studio; YouTube may apply a label automatically if its systems detect undisclosed branded contentYouTube, through removal, age restriction, and channel and Partner Program consequencesAt upload
- An advertisement shown to a New York audienceA synthetic performer appears and the business producing the advertisement has actual knowledgeConspicuous disclosure within the advertisementNew York GBL §396-b; civil penalty of $1,000 for a first violation, $5,000 for each subsequent oneAt publication
- Content deployed in the EUThe content is a deepfake as the AI Act defines itClear, perceivable disclosure to the person on first exposure at the latestNational market surveillance authorities; fines up to €15 million or 3% of total worldwide turnoverAt first exposure
- Paid social generallyA material connection between brand and endorserClear and conspicuous disclosure of the connectionFTCAt publication
Amazon's is the hardest, because it happens before upload
This is a file operation performed on the asset, not a label applied at publication.
Amazon notified third-party sellers on July 22, 2026. Where a photorealistic AI-generated person appears in a listing image, product video or A+ Content, the exact keyword contains-synthetic-performer must be written into the dc:subject XMP field of the file, using a metadata editor supporting IPTC-compatible embedded metadata, before the file is added to the listing. Amazon then surfaces an indicator to customers where applicable. The requirement applies across Amazon's worldwide stores.
The keyword is exact and the field is specific.
Metadata also does not reliably survive an export: a file tagged in one application and then flattened or re-exported through another can arrive without it. If your creative passes through a retoucher, an agency, a resizing step or a DAM, the tag needs verifying on the final file, not the working file.
Amazon's published guidance carves out four cases:
- Media containing only real people, even where AI tools were used to edit them
- Media containing characters from movies, television, streaming content, documentaries, video games or other expressive works
- Media containing no people
- Media containing people who are not photorealistic
For teams running creator content onto retail surfaces, the consequence is that the disclosure decision has to be made by someone who knows how the asset was produced, before the file moves. Your PDP approval queue sits downstream of the only moment the question can be answered.
YouTube's definition captures product seeding
If you send product to a creator, YouTube's branded content policy applies, and the declaration duty sits with the creator.
YouTube defines branded content as content influenced by a brand partner in exchange for something of value, and names free products and benefits received later as examples. The policy applies wherever the content appears, including videos, descriptions, comments, live streams and Shorts, and YouTube states it applies to the entirety of the content rather than only the portion featuring the brand.
If you run a product seeding program, that is your program. Seeded creators receive product with no separate fee, post organically, and may not consider themselves to be in a paid relationship at all. Under this policy they have a declaration to make.
YouTube also states that where its systems detect undisclosed branded content, it may apply a label automatically and notify the creator, who may have the option to certify that the video does not contain branded content and override it. YouTube does not publish the signals its systems use or their error rate, and the override is described as something a creator may have rather than will have.
Separately, Google Ads prohibited and restricted category rules now reach branded content that is not itself an ad. Alcohol, financial services, healthcare and medicines, gambling, and elections and political content carry additional restrictions, and the creator is responsible for confirming that brand partners hold the relevant Google certification. If you are in a regulated category and you seed, that is a requirement you have pushed onto a creator who does not know it exists.
The EU: you are a deployer, and the provider's mark does not discharge your duty
The obligation that binds you is deepfake disclosure, and you cannot satisfy it with metadata.
Article 50 of the AI Act has applied since 2 August 2026. The Commission's own guidance draws the line clearly. Providers develop AI systems and place them on the EU market, and they carry the machine-readable marking obligation under Article 50(2). Deployers use AI systems under their authority, and the Commission gives an advertising company as its example of a deployer.
Your obligation is Article 50(4): clear disclosure of deepfake content to the person exposed to it, on first exposure at the latest.
Four points that matter operationally.
The marking does not count as your disclosure. The Commission states directly that deployers cannot simply rely on the machine-readable marking embedded by the provider to fulfill their own disclosure obligation. Content Credentials, watermarking and provenance metadata are all useful. None of them is the disclosure.
Your creators may not be separate deployers. Where the deployer is a legal person, employees acting under its instruction and control are not separate deployers, and the Commission states that a legal person remains the deployer even where contractors or freelancers are involved in operating the system on its behalf and under its responsibility and control. A creator operating independently and gaining economic benefit regularly is a deployer in their own right. Which of those describes your relationship is a question for counsel, and it is the question that determines where the obligation sits.
Standard editing is carved out. The marking obligation does not apply where the AI system performs an assistive function for standard editing. That is the same line Amazon draws between a real person edited with AI and a person generated by it. Two regimes, one distinction, which is convenient for anyone building a single policy.
Not everything synthetic is a deepfake. The AI Act's definition requires three cumulative conditions: a high level of resemblance, a subject that exists or could plausibly exist, and content that would falsely appear to be authentic or truthful. The Commission's guidance allows the intended audience and deployment context to bear on the third condition. Whether a given creator ad meets all three is a judgment, not a lookup.
Two dates worth knowing.
A limited grace period runs to 2 December 2026, but only for AI systems placed on the market before 2 August 2026 and only for the Article 50(2) marking obligation, which is a provider's relief rather than an advertiser's. And content generated before 2 August 2026 does not have to be labeled retroactively, though the Commission encourages it. That is a meaningful answer to the back-catalogue question in the EU, and it is narrower than it looks: it addresses generated content, not your other obligations.
Why disclosure is an accountability problem
You cannot disclose what you did not ask about, and every one of these rules assumes you know.
New York's statute conditions the duty on the producing business having actual knowledge that a synthetic performer appears. A reader could draw exactly the wrong conclusion from that, namely that the safest posture is to avoid finding out. Whether a deliberate absence of inquiry protects anyone is a question for counsel, and we are not going to characterize it.
The reasoning fails on its own terms regardless. Amazon's requirement is not conditioned on your knowledge; it is a file that is either tagged or not. YouTube's sits with the creator, and YouTube may label the video whatever you know. A brand organized not to know still has an untagged file on a PDP and a mislabeled video on a channel.
So capture the fact where it is knowable, from the person who knows it. A written attestation from the creator, at delivery, recorded against the asset. Not a checkbox in an approval tool three steps downstream where the only available answer is a guess.
The burden is probably lighter than it feels. CreatorIQ's 2026 creator survey, run with Influencers.club across roughly 5,000 creators, reported that 72% of creators have used AI tools but only about 5% use them to generate images or visuals. That is CreatorIQ's finding about its own survey population rather than an independent market measurement. If the direction is right, most attestations will be a single honest "no," and the workflow cost of asking is small relative to what you get, which is a record.
One thing automated checking does not do is settle this for you. Cohley's published position on what automated asset checks can and cannot evaluate is deliberately bounded, and rights and provenance sit on the wrong side of that boundary: a determination about permission or origin is a judgment about facts outside the file, not an observation about the file. Automated checks are a filter in front of your queue. They are not compliance, and they do not replace human review.
What to change in your brief and your contract
At the brief stage, the question is whether the brief asks in terms specific enough that the answer is observable rather than interpretive. The discipline that makes content requirements enforceable applies here. "No AI" is not a requirement anyone can apply consistently, because AI editing, AI backgrounds and AI-generated people are different things under every regime above.
Requirements that name the thing are answerable: whether a synthetic human likeness may appear; whether AI editing of a real person is permitted; whether AI-generated backgrounds or environments are permitted; whether synthetic voice is permitted.
At the contract stage, the topics for counsel are an attestation as to whether a synthetic performer or synthetic voice appears; a representation about which AI tools were used and for what; an obligation to make the platform-side declaration where the creator is the party who must make it, as on YouTube; and a notification duty if the answer changes after delivery.
At the delivery stage, the attestation needs to sit against the asset rather than in an email thread, because the value of a record is that it survives staff turnover and can be produced later. Brief Analysis reviews requirements before a Brief goes out, which is the cheapest moment to find that the brief never asked.
A starting policy by content type
A starting point for the Legal conversation, not an approved policy.
- Fully humanNone beyond existing endorsement disclosureConfirm no generative AI used in the deliverableAttestation on file
- AI-assisted editing of real footage or a real personGenerally outside Amazon's metadata rule and outside the EU marking obligation as standard editingWhich tools, applied to whatThat the edit did not cross into generating a person
- AI-generated elements that are not peopleNo synthetic-performer trigger; check the ad's overall truthfulnessWhether backgrounds or environments were generatedThat the product is still depicted accurately
- AI-generated photorealistic personAmazon metadata before upload; NY disclosure where applicable; EU deepfake assessmentExplicit yes/no, mandatoryMetadata present on the final file; in-ad disclosure where required
- Synthetic voice or likeness of a real personHighest scrutiny; rights and publicity issues beyond disclosureWhose likeness, what consent existsCounsel review before activation
Auditing what is already in market
Triage by destination and by risk. Do not attempt asset-by-asset review of a back catalogue.
- Amazon surfaces first. Narrowest population, binary requirement, and metadata presence can be checked programmatically against the files you hold.
- Advertisements running in New York. The statute reaches advertisements and the business producing them.
- EU-deployed content. Content generated before 2 August 2026 does not require retroactive labeling, which narrows this considerably.
- Creator relationships that produced YouTube content. The declaration duty sits with the creator, so this is a communication task, not a file task.
- Separate assets where a synthetic human likeness could plausibly appear from those where it could not. Most product photography and most creator video contains a real person or no person.
- Where provenance is unknown and cannot be reconstructed, the decision is a risk decision for counsel, not a content decision.
Step 6 is the cost of solving this at publication rather than at the brief. If nobody captured the attestation at creation, it may not be recoverable, particularly where the relationship has ended.
What is still unclear
More than the vendors in this category will admit.
YouTube does not publish the accuracy of its automated branded-content detection, the signals it uses, or how a creator contests a label beyond stating they may have the option to override. Its published policy addresses content going forward and does not describe back-catalogue treatment.
Amazon states it will display an indicator "where applicable" without fully specifying what makes it applicable, and has published no grace period or penalty specific to missing AI metadata. Its general image policies already permit removal of non-compliant images and suppression of listings.
No enforcement action under New York GBL §396-b has been identified as of September 2026. The statute exempts the advertising medium itself, along with audio advertisements, cases where AI is used solely for language translation of a human performer, and advertising for expressive works where the use is consistent with the work.
In the EU, Article 50 enforcement sits mainly with national market surveillance authorities, which means practice may differ by member state before it converges.
And this is not an exhaustive list. It is the set verified as of September 2026 for these destinations. Other jurisdictions and other platforms have their own.
Frequently asked questions
Do brands have to disclose AI-generated ads?
It depends on the destination and on what the AI generated. There is no general US federal requirement to disclose AI use in advertising. Specific duties apply: Amazon requires metadata on media containing photorealistic AI-generated people, New York requires in-ad disclosure of a synthetic performer where the advertiser has actual knowledge, and in the EU a deployer must disclose deepfake content. AI used for standard editing of real footage generally sits outside these.
Does the FTC require AI disclosure?
The FTC's endorsement rules at 16 CFR Part 255 require disclosure of material connections between an advertiser and an endorser. That is a rule about the commercial relationship, not about whether AI was used. It applies to creator content regardless of how the content was made.
What does the EU AI Act require for advertising content?
Article 50 has applied since 2 August 2026. For a brand, the relevant obligation is as a deployer: clear disclosure of deepfake content on first exposure at the latest. The machine-readable marking obligation under Article 50(2) falls on providers of AI systems, not on advertisers, and a deployer cannot rely on that marking to satisfy its own disclosure duty.
Does California's AB 853 apply to my brand?
Almost certainly not directly. AB 853 amended the California AI Transparency Act and moved its operative date to 2 August 2026. Its obligations fall on providers of large generative AI systems and, from 1 January 2027, on large online platforms, GenAI hosting platforms, web browsers and capture-device manufacturers. A consumer brand running creator advertising is not a covered entity.
Who is responsible if a creator uses AI without telling the brand?
That depends on the regime and on the relationship. Under the EU AI Act, a legal person remains the deployer even where contractors or freelancers operate the system on its behalf and under its control, while a creator acting independently for regular economic benefit is a deployer in their own right. New York's statute conditions the advertiser's duty on actual knowledge. Amazon's requirement is not conditioned on knowledge at all. Which of these describes your situation is a question for counsel, and it is the reason the attestation belongs in the agreement.
Should a creator brief ask about AI use?
Yes, and specifically rather than generally. "No AI" cannot be applied consistently because AI editing, AI-generated environments and AI-generated people are treated differently under every regime above. Ask whether a synthetic human likeness may appear, whether AI editing of a real person is permitted, and whether synthetic voice is permitted.
Is AI-assisted editing the same as AI-generated content?
Not under these rules. Amazon's requirement excludes media containing only real people even where AI tools were used to edit them. The EU's marking obligation does not apply where the AI system performs an assistive function for standard editing. The line that matters is whether a person was generated, not whether AI touched the file.
Does using a creator platform make me compliant?
No. No platform can make a brand compliant, and any vendor suggesting otherwise is describing something that does not exist. Disclosure obligations attach to the advertiser and, in some cases, to the creator. A platform can help you ask the question, capture the answer and keep the record. The obligation remains yours.
Next step
The first question is not which assets are non-compliant. It is whether your current workflow could produce the record if you were asked for it. If the answer is no, that is a brief-stage change rather than an audit. Talk to us about creator content governance.
See Cohley in action
Schedule a 30-minute demo. Led by a product expert.

