Bily Editorial Team
The Bily Editorial Team writes about advertising measurement, data quality, and the decisions they support.
Date
Read time
Read time

On 20 July 2026, the European Commission published new guidance and a detailed FAQ for Article 50 of the EU AI Act. The obligations apply from 2 August 2026.
For an ad team serving people in the EU, the first question is not simply whether AI touched the asset. The useful questions are who provided and deployed the system, what kind of content it produced, when it was generated, how it will be presented, and who owns the final disclosure decision.
This is an operational briefing, not legal advice. A qualified reviewer still needs to assess the actual system, asset, audience, and deployment context.
What the guidance separates
Providers of generative AI systems have a system-level duty to make covered synthetic audio, image, video, and text outputs machine-readable and detectable. The Commission also describes boundaries, including an exception when the AI system performs an assistive function for standard editing.
Deployers are the people or organisations using an AI system under their authority for professional activity. The Commission FAQ uses an advertising company as an example of a legal-person deployer. Employees or contractors acting under that company’s responsibility and control are not automatically separate deployers.
A deployer that uses covered deepfake content must disclose it clearly by the first exposure at the latest. The FAQ says a provider’s machine-readable mark is not, by itself, enough to fulfil that deployer disclosure duty.
AI-generated or manipulated text is treated differently again. The deployer labelling duty described by the Commission concerns published text intended to inform the public on matters of public interest. Substantive human review or editorial control can change whether that text-labelling duty applies; superficial proofreading does not count as substantive review.
The practical boundary: Article 50 does not create one universal visible-label rule for every AI-assisted advertisement. Role, content class, timing, context, and audience matter.
The five-field trafficking decision card
1. System and provider
Record the system used to generate or manipulate the asset and the entity providing that system. Ask what machine-readable marking the provider supplies and whether your editing, export, or upload path preserves it. Do not assume a platform toggle can repair metadata that disappeared earlier in the workflow.
2. Professional deployer
Name the legal person using the system under its authority. If a brand, agency, production studio, or contractor participates, record who controls the work and who is responsible for the final deployment. Do not assign the role from a job title alone.
3. Generation date
Record when the content was generated. The Commission says content generated before 2 August 2026 does not need to be labelled retroactively. Its limited grace period to 2 December 2026 concerns the provider marking-and-detection duty for systems placed on the market before 2 August; it is not a blanket delay for every deployer obligation.
4. Content and deployment context
Classify the asset before deciding the treatment. Is this standard editing, other synthetic content, a deepfake that resembles an existing or plausibly existing subject and could falsely appear authentic, or text published to inform the public on a matter of public interest? Record the intended audience, message, placement, and any substantive human review.
5. EU exposure and disclosure owner
Confirm whether the asset will be served to people in the EU. Then name the owner who checks provider marking, deployer disclosure, platform-specific fields, accessibility, and first-exposure placement. A platform field may be part of the implementation, but it does not decide the legal classification for you.
What to do before 2 August
Start at asset intake
Add the five fields to the creative brief or asset record: system and provider, professional deployer, generation date, content and context class, and EU-serving disclosure owner. Keep the source file and provider metadata where the workflow permits it.
Review queued EU campaigns
Prioritise assets scheduled to run on or after 2 August rather than relabelling the entire library by default. Escalate any asset that could falsely appear authentic, uses a real or plausibly real subject, or carries public-interest information without a clear substantive review record.
Test the handoff
Check whether machine-readable metadata survives the generation, editing, export, agency handoff, and platform upload path. Separately verify that any required human-facing disclosure is clear at first exposure. These are different controls with different owners.
Record the decision and the uncertainty
Capture the classification, reviewer, date, evidence, and unresolved question. If the facts do not support a confident classification, stop the asset from automatic trafficking and route it to the appropriate legal or compliance owner.
What this alert does not establish
It does not determine whether a specific ad is a deepfake, whether a specific organisation is the provider or deployer, or whether a platform disclosure control is sufficient. It also says nothing about ad effectiveness, conversion lift, or campaign performance.
The operator decision is narrower: before an AI-generated or manipulated asset enters EU trafficking, preserve enough provenance to classify it, identify the responsible owner, and obtain qualified review where the answer remains uncertain.
Official sources and update policy
European Commission guidelines; European Commission FAQ; and the Article 50 text.
Source review: 21 July 2026. Recheck this alert if the Commission updates the guidelines or FAQ, if a competent authority publishes relevant enforcement guidance, or if the asset workflow changes how provider metadata and human-facing disclosures are preserved.
Read also



