Logo
Back to Blog
Aug 31, 2026/Industry Benchmarks

What the New AI Disclosure Rules Actually Ask of Advertisers

What the new EU, California and New York AI disclosure rules require of advertisers, which uses of AI need a label, and which do not.

What the New AI Disclosure Rules Actually Ask of Advertisers

The IAB published the second version of its AI Transparency and Disclosure Framework on 18 August, the first update since the original guidance appeared in January. It is an attempt to make sense of four separate sets of rules that all arrived within about ten weeks of each other.

The timing explains why it exists. Article 50 of the EU AI Act, the section covering transparency, became binding on 2 August. California's SB 942 took effect on the same day, New York's law on digital replicas of real performers has applied since 9 June, and South Korea's AI Basic Act arrived in January with a grace period attached. That is four jurisdictions, each with a different view of which uses of AI have to be declared to consumers.

Most marketing teams are working from one of two assumptions about this, and both are wrong in ways that cost money.

The first assumption is that your vendor has it covered

California's SB 942 does not regulate advertisers. It applies to companies supplying generative AI systems to more than a million monthly users, which in practice means Adobe, OpenAI, Google and their equivalents. Those suppliers have to offer a free public tool capable of detecting AI-generated content, embed a hidden marker inside any AI-generated image, video or audio their systems produce, and give users the option of adding a visible label as well. The hidden marker is designed to be read by software rather than seen by a person, so the file carries a record of how it was made wherever it ends up. Penalties run to $5,000 for each violation, and every day of continued non-compliance counts as a separate one.

This matters to you less than it first appears. Your supplier's compliance produces the technical marking, but it does not discharge any obligation of your own. Whether a visible label appears on the finished advertisement is still your decision, and your risk.

The second assumption is that any use of AI needs a label

This one is more expensive, because it pushes teams either into labelling everything or into avoiding AI in creative work while they wait for somebody to clarify what is allowed.

Every requirement across these regimes concerns a fake human or a fake photograph. That covers digital replicas of real and recognisable performers, cloned voices, and AI-generated images of people, objects or events that a reasonable viewer might take to be real. The European rule does apply to advertisers directly rather than stopping at their suppliers, and it applies on the basis of who sees the advertisement rather than where the company is registered, so a UK or Turkish brand running campaigns to consumers inside the EU is covered. What it catches is content reproducing the appearance of a real person, organisation or event.

AI-written copy is not covered by any of it, which surprises people. An AI-drafted headline, generated body copy, a subject line written by a model: none of these require a label under any of the four regimes currently in force. This is the single most common misunderstanding in the whole area, and it works in both directions.

The IAB framework applies the same test. A label is called for when AI materially affects authenticity, identity or representation in ways that could mislead consumers, while routine production work, background tools and creative that is obviously stylised do not require one.

Why the industry wants a narrow standard

There is a commercial reason underneath the framework's position, and the framework is fairly open about it.

The guidance cites research from NYU Stern finding that disclosing the use of generative AI reduced an advertisement's click-through rate by 31.5%. Caroline Giegerich, who leads AI at the IAB, has argued that labelling every use of AI teaches consumers to ignore labels altogether. That is a reasonable argument, and it also happens to align with a measurable cost to advertisers.

Consumers say something different. A survey by Fractl and Search Engine Land covering just over a thousand US consumers in the second quarter found that 91% wanted AI-generated video labelled, along with 90% for images, 87% for audio and 84% for written content, which no law currently requires anyone to label. The same research found that only around a fifth of organisations always disclose their use of AI, while roughly a third never do.

So consumers want labels on almost everything, the available evidence suggests those labels cost roughly a third of your click-through rate, and the law requires them only on a narrow range of content involving fake people and fake imagery. The framework is trying to hold a position between those three positions, and it is fair to read it knowing that the IAB represents advertisers.

The IAB's own earlier research complicates its case. It found that 73% of Gen Z and Millennial respondents said clear disclosure would either increase their likelihood of buying or make no difference to it. The 31.5% figure measures the immediate click and nothing after it, so it says very little about what happens to a brand caught not disclosing.

What this changes in practice

In the United States you now have a standardised choice between a small sparkle icon and a plain text label. Either satisfies the framework, so the decision comes down to whatever suits the format and placement.

In the EU there is no prescribed icon. Article 50 requires disclosure without specifying its appearance, and the Code of Practice accompanying the law, finalised in early June, is voluntary rather than binding. The European Commission has published free labelling icons, but a single common EU icon has not been agreed. In practice you will be making a judgement and keeping a record of your reasoning.

One date is worth noting. Under transitional provisions in the EU's AI Omnibus package, a set of amendments to the original timetable, generative systems already on the market before 2 August are expected to have until 2 December to meet the hidden-marker requirement. That gives suppliers extra time to update their tools. It does not delay your own duty to label. Given how quickly this area is moving, confirm it against the enacted text before relying on it.

It is also useful to know where the duty sits once platforms are involved. Google's documentation, updated in July, places it on advertisers rather than on the websites carrying Google ads.

The part nobody has started discussing

All of this points towards provenance, meaning a durable record of how a piece of content was made that stays attached to the file and can be read by software.

That record is being created to satisfy regulators. But anything readable by software is readable by any software, including the systems that crawl, index and cite content across the web. It is not difficult to imagine those markers eventually informing what AI systems treat as reliable enough to quote in an answer.

That is speculation and I would flag it as such. The practical point is that if you are going to build this marking capability anyway because the law now requires it, it is worth knowing that the same records may end up serving two purposes rather than one.