First off, let's be clear: At Puntt, we hold ourselves in very high regard but we are not lawyers and this is not legal advice. The purpose of this blog is to raise awareness about the EU's new law and make sure marketing leaders at least consider its implications, if not act quickly on it. If, after reading this blog, you pinged your counsel about it, we did our job.
Buried in the European Commission's guidance on Article 50 of the AI Act is one sentence that should stop every marketing leader in a regulated category:
"Superficial, solely formal, or procedural checks (e.g. spell-checking or grammatical correction) are not considered to be human review or editorial control."
A regulator has now written down what does not count as reviewing something.
Article 50 became applicable in the European Union (EU) on August 2, 2026. Most of the coverage since has been written by law firms for other lawyers, and most of it answers a question marketing teams weren't asking. The version that matters to anyone running brand or regulatory work at a global consumer company is narrower, stranger, and considerably more interesting than "AI is regulated now."
Here is what the rule actually says, where marketing teams may be exposed, and the part almost everyone is getting wrong.
What is Article 50 of the EU AI Act?
Article 50 sets transparency obligations for providers and deployers of certain AI systems. It applied to any content generation starting August 2, 2026. It covers four situations: AI systems that interact directly with people, synthetic content marking, emotion recognition and biometric categorisation, and the labelling of deepfakes and of AI-generated text published to inform the public on matters of public interest.
For a large company, the penalty ceiling is up to €15 million or 3% of total worldwide annual turnover, whichever is higher. And it is worldwide, not just Europe.
The distinction that decides your obligations is provider versus deployer. A provider develops the AI system and places it on the market. A deployer uses one under its own authority. A brand using a generative tool to produce campaign assets is a deployer, and the Commission is explicit that individual employees don't carry this personally. Designers, copywriters and content creators acting under a company's control aren't separate deployers.
Which means the obligation lands on the organisation, and organisations discharge obligations through process.
Does Article 50 apply to advertising?
Mostly not, for ordinary ad copy, and that exemption is thinner than it first appears. The AI-generated-text obligation is triggered only by publishing text to inform the public on a matter of public interest. Advertising, as a category, isn't on the Commission's list. However, two separate provisions reach marketing.
Start with the list itself. The Commission defines matters of public interest as "politics and democratic processes, public administration and services, administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety and any economic, financial, political, scientific, or cultural developments that may be relevant subject of public debate."
The three that stand out: Public health, environmental protection, consumer safety.
Taking the broad interpretation, a global, regulated CPG brand is likely touching one, if not all three of these categories. The line the guidance draws is that product descriptions making no health or safety claims sit outside the scope. So the plain product copy is fine, but the nutrition claim, the safety claim, the sustainability claim on the same asset is a different conversation.
Article 50(4) actually contains two obligations that work nothing alike, and conflating them is where most marketing teams get their risk picture wrong.
The deepfake obligation is triggered by synthetic content resembling existing people, places, objects or events in a way that would falsely appear authentic. Subject matter is irrelevant so there is no public-interest test to fail. It reaches advertising directly wherever the content depicts something real, and it offers no human-review exemption at all. The only carve-outs are for law enforcement, and a reduced-disclosure allowance for evidently artistic or satirical work that the Commission has confirmed is not available to commercial advertising.
The public-interest text obligation is triggered by something else entirely: publishing text with the purpose of informing the public on a matter of public interest. It reaches marketing copy only where the claim touches health, safety, environment or a similar listed subject. And unlike the deepfake rule, it comes with some relief, when there is a substantive human review, with named editorial responsibility.
The deepfake obligation carries no public-interest trigger and no editorial-review exemption. Its boundary is definitional instead: content has to resemble something that exists. A fully invented scene isn't a deepfake. An AI-generated version of a real person, a real place, or a real product is.
And the Commission has closed the obvious door that commercial advertising cannot claim the artistic or satirical carve-out. An AI-generated celebrity in an ad is about as clearly in scope as this gets.
So the question was never "are we an advertiser." It's "what is this specific asset claiming, and does it depict something real." Which is an asset-level question, asked across every market, on every launch.
What counts as human review under the AI Act?
Where the text obligation applies, disclosure isn't required if the content underwent human review or editorial control with a person thatholds editorial responsibility. The Commission's guidance then defines those terms with precision, and the definition is a quality standard, not a checkbox.
Human review means "the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny."
Editorial responsibility means "a person must hold the ultimate legal responsibility over the publication of the content."
And then the exclusion, quoted at the top of this piece: superficial, solely formal, or procedural checks don't count.
The precise language lives in the Commission's Article 50 guidance and FAQ, which is non-binding soft law. The Regulation itself says only "human review or editorial control" and "editorial responsibility." But guidance is what regulators reason from, and it's what your general counsel will read.
For a decade, review at large consumer companies has been a social act. Someone senior looked at the thing. They said it was fine. It moved. The record of that was a thread, an initialled PDF, a name in a workflow field, a meeting where nobody dissented.
What the guidance describes is an evidentiary act. Who examined this. What were they qualified to assess. Did they engage with the substance or the surface. Who holds responsibility for publishing it.
Those are different activities that have shared a name for a long time. Most enterprise review processes were built to produce the first one. Almost none were built to produce a record of the second.
What did the Digital Omnibus change?
Article 50 applied on August 2, 2026 as scheduled. Nothing in it was delayed. The AI Omnibus gave generative AI systems that were already on the market before that date until December 2, 2026 to meet the Article 50(2) machine-readable marking requirement, which was a grace period for existing systems, not a general postponement.
Several widely-shared summaries have this wrong, and the distinction matters commercially: a generative tool launched on or after August 2 owes machine-readable marking today.
Separately, and this is where the real delay landed, the high-risk obligations moved substantially. Annex III systems went from August 2026 to December 2, 2027. Annex I systems from August 2027 to August 2028. Both are now law under Regulation (EU) 2026/1744.
The practical shape of this: deployer obligations are live now, while the upstream marking that would let you detect synthetic assets automatically is uneven until December. For the next four months, the review layer is the backstop.
Does the EU AI Act apply to US companies?
Yes. Article 2(1)(c) covers providers and deployers established outside the EU where the output produced by the AI system is used in the Union. Penalties calculate on worldwide turnover.
For a US-headquartered consumer company running campaigns across European markets, this isn't a problem that belongs to the European subsidiary. The trigger is output actually used in the Union, not content merely accessible from it.
What marketing leaders should do now
Three things, in order.
1. Sort your assets by type, not by campaign. Synthetic imagery depicting real people, places or products carries an obligation that plain copy doesn't, and no editorial exemption exists for it. Copy making health, safety or environmental claims sits closer to the line than copy that doesn't. These are different risk objects that currently move through the same pipeline.
2. Make review evidentiary. If someone asked who examined a specific claim, what they were qualified to assess, and who holds responsibility for publishing it, could you answer for any asset that shipped last quarter, in any market? Most teams can produce the approval. Far fewer can produce the examination.
3. Treat December 2 as the second date. When Article 50(2) marking coverage fills in, the detection picture changes and some of this gets easier. Whatever record-keeping you build over the next four months should still hold after it.
None of this requires slowing down. That's the part the compliance framing gets backwards. A team that can show its work moves faster than one that has to reconstruct it because reconstruction is what actually eats the calendar when a regulator, a retailer, or your own legal team asks a question about an asset that shipped eleven weeks ago.
The regulation doesn't say review has to be slower. It says it has to be real.
Those are not the same requirement, and most teams have spent a decade optimising for the wrong one.
FAQ
What is Article 50 of the EU AI Act?Article 50 sets transparency obligations for providers and deployers of certain AI systems, covering AI systems that interact with people, synthetic content marking, emotion recognition and biometric categorisation, and the labelling of deepfakes and AI-generated public-interest text. It applied from August 2, 2026.
When did Article 50 take effect?August 2, 2026. Generative AI systems already on the market before that date have until December 2, 2026 to meet the Article 50(2) machine-readable marking requirement.
Does Article 50 apply to advertising and marketing content?Ordinary ad copy generally falls outside the public-interest text obligation. But the deepfake obligation applies regardless of subject matter to synthetic content depicting real people, places or objects, and commercial advertising cannot claim the artistic or satirical carve-out. Copy making health, safety or environmental claims can also fall within the public-interest scope.
What are the penalties for non-compliance?For a large company, up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The test inverts to whichever is lower for SMEs, start-ups and small mid-caps.
Does the EU AI Act apply to US companies?Yes, where the output of the AI system is used in the European Union, regardless of where the company is established.
What counts as human review under Article 50?Commission guidance defines it as deliberate examination of the substance of the content by one or more natural persons with relevant knowledge and professional judgement, with a person holding ultimate legal responsibility for publication. Superficial, formal or procedural checks such as spell-checking do not qualify.
What did the Digital Omnibus change?It did not delay Article 50. It provided a grace period to December 2, 2026 for pre-existing generative systems to meet Article 50(2) marking, and postponed high-risk obligations — Annex III to December 2, 2027 and Annex I to August 2, 2028.
Sources
- Transparency obligations under Article 50 of the AI Act (FAQ) — European Commission
- Guidelines on transparency obligations for AI-generated content — European Commission
- Article 50 — EU Artificial Intelligence Act
- Article 2 (scope) — EU Artificial Intelligence Act
- Article 99 (penalties) — EU Artificial Intelligence Act
- Regulation (EU) 2026/1744 — EUR-Lex
- The AI Act implementation timeline: what changes under the AI Omnibus — Future of Privacy Forum
- EU AI Act Omnibus Agreement — Gibson Dunn
.png)