A tool I built to help me navigate AI changes in my own work, shared in case it is useful to someone else. It is a working reference rather than legal advice, and no substitute for a qualified attorney, see the full disclaimer at the bottom of the page.
Grouped from lowest concern to highest. Click any row to see what each jurisdiction and platform asks for.
| What was done to the asset | Tier | Notify the audience? |
|---|
Relighting, wardrobe changes, or hair changes on a real person in video. These are normal craft techniques, but they change how a real person looks in a way a background swap does not. Ask whether the change could mislead someone about who is shown or what they really look like. If it could, treat it as Tier 3. If it is clearly styling that nobody would read as a factual claim, it behaves like Tier 2. Do not let it fall into Tier 2 out of habit.
Three different things can require a label, and one asset can be covered by all three at once. Whichever is strictest is the one to follow. A US business running ads that reach the EU has to meet the EU rules for that campaign, the US rules, and whatever the platform asks for.
One common mix-up is worth clearing up. People often think AI labeling in the US is a social media rule. It is the other way around. The social media requirement comes from platform policy, which is a contract with the platform, not a law. Actual US legal requirements are not limited to social channels at all.
| Who says so | When it applies to you | What it asks for | If you skip it |
|---|---|---|---|
| EU AI ActArticle 50, live 2 Aug 2026 | Your client is based in the EU, sells there, or this asset reaches an EU audience.Not limited to advertising. Organic posts, website images, email, and decks all count. | A visible label on deepfakes, and on AI-written text published to inform the public on public-interest topics. Hidden machine-readable marking is the AI tool maker's job, not yours. | Up to EUR 15 million or 3% of worldwide turnover, whichever is higher.For SMEs and start-ups that flips to whichever is lower. |
| US: FTCOngoing, every channel | Any commercial content aimed at US consumers, anywhere it runs.Wider than paid ads. An organic brand post promoting a product is commercial content. There is no social-media-only carve-out either. | Hiding AI use is deceptive when it misleads. An AI figure used as an endorser needs two disclosures: that it is a paid placement, and that it is AI. AI-written reviews of a product nobody actually used are deceptive on their face. | FTC enforcement, civil penalties, consent decrees. |
| US: New YorkLive 9 June 2026 | Any ad that reaches New York consumers, no matter where your business is based. Covers paid channels, not just social. | A clear disclosure when an ad shows an AI-generated "synthetic performer," meaning a person who was made up and is not anyone real. | USD 1,000 for a first violation, USD 5,000 for each one after. |
| EU: AI literacyArticle 4, enforced from 2 Aug 2026 | Same EU exposure test as Article 50. Applies to you as a deployer if you use AI tools in work that reaches the EU. | Make sure people using AI tools on your behalf understand the risks, with hallucination as the Commission's own example. Covers contractors, not only employees. No certificate or formal course needed, an internal record is enough. | National authorities can penalise, but the approach is explicitly proportionate. Most likely to bite if an incident traces back to untrained staff. |
| US: CaliforniaSB 942, live 2 Aug 2026 | Applies to the AI tool makers themselves, meaning systems with over a million monthly users. It does not apply to you for using those tools. | They must offer a label option and embed provenance data. Useful to you as a reason to pick tools that already comply. | Falls on the AI company, not on you. |
| Platform policyMeta, TikTok, YouTube | Posting or running paid media on that platform, anywhere in the world. | Disclose realistic AI content, synthetic people, AI-altered product demos, and AI audio or video that looks like a real scene. Usually a built-in toggle rather than a caption. | Ads rejected, posts taken down, and account limits for repeat offenders. Not a fine, but often the first thing that actually stops you. |
How much accidental EU reach is enough to pull a US business into the EU rules. Buying ads into the EU on purpose is plainly covered. A US company whose posts happen to pick up some EU followers is far less clear, and the published guidance does not draw that line. For a real answer on a specific situation, use the EU AI Act Service Desk under Sources.
The whole thing, short.
_ai-gen and _ai-mod cost nothing and make assets easy to find and swap later.These are contracts, not statutes. Breaking one does not bring a regulator, it gets your ad rejected, your post removed, or your account limited. For most people that is the consequence they actually meet.
They also do not agree with each other, and in places they ask for more than the law does. Treating "platform policy" as one rule hides that.
Treating "platform policy" as one rule hides real differences. YouTube publishes the most specific list, and it is worth reading directly. TikTok sets a broader bar. Meta increasingly decides for you by detecting AI automatically.
| Platform | The test they apply | Named as exempt | Named as needing a label |
|---|---|---|---|
| YouTubeMost specific policy of the three | Does it meaningfully alter or generate photorealistic content? Three triggers:
|
|
|
| TikTokBroadest bar | Is it realistic? Any AI-generated or significantly AI-edited image, audio, or video that looks real. Their synthetic media policy names realistic synthetic people, events, and voices. |
|
|
| MetaFacebook, Instagram | Are there AI-generated or materially AI-altered visuals, text, or audio in an ad? Meta also detects AI itself rather than waiting for you to declare it. |
|
|
All three read C2PA Content Credentials, the provenance data many AI tools embed automatically. So the platform may label your asset whether or not you declare it. TikTok has labeled over a billion videos this way. On YouTube, content carrying C2PA metadata or made with YouTube's own AI tools gets a label you cannot remove.
Declaring it yourself is the safer play. Content flagged after the fact is treated worse than content disclosed upfront, and repeatedly failing to disclose can cost you monetization or the account. YouTube states plainly that disclosing does not limit your audience or your ability to earn.
Disclosing is mandatory. These specific icons are not. Those are two different questions, and the Commission's own page states both in the same breath, which is why people come away confused.
Where the EU rules apply, you must tell the audience. How you tell them is up to you: plain text, your own label, an audio disclaimer, or this icon set. The icons are a free, user-tested option, not the required form.
One caveat. Using an icon does not prove you complied. Responsibility stays with whoever publishes. And if you formally sign the Code of Practice, you are then committed to following its placement rules.
Two filters, and you need both.
Does the EU reach this asset? The rules follow the audience, not your address. They apply if the business is based in the EU, sells there, or the asset is aimed at an EU audience. If none of that is true, none of this is required of you, though you may still choose to disclose.
Is it the kind of content the rules cover? Only two categories trigger the duty to tell the audience:
The Commission says plainly that not all AI content needs a label. In this tool's terms, that means the icons belong on Tier 3 and Tier 4 work, never on a Tier 2 background swap. Putting an "AI generated" mark on an ordinary product shot with a new backdrop is not required, and over-labeling causes exactly the label blindness these rules exist to prevent.
There are three. Pick based on how much of the piece was AI.
| Icon | Use it when | The Commission's own example |
|---|---|---|
| Basic AI | AI played some part, or you are pairing the mark with your own wording. | A deepfake video labeled "voices generated with" followed by the icon. |
| Fully AI-Generated | The whole thing is AI, with no human-made parts and no human editing beyond the prompt. |
|
| Partially AI-Modified | Something a human made was then partly changed by AI, and the result became a deepfake. |
|
The Commission lists furnishing a real, empty apartment with AI as Partially AI-Modified, meaning it needs disclosure. So adding things into a real scene is treated differently from swapping the backdrop behind a real subject. That is exactly the line between Tier 2 and Tier 3 in this tool, and it comes from an official example rather than guesswork.
The Commission's rules, in short:
Pair it with words. Commission user testing found the basic icon performed better across every measure when paired with a short text label than when used alone. An icon by itself is ambiguous.
Make it accessible. Use a visible size, plain wording with no jargon beyond "AI," alt text or ARIA labels so screen readers catch it, and if the disclosure is only on screen briefly, leave it up long enough to actually be read.
Free for anyone to use, with no credit required. Each icon comes in four versions: black, white, and both at 50% transparency. Both links download a .zip directly.
Full placement specifications and licence terms are on the Commission's icon page.
The questions that come up most, and the ones where the intuitive answer is wrong. Click any question to open it.
The most common mistake here, and one this tool made until 3 August 2026, is assuming a deepfake has to copy a specific real person. It does not.
The Guidelines say a subject counts as "existing" if it exists, can plausibly exist, or could plausibly have existed. So a photorealistic invented person is inside the definition, because such a person plausibly could exist. The same goes for realistic depictions of invented objects, places, animals, and events.
What falls outside is the impossible: a sphinx flying over the Eiffel Tower, dragons, elephants driving cars. Things that defy nature or biology are not pretending to be real, so nobody could be misled about reality by them.
The working heuristic: photorealistic and plausible is inside, stylized or impossible is outside. That is a much better predictor than asking whether a real person was copied.
Practical upshot: the EU, New York, and the platforms all agree that an invented human in an ad needs disclosure. They arrive there by different routes, but there is no gap to exploit.
| Scenario | EU | US law | Platforms |
|---|---|---|---|
| Background swapped behind a real, unchanged product | No label | No disclosure | Generally none |
| An AI-generated model or spokesperson who is not real | Required | Required | Required |
| Something impossible: dragons, a sphinx over the Eiffel Tower | Outside the definition | No disclosure | Not required |
| Face swap or synthetic version of a real person | Deepfake, label required | Deceptive, plus likeness exposure | Required |
| Product made to look better than what ships | Label required | Deceptive under FTC | Required |
| AI-written review of a product nobody used | Text rules if public-interest | Deceptive on its face | Not allowed |
| Routine retouching, exposure, crop, dust removal | Exempt | No disclosure | Not required |
Follow both, and let the stricter one decide. In practice this is easier than it sounds, because the two systems agree on nearly everything. They part ways in one spot, the invented-person case above, and there the safe move is to disclose.
Do not assume a US-based client is outside the EU rules. What matters is who sees the asset, not where the business is registered. Deliberately buying ads into the EU is the clearest trigger.
Mostly you are outside these rules, but not entirely, and the exceptions are the ones that bite hardest. Three different tests are running, and only one of them cares which tool you used.
The short version worth remembering: the AI rules follow the tool. The deception rules follow the result. New York's rule follows the output, meaning a fabricated human, regardless of how it was made.
So switching from AI to manual work removes the labeling paperwork. It does not make a misleading image safe, and it does not get a fake spokesperson past New York.
They follow the audience, not your address. They apply where the business is based in the EU, sells there, or the asset is aimed at an EU audience. Without one of those, everything below Tier 3 is a trust choice rather than a legal duty, and it should never be presented to a client as a legal duty.
Tier 3 and Tier 4 still matter everywhere regardless. Misrepresenting a real product is a false advertising problem in any market, and the Tier 4 lines are a studio policy rather than something copied from one regulator.
The Digital Omnibus did postpone deadlines for high-risk AI systems, and that got most of the coverage. Article 50, the transparency and labeling rules this tool is about, was not delayed. It applied on 2 August 2026 as scheduled.
There is one narrow grace period, and it does not help you. Systems already on the market before 2 August 2026 get until 2 December 2026 to meet the machine-readable marking requirement. That is a provider-side duty sitting with the AI tool vendors. It does not extend any deadline for the person publishing the content.
Almost every point of confusion in this subject comes from treating these as one thing. They are not.
_ai-gen or _ai-mod) is a habit for your own organization. No law asks for it. It exists so you can scan a delivery folder and swap an AI asset later without hunting.So do not read "it got tagged" as "the law says disclose this." And do not read "the law does not require it" as "the platform will not flag it."
It comes down to who decided to use AI, not who pressed publish.
So a clear record of who chose to use AI matters more than who clicked the button. When that is murky, label it rather than argue about it later.
There are two layers of marking, and only one of them is yours.
Worth knowing that the platforms read that hidden data, which is how they label your content automatically whether or not you declare it.
AI literacy, Article 4. If you use AI tools in your work and you have EU exposure, you are required to make sure the people using them understand what they are and what can go wrong. This is separate from disclosure and it has nothing to do with labels.
The Commission's own FAQ answers the exact case: a company whose staff use ChatGPT to write advertising copy or translate text does have to comply, and should make sure those people are informed about specific risks such as hallucination.
It is lighter than it sounds. There is no certificate, no mandated training format, no AI officer, and no governance board required. Keeping an internal record of whatever training or guidance you gave is enough. It also reaches contractors and freelancers working on your behalf, not just employees.
Timing worth knowing: the obligation has technically applied since 2 February 2025, but enforcement only began 2 August 2026. Note also that the Commission proposed shifting this duty onto Member States in the Digital Omnibus of 19 November 2025, so it may change. Watch it rather than treating it as settled.
The headline figure is up to EUR 15 million or 3% of worldwide turnover, whichever is higher. For SMEs, including start-ups, that flips: the cap is whichever of the two is lower. For a small practice that means the percentage, not the fifteen million.
Enforcement sits with national market surveillance authorities in each member state, not with Brussels directly, and they are required to be proportionate, weighing the nature and gravity of the infringement and whether it was intentional or negligent.
Short answer: usually yes, and this is the single most misunderstood point in the whole subject. Trademark and copyright are separate systems with separate rules, and AI lands differently in each.
Trademark: generally available. The USPTO does not ask who or what created a mark. It asks whether the mark identifies the source of your goods, whether you are actually using it in commerce, and whether it conflicts with something already registered. AI-generated logos have been registered. Nothing about using AI disqualifies a mark on its face.
Copyright: not available for AI-only work. US law requires a human author. The Copyright Office refuses registration for work created without human creative input, courts have upheld that, and the Supreme Court declined to reconsider it in March 2026. Where a human meaningfully shapes, selects, arranges, or edits AI output, that human contribution can be registered, and the AI-generated parts have to be disclaimed on the application. The Copyright Office has registered hundreds of works on that basis.
So why avoid AI for a finished logo anyway? Not because it is unprotectable. Because of what you give up and what you take on:
You lose the copyright layer, so you can still stop a competitor using your mark as a brand identifier, but you have a weaker position against someone simply copying the artwork.
Distinctiveness gets harder. Similar prompts produce similar results, and a mark that looks like everyone else's is a weaker mark by definition.
Conflict risk goes up. AI works from patterns in existing material and can produce something close to a mark already in use.
Whatever you do, a professional trademark clearance search before committing to a mark is not optional, and that is true for human-made logos too. This tool does not replace one.
Listed strongest first. The Regulation is binding law. Commission guidelines and codes of practice explain it and are voluntary, though they carry real weight in showing you complied. Law firm write-ups are secondary, useful mainly where several independent ones say the same thing. All links checked 3 August 2026.
Tier 2 assets get a file tag even though no public label is required for them. That is a deliberate transparency choice, not a legal necessity, and it is flagged as such throughout so the two never blur together.
Two questions are genuinely unanswered in the published guidance, and they are marked that way wherever they come up: exactly when AI effects added to real video would cross into needing disclosure, and how much accidental EU reach pulls a US business into the EU rules. For either, the Service Desk above is the way to get a real answer.
This page is run by Lionel Lowery at lionel.marketing.
Questions or suggestions, contact support@lionel.marketing.