Use-case guide
AI in Marketing & Advertising
AI has rewired the advertising stack — from algorithmic targeting and creative generation to dynamic optimisation and influencer-style synthetic personalities. Regulators have been catching up, fast. The biggest exposure today is in three buckets: (1) AI-generated content that's not labelled, (2) automated decisioning that determines who sees what (and at what price), and (3) the political-advertising and election-integrity overlay where the rules are tightest and the penalties are highest. None of this is hypothetical — the Italian Garante, FTC, and ASA have all opened cases against advertisers using generative AI without disclosure.
For: CMOs, performance marketers, creative directors, brand teams, ad-tech founders, advertising counsel
What's at stake
Generative AI ads need a label
EU AI Act Article 50 requires AI-generated images, audio, and video to be labelled as artificially generated, with limited exceptions. In the UK, the ASA has been enforcing similar transparency principles under existing CAP/BCAP rules.
Deepfakes in political ads are increasingly illegal
California (AB 2655 / AB 2839), Texas (SB 751), New York, and a growing number of US states criminalise or restrict AI-generated political content within defined windows around elections. The EU's AI Act treats election-relevant deepfakes as a special transparency case.
Targeted advertising data is regulated data
Profile-based targeting using ML almost always touches personal data subject to GDPR, CCPA/CPRA, and the EU's Digital Services Act. The DSA prohibits ad targeting based on special-category data and any profiling of minors.
Synthetic endorsers create FTC liability
The FTC's Endorsement Guides explicitly cover AI-generated reviews, testimonials, and synthetic influencers. Failure to disclose AI origin or material connection is treated as a deceptive practice.
Regulations that apply
EU AI Act
LawArticle 50 transparency obligations for synthetic content; Article 5 prohibition on manipulative subliminal techniques; GPAI provider duties for foundation-model ads creative.
Where in the text: Articles 5, 50, 52.
EU Digital Services Act
LawBans ad targeting based on profiling using special-category personal data; prohibits any profiling of minors for ads; transparency rules for sponsored content. Strict on platforms but flows to advertisers via contractual chain.
Where in the text: Articles 26, 28, 39 (DSA).
California deepfake & election content laws
LawAB 2655 (combatting deepfake elections), AB 2839 (deceptive election content), AB 2355 (AI disclosure in political ads). Civil and criminal exposure for AI political content distributed within statutory windows.
Where in the text: Cal. Elec. Code §§ 20010-20012; Cal. Bus. & Prof. Code §§ 17040 et seq.
US FTC Endorsement Guides + Section 5
GuidelineSynthetic testimonials, AI-generated reviews, virtual influencers, and undisclosed AI co-creation all fall under the Guides. FTC Section 5 enforcement against unfair/deceptive practices is the active vehicle.
Where in the text: 16 C.F.R. Part 255; FTC Act § 5.
Do
- ✓Label all AI-generated creative — image, video, audio — visibly in the ad surface AND in the underlying metadata where the platform supports it (C2PA, SynthID, OpenAI manifest).
- ✓Run political-content rules per jurisdiction with a calendar: pre-/post-election windows, candidate likeness, voter manipulation language all carry different triggers.
- ✓Get your DPIA done before launching any new targeting model that uses personal data — EU and UK supervisors expect this.
- ✓Update your endorser/influencer contracts so the AI-disclosure obligation flows down to anyone you pay or trade with.
- ✓Maintain an audit trail of which model generated which asset, with timestamps, prompts (or paraphrase), and approval sign-off.
Don't
- ✗Don't use a real person's likeness or voice in generative AI ads without explicit, recorded consent — increasingly the basis for civil suits even outside dedicated AI laws.
- ✗Don't use 'lookalike audiences' built from sensitive inferred categories (health, sexual orientation, religion, political view) — flat banned by GDPR + DSA.
- ✗Don't target minors with AI-driven personalised ads in the EU. Period.
- ✗Don't deploy generative-AI customer-service bots that pretend to be human — the EU AI Act, FTC, and several state laws now all require disclosure.
- ✗Don't run political deepfakes within the statutory windows of any US state where the candidate has been the subject of the content — even satire is in scope under many of these laws.
Also worth knowing
If you operate at any scale in the EU: the DSA categorises platforms with >45M EU users as VLOPs (Very Large Online Platforms) which face systemic-risk audits including over generative-AI advertising surfaces. Advertisers on those platforms inherit some compliance via contract. NYC's Local Law 174 (proposed) would add audit duties for AI-driven personalisation; track it.
Want a tailored answer?
The wizard takes your jurisdiction, AI use case, and data types and gives you the top-3 regulations to focus on — in 60 seconds.
Start the wizard →Educational guide. Not legal advice. For specific compliance decisions, consult qualified counsel in the relevant jurisdiction.
Note: this guide was drafted with AI assistance — Anthropic Claude.