If your team made an ad this month with an image or music model, the files may well have left the tool carrying provenance signals nobody on the team added. Two September launches do this by default, and new EU rules and two pending California bills make clear those signals are not the end of the job. The vendor marks the file. Telling the viewer is still up to the advertiser and the agency.
What shipped in September
OpenAI released ChatGPT Images 2.5 on September 8, 2026, according to 9to5Mac. OpenAI's system card describes two provenance layers: C2PA metadata, a framework that "enables automated disclosure of provenance information", and Google DeepMind's SynthID, an invisible watermark applied across ChatGPT, Codex and the OpenAI API. OpenAI adds that "there is no single solution to provenance".
On September 4, Google made its Lyria 3.5 music model available to all Gemini users globally, and in Google Flow Music, Google AI Studio and Google Vids. Its announcement lists "a unique brand jingle" among the uses. Google's Gemini music page says all tracks generated in the Gemini app are embedded with SynthID, and that Gemini can check an uploaded file for it.
California's legislature sent Governor Gavin Newsom roughly 30 AI bills, and he has until September 30 to decide, according to the Transparency Coalition. Two bear directly on ad creative. According to Venable, SB 1050 would make it an unlawful advertising practice to create and publish an ad that prominently includes a synthetic performer without a clear and conspicuous disclosure. SB 1000 would amend the California AI Transparency Act, including by requiring latent disclosures to indicate whether a generative AI system created or altered the content. If signed, SB 1050 takes effect January 1, 2027, and SB 1000, an urgency bill, immediately.
Marking is not labeling
The EU AI Act draws the line most clearly. Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format, detectable as artificially generated or manipulated. SynthID and C2PA are marking of this kind. Article 50(4) puts a separate duty on deployers, meaning professional rather than personal users: where a system generates or manipulates image, audio or video content constituting a deep fake, they must disclose that the content has been artificially generated or manipulated.
The European Commission's FAQ on Article 50 closes the obvious shortcut. Deployers must disclose a deep fake at first exposure at the latest, in a way people can perceive, "e.g. with visible or audible labels", so they cannot simply rely on the provider's machine-readable marking. The FAQ gives an advertising company as an example of a deployer, one that remains the deployer when contractors or freelancers operate the system on its behalf and under its responsibility and control. How the role splits between an agency and its client is not addressed, so ask counsel and record the answer in the contract.
| Layer | Who applies it | What it does | What it cannot do |
|---|---|---|---|
| C2PA metadata | Model vendor | Records provenance inside the file | Survive sharing reliably, since metadata is often stripped in transit |
| Invisible watermark such as SynthID | Model vendor | Embeds a signal that detection tools can read | Tell a viewer anything without a tool |
| Visible or audible label | Advertiser or agency | Tells the person seeing or hearing the ad | Help if a crop or placement cuts it out |
Article 50 applies from August 2, 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published on July 24, 2026, gave providers whose systems were placed on the market before August 2, 2026 until December 2, 2026 to meet the marking duty. The Commission says that grace period covers only marking and detection, so the deployer's disclosure duty is not deferred. Content generated before August 2, 2026 does not need to be labeled retroactively. Under Article 99, as amended, breaches of Article 50 can draw fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, and whichever is lower for SMEs and small mid-caps.
When an ad counts as a deep fake
Not every AI-assisted ad needs a label under Article 50. The Commission sets out three cumulative criteria for a deep fake: the content closely resembles its subject, the subject exists or could plausibly exist, and the content would falsely appear authentic or truthful. Audience expectations count. The FAQ's example: AI-generated background scenes and special effects in standard movie production are not likely to make content falsely appear authentic or truthful. Evidently artistic, creative, satirical or fictional work needs only an appropriate disclosure that does not hamper its display or enjoyment.
On our reading, that points one way for ads. A photoreal spokesperson giving a testimonial, a generated shot of a product somewhere it has never been, or a voice that sounds like a real person carries the most risk. An obviously illustrated mascot carries less. None of this is legal advice: the call on a specific asset is one to make with counsel, and UK and Gulf campaigns need their own check.
A labeling workflow for creative teams
The practical work sits in production and in the AI governance process that decides which tools a team may use. Five steps cover most of it.
- Keep an asset log. For each generated or AI-edited asset, record the tool and model version, date, prompt or brief, who made it, what was changed by hand and where it will run. When a client, platform or regulator asks how something was made, the log is the answer.
- Archive the untouched original. Store the file as it left the model, metadata intact, next to the finished master. Edit copies.
- Test whether provenance survives your pipeline. A 2025 World Privacy Forum review of C2PA notes that files uploaded to social platforms or shared through other systems are often stripped of their metadata. Run a generated file through each step you use and check the C2PA data at every stage. Where it drops out, the log carries the record.
- Decide the label per asset, not per campaign. Does it show a realistic person, place, product or event? Would the intended audience take it as real? Does it feature a synthetic performer? Record the decision and the reason.
- Get written client sign-off on who is responsible for the disclosure, which assets carry a label, the wording and the markets, and file it with the creative.
Labels also belong in the brand system. A standard wording, a fixed position per format and a spoken line for audio mean the decision is made once, in the brand guidelines, not improvised ad by ad. Whether AI creative is any good is a separate question, covered in AI creative at scale without the slop. This one is mechanical: the vendor has marked the file, and the viewer still has to be told.
Sources
- https://deploymentsafety.openai.com/chatgpt-images-2-5
- https://9to5mac.com/2026/09/08/openai-releases-chatgpt-images-2-5-with-sharper-details-and-more-precise-editing/
- https://blog.google/innovation-and-ai/products/gemini-app/better-tracks-lyria-gemini/
- https://gemini.google/overview/music-generation/
- https://www.transparencycoalition.ai/news/ai-legislative-update-september4-2026
- https://www.venable.com/insights/publications/2026/09/state-quick-hits-california-privacy-law-update
- https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689
- https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
- https://worldprivacyforum.org/posts/privacy-identity-and-trust-in-c2pa/
- https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB1000



