AI content disclosure laws in 2026: the complete field guide
A tracker of the AI content disclosure laws creative and marketing teams work under in 2026 - the EU AI Act Article 50, California SB 942, New York S8420A, Texas TRAIGA, and the labeling rules live in China, India, and South Korea - with dates, who each one binds, and what a studio actually has to do.
Disclosure used to be the thing your legal team mentioned once and then forgot about. That's changed. The EU's transparency rule has applied since 2 August 2026, and California's watermarking law took effect the same day. New York's synthetic-performer law is in effect, Texas has been enforcing since January, and mandatory labeling regimes are live in China, India, and South Korea. This is no longer a Western story.
This is the rundown of what actually matters for creative and marketing work - the dates, who each law binds, and what that means for a studio.
Updated 30 September 2026. AI law moves fast - always check primary sources before making decisions.
Where things stand
| Law | Jurisdiction | Key date | What it does |
|---|---|---|---|
| EU AI Act Article 50 | EU | In force since 2 Aug 2026 (existing-system marking: 2 Dec 2026) | Machine-readable marking of AI output by providers; deepfake disclosure by deployers |
| SB 942 | California | In force since 2 Aug 2026 | Large AI providers watermark generated media and offer a free public detection tool |
| S8420A synthetic performers | New York | June 2026 | Label AI-generated synthetic performers in ads |
| TRAIGA | Texas | Live since 1 Jan 2026 | Intent-based ban on harmful AI deployment; disclosure in some contexts |
| AI content labeling | China | Live since 1 Sep 2025 | Visible labels plus invisible metadata on AI media |
| AI Basic Act | South Korea | Live since 22 Jan 2026 (penalties ~2027) | Label AI content; watermark synthetic output |
| IT Rules amendment | India | Live since 20 Feb 2026 | Platform labeling and traceable metadata for AI content |
| Deepfake disclosure laws | 30 US states | Varies | Mostly political-ad and likeness disclosure |
EU AI Act Article 50
Article 50 is a transparency rule, not a ban. Its core obligations have applied since 2 August 2026. The EU Digital Omnibus - adopted by Parliament on 16 June 2026 and cleared by the Council on 29 June 2026 - gives systems already on the market before that date until 2 December 2026 to add the machine-readable marking.
It splits the work between two parties:
Providers - the companies shipping generative AI tools - must mark outputs (text, image, audio, video) in a machine-readable format that's detectable as artificially generated. That is Article 50(2), and it binds the model makers, not the studios using their models.
Deployers - organizations putting AI media in front of real audiences - must disclose deepfakes and certain AI-generated text on matters of public interest. That is Article 50(4): a human-readable disclosure, such as a label or caption, at the point of publication. There's a carve-out for text that underwent genuine human review and editorial control.
One thing worth knowing: the deepfake rules aren't about intent. If content looks or sounds like a real person, it needs a label - even if no actual person was depicted. The regulation doesn't ask whether you meant to mislead anyone.
Being based outside the EU doesn't exempt you. If the content reaches EU users, the deployer disclosure duty can reach you - and your EU-facing clients will ask for provenance on what you deliver regardless.
What a studio should do: don't strip the marking your tools add (an export, re-encode, or compositing step can silently drop it), put the human-readable disclosure on deepfake-style content where you publish, and keep a project-level record of what was made, with which tools, and who signed off. A visible badge on its own is not the machine-readable marking - that comes from the provider's tool.
California SB 942: the US counterpart
California SB 942, the AI Transparency Act, requires large generative AI providers - those with more than a million monthly users - to embed technical watermarks in AI-generated image, video, and audio, and to publish a free public tool anyone can use to detect them.
Its operative date was originally 1 January 2026, but AB 853 (signed October 2025) moved it to 2 August 2026 - the same day Article 50 took effect. Penalties run up to $5,000 per violation.
Like Article 50(2), it binds the providers, not the studios using their tools. The practical effect for a studio is the same: the tools you use should now be marking their output, and a pipeline that strips those markings in post throws away evidence your clients increasingly expect to see.
New York S8420A: synthetic performers in ads
S8420A requires advertisers to clearly label AI-generated synthetic performers - faces, voices, digital doubles - used in place of real people. It applies to advertising specifically, not just political speech, which makes it one of the first US laws that directly affects standard brand and agency work.
If a campaign running in New York uses an AI-generated person, that needs disclosure. The smart move is to flag AI likenesses at the project level so the disclosure requirement is already documented when you ship, not something you're reconstructing afterward.
Texas TRAIGA: the intent-based approach
Texas TRAIGA has been live since 1 January 2026. It's intent-based: the question is whether you deliberately deployed AI to discriminate, manipulate, or harm. Penalties run up to $200,000 per violation, with a 60-day cure period. Notably, there's a safe harbor for organizations following the NIST AI Risk Management Framework - one of the few statutory NIST safe harbors in US AI law. Good-faith process, documented, matters here.
TRAIGA is broader than media disclosure, but the takeaway for creative teams is the same one that runs through every regime in this guide: a documented trail of what you deployed and why is what turns a legal question into a non-event.
30 states, and what California's failure means
Thirty US states regulate deepfakes as of mid-2026, up from 28 at the start of the year. Most are disclosure-based rather than outright bans, and the biggest cluster targets political advertising.
California's broad AI political-content law is worth studying as a cautionary example: a federal judge struck it down on First Amendment grounds, ruling it too sweeping when it could have been narrowly targeted at demonstrably false speech causing real harm. The lesson for drafters is that disclosure mandates survive better than broader restrictions - which is why nearly everything passing at the state level is framed around labeling, not prohibition.
Beyond the West: China, India, and South Korea
If your brand work reaches audiences in Asia, these rules are already in force. Three of the largest markets have live labeling regimes, and all three use the same two layers the EU now requires: a visible label for the audience, and machine-readable metadata for traceability.
China has required labeling since 1 September 2025. A joint measure from four regulators - the Cyberspace Administration, MIIT, the Ministry of Public Security, and the broadcast regulator - mandates both audience-facing labels and invisible traceability metadata on AI-generated text, image, audio, and video distributed to Chinese users. Enforcement is actively running.
South Korea's AI Basic Act came into force on 22 January 2026, requiring labeling of AI-generated content and invisible watermarks on synthetic output. The government has said enforcement fines will not be imposed for roughly the first year, so real penalties (up to 30 million won) begin around January 2027.
India's IT Rules amendment took effect on 20 February 2026, requiring platforms - social media, video hosting, and online intermediaries - to label AI-generated content and carry traceable metadata where technically feasible. The duties sit primarily on the platforms, but the labeling chain reaches the creators supplying the content, and India is consulting on stricter continuous-labeling rules on top.
The through-line: the formal duties in all three sit mainly on platforms and providers, but none of them is met by a caption alone. They want a marking that travels with the media - the same kind Article 50 and SB 942 put on the providers - so the platforms you publish to will increasingly check for it.
What the stakes actually are
Article 50 transparency violations sit in the lower enforcement tier under the AI Act, but "lower" is relative - up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. California SB 942 adds up to $5,000 per violation for the providers it covers. For most studios, though, the more immediate pressure isn't a regulatory fine.
Enterprise procurement teams are adding AI content questions to vendor assessments. Platforms are building their own provenance requirements on top of existing law. And in any dispute, a team with a clear documented system looks very different from one reconstructing what happened from Slack messages and export logs.
The single asset that answers all of these - clients, platforms, and your own legal team - is a per-project provenance record. What that looks like in practice is here.
One baseline that covers most of it
Tracking every statute separately is a losing game because they keep changing. A better approach is to build one working habit that holds up under all of them:
- Keep machine-readable marking intact on every finalized asset. The providers now have to add it; your job is not to lose it in export, compositing, or re-encoding - and to be able to show what went into the parts no single tool's marking covers.
- Disclose AI-generated people and deepfakes in every consumer-facing asset. New York, the EU, and most state laws all converge here.
- Keep a per-project record of models, prompts, approvals, and distribution territories. Intent-based regimes want documented process; impact-based regimes want documented risk assessment. Both are answered by the same record.
- Know where you're publishing before you ship. The distribution territory determines which rules apply. Finding out after the fact is what turns a manageable question into an actual problem.
Frequently asked questions
When does the EU AI Act require AI labeling? The Article 50 transparency obligations have applied since 2 August 2026. Under the Digital Omnibus (adopted June 2026), systems already on the market before that date have until 2 December 2026 to add machine-readable marking.
Who does Article 50 actually bind? Two different parties. Article 50(2) puts the machine-readable marking duty on the providers of generative AI systems - the companies shipping the models. Article 50(4) puts a human-readable disclosure duty on deployers publishing deepfakes and certain AI-generated text. A studio is usually a deployer, not a provider.
Does the EU AI Act apply to US companies? Yes, if the content targets EU users. Where you're incorporated doesn't matter.
Which US states require AI content disclosure? Thirty states regulate deepfakes as of mid-2026. California SB 942 has required large generative AI providers to watermark output since 2 August 2026. New York separately requires labeling AI synthetic performers in advertising. Texas has required compliance with TRAIGA since January 2026.
Do non-Western markets require AI labeling? Yes. China has mandated visible labels plus invisible metadata since September 2025, South Korea's AI Basic Act since January 2026 (penalties from around 2027), and India's IT Rules amendment since February 2026. The duties sit mainly on platforms and providers, and all three want a marking that travels with the media, not just a caption.
How do I handle multiple jurisdictions at once? Keep the markings your tools add intact, disclose AI-generated people wherever the work is published, and keep a per-project record of what was made, with what, and where it shipped. Details in the provenance guide.
The bottom line
The laws differ in scope, framing, and geography. But they all ask the same underlying question: can you show what's AI, how it was made, and who approved it? The teams that answer that question easily are the ones who built it into how they work, not the ones who start looking for files the week a client asks.
Want to know which of these laws touch your pipeline? See what applies to your work. For the usage terms of the models themselves - commercial use, training on your inputs, output ownership - see AI model terms.