AI content disclosure laws in 2026: the complete field guide
A living tracker of the AI content disclosure laws creative and marketing teams must plan around in 2026 - the EU AI Act Article 50, California SB 942, New York S8420A, Texas TRAIGA, and the labeling rules already live in China, India, and South Korea - with deadlines, who is covered, and what to do before each one bites.
Disclosure used to be the thing your legal team mentioned once and then forgot about. That's changed. The EU's transparency rule lands in August. California's watermarking law now lands the same day. New York's synthetic-performer law is already in effect, Texas has been enforcing since January, and mandatory labeling regimes are already live in China, India, and South Korea. This is no longer a Western story.
This is the rundown of what actually matters for creative and marketing work - the dates, who's caught, and what you need to do before each one becomes your problem.
Updated 6 July 2026. AI law is moving fast. We refresh this monthly - always check primary sources before making decisions.
The fastest-moving deadlines
| Law | Jurisdiction | Key date | What it does |
|---|---|---|---|
| EU AI Act Article 50 | EU | 2 Aug 2026 (existing-system marking: 2 Dec 2026) | Machine-readable marking of AI output; deepfake disclosure |
| SB 942 | California | 2 Aug 2026 | Watermark AI-generated media; offer a free public detection tool |
| S8420A synthetic performers | New York | June 2026 | Label AI-generated synthetic performers in ads |
| TRAIGA | Texas | Live since 1 Jan 2026 | Intent-based ban on harmful AI deployment; disclosure in some contexts |
| AI content labeling | China | Live since 1 Sep 2025 | Visible labels plus invisible metadata on AI media |
| AI Basic Act | South Korea | Live since 22 Jan 2026 (penalties ~2027) | Label AI content; watermark synthetic output |
| IT Rules amendment | India | Live since 20 Feb 2026 | Platform labeling and traceable metadata for AI content |
| Deepfake disclosure laws | 30 US states | Varies | Mostly political-ad and likeness disclosure |
EU AI Act Article 50
Article 50 is a transparency rule, not a ban. Its core obligations apply from 2 August 2026. The EU Digital Omnibus - adopted by Parliament on 16 June 2026 and cleared by the Council on 29 June 2026 - gives systems already on the market before that date until 2 December 2026 to add the machine-readable marking. Those dates are now locked: August for new output, December for the back catalogue.
Here's what it actually requires:
Providers - the companies shipping generative AI tools - must mark outputs (text, image, audio, video) in a machine-readable format that's detectable as artificially generated.
Deployers - organizations putting AI media in front of real audiences - must disclose deepfakes and certain AI-generated text on matters of public interest. There's a carve-out if the content underwent genuine human review and editorial control.
One thing worth knowing: the deepfake rules aren't about intent. If content looks or sounds like a real person, it needs a label - even if no actual person was depicted. The regulation doesn't ask whether you meant to mislead anyone.
Being based outside the EU doesn't exempt you. If the content reaches EU users, the deployer disclosure duty in Article 50(4) can reach you - and your EU-facing clients will expect the machine-readable provenance regardless. See the EU AI Act explainer for the full picture.
Before August: audit every AI touchpoint in your pipeline. A visible badge won't satisfy "machine-readable and detectable" - you need the manifest embedded in the asset and a project-level record of what shipped and who signed off.
California SB 942: the US law that lands the same day
While Article 50 is the headline, the US now has a direct counterpart. California SB 942, the AI Transparency Act, requires large generative AI providers - those with more than a million monthly users - to embed technical watermarks in AI-generated image, video, and audio, and to publish a free public tool anyone can use to detect them.
Its operative date was originally 1 January 2026, but AB 853 (signed October 2025) pushed it to 2 August 2026 - the same day Article 50 applies. So the practical planning date is a single one: get machine-readable marking on your AI media by 2 August, and you have moved on both the EU and California obligations at once. Penalties run up to $5,000 per violation.
This is the one to watch for US-facing work. It is framed around exactly what provenance tooling produces: a marking embedded in the media that a public checker can verify, not a caption a platform can strip.
New York S8420A: synthetic performers in ads
S8420A requires advertisers to clearly label AI-generated synthetic performers - faces, voices, digital doubles - used in place of real people. It applies to advertising specifically, not just political speech, which makes it one of the first US laws that directly affects standard brand and agency work.
If a campaign running in New York uses an AI-generated person, that needs disclosure. The smart move is to flag AI likenesses at the project level so the disclosure requirement is already documented when you ship, not something you're reconstructing afterward.
Texas TRAIGA: the intent-based approach
Texas TRAIGA has been live since 1 January 2026. It's intent-based: the question is whether you deliberately deployed AI to discriminate, manipulate, or harm. Penalties run up to $200,000 per violation, with a 60-day cure period. Notably, there's a safe harbor for organizations following the NIST AI Risk Management Framework - one of the few statutory NIST safe harbors in US AI law. Good-faith process, documented, matters here.
TRAIGA is broader than media disclosure, but the takeaway for creative teams is the same one that runs through every regime in this guide: a documented trail of what you deployed and why is what turns a compliance question into a non-event.
30 states, and what California's failure means
Thirty US states regulate deepfakes as of mid-2026, up from 28 at the start of the year. Most are disclosure-based rather than outright bans, and the biggest cluster targets political advertising.
California's broad AI political-content law is worth studying as a cautionary example: a federal judge struck it down on First Amendment grounds, ruling it too sweeping when it could have been narrowly targeted at demonstrably false speech causing real harm. More challenges are coming. The lesson for drafters is that disclosure mandates survive better than broader restrictions - which is why nearly everything passing at the state level is framed around labeling, not prohibition.
Beyond the West: China, India, and South Korea already require labeling
If your brand work reaches audiences in Asia, the obligation is not coming - it is already here. Three of the largest markets have live labeling regimes, and all three converge on the same two-layer approach the EU is moving toward: a visible label for the audience, and machine-readable metadata for traceability.
China has required labeling since 1 September 2025. A joint measure from four regulators - the Cyberspace Administration, MIIT, the Ministry of Public Security, and the broadcast regulator - mandates both audience-facing labels and invisible traceability metadata on AI-generated text, image, audio, and video distributed to Chinese users. Enforcement is actively running. If you produce AI creative for a brand with China-market exposure, this applies to that content now.
South Korea's AI Basic Act came into force on 22 January 2026, requiring labeling of all AI-generated content and invisible watermarks on synthetic output. There is one honest caveat: the government has said enforcement fines will not be imposed for roughly the first year, so real penalties (up to 30 million won) begin around January 2027. The obligation is live now; the teeth arrive later.
India's IT Rules amendment took effect on 20 February 2026, requiring platforms - social media, video hosting, and online intermediaries - to label AI-generated content and carry traceable metadata where technically feasible. The duties sit primarily on the platforms, but the labeling chain reaches the creators supplying the content, and India is consulting on stricter continuous-labeling rules on top.
The through-line: none of these can be satisfied with a caption alone. All three want a marking that travels with the media. That is the same artifact Article 50 and California SB 942 ask for - which is the whole argument for building to the marking, not to any one statute.
What the stakes actually are
Article 50 transparency violations sit in the lower enforcement tier under the AI Act, but "lower" is relative - up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. California SB 942 adds up to $5,000 per violation on top for US-facing work. That said, the more immediate pressure for most teams isn't the regulatory fine.
Enterprise procurement teams are adding AI content questions to vendor assessments. Platforms are building their own provenance requirements on top of existing law. And in any dispute, a team with a clear documented system looks very different to a regulator than one reconstructing what happened from Slack messages and export logs.
The single asset that covers all of these - regulators, clients, platforms - is the same thing: a per-project provenance record. What that looks like in practice is here.
One baseline that covers most of it
Tracking every statute separately is a losing game because they keep changing. A better approach is to build to the strictest common denominator and let the compliance follow:
- Embed machine-readable AI marking by default on every finalized asset. That's the marking Article 50 puts on the model providers - and the provenance your clients now expect on the deliverable. It also future-proofs you against any state law that moves in the same direction.
- Disclose AI-generated people and deepfakes in every consumer-facing asset. New York, the EU, and most state laws all converge here.
- Keep a per-project record of models, prompts, approvals, and distribution territories. Intent-based regimes want documented process; impact-based regimes want documented risk assessment. Both are answered by the same audit trail.
- Know where you're publishing before you ship. The distribution territory determines which rules apply. Finding out after the fact is what turns a manageable compliance question into an actual problem.
Frequently asked questions
When does the EU AI Act require AI labeling? The Article 50 transparency obligations apply from 2 August 2026. Under the Digital Omnibus (adopted June 2026), systems already on the market before that date have until 2 December 2026 to add machine-readable marking. Both dates are now fixed.
Does the EU AI Act apply to US companies? Yes, if the content targets EU users. Where you're incorporated doesn't matter.
Which US states require AI content disclosure? Thirty states regulate deepfakes as of mid-2026. California SB 942 requires large generative AI providers to watermark output from 2 August 2026. New York separately requires labeling AI synthetic performers in advertising from June 2026. Texas has required compliance with TRAIGA since January 2026.
Do non-Western markets require AI labeling? Yes, and several are already live. China has mandated visible labels plus invisible metadata since September 2025, South Korea's AI Basic Act since January 2026 (penalties from around 2027), and India's IT Rules amendment since February 2026. All three want a marking that travels with the media, not just a caption.
Is Texas TRAIGA a media-labeling law? Not exactly - it's a broader intent-based rule against deploying AI to discriminate, manipulate, or harm, live since January 2026. It matters to creative teams mainly because the documented audit trail it rewards is the same one every disclosure law rewards.
How do I handle multiple jurisdictions at once? Machine-readable marking by default, per-project audit trails, and disclosed AI likenesses everywhere covers most of the field. Details in the provenance guide.
The bottom line
The laws are different in scope, framing, and geography. But they all ask the same underlying question: can you show what's AI, how it was made, and who approved it? The teams that answer that question easily are the ones who built it into how they work, not the ones who started the compliance project the week before a deadline.
Want to know which of these laws touch your pipeline? See what applies to your work, or try the risk preview.