← All posts

The Archibal Team

Commissioning AI content without inheriting the risk: a brand's guide

When a brand commissions AI-generated work from an agency, the legal and reputational risk often lands on the brand, not the vendor. Here is how to brief, verify, and archive AI deliverables so you can prove compliance across every agency you work with.

The agency builds it. You publish it. Under most AI disclosure laws, that makes you the one with obligations - not them.

That's not a hypothetical. The EU AI Act's Article 50 places disclosure duties on the organization that deploys AI content to an audience, which is almost always the brand, regardless of who produced the asset. New York's S8420A targets the advertiser running the campaign, not the production shop. This guide is for the in-house team that ends up holding the bag: what to ask for, how to check what you receive, and how to stay organized when you're working with more than one agency.

Why the risk lands on the brand

When an agency hands over a polished AI-generated campaign with no provenance attached, they're handing you the creative upside and leaving you the legal exposure. You can't outsource the deployer obligation - the law attaches it to whoever puts the content in front of an audience.

The practical implication: if a regulator or client asks "did you know this was AI-generated, and can you prove it was handled correctly?" - the answer has to come from you. Not from your agency's inbox. See the field guide to AI disclosure laws for the full landscape of what applies where.

What to require before sign-off

Provenance should be a deliverable, the same as the final file. For any AI-touched asset, require:

Content Credentials in the file. A C2PA manifest recording the models used, the production stages, and a cryptographic signature. This is the machine-readable marking the EU AI Act is pointing toward, and it's the thing a Content-Credentials-aware viewer can check in seconds.

A signed project compliance record. A human-readable document covering every delivered asset - the models and prompts that shaped it, the sign-off chain with timestamps, and content hashes tying each asset to the record. When a platform strips the file's embedded metadata (and most of them do), this document is what remains.

An explicit list of AI likenesses and deepfakes. If any face, voice, or digital double in the deliverable is AI-generated, it needs to be flagged. Several jurisdictions now require the brand to label these, not the agency.

Territory scope. Confirmation the work was assessed against the rules in the markets you're actually publishing to. "Compliant" without knowing where you're running it means nothing.

If an agency can't produce these, that's worth knowing before the campaign runs, not after.

How to check what you receive

Don't accept "it's compliant" without looking. When the provenance is real, verification takes minutes:

  1. Read the Content Credentials. Open the file in a Content-Credentials-aware viewer - verify.contentauthenticity.org is the public one - and confirm the manifest is present, signed, and actually describes the asset in front of you.
  2. Review the signed project record. Check that it covers every delivered file, names the approvers, and has timestamps. A record that covers five of seven assets is not a record.
  3. Confirm the fingerprint. A perceptual fingerprint - built at ingest, a content-derived hash of the media itself - means you can match an asset later even if it's been re-encoded or the metadata has been stripped. If you're receiving assets through Archibal, this is automatic; if you're not, ask the agency how they handle it. For the fuller explanation of how these layers fit together, see what is AI provenance.

The multi-agency problem

Most brands aren't working with one agency. They're working with several, each with different tools, different workflows, and different ideas about what "compliant" means. The compliance record that lives in three different vendor portals and two email threads is a compliance record you can't actually produce when someone asks.

The answer is one archive that aggregates everything: every deliverable, every proof, every campaign, from every agency. A roll-up that can tell you which laws applied to which campaigns, whether each obligation was met, and how long the evidence needs to be kept. Regulatory investigations and client audits tend to arrive long after the campaign ended - the retention period matters.

Archibal is built around that model: the agency delivers into it, you receive and verify in it, and the archive is yours regardless of which vendor made the work.

Contract clauses that actually help

Make provenance an expectation in the contract, not something you ask for after the fact:

Provenance warranty. The agency warrants that every AI-touched deliverable ships with Content Credentials and a signed compliance record. Not "will endeavor to" - warrants.

Disclosure obligation. The agency identifies all AI-generated likenesses, voices, and synthetic performances in the deliverable, explicitly, in writing.

Indemnity. The agency indemnifies you for losses arising from undisclosed or misrepresented AI use. This shifts consequences for the things they know and you don't.

Audit cooperation. The agency agrees to provide provenance records on request, for whatever retention period you specify in the brief.

None of these are unusual asks in a world where the brand carries the disclosure obligation. They're what accountability looks like in a contract.

Frequently asked questions

If the agency makes the AI content, am I still liable? Usually yes - as the organization publishing it, you're the deployer under most AI disclosure laws, and that duty is independent of whatever agreement you have with the agency.

What's the minimum I should ask for? Content Credentials in the file, a signed project record covering every delivered asset, explicit disclosure of any AI likenesses, and confirmation the work was assessed for your distribution territories.

How do I handle compliance across several agencies? One archive, one retention policy. Provenance scattered across vendor portals is provenance you can't produce. Aggregate it centrally.

How long do I need to keep the records? It depends on jurisdiction, but plan for the length of the statute of limitations in your publishing markets - typically three to six years for EU Article 50 and most US state contexts. When in doubt, keep more.

The bottom line

Commissioning AI content isn't the risk. Commissioning it blind is. The brands that don't end up in a difficult conversation with a regulator or a client are the ones who treated provenance as a procurement standard - required it in the brief, verified it on receipt, and kept one durable archive across all their agencies. That's what the receive-and-verify workflow in Archibal is built for.

Commissioning AI work? See how brands receive and verify certified deliverables with Archibal.

© 2026 Archibal.AI Inc. All rights reserved.