THEY SAID*

GETTING GROWING / THE ANSWER / 12 AUG 2026 / 4 MIN READ

Does our agency have to disclose that we used AI on a client's work?

For public-facing work reaching the EU or California, increasingly yes. Both regimes came into force on 2 August, and the labelling requirement follows on 2 December.

If the work is public-facing and reaches an audience in the EU or California, increasingly yes - the EU AI Act's Article 50 transparency duties and California's AI Transparency Act both came into force on 2 August 2026, and the machine-readable labelling requirement for AI-generated content follows on 2 December.

This is an editorial answer rather than a legal one, and anything with a €15m ceiling attached to it deserves a real lawyer. What follows is the version an agency leader needs in order to know what to go and ask.

What actually came into force on 2 August

Two things landed on the same day, which is why the week produced so much noise.

The EU AI Act's transparency obligations under Article 50 now apply. They cover four situations: systems interacting directly with a person, AI-generated content, emotion recognition and biometric categorisation, and deep fakes or AI-generated text published on matters of public interest. The duty splits between providers, who have to build systems that mark their own output, and deployers, who have to tell people when they are on the receiving end of one. An agency using a commercial model to make client work is a deployer.

California's AI Transparency Act became operative the same day, requiring hidden provenance watermarks with a visible disclosure option available. The two regimes are converging on the same idea from different directions, which is the detail worth noticing. This is not one jurisdiction being difficult.

Territorial reach is the part agencies get wrong. Neither regime cares much where your office is. They care where the audience is.

The bit that bites in December

The obligations that arrived this month are largely about telling people. The requirement to embed machine-readable marks in AI-generated content - the plumbing rather than the notice - was deferred to 2 December.

Four months is not long for a production process that currently has no field in it for provenance. The AI Office has also published a voluntary Code of Practice on transparency of AI-generated content; signatories get a degree of presumed conformity and a friendlier enforcement posture, while everyone else has to demonstrate compliance some other way.

For an agency, that is the practical fork in the road. Either the provenance question gets answered once, upstream, in how work is made and logged - or it gets answered forty times a year, badly, by whoever is closest to the deadline.

Why "we'll handle it case by case" is the expensive answer

Most agencies currently have no position on this, which functionally means the position is set by whichever producer is on the job.

That works until the first time it doesn't. The failure is rarely a regulator. It is a client's legal team asking, three days before a launch, whether any part of the asset was generated, and nobody being able to answer with confidence because the answer is spread across four freelancers, two tools and a Slack thread from June.

The cost is the delay, the emergency reshoot, and the client's conclusion that you are not in control of your own production. None of that appears in a fine.

The regulation is not the risk. Not being able to answer the question quickly is the risk.

What clients are about to start asking

The commercial change arrives ahead of any enforcement action, and it arrives through contracts.

Expect AI provenance warranties to start appearing in master services agreements. Expect procurement to ask which models were used on which deliverables, and to ask it in a form that requires a written answer. Expect at least one large client to ask you to sign something you have not read carefully enough, because their legal team is also improvising.

Agencies that can answer these questions crisply will find it becomes a small competitive advantage almost immediately, in the same unglamorous way that information security questionnaires quietly sorted the market a decade ago. Agencies that cannot will spend the autumn drafting answers under time pressure.

The reputational layer the law does not touch

Running underneath the compliance question is a second one that no statute addresses, and it cuts in both directions.

Some agencies are under-declaring AI in the work while over-declaring it in their credentials. Julie Seal and Art Tindsley wrote about the red flags and snake oil in AI adland in The Drum last week, and the pattern they describe is familiar: capability claimed in a pitch that does not exist in the studio. That gap was survivable while nobody could check. Disclosure rules make one half of it checkable, and clients are getting better at testing the other half.

The agencies in the strongest position are the ones whose public account of how they work matches what actually happens on a Tuesday. That has always been true. It is now becoming enforceable in one direction and easily embarrassing in the other.

The position worth having

You do not need a policy document this month. You need a settled answer to three questions, held by a named person rather than a committee.

Where does the audience sit, and therefore which regimes touch your output. What gets recorded at the point work is made, so provenance is a lookup rather than an investigation. And who signs off the disclosure line when it is genuinely ambiguous - because it will be, often, and the ambiguity is where the delay lives.

Agencies that answer those three now will find December uneventful. The rest will find out what their production process actually records, at the worst possible moment.

If you want a view on how your agency should be talking about its use of AI in public - which is a positioning question long before it is a compliance one - drop us a line.

WRITTEN BY

Fayola Douglas, founder of They Said

MORE IN GETTING GROWING

Want this engine running on your agency?

Book a call ↗