The label was on the screen. The regulator ruled it wasn't enough
Two rules landed a fortnight apart. One says label the synthetic content. The other says a label nobody read is not a defence, and that gap is where AI disclosure stops being a legal task and becomes a creative one.
By Katie Delaney · 2026-08-08 · 17 min read
What Italy's Garante did to a satirical deepfake#

The fox does not argue with the fence, it finds the gap. A gap opened this week between two rules on AI disclosure that most marketers assumed said the same sensible thing, and a great deal of AI-era advertising creative is about to fall straight through it. The rule you have been briefed on says label the synthetic content. The rule that just bit says a label a viewer never registered is not a defence at all.
Italy's data protection authority adopted a provvedimento against R.T.I. Reti Televisive Italiane S.p.A., the Mediaset company behind the satirical programme Striscia la Notizia, over segments that used AI systems to manipulate the image and the voice of the journalist Enrico Mentana. The decision, doc-web 10281021, was adopted on 23 July 2026 and publicised on 7 August 2026, per the Garante's own record. Two dates, one document, and the second is the one the headlines held.
The measures matter more than the mood. Under Article 58(2)(f) the authority ordered, in Italian, the "divieto di ulteriore trattamento dei dati del reclamante con le modalità sopra descritte, eccettuata la mera conservazione degli stessi ai fini di un loro eventuale utilizzo in sede giudiziaria". Paraphrasing, and this paraphrase is ours rather than the authority's own English, that is a stop on processing the complainant's data in the manner described, with mere retention permitted only for possible court use.
Alongside the ban came a formal ammonimento under Article 58(2)(b), an annotation in the internal register, and thirty days from notification to report back on what has actually changed. The provisions cited run to GDPR Article 5(1)(a), (b) and (c), Article 6 and Article 25, plus Article 137 of the Italian Codice, the essentiality principle that governs journalism. What did not arrive is the thing every brand team looks for first: there was no monetary fine.
None of that reads like an AI disclosure case on paper, and that is precisely why it should be read as one. No AI-specific statute was invoked. A broadcaster showed warnings, a viewer complained, and general data protection law did the rest. Every brand shipping synthetic media should track that route through the undergrowth, because it is the route the next complaint will take.
The dates, said plainly, and one honest caveat#
The decision is a fortnight old, not fresh from the oven, and any brand strategy consulting practice that presents it as a brand-new ruling is reading the press cycle rather than the record. The Garante's Italian comunicato stampa carries the 7 August publication, per the authority's press release, and ANSA ran the statement at 14:00 Rome the same day. The authority's English-language press listing would not load while this was written, so that date rests on those two records rather than on an English original.
The reasoning is the part that should reorganise your creative process. The thrust of it, drawn from the decision's own record and from Italian reporting rather than from any single quoted English sentence, is that the warnings shown were not clear enough for an ordinary or inattentive viewer, and that realistic studio staging made the alteration hard to perceive. Il Sole 24 Ore reports the realism of the images and the plausibility of the statements as central to the finding.
Why AI disclosure is a comprehension test, not a badge#
Here is the collision, and it is sharper than the coverage suggests. The AI Act tells you to label. The Garante has just held that labelling, on its own, is not a defence. Both statements are true at once, and the space between them is where every synthetic media brief now lives. Treat AI disclosure as a filing exercise and you will pass the paperwork and fail the person.
Start with what the Act actually asks. Article 50's transparency obligations became applicable on 2 August 2026, and the Commission's enforcement announcement names three duties: interactive systems must tell people they are dealing with AI rather than a human, images, video and audio edited or generated with AI must be labelled, and that content must also carry machine-readable marks so it can be detected more easily. Three duties, one direction: make the artificial announce itself.
The wording of the deepfake duty is narrow and worth reading twice. Deployers of a system that generates or manipulates image, audio or video content constituting a deep fake "shall disclose that the content has been artificially generated or manipulated", per the AI Act Service Desk text of Article 50. Disclose. Not explain, not verify, not confirm comprehension. Disclose. Read literally, the statutory bar for AI disclosure is presence, and presence is a low hedge to hop.
The Commission's guidance tightens the timing rather than the test. Deployers must disclose deepfakes upon first exposure at the latest, in a clear and distinguishable manner, without demanding special technical tools of the viewer, per the Commission's Article 50 transparency FAQ. That same FAQ sets three cumulative criteria for a deepfake: close resemblance, an existing or plausibly real subject, and a false appearance of authenticity capable of misleading someone about whether the content is genuine.
Labelled is a legal state, understood is a creative outcome#
Read those two tests together and the folkfox argument writes itself. AI transparency measured as label presence is a checkbox any producer can tick in an afternoon. AI transparency measured as viewer comprehension is a design problem, and design problems belong to creative teams, not to legal review. The Garante's finding did not turn on whether a warning existed. It turned on whether an average viewer, including one who joined mid-broadcast, actually took it in.
So AI disclosure is a comprehension outcome, and comprehension is a creative problem long before it is a legal one. The lawyer can tell you the label is required. Only the art director can tell you whether anybody will see it, and only the media plan can tell you at what size, on what device, for how many seconds.
Advertising creative is consumed on mute, at thumb speed, in a scrolling feed, often mid-sentence. If AI disclosure has to survive that environment, it has to be built for that environment, which means the same craft you would spend on a hook. That is the practical thesis behind our read on AI slop as a distribution problem, and it is why we keep filing AI disclosure under creative direction rather than under compliance.
Legally present, practically invisible
Six-point grey type in the lower corner, on screen for two seconds, burned under a busy studio composite. This AI disclosure satisfies a checklist, survives a screenshot audit, and an inattentive viewer arriving mid-scroll will never see it. Presence is the only thing it proves.
Built to be caught at thumb speed
AI disclosure at first frame, legible on mute, sized for a phone held at arm's length, repeated on re-entry, mirrored in the caption and in the machine-readable mark. It is designed to be registered, not merely to exist. Comprehension is the thing it proves.
The signing behaviour around the voluntary code shows how new all this still is. The Commission's enforcement page counts more than 180 signatories to the Code of Practice on Transparency of AI-generated Content, while its policy page for the same code puts the end-of-July count at roughly 190, a small discrepancy worth flagging rather than smoothing over. Adherence to that code is voluntary. The Article 50 obligations underneath it are not.
Those five dates are the Commission's own, published on the code's policy page, and the accompanying transparency guidelines arrived to explain who counts as a provider and who counts as a deployer. There are even three optional EU icons for labelling, in twelve variants, per the Commission's icon page. The icons are optional. The labelling is not.
Two regimes, one asset, and a real person in the frame#
The third strand is the one that catches brands unprepared, because it is not about AI at all. This was a complaint by an identifiable individual about his own likeness. Article 50 governs synthetic media generally. GDPR governs a person. Put a real, recognisable human into your generated creative and you are standing in both regimes at once, with two different complainants, two different sanctions and two different clocks.
The Garante found RTI violated GDPR articles 5 and 25, so the warning and ban were issued.
That distinction has a commercial edge with teeth. Consent to appear is not consent to be synthesised. A talent contract that licenses a shoot does not license a model trained on the footage, and a release form drafted before 2023 almost certainly says nothing useful about voice cloning. The scent to follow here is contractual, not technical, and no amount of AI disclosure repairs a release that never contemplated synthesis.
| Question | AI Act, Article 50 | GDPR, as applied here |
|---|---|---|
| What it regulates | AI-generated or manipulated content, whoever appears in it | Personal data of an identifiable individual |
| Who raises it | Market surveillance authorities under the Act's enforcement structure | The individual, by complaint to a supervisory authority |
| The test | Was the content disclosed and machine-readably marked | Was processing lawful, fair, transparent and essential |
| Satire | Explicitly softened for evidently satirical work under Article 50(4) | No equivalent carve-out for a person's dignity |
| The sanction | Fines up to EUR 15,000,000 or 3% of worldwide turnover | Prohibition, warning, compliance reporting, and fines where imposed |
The UK arrives at a similar destination by a different path. There is no blanket legal requirement in the UK to disclose the use of AI in advertisements, per the ASA's disclosure guidance, which instead asks two questions: is the audience likely to be misled if the use of AI is not disclosed, and if so, does the disclosure clarify the message or contradict it.
That second question is the sharp one, and it points where the Garante pointed. An AI disclosure that contradicts the message is a disclosure the viewer resolves in favour of the message. The CAP Code is media-neutral, so the rules apply regardless of how content was created, and advertisers remain responsible for the final result whatever tool produced it, per the ASA's deepfake briefing of 11 June 2026. Three jurisdictions, one direction of travel: AI disclosure is measured on the viewer, not on the file.
The regulator did not ask whether you disclosed. It asked whether anybody understood.
Existing rules already cover a surprising amount of this. Misleading images, false endorsements and harmful imagery are handled by the codes as they stand, per CAP's policy monitoring note. So the honest framing for a board is not that new law has appeared from the undergrowth. It is that old law has found a new asset class, and the asset class is yours.
Price the prohibition, because the fine was never the risk#
Notice what the Garante did not do. No fine landed. The sanction was a prohibition and a warning, and for a brand that ordering is worse rather than better, which is the single most under-reported line in the whole story.
Run the arithmetic a marketing director actually runs. A fine is a number that arrives after the campaign has finished earning. A prohibition is an order to stop using an asset while it is still in flight. It strands the production spend, orphans the media commitments already booked against that asset, and forces a replacement through a compressed approval chain at exactly the moment the brand least wants attention. The trail from stop order to reshoot is short, expensive and public.
That is the real price of getting AI disclosure wrong, and it is nowhere near the fine schedule. Weak AI disclosure does not cost you a penalty line, it costs you the asset, and the asset is where the money already went.
The penalty ceilings still deserve a look, because they set the outer edge of the AI Act conversation. Breaching Article 50 sits in the middle tier, capped at EUR 15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, per the Commission's transparency FAQ. The full tier structure of Article 99 appears in an unofficial consolidated text, which flags its own machine-generated status, and the authoritative wording lives in Regulation (EU) 2024/1689 on EUR-Lex.
The clock is the other cost#
Every deadline in this story is short, and the calendar is where the real pressure sits. The Garante gave thirty days to report back. The Commission's FAQ records a grace period running to 2 December 2026 for marking and detection obligations on systems placed on the market before 2 August. The code that explains how to comply took 270 days to write, from the kick-off plenary on 5 November 2025 to applicability on 2 August 2026.
Days from adoption to publication
Adopted 23 July 2026, publicised 7 August 2026.
Monetary fine imposed, in euros
A prohibition and a warning instead, which for a live campaign costs more.
Days to report compliance
Counted from notification of the decision.
Brands that have already built a deepfake detection and provenance habit will find this cheap. Brands that have not will discover that the audit itself, the inventory of every asset touched by a generative tool, takes longer than the AI disclosure does. That inventory is the first thing our brand strategy engagements now open with, and the reason we wrote about AI-generated advertising losing the right to stay quiet. Good brand strategy consulting prices the pull, not the penalty.
Five honest lessons for anyone shipping synthetic media#
The fox does not waste a warning, and this one was issued at somebody else's expense. Five lessons, each of them a creative instruction rather than a legal one.
First, design the disclosure for the worst viewer, not the attentive one. The Garante's reasoning turned on the ordinary and the inattentive, the person who joined mid-broadcast and never saw the opening card. Your equivalent is the muted autoplay in a crowded feed. Build for that viewer and every other viewer is covered.
Second, put AI disclosure into the creative brief, at concept stage, next to the hook. AI disclosure retrofitted in the edit is always the wrong size, the wrong shade and the wrong duration, because nothing in the composition was built to leave room for it. Treat it as a design constraint and it becomes part of the craft rather than a scar across it.
Third, mark the file as well as the frame. Article 50(2) asks for machine-readable marking that is effective, interoperable, robust and reliable, per the Service Desk text. The industry answer is provenance metadata: the Coalition for Content Provenance and Authenticity publishes the Content Credentials specification for certifying the source and history of media, and TikTok became the first video platform to read those credentials automatically from 9 May 2024, per TikTok's newsroom.
Write the AI disclosure into the creative brief at concept, with a size, a duration and a position, so the composition leaves room for it.
Review every synthetic asset silently, at phone size, entered halfway through. If the disclosure is missed, it has failed the Garante's test whatever legal says.
Embed provenance credentials on export so the asset stays detectable after a download, a re-upload and a crop.
Confirm that every recognisable person consented to synthesis specifically, not merely to appearing, and that the release names the technique.
Agree in advance who can stop a live asset within 24 hours, and what replaces it, so a prohibition is a procedure rather than a panic.
Fourth, remember that the platforms already police this, and their rules bite faster than any regulator. YouTube requires creators to disclose when AI meaningfully alters or generates photorealistic content, including making a real person appear to say something they did not, and applies its own label in the player when they do not, per YouTube's disclosure policy. Meta has run an AI info label on detected content since 2024, per Meta's labelling announcement. Your creative meets the platform rule long before it meets the statute.
Fifth, market the discipline. In a category where every competitor is quietly generating, a brand that can prove provenance has a trust asset, and trust is the quarry that generative search is already hunting for. Being the recognisable, verifiable source is the same advantage we tracked in the study on models searching for brands they already know, and the same reason a brand can be cited everywhere and recommended nowhere.
None of this needs a new department. It needs the disclosure to be drawn rather than declared, which is a job for the people who already know how to make something land in two seconds. If you want that built into the work rather than bolted onto it, that is what our content marketing and paid social teams do, with a conversation as the cheapest possible starting point. The label was never the point. The understanding was.
Frequently asked questions#
What did Italy's Garante actually decide about the Striscia la Notizia deepfakes?
It adopted a decision on 23 July 2026, publicised on 7 August, banning R.T.I. Reti Televisive Italiane from further processing of Enrico Mentana's data in the manner described, issuing a formal warning, and requiring a compliance report within thirty days. No monetary fine was imposed.
Is AI disclosure on an advert enough to satisfy the law?
Not on its own. The EU AI Act requires AI disclosure, but the Garante's reasoning turned on whether an ordinary or inattentive viewer actually understood the content was artificial. A label that exists but is not registered can still leave the underlying processing unlawful.
Does the EU AI Act have an exemption for satire?
Yes, in part. Article 50(4) softens the deepfake obligation for evidently artistic, creative, satirical or fictional work, requiring disclosure in a manner that does not hamper enjoyment of the work. That exemption sits in the AI Act, not in data protection law.
What is the maximum fine for breaching the AI Act's transparency rules?
Breaches of the transparency obligations are capped at EUR 15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is a statutory ceiling under Article 99, not a typical outcome.
If our advert features a real person generated by AI, which rules apply?
Both. The AI Act governs the synthetic content, and data protection law governs the identifiable person in it. Consent to appear in a shoot is not consent to be synthesised, so check whether your talent release names the technique explicitly.
Do the platforms have their own AI disclosure rules?
Yes, and platform AI disclosure usually bites sooner. YouTube requires creators to disclose meaningfully altered photorealistic content and labels it in the player, and Meta has applied an AI info label to detected content since 2024. Platform enforcement typically precedes any regulator.
Who should own AI disclosure inside a marketing team?
Creative, with legal as a reviewer rather than an author. Legal can confirm that AI disclosure is required and what it must say. Only the creative team controls whether it is seen, since size, position, duration and contrast decide comprehension, and comprehension is what regulators are actually testing.
Read more on this topic#
AI generated advertising just lost the right to stay quiet
The Article 50 obligations themselves, and what they ask of a production pipeline.
Read the pieceThe model searches for the brands it already knows
Why provenance and familiarity are becoming the same competitive asset.
Read the pieceThe platforms just made AI slop a distribution problem
What happens to generated creative once the feed itself starts filtering it.
Read the pieceThe model cites you everywhere and recommends you nowhere
Being quoted is not the same as being trusted, in search or in law.
Read the piece
Want AI disclosure designed rather than bolted on?
folkfox audits generated creative against the rules it actually answers to, then builds AI disclosure that a muted, scrolling, half-attentive viewer genuinely registers.