Austria's Interactive Advertising Bureau and law firm act legal Austria published a five-page guide on September 16, 2026 setting out when advertising produced with artificial intelligence needs a visible disclosure under the EU AI Act, and it concludes that the agency operating the AI tool is normally the responsible party, not the brand paying for the campaign.

In Short

Austria's online advertising association and a Vienna law firm wrote a short guide on when ads made with AI need a visible notice saying so, under EU rules that have applied since August 2, 2026. It matters to agencies, brands and publishers because the guide says the agency using the AI tool is normally responsible, while brands and publishers only pick up duties of their own if they direct or change the AI work themselves. What changes is that every company in an advertising deal is being asked to write into its contracts who decides on a label, who adds it and who pays if it is missing.

What the guide covers

The document is short. Titled "KI-Kennzeichnung im Digitalmarketing" - AI labelling in digital marketing - it runs to five numbered pages and six sections, all in German; the quotations in this article are PPC Land translations. Its subject is Article 50 of Regulation (EU) 2024/1689, the transparency chapter of the AI Act, which according to the guide has applied since August 2, 2026 and has brought new transparency obligations to the communications industry.

Authorship sits with the iab AG Artificial Intelligence, IAB Austria's working group on AI, which drew up the text with act legal Austria. According to IAB Austria, the group is led by Iris Handlsberger of e-dialog, with Gerhard Günther of DSR Agency, Maximilian Mondel of MOMENTUM, Stephanie Mauerer of e-dialog and Christoph Truppe as members. The legal assessment came from Mag. Philipp E. Stephan, a Rechtsanwalt at act legal Austria, who stresses that any concrete application has to be judged case by case, according to IAB Austria. The memo itself states only that it was written in September 2026; the publication date comes from the association's news item presenting the guide, dated September 16.

It is not the association's first practical rulebook this year. IAB Austria's creator unit published a 40-page influencer marketing guide on March 3, 2026 covering legal, tax and disclosure rules, and recommended that cooperation agreements specify labelling obligations and approval processes. The AI memo is far shorter. It closes with a disclaimer: the text offers a first, general overview, makes no claim to completeness and does not replace legal advice in an individual case, according to the guide.

What falls outside the duty

The memo opens with the exemptions and presents them as the most important point. "Not every advertising asset in which AI played a part must necessarily bear a label," according to the guide. Abstract AI graphics, cartoon characters, obviously fictional depictions and simple technical edits are all exempt from the visible labelling requirement. The technical edits it names are noise reduction, colour correction and classic retouching.

Timing gets a box of its own. Content created before August 2, 2026 does not have to be labelled retroactively, according to the guide. That protection ends when such content is newly published or served again from that date, at which point the labelling obligation applies.

The second sentence matters for programmatic trading. The German verb the guide uses, ausspielen, is the everyday industry term for serving an ad. Read literally, a creative produced in June and still delivering impressions in September is being served again with every impression. The guide does not say whether an in-flight campaign that simply continued across the August 2 boundary falls into that category, or whether only a fresh publication or relaunch does. For evergreen assets in always-on campaigns, the difference is not academic.

Three situations that trigger a visible label

Where the obligation does apply, according to the guide, is mainly with content that looks realistic and gives the impression of being genuine. Three categories are listed.

Image, video and audio

The first covers media that look deceptively real, imitate real situations or materially falsify them. The guide names deepfakes, cloned AI voices, fake testimonials and manipulated real places or events.

A warning box headed "case-by-case review" follows. Whether an advertising asset counts as a deepfake depends, among other things, on how closely it resembles a real person, a real place or a real event, and on whether it can give the audience the false impression of being authentic. "Even small design differences can change the legal assessment," the guide states. It points to the Commission's guidelines on Article 50, which contain practical examples, particularly for advertising, and recommends obtaining legal advice in doubtful cases before an asset is served.

Those guidelines were issued as Communication C(2026) 5054 final on July 20, 2026, together with a finalised Code of Practice on Transparency of AI-Generated Content. The Austrian test lines up closely with the one Dutch trade association VIA Nederland set out for creative agencies on September 5, which also turns on whether a viewer could be misled about authenticity and which also treats minor colour grading or lighting adjustments as outside the disclosure duty. One difference stands out. The Dutch guidance works through the AI Act's lighter regime for artistic, satirical and fictional works and states that it does not apply to creative advertising where the commercial message dominates. The Austrian memo does not mention that carve-out. The closest it comes is the opening section, which exempts obviously fictional depictions from labelling altogether rather than allowing a less prominent label.

Text

The second category is narrower. It covers publicly accessible AI-generated texts on matters of public interest that are published without prior editorial control, according to the guide. Routine advertising copy does not appear in the list. What level of human review counts as editorial control is left undefined in the Austrian text; the Dutch guidance, by comparison, states that a spelling check or the rewriting of a handful of sentences is not enough.

Chatbots and support tools

The third category is direct interaction. When an AI communicates with people through chatbots or support tools, that fact must be clearly recognisable, according to the guide. The Austrian memo lists this among the situations requiring visible labelling without saying which party in the chain holds the duty. Article 50 does split that question: the obligation to inform users that they are dealing with an AI sits with providers of interactive systems, as the Commission's September 2025 consultation set out, and VIA Nederland attributes the chatbot disclosure to the provider as well.

A watermark is not a label

On form, the memo is blunt. An invisible watermark, metadata or a hidden note in the imprint and the terms and conditions are not sufficient, according to the guide. The label must be clearly and understandably visible to users within the advertising asset itself or, for audio, audible.

For design, the guide points to the free official EU icons the European Commission offers for download at several transparency levels. The Commission released that icon set on June 10, 2026: three designs, each with four visual variations, in SVG and PNG format. The variants carry the acronym "AI" on its own, "AI GENERATED" for fully synthetic content and "AI MODIFIED" for partially altered content.

The consequence for platform-built creative is specific. Google applies an imperceptible SynthID watermark and C2PA metadata automatically to images and videos generated inside its advertising tools. Both are machine-readable signals. Under the Austrian reading, neither on its own amounts to the visible disclosure that a qualifying creative requires.

The memo then turns to the voluntary Code. Providers and deployers of generative AI systems can sign the EU code of conduct on the transparency of AI-generated content, and signatories gain additional legal certainty, according to the guide: compliance with a code assessed as adequate can be treated as a mitigating factor when fines are calculated.

The guide is silent on the calendar. Google signed the Code on July 24, two days after July 22, the date by which organisations seeking a presumption of compliance were expected to sign. Meta confirmed its signature on July 28. Whether a signature added in September carries the same weight as one lodged before July 22 is a question the Austrian memo does not address.

Agencies as the default deployer

The fourth section is the core of the document. For labelling duties, the AI Act distinguishes two central roles, according to the guide: the provider of the AI tool, as a rule the software maker, and the deployer, meaning whoever actually uses the tool in production and decides whether and how it is used. Producing and serving an AI-assisted ad typically involves several actors - a client, an agency that makes the asset with AI, and a publisher that serves it or publishes it on its platform - so the division of roles has to be examined each time.

For the producing agency, the answer is direct. The agency is as a rule the responsible deployer, according to the guide. It must assess whether an advertising asset requires labelling and must implement the visible label technically. Bringing in third-party service providers to do the production work does not change that.

When an agency becomes a provider

A second layer applies to agencies that build tools. An agency can additionally count as a provider of an AI system if it develops its own AI solution, or modifies an existing one, and places it on the market or puts it into service under its own name or brand, according to the guide. White-label products offered to third parties under the agency's brand are the example given. In that case the agency takes on provider obligations beyond those of a deployer, in particular machine-readable marking of AI-generated content and technical documentation.

The boundary is drawn with care. Merely using a white-label or third-party AI solution internally as a production tool, without passing it on under the agency's own name or brand, does not create provider status, according to the guide.

Provider status brings the technical side of the Code into view. The finalised text obliges providers to apply at least two machine-readable marking layers, to watermark free-form text longer than 200 tokens and to offer a free detection solution. Generative systems already on the market before August 2 have until December 2, 2026 to bring machine-readable marking into conformity, with a watermark-detection interoperability requirement following on February 2, 2027. The Austrian memo cites neither date, although on its own definition the transition could cover an agency that put a branded generative tool into service before August.

Where the brand's exemption ends

For clients, the default runs the other way. A client that leaves the decision on AI use to the producing agency is regularly under no obligation of its own under the AI Act, according to the guide. The memo cites the Commission's Article 50 guidelines as stating expressly that a company which merely commissions an agency to create an ad, without deciding on or controlling whether and how the agency uses AI in production, does not count as a deployer of the AI system.

That exemption has conditions attached. The client's position must be examined as soon as it influences the AI use itself, according to the guide: by specifying which AI tool is to be used, by issuing its own prompting instructions, by setting parameters or by deploying its own AI tools. In those cases the client can become a deployer in its own right and take on obligations under the Act.

A further note concedes that the line is not sharp. The guide describes a fluid transition between simply accepting a finished advertising asset and actively directing the AI use. "The mere knowledge that an advertising asset is being created with AI does not, taken on its own, establish deployer status," the guide states. Yet the more a client intervenes in the specific AI use - through iterative correction rounds with content instructions for the generation, or by prescribing particular AI functions or parameters - the more likely it becomes that the client holds its own or a shared responsibility as deployer.

How many rounds of prompt-level feedback turn a reviewing client into a co-deployer? The guide sets no threshold. It recommends assessment in each individual case, legal advice where there is doubt and a clear contractual allocation of responsibilities.

Separately, and regardless of the AI Act role, the memo notes that under Austria's unfair competition law, the UWG, a client is regularly liable for misleading advertising distributed in its name, even when another company produced it.

Platforms allocate the duty differently

The Austrian reading sits beside two allocations already in circulation. Google's documentation of July 9 and July 13 placed responsibility for AI ad labelling on advertisers, confirmed that AdSense publishers have no equivalent setting, and stated that using the label setting does not guarantee compliance with any specific regulation. The IAB's AI Transparency and Disclosure Framework, in the second version released on August 18, places ultimate responsibility on the organisation that creates the advertising content, says that accountability cannot be delegated, and allows agency and client to share it where agencies create and control content.

The three answer different questions. Google's documentation governs who configures a setting inside an ad account; the IAB framework is a voluntary industry standard; the Austrian memo describes who holds the legal role of deployer under the AI Act and, separately, who answers under national competition law. Where an agency runs a brand's account and generates its creative, the agency could be the deployer under the Act while the brand remains the advertiser of record on the platform and the liable party under the UWG.

Publishers: conduit or deployer

Publishers receive the lightest default treatment. Where a finished advertising asset is merely distributed unchanged in a media-technical sense, publishers as a rule have no labelling duty of their own under the AI Act, according to the guide.

That changes once publishers alter an ad using AI, personalise it or build it into their own AI formats, with chatbots named as the example. Publishers then regularly become deployers of an AI system themselves, according to the guide, with their own obligations: assessing whether the modified or personalised content must be labelled and implementing the label technically.

On this reading, a publisher that runs an advertiser's creative through a generative model to adapt it to a page, a reader or a chat context is no longer a neutral carrier of someone else's asset.

Competition law reaches publishers too. Under the UWG, publishers can be pursued where misleading advertising is distributed by or through their platforms, according to the guide, which recommends that publishers leave existing labels in place and obtain contractual assurances that delivered ads are already correctly labelled. On Google's side the question of removal is partly settled by design: labels applied automatically by its AI tools cannot be removed.

Settling roles in contracts

Section five converts the role analysis into process. For the advertising ecosystem, what matters is where a company stands in the commissioning chain, according to the guide. All participants - agencies, clients, publishers and technology service providers - are expected to record responsibilities and obligations in bilateral or multilateral contracts and to set up reliable processes around three core questions. The first concerns role: provider or deployer in the AI distribution chain. The second concerns control, namely who decides whether content must be labelled, who applies the label technically and who checks it. The third concerns failure: who is liable, who corrects errors, and which contractual warranties, indemnities and recourse clauses protect the parties.

A closing note sets a limit on what a label achieves. Labelling alone does not replace the review of legal basics, according to the guide; copyright, personality rights, data protection and the prohibition on misleading practices must still be checked separately. Data protection here points first to the GDPR. Personality rights have already produced case law on synthetic media in the German-speaking market: a Berlin court ordered a YouTuber to pay 4,000 euros on August 20, 2025 for using an AI clone of a voice actor's voice in commercial videos without consent.

Two sanction routes, running in parallel

The final section is brief. Breaches of the labelling duties can become expensive, according to the guide: under the AI Act, fines reach up to 15 million euros or 3 percent of worldwide annual group turnover, whichever is higher. Where a missing label also qualifies as misleading advertising, all participants additionally face injunction claims from competitors or associations and, in some circumstances, damages claims under Austrian competition law. "Both consequences can occur side by side," the guide states.

The AI Act ceiling has a lower edge that the memo does not mention. For small and medium-sized enterprises and start-ups, each fine is capped at whichever of the two amounts is lower. The Article 50 duties themselves are not Austrian: they apply across the EU and the EEA, and reach organisations outside the bloc whose AI output is used inside it.

Public enforcement of the AI Act runs through national market surveillance authorities and the AI Office, which opened complaint routes in August, although complaints about most AI systems go to national competent authorities. That architecture borrows from data protection, where only 1.3 percent of GDPR cases resulted in fines between 2018 and 2023, a figure recalled on the eve of Article 50's applicability. The UWG route does not depend on a regulator's caseload. Competitors and associations have standing of their own, so in Austria a missing label can reach a courtroom without any authority opening a file.

Why the exemptions carry commercial weight

The reason marketers read the exemption list closely is measurable. An NYU Stern study cited in the IAB framework found that an AI disclosure cut an ad's click-through rate by 31.5 percent. Earlier IAB research put the share of advertising executives who believed Gen Z and Millennial consumers felt positively about AI-generated ads at 82 percent, against 45 percent of those consumers, a gap that widened from 32 points in 2024 to 37 points in 2026. Labelling too little invites fines and competitor claims; labelling too much has a documented cost in clicks.

The Austrian memo is the third piece of industry guidance on the question in a month. The IAB framework came on August 18, VIA Nederland on September 5 and IAB Austria on September 16. All three converge on a deception-based test for synthetic media and on a label that people can actually perceive. Where they differ is in how they distribute responsibility. The US framework treats creator accountability as non-delegable; the Dutch guidance organises the question around an agency's role and use case; the Austrian memo adds two tests the others do not spell out in the same detail - the degree of client control over AI production, and whether a publisher modifies the creative - and layers a national competition statute on top.

Two further omissions

Beyond the gaps already noted, two more stand out. The memo does not cover the separate Article 50 obligations on emotion recognition and biometric categorisation, and it does not name the authority that would enforce the AI Act's transparency duties in Austria. The next fixed points on the Article 50 timetable are the December 2, 2026 marking deadline and the February 2, 2027 interoperability requirement for watermark detection, neither of which appears in the text.

Timeline

Summary

Who: IAB Austria's working group on artificial intelligence, led by Iris Handlsberger of e-dialog, together with law firm act legal Austria and its lawyer Mag. Philipp E. Stephan. The guide addresses agencies, advertisers, publishers and technology service providers in the Austrian market.

What: A five-page German-language memo setting out when AI-generated advertising needs a visible label under Article 50 of the EU AI Act, what form that label must take, and how responsibility is divided. It finds the producing agency is normally the deployer, that clients become deployers only when they influence the AI use through tool choice, prompts, parameters or their own tools, and that publishers become deployers when they modify, personalise or embed ads in their own AI formats. Hidden metadata and invisible watermarks do not satisfy the visible requirement, and content created before August 2, 2026 falls under the duty once it is republished or served again.

When: IAB Austria published the guide with a news item dated September 16, 2026; the memo itself is dated September 2026. The Article 50 obligations it interprets have applied since August 2, 2026.

Where: Austria, as part of the EU-wide Article 50 regime, with an additional layer of liability under the Austrian unfair competition act, the UWG.

Why: Breaches can bring AI Act fines of up to 15 million euros or 3 percent of worldwide annual group turnover, and in parallel injunction and damages claims from competitors or associations under the UWG. Because disclosure labels carry a measured cost in click-through, the exemptions and the question of who decides on a label have direct commercial consequences for everyone in the commissioning chain.