Explore our AI courses, practical training for non-technical teamsExplore courses Explore AI courses
AI for MarketingComplianceContent Workflow

The AI Marketing Compliance Checklist: Catching Disclosure Risk Before You Hit Publish

Two days before this rule became enforceable, one team almost shipped an AI-generated 'customer' testimonial with zero disclosure. Here's the checklist that would have caught it.

TLDR: This one is the workflow piece, the legal explainer already exists elsewhere on the site. You get four risk categories to run every AI-assisted asset against: disclosure gaps, unverified claims, fake testimonial risk, and deepfake or likeness risk. You also get the actual pre-publish checklist I use before anything ships, plus a straight answer on when a marketing call needs to become a legal one. Two days from now, the EU AI Act’s Article 50 disclosure rules become enforceable. The FTC’s ban on fake AI-generated reviews has already been law for almost two years. I didn’t pick this week by accident.
91%of consumers say they expect brands to disclose when they use AI in marketing, per Emplifi survey data reported by eMarketer
31% vs 7%share of consumers who say visible AI-generated marketing content makes them trust a brand less, versus the share who say it builds more trust, per Klaviyo and Datalily's 2026 AI Consumer Trends survey of 8,000 consumers
Aug 2, 2026the date the EU AI Act's Article 50 transparency obligations for AI-generated content and deepfakes become enforceable

Share this article

The Short Version

Most marketing teams don’t have a repeatable process for checking AI-generated content against disclosure rules before it goes out. It gets caught, or it doesn’t, in an ad hoc Slack thread the day of launch. This piece gives you four risk categories to screen every asset against: disclosure gaps, misleading AI claims, fake reviews and testimonials, and deepfake or likeness risk in AI video and images. It summarizes what the FTC already requires around endorsements and reviews, walks through what changes under the EU AI Act’s Article 50 starting August 2, 2026, and hands you a full pre-publish checklist with the actual prompts I use to get AI to review its own output first. One honest caveat up front: I’m a working marketer, and what follows is operational guidance. It is not legal advice. A handful of the calls in here genuinely need a real lawyer.

The near miss that should worry every marketing team

I’ll start with the one that still makes me wince a little. Last year, during a launch push, someone on my own team built a UGC-style ad using an AI avatar reading a testimonial script we’d written to sound like a real customer. It looked good. It sounded like real feedback. Nobody had put a disclosure anywhere in it, not in the caption, not in the video, not in the ad account settings, and it made it all the way to scheduled before I caught it, scrolling through the next day’s queue later than I’d like to admit. My question wasn’t “is this compliant.” It was “wait, who is this supposed to be?” Nobody on the thread could answer that cleanly, which told me everything I needed to know.

I’m telling you that story because it happens more than people think, and not just to sloppy teams. It happens whenever content production outruns content review, full stop, and it’s happening now at a rough moment for it to happen at all. Two days after this article publishes, the EU AI Act’s Article 50 transparency rules become enforceable, requiring disclosure of AI-generated deepfakes and synthetic content [4]. The FTC’s ban on fake and AI-generated consumer reviews and testimonials has already been active for close to two years [1][2]. We’ve covered why this matters at scale already, in our piece on why 78% of brands are publishing AI content without disclosing it, and the regulatory detail gets its own full treatment in our plain-English EU AI Act compliance guide. This piece does something narrower: the actual workflow, what to check and in what order, before anything with AI fingerprints on it goes near publish.

Quick honest note before we get into it. I’ve spent more than ten years doing hands-on marketing execution, the last several running Future Factors AI with my twin sister Sana, and I am not a lawyer. I won’t pretend otherwise anywhere in this piece. What follows is a practical review process built from watching how compliance-minded marketing teams actually operate day to day, including my own. For the genuinely complicated calls, and there will be some, you need a real lawyer looking at your specific content, your specific audience, and your specific jurisdiction. More on exactly where that line sits toward the end.

The four places AI marketing content actually gets you in trouble

Almost every AI marketing compliance problem I’ve seen or heard about from other marketers, including a couple of close calls of my own, falls into one of four buckets. Knowing the buckets matters because each one needs a different kind of check; lump them together and things slip through the cracks.

1. Disclosure gaps

This is the simplest one to describe and, in my experience, the easiest one to skip: content that’s wholly or substantially AI-generated (an image, a video, a voice, a block of written copy) with no indication anywhere that it is. Not every AI-assisted asset needs a disclosure. A blog post you drafted with AI help and then rewrote in your own voice is a different animal than a photorealistic AI-generated “customer” holding your product with nothing said about it anywhere.

2. Misleading AI-generated claims

Generative tools are confident by design, and that confidence doesn’t care whether the number it just wrote is real. Ask an AI tool to write ad copy and it will happily invent a statistic (“clinically proven,” “9 out of 10 users”), a comparison claim, or a feature your product doesn’t actually have, phrased with total certainty. Truthfulness problems like this existed long before generative AI ever showed up. What’s changed is how fast you can produce them at volume now, often without anyone meaning to.

3. Fake reviews and testimonials risk

This is the one with the newest and sharpest regulatory teeth behind it. Using AI to generate a “customer” persona, a fabricated review, or a testimonial that implies a real experience nobody actually had sits squarely inside what the FTC’s current rules are built to stop [1][2]. It doesn’t matter whether a human typed the fake review by hand or an AI tool spit it out in two seconds. The FTC’s rule cares about the misrepresentation. The tool that produced it is beside the point.

4. Deepfake and likeness risk in AI video or images

The riskiest, least forgiving category. Using AI to generate or manipulate a face, voice, or persona that resembles a real, identifiable person (a customer, an employee, a public figure, even a stock talent fed into a generation tool) without consent, or without the disclosure specific regulations now require, is where compliance risk overlaps hardest with reputational and legal risk. A small disclaimer tacked on after the fact will not save you here, and getting legal input early pays off more in this category than almost anywhere else in this checklist.

My honest read after going through a fair number of content pipelines, including my own: disclosure gaps and misleading claims get caught reasonably often, because someone eventually reads the copy closely enough. Fake testimonial risk and deepfake risk slip through far more, and it’s not because reviewers are careless. A compelling AI-generated “customer” moment just doesn’t look suspicious. It looks like good creative, and good creative is exactly what nobody wants to slow down to interrogate. Which is the whole argument for a checklist over a gut check.

The FTC rules that already apply to your AI content

None of this required a brand-new AI-specific law in the US to already apply to you, which surprises people every time I explain it. The FTC has spent the last few years tightening existing consumer protection rules, mostly because deceptive endorsements, fake reviews, and now AI-generated versions of both kept showing up in its enforcement work.

The FTC finalized a rule addressing fake and AI-generated consumer reviews, testimonials, and celebrity endorsements, and it took effect back in October 2024 [1][2]. Put plainly, manufacturing a review or testimonial that misrepresents who the reviewer is, whether they actually exist, or what they actually experienced is prohibited, and that prohibition explicitly covers AI-generated reviews and testimonials, not just the human-written fake ones [1]. Buying, spreading, or knowingly using that kind of content in your marketing carries the same exposure as creating it yourself.

Sitting alongside that rule are the FTC’s Endorsement Guides (revised in 2023), which require that any material connection between an endorser and your brand, meaning payment, free product, a discount, an affiliate commission, or any other compensation, gets disclosed clearly [1]. And underneath both of those sits the FTC’s long-standing “clear and conspicuous” disclosure standard, which the agency has described as requiring disclosures to be difficult to miss and, for digital and social content specifically, effectively unavoidable rather than technically present somewhere on the page [3].

  • A disclosure buried in a bio link or an “ad” tag three hashtags deep in a caption almost certainly does not meet the “unavoidable” bar the FTC has articulated for digital and social disclosures [3].
  • An employee, officer, or their immediate family member posting a review or testimonial without disclosing that relationship is a direct violation, regardless of whether AI helped write it [1].
  • A fabricated “verified buyer” persona, AI-generated or otherwise, gets treated as a fake review under this rule if it misrepresents a real identity or experience, regardless of how deliberate or stylistic it seemed at the time [1][2].

None of this is exotic, honestly. It’s the same honesty standard advertising has run on for decades, and the FTC has been consistent that AI-generated content doesn’t get a pass just because a model produced it instead of a person.

What changes on August 2: the EU AI Act's Article 50

If your marketing reaches audiences in the EU, the timing on this one is not abstract. Article 50 of the EU AI Act becomes enforceable on August 2, 2026 [4], either two days from now or already in effect depending on when you’re reading this. It introduces transparency obligations more specific than anything in US federal law right now, and they land directly on marketing content.

The core obligations, straight from the article text, break into four parts [4]:

  • AI interaction disclosure. If a person is interacting directly with an AI system (a chatbot, a virtual assistant embedded on your site), they need to be told they’re talking to an AI, unless that’s already obvious from context.
  • Synthetic content marking. Providers of AI systems generating synthetic audio, image, video, or text need to make the output detectable as AI-generated or manipulated in a machine-readable format, where technically feasible.
  • Deepfake disclosure. If you use AI to generate or manipulate image, audio, or video content that constitutes a deepfake (content resembling a real, identifiable person, object, place, or event that would appear authentic), you need to disclose that it was artificially generated or manipulated.
  • AI-generated text disclosure for public-interest content. Text generated or manipulated by AI and published to inform the public on matters of public interest needs to disclose its artificial origin, unless it went through genuine human review with a real person or organization holding editorial responsibility for it.

Timing matters here too: the disclosure has to happen “at the latest at the time of the first interaction or exposure” [4], meaning after-the-fact disclosures added once someone complains don’t satisfy the obligation. There are carve-outs for law enforcement use and for content that’s evidently artistic, satirical, or fictional, though even those still require some disclosure that generated content exists [4].

I’m going to resist the urge to turn this into a full legal breakdown of who exactly is covered, how the “deployer” versus “provider” distinction plays out for a marketing team using a third-party AI video tool, or what penalties look like, because we’ve already written that piece and it deserves the space a full article gives it. If you need the fuller regulatory picture, our EU AI Act compliance guide covers scope, penalties, and who counts as a deployer in more depth than fits here. What matters for this piece is simpler. If there’s any real chance your content reaches an EU audience, AI-generated video, images, and synthetic voice in your marketing need a documented disclosure plan now. Waiting until someone asks is how a five-minute fix turns into a scramble.

The pre-publish compliance checklist (steal this one)

This is the part you can actually put to use this week, the same five passes I run on my own team’s output. Run every AI-touched marketing asset through them before it goes live. It won’t take as long as it looks like it will once it’s a habit instead of a special occasion.

Pass 1: Claims and copy

  • Every specific number, statistic, or comparison claim traces back to a real, checkable source, not something the AI tool generated on its own.
  • No unverified superlatives (“clinically proven,” “guaranteed results”) that a claims-substantiation reviewer hasn’t signed off on.
  • Any competitor comparison is factually accurate as of today, not from the AI’s training data or a hallucinated guess.
  • If AI drafted a meaningful share of the copy, someone confirms whether a disclosure is warranted given how the content will be used.

Pass 2: Testimonials and reviews

  • Every person shown or quoted as a customer is a real person who actually said or experienced what’s depicted, or the content is clearly labeled as illustrative or AI-generated.
  • No AI-generated “verified buyer” personas, avatars standing in for real customers, or composite reviews presented as one real reviewer’s words.
  • Any employee, officer, or immediate family member appearing in a review or testimonial discloses that relationship [1].
  • Any paid, gifted, or compensated endorsement discloses the material connection clearly, not just in a linked terms page [1].

Pass 3: AI images and video

  • Any AI-generated face, voice, or persona resembling a real, identifiable person has documented consent, or doesn’t resemble anyone identifiable closely enough to raise the question.
  • Anything that could plausibly be mistaken for real footage carries a deepfake disclosure, placed where a viewer will actually see it [4].
  • Product visuals generated or heavily altered by AI don’t misrepresent the product’s actual appearance, size, or function.
  • Someone who didn’t work on the asset does a fresh-eyes pass and answers honestly: “if I saw this cold, would I assume it was real?”

Pass 4: Disclosure wording and placement

  • The disclosure is legible, in a contrasting color or font weight, sized to actually be read, not compliance-shaped tiny text.
  • For video, the disclosure appears at or near the very start, not only in a description field most viewers never open.
  • For chatbots or AI assistants embedded on-site, the AI nature of the interaction is disclosed before or at the first exchange, not buried in a settings menu [4].
  • The disclosure language is plain and specific (“this video uses an AI-generated voice,” not a vague “content may include AI”) wherever precision is realistic.

Pass 5: Paid and social-specific checks

  • Ad account and platform-specific AI-content or synthetic-media disclosure settings (where platforms offer them) are turned on, not left at default.
  • Influencer or creator partners using AI-generated content in a sponsored post know what disclosure is required of them, not left to guess.
  • Geo-targeting is checked: if any portion of the audience is in the EU, the Article 50 obligations apply regardless of where your company is headquartered [4].

Prompt for a first pass on written copy: “Read this ad copy as a skeptical regulator would. Flag every specific claim, statistic, or comparison, and tell me which ones are backed by something in the text versus which ones sound generated or unverifiable.” Run it before a human does the deeper read, not instead of one.

Prompt for a testimonial or UGC script: “List every implied fact about the person speaking in this script: their identity, whether they are a real customer, and what result they claim. Flag anything that isn’t explicitly confirmed as real.” AI is decent at spotting its own patterns once you ask it directly.

How to actually use AI to catch these risks first

There’s something almost circular about this next part: AI is genuinely useful for catching the exact problems AI creates, provided you’re honest about what it can and cannot do reliably.

What it’s actually good at is pattern matching against a checklist you hand it. Feed a draft into an AI tool with an explicit prompt, like the two examples above, and it does a genuinely fast, useful first pass. It catches the boring, high-volume stuff, a vague superlative, a claim with no source, a testimonial that never says “verified customer”, faster than a human skimming the same draft for the fifth time that week.

Where it falls apart is judgment. An AI tool cannot tell you whether a generated face is “close enough” to a real, identifiable person to trigger a deepfake disclosure obligation, and it cannot tell you whether a claim crosses from aggressive marketing into deceptive under your specific jurisdiction’s standard. Those calls need a human who actually understands the regulatory bar. Sometimes that human needs to be a lawyer, and no amount of clever prompting changes that.

Here’s what actually works. AI takes the first, fast pass across every asset, since no team has time to manually re-read every ad line by line, and it catches the obvious stuff at scale. Then a trained human does a second pass, focused specifically on the judgment calls AI can’t make: consent, likeness, anything borderline. Last, a designated compliance owner checks anything flagged, and that person needs the actual authority to hold the asset, not just an opinion about it. Skip any one of those three steps and you’re back to hoping someone asks the right question in a Slack thread.

Honestly, the tool matters less here than the discipline of running the check at all. I’ve seen teams with genuinely good AI review prompts still ship risky content because nobody owned the “does this actually get flagged and stopped” part of the process. A checklist without an enforcement point is just a document nobody reads twice.

Build the sign-off step, or the checklist is just a suggestion

Every team I’ve seen succeed at this has one thing in common: a named person or small group who owns the final call, with real authority to say “this doesn’t go live yet.” Without that, a checklist gets skipped the first time a launch date is tight, exactly when the risk is highest.

  • Assign an owner, not a committee. At Future Factors, this one’s easy since there are literally two of us, so the question of who has final say barely comes up. On a bigger team it takes more discipline: pick one person, often marketing ops, sometimes legal or a compliance lead if you have one, who has final say on flagged content, and make sure everyone else knows it’s not their call to make.
  • Set a clear escalation trigger. Anything touching deepfake or likeness risk, any claim a reviewer can’t verify in five minutes, and anything targeting a regulated industry (health, finance, alcohol) escalates automatically, no exceptions for tight deadlines.
  • Log the decision, even the boring ones. A quick record of what was checked and who approved it is worth far more than memory once something gets questioned months later.
  • Build the checklist into the tool you already use, whether that’s a project management board, an approval workflow, or a shared doc. A checklist that lives somewhere separate from where work actually happens gets ignored within a month.

None of this needs to be heavy. A five-minute checklist pass with a named owner beats an elaborate compliance framework that nobody actually follows once a deadline gets tight. What you’re building is a process that survives a busy Tuesday. Most compliance frameworks only ever get tested in the calm week when someone designed them, which is exactly when you don’t need them.

I want to be straightforward about the limits of everything above, because pretending a marketing checklist solves a legal problem is exactly the kind of overpromise Future Factors tries not to make. This article is operational guidance, built from how compliance-conscious marketing teams actually run their review process. It is not legal advice, and it should not be treated as a substitute for it.

The FTC rules, the Article 50 provisions, and the standards referenced throughout this piece are real and current as of this writing, and every specific claim is sourced directly to the FTC or the official EU AI Act text below. But regulations get interpreted, enforced, and amended, jurisdictions differ, and your specific situation (industry, audience location, vendor contracts, risk tolerance) changes what “compliant” actually requires. A checklist built for a general audience can’t account for all of that.

  • Get a lawyer involved before you rely on your own read of the rules if: your content touches a regulated industry (health claims, financial products, alcohol, anything requiring specific substantiation standards).
  • Get a lawyer involved if: you’re using AI-generated likeness of any real, identifiable person, even with what you believe is adequate consent, especially across multiple jurisdictions.
  • Get a lawyer involved if: you’re building influencer or creator contracts that need to specify AI-disclosure obligations, since getting that wording wrong shifts liability in ways a marketing team shouldn’t be deciding alone.
  • Get a lawyer involved if: you’ve already received a complaint, inquiry, or takedown request related to AI-generated content. That’s no longer a pre-publish problem, and this checklist wasn’t built for it.

Here’s my honest bottom line. This checklist will catch a large share of the risk that actually shows up in day-to-day content production, and it would have caught the near miss I opened this piece with. It won’t replace legal counsel for the genuinely complicated calls. No article, prompt, or checklist honestly can, and I’d be lying if I told you otherwise.

Frequently Asked Questions

Do I need to disclose AI use if a human edited the content afterward?

Honestly, it depends on how substantial the human edit was, and this is exactly the line the EU AI Act draws. Article 50’s text-disclosure obligation for public-interest content includes an exception where the AI-generated text underwent genuine human review, with a real person or organization holding editorial responsibility for the final version. A quick grammar pass is not the same thing as a substantive rewrite. If you’re leaning on this exception for anything high-stakes, get that judgment call reviewed by counsel instead of assuming a light edit clears the bar.

What actually counts as a 'clear and conspicuous' AI disclosure under FTC rules?

The FTC has described the standard as difficult to miss and easily understandable by an ordinary consumer. For digital and social content specifically, the agency has pushed toward disclosures being effectively unavoidable, not just technically present somewhere on the page. A disclosure buried in a bio link, a fourth hashtag, or a video description almost certainly falls short. Placement matters as much as wording, arguably more. Put the disclosure where the audience is already looking, even if that spot is less convenient for you to edit than the one you’d default to.

Does the EU AI Act's Article 50 apply to my company if we're not based in the EU?

The obligations attach to whether your AI system’s outputs reach people in the EU. Where your company is headquartered doesn’t matter nearly as much, which is why geo-targeting deserves more attention than your mailing address for this specific question. That said, exactly how ‘deployer’ and ‘provider’ roles apply to a marketing team using a third-party AI content tool is a real nuance worth getting confirmed for your specific setup rather than assumed. Our EU AI Act compliance guide goes deeper on scope; for anything with meaningful EU exposure, verify your specific situation with counsel.

Can I use an AI-generated 'customer' testimonial if I clearly label it as fictional or illustrative?

A clear, prominent label that the testimonial is illustrative or AI-generated, and not a real customer’s actual experience, moves you away from the FTC’s core concern, which is a testimonial that misrepresents a real identity or experience. But ‘clearly labeled’ has to meet the same clear-and-conspicuous bar as any other disclosure. A tiny asterisk or a caption note buried below the fold is unlikely to satisfy that standard, and honestly, the safer move for anything resembling a real customer review is usually to just use real customers.

What's the fastest way to add a compliance check without slowing down content production?

Run the AI-assisted first pass described in this piece, a structured prompt flagging unverified claims, missing disclosures, or ambiguous testimonial language, at the draft stage instead of saving it as a final gate right before launch. An issue caught early costs you a few minutes. The same issue caught the day before a campaign launches can cost you the launch date entirely. Pair that fast AI pass with one named human owner who actually has the authority to hold an asset, and most teams find the whole process adds far less time than the rework it prevents.

About This Article

This piece draws on the FTC’s official business guidance on endorsements, influencers, and reviews, the FTC’s Consumer Reviews and Testimonials Rule Q&A, the FTC’s Disclosures 101 resource, the official text and summary of Article 50 of the EU AI Act, and eMarketer’s May 2026 coverage of Klaviyo/Datalily and Emplifi consumer trust survey data. All sources were fetched and read directly this session; links are below. I run Future Factors AI with my twin sister Sana, and my background is over a decade of hands-on marketing execution, not law. This article is operational guidance built from that experience. It is not legal advice, full stop. For anything touching regulated industries, real people’s likeness, or an actual complaint or inquiry, talk to a lawyer who can review your specific situation.

Sources

  1. FTC, Endorsements, Influencers, and Reviews (business guidance hub) https://www.ftc.gov/business-guidance/advertising-marketing/endorsements-influencers-reviews
  2. FTC, The Consumer Reviews and Testimonials Rule: Questions and Answers https://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers
  3. FTC, Disclosures 101 for Social Media Influencers https://www.ftc.gov/business-guidance/resources/disclosures-101-social-media-influencers
  4. EU Artificial Intelligence Act, Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems https://artificialintelligenceact.eu/article/50/
  5. eMarketer, Shoppers aren’t impressed by AI-generated marketing (citing Klaviyo/Datalily and Emplifi survey data) https://www.emarketer.com/content/shoppers-aren-t-impressed-by-ai-generated-marketing
Hina Mian
Hina Mian, Co-Founder of Future Factors AI

Hina is a marketing strategist with over a decade of hands-on campaign experience across B2B and consumer brands. She writes about using AI to run leaner, sharper marketing without losing the human touch. Future Factors offers AI Bootcamps, Corporate Workshops, and Speaking & Consulting for teams that want to put AI to work properly.

More about Hina →

Psst, Hey You!

(Yeah, You!)

Want helpful AI tips flying Into your inbox?

Weekly tips. Real examples. Practical help for busy professionals.

We care about your data, check out our privacy policy.