Two days before this rule became enforceable, one team almost shipped an AI-generated 'customer' testimonial with zero disclosure. Here's the checklist that would have caught it.
Most marketing teams don’t have a repeatable process for checking AI-generated content against disclosure rules before it goes out. It gets caught, or it doesn’t, in an ad hoc Slack thread the day of launch. This piece gives you four risk categories to screen every asset against: disclosure gaps, misleading AI claims, fake reviews and testimonials, and deepfake or likeness risk in AI video and images. It summarizes what the FTC already requires around endorsements and reviews, walks through what changes under the EU AI Act’s Article 50 starting August 2, 2026, and hands you a full pre-publish checklist with the actual prompts I use to get AI to review its own output first. One honest caveat up front: I’m a working marketer, and what follows is operational guidance. It is not legal advice. A handful of the calls in here genuinely need a real lawyer.
I’ll start with the one that still makes me wince a little. Last year, during a launch push, someone on my own team built a UGC-style ad using an AI avatar reading a testimonial script we’d written to sound like a real customer. It looked good. It sounded like real feedback. Nobody had put a disclosure anywhere in it, not in the caption, not in the video, not in the ad account settings, and it made it all the way to scheduled before I caught it, scrolling through the next day’s queue later than I’d like to admit. My question wasn’t “is this compliant.” It was “wait, who is this supposed to be?” Nobody on the thread could answer that cleanly, which told me everything I needed to know.
I’m telling you that story because it happens more than people think, and not just to sloppy teams. It happens whenever content production outruns content review, full stop, and it’s happening now at a rough moment for it to happen at all. Two days after this article publishes, the EU AI Act’s Article 50 transparency rules become enforceable, requiring disclosure of AI-generated deepfakes and synthetic content [4]. The FTC’s ban on fake and AI-generated consumer reviews and testimonials has already been active for close to two years [1][2]. We’ve covered why this matters at scale already, in our piece on why 78% of brands are publishing AI content without disclosing it, and the regulatory detail gets its own full treatment in our plain-English EU AI Act compliance guide. This piece does something narrower: the actual workflow, what to check and in what order, before anything with AI fingerprints on it goes near publish.
Quick honest note before we get into it. I’ve spent more than ten years doing hands-on marketing execution, the last several running Future Factors AI with my twin sister Sana, and I am not a lawyer. I won’t pretend otherwise anywhere in this piece. What follows is a practical review process built from watching how compliance-minded marketing teams actually operate day to day, including my own. For the genuinely complicated calls, and there will be some, you need a real lawyer looking at your specific content, your specific audience, and your specific jurisdiction. More on exactly where that line sits toward the end.
Almost every AI marketing compliance problem I’ve seen or heard about from other marketers, including a couple of close calls of my own, falls into one of four buckets. Knowing the buckets matters because each one needs a different kind of check; lump them together and things slip through the cracks.
This is the simplest one to describe and, in my experience, the easiest one to skip: content that’s wholly or substantially AI-generated (an image, a video, a voice, a block of written copy) with no indication anywhere that it is. Not every AI-assisted asset needs a disclosure. A blog post you drafted with AI help and then rewrote in your own voice is a different animal than a photorealistic AI-generated “customer” holding your product with nothing said about it anywhere.
Generative tools are confident by design, and that confidence doesn’t care whether the number it just wrote is real. Ask an AI tool to write ad copy and it will happily invent a statistic (“clinically proven,” “9 out of 10 users”), a comparison claim, or a feature your product doesn’t actually have, phrased with total certainty. Truthfulness problems like this existed long before generative AI ever showed up. What’s changed is how fast you can produce them at volume now, often without anyone meaning to.
This is the one with the newest and sharpest regulatory teeth behind it. Using AI to generate a “customer” persona, a fabricated review, or a testimonial that implies a real experience nobody actually had sits squarely inside what the FTC’s current rules are built to stop [1][2]. It doesn’t matter whether a human typed the fake review by hand or an AI tool spit it out in two seconds. The FTC’s rule cares about the misrepresentation. The tool that produced it is beside the point.
The riskiest, least forgiving category. Using AI to generate or manipulate a face, voice, or persona that resembles a real, identifiable person (a customer, an employee, a public figure, even a stock talent fed into a generation tool) without consent, or without the disclosure specific regulations now require, is where compliance risk overlaps hardest with reputational and legal risk. A small disclaimer tacked on after the fact will not save you here, and getting legal input early pays off more in this category than almost anywhere else in this checklist.
My honest read after going through a fair number of content pipelines, including my own: disclosure gaps and misleading claims get caught reasonably often, because someone eventually reads the copy closely enough. Fake testimonial risk and deepfake risk slip through far more, and it’s not because reviewers are careless. A compelling AI-generated “customer” moment just doesn’t look suspicious. It looks like good creative, and good creative is exactly what nobody wants to slow down to interrogate. Which is the whole argument for a checklist over a gut check.
None of this required a brand-new AI-specific law in the US to already apply to you, which surprises people every time I explain it. The FTC has spent the last few years tightening existing consumer protection rules, mostly because deceptive endorsements, fake reviews, and now AI-generated versions of both kept showing up in its enforcement work.
The FTC finalized a rule addressing fake and AI-generated consumer reviews, testimonials, and celebrity endorsements, and it took effect back in October 2024 [1][2]. Put plainly, manufacturing a review or testimonial that misrepresents who the reviewer is, whether they actually exist, or what they actually experienced is prohibited, and that prohibition explicitly covers AI-generated reviews and testimonials, not just the human-written fake ones [1]. Buying, spreading, or knowingly using that kind of content in your marketing carries the same exposure as creating it yourself.
Sitting alongside that rule are the FTC’s Endorsement Guides (revised in 2023), which require that any material connection between an endorser and your brand, meaning payment, free product, a discount, an affiliate commission, or any other compensation, gets disclosed clearly [1]. And underneath both of those sits the FTC’s long-standing “clear and conspicuous” disclosure standard, which the agency has described as requiring disclosures to be difficult to miss and, for digital and social content specifically, effectively unavoidable rather than technically present somewhere on the page [3].
None of this is exotic, honestly. It’s the same honesty standard advertising has run on for decades, and the FTC has been consistent that AI-generated content doesn’t get a pass just because a model produced it instead of a person.
If your marketing reaches audiences in the EU, the timing on this one is not abstract. Article 50 of the EU AI Act becomes enforceable on August 2, 2026 [4], either two days from now or already in effect depending on when you’re reading this. It introduces transparency obligations more specific than anything in US federal law right now, and they land directly on marketing content.
The core obligations, straight from the article text, break into four parts [4]:
Timing matters here too: the disclosure has to happen “at the latest at the time of the first interaction or exposure” [4], meaning after-the-fact disclosures added once someone complains don’t satisfy the obligation. There are carve-outs for law enforcement use and for content that’s evidently artistic, satirical, or fictional, though even those still require some disclosure that generated content exists [4].
I’m going to resist the urge to turn this into a full legal breakdown of who exactly is covered, how the “deployer” versus “provider” distinction plays out for a marketing team using a third-party AI video tool, or what penalties look like, because we’ve already written that piece and it deserves the space a full article gives it. If you need the fuller regulatory picture, our EU AI Act compliance guide covers scope, penalties, and who counts as a deployer in more depth than fits here. What matters for this piece is simpler. If there’s any real chance your content reaches an EU audience, AI-generated video, images, and synthetic voice in your marketing need a documented disclosure plan now. Waiting until someone asks is how a five-minute fix turns into a scramble.
This is the part you can actually put to use this week, the same five passes I run on my own team’s output. Run every AI-touched marketing asset through them before it goes live. It won’t take as long as it looks like it will once it’s a habit instead of a special occasion.
Prompt for a first pass on written copy: “Read this ad copy as a skeptical regulator would. Flag every specific claim, statistic, or comparison, and tell me which ones are backed by something in the text versus which ones sound generated or unverifiable.” Run it before a human does the deeper read, not instead of one.
Prompt for a testimonial or UGC script: “List every implied fact about the person speaking in this script: their identity, whether they are a real customer, and what result they claim. Flag anything that isn’t explicitly confirmed as real.” AI is decent at spotting its own patterns once you ask it directly.
There’s something almost circular about this next part: AI is genuinely useful for catching the exact problems AI creates, provided you’re honest about what it can and cannot do reliably.
What it’s actually good at is pattern matching against a checklist you hand it. Feed a draft into an AI tool with an explicit prompt, like the two examples above, and it does a genuinely fast, useful first pass. It catches the boring, high-volume stuff, a vague superlative, a claim with no source, a testimonial that never says “verified customer”, faster than a human skimming the same draft for the fifth time that week.
Where it falls apart is judgment. An AI tool cannot tell you whether a generated face is “close enough” to a real, identifiable person to trigger a deepfake disclosure obligation, and it cannot tell you whether a claim crosses from aggressive marketing into deceptive under your specific jurisdiction’s standard. Those calls need a human who actually understands the regulatory bar. Sometimes that human needs to be a lawyer, and no amount of clever prompting changes that.
Here’s what actually works. AI takes the first, fast pass across every asset, since no team has time to manually re-read every ad line by line, and it catches the obvious stuff at scale. Then a trained human does a second pass, focused specifically on the judgment calls AI can’t make: consent, likeness, anything borderline. Last, a designated compliance owner checks anything flagged, and that person needs the actual authority to hold the asset, not just an opinion about it. Skip any one of those three steps and you’re back to hoping someone asks the right question in a Slack thread.
Honestly, the tool matters less here than the discipline of running the check at all. I’ve seen teams with genuinely good AI review prompts still ship risky content because nobody owned the “does this actually get flagged and stopped” part of the process. A checklist without an enforcement point is just a document nobody reads twice.
Every team I’ve seen succeed at this has one thing in common: a named person or small group who owns the final call, with real authority to say “this doesn’t go live yet.” Without that, a checklist gets skipped the first time a launch date is tight, exactly when the risk is highest.
None of this needs to be heavy. A five-minute checklist pass with a named owner beats an elaborate compliance framework that nobody actually follows once a deadline gets tight. What you’re building is a process that survives a busy Tuesday. Most compliance frameworks only ever get tested in the calm week when someone designed them, which is exactly when you don’t need them.
I want to be straightforward about the limits of everything above, because pretending a marketing checklist solves a legal problem is exactly the kind of overpromise Future Factors tries not to make. This article is operational guidance, built from how compliance-conscious marketing teams actually run their review process. It is not legal advice, and it should not be treated as a substitute for it.
The FTC rules, the Article 50 provisions, and the standards referenced throughout this piece are real and current as of this writing, and every specific claim is sourced directly to the FTC or the official EU AI Act text below. But regulations get interpreted, enforced, and amended, jurisdictions differ, and your specific situation (industry, audience location, vendor contracts, risk tolerance) changes what “compliant” actually requires. A checklist built for a general audience can’t account for all of that.
Here’s my honest bottom line. This checklist will catch a large share of the risk that actually shows up in day-to-day content production, and it would have caught the near miss I opened this piece with. It won’t replace legal counsel for the genuinely complicated calls. No article, prompt, or checklist honestly can, and I’d be lying if I told you otherwise.
Honestly, it depends on how substantial the human edit was, and this is exactly the line the EU AI Act draws. Article 50’s text-disclosure obligation for public-interest content includes an exception where the AI-generated text underwent genuine human review, with a real person or organization holding editorial responsibility for the final version. A quick grammar pass is not the same thing as a substantive rewrite. If you’re leaning on this exception for anything high-stakes, get that judgment call reviewed by counsel instead of assuming a light edit clears the bar.
The FTC has described the standard as difficult to miss and easily understandable by an ordinary consumer. For digital and social content specifically, the agency has pushed toward disclosures being effectively unavoidable, not just technically present somewhere on the page. A disclosure buried in a bio link, a fourth hashtag, or a video description almost certainly falls short. Placement matters as much as wording, arguably more. Put the disclosure where the audience is already looking, even if that spot is less convenient for you to edit than the one you’d default to.
The obligations attach to whether your AI system’s outputs reach people in the EU. Where your company is headquartered doesn’t matter nearly as much, which is why geo-targeting deserves more attention than your mailing address for this specific question. That said, exactly how ‘deployer’ and ‘provider’ roles apply to a marketing team using a third-party AI content tool is a real nuance worth getting confirmed for your specific setup rather than assumed. Our EU AI Act compliance guide goes deeper on scope; for anything with meaningful EU exposure, verify your specific situation with counsel.
A clear, prominent label that the testimonial is illustrative or AI-generated, and not a real customer’s actual experience, moves you away from the FTC’s core concern, which is a testimonial that misrepresents a real identity or experience. But ‘clearly labeled’ has to meet the same clear-and-conspicuous bar as any other disclosure. A tiny asterisk or a caption note buried below the fold is unlikely to satisfy that standard, and honestly, the safer move for anything resembling a real customer review is usually to just use real customers.
Run the AI-assisted first pass described in this piece, a structured prompt flagging unverified claims, missing disclosures, or ambiguous testimonial language, at the draft stage instead of saving it as a final gate right before launch. An issue caught early costs you a few minutes. The same issue caught the day before a campaign launches can cost you the launch date entirely. Pair that fast AI pass with one named human owner who actually has the authority to hold an asset, and most teams find the whole process adds far less time than the rework it prevents.
This piece draws on the FTC’s official business guidance on endorsements, influencers, and reviews, the FTC’s Consumer Reviews and Testimonials Rule Q&A, the FTC’s Disclosures 101 resource, the official text and summary of Article 50 of the EU AI Act, and eMarketer’s May 2026 coverage of Klaviyo/Datalily and Emplifi consumer trust survey data. All sources were fetched and read directly this session; links are below. I run Future Factors AI with my twin sister Sana, and my background is over a decade of hands-on marketing execution, not law. This article is operational guidance built from that experience. It is not legal advice, full stop. For anything touching regulated industries, real people’s likeness, or an actual complaint or inquiry, talk to a lawyer who can review your specific situation.