Every conversation about AI watermarking for marketers starts in the wrong place: with the marking obligation, which is the one thing here almost certainly not your responsibility.
The rules that do land on you are different in kind, already in force, and one is satisfied by something most marketing teams already do but cannot prove.
This reports published regulatory guidance and is not legal advice. Take specifics to a lawyer.
AI watermarking for marketers: three duties, only some yours
Article 50 of the EU AI Act splits by role, and the split is the whole game.
The European Commission’s own guidance defines a provider as those who "develop AI systems, or have them developed, and place them on the EU market or put them into service under their own name or trademark." A deployer is anyone "using AI systems under their authority, excluding use for personal, non-professional activities."
If you run marketing, you are a deployer. You use other people’s models. The machine-readable marking obligation that generated all the headlines sits with the providers. It is their engineering problem, and Anthropic’s description of its approach and support documentation are the model for how it gets discharged. Our explainer on how AI content watermarking works covers that side.
What deployers get instead is a disclosure duty. Not marking, disclosing. Those are different obligations with different mechanics, and conflating them is why so much of the current advice is unusable.
Deepfakes: the rule that catches synthetic spokespeople
Here is the deployer obligation most likely to apply to a marketing team, rarely described in marketing terms.
The Commission states that deployers must disclose deepfakes "upon first exposure at the latest" in "a clear and distinguishable manner." A deepfake in this sense is AI-generated or manipulated image, audio or video content resembling real people, places or events.
This is where AI watermarking for marketers stops being abstract. Translate it into a media plan. A synthetic brand ambassador. A cloned voice-over of a real presenter. A localised ad where a spokesperson’s mouth is remapped to another language. AI-generated testimonials with faces that look like customers. None of it is exotic now, all of it is pitched to brands weekly, and all of it plausibly sits inside the definition.
There is an exemption, narrower than most will want. For deepfakes "part of evidently artistic, creative, satirical, fictional or analogous works or programmes," the obligation is "limited to the disclosure of the deepfake content in an appropriate manner that does not hamper the display or enjoyment of the work." The duty is reduced, not removed, and it turns on the work being evidently creative. A brand film might qualify. A performance ad almost certainly does not.
A machine-readable mark is not a disclosure
This is the operational point that changes what you have to build, and it is the one I would flag to an agency first.
The Commission’s wording on how deepfake disclosure must be made is unusually specific. It has to be "understandable and perceivable by natural persons (e.g. with visible or audible labels), without need for any specific technical tools."
That rules out the entire provenance stack as a compliance answer. A C2PA manifest is machine-readable and needs a tool to inspect. A statistical text watermark is invisible and needs a vendor’s key. Both are useful; neither discloses anything to a person looking at your ad.
There is a second reason not to lean on provenance metadata in advertising. Metadata is separable from content, and ad platforms re-encode, resize and transcode creative as a matter of course. Any signal living alongside the file rather than inside the frame is one you should assume may not arrive. Worth testing on your own pipeline.
The text duty is narrower than it sounds
The other deployer obligation gets quoted at marketers constantly and mostly does not apply to them.
Deployers "must clearly label AI-generated or manipulated text published with the purpose of informing the public on matters of public interest." That is the trigger, and the qualifying phrase is doing enormous work.
Product descriptions are not matters of public interest. Nor are category pages, promotional emails, ad copy, social captions or landing pages. The overwhelming majority of what a marketing team produces falls outside this duty, and anyone telling you every AI-assisted blog post needs a label is overreading it.
What plausibly does fall inside: corporate communications on public issues, thought leadership reporting on regulation or industry conditions, PR and issues advocacy, health or financial guidance, and anything functioning as journalism regardless of publisher. Content marketing that has drifted into publishing is the case to look at, and it is a large category for B2B brands.
The other reason not to lean on marks here is one we established when looking at what editors can actually verify: short, factual, tightly constrained copy is the least markable content there is. Marketing writing is mostly short, factual and constrained. AI watermarking for marketers is weakest precisely where marketing volume is highest.
Human review is the exemption, and it has a bar
This is the most useful sentence in the guidance for a marketing team, and it has barely been reported.
"Published text that has undergone human review or editorial control does not need to be labelled."
Most marketing teams already do this. A person reads the draft, changes it, approves it. That is the exemption, sitting unclaimed.
The bar is real though. Human review means "deliberate examination of the substance of the content by one or more natural persons" with relevant expertise. Editorial control means oversight by "a responsible editorial entity (e.g. an editor-in-chief)" with authority to "approve, alter or reject the substance." And the guidance explicitly excludes "superficial, solely formal, or procedural checks (e.g. spell-checking or grammatical correction)."
So the exemption turns on substance, expertise and authority, none of which are visible in a document six months later. The gap for most teams is not the reviewing. It is that nothing records who reviewed, what they changed, and whether they had standing to reject it. A named approver and a retained revision history turn a practice you already have into a defensible position. That is a records project, not a technology one.
How you can accidentally become the provider
Now the trap.
The duty to tell people they are talking to a machine sits with providers, not deployers: "Providers of AI systems that directly interact with people must design and develop those systems in such a way that the individuals concerned are informed that they are interacting with an AI system, unless this is obvious." Disclosure is required "from the start of the first interaction," and is unnecessary where an "average person, who is reasonably well-informed, circumspect, and observant" would find it obvious.
Comfortable reading, until you return to the provider definition: those who develop AI systems, or have them developed, and place them on the market or put them into service under their own name or trademark.
Take a vendor’s conversational agent, brand it, name it after your company, put it on your site as your own assistant. That is a reasonable description of putting a system into service under your own name or trademark. The white-label decision that looked like branding may also have been a regulatory one, and marketing usually makes it without anyone flagging that. Whether it lands that way is a question for counsel, but it is the question to ask before the bot ships.
What to do about it
Five positions, in the order I would take them.
Separate the three duties first. Marking is the vendor’s. Deepfake disclosure is yours if you use synthetic people. Text labelling is yours only for public-interest content. Most confusion here is a role error, not a rules error.
Inventory synthetic humans across live creative. Voice clones, AI presenters, generated testimonials, lip-sync localisation. Highest-exposure category, and the one agencies are selling hardest.
Design the label into the creative, not the metadata. Visible or audible, present at first exposure, surviving every cutdown and crop. Brief it like a legal line, because functionally it is one.
Name an approver and keep the revision history. You almost certainly already meet the human-review exemption. Nothing currently proves it. This is the cheapest item on the list and the one with the best return.
Ask who the provider is before you brand a bot. Get it in the contract, with the same seriousness you would apply to a data-processing question. If you are putting a conversational system into service under your own trademark, find out whose obligation the interaction disclosure is, in writing, before launch.
The pattern is the one running through Google’s move to unpublished advertiser qualification: the rules governing marketing are shifting from checklists you complete to conditions you must evidence. Marks and metadata do not satisfy them. Records and visible labels do.
Frequently Asked Questions
Do I have to watermark my AI-generated marketing content?
Almost certainly not, and this is the central confusion in AI watermarking for marketers. The marking obligation falls on providers of generative AI systems, not on the businesses using them. As a marketer you are a deployer. What applies to you is a disclosure duty in specific circumstances, principally deepfakes and text published to inform the public on matters of public interest, and disclosure works differently from marking.
Does a C2PA credential satisfy the disclosure requirement?
No. The Commission’s guidance requires that deepfake disclosure be understandable and perceivable by people without the need for any specific technical tools, giving visible or audible labels as the example. C2PA manifests are machine-readable and require a tool to inspect, so they are useful provenance and are not disclosure. If you need to disclose, the label has to be in the creative where a person will see or hear it.
What counts as a deepfake in advertising?
AI-generated or manipulated image, audio or video resembling real people, places or events. In practice that reaches synthetic brand ambassadors, cloned voice-overs, AI-generated testimonial faces and lip-sync localisation. A limited exemption exists where content is evidently artistic or satirical, but it reduces the obligation rather than removing it, and a performance ad is unlikely to qualify.
Does every AI-assisted blog post need a label?
No. The text-labelling duty is limited to text published with the purpose of informing the public on matters of public interest. Product pages, ad copy, emails, social captions and most content marketing sit outside it. Corporate communications on public issues, issues advocacy, and content marketing that functions as journalism are the cases worth reviewing, which matters more for B2B brands that publish heavily.
What is the human review exemption?
Published text that has undergone human review or editorial control does not need to be labelled. The bar is deliberate examination of the substance by a person with relevant expertise, or oversight by a responsible editorial entity with authority to approve, alter or reject the substance. Superficial or purely formal checks such as spell-checking do not qualify. Most teams already clear this bar in practice and cannot demonstrate it on paper.
How do I prove human review happened?
Record it at the time. A named approver with relevant expertise, a retained revision history showing substantive rather than formatting changes, and documented authority to reject. None of that needs new tooling, and most content systems already capture revisions. The work is deciding who approves and making the record survive.
Am I responsible for disclosure on my branded chatbot?
Possibly, depending on deployment. The interaction-disclosure duty falls on providers, defined to include those putting an AI system into service under their own name or trademark. Taking a vendor’s agent and launching it under your brand can fit that. Establish which party carries the obligation, in the contract, before launch, rather than assuming the vendor absorbed it.
Can I use watermark detection to check what my agency delivered?
Not usefully today. There is no public detection tool for text marks, the key sits with the model vendor, and marketing copy is short and factual, the register where marks are weakest. A negative result tells you almost nothing. Asking which tools were used at which stage, and requiring that contractually, is answerable and enforceable in a way detection is not.