Navigating the EU AI Act: New Austrian Guidance Clarifies Transparency and Liability for Advertisers

As of August 2, 2026, the European Union’s landmark AI Act—Regulation (EU) 2024/1689—has fundamentally altered the landscape of digital marketing. With the enforcement of its transparency provisions, the advertising industry has faced a pressing question: Who is legally responsible when AI-generated content is served without a mandatory disclosure label?

To address this uncertainty, the Interactive Advertising Bureau (IAB) Austria, in collaboration with the law firm act legal Austria, released a critical five-page guidance document titled "KI-Kennzeichnung im Digitalmarketing" (AI Labelling in Digital Marketing) on September 16, 2026. This memo serves as a practical roadmap for agencies, brands, and publishers, detailing the triggers for mandatory disclosures and providing a framework for contractual risk mitigation.


The Core Mandate: Defining Responsibility

The central conclusion of the guide is that, in the typical advertising commissioning chain, the agency acts as the primary "deployer" of the AI tool. Consequently, the agency holds the burden of assessing whether an asset requires a label and ensuring that such a label is technically applied.

The guide draws a sharp distinction between the "provider" (the software developer) and the "deployer" (the user). While the provider must ensure the AI system itself is compliant, the deployer is responsible for the final output. The memo clarifies that merely knowing an asset was created with AI does not make a client (the brand) a deployer. However, if a client exercises direct influence—by selecting specific AI tools, issuing detailed prompts, or adjusting parameters—they risk being classified as a co-deployer, thereby sharing the legal risk.


Chronology: The Regulatory Timeline

The implementation of the AI Act has been a staged process, creating a complex calendar for industry players:

  • August 2, 2026: Article 50 of the AI Act becomes applicable. This date marks the onset of transparency obligations for AI-generated content.
  • August 18, 2026: The IAB releases its second version of the AI Transparency and Disclosure Framework, setting an industry-wide standard that posits creator accountability as non-delegable.
  • September 5, 2026: VIA Nederland (the Dutch trade association) publishes its own guidance, focusing on the specific use cases of creative agencies.
  • September 16, 2026: IAB Austria publishes its formal guide to bridge the gap between EU regulation and Austrian national law.
  • December 2, 2026: Deadline for generative systems already on the market before August 2 to conform to machine-readable marking requirements.
  • February 2, 2027: Deadline for the implementation of watermark-detection interoperability, ensuring that various systems can verify the origin of AI content.

Supporting Data: When Disclosure Becomes Mandatory

Not every piece of AI-assisted content requires a "watermark" or label. The IAB Austria guidance emphasizes that common production techniques such as noise reduction, color correction, and standard retouching do not trigger the obligation.

The Trigger Matrix

According to the guide, a visible label is required when content is "deceptively real" or aims to mimic genuine human experience. Specifically:

  1. Media: Deepfakes, cloned voices, fake testimonials, and manipulated depictions of real events or places.
  2. Text: Publicly accessible content concerning matters of public interest created without editorial control. (Standard ad copy is generally excluded).
  3. Interaction: Chatbots and support tools must clearly signal to the user that they are communicating with an AI.

The "Visible" Requirement

The guide is blunt regarding compliance: hidden metadata, invisible watermarks (like Google’s SynthID), or disclosures buried in the "Terms and Conditions" are insufficient. Labels must be clearly visible within the asset itself. The European Commission has provided a set of standardized icons (available in various formats) that denote "AI GENERATED" or "AI MODIFIED," which the guide recommends as the standard for the industry.


Official Perspectives and Market Nuance

The Austrian guidance is part of a broader, often conflicting, ecosystem of advice. The industry is currently balancing three distinct approaches:

  • The Platform View: Google has shifted responsibility for AI labeling entirely onto the advertiser through account settings.
  • The Industry Framework: The IAB’s international framework emphasizes that the organization creating the content cannot delegate its accountability.
  • The Austrian View: By layering these mandates over the UWG (the Austrian Act against Unfair Competition), the IAB Austria guide adds a layer of litigation risk that goes beyond administrative fines.

According to Mag. Philipp E. Stephan of act legal Austria, any individual application must be judged on a case-by-case basis. There is no "one-size-fits-all" solution. Agencies and brands are urged to write explicit "labelling clauses" into their contracts, clearly defining who carries the burden of labeling, who pays for technical implementation, and who indemnifies the other in the event of regulatory scrutiny.


Implications: The High Cost of Compliance

The stakes for failure are significant. Under the EU AI Act, organizations face potential fines of up to €15 million or 3% of their total worldwide annual turnover, whichever is higher.

The Economic Dilemma

Beyond administrative fines, there is a commercial incentive to avoid "over-labeling." An NYU Stern study highlighted in the IAB framework revealed that AI disclosure labels can reduce click-through rates by as much as 31.5%. This creates a delicate tension:

  • Under-labeling risks massive regulatory fines and lawsuits from competitors under the UWG.
  • Over-labeling risks alienating consumers and suffering a measurable drop in campaign performance.

Publisher Responsibility

Publishers are generally treated as "conduits" and are exempt from labeling duties provided they serve the ad as-is. However, the moment a publisher modifies an ad, personalizes it, or integrates it into their own AI-driven chatbots, they become a "deployer" and inherit the full scope of disclosure requirements. This creates a new barrier to entry for publishers looking to optimize ads through internal AI models.


Strategic Recommendations for Stakeholders

To navigate this new environment, the IAB Austria guide recommends a three-step internal process:

  1. Role Assessment: Determine if your organization is the "provider" (software developer) or "deployer" (user) for every specific campaign.
  2. Control Mapping: Document who holds the power to approve content, who manages the technical application of labels, and who has the final say on the creative strategy.
  3. Liability Allocation: Draft robust contracts that include indemnification clauses. If a brand directs the agency to avoid a label, the brand must be prepared to accept the liability for that decision.

The guidance concludes with a necessary reminder: labelling is not a substitute for legal due diligence. AI compliance does not exempt an ad from existing laws regarding copyright, personality rights, or data protection (GDPR). The recent ruling by a Berlin court ordering a YouTuber to pay €4,000 for using an unauthorized voice clone serves as a stark warning that synthetic media remains subject to long-standing personality rights, regardless of whether it carries an AI disclosure label.

As the industry moves toward the December 2026 deadline for machine-readable markings, the focus will likely shift from simple transparency to the technical interoperability of these systems. For now, the Austrian advertising sector has a clear message: transparency is no longer optional, and the responsibility for that transparency starts with the hand that holds the prompt.