Subscribe
Learn Library

AI Marketing: The Era of Unchecked Growth Is Over

An article explaining how new AI regulations like the EU AI Act and California SB 942 turn AI marketing from an ethics topic into a legal obligation, covering content labeling, hallucination liability, training data, and ad algorithm audits.

ai-marketingevidence
2026-08-30SupaMarketers9 min read

A few nights ago, at 11 p.m., an old friend of mine who runs an e-commerce business called, his voice unsteady.

The AI customer service agent they'd just launched went rogue and promised a customer "buy one, get one free." Marketing never approved any such promotion. The customer had already placed the order — screenshots saved and all.

He asked me: do we honor this order or not?

I said: honor it. Because legally, that promise came from your brand.

Unwilling to let it go, he went digging through the contract. Over at the vendor, a line of fine print had long been waiting for him: this service is provided "as is," with no liability for generated content.

After we hung up, I lay awake for the longest time.

Let me be clear up front: I'm not a lawyer. What follows is about trends and common sense. For your specific business, get professional legal advice. But I'm more and more certain of one thing: AI in marketing has gone from an ethics discussion question to a legal exam you're required to answer.

The Rules Grew Teeth

A few years ago, when people talked about AI marketing, the talk was "what does responsible AI look like." Guidelines were everywhere — all voluntary, all on the honor system.

Now, when industry folks get together, they talk about fines.

Why? Because binding legal frameworks have landed. The EU's Artificial Intelligence Act (EU AI Act) saw its enforceable provisions take effect this August; on the US side, California's SB 942 and Colorado's AI Act are now being enforced as well.

Still sitting on the fence? Fine. But "wait and see" is no longer called prudence.

It's called legal liability.

So what exactly is on the test? I've broken it into a few big questions — let's go through them one at a time.

Question One: AI-Generated Content Must Show Its ID

What does showing your ID mean here?

Any AI-generated image, video, or audio that could be mistaken for a real person or real events must carry two things: visible disclosure, and an invisible technical marker embedded in the file's metadata. The EU requirement, plus California's SB 942 — this isn't a "best practice." It's the law.

What about virtual livestream hosts? AI-generated "influencer" venue reviews? If the audience could take them for real, they count.

How much are the fines? Fail your transparency obligations and the EU can fine you up to €15 million, or 3% of global annual turnover — whichever is higher. For the most serious violations, such as passing synthetic content off as real people and real events without labeling, the top tier can reach 7% of global turnover.

Let me do the math for you. A company with 10 billion in annual revenue — what's 7%? 700 million. How many marketing departments would that bankroll?

And there's one detail that's especially easy to miss: the marker has to be impossible to strip out. Assets get cropped, transcoded, re-edited; once they're out in the wild, they're beyond your control. Lose the marker and your compliance falls apart. So when you're vetting vendors, test this one as its own line item.

Question Two: When AI Gets It Wrong, You're on the Hook

Remember that midnight phone call from the opening?

Why must the brand honor it? Because the law treats what your AI says as what you said.

This past March, the US Federal Trade Commission (FTC) issued a policy statement classifying AI hallucinations as "unfair or deceptive commercial practices." The courts, for their part, are increasingly unwilling to accept "it was just a technical glitch."

The regulators' logic is disarmingly simple: if your human sales rep misspeaks and quotes the wrong price, you have to own it. So why would a bot's words get a pass?

What do you do, then? There's an approach gaining ground in the industry that I find rather ruthless: use AI to police AI. Every external sentence a bot produces goes through another AI acting as auditor first, then a human signs off, and only then does it go out.

One more gate, one fewer midnight phone call.

Question Three: The Model's "Ingredients" Have to Survive Inspection

California has a new law, AB 2013, requiring AI developers to publish summaries of their training datasets.

In plain language: what an AI was fed growing up is now a matter of public record.

What does this mean for marketers? That AI tool you casually reach for may have grown up on pirated material. The images, copy, and videos it generates — a copyright time bomb is buried right there in your own asset library, no telling when it goes off.

So when you negotiate with AI vendors now, you have to walk away with two things.

First, IP indemnification: if the assets it generates land in a copyright lawsuit, the vendor pays. In black and white, written into the contract.

Second, proof of "clean data": training data properly licensed, provenance traceable.

Can't produce either one? However good the tool is, it waits.

Question Four: Algorithms That Play Favorites Will Get Audited

Programmatic buying is under the spotlight now too.

Colorado's AI Act took effect this June. It requires deployers of high-risk AI to run an impact assessment every year. What counts as high-risk? Any system that automatically decides who sees your ads — and who doesn't.

The FTC and Australia's ACCC have both taken to one term: "disparate impact." Intent doesn't matter — only outcomes. The question is whether a particular group is being systematically screened out of housing, credit, or job ads by your model.

Here's an example. A delivery model sees that certain ZIP codes "convert poorly," so it quietly reallocates the budget. But why do those ZIP codes convert poorly? Perhaps they're simply neighborhoods where particular ethnic communities live. The model has no malice — yet the outcome is discrimination.

The fines are real. And no brand can afford not to run that math.

Question Five: Data Fed into a Model Doesn't Come Back

The privacy front has leveled up too.

The EU's GDPR and California's CCPA used to police how you collected data. The question that can really kill you now: has the data you collected been "fed" to some third-party large model?

A customer exercises their "right to be forgotten" and asks you to delete their data. You scrub your database spotless. Then what? If that data was used to train some global model a year ago, it has already dissolved into the model's "muscle memory."

Deleting one person from the model weights? Engineering can't do it. And legally, no explanation will hold up.

It's a dead end no matter which way you turn. Which is why the only safe play is a privately deployed AI instance: your data can come in and do the work, but it never joins the training of anyone else's foundation model.

While we're here, a question a lot of people ask me: can you train your own model on customer data? Yes — but the authorization has to spell out, explicitly, "for AI training." A tired old "for marketing purposes" clause no longer cuts it with regulators.

Three More Items, None of Them Small

First, digital faces and voices. Cloning a celebrity's voice or likeness requires written authorization. Using AI to spin up a virtual human who "bears an uncanny resemblance to a star"? That can be illegal too — in the US, the dedicated NO FAKES Act exists to police exactly this.

Second, don't dress automation up as AI. The FTC and ACCC are cracking down hard on "AI washing": the product is nothing but a rules engine, yet the landing page insists it's "AI-powered." After this year's Growth Cave and Workado cases, you have to be able to spell out exactly how much AI actually improves your product. If you can't, that's overclaiming.

Third, don't let your AI pick on the vulnerable. Some interfaces probe a user's emotional state in real time and push the sale at the moment a person is weakest. Regulators already treat this kind of "predatory steering" as a dark pattern — Section 5 of the FTC Act and the EU's Digital Services Act can both reach it.

Every Question Comes Down to One Sentence

You can outsource the work. You cannot outsource the accountability.

When regulators come knocking, they come for the brand. You can seek recourse from your agencies and vendors afterward — but that's between you and them, and it won't put out the fire in front of you.

That's why the marketing management consultancy TrinityP3 recommends attaching an AI compliance rider to every master service agreement (MSA) you sign with agencies and technology vendors. At minimum, it should pin down three things: who runs bias testing, how hallucinations get intercepted, and whether training data is properly licensed. Best of all, add a "zero data retention" clause: your data is used, then discarded.

One more thing. When a regulator asks why the machine rejected this customer, or quoted them this price, "the algorithm decided" is no longer an acceptable answer. You need to keep thorough AI decision logs, and you need to explain in plain language which factors shaped the decision.

A Self-Audit Checklist

Tonight, go back and run your operation through these six:

  • Is there a marker embedded in your synthetic content that can't be stripped out?
  • Your AI vendor's IP indemnification — is it signed?
  • Does the data processing agreement expressly forbid training models on our data?
  • Has this quarter's programmatic buying had its "disparate impact" checkup?
  • Does externally published AI-generated content pass through a human sign-off gate?
  • Of the AI systems we use, which ones count as "high-risk" under EU or Colorado definitions — have you listed them?

Six for six? Congratulations — you're already ahead of most of your peers.

A Final Word

Some people tell me the good days of AI marketing are over.

I don't see it that way. The Wild West era is indeed over — the borders are drawn, the checkpoints are manned, the patrols are out. But for anyone genuinely building a brand for the long haul, that's good news.

When everyone is forced to run trust as an asset, the people who do honest work finally have the system at their backs.

Here's wishing you never have to take one of those calls at midnight.