Navigating the Regulatory Landscape — FTC, EU AI Act, and Beyond
In January 2026, a supplement company received a $4.2 million FTC fine for running AI-generated testimonial videos on its website. The videos featured synthetic faces, synthetic voices, and fabricated health claims attributed to fictional customers. The company's defense — that AI-generated content was not explicitly covered by existing testimonial guidelines — was rejected. The FTC's position was unambiguous: "The technology used to create deceptive content does not determine whether the content is deceptive. A false testimonial is a false testimonial whether written by a human, generated by AI, or carved in stone."
That ruling signaled something every marketer needs to understand: regulators are not waiting for AI-specific laws to enforce existing consumer protection standards against AI-enabled marketing practices. The regulatory landscape for AI in marketing is not a blank slate waiting to be written. It is an evolving patchwork of existing laws being reinterpreted, new AI-specific regulations being enacted, and enforcement actions establishing precedent in real time.
This lesson maps that landscape. You will learn what the FTC currently requires and what it has signaled it will require. You will understand the EU AI Act's classification system and what it means for marketing operations that touch European consumers. You will see how state-level privacy laws in the United States are creating a fragmented compliance environment. And you will leave with a practical compliance checklist you can implement immediately — because the time to figure this out is before an enforcement action, not after.
The FTC's Evolving Position on AI in Marketing
The Federal Trade Commission is the primary regulator of advertising and marketing practices in the United States, and it has been increasingly vocal about AI since 2023. Understanding the FTC's approach requires understanding a fundamental principle: the FTC regulates outcomes, not technologies. It does not need a specific law about AI-generated marketing to take action against AI-generated marketing that is deceptive, unfair, or harmful.
The FTC's authority comes primarily from Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices in or affecting commerce." This broad mandate has been applied to every new marketing technology from radio to television to the internet, and it applies with equal force to AI.
The deception standard. The FTC considers marketing deceptive if it contains a material representation, omission, or practice that is likely to mislead a consumer acting reasonably under the circumstances. AI does not change this standard — it simply creates new ways to violate it. AI-generated testimonials from non-existent customers are deceptive. AI-generated product demonstrations showing capabilities a product does not have are deceptive. AI-personalized pricing that creates false impressions of scarcity or urgency is deceptive. The technology is new; the legal standard is not.
The unfairness standard. The FTC considers a practice unfair if it causes or is likely to cause substantial injury to consumers that is not reasonably avoidable and not outweighed by benefits to consumers or competition. AI-driven dark patterns that make it unreasonably difficult to cancel subscriptions meet this standard. AI targeting that steers vulnerable populations toward harmful products meets this standard. AI-powered surveillance pricing that charges different consumers different prices based on their willingness to pay, without disclosure, is being actively examined under this standard.
Key FTC guidance documents. The FTC has issued several guidance documents specifically addressing AI in marketing:
The April 2023 blog post "Keep your AI claims in check" warned companies against making unsubstantiated claims about AI capabilities and against using AI in ways that are deceptive. The August 2023 guidance "AI and the FTC: No exemption for emerging tech" reinforced that existing FTC rules apply fully to AI-generated content. The February 2024 "AI is not an excuse" enforcement statement directly addressed AI-generated testimonials, endorsements, and reviews, making clear that synthetic endorsements are held to the same standards as real endorsements. And the March 2026 updated endorsement guides explicitly included AI-generated content, requiring that any material connection between an endorser and a brand be disclosed — including the material fact that the endorser is not a real person.
Enforcement trends. The FTC has brought multiple enforcement actions involving AI in marketing since 2024, and the trend is toward increasing scrutiny and larger penalties. Common enforcement targets include: fake reviews and testimonials generated by AI, AI-generated health and safety claims that are unsubstantiated, AI-powered surveillance pricing without adequate disclosure, deceptive AI chatbots that impersonate human customer service representatives without disclosure, and dark patterns in AI-optimized subscription flows.
Important: The FTC does not require you to disclose that you use AI in your content creation process. It requires you not to deceive consumers. The distinction matters. If you use AI to help draft a blog post that a human reviews, edits, and publishes under their byline, the FTC has not indicated that this requires disclosure. But if you use AI to create a synthetic person who appears to be a real customer giving a real testimonial, that is deceptive with or without a disclosure statement. Focus on whether your AI usage creates deception, not on whether you are "using AI" in a general sense.
The EU AI Act: What Marketers Need to Know
The European Union's AI Act, which entered into force in stages beginning in 2024, is the world's first comprehensive AI-specific regulation. If your marketing reaches EU consumers — and if your brand has a website, it almost certainly does — you need to understand how this law affects your operations.
The EU AI Act uses a risk-based classification system that categorizes AI applications into four tiers: unacceptable risk (banned), high risk (heavily regulated), limited risk (transparency obligations), and minimal risk (no additional obligations). Most marketing applications fall into the limited risk and minimal risk categories, but the boundaries are important to understand.
Transparency obligations for AI-generated content. The EU AI Act requires that AI-generated content be labeled as such when it could be mistaken for human-generated content. This applies directly to marketing: if you publish AI-generated text, images, audio, or video that a reasonable consumer might believe was created by a human, you must disclose that it was AI-generated. The specific labeling requirements are still being finalized through implementing regulations, but the principle is clear — deception by omission about AI origin is prohibited.
Chatbot disclosure requirements. If your marketing uses AI chatbots — for customer service, lead qualification, product recommendations, or any other consumer-facing function — the EU AI Act requires that consumers be informed they are interacting with an AI system. The disclosure must be clear and timely — presented before or at the beginning of the interaction, not buried in terms of service. This applies regardless of how human-like the chatbot sounds.
Emotion recognition restrictions. The EU AI Act places significant restrictions on AI systems that detect and respond to human emotions. In a marketing context, this means that AI tools that analyze facial expressions, voice tone, or biometric data to determine a consumer's emotional state and adapt marketing messages accordingly face stringent requirements — and some applications may be prohibited entirely. If your marketing technology stack includes emotion recognition capabilities, legal review is essential.
Subliminal manipulation prohibition. The EU AI Act explicitly prohibits AI systems that deploy "subliminal techniques beyond a person's consciousness" to materially distort behavior. In a marketing context, this creates potential liability for AI-optimized marketing experiences that are designed to influence purchasing decisions through techniques the consumer cannot consciously perceive. The scope of this prohibition is still being defined through guidance and case law, but the intent is clear: AI-powered marketing that works by bypassing conscious awareness is on the wrong side of this line.
Profiling and automated decision-making. The EU AI Act, building on the GDPR's existing provisions, imposes requirements on automated profiling that produces legal or significant effects on individuals. AI-driven marketing personalization that determines which consumers see which offers, what prices they are shown, or which services they can access may trigger these requirements — particularly if the profiling is based on sensitive categories like health status, financial situation, or political beliefs.
US State Privacy Laws: The Fragmented Landscape
In the absence of a comprehensive federal AI law in the United States, state legislatures have created a patchwork of privacy and AI regulations that marketers must navigate. As of early 2026, more than 15 states have enacted comprehensive privacy laws, and several have passed or are considering AI-specific legislation.
California. The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives consumers the right to opt out of automated decision-making technology, including AI-powered profiling used for marketing purposes. California's proposed AI transparency legislation would require businesses to disclose when consumers are interacting with AI systems and when content is AI-generated. California also has specific regulations around the use of digital replicas — synthetic media depicting real people — that have direct implications for AI-generated marketing content.
Colorado. The Colorado AI Act, enacted in 2024, requires deployers of "high-risk AI systems" to provide transparency about how AI is used in decisions that affect consumers. While most marketing applications are not classified as high-risk, AI systems that make decisions about pricing, credit, insurance, or employment — all of which intersect with marketing — may trigger compliance obligations.
Illinois. The Illinois Biometric Information Privacy Act (BIPA) has been used in lawsuits against companies that use facial recognition and biometric data in marketing contexts. If your AI marketing tools analyze facial features, voice patterns, or other biometric identifiers, BIPA's consent and disclosure requirements apply to interactions with Illinois residents.
Virginia, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Texas, Oregon, and Delaware have all enacted comprehensive privacy laws with varying provisions related to automated decision-making, profiling, and consumer opt-out rights. The specific requirements differ across states, creating a compliance challenge for brands that market nationally.
The practical reality is that marketers operating in the United States must comply with the strictest applicable state law for each consumer they reach — which in practice means building systems that can accommodate the most stringent requirements, since identifying which state a consumer is in and applying different rules is technically possible but operationally complex.
Tip: Do not try to track and comply with each state's laws individually in real time. Instead, identify the strictest requirements across all states where you operate and build your compliance baseline to that level. This approach is more expensive upfront but far less expensive than maintaining 15 different compliance frameworks or risking violations in states with stricter standards. When in doubt, apply the EU standard — it is generally the strictest in the world and provides a defensible compliance position almost everywhere.
International Regulations Beyond the EU
If your marketing reaches consumers outside the US and EU, additional regulatory frameworks may apply.
United Kingdom. Post-Brexit, the UK has taken a "pro-innovation" approach to AI regulation, relying on existing regulators to apply existing laws to AI contexts rather than creating a comprehensive AI-specific law. The Advertising Standards Authority (ASA) has issued guidance on AI-generated marketing content, requiring that ads be "obviously identifiable as marketing communications" regardless of how they are created. The Information Commissioner's Office (ICO) applies GDPR-derived data protection standards to AI-powered marketing personalization.
Canada. The Artificial Intelligence and Data Act (AIDA), part of Canada's Bill C-27, establishes requirements for high-impact AI systems including transparency, risk assessment, and harm mitigation. Marketing applications that use AI for consumer profiling or automated decision-making may fall within scope.
Brazil. Brazil's AI Bill, building on the country's existing data protection framework (LGPD), requires transparency about AI usage in consumer-facing applications and gives consumers the right to human review of automated decisions. Marketing that relies on AI-driven personalization for Brazilian consumers must accommodate these rights.
China. China has enacted multiple AI regulations including rules on algorithmic recommendation systems, deep synthesis (deepfakes), and generative AI. Marketing content that uses AI-generated synthetic media, recommendation algorithms, or generative AI for Chinese consumers must comply with disclosure requirements and content restrictions that in some cases are stricter than those in the US or EU.
The trend across all jurisdictions is toward greater transparency, more consumer control, and stricter accountability for AI-generated content. Marketers who build their compliance frameworks to anticipate this trend will be better positioned than those who scramble to comply with each new regulation as it is enacted.
Your AI Marketing Compliance Checklist
Use this checklist to assess and improve your current compliance posture. No checklist can substitute for legal counsel specific to your situation, but this provides a starting framework for identifying gaps and prioritizing fixes.
Content truthfulness. Are all claims in AI-generated marketing content substantiated with evidence? Is there a verification step between AI generation and publication? Are AI-generated statistics, quotes, and references checked against original sources? Would every claim survive FTC scrutiny for accuracy and substantiation?
Testimonial and endorsement integrity. Are all testimonials from real customers who have actually used the product? Are material connections between endorsers and the brand disclosed? If synthetic media is used in testimonials or endorsements, is the synthetic nature clearly disclosed? Are AI-generated reviews or ratings labeled as such?
Transparency and disclosure. Are consumers informed when they are interacting with AI chatbots? Is AI-generated content labeled when required by applicable law? Is your AI usage policy documented and available to consumers who ask? Are deepfakes and synthetic media clearly identified as such?
Data and privacy. Is consumer data used for AI-powered personalization collected with appropriate consent? Are consumers able to opt out of AI-driven profiling and automated decision-making? Is biometric data (facial features, voice patterns) collected and processed in compliance with applicable biometric privacy laws? Are data retention policies applied to AI training data?
Targeting and fairness. Are targeting criteria reviewed for potential discrimination or exploitation of vulnerable populations? Is AI-driven pricing transparent and non-discriminatory? Are cancellation, opt-out, and unsubscribe processes clear and not unreasonably difficult? Are dark patterns identified and eliminated from AI-optimized user flows?
Documentation and governance. Is your AI marketing ethics framework documented? Are AI marketing decisions logged for potential regulatory review? Is there a named person responsible for AI marketing compliance? Are compliance reviews conducted at least quarterly?
What to Do Monday Morning
- Run the compliance checklist above against your current operations. Go through each category and honestly assess your current state. Mark items as "compliant," "partially compliant," or "non-compliant." Prioritize fixing non-compliant items that carry the highest regulatory risk.
- Brief your marketing team on FTC basics. Share the core principle: existing consumer protection laws apply fully to AI-generated marketing content. The technology does not create an exemption. Every claim must be substantiated, every testimonial must be real, every material connection must be disclosed.
- Identify your EU exposure. Determine whether your marketing reaches EU consumers (it almost certainly does if you have a website). If so, begin planning compliance with the EU AI Act's transparency requirements — particularly chatbot disclosure and AI-generated content labeling.
- Schedule a legal review of your AI marketing practices. If you have not had a lawyer review your AI-enabled marketing processes, schedule that review this month. Provide your legal team with a comprehensive list of all AI tools you use, all AI-generated content types you publish, and all AI-driven targeting and personalization practices you employ.
- Subscribe to regulatory updates. The regulatory landscape is changing rapidly. Subscribe to the FTC's business blog, the EU AI Act implementation updates, and at least one AI regulation tracking service. Designate one person on your team as the regulatory point of contact who monitors updates and flags relevant changes.
Key Takeaways
- Understand that the FTC regulates outcomes, not technologies — existing consumer protection laws apply fully to AI-generated marketing, and "the AI did it" is not a defense.
- Know the EU AI Act's transparency requirements for AI-generated content, chatbot disclosure, emotion recognition restrictions, and subliminal manipulation prohibition — all of which affect marketing operations that reach EU consumers.
- Recognize that US state privacy laws create a fragmented compliance landscape where marketers must meet the strictest applicable standard for each consumer they reach.
- Track international regulations in the UK, Canada, Brazil, China, and other markets where your marketing operates, as the global trend is toward greater transparency and accountability.
- Use the compliance checklist to assess your current posture across content truthfulness, testimonial integrity, transparency, data privacy, targeting fairness, and governance.
- Build compliance systems that anticipate regulatory trends rather than scrambling to meet each new requirement — the direction of regulation is clear even when the specific requirements are still being finalized.
Skill.re