Disclosure Day: Do AI-generated emails need a disclaimer?
What email marketers actually need to know about AI labels, the word “provenance,” and the growing list of laws trying to figure out what the robots did in your emails.

In this article:
- Whether the EU AI Act actually requires an AI disclosure label on marketing emails
- What Article 50 of the EU AI Act really says and who it applies to (providers or deployers)
- When AI-generated images do need a disclosure label in emails (deepfakes, realistic depictions) vs. when they don't
- If AI-assisted subject lines, copy, and layout assembly trigger disclosure requirements
- What counts as "meaningful human review" under EU guidance
- How real-time personalization in emails fall under AI disclosures in email
- What "AI provenance" means, and what your team should actually be tracking even when disclosure isn't required
Also, a quick note from our legal team who reviewed this article and loved every section, but wanted me to emphasize this: This article is for general information purposes only and does not constitute legal advice. For guidance on your specific situation, consult qualified counsel.
Does your current email workflow look like this? You open up Figma and ask AI to remove that sad-looking ficus behind your product (there’s always one). Then you realize that you need to extend the background because it’s not wide enough for that hero spot in the email. From there, you ask ChatGPT to make the subject line “way less desperate” and maybe give you some ideas about how to make the CTAs a little less boring too. But you aren’t done yet. With the images and copy ready, you give it to an agent with your brief… which takes an existing template in your email builder, rearranges some rows to fit your brief’s instructions, and then saves a new version for you to review and export to your ESP.
Congratulations, because you’ve involved AI in so many different ways in one email. But do you have to tell anybody? Do you need a cute little “Made With Robots” label in your email? Do you need to add back that Gemini sparkle icon into the bottom right of the hero image? And most importantly, does anyone in Legal know you did this stuff?
Welcome to the surprisingly weird world of AI “provenance.”
You’ll see the word provenance a lot here. Provenance is basically the history of where a piece of content came from and what happened to it along the way. For email makers, think of it like a creative paper trail where you document what items you made, what things AI did, and how it was put together.
Provenance is pretty much a new concept in email, mostly because of new laws and regulations that are going into effect. The EU AI Act is the big one. Its transparency requirements for AI-generated content began applying in August 2026. China already has AI-content labeling rules in effect. South Korea's AI Basic Act took effect in 2026. California has new requirements around provenance for certain AI-generated media. Other countries and states are figuring out their versions now too.
And to make it more complicated, the rules aren't all the same. Some care about visible labels. Some care about invisible, machine-readable information. Some focus on deepfakes. Some focus on how AI interacts with consumers. And some barely affect the kind of AI assistance email makers use every day.
So, what’s an email maker supposed to do? You are in luck, because that’s what this article is all about. Kachow!
First: No, Europe doesn't require an "AI made this email" label. Well, almost doesn’t require it.
With the new laws being applied this month in the EU, the specific transparency requirements don’t say that you need to tell everyone every reason you used AI. This is probably the biggest misconception about the regulation that we’ve seen online. (We asked our lawyers based in Europe. They confirmed that this is over hyped.)
That’s because the rules distinguish between the kinds of AI purposes and different responsibilities.
Let’s explain. The providers of Gen-AI systems (like Claude, OpenAI, Gemini) have obligations around making AI-generated/manipulated outputs detectable. Whereas for businesses using AI, visible disclosure is much narrower. As you’d expect, deepfakes and public-impacting text are part of that narrower focus. But what about all the other things that email makers use AI to do?
Another quick vocabulary check, since it comes up again later: the provider built the AI tool (OpenAI, Adobe, your ESP's AI feature). The deployer is your company (and eventually you, using the AI tool). Most of the embedded obligations fall on providers. Most of what you need to worry about as a deployer is disclosure, review, and not accidentally destroying what the provider already embedded.
For example, what if your original subject line and headline were “Your butt deserves better,” but then, after AI changed it to “Vote on these public toilet ideas” to make it a bit safer for a general audience, your boss asks if you need to disclose the much weaker output. Because, of course, we all know that the original would’ve slayed.
So… I was thinking that we could do some scenarios and have you guess which ones you’d need to disclose. Sounds like a fun game, right? Well, I’m going to make you play the game even if you said no.
Also, before we start, just a heads up that these scenarios are specific to the EU AI Act. Other listed jurisdictions have their own rules and exemptions, which may not mirror the EU's. We cover a little bit of those later in the article.
🎭 ROLE PLAYING TIME
Scenario 1: AI Subject Line
You used AI to rewrite the subject line. Congrats. (Do you need to disclose AI was used to write a subject line?)

Do you need an AI disclosure? Generally, no.
For ordinary commercial email, the EU doesn't impose a blanket recipient-facing disclosure simply because generative AI helped write or rewrite marketing copy.
Your design does not need to add: This subject line was lovingly rewritten by a large language model.
You also don’t need to format your subject line like this:
Subject: Your weekend shoes are 20% off [AI GENERATED]
Please don't do that.
Scenario 2: AI arranges the email
(Do you need to disclose that AI arranged your emails?)

Disclosure?
Again, generally no automatic recipient-facing AI disclosure simply because AI assembled the email. If that last part — an agent editing a template on your behalf — sounded oddly specific, it's because it's not hypothetical. This is exactly what tools like RGE Studio's MCP Server do: they let an AI agent open an existing template, make changes, and push them into the editor in real time. It's a good example to keep in your head for the rest of this article, because "AI assembled it" is about to become a very normal sentence.
And the distinction is going to become increasingly important:

The AI involvement scale
Think of AI participation in an email something like this:
- Level 0 — HUMAN: Sarah wrote it.
- Level 1 — AI ASSISTED: Sarah wrote it. AI fixed the grammar.
- Level 2 — AI MODIFIED: Sarah wrote it. AI substantially rewrote it.
- Level 3 — AI SELECTED: AI picked existing approved assets/modules that Sarah already created.
- Level 4 — AI ASSEMBLED: AI built an email from approved pieces, top to bottom (not just a couple selections) from what Sarah already created.
- Level 5 — AI GENERATED: AI created original copy/images/layout based on Sarah’s prompt.
- Level 6 — AUTONOMOUS: AI decided what to say, who should receive it, created everything, and probably even sent it for you. Sarah wasn’t involved in really any of it.
When we get to Level 5, this is where we need to start worrying about things. And the last one is the most important, because this is where you start looking at your LinkedIn profile.
Okay, let’s move on to some harder scenarios.
🎭 Scenario 3: AI images in your email
The intern has created Timothée Chalamet (Do you need to disclose that you used AI-generated images in your email?)

Disclosure? Okay. Now Legal may actually want to join the meeting.
The EU requires disclosure for qualifying deepfakes, whether it’s AI-generated or manipulated image, audio or video content resembling real people, objects, places, entities or events in a way that could falsely appear authentic.
That disclosure, as described by the EU for deepfakes, is this label:

It also applies when you generate news stories or summaries.
2026 guidance says the icon should be clearly perceivable at first exposure and, ordinarily, directly embedded into the deepfake itself (or presented through an equivalent UI overlay).
Now, let’s just say you had an image of an open room and you just filled it with furniture (from pictures your team has from the product catalog) with AI to make it look realistic. That would land you with this label instead:

Both of these examples (famous person wearing sneakers and furniture placed in a room) may use your product image, but the context is different. However, remember that these icons are not mandatory (the EU just advises using them to provide clarity). And, to complicate things a little more, what do you think if your prompt was this?
“Generate a purple shoe floating above Saturn.”
Nobody reasonably believes Nike launched a retail location on Saturn…Yet. So you don’t need to actually disclose AI was used in that scenario because you aren’t trying to convince someone that it is real.
But there's another kind of label you might never see
Here's where this gets nerdy. And useful. AI provenance doesn't necessarily mean putting something visually on an email. An AI-generated JPEG can contain information about its origin inside the file itself and this is what is embedded by the AI provider.
Think: hero.jpg
👀 What the subscriber sees:
> A beautiful person holding an implausibly beautiful sandwich.
🤖 What software may be able to see:
> AI generated
> Provider: [generator]
> Creation information
> Content credential
> Cryptographic provenance data
Technologies such as Content Credentials/C2PA are designed to make this kind of provenance possible. It gets baked into your image metadata, and then can be read by any system that knows what to look for. OpenAI even has a page where you can upload images and it will check for you.
Generated images also now contain a synthetic label, which may be unseeable by a human but can be detected by one of these verification tools.
But… your email platform may accidentally murder all of that on accident.
Quick clarification before we go further: you don't have to build this embedding yourself. That machine-readable marking (the invisible "AI generated" data baked into the file) is the AI tool's job to create, not yours. If you're using Midjourney, Firefly, or your ESP's built-in image generator, the marking obligation legally sits with them as the provider of the generative system. You're the deployer, which means that you didn't build the tool; you just used it.
So why should you care at all? Because even though you're not responsible for putting the marking there, you can absolutely be the reason it disappears. And once it's gone, so is your ability to point to it if anyone ever asks where an asset came from.
Let’s take this situation: You generate an image, that image gets uploaded to your ESP, and then your ESP changes the format.

Resizing, re-encoding, compressing and otherwise processing an image can potentially affect embedded provenance information depending on the technology and implementation.
Which creates an important question for email platforms: Should they preserve provenance when they process assets? Increasingly, the answer is looking like yes, whenever technically feasible.
So before we jump into another scenario, how about a quick round up of what’s going on in the world?
🌎 The extremely simplified AI-labeling world tour
This is intentionally simplified because lawyers deserve employment too.
(Quick aside if you're the one actually localizing these campaigns: this is where translation tools — like the translation feature inside RGE Studio's AI Assistant — earn their keep. Same logic applies: AI translating your existing, human-approved copy into Korean or Portuguese is assistive editing, not new AI-generated content. The disclosure question doesn't change just because the language did.)
I couldn’ve added more, but at this point this article is already getting pretty long. Suffice it to say, the landscape is changing all the time. Also, I can tell you are getting bored with this part, so let’s move onto anothe scenario.
🎭 Scenario 4: AI-written newsletters
AI writes your regulatory newsletter (Do you need to disclose that AI wrote your newsletter for you?)

Disclosure?
The EU specifically addresses AI-generated/manipulated text published for the purpose of informing the public about matters of public interest. And it dictates that humans need to be meaningfully involved in that process.
But meaningful human review is doing a lot of work in that sentence, and it's worth being precise about what "meaningful" means. The EU's own guidance draws a line here: a quick skim, a spell-check, or a "looks good, send it" doesn't count. What counts is someone actually reading it for substance — checking claims, tone, and accuracy — and putting their name on it as the person responsible for what went out. It needs genuine human review with attributable editorial responsibility.
So there's a real difference between:
- AI drafts it → Sarah rubber-stamps it → sent. (Probably doesn't clear the bar.)
- AI drafts it → Sarah reads it line by line, fixes things, and is the named owner of what shipped → sent. (Clears the bar.)
If your review step is a checkbox with nobody's name attached to it, that's the thing to fix first because it changes whether you need a visible label (usually still no). It's also the difference between having a real defense and not having one.
So what should email teams actually track?
Here's where we think this gets much bigger than AI labels. Imagine opening an email's history and seeing:
This is the provenance thing again. It tell sus much more than if an email is made with AI. Because “was this email made with AI?” is becoming harder to define with every step added in and the importance of that origin to the overall message. This is why this gets messy and complicated because AI could’ve changed one comma or literally everything.
But, the distinction between tracking what’s been done and disclosing what has been done are two different things. Tracking is important because you may need to defend yourself later (e.g., “The boss is who put that paragraph in there. Not me!”) whereas disclosing specific content that has been generated.
🎭 Scenario 5: AI audits for your emails
YOU ARE NOW THE AI DETECTIVE (Where do you look if an AI audit is done on your emails?)

Where would you go if someone asked you if AI was used in your email? The people responsible for the content? The changelogs of your builder? Some third party system to validate? If your ESP or email builder is keeping track of versions and who did what, this is probably the best place to look. For example, it may look like this:
10:42 AM Sarah wrote headline
10:44 AM AI generated five alternatives
10:46 AM Sarah selected #3
10:48 AM Sarah edited #3
11:03 AM AI assembled layout
11:17 AM Sarah changed layout
2:31 PM Mark approved campaign
3:02 PM Exported to ESP
Case closed. (Mostly.) Now the legal team gets to decide to do with this information. And this is why AI audit trails may become a very big deal.
Which takes us to a point we haven’t included yet: AI systems that interact directly with people. If a recipient replies to one of your emails and a bot answers, or your “dynamic content” is actually a live AI system deciding what to show to a specific reader in real time rather than picking from pre-approved options, then that is an AI interaction.
The EU AI Act has a whole section about this (Article 50(1) - linked below), which states that people need to know when they’re talking to AI. This is an easy miss that we haven’t seen other people talk about because it doesn’t feel like “content” the way that a subject line does. And here’s a couple places that this shows up in email specifically:
- Reply-bots on transactional or support emails
- Real-time AI personalization
The real catch isn’t that this isn’t your problem because it happens automatically. Your company is the deployer either way (whether AI wrote the subject line or a bot is replying realtime to subscribers), and the obligation to know what went out the door doesn’t shrink just because a human on your team didn’t personally click “send.”
And, if anything, this deserves more scrutiny. A subject line rewrite is static and reviewable before it ships, but a live AI system deciding what to say to each subscriber is generating new decisions after you’ve already set up the campaign, which means your review process has to happen at the system level (e.g. what’s this AI allowed to say, what content can it grab, how much of a discount can it give in a certain situation, etc). That needs to be logged along with frequent reviews to make sure it doesn’t fall off the rails.
Here’s a real example from how we are doing this at Really Good Emails to make sure that anything autonomous doesn’t get sent out the door without being reviewed first:
- After a sales or support call, the call’s transcription is pulled by an AI agent
- That AI agent then reads the transcript and checks our our internal content/knowledge base (via MCP) for information that should be included in a post-call follow up email
- An agent then uses Claude to write a quick summary based on step 2’s directions and formatting
- An agent then takes that written output and connects to the RGE Studio MCP, where it locates our post-call follow up template, creates a new personalized version, and then places a draft email into an approved folder

- The person at RGE who was responsible for following up then receives an email that the email is ready to be reviewed in RGE Studio before being sent. From there, the individual can make changes as needed using RGE Studio’s editor and then send.
Here’s what that looks like when the workflow is completed and the email is ready to be reviewed:

But maybe even more importantly, because we have established a dedicated folder for this and RGE Studio automatically saves a paper trail of any changes, we can see what the individual did and when they exported the email to our ESP.

Right now the AI conversation is obsessed with if AI was used, but the future question is what AI did.
The takeaway
Email marketers typically don't need to start putting MADE WITH AI at the bottom of every campaign. But we should start paying attention to the paper trail.
- Who created the content?
- What did AI generate?
- What did it merely edit?
- What did it select?
- What did it assemble?
- Which model touched it?
- Was the original provenance preserved?
- Did a human review it?
- What actually got sent?
These are just some things we’re thinking of because AI regulation is still evolving. For most routine marketing tasks (like rewriting a subject line or building a layout), a visible label is typically not required, whereas for deceptive content or deepfakes, disclosure is necessary.
Today, recording all of this might feel excessive. But as soon as next year, you may get asked how AI was used in the campaign. And instead of saying, “let me ask Sarah,” you can point them to what was exactly done with those public toilets and sneaker-wearing celebs.
Frequently asked questions (that our legal team got sick of answering)
Does the EU AI Act require an AI disclosure label on marketing emails?
Generally, no. For ordinary commercial email (subject lines, body copy, layout, personalization) the EU AI Act doesn't require a recipient-facing "made with AI" label. The disclosure requirements are narrower and apply to specific situations, mainly deepfakes and AI-generated text published to inform the public on matters of public interest. Most marketing email doesn't fall into either bucket.
How does the Article 50 of the EU AI Act relate to email?
Article 50 is the part of the EU AI Act that deals with transparency around interacting with AI, and marking AI-generated content. It splits obligations between providers (the companies that build AI systems, like OpenAI or Adobe) and deployers (companies that use those systems, like you). Providers have to make their outputs technically detectable as AI-generated. Deployers only have to add a visible disclosure in narrower cases, like deepfakes, in their emails.
What's the difference between an AI "provider" and a "deployer"?
The provider built the AI tool. The deployer is the company using it. If you're using ChatGPT, Midjourney, or an AI feature inside your email builder, you're company is the deployer — not the provider. Most of the technical marking obligations (the invisible, machine-readable stuff) sit with the provider. Most of what a deployer needs to worry about is disclosure in specific cases, human review, and not accidentally stripping out marking the provider already added.
Do I need to disclose that AI wrote or rewrote my subject line?
No. Rewriting a subject line, tightening copy, or generating a few CTA options is the kind of everyday assistive editing the EU AI Act doesn't require a label for. You're still the one deciding what actually ships.
Do I need to disclose that AI arranged or assembled my email layout?
Generally, no. AI selecting modules or assembling a layout from your existing, approved content doesn't trigger a recipient-facing disclosure requirement on its own. Where this can get more complicated is if AI is generating layout and content with little to no human review because that's when you're closer to territory that deserves a second look (see the AI involvement scale earlier in this piece).
Do AI-generated images need a disclosure label?
Sometimes. If the image is a realistic depiction (like a real-looking person, place, or event) that could be mistaken as authentic/real, it likely needs a disclosure. If it's obviously not real (like a floating shoe store over Saturn), it generally doesn't. The test isn't "was AI used," it's "could someone reasonably believe this is real."
Is using the EU's official AI icons required?
No, the icons themselves are optional; you can design your own disclosure. What's not optional is the underlying requirement to disclose when disclosure applies. The Commission just recommends the icons because they've tested well for clarity.
If AI translates my already-approved copy, do I need a new disclosure?
No. Translating existing, human-approved content into another language is assistive editing, not new AI-generated content. The disclosure question doesn't change just because the language did… though the other country's own AI-labeling rules might still apply (see the world tour table above).
Do other countries have the same rules as the EU?
Nope. We primarily focused on the EU in this article because that’s what recently went into effect, but China, South Korea, India, and others have their own AI-labeling frameworks and they don't mirror the EU's. Some care about visible labels, some about invisible machine-readable markers, some about specific content types. If you're sending into multiple markets, treat each jurisdiction's rules separately rather than assuming EU compliance covers you everywhere.
What should email teams actually track, even if disclosure isn't required?
Provenance. It’s basically a record of who made what and how AI was involved at each step (drafted, edited, selected, assembled). You may not need to disclose most of this to recipients, but you may need to explain it internally later (e.g., to legal, to a client, or to a regulator asking what AI did in a specific campaign).
Sources & further reading
- European Union — EU AI Act, Article 50 and Recitals 133–134. The primary legal source for the article's discussion of machine-readable marking, deepfakes, AI-generated public-interest text, provenance, authenticity, metadata, watermarks, logging and fingerprints. Recital 133 specifically uses the phrase “cryptographic methods for proving provenance and authenticity of content.”
Read the EU AI Act - European Commission — Article 50 Transparency Guidelines. Probably the most useful source for an email marketer. The Commission's July 2026 guidance explains how Article 50 applies in practice, including provider obligations for machine-readable marking and deployer obligations involving deepfakes and certain public-interest text.
Read the Article 50 guidelines - European Commission — Code of Practice on Transparency of AI-Generated Content. Practical implementation guidance supporting Article 50's marking, detection and labeling requirements. It also confirms that these Article 50 obligations became applicable on August 2, 2026.
Read the Code of Practice - C2PA — Content Credentials specification. The technical basis for our discussion of provenance living with images. C2PA defines provenance as understanding an asset's history and interactions with actors and other assets. Its specification describes how Content Credentials can be embedded in formats including JPEG and PNG, as well as how cryptographic bindings can detect modification.
Read the C2PA specification - European Commission — EU Icons for Labelling AI-Generated Content. The EU's official guidance and downloadable icons for visually identifying certain AI-generated or manipulated content. It explains the Fully AI-Generated, Partially AI-Modified, and basic AI icons; when they can be used; and how they should be displayed. The Commission says disclosures should be clearly perceivable by the time of first exposure and recommends directly embedding the icon into covered content unless an equivalent method, such as a UI overlay, is available. It also notes that user testing found the icons performed better when accompanied by a plain-language text label. Importantly, using the EU icons is optional; complying with Article 50's applicable disclosure requirements is not.
EU Icons for Labelling AI-Generated Content
Subscribe to our newsletter.
Dive into the world of unmatched copywriting mastery, handpicked articles, and insider tips & tricks that elevate your writing game. Subscribe now for your weekly dose of inspiration and expertise.





