Social media and advertising rules
What a UK business must do when it posts, advertises or listens on social media with AI in the loop: the CAP Code and the ASA on AI-made ads and on labelling ads, the CMA's consumer-law backstop, platform rules on labelling AI content, Online Safety Act duties, UK GDPR for social data, and who owns AI-generated work.
Any organisation or sole trader that posts, pays for reach, works with influencers, or runs social listening and customer data through scheduling tools. The ASA's remit covers brand-owned social posts and paid-for ads; consumer law and UK GDPR apply regardless of channel.
Latest check 5 Oct 2026 15 rules · See changes in the Ledger
The rules
How the CAP Code treats AI-generated ads
The CAP Code is media-neutral: if an ad is in the ASA's remit the rules apply however it was made, because the ASA judges ads on how consumers will interpret them. There are no AI-specific rules in the CAP or BCAP Codes, and responsibility stays with the advertiser even when an ad is generated or placed by an automated AI platform.
Verified 5 Oct 2026 · Read the source
Whether AI use in an ad must be disclosed (ASA, 29 May 2025)
There is no general duty to label an ad as AI-made. The ASA's 29 May 2025 article asks two questions: would the audience be misled if AI use is not disclosed, and would a disclosure clarify or contradict the ad's message? A disclosure cannot cure a misleading claim: making a misleading claim and then relying on an AI label to rebut it is against the rules. Making clear that a deepfake or AI influencer is used for comic effect can help avoid a misleading impression.
Verified 5 Oct 2026 · Read the source
AI images, efficacy claims and social responsibility
If AI-generated images are used to show what a product does, they can mislead if they do not accurately reflect its real efficacy. The ASA also warns that generative tools can amplify bias in their training data, so advertisers should sense-check AI imagery against the social responsibility rules. An AI-generated celebrity 'endorsement' real enough to mislead is likely to breach the Code.
Verified 5 Oct 2026 · Read the source
The CAP and CMA influencers' guide (third edition, 23 March 2023)
'Influencers' guide to making clear that ads are ads' was first published by CAP and the CMA on 28 September 2018, with a second edition on 2 February 2020 and the third on 23 March 2023. It covers when content is an ad, affiliate marketing, how to label, visual examples and what happens if content is not disclosed. The ASA and CMA prefer labels that say what the content is: Ad, Advert, Advertising, Advertisement or Ad Feature.
Verified 5 Oct 2026 · Read the source
Meta's 'AI info' label on Facebook, Instagram and Threads (from May 2024)
Announced 5 April 2024 and applied from May 2024: Meta labels a wider range of video, audio and image content when it detects industry-standard AI indicators or when the poster discloses AI-generated content. The label is 'AI info'. From September 2024, content detected as only edited with AI tools carries the label in the post menu rather than on the post itself.
Verified 5 Oct 2026 · Read the source
AI labels on Meta ads (3 February 2025)
Ads created or significantly edited with Meta's own generative AI creative tools carry an 'AI info' label inside the 'About this ad' menu on every ad. Meta also began automatically detecting ads made or edited with third-party AI tools through industry-standard signals and applying the same label.
Verified 5 Oct 2026 · Read the source
TikTok's AI-generated content rules (Content Credentials from May 2024)
TikTok's Community Guidelines require clear labelling when AI or editing realistically depicts people or scenes, and prohibit AI content that misleads on matters of public importance or harms individuals. Content made with TikTok's own AI effects is labelled automatically; for other tools, creators use the 'AI-generated content' toggle or an in-video note. From May 2024 TikTok reads C2PA Content Credentials to auto-label AI content from other platforms, and attaches Content Credentials to TikTok content.
Verified 5 Oct 2026 · Read the source
YouTube's altered or synthetic content disclosure (from 18 March 2024)
Since 18 March 2024 creators must disclose in the upload flow when realistic content (something a viewer could mistake for a real person, place, scene or event) is made with altered or synthetic media, including generative AI. Clearly unrealistic content, animation, special effects and AI used for production help (scripts, ideas, captions) need no disclosure. YouTube may add a label itself where content could mislead.
Verified 5 Oct 2026 · Read the source
YouTube's automatic AI labels (May 2026)
From May 2026 YouTube applies a single, more prominent label for photorealistic, meaningfully AI-altered or generated content: below the player on long-form videos and as an overlay on Shorts. If a creator does not disclose but YouTube's systems detect significant photorealistic AI use, the label is applied automatically. Disclosures are permanent for content made with YouTube's own AI tools or carrying C2PA metadata showing it is fully generative.
Verified 5 Oct 2026 · Read the source
X's synthetic and manipulated media rules and 'Made with AI' (March 2026)
X's synthetic and manipulated media policy lets it label or remove media that is significantly altered or fabricated and likely to deceive or cause harm. On 3 March 2026 X's head of product announced that creators in Revenue Sharing who post AI-generated videos of an armed conflict without a 'made with AI' disclosure are suspended from the programme for 90 days, and permanently for repeat breaches. X's Media Literacy Action Plan (July 2026) describes 'Made with AI' indicators alongside a creator toggle.
Verified 5 Oct 2026 · Read the source
Online Safety Act duties for businesses (illegal content duties from 17 March 2025)
The Online Safety Act 2023 covers user-to-user services with links to the UK: any site or app that lets users share content or interact with each other, however small, including comment sections and community features run by ordinary businesses. Since 17 March 2025 in-scope services must have systems to assess, remove and let users report illegal content. Ofcom can fine up to £18m or 10% of qualifying worldwide revenue, whichever is greater. Posting on someone else's platform does not make you a regulated service.
Verified 5 Oct 2026 · Read the source
UK GDPR and PECR for social listening, targeting and scheduling tools
Names, handles, email addresses and online identifiers gathered through social listening or scheduling tools are personal data. Using them for direct marketing needs a lawful basis (in practice consent or legitimate interests), and people must be told upfront that you are targeting them on social media. An unsolicited direct message with a marketing or affiliate link counts as electronic mail under PECR and usually needs consent. The right to object to direct marketing is absolute.
Verified 5 Oct 2026 · Read the source
Who owns a computer-generated work (CDPA 1988, s9(3))
'In the case of a literary, dramatic, musical or artistic work which is computer-generated, the author shall be taken to be the person by whom the arrangements necessary for the creation of the work are undertaken.' Protection for such works lasts 50 years from creation (s12(7)). Whether a prompt counts as the necessary arrangements, and whether the output is original enough to be protected at all, has not been settled by a UK court.
Verified 5 Oct 2026 · Read the source
The copyright and AI consultation, and where it stands (report of 18 March 2026)
The government consulted on copyright and AI from 17 December 2024 to 25 February 2025, with a text-and-data-mining exception plus rights reservation (opt-out) as its preferred option. Sections 135 and 136 of the Data (Use and Access) Act 2025 required an impact assessment and report, published on 18 March 2026. The report drops the opt-out exception as the preferred option, endorses no alternative, and commits to gather more evidence and monitor international developments. No AI copyright legislation is before Parliament.
Verified 5 Oct 2026 · Read the source
What people get wrong
The five misreadings we see most often, and what follows from them.
The ASA says disclosure cannot cure a misleading message. In April 2026 it upheld complaints against a claims firm whose AI-written '100% Free Service' claim misled, and the firm's explanation that the copy came from AI did not help.
The CAP Code needs the label to be obvious upfront, and since 6 April 2025 hidden advertising is also a banned practice under the DMCC Act, where the CMA can fine up to 10% of global turnover without going to court.
YouTube, TikTok and Meta each require disclosure of realistic AI-altered content and can apply a label automatically. Platform labels do nothing for the CAP Code: an ad still has to be obviously identifiable as an ad and not mislead.
Social handles and profile data are personal data. Unsolicited marketing DMs need consent under PECR, and anyone can object to direct marketing with no exceptions; the Information Commission enforces both.
Section 9(3) gives authorship to whoever made the arrangements, but the courts have not decided whether a prompt is enough or whether the output is original. Check the tool's content-rights terms before building a brand asset on it.
The other five
Knowing the rule is not the same as having a process
Module 31, AI regulation: the EU AI Act and the UK approach, turns these into what you actually need: which rules apply to you, what they require and by when, and the steps to put in place.
This is education, not legal advice. Every rule links to its primary source so you can read the original for yourself.
