All In
Back to blog
allinmedia 18 min read

The EU AI Act Reaches Your LinkedIn Marketing, Even From Ohio

| By Patrick de Carvalho

Contents


I have run LinkedIn campaigns for American clients whose entire go-to-market was Ohio and Texas, and who still had a fifth of their post views coming from Munich, Amsterdam and Warsaw, unplanned, unpaid, unnoticed. On August 2, 2026, the transparency obligations of the EU AI Act's Article 50 became fully applicable. Nobody at those companies checked whether that mattered, because nobody thought a Colorado marketing team, or an Ohio one, had anything to do with Brussels. That assumption is wrong, and this piece explains why, in plain terms, with the actual text of the law and the three other rulebooks a US company has to track: California, Colorado, and the near-total void that is federal AI policy.

In short: The EU AI Act applies to US companies under Article 2(1)(c) whenever the output of an AI system they deploy is used in the Union, regardless of where the company is based. Article 50 requires disclosing AI-generated text on matters of public interest and AI chatbot interactions, unless a named person substantially reviews the content first. California's AI Transparency Act, effective the same day, explicitly excludes text. Colorado's original AI Act no longer exists in the form most compliance guides still describe. The UK has no equivalent law at all.


Why a law you've never heard of already covers your LinkedIn posts

Most American marketing directors read "EU AI Act" and mentally file it under "not my jurisdiction." The text of the regulation disagrees with them.

Article 2, paragraph 1(c) of the AI Act extends its scope to "providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union." A deployer, under Article 3(4), is anyone who uses an AI system under their own authority in a professional context. If your Nashville-based SaaS company runs a ChatGPT-assisted carousel campaign on LinkedIn and that carousel is served to followers in Lyon and Rotterdam, you are, on the plain text, a deployer whose output is used in the Union. Company headquarters, incorporation state, and sales territory do not appear anywhere in that sentence.

I want to be precise about what this does not mean. It does not mean every American small business now answers to a Brussels regulator for every post. It means the trigger is the audience, not the address. A B2B company that genuinely sells only in North America but happens to have European followers, European hires reposting content, or a European distributor sharing its LinkedIn page, meets that trigger far more often than its legal team assumes.

What Article 50 actually requires

Article 50 sets out four separate obligations, two on the companies that build AI tools and two on the companies that use them. LinkedIn marketing teams sit squarely in the second group.

Obligation Who carries it What it means for LinkedIn Applies from
Disclose AI chatbot interactions (§1) Deployer, meaning you Any LinkedIn DM automation or chatbot must make its artificial nature clear before the conversation starts, unless that nature is obvious to a reasonably informed person August 2, 2026
Machine-readable marking of generated content (§2) Provider, meaning the tool vendor You must not strip the watermark or metadata a generative tool embeds in an image or video before you publish it August 2, 2026
Disclose deepfakes and AI text on matters of public interest (§4) Deployer, meaning you An AI-assisted post commenting on regulation, industry trends, or public affairs may need a disclosure, unless it was substantially reviewed by a named person August 2, 2026
Editorial review exemption (§4, second sentence) Deployer, meaning you Where a natural or legal person holds editorial responsibility and reviewed the content, the disclosure duty falls away August 2, 2026

Two things narrow the obligation considerably, and most coverage skips both. First, the public-interest text requirement applies to content that informs the public on matters of public interest, not to every sales post you publish. A carousel selling your Q3 pricing plan is commercial speech, not public-interest journalism. Second, the exemption in the fourth row exists precisely because Brussels anticipated that most professional content involves a human doing real editorial work on top of an AI draft.

The exemption that covers most of what you publish

Article 50 states the exemption as follows: the disclosure obligation does not apply "where the content forms part of a work or programme that is subject to human review or editorial control and where a natural or legal person holds editorial responsibility." No European directive spells out a checklist for what counts as sufficient review, so the working standard used by EU law firms rests on the same two conditions the EU AI Act uses elsewhere: substantial modification of the AI output, and a named person accountable for the final version.

In practice, three habits get you there. Keep the AI draft and the published version somewhere you can retrieve both. Have one person, named, responsible for the post, not a rotating intern queue. And change more than punctuation: reorder a paragraph, cut a claim you cannot back, add a number the model did not have.

None of that is new advice. It is what a competent editor does anyway. The AI Act just turned it into documentation you may eventually need to produce.

What you risk if you ignore it

Article 99 sets penalties for violations of Article 50 at up to €15 million or 3% of worldwide annual turnover, whichever is higher for a large company. For small and medium enterprises, including startups, the regulation applies the lower of the two figures instead of the higher one, an explicit proportionality rule written into the text itself.

What the regulation does not spell out clearly is how a national authority enforces a fine against a company with no EU subsidiary, no EU bank account and no registered agent in the Union. Large-scale AI system providers face an EU authorized representative requirement under a different article. Ordinary deployers, the category most LinkedIn marketing teams fall into, do not. That gap is real, and I am not going to pretend a compliance blog post can resolve it. What I can tell you is what every EU privacy lawyer I have read on this says off the record: enforcement against foreign deployers with no EU footprint starts with complaints, not audits, and complaints usually come from a competitor, a disgruntled customer, or a journalist working a story. Being invisible to regulators is not the same as being exempt from the law.

Back home: no federal law, and a fight over whether states get to write one

There is no federal statute in the United States requiring disclosure of AI-generated marketing content. None. What exists instead is a fight over who gets to write the rules that would fill that gap, and the fight is not settled.

On July 1, 2025, the Senate voted 99 to 1 to strip a ten-year moratorium on state AI regulation from what became known as the "One Big Beautiful Bill," the reconciliation package the administration was pushing through Congress. The amendment, sponsored jointly by Senator Maria Cantwell and Senator Marsha Blackburn, killed the provision after opposition from state attorneys general, governors on both sides of the aisle, and child-safety groups. Ninety-nine senators against one is not a close vote on anything.

The administration tried a different route five months later. On December 11, 2025, an executive order titled "Ensuring a National Policy Framework for Artificial Intelligence" directed the Attorney General to stand up an AI Litigation Task Force within 30 days to challenge state AI laws in court, and directed Commerce to flag "onerous" state statutes within 90 days, with the threat of losing federal broadband funding attached. A narrower legislative attempt, H.R. 5388, introduced by Representative Michael Baumgartner in September 2025, proposes a five-year moratorium on state and local regulation of AI systems in interstate commerce. It sat in subcommittee as this article was written, its outcome unresolved.

The upshot for a marketing director: state laws remain enforceable while the litigation plays out, and there is no telling yet which states will still have functioning AI statutes in eighteen months. That uncertainty is the environment, not a bug in my research.

California regulates AI content, just not your words

California's AI Transparency Act, originally SB 942 and amended by AB 853, became operative on August 2, 2026, the same day as the EU's Article 50, after its original January 1, 2026 date was pushed back. If you read one thing about it, read this: it does not regulate AI-generated text.

Morgan Lewis put it in a single sentence that saves a lot of confused compliance meetings: "By its own terms, CAITA's requirements do not apply to AI-generated textual content." The law covers image, video and audio content only. Covered providers, meaning generative AI systems with more than 1,000,000 monthly visitors or users publicly available in California, must embed latent, machine-readable disclosure carrying the system's name, version and creation date, and must publish a free, publicly accessible detection tool. Visible, on-image labeling stays optional. Penalties run $5,000 per violation, each day counted separately, enforced by the state with no private right of action.

For a US company running LinkedIn image or video ads through a generative tool that qualifies as a covered provider, the practical task is narrow: check that the platform you use maintains its embedded metadata through export, and do not strip it during your own editing pass. Your written posts, captions and articles are untouched by this particular statute.

Colorado's AI Act isn't the law you might remember

If your compliance checklist still says "Colorado AI Act, effective February 2026," it is describing a law that no longer exists in that form.

The original SB24-205, Colorado's 2024 AI Act, would have imposed a duty of reasonable care on developers and deployers of high-risk AI systems, tied to an impact-assessment regime, with an effective date of February 1, 2026. Governor Jared Polis signed SB25B-004 during a special legislative session on August 28, 2025, pushing that date to June 30, 2026. Lawmakers used the extra time to rewrite the law rather than implement it: on May 14, 2026, Polis signed SB26-189, which repeals and reenacts SB24-205 outright as the Colorado Automated Decision-Making Technology Act, narrows its scope to "consequential decisions" in employment, housing, credit, insurance, healthcare and education, drops the original duty-of-care and impact-assessment framework, and sets a new effective date of January 1, 2027 for developer documentation requirements.

Two consequences for a LinkedIn marketing team. First, general marketing content and ordinary social posts sit outside the consequential-decisions scope; the law was never really about your carousels, and it is even less so now. Second, if your business uses AI to screen job applicants who found you through a LinkedIn recruiting campaign, that is precisely the category SB26-189 targets, and the January 2027 date applies to you directly.

The United Kingdom: nothing on the books, yet

There is no UK statute requiring you to label AI-generated content in 2026. The Department for Science, Innovation and Technology lists content labeling among four priority areas in its AI policy work, without a published timetable, according to the House of Commons Library's 2026 research briefing on the subject.

What came out of the UK's own consultation process is worth more than the absent law. Respondents explicitly distinguished wholly AI-generated content from AI-assisted work, the same distinction that determines whether Article 50's exemption applies in the EU. A consultation with no statutory force reasoned about the underlying question more carefully than most compliance vendors selling detection software.

Four jurisdictions, one table

Put the four frameworks side by side and the pattern is not subtle. Two lawmaking bodies wrote rules around who is accountable for content. One wrote rules around what a machine embeds in a file. One wrote nothing.

EU AI Act, art. 50 California CAITA Colorado ADMT Act United Kingdom
Covers AI-written marketing text? Yes, for public-interest content No, explicitly excluded No, scoped to consequential decisions No statute
What triggers the obligation Output used in the Union 1,000,000+ monthly CA users, image/video/audio Consequential decisions (employment, credit, housing) n/a
Editorial review exemption Yes, named person + substantial review n/a n/a Recognized in consultation, not codified
Penalty €15M or 3% of turnover (higher for large firms, lower for SMEs) $5,000 per violation, per day Enforced as deceptive trade practice n/a
Status as of August 2026 In force In force Effective January 1, 2027 No timetable

What to do before August 2, concretely

All In uses a five-step framework for this, C.L.A.I.R., built for the French version of this compliance conversation and just as usable here: Catalog, Label, Audit, Instruct, Review.

Catalog every AI tool that touches anything a European follower might see: post drafting, image generation, DM automation, ad copy. Label by exception, not by default. Decide which content categories genuinely fall under a public-interest reading of Article 50, and stop worrying about the rest. Audit your editorial chain: who reviews AI drafts, and can you show it. A shared spreadsheet with the prompt, the raw output, the published version and the reviewer's name is enough; the sophistication of the system matters less than whether anyone actually uses it. Instruct whoever runs your chatbot or DM automation to add a one-line disclosure before the conversation starts. Review quarterly, because Colorado just proved a state can rewrite its entire AI law twice in eighteen months, and the EU's own high-risk chapter already slipped by more than a year through the July 2026 Digital Omnibus. Our full breakdown of that framework lives on All In's methods page.

Set this against the day-to-day discipline that keeps a post out of trouble regardless of jurisdiction: a proprietary number nobody else has, a dated and located example, a position you are willing to defend under your own name. That is also the argument at the center of our reporting on LinkedIn's own AI-detection button: the reader, and increasingly the regulator, cares less about which tool touched your draft than about whether a real person stands behind what got published.

What I don't know

I do not know the enforcement mechanism a national EU authority would actually use against a company with nothing on this side of the Atlantic for a judgment to attach to. The regulation is silent on that point for ordinary deployers. I do not know whether "output used in the Union" will be read narrowly, as paid advertising deliberately targeted at EU users, or broadly, as any organic reach into EU inboxes and feeds; no enforcement action has tested that question yet. I do not know the fate of H.R. 5388, still parked in subcommittee at the time I researched this piece. I do not know whether Colorado's January 2027 date holds, given that the state has already moved it twice. If any of these resolve before your compliance review, that resolution belongs in your notes, not in mine.

The deadline doesn't check your zip code

The four frameworks in this piece agree on almost nothing, except one thing worth sitting with: every serious one of them, EU included, gives you a way out through honest human review. None of them punishes AI assistance. They punish content nobody stands behind.

A US company that documents who wrote what, keeps a name attached to every published post, and treats "substantially reviewed" as a real practice rather than a checkbox satisfies the spirit of Article 50 whether or not a European regulator ever looks its way. That posture also happens to be the only one that survives whichever version of Colorado's law, or California's, or a future federal statute, shows up next.

FAQ

Does the EU AI Act apply to a US company that has never sold anything in Europe?

Potentially, yes. Article 2(1)(c) extends the regulation to deployers based in third countries whenever the output of an AI system they use is served to users in the Union, regardless of sales activity there. A company with European followers, employees or partners sharing AI-assisted LinkedIn content can meet this trigger without ever invoicing a European customer.

What exactly do I have to label under Article 50?

Two categories: AI chatbots or DM automation that interact with users without disclosing their artificial nature, and AI-generated or manipulated text published to inform the public on matters of public interest. Routine commercial posts, product updates and sales content generally fall outside the public-interest category.

Does the human editorial review exemption cover a LinkedIn post I wrote with ChatGPT?

It can, if a named person substantially reviewed and modified the draft and holds editorial responsibility for the final version. Simply clicking publish on an unedited draft does not qualify. Keeping the raw AI output, the edited version and the reviewer's name on file is the practical way to demonstrate it.

What are the penalties, and will a US company actually face them?

Article 99 sets fines up to €15 million or 3% of global turnover for Article 50 violations, with the lower figure applied to SMEs. Whether a US company with no EU establishment will actually be pursued is genuinely unclear; the regulation does not detail an enforcement mechanism against foreign deployers with no EU footprint, and no such case has been reported as of this writing.

Is there a federal US law that requires AI content disclosure?

No. Congress has not passed one, and a July 2025 Senate vote of 99 to 1 removed a proposed ten-year moratorium on state AI regulation from a federal budget bill. A December 2025 executive order directs federal agencies to challenge state AI laws in court, but that litigation remained unresolved at the time of writing, and state laws stay enforceable in the meantime.

Does the Colorado AI Act still apply in 2026?

Not in its original form. SB24-205, the 2024 Colorado AI Act, was delayed twice and then repealed and reenacted as the Colorado Automated Decision-Making Technology Act on May 14, 2026, with a narrower scope limited to consequential decisions like employment and credit, effective January 1, 2027.

Do I need to label AI-generated images the same way as AI-generated text?

No, and the rules differ by jurisdiction. California's AI Transparency Act covers images, video and audio but explicitly excludes text. The EU AI Act's Article 50 covers marking for generated media under a separate provision from the one covering public-interest text, with different technical requirements for each.

Sources

  1. European Union, Regulation (EU) 2024/1689, Article 2: Scope, artificialintelligenceact.eu. https://artificialintelligenceact.eu/article/2/
  2. European Union, Regulation (EU) 2024/1689, Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems, artificialintelligenceact.eu. https://artificialintelligenceact.eu/article/50/
  3. European Union, Regulation (EU) 2024/1689, Article 99: Penalties, artificialintelligenceact.eu. https://artificialintelligenceact.eu/article/99/
  4. EUR-Lex, Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus), postponing the AI Act's high-risk chapter. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  5. Morgan Lewis, California AI Transparency Act guidance, August 2026, on CAITA's exclusion of AI-generated text.
  6. Colorado General Assembly, SB25B-004, Transparency for Algorithmic Systems, signed August 28, 2025. https://leg.colorado.gov/bills/sb25b-004
  7. Colorado General Assembly, SB26-189, Automated Decision-Making Technology, signed May 14, 2026. https://leg.colorado.gov/bills/sb26-189
  8. Congress.gov, H.R. 5388, American Artificial Intelligence Leadership and Uniformity Act, introduced September 16, 2025. https://www.congress.gov/bill/119th-congress/house-bill/5388
  9. The White House, Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, December 11, 2025. https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/
  10. Reuters, "US Senate strikes AI regulation ban from Trump megabill," July 1, 2025. https://www.reuters.com/legal/government/us-senate-strikes-ai-regulation-ban-trump-megabill-2025-07-01/
  11. House of Commons Library, research briefing CBP-10467, 2026, on UK AI content labeling policy.
  12. All In, editorial disclosure and AI-use policy. https://media-all.in/en/about

All In: compliance that survives the next rewrite, not just this one

Colorado rewrote its AI law twice in eighteen months. The EU pushed back its own high-risk chapter by a year. The rules a marketing team can actually rely on are the ones that do not depend on which version of which statute is current: a named author, a documented review, a claim that holds up under your own name.

All In is the B2B media that decodes LinkedIn, expert blog, weekly podcast and newsletter for SME leaders and sales directors who want to turn LinkedIn into measurable growth. An original creation by Patrick de Carvalho, on LinkedIn since 2004. Motto: "I Never Lose."

Discover All In and get what matters on LinkedIn, every week.