AI Writes Marketing Copy Fast — But It Backfires Even Faster. Five Legal Pitfalls, Each Already Drawing Real Fines
A while back, I read a piece of news that made me genuinely uncomfortable.

A while back, I read a piece of news that made me genuinely uncomfortable.
Coca-Cola put out an AI-assisted holiday ad. By all rights, a century-old brand doing holiday marketing should be a safe bet. The result? Consumers hated it. The creative industry hated it. And the one word at the heart of every complaint was the same: fake.
Not long after, Valentino took a swing at it. Luxury sells "craftsmanship, heritage, the human hand." They used AI to produce a set of surreal visuals. The entire internet converged on the same word: tacky.
Strange, isn't it. Put the two side by side and one thing becomes obvious: AI is a blade marketers swing easily — but the moment it cuts, that thick legal book sitting next to it opens at the very same time.
Copyright. Data protection. Ad compliance. Consumer rights. Online safety. Not one of them is idle.
I dug this back up recently and thought it through again. The more I think about it, the clearer it becomes: this is far more serious than a "PR crisis." Let me walk you through five pitfalls, piece by piece — and every single one has already cost somebody real money in penalties.
Pitfall One: What You Wrote Might Not Actually Be Yours
What does copyright risk mean?
It means the image AI generated, the copy it produced — they look like things you "made." But the raw materials may well have been stolen from someone else.
How is generative AI trained? You feed it a mountain of data. How much of that data is licensed? How much was scraped? A lot of the vendors themselves can't tell you.
You think that's the end of it? No.
There's a case still working its way through the UK courts. Getty Images is suing Stability AI. The claim boils down to two things: first, you trained your model on my images without paying; second, what your model spits out looks way too much like my work.
Think about what that means.
It means the risk comes in two layers. One at the training stage, another at the output stage. You buy an AI tool from some vendor, generate an image, put it on your website — you think it's a marketing asset, but the plaintiff's cease-and-desist letter is already half-written.
How do you dodge it?
- Don't procure blind. Before you buy, ask the AI vendor where the training data comes from and whether it's licensed.
- Add a clause to the contract: if a copyright issue blows up, the AI vendor pays.
- Run a human review before publishing. Anything that looks even close to a known IP — delete it immediately.
Pitfall Two: You Feed User Data to AI, the User Takes You to Court
Data protection might be the single easiest place for a marketer to step on a landmine.
Why?
Because the core moves of AI marketing — user profiling, behavioral targeting, personalized recommendations — every one of them processes "personal data." And here in the UK, the UK GDPR and the Data Protection Act 2018 are genuinely enforced. They are not for show.
Let me give you the latest.
In February 2026, the UK Information Commissioner's Office (ICO) issued a fine. Who got hit? MediaLab. You probably haven't heard of the company, but there's a good chance you've used one of its products: Imgur, the veteran image-sharing platform.
Why the fine? Because for years it had been processing children's personal data without doing age verification. Years.
What does "years" mean? It means this wasn't a hole that suddenly appeared one day — it was a hole left unplugged, year after year, with nobody minding it.
The ICO was blunt about it: if children's data can flow through your product, you'd better have the corresponding protections in place. That's not advice. That's a requirement.
So what does this mean for marketers, concretely?
- Before you deploy any AI marketing tool, run a DPIA (Data Protection Impact Assessment).
- Before you build user profiles or targeted ads, ask yourself one question: do I have a lawful basis for this?
- Data minimization, transparency, human review — these three things are not optional. Skip none of them.
Pitfall Three: You Say "I Didn't Deceive Anyone — AI Wrote It." The Regulator Disagrees.
A lot of people carry a misconception: "As long as I label it AI-generated, I'm off the hook if the ad goes wrong."
Wrong.
The UK's advertising codes (the CAP and BCAP Codes — the UK's rulebooks for advertising) are technology-neutral. What does that mean? It means whether a human wrote it or a machine did — deceptive is deceptive.
Picture this scene: a cosmetics brand uses AI to generate a model's "before-and-after" comparison photo. The retouching is aggressive. Skin smoothed to a filter-like glaze, wrinkles vanishing in a single second. Then, in tiny type on the product page, a line reads: "This image was created with the assistance of AI."
What does the regulator do when it sees that?
The answer: your labeling is your labeling, and misleading is misleading. The fine still lands.
The ASA (Advertising Standards Authority) has been busy with exactly this kind of thing lately. An in-game ad for an AI photo-retouching app was banned outright — for sexualizing women, being harmful, and being irresponsible. There are other cases too, pulled down for "causing serious or widespread offense."
So what should marketers do? It really comes down to three things:
- Hold AI-written content to the exact same standard as human-written content for fact-checking and effect verification.
- Stand in the consumer's shoes for a moment and ask: if I don't label this as AI, will they be misled? If yes, label it. If no, at least keep an internal record.
- Don't cut corners. Internal approval workflows, legal review — none of it is optional.
Pitfall Four: Deepfakes Are Already a Criminal Offense
This pitfall is weightier than the previous three.
What's a deepfake? It's using AI to generate a real person's face, voice, or video. It looks identical to the real thing.
Why do I say weightier? Because in early 2026 the UK government confirmed something: sharing, or threatening to share, non-consensual intimate deepfake imagery constitutes a criminal offense under the Online Safety framework (the UK's online-harms legislation).
Criminal. Not civil damages — the kind where someone shows up at your door to arrest you.
And it's not just the UK moving. Law enforcement across Europe is also investigating AI systems built specifically to generate harmful sexualized imagery. Cross-border enforcement is already running.
What does this mean for marketers?
Simply put: don't touch real people's faces.
- If any AI-generated marketing material features a recognizable, specific individual, you must obtain that person's explicit consent first. Zero wiggle room.
- Build an internal content review and escalation mechanism. When something goes wrong, you can locate it and pull it down immediately.
- Train the team. Every person on the marketing team needs to know where the red lines are on defamation, harassment, and online safety law.
Pitfall Five: Even If You Didn't Break the Law, You Can Still Lose the Public's Trust
The last pitfall is the most hidden — and the hardest to defend against.
The law is one line; ethics is another. And the ethics line sits much lower than the legal one. Plenty of things aren't illegal, but the moment consumers feel they've been "gamed," your brand is finished.
Deepfakes now circulate at a volume of millions per year, globally. What does a number like that mean? It means public vigilance is rising. It means any marketing move that "looks like AI manipulation" will be examined under a magnifying glass.
Regulation is shifting too. It used to ask whether a specific rule had been broken; now it increasingly looks at "overall fairness and transparency." In other words, even if you successfully exploit a legal loophole, consumer protection law and the fair-trading regime will still come knocking. And even if there's no fine, your reputation doesn't come back.
How do you fill this pitfall?
- Build an AI governance framework inside the company. Align it with the regulator's expectations — not with "how much more cost can we squeeze out."
- Run fairness and bias testing before launch. Is the AI serving discriminatory content to certain groups?
- Give consumers a clear channel to be informed, and a clear channel to complain.
A Few Final Words
After working through these five pitfalls, what's my biggest takeaway?
AI in marketing isn't a technology problem — it's a governance problem.
Technology problems, you buy a tool and they're solved. Governance problems require changing processes, contracts, people, and the organization.
Here in the UK, copyright lawsuits are working through the courts, the ICO is issuing fines, the ASA is banning ads, and deepfakes have entered criminal law. These are all happening right now, in 2026 — not on some future day "when regulation catches up." Regulation has already caught up. In many cases, it's running faster than the marketing teams.
So my advice is simple: don't wait. Today, take compliance out of the legal team's hands and put it on the marketing lead's desk. Contractual indemnity clauses, data protection assessments, content review, ethics oversight — these four things, start whichever one you want. The point is to start.
Early movers reap the upside. Late movers pay the tuition.