TL;DR There is no 2027 disclosure regime. The rule that will decide whether a sponsored citation is lawful is one sentence drafted for a 2005 European directive, transposed into UK law on 26 May 2008 and re-enacted word for word on 6 April 2025. It requires that a payment be made clear in the content or by images or sounds clearly identifiable by the consumer. Content, images, sounds. An HTML attribute is none of the three — so the disclosure the link building industry actually ships, rel=”sponsored”, is addressed to a crawler and satisfies a search engine’s guidelines while doing nothing at all for consumer protection law. Because every trigger in the regime is a gap between what a reader believes about why a sentence reached them and why it really did, the duty is heaviest where the payment is least visible: a labelled sponsored answer card is the safest paid surface in the AI stack, and a bought slot in a third-party roundup that an engine paraphrases into an unattributed recommendation is the most dangerous. This piece gives you THE ADDRESSEE MAP, THE EXPECTATION GAP TEST and THE CARRIED-DISCLOSURE RULE, corrects the penalty figure the field keeps quoting, and explains why the tougher jurisdiction for a UK programme is now home rather than Washington.
Something changed in the UK on 11 August 2026 that almost nobody in link building noticed. OpenAI extended its advertising pilot to Britain, Mexico, Brazil, Japan and South Korea. Until that date, the paid layer of the answer economy was a story about somebody else’s market. From that date, a British consumer asking a British question can receive a British brand’s sponsored recommendation, and every UK advertising rule that has ever applied to a paid message applies to it.
The interesting consequence is not the one the trade press covered. Sponsored answer cards arrive with a label, a visual separation and a compliance department behind them. The exposure sits somewhere else entirely: in the third-party pages you have been buying for years, which now feed the unlabelled half of the same screen.
1. There is no 2027 regime, and that is exactly the problem
Every few months a compliance post announces a coming reckoning — new AI advertising rules, a 2027 regime, a disclosure standard for generative answers.
What are the AI ad disclosure rules in 2026?
There are none that are specific to AI. The rules that govern a sponsored citation are the general advertising-disclosure rules, and they are technology-neutral by design. In the UK the Advertising Standards Authority has said so directly: its Codes contain no AI-specific rules, and the existing rules apply regardless of how content is generated, edited or targeted. There is no blanket UK requirement to disclose the use of AI in an ad at all. The labelling regimes that do exist — AI-content labelling schemes, and the EU AI Act content rules — answer whether something was made by a machine, not whether it was paid for.
Four instruments carry the whole load, and all four predate generative search:
- Schedule 20, paragraph 12 of the Digital Markets, Competition and Consumers Act 2024 (the DMCC Act, the UK’s consumer-protection statute), in force 6 April 2025: using editorial content in the media to promote a product where a trader has paid for the promotion, without making that clear in the content or by images or sounds clearly identifiable by the consumer.
- Section 2 of the CAP Code (the UK non-broadcast advertising rulebook), which requires marketing communications to be obviously identifiable as such — and, at rule 2.4, requires advertisement features to be recognisable as advertising even though they are designed to look like editorial.
- Section 5 of the US Federal Trade Commission Act, which prohibits practices likely to deceive a reasonable consumer, and the Endorsement Guides at 16 CFR Part 255, which require clear and conspicuous disclosure of a material connection the audience would not reasonably expect.
- Annex I, point 11 of the Unfair Commercial Practices Directive — the European original from 2005, from which the British sentence is copied.
The eighteen-year sentence
Here is the detail that reframes the whole conversation. The advertorial prohibition entered UK law as paragraph 11 of Schedule 1 to the Consumer Protection from Unfair Trading Regulations 2008, in force from 26 May 2008. On 6 April 2025 the DMCC Act repealed those Regulations and re-enacted the provision as paragraph 12 of Schedule 20. The wording is identical, clause for clause, with one edit: the 2008 version ended with the parenthetical label (advertorial), and the 2024 Act dropped it.
Parliament kept the rule and deleted the format name. That is not a drafting accident; it is what technology-neutral legislation looks like when the format it was named after stops being the main way the practice happens. The banned thing was never the magazine spread. It was the concealment.
Key takeaway. What arrives in 2027 is not a rule. It is penalty and jurisdiction. The European Commission’s Digital Fairness Act — the initiative most often cited as the coming regime — is scheduled as a Q4 2026 proposal, with Parliament and Council negotiation through 2027 and staggered application expected between 2028 and 2030. Nothing in it will bind a placement you buy next quarter. The sentence that will is already twenty-one years old.
2. The five words that decide everything
Read paragraph 12 again and notice where the operative test sits. The payment must be made clear in the content or by images or sounds clearly identifiable by the consumer. The statute does not say “disclosed”. It does not say “declared”. It names three carriers — content, images, sounds — and one addressee: the consumer.
Does rel=”sponsored” count as a disclosure?
No, and it never did. The rel=”sponsored” attribute (a machine-readable flag telling a crawler that a link was paid for) was introduced by Google in September 2019 alongside rel=”ugc”, extending a convention that began with rel=”nofollow” in 2005. It is a statement to a search engine about how to treat a backlink in a link graph. It is not text, not an image and not a sound. It is invisible to every consumer who has ever read the page.
This matters more than it sounds, because the attribute is the industry’s entire disclosure practice. Ask an agency how it handles paid placements and you will hear that the links are marked correctly. Marked correctly for whom? Google’s link-spam guidelines are satisfied — that is a real and useful compliance act, and it keeps the placement out of the territory where paid links get treated as spam. But a search engine and a consumer-protection regulator are asking different questions, of different readers, with different remedies. One can demote a page. The other can prosecute a company.
There is an unflattering symmetry here. When researchers ran the first large observational study of ChatGPT advertising, collecting 3,602 confirmed ad impressions across 48 accounts during the March 2026 rollout, they identified the ads by reading the Sponsored label in the page HTML. The platform’s disclosure is legible to a machine and to a person, because it is rendered as text next to the thing it qualifies. Yours is legible to the machine only.
Two regulators, two addressees, two remedies
Almost every mistake in this area comes from collapsing two compliance systems into one. Search-engine guidelines are private rules about ranking, enforced by algorithmic and manual action against a domain. Consumer-protection law is public rules about deception, enforced against a trader by a regulator or a court. A paid placement can be perfectly compliant with the first and a strict liability offence under the second, and the field has spent fifteen years optimising for the first because it is the one that shows up in a rank tracker.
The corollary is worth stating plainly: passing a competitor backlink analysis cleanly, or surviving a core update, tells you nothing about your position under paragraph 12. Those are different examinations.
3. THE ADDRESSEE MAP
If the legal test is whether a named reader can perceive the commercial connection, then every disclosure device you might use can be sorted by who can actually read it.
| Disclosure device | Who can read it | Which regime it satisfies | Survives extraction into an answer? |
| rel=”sponsored” attributes | Crawlers only | Search-engine link guidelines only | No — an attribute is not text |
| Structured data / metadata | Crawlers only | None. No vocabulary in wide use has a property for a commercial relationship | No |
| “#ad” at the end of a caption or paragraph | Consumers who read to the end | Weak. The ASA repeatedly finds buried labels insufficient | No — usually outside the retrieved passage |
| “Advertisement feature” banner | Consumers, visually | CAP 2.4 and para 12, if genuinely prominent | No — page furniture is stripped before the claim is read |
| Platform ad label on a sponsored answer card | Consumers and crawlers | All of them, and the platform owns the duty | Not applicable — re-rendered on every impression |
| Standfirst or byline line naming the payer in prose | Consumers and models | Para 12 (“in the content”), CAP 2.1 | Sometimes — only if it sits in the retrieved chunk |
| The payer named inside the claim | Consumers and models | All of them | Yes — it cannot be separated from the sentence |
Two rows survive both readers unconditionally, and one of them is not yours to build. The platform label works because the platform re-renders it every time the ad is served; you cannot borrow that property, because your placement is fetched once and paraphrased afterwards. Which leaves exactly one device you control that reaches both addressees: the payer named inside the claim itself.
Notice what falls into the red band. Every disclosure the industry has standardised on is either a machine-only declaration or a piece of page furniture. Once a citation set gets assembled from extracted passages, furniture and attributes are the two things guaranteed not to travel. The same limit binds every other machine-only mark, from provenance signatures applied to links to the difference between signed and unsigned content.
4. Why the duty is heaviest where the payment is least visible
Look at what the four instruments are actually measuring. Section 5 asks whether a practice is likely to deceive a reasonable consumer. The Endorsement Guides require disclosure of a material connection the audience would not reasonably expect. CAP rule 2.1 asks whether a communication is obviously identifiable as marketing. Paragraph 12 asks whether the payment was made clear.
None of them regulates money. All four regulate a gap between what the audience believes about why a message reached them and why it really did. Payment is the fact that creates the gap; the gap is the violation. This is why the same £2,000 can be entirely lawful in one channel and a criminal offence in another with no change to the invoice.
The sponsored answer card is the safe one
Run that test across the surfaces available to a 2027 programme and the ranking inverts everything the field assumes. A sponsored recommendation on ChatGPT sits in a demarcated block beneath the answer, carries a Sponsored label, is visually separated from the generated text, and comes with a “why am I seeing this ad” affordance. The expectation gap is close to zero, and — decisively — the duty to maintain the label belongs to the platform, which re-serves it on every impression.
Now take a bought slot in a third-party “best supplier in Britain” roundup: a paid guest placement, a niche edit into an existing ranking page, or a line inserted into a comparison table. An engine retrieves that page, extracts the sentence about you, and emits it as one of three or four independent-looking sources by the same retrieval path through which backlinks feed AI Overviews. The reader’s account of why that sentence reached them is “a publication assessed the market and named them”. That account is false. And it is false in the direction that changes the weight the reader puts on it, which is the legal definition of the problem.
Key takeaway. The safest paid surface in the AI answer stack is the one that looks most like an advertisement. The most exposed is the one that looks most like earned coverage. The field’s prospecting sheets are optimised to maximise exactly the second property — every brief that asks for placements which “read as editorial” is a brief to widen the expectation gap.
Who is liable when an AI answer repeats a paid claim?
The advertiser, first and most reliably. UK and US enforcement both attach the duty to the trader who benefits from the promotion, not only to whoever pressed publish — the ASA treats a brand as at least jointly responsible for affiliate content regardless of whether it knew about or controlled the specific item, and paragraph 12 bites on the trader who paid. Publishers carry their own exposure: under the CAP Code, responsibility for advertisement features falls on marketer and publisher.
The engine is the party with the least exposure and the most control, which is an uncomfortable but stable arrangement. It did not take the money, it did not write the sentence, and in the UK the ASA’s remit does not extend to output that is not in paid space or under a marketer’s control. Waiting for the platform layer to solve this is not a strategy. The document you paid for is the artefact a regulator can read, and it has your name on the invoice.
5. THE EXPECTATION GAP TEST
If the violation is a belief gap, then the audit runs on beliefs, not contracts. Take one placement and ask three questions in order. Ask them about the sentence a stranger will read, never about the deal you signed.
THE EXPECTATION GAP TEST
Q1 — The account. Stop the reader immediately after the sentence and ask: why do you think this page says that about them? Write down the most likely answer in the reader’s own words.
Q2 — The truth. Is that answer correct? Not defensible, not arguable — correct.
Q3 — The materiality. If the reader learned the real answer, would it change the weight they put on the sentence? If it would not, there is no consumer harm to disclose.
Band A — No gap. The reader’s account is right. An ad in an ad slot; a placement whose text names the payer. Nothing owed.
Band B — Closed gap. A gap exists, and the correction sits inside the passage a reader or a model actually retrieves. Nothing owed at the point of reading.
Band C — Open gap, immaterial. The connection is real but would not move the reader — a conference sponsorship named on a delegate list, a supplier credit in a technical appendix. Document it; do not label it.
Band D — Open gap, material. The reader’s account is wrong and the truth would move them. This is the only band that is a legal problem — and it is the band a placement brief written for maximum editorial resemblance is designed to produce.
The test is answerable without a lawyer, and it produces a number you can put in a board pack — the share of your live placements sitting in Band D. In most programmes that share is far higher than anyone has ever counted, because nobody has been counting it.
Run it across a full quarter and the output doubles as a procurement brief. Band D placements are not simply risky; they are the ones whose value depends on a false belief, which means their value is contingent on the belief surviving. That is a different kind of asset from the one your 2026 benchmarks assume you are buying.
6. What the penalty numbers actually say
The figure that circulates in every AI-disclosure post is $53,088 per violation. It is a real number, it is current, and it is almost always applied to the wrong thing.
The correction
$53,088 is the maximum civil penalty under sections 5(l), 5(m)(1)(A) and 5(m)(1)(B) of the FTC Act. Those provisions bite on violations of a final Commission order, or of a trade regulation rule. The Endorsement Guides are not a rule. They are administrative interpretations — guidance on how the Commission reads section 5 — and breaching them carries no civil penalty of itself. The FTC’s route against an undisclosed sponsored citation runs through section 5 deception, and since AMG Capital Management v FTC (2021) removed monetary relief under section 13(b), the realistic first-instance outcome is an order rather than a cheque. The penalty arrives on the second offence.
And $53,088 is the 2025 figure. It is still current in 2026 not because it was reaffirmed but because the annual inflation adjustment was cancelled: the October 2025 CPI-U was never produced during the appropriations lapse that ran from 1 October to 12 November 2025, the statutory formula has no fallback, and OMB Memorandum M-26-11 of 17 April 2026 cancelled the 2026 adjustment across the federal government. The penalty for concealing a payment is frozen because a price index went unpublished.
Why the UK is now the harder jurisdiction
Set the American picture — guidance, an order first, penalties later — against the British one. Paragraph 12 is a criminal offence. It is a strict liability offence, meaning the trader’s state of mind at the time is irrelevant; there is a due diligence defence, but no requirement for the prosecution to show you intended to conceal anything. Trading Standards can prosecute in the criminal courts.
And since 6 April 2025 the Competition and Markets Authority can decide for itself that consumer law has been broken and impose a penalty directly, without going to court, up to the higher of 10% of global annual turnover or £300,000. It used those powers for the first time on 18 November 2025 against eight companies, alongside advisory letters to a hundred more. In April 2026 it issued its first substantive fine — over £4 million against the AA for drip pricing — concluding the investigation in roughly five months, with a 97% proportionality reduction and a 40% settlement discount already applied. By 23 June 2026 the CMA reported more than £5 million in fines and £1.95 million in consumer refunds, fourteen investigations opened in the first year, 157 advisory and warning letters and 46 information notices.
A UK-facing programme has been holding its compliance conversation in the wrong hemisphere. The instrument with criminal liability, strict liability, turnover-linked penalties and a regulator that no longer needs a judge is the domestic one.
7. THE CARRIED-DISCLOSURE RULE
If exactly one device reaches both addressees, the operational question is how to build it. The distinction that matters is grammatical rather than visual, and it sorts into three tiers.
THE CARRIED-DISCLOSURE RULE
Adjacent. The disclosure sits near the claim — a badge, a banner, a coloured strip, a note at the foot. Delete it and the claim reads perfectly. It travels nowhere.
Attached. The disclosure is a separate sentence in the same paragraph as the claim. Delete it and the claim still reads. It travels sometimes, depending on where the passage boundary falls.
Carried. The payer is a noun phrase inside the claim: “in bench testing commissioned by Marrable & Fen”, “according to the manufacturer’s own durability trial”. Delete it and the sentence is ungrammatical or unsourced.
The rule: name the payer as the subject of the claim or as the qualifier of its evidence — never as a label beside it. The test is whether the sentence survives the deletion. If it does, the disclosure was decoration.
Here is the part that surprises people who assume disclosure suppresses citation. A carried disclosure adds an attributive noun phrase to the sentence, and attribution is one of the things extraction preserves best — the evidence on paraphrase behaviour consistently shows that named sources and numbers survive summarisation while voice and narrative do not. A claim reading “independent testing shows” is weaker material for an answer engine than one reading “testing commissioned by the manufacturer shows”, because the second is a complete, checkable proposition and the first is an orphan.
This is not a claim that disclosed placements get cited at the same rate as concealed ones. Nobody has run that experiment, and I am not going to pretend the result. It is a claim about mechanism: the thing you must add for legal reasons happens to be the thing the extraction layer is built to keep. That alignment is rare enough to be worth using.
It also changes what you ask a publisher for. “Can you mark the link as sponsored” is the wrong request — it is free for them and worthless to you. “Can the sentence name who paid for the test” is a request about copy, which means it goes to an editor rather than to the technical team that implements links, and it is the version that both satisfies paragraph 12 and survives the trip into a deep research report.
8. The strongest objection: nobody is enforcing this
The honest counter-argument is not that the law is unclear. It is that the law is clear and inert.
The paid placement market has operated in plain sight for fifteen years in every jurisdiction with an advertorial prohibition, and the enforcement record against it is close to empty. The CMA’s first year under its new powers went to drip pricing, fake and misleading reviews, and online choice architecture — not one of the fourteen investigations concerned paragraph 12. The ASA’s disclosure enforcement is overwhelmingly about influencer captions on Instagram and TikTok, not business-to-business comparison articles. The FTC needs an order before it can fine anybody. A rational operator looking at expected cost would conclude that the probability of enforcement multiplied by the penalty is smaller than the cost of asking publishers to change copy, and would carry on as before.
That objection is correct on today’s evidence, and I am conceding it rather than answering it. The exposure described in this piece is latent, not demonstrated. Three things bound it.
- The baseline moves against you without you acting. The trigger is what a reader reasonably expects. As labelled sponsored blocks become ordinary on the answer surface — already appearing on around half of US free-tier replies by mid-2026 — a reader’s confidence that an unlabelled recommendation is independent goes up, not down, and in a zero-click session there is nothing else to check it against. The gap on your existing placements widens while the placements sit still.
- Enforcement follows attention, and attention follows the money. A regulator’s docket is a resource ordering, not a legal one. The moment a paid answer surface exists in a jurisdiction — the UK, as of 11 August 2026 — the regulator acquires a reason to ask what the unpaid-looking half of the same screen is made of. The CMA’s first-year priorities tracked complaint volume; complaint volume in this category has been zero because consumers cannot see the practice, which is the practice working as designed rather than evidence it is permitted.
- The remedy costs one noun phrase. This is the rare compliance obligation whose price is a rewrite rather than a workflow, a vendor or a headcount. Even at a low probability of enforcement, refusing a near-zero-cost fix is not a considered risk position, it is an unexamined one.
Two honest negatives
First, asking for a carried disclosure will cost you placements. A meaningful part of the paid-placement market is selling precisely the absence of the label; that is the product. Some publishers will decline, and the ones most likely to decline are often the ones with the strongest retrieval footprint. That is a real loss, not a rounding error, and any plan that pretends otherwise will fail on contact with a media list.
Second, the regime is consumer-facing. Paragraph 12, the CMA’s direct enforcement powers and section 5 all protect consumers, so a purely business-to-business programme has a genuinely narrower exposure than a consumer one. Narrower is not nil — the Business Protection from Misleading Marketing Regulations 2008 cover business-to-business misleading advertising, and the CAP Code applies to business audiences too — but anyone selling enterprise software to procurement teams should discount the risk described here rather than adopt it wholesale. Overstating this would be its own kind of misleading claim.
9. What this does to a 2027 acquisition plan
The practical effect is not a compliance programme. It is a change in the unit cost of a bought placement, and therefore a change in what link building is actually buying.
Purchasing a placement in 2027 means purchasing a placement plus a disclosure that has to travel with the claim through an unbounded number of downstream emissions you neither control nor can recall. A genuinely earned placement carries no such obligation, because the honest answer to “what was the material connection?” is that there wasn’t one. That is not a moral observation. It is the only line item in an acquisition plan that gets cheaper as enforcement gets tougher — the practical form of the authenticity premium — and it belongs in the same column as the durability arguments that already govern how a strategy set is chosen.
Marrable & Fen: a worked example
Marrable & Fen is a Bristol direct-to-consumer sleep brand, £14.2M revenue, selling mattresses and bedding almost entirely online. In January 2026 it ran an £11,000-a-month retainer producing roughly 22 placements a quarter in “best mattress UK” roundups. Fourteen of the 22 were paid, at an average of £1,850 each described on the invoice as an editorial fee. All 22 links were marked rel=”sponsored”. The agency’s quarterly deck reported the programme as fully compliant.
In April 2026 the marketing director ran the Expectation Gap Test across all 22. Eight fell into Band A or C. Fourteen — every paid one — landed in Band D: the reader’s account was “a review site tested the market”, and it was wrong in the direction that mattered.
The May rewrite request went to all fourteen publishers. Six accepted a carried disclosure — the claim itself rewritten to read “in comfort testing commissioned by Marrable & Fen”. Five offered an “Advertisement feature” banner above the article and nothing in the copy, which is page furniture and satisfies the CAP Code’s presentation rule while failing the extraction test entirely. Three refused any disclosure and were withdrawn, recovering £5,550 a quarter.
The July re-audit is the interesting part. Across 31 sampled engine citations drawn from the six carried-disclosure pages, 19 retained the attributive phrase naming Marrable & Fen as the commissioning party. Across 24 citations drawn from the five banner-only pages, none carried any commercial signal at all: the banner never once made it into a retrieved passage. Same publishers, same money, same placement pacing — and one group’s disclosure existed at the point of reading while the other’s existed only on a page nobody in the chain looked at.
The recovered £5,550 went into two commissioned comparison tests run by an independent testing house that published its own methodology and its own verdict. One of the two verdicts placed Marrable & Fen second in its category. They published it anyway, and that document generated more citation coverage over the following quarter than the three withdrawn placements had in the previous four.
The cost was real. Two of the six carried-disclosure placements were dropped from their roundups at the next refresh, and the agency’s reported citation share fell for six weeks before recovering. A programme that cannot tolerate a quarter of visible decline will not survive this change, which is worth knowing before you start rather than after.
The Monday checklist
- Export every live paid placement from the last four quarters, with the invoice value and the exact sentence that names you. Not the URL — the sentence.
- Run the Expectation Gap Test on each one and record the band. Report the Band D share as a single number to whoever signs the retainer.
- Search each Band D page for the words your payment bought. If the only commercial signal in the file is an attribute or a banner, treat the placement as undisclosed.
- Rewrite the standard placement brief. Delete “reads as editorial” and add a required carried disclosure clause naming the commissioning party inside the claim.
- Re-price the media list. A publisher who will not carry a disclosure in copy is selling a Band D asset, and it should cost less than one that will, not more.
- Split the register. Paid placements, genuinely earned coverage and sponsorship placements have different disclosure duties and should stop living in one spreadsheet.
- Move the recovered budget into work that produces a true answer to Q1 — commissioned independent testing, published data, the kind of asset that earns its own presence audit without a payment behind the sentence.
The through-line. Advertising disclosure law has never regulated payment. It regulates the difference between why a reader thinks a sentence reached them and why it did. Generative answers did not create that gap, they industrialised it — one payment now produces an unbounded run of unlabelled impressions in words you did not write. The regime that governs this in 2027 is a sentence from 2005 with a criminal penalty and a regulator that no longer needs a court. The only disclosure that reaches both readers is the one inside the claim, and the only placement that needs none is the one nobody paid for.
