Microsoft checks the file, not the picture

On September 14, 2026 Microsoft Advertising posted a separate help page, "AI-generated and synthetic content in advertising", meaning rules for ads created or substantially modified by AI. The news went around the industry the same day: Search Engine Land published a breakdown, and Hana Kobzová pushed the page into the PPC community feed. The interesting part is not the line about banning deepfakes, everyone expected that. The interesting part is different: the platform requires keeping watermarks, metadata and other provenance information inside the file, the data that shows how the content was made. Until now moderation looked at what was drawn in the creative. Now it also looks at what sits inside the file.
Let me go through it in order: what exactly Microsoft requires, how a machine readable trace differs from a visible label, where that trace disappears on its own, and what to do with images generated right inside the ad account.
What Microsoft Advertising demanded from advertisers on September 14, 2026
The platform's wording is cautious: if AI created or substantially modified an ad, the consumer may need to be told about it. The word "may" here is not about freedom of choice, it is about disclosure requirements differing from country to country. Microsoft puts responsibility for following the law on the advertiser in every region where the ads run. One campaign across five countries means five sets of requirements, and the person paying for the clicks is the one who has to sort them out.
Further down the page there are three blocks of requirements: disclosing the fact of generation, having permissions, and separate rules on using a person's image or voice. Plus the requirement not to touch the technical provenance traces.
Microsoft names five grounds for rejection under the new rules:
- prohibited deepfakes;
- impersonating a real person or organization;
- using someone else's image or voice without permission;
- missing mandatory disclosure where it is required;
- tampering with machine readable provenance data in the file.
The last point is the news. The first four are about ad content, and you can find them in one form or another in the rules of any large ad system. The fifth is about the file. This is the first time an ad system has directly tied creative approval to the integrity of technical data, not only to what a human sees on screen.
Some context helps: Microsoft had specific synthetic content rules since 2024, but only for political advertising. Back then it looked like a narrow story for election campaigns. Now the same logic has been moved into the general requirements, and it applies to a shoe store exactly as much as to a party headquarters.
How invisible metadata differs from a "made with AI" label on the picture
It is easy to get confused here, because both traces are called a watermark, and they work differently.
Machine readable provenance data is a record inside the file: what made it, when, with which tool. Plus invisible watermarks embedded in the pixels themselves or in the audio. A human does not see or hear them, a machine reads them. Microsoft notes separately: content created with Microsoft's own AI tools may contain such data and invisible watermarks by default.
Visible disclosure is a label for a human. A tiny line in the corner of the image, a caption in the video, a phrase in the voiceover. Microsoft asks that disclosure be clear and placed next to the content it refers to, not somewhere off to the side. The platform's recommendation: embed the label directly into the image or video. For formats that support it, you can use the disclaimer feature already available in the ad.
And here is the main takeaway from this point. Since invisible signals are not visible to the user, they do not count as disclosure. So generating an image with a Microsoft tool, getting all the proper metadata inside the file and calling it a day will not work: the advertiser still adds the visible or audible label themselves. The file talks to moderation, the label talks to the human. You need both conversations.
Why a "made with AI" label will not save a misleading creative
The rules say it in a separate line: disclosure does not legalize deception. An ad with an honest AI label can still be rejected, limited in impressions or pulled if the content lies.
This matters, because the temptation is obvious: put a note in the corner, you warned people, so you can draw anything. No. Microsoft recommends checking an AI creative against reality on four things before submission: the people, products, places, claims and events in it must be real. A generated model in the frame who does not exist is one story. A generated product that you actually sell in a different configuration is another. A storefront that does not exist at the stated address is a third.
Search Engine Land put it this way in its breakdown: Microsoft is not banning AI in advertising, it is separating using AI to create an ad from using AI to deceive the viewer. A clean and useful formulation, worth keeping in mind as a filter at the stage when you brief the generator.
[example needed] as of the rules going live there is no public rejection under the new policy, so it is too early to judge how strict moderation really is.
Where provenance data disappears on its own, with no bad intent
Microsoft asks advertisers not to cut metadata and watermarks out of AI assets. The wording sounds as if it is about deliberate scrubbing. In practice this data is more often lost in the normal production cycle, and nobody notices.
What erases the trace in a file:
- a screenshot instead of a download: a new file, no history inside;
- resaving through an online converter or an image compressor;
- resizing and cropping in an editor with the export setting "no metadata";
- assembling a collage where the generated image is one layer out of five;
- delivery through an intermediary: the file went through a messenger or a task tracker that automatically re-encoded the image.
The last point is the nastiest, because it is out of the designer's hands. The picture went into a chat, came back as a different file, and went on into the ad account.
Hence a simple working rule: the original from the generator is stored separately and never edited, and all retouching happens on a copy. If moderation or a lawyer asks where the picture came from, the original with its internal data is the answer. It is easiest to store it in the same place as the campaign brief, in one folder with the generation date and the tool name.
- the original from the generator sits untouched
- retouching happens only on a copy
- export without the "remove metadata" checkbox
- the file is uploaded to the ad account directly, not through a messenger
- the visible or audible generation label is in place
What to do with creatives generated inside the ad account itself
Image generators and text variant generators are now built into almost every ad account, and this is the most common way to end up with an AI creative: you did not deliberately generate anything, you just clicked "create variants". Under Microsoft's rules such content falls under the same requirements, and on the provenance side it is even in better shape: a file made with Microsoft's AI tools may already contain metadata and an invisible watermark.
But there is no visible disclosure there. The platform will not add it for you, the page says so directly. So the order is this:
- Mark on your side which ads were built with generation involved, including the ones where AI only rewrote the text or replaced the background.
- Check for each market you run in whether mandatory disclosure is required there.
- Where it is required, add the label: through the disclaimer feature in the ad if the format supports it, or directly in the image and video.
- Check that the label sits next to the element it refers to and is readable on a mobile screen, not only in a mockup on a big monitor.
Step 1 is usually where it breaks. A month into the work nobody remembers which of the 40 creatives in the campaign the generator touched. So the generation flag is worth keeping right in the file name or in the asset name, not in a separate spreadsheet that everyone forgets to update.
How this fits with the other changes of mid September 2026
The topic made it into the daily industry roundup on September 15, 2026 together with two things worth knowing for anyone running campaigns in Google.
First: Google is testing text link ads with a "Sponsored" label inside AI Mode, meaning inside the mode where search answers with generated text rather than a list of links. Advertising is moving into AI surfaces, and labels there are becoming part of the interface.
Second: on September 15, 2026 Performance Max, Google Ads' automated campaign type where the system spreads the budget across all Google inventory itself, got the option "Where should people go after clicking your ads?" with two choices: the website or the company's Google business profile. For those who do not really have a website but do have a listing in Maps and search, that is a noticeable option.
Third, from the same roundup: Google confirmed that the rebuild of the Target CPA and Target ROAS algorithms, the automated bidding strategies for a target cost per conversion and a target return on ad spend, ran from August 17, 2026 to August 27, 2026 and finished before the September campaigns. If your bids were jumping at the end of August, now you know why, and the September numbers can be treated as clean.
- 2024synthetic content rules only in Microsoft political advertising
- 17 to 27 August 2026Google rebuilds Target CPA and Target ROAS
- 14 September 2026Microsoft publishes general rules for AI creatives
- 15 September 2026Performance Max gets a click destination choice
What to do this week
- Open the Microsoft Advertising account and mark the ads where AI took part in creating the image, video, voice or text. A simple list is enough.
- Among those, find the ones with a person in them: a face, a voice, a recognizable way of speaking. For each one answer whether you have permission. If there is no answer, pause it until you find out.
- Check by country of delivery where disclosure is mandatory, and add the label through the disclaimer in the ad or directly in the creative.
- Introduce a rule for storing generator originals unedited and a ban on resaving files through converters and messengers.
- Before every next submission, run the creative through Microsoft's four points: the people, products, places, claims and events in it match reality.
Checking the file instead of checking the picture changes habits more than it seems. For years designers did exactly the opposite: cleaned metadata, compressed, resized, exported without the extras. Now the extras have become mandatory.
mrpopular has been running since 2014, and promotion has been in front of my eyes all that time: social networks, search engines, ads, suppliers, orders, disputes, statistics.
One company holds every side of the market: a promotion service where most services are our own rather than resold; the etask marketplace, where tasks are done by real people; a support desk that shows what customers actually complain about. So the texts contain what agency reports leave out: supplier prices, drop-off rates, chat logs, statistics screenshots.
A marketing blog without fairy tales. What works, what stopped working, what it costs and why.
My topics: social networks and paid boosts, ads, traffic, suppliers and the market from the inside, plus the marketing news issue every morning.


