Five Rulebooks for Campaign AI: What Will and Won't Be Legal in the 2026–27 Cycle

4 min read

4 min read

4 min read

Campaign Tech & AI

Compliance is now a campaign capability. For most of the last decade, the rules on synthetic media were vague enough that legal review was an afterthought — a box ticked somewhere between production and publication. That era is over. Between 2024 and 2026, regulators across a dozen jurisdictions moved to govern how campaigns use artificial intelligence — some with binding statute, others with advisories that carry real enforcement weight. Five of those frameworks will shape what campaigns can and cannot deploy across the 2026–27 cycle. Knowing where the lines sit is no longer a legal nicety. It is an operational advantage.

The five frameworks

The European Union — the EU AI Act (Regulation 2024/1689). The Act has no election-specific chapter, and it is worth being precise about that, because the commentary often implies one. What it has instead is two things that bite on political content. Article 50 requires that deepfakes and AI-generated material be labelled as artificially generated, with the transparency obligations taking effect on 2 August 2026 — though the provider-side marking rules may slip to December under the pending AI Omnibus. Separately, the Act classifies AI systems intended to influence the outcome of an election or referendum as high-risk. The model is horizontal and disclosure-led: label it, or answer for it.

Brazil — TSE Resolution 23.732/2024. The most aggressive electoral-authority rule anywhere. It does not merely require disclosure; it bans the use of deepfakes in campaign content outright, mandates labelling of other AI-generated material, and carries penalties up to the revocation of a candidate's registration. It was enforced in the 2024 municipal cycle — content removed, candidates fined — and the framework carries directly into Brazil's 2026 presidential election.

The United States — a patchwork under constitutional strain. There is no federal statute; the Federal Election Commission declined to write one, resting on the existing prohibition against fraudulent misrepresentation of campaign authority. In its place, roughly thirty states have enacted election-deepfake laws, split between disclosure requirements and outright prohibitions. The signal that matters for planning: the prohibitions are losing in court. California's attempt to ban deceptive election deepfakes was struck down on First Amendment grounds in 2025, and similar laws face challenge. Disclosure is the surviving model — and even disclosure is contested. In the US, assume the ground is still moving.

India — the advisory-first model. India regulates campaign AI through Election Commission advisories rather than statute. Since the 2024 general election the ECI has directed parties to label synthetic content and to pull deepfakes within hours of notice, tightening the guidance ahead of each subsequent state election. These are not yet binding law — the IT Rules that would make labelling a statutory obligation were still in draft as of late 2025 — but they set the operating expectation for any party campaigning in India, and the direction of travel is toward binding.

Kenya — the outlier that matters most. Kenya's instrument is not about synthetic media at all. The Office of the Data Protection Commissioner's Guidance Note on the Processing of Personal Data for Electoral Purposes, issued under the Data Protection Act 2019, governs how campaigns collect, target and process voter data — consent, lawful basis, impact assessments. With Kenya's next general election set for August 2027, it is the one framework in this group aimed squarely at the targeting layer.

The asymmetry — and where it leaves room to operate

Line the five up and a pattern emerges. Four of them — the EU, Brazil, the US, India — regulate the output: the synthetic image, the cloned voice, the manipulated video. Only Kenya regulates the input: the voter data that decides who sees the message in the first place. Regulators worldwide have moved fastest on the thing that is visible and viral, and slowest on the infrastructure that does the quieter, more consequential work of targeting.

That asymmetry is not a loophole to exploit; treated as one, it is a reputational landmine. But it does tell you where scrutiny is concentrated and where it is thin, and a serious operation plans accordingly — over-investing compliance attention on synthetic media, and getting ahead of the data-layer rules before regulators outside Kenya catch up to them, as they will.

Disclosure is the common denominator — but not a common standard

Every framework here converges on one idea: audiences should know when persuasive content was made by a machine. That is where the convergence ends. What counts as "AI-generated," what triggers a label, how prominent the label must be, whether satire is exempt — these differ enough that a single asset can be fully compliant in one market and sanctionable in another. A voice-cloned radio spot that is legal with a disclaimer in one country is a candidate-disqualifying offence in Brazil.

For any campaign operating across borders, the implication is concrete: do not run to each jurisdiction's minimum. Set one internal standard, calibrated to the strictest jurisdiction you touch, and hold every asset to it. It is cheaper than maintaining a different rulebook per market, and it is the only version that survives a cross-border asset being reshared into a jurisdiction it was never made for — which, online, is every asset.

Build compliance into the pipeline, not onto the end of it

The practical conclusion is a workflow decision, not a legal one. Teams that treat legal review as a final gate — the last checkpoint before an asset ships — pay for it in the currency they can least afford in the closing weeks of a race: time. A contested asset held for review while a news cycle turns is a message that arrives after the moment it was built for.

The alternative is to move review upstream, into the creative process itself: a compliance standard the studio designs against from the first draft, so that labelling, provenance and data-handling are built in rather than bolted on. Done well, it stops being a constraint and becomes a capability — the ability to move fast and clean while competitors are still arguing with their lawyers.

Compliance used to be what slowed a campaign down. In the 2026–27 cycle, for the campaigns that build it in early, it is what lets them move.

Compliance is now a campaign capability. For most of the last decade, the rules on synthetic media were vague enough that legal review was an afterthought — a box ticked somewhere between production and publication. That era is over. Between 2024 and 2026, regulators across a dozen jurisdictions moved to govern how campaigns use artificial intelligence — some with binding statute, others with advisories that carry real enforcement weight. Five of those frameworks will shape what campaigns can and cannot deploy across the 2026–27 cycle. Knowing where the lines sit is no longer a legal nicety. It is an operational advantage.

The five frameworks

The European Union — the EU AI Act (Regulation 2024/1689). The Act has no election-specific chapter, and it is worth being precise about that, because the commentary often implies one. What it has instead is two things that bite on political content. Article 50 requires that deepfakes and AI-generated material be labelled as artificially generated, with the transparency obligations taking effect on 2 August 2026 — though the provider-side marking rules may slip to December under the pending AI Omnibus. Separately, the Act classifies AI systems intended to influence the outcome of an election or referendum as high-risk. The model is horizontal and disclosure-led: label it, or answer for it.

Brazil — TSE Resolution 23.732/2024. The most aggressive electoral-authority rule anywhere. It does not merely require disclosure; it bans the use of deepfakes in campaign content outright, mandates labelling of other AI-generated material, and carries penalties up to the revocation of a candidate's registration. It was enforced in the 2024 municipal cycle — content removed, candidates fined — and the framework carries directly into Brazil's 2026 presidential election.

The United States — a patchwork under constitutional strain. There is no federal statute; the Federal Election Commission declined to write one, resting on the existing prohibition against fraudulent misrepresentation of campaign authority. In its place, roughly thirty states have enacted election-deepfake laws, split between disclosure requirements and outright prohibitions. The signal that matters for planning: the prohibitions are losing in court. California's attempt to ban deceptive election deepfakes was struck down on First Amendment grounds in 2025, and similar laws face challenge. Disclosure is the surviving model — and even disclosure is contested. In the US, assume the ground is still moving.

India — the advisory-first model. India regulates campaign AI through Election Commission advisories rather than statute. Since the 2024 general election the ECI has directed parties to label synthetic content and to pull deepfakes within hours of notice, tightening the guidance ahead of each subsequent state election. These are not yet binding law — the IT Rules that would make labelling a statutory obligation were still in draft as of late 2025 — but they set the operating expectation for any party campaigning in India, and the direction of travel is toward binding.

Kenya — the outlier that matters most. Kenya's instrument is not about synthetic media at all. The Office of the Data Protection Commissioner's Guidance Note on the Processing of Personal Data for Electoral Purposes, issued under the Data Protection Act 2019, governs how campaigns collect, target and process voter data — consent, lawful basis, impact assessments. With Kenya's next general election set for August 2027, it is the one framework in this group aimed squarely at the targeting layer.

The asymmetry — and where it leaves room to operate

Line the five up and a pattern emerges. Four of them — the EU, Brazil, the US, India — regulate the output: the synthetic image, the cloned voice, the manipulated video. Only Kenya regulates the input: the voter data that decides who sees the message in the first place. Regulators worldwide have moved fastest on the thing that is visible and viral, and slowest on the infrastructure that does the quieter, more consequential work of targeting.

That asymmetry is not a loophole to exploit; treated as one, it is a reputational landmine. But it does tell you where scrutiny is concentrated and where it is thin, and a serious operation plans accordingly — over-investing compliance attention on synthetic media, and getting ahead of the data-layer rules before regulators outside Kenya catch up to them, as they will.

Disclosure is the common denominator — but not a common standard

Every framework here converges on one idea: audiences should know when persuasive content was made by a machine. That is where the convergence ends. What counts as "AI-generated," what triggers a label, how prominent the label must be, whether satire is exempt — these differ enough that a single asset can be fully compliant in one market and sanctionable in another. A voice-cloned radio spot that is legal with a disclaimer in one country is a candidate-disqualifying offence in Brazil.

For any campaign operating across borders, the implication is concrete: do not run to each jurisdiction's minimum. Set one internal standard, calibrated to the strictest jurisdiction you touch, and hold every asset to it. It is cheaper than maintaining a different rulebook per market, and it is the only version that survives a cross-border asset being reshared into a jurisdiction it was never made for — which, online, is every asset.

Build compliance into the pipeline, not onto the end of it

The practical conclusion is a workflow decision, not a legal one. Teams that treat legal review as a final gate — the last checkpoint before an asset ships — pay for it in the currency they can least afford in the closing weeks of a race: time. A contested asset held for review while a news cycle turns is a message that arrives after the moment it was built for.

The alternative is to move review upstream, into the creative process itself: a compliance standard the studio designs against from the first draft, so that labelling, provenance and data-handling are built in rather than bolted on. Done well, it stops being a constraint and becomes a capability — the ability to move fast and clean while competitors are still arguing with their lawyers.

Compliance used to be what slowed a campaign down. In the 2026–27 cycle, for the campaigns that build it in early, it is what lets them move.

Follow us to keep in touch.

We help political movements and public-interest organisations build work that lasts.

Bucharest (RO)--:--