Advanced

AI in crisis communications: the rules that actually bind

One clause of the EU AI Act decides whether an AI-drafted public statement is legal without a label, and the disclosure clocks are shorter than most drafting cycles. What applies, from when, and where the profession draws the line.

6 min readUpdated 26 Aug 2026

A crisis compresses everything: the statement, the legal review, the sign-off. That is exactly the pressure under which teams reach for a model — and exactly when regulation is least forgiving. The good news is that the binding rules are narrow and quotable, and one of them contains an exemption that most comms teams already satisfy without knowing it.

Two clocks matter more than any of it. If you are drafting past them, the drafting method was never the problem.

What is actually established

From the regulations and the profession's published ethics guidance.

  • The EU AI Act has a press-statement clause. Article 50(4): deployers of a system generating or manipulating text "which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated."
  • Human review is the exemption. That same clause does not apply "where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content." A reviewed statement with a named accountable publisher needs no AI label; an unreviewed one does.
  • Deepfakes must always be disclosed. Article 50(4) first paragraph requires deployers of AI generating deep-fake image, audio or video content to disclose it, regardless of review.
  • Disclosure has a deadline within the interaction. Article 50(5) requires it "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure."
  • The date is 2 August 2026. Article 50 sits in Chapter IV, which applies from that date under Article 113.
  • The Commission's Code of Practice is voluntary; the obligation is not. "Even though adherence to the code is voluntary, the transparency requirements under article 50 of the AI Act are legal obligations." Non-signatories must demonstrate their measures are adequate.
  • The disclosure clocks are shorter than a drafting cycle. A material cybersecurity incident goes on SEC Form 8-K Item 1.05 "generally due four business days after a registrant determines that a cybersecurity incident is material." GDPR Article 33 requires notifying the supervisory authority "without undue delay and, where feasible, not later than 72 hours after having become aware of it."
  • High-risk breaches must reach the people affected. GDPR Article 34 requires communication to data subjects without undue delay and "in clear and plain language," unless the data was rendered unintelligible, for instance by encryption.
  • The profession puts crisis outside the automation boundary. PRSA: "Use AI for drafting, summarizing, trend spotting, and brainstorming — but let human judgment lead strategy, ethics, crisis response, and reputation management."
  • Some uses are named as unethical outright. PRSA lists creating "fake accounts, chatbots, or impostors that pose as authentic voices," and leaving inaccurate AI-amplified information uncorrected on a website or in a media kit.
  • Fabricated endorsements now carry civil penalties in the US. The FTC's Fake Reviews Rule makes it a deceptive practice to create or disseminate a review or testimonial misrepresenting "that the reviewer or testimonialist exists" — the FTC names AI-generated fake reviews explicitly.
  • Sensitive material stays in closed systems. PRSA advises closed AI systems for sensitive client work, and public tools only where the tool does not store or reuse inputs and no confidential data is entered.

How to run it

Decide this before the incident, because none of it can be decided during one.

  1. Write down now who holds editorial responsibility for public statements. That named person is what moves an AI-assisted statement into the Article 50(4) exemption.
  2. Make human review a recorded step, not an assumption — the exemption turns on a review process existing, so log who reviewed and when.
  3. Map your clocks first: 72 hours for a GDPR notification, four business days after a materiality determination for an SEC 8-K. Build the drafting process to fit inside them.
  4. Pre-approve a closed AI environment for incident work, and ban public tools for anything containing personal data, unreleased facts or legal analysis.
  5. Never synthesise a spokesperson. Deepfake disclosure is mandatory regardless of review, and PRSA treats impostor voices as unethical outright.
  6. Prepare a verification routine for inbound synthetic material — trace the original source, reverse image search, check for corroborating reports from trusted outlets — because a crisis is when fabricated assets arrive.
  7. Keep a correction path open. Leaving inaccurate AI-amplified information uncorrected is itself named as improper conduct.

How to measure it

In a crisis the useful measures are about time and traceability, not sentiment.

  • Time from materiality determination to filed disclosure, against the four-business-day and 72-hour clocks.
  • Proportion of public statements with a logged human review and a named responsible person — your Article 50(4) evidence.
  • Number of statements published with an AI-generation label where no review was recorded, which should be zero.
  • Time to correct any inaccurate published information, tracked to closure.
  • Verification turnaround on inbound suspect media, from receipt to a provenance verdict.

Where teams get this wrong

  • Assuming an AI label is always required. With recorded human review and a named responsible publisher, Article 50(4) does not require one for text.
  • Assuming a label is never required. Deep-fake image, audio and video disclosure applies regardless of review.
  • Pasting incident detail — personal data, unreleased facts, legal analysis — into a public chatbot.
  • Letting an AI-drafted holding statement go out without a recorded reviewer, which forfeits the exemption and the accountability at once.
  • Publishing synthetic audio or video of a real spokesperson.
  • Treating the Commission's Code of Practice as optional in substance. Signing is voluntary; the Article 50 obligations are law from 2 August 2026.

Sources

AI in crisis communications: common questions

Do we have to label an AI-drafted press statement?

Under EU AI Act Article 50(4), not if it went through human review or editorial control and a named person or organisation holds editorial responsibility for publication. Without that review, a public-interest statement must disclose that the text was artificially generated.

When does this apply?

Article 50 sits in Chapter IV of Regulation (EU) 2024/1689, which applies from 2 August 2026 under Article 113.

Can we use AI to draft the holding statement?

PRSA's position is that human judgment should lead crisis response, with AI used for drafting, summarising and brainstorming. Combined with Article 50(4), the workable pattern is AI-assisted drafting plus recorded human review and a named accountable publisher.

What about a deepfake of our CEO circulating?

Your own response must not answer it with synthetic media: deepfake disclosure is mandatory regardless of review, and PRSA treats impostor voices as improper. Verify the inbound material through source tracing and reverse image search before responding.

In use at

Deutsche TelekomAllianzLufthansaARDTDKStröerServiceplan Group

Put this into practice

Brief a coworker with what you just read and see what comes back. Signing up is free.

Start free

*No Credit Card required