Skip to main content
Practitioner frameworkPractitionerEU-wide14 min readTechnology, AI and Infrastructure

AI-Assisted Campaign Content: Human Review Checklist

Eight checks every piece of AI-assisted political content must pass before publication — built around the EU AI Act, GDPR, and the practical realities of fast-moving campaigns.

Dr Henrik Voss

Senior Research Fellow

Institute for Democratic Innovation, Berlin · Germany

Henrik Voss researches political communication, digital campaigning, and electoral integrity at the Institute for Democratic Innovation in Berlin. He has published on EU political advertising regulation, AI governance in electoral contexts, and the effects of platform policy on political speech. He previously worked as a policy adviser in the Bundestag and at the European Parliament.

EU complianceDigital regulationPolitical advertisingElectoral integrityAI governance

Disclosure

Dr Voss is a salaried researcher at the Institute for Democratic Innovation, a non-partisan think tank. He holds no positions in active campaigns or political parties. His research is funded by the Institute and, where relevant, by EU research grants, which are disclosed in full in his academic publications.

Peer reviewed

Elena Christodoulou

Legal Counsel, Political and Regulatory Affairs, Christodoulou & Partners

Reviewed May 2026

What it covers

Why human review of AI-generated political content is non-negotiable, what the EU AI Act requires, an eight-check workflow for campaign teams, who should sign off on what, and the most common failure modes.

Who it is for

Campaign managers, digital directors, compliance leads, and any staff responsible for content approval in campaigns using AI tools for content production.

When to use it

Before publishing any piece of content that was substantially produced or assisted by AI tools — including drafts, social captions, press releases, ad copy, speeches, and email copy. Also useful when designing a new AI content workflow from scratch.

Key takeaway

AI tools accelerate content production; human review is what makes that content legally and politically safe to publish. The two are not in tension — they are designed to work together. The EU AI Act makes human oversight a legal obligation, not a best practice.

In brief

  • The EU AI Act, in force from August 2026, creates binding transparency obligations for AI-generated political content.
  • Article 50 of the AI Act requires that AI-generated content likely to be seen as authentic be labelled as machine-generated.
  • Political content sits in a category of heightened risk under the AI Act, attracting additional scrutiny.
  • Human review is not optional — it is the mechanism through which campaigns demonstrate compliance with the Act's transparency requirements.
  • Eight checks cover factual accuracy, legal compliance, AI disclosure, synthetic media, targeting lawfulness, reputational risk, human approval, and audit trail.
  • Failure modes cluster around speed pressure: the most dangerous AI content errors happen when campaigns skip review to meet a deadline.

Framework

The eight-check AI content review

A sequential review framework for AI-assisted campaign content that covers legal compliance, factual integrity, and political risk before publication.

LayerLabelDescription
Check 1: Factual accuracyVerifyEvery claim in the content is checked against a primary source by a human reviewer
Check 2: Legal reviewClearContent passes a legal screen for defamation, electoral law, and data use
Check 3: AI disclosureLabelAI-generated or AI-assisted content is disclosed as required by EU AI Act Art. 50
Check 4: Synthetic mediaAssessSynthetic images, audio, or video are identified and treated under the synthetic media rules
Check 5: Targeting lawfulnessConfirmIf the content will be targeted using personal data, targeting parameters are lawful under GDPR
Check 6: ReputationScreenContent is reviewed for reputational risk, unintended associations, and off-message claims
Check 7: Human approvalSign offA named, accountable human signs off before publication — not an automated system
Check 8: Audit trailDocumentA record is created of who reviewed what, when, and what was approved

Why human review is non-negotiable for political content

AI tools have transformed the pace at which campaign teams can produce content. What once took a copywriter a day can now be drafted in minutes. What required a design team can be produced by a single operator with a generative image tool. For campaigns operating under time pressure, resource constraints, and the constant demand for multi-channel output, the productivity gain is real and significant.

But the speed gain creates a risk that campaigns are only beginning to understand fully: AI-generated content can be factually wrong, legally non-compliant, reputationally damaging, or in violation of the EU AI Act — and it can be all of those things in ways that are not immediately obvious to a human reader skimming a draft. Language models do not know what is true; they know what is plausible. Image generators do not know who is pictured in a real photograph; they generate what looks right. The political consequences of publishing content that is wrong, or synthetic, or non-compliant, without human review, can be severe and immediate.

The EU AI Act, which applies to systems deployed in the EU from August 2026, makes human oversight of AI systems in high-risk and sensitive contexts a legal requirement, not a recommendation. Political content is an explicitly sensitive area under the Act. Article 50 creates specific disclosure obligations for AI-generated content that is "likely to be perceived as authentic" — a standard that encompasses most professionally produced AI campaign content. Campaigns that do not have a documented human review process are not just taking a reputational risk; they are taking a legal one.

The EU AI Act: what campaign teams need to know

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) creates a risk-based regulatory framework for AI systems operating in the EU. It establishes categories of AI risk — from unacceptable risk (prohibited) through high risk (requiring conformity assessment) to limited and minimal risk — and sets obligations that scale with the level of risk. For political campaigns, the most directly relevant provisions are those in Article 50, which govern transparency obligations for AI-generated content.

Article 50 requires that deployers of AI systems that generate synthetic content — including text, images, audio, and video — that is likely to be perceived by persons as authentic must ensure that the content is labelled as AI-generated in a way that is "machine-readable and detectable." For political content, this is not a theoretical obligation. If your campaign uses a language model to draft a press release, an image generator to produce campaign imagery, or a voice synthesis tool to produce audio content, Article 50 requires disclosure. The obligation applies to content "likely to be seen as authentic" — not only to content that is explicitly presented as AI-generated.

Campaigns should also be aware that AI systems used for targeting political content to individuals using personal data may fall under higher-risk categories of the Act, depending on how the system classifies or profiles individuals. Voter scoring models, sentiment-based targeting systems, and personalisation engines all require review against the Act's high-risk provisions, which include requirements for human oversight, transparency, and accuracy. The interaction between the AI Act and GDPR is particularly complex in political contexts, where personal data processing for targeting purposes intersects with special category data rules on political opinions.

The practical implication for campaign teams is that operating without documented human review of AI-generated content is not simply careless — it may be non-compliant. Supervisory authorities in EU member states are developing enforcement guidance for the political sector, and the first enforcement actions under the AI Act's transparency provisions are expected during the 2026–27 electoral cycle. Campaigns that have no process will be exposed; campaigns with a documented, functioning process will have a credible compliance position.

The eight-check workflow

The eight checks are sequential, not parallel. Each check gates the next. Content that fails Check 1 (factual accuracy) should not proceed to Check 2 — not because the other checks are less important, but because factual errors change the legal and reputational risk calculus for every subsequent check. A content item that does not pass all eight checks should not be published. It should be returned for revision or, if revision is not possible in the time available, held.

Check 1, factual accuracy, is the most time-consuming check and the most frequently skipped. AI language models produce plausible-sounding text — they are optimised to do so. That optimisation does not include a commitment to accuracy. Statistics may be wrong, dates may be hallucinated, names may be transposed, and quotations may be invented. Every factual claim in AI-generated content must be verified against a primary source — a published report, a verified news source, an official government or institutional document — before the content moves forward. If a claim cannot be verified, it must be removed or rewritten.

Check 3, AI disclosure, is where many campaigns currently have a gap. The default position should be to disclose. If your content was drafted with AI assistance, label it. The EU AI Act requires disclosure in any case where the content is "likely to be perceived as authentic" — which, for polished campaign copy, is almost always the case. The disclosure does not need to be prominent or to undermine the content's impact; it can be a small-text statement at the foot of a page, a metadata tag on an image, or a platform-standard label on an ad. What it cannot be is absent.

Check 5, targeting lawfulness, is specific to content that will be delivered to individuals using personal data for targeting. Under GDPR, processing personal data to deliver political content to individuals requires a lawful basis. In most EU member states, political opinions are special category data under GDPR Article 9, attracting the stricter conditions of Article 9(2). Inferred political opinion — even where the individual has not disclosed their views — is increasingly treated as special category data by EU data protection authorities. If your targeting parameters involve any inference about political preference, interest, or behaviour, you need to confirm the lawful basis and data minimisation approach with a qualified data protection professional before the content goes live.

Who signs off on what

Check 7, human approval, requires a named accountable human to sign off on content before publication. "Named" and "accountable" are both essential. An anonymous approval step, or an approval by an automated system, does not meet the standard. The person signing off must be identifiable, must have the authority to halt publication, and must understand that they are taking responsibility for the content at the time of approval.

For most campaign structures, the most appropriate sign-off hierarchy depends on the type of content and its risk profile. Routine social media posts drafted with AI assistance might require sign-off from a digital manager. Paid advertising must require sign-off from a compliance lead and the campaign manager or director. Any content referencing regulatory matters, legal proceedings, named individuals, or policy positions should require legal review — even a short legal screen — before the communications sign-off. Any synthetic media must require the most senior communications authority the campaign has, because synthetic media carries the highest legal and reputational risk.

The sign-off record should be created at the time of approval, not reconstructed after the fact. A simple log — content item, date, reviewer name, what was reviewed, and the outcome — is sufficient for most campaigns. Larger campaigns with high-volume content production should consider a content management system that builds the audit trail automatically as part of the approval workflow. What cannot be acceptable is a system where approved content cannot be traced back to a named approver, because that system provides no accountability and no compliance defence.

Common failure modes

The deadline override is the most dangerous failure mode. A campaign needs content for a time-sensitive moment — a breaking news event, a conference appearance, a response to an opponent — and the review process is shortened or skipped to meet the deadline. This is exactly the scenario in which AI content errors are most likely to cause damage, because the speed pressure that created the override also means less time for human fact-checking and correction after publication. Build the review process so that it can move quickly — but build it so that it cannot be bypassed entirely.

The distributed responsibility failure happens when no one person owns the review process. If factual accuracy is "everyone's responsibility," it is nobody's responsibility. Assign a named individual to each of the eight checks for each piece of content. That individual is accountable for their check. If they are not available, a named deputy must cover the check. Content does not proceed until the check is complete and recorded.

The synthetic media blind spot occurs when campaign teams treat AI-generated images, audio, and video as equivalent to stock photography or licensed footage. They are not equivalent. Synthetic media carries specific disclosure obligations under the AI Act, specific risks around the representation of real people (who may have legal recourse if their likeness is used without consent), and specific risks around misidentification — AI image generators routinely produce images of real people who are unrecognisably altered, potentially creating defamation exposure. Every piece of synthetic media must be identified as such at the point of production, before it enters the review queue, and must be subject to the synthetic media check.

Finally, the audit trail gap is a failure mode that only becomes visible when something goes wrong. Campaigns that cannot demonstrate, with a contemporaneous record, what was reviewed, by whom, and when, have no compliance defence if a piece of AI-generated content is challenged by a data protection authority, an electoral commission, or a court. The audit trail is not bureaucracy — it is the evidence of the human oversight that the AI Act requires.

AI workflow suggestions

  • 1.Use an AI drafting tool to produce the first draft of campaign content — then route every draft through the eight-check review before any further production work.
  • 2.Prompt an AI model to identify factual claims in a draft and list the sources that would be needed to verify each — use this as the input for Check 1.
  • 3.Use an AI content detection tool as a first-pass screen for synthetic media within a content batch — then apply human review to any item flagged as potentially synthetic.
  • 4.Ask an AI model to identify which statements in a draft are most likely to attract legal scrutiny — use this to prioritise the legal review in Check 2.

Prompt pack

Factual claim extraction prompt

Review the following campaign content and list every factual claim it makes, including statistics, dates, named individuals, organisations, and policy positions. For each claim, indicate what type of primary source would be needed to verify it. Do not evaluate whether the claims are true — only identify them and the verification standard required.

[PASTE CONTENT HERE]

Legal risk identification prompt

Review the following political campaign content and identify any statements that could create legal exposure, including: potential defamation (naming individuals with negative claims), electoral law compliance issues (references to electoral activity, spending, or targeting), data protection issues (references to personal data or audience characteristics), and regulatory compliance issues (claims about regulated activities or regulated entities). Flag each issue and indicate the legal domain it falls under.

[PASTE CONTENT HERE]

Reputational risk screen prompt

You are a senior communications adviser reviewing the following campaign content before publication. Identify any statements, phrasings, or associations that could: (1) be taken out of context in a way that damages the campaign; (2) alienate a target audience segment; (3) contradict the campaign's known public positions; or (4) create an association with a person, organisation, or issue that the campaign would not want to be associated with. Be specific about the risk and the segment affected.

[PASTE CONTENT HERE]

Checklist

  • Check 1 — Factual accuracy: all factual claims verified against a primary source by a named human reviewer
  • Check 2 — Legal review: content screened for defamation, electoral law compliance, and data use by a qualified reviewer
  • Check 3 — AI disclosure: content labelled as AI-generated or AI-assisted in compliance with EU AI Act Article 50
  • Check 4 — Synthetic media: all AI-generated images, audio, and video identified and reviewed under synthetic media rules
  • Check 5 — Targeting lawfulness: where content will be targeted using personal data, a lawful basis under GDPR has been confirmed
  • Check 6 — Reputation: content reviewed for reputational risk, unintended associations, and off-message claims
  • Check 7 — Human approval: a named, accountable human has signed off on the content before publication
  • Check 8 — Audit trail: a contemporaneous record exists of who reviewed what, when, and what was approved

Sources

  1. 1.Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on Artificial Intelligence (EU AI Act)
  2. 2.Regulation (EU) 2016/679 (General Data Protection Regulation)
  3. 3.Regulation (EU) 2024/900 on the transparency and targeting of political advertising
  4. 4.European Data Protection Board (2024). Guidelines on the use of AI systems in the processing of personal data.
  5. 5.European AI Office (2025). Guidance on transparency obligations under Article 50 of the AI Act.

Further reading

  • Legal briefingEU Political Advertising: What Campaign Teams Need to Know12 min
  • ExplainerEU AI Act and Synthetic Media Governance10 min
  • PlaybookContent Approval Workflows for Campaigns8 min

Version history

  • 2026-05-01Initial publication, reviewed by Elena Christodoulou against the EU AI Act as in force from August 2026.