Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Aug 12, 2026 · 7 min read

NAI Issues First AI Rules for Ad Tech Data Use

The Network Advertising Initiative has published nine plain English dos and don'ts for members running AI and agentic workflows, plus a one page checklist. It is entirely voluntary, and it arrived three days after the EU AI Act's transparency duties became enforceable.

Trade associations write voluntary guidance for one of two reasons: the members genuinely do not know what good practice looks like, or binding rules are close enough that the industry would rather define the standard than inherit one. The NAI's new AI guidance reads like both. The useful question for anyone carrying compliance risk is not whether the document is sensible. It is. The question is what it buys you when a regulator calls.

Key Takeaways

  • The NAI published "Key Do's & Don'ts for Using AI in Network Advertising," covering nine topics with a one page self assessment checklist, and the IAPP reported it on 5 August 2026.
  • NAI Vice President Tony Ficarrotta framed the guidance as something members should follow "in the absence of mandatory standards or clear regulation," which is an explicit acknowledgement that it is not law.
  • Article 50 of the EU AI Act became applicable on 2 August 2026, carrying penalties up to €15 million or 3% of worldwide annual turnover, and NAI membership provides no defence against it.
  • The NAI has roughly 100 member companies including Google, Amazon Ads, Adobe and Microsoft, and its Code of Conduct has drawn criticism for weak enforcement since the FTC reviewed the framework in 2009.

What Does the NAI Guidance Actually Require?

Nothing, in the enforceable sense. It recommends. The NAI's own announcement describes the document as "a set of plain-English do's and don'ts for adopting AI-enabled and agentic advertising workflows," and says the voluntary guidance "is now available to use."

The nine topics, in the order the drafters put them:

  • Inventory and enablement of AI use cases
  • Advertising audience and segment review and activation
  • Testing and monitoring of AI systems
  • Disclosures about how AI systems are used
  • Permissions and constraints applied to AI systems
  • Choice and signal handling
  • Oversight and logging for agentic systems
  • Contracting and risk allocation between AI users and AI vendors
  • Accountability

The organising principle is proportionality by autonomy. As the NAI puts it, "the more authority a system has to change a privacy or legal outcome on its own, the stronger the case for testing, permissions, monitoring, and a proven way for human intervention." That maps closely to how the EU AI Act scales obligations, and the concern driving it is concrete: agentic systems now access data, bid on inventory and execute transactions autonomously, so a model can make a legally consequential decision about a person before any human sees the specific action.

Is Voluntary Guidance a Safe Harbor?

No, and nobody at the NAI claims otherwise. Ficarrotta told the IAPP that members should proactively follow the guidance "in the absence of mandatory standards or clear regulation," which is a candid description of a gap, not a claim of legal cover.

This is where institutional history matters. The NAI has existed since 2000 and its self regulatory framework was one of the two pillars the FTC examined in its 2009 staff report on self regulatory principles for online behavioural advertising. Even then, commenters told the Commission the NAI Principles suffered from a lack of enforcement and an opt out system that was cumbersome and inaccessible, and that they covered only network advertisers rather than the wider ecosystem. Seventeen years later the same critique lands on the DAA's AdChoices programme, which offers an opt out from targeted ads rather than from tracking itself.

Here is the read most coverage misses. The value of this guidance is not the safe harbor it fails to provide. It is that a trade body of roughly 100 members, Google and Amazon Ads among them, has written down what the industry considers reasonable care with agentic systems. That becomes the yardstick a plaintiff's lawyer or a state attorney general holds up when your company falls short of it. Voluntary standards do not create liability. They create a published baseline you can be measured against.

A printed compliance checklist on a desk beside a laptop showing an advertising dashboard, lit by window light

How Does This Map to the EU AI Act and GDPR?

Imperfectly, and the timing is the story. Article 50 of the EU AI Act became applicable on 2 August 2026, three days before the IAPP covered the NAI document. The European Commission's Article 50 transparency guidelines, adopted 20 July 2026, cover direct interaction with people, AI generated content, emotion recognition and biometric categorisation, and synthetic media. Breach exposure reaches €15 million or 3% of worldwide annual turnover. We walked through the wider timetable in our piece on what changes under the EU AI Act from August 2.

Three mismatches deserve attention:

  • Disclosure is not the same duty in both regimes. The NAI treats "disclosures about how AI systems are used" as a governance recommendation. GDPR Articles 12 to 14 require specific, intelligible information to the data subject at collection, and Article 22 adds constraints where solely automated processing produces legal or similarly significant effects. A checklist tick discharges neither.
  • Emotion recognition and biometric categorisation now carry named obligations. Segmentation that infers emotional state or sensitive category membership from behavioural signals sits close to Article 50 territory, and ad tech vocabulary has historically avoided calling it that.
  • Choice signal handling is where US state law bites hardest. Global Privacy Control honouring is mandatory under several state regimes, not advisory. Our survey of how 2026 privacy laws are reshaping ad tech covers the state by state picture.

On the US side, the FTC has not waited for AI specific legislation. It has run Operation AI Comply since September 2024 using Section 5 unfairness and deception authority, with 2026 actions including an $18 million judgment against Air AI in March. And its data flow enforcement against advertising platforms is live: see our coverage of the FTC complaint over health data sent to ad platforms.

What This Means for Email Marketing Programmes

Email is where AI driven segmentation surfaces most visibly to the person receiving it. An agentic system that builds a lookalike audience, scores propensity and triggers a send has made a decision about someone using their personal data, and the recipient sees only the message. Nothing in the NAI document changes what you must tell that person, and the EDPB's coordinated action on email tracking transparency shows regulators already probing disclosure quality in this exact channel.

If your privacy notice describes segmentation as human curated and a model now holds autonomy over activation, the notice is inaccurate. That is a straightforward Article 13 problem, and the kind of discrepancy an auditor finds in an afternoon.

What Should a Privacy Team Do This Quarter?

Use the NAI checklist as a discovery instrument, then map every finding onto a binding obligation. Concretely:

  • Build the AI use case inventory first. Record for each system what personal data it touches, how much autonomy it holds, and whether a human reviews the specific action or only the aggregate outcome. Everything else depends on this artefact.
  • Extend DPIA coverage to automated activation. Any system that changes who receives what, using personal data, without prior human review of the individual decision needs a documented assessment. Many ad tech DPIAs predate agentic deployment entirely.
  • Rewrite the disclosure copy, not just the internal policy. Align the privacy notice, the consent flow and the Article 50 interaction disclosure. Test that a reader can tell an AI system is involved.
  • Push permissions and constraints into vendor contracts. The NAI's contracting topic is the most useful part of the document. Turn it into clauses: permitted data uses, prohibited inferences, logging retention, incident notification, and audit rights over model behaviour.
  • Log agentic decisions to an evidentiary standard. Not debug logs. Records you could hand a regulator to show which constraint applied when.

And be clear about what the guidance does not get you: no safe harbor, no regulatory presumption of compliance, no defence to a GDPR fine, no shield from a state attorney general. Given that cumulative GDPR fines passed €7.1 billion, treating a trade body checklist as a compliance programme would be an expensive category error.

Self regulation arriving in the middle of an enforcement wave is not a substitute for rules. It is a signal that the rules are coming, and an invitation to shape them. Read the document, run the checklist, then do the statutory work anyway.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.