The man in Midnite's TikTok ad had no date of birth because he did not exist: he was generated by AI without source images or footage of a real person. Yet the Advertising Standards Authority concluded that his youthful features, styling and behaviour made him seem as though he were in his late teens or early twenties, which was enough to put the ad in breach.

The ruling published on 16 September 2026 concerned a paid TikTok ad seen on 3 July. It showed the character using a gambling app, reacting excitedly to a promotional offer and encouraging viewers to bet with Midnite. The CAP Code prohibits anyone who is or seems to be under 25 from gambling or playing a significant role in a gambling ad. The ASA concluded that the character seemed to be under 25 and upheld the complaint.

The breach did not turn on a misleading sentence; it emerged from the way a person who did not exist had been generated, presented and approved. This makes the ruling a useful example of how generative marketing changes the location of compliance work.

The failure began before the character existed

Midnite told the ASA that it had not sanctioned the ad, which had been created by an affiliate called Limay Media. It also said it had not contracted the affiliate to publish paid social posts and later ended the relationship.

Limay Media said the individual was an entirely AI-generated fictional character, created without source images or footage of a real person and not altered afterwards. The intention was to depict an adult, but the prompt did not specify an age.

That omission matters because the age restriction was known before the asset existed, when the instruction could have required a character who clearly appeared to be at least 25 and excluded youthful styling or features. The ASA noted that it had seen no evidence the AI had been prompted to respect the relevant age threshold.

Limay Media's remediation reflected this point: it introduced age-specific prompts, reviews focused on perceived age and restrictions on styling or facial features that might suggest somebody under 25. It also said it would retain records of the generation and approval process.

Prompts are therefore becoming part of the control environment for generative marketing because they can express known restrictions at the moment an asset is made: age limits, prohibited imagery, product eligibility, mandatory elements or claims that require substantiation. They remain an imperfect control, however, because an instruction describes the intended output without determining how every detail will appear or how a viewer will interpret the result. Encoding a rule before generation can reduce avoidable risk without deciding whether the finished communication complies.

The output still has to pass the test

The ASA assessed the person customers could see, pointing to youthful facial features, smooth skin, a boyish hairstyle and a plain grey hoodie. His animated expressions and excitement added to the impression, while nothing in his appearance, styling or behaviour clearly indicated that he was older than 25.

The character's fictional status did not change the assessment because the rule covers people who seem to be under 25. The ASA therefore did not need a verifiable age or evidence that a real young person had participated; the overall impression was what mattered.

This is why an age instruction in a prompt could never have been the final control: a model might receive a request for a 30-year-old character and still produce someone an ordinary viewer reads as younger. The same problem can arise through clothing, voice, movement, setting or the combination of cues across an image or video.

Some compliance decisions only become possible after generation because they depend on the completed communication. The words, imagery, layout, audio and context create an overall impression that none of their instructions can establish in isolation. Generative review must therefore be multimodal where the communication is multimodal.

The distinction is easy to miss when prompt records are treated as evidence of compliance, although they document only the instruction while the output shows what was actually created.

The workflow failed as well

The ruling also records a more familiar operational problem: Limay Media's normal process required managerial review before publication followed by client approval, but neither happened. The affiliate described this as an isolated human error and said a manager paused the ad after a few hours.

That failure keeps the case from becoming a narrow lesson about better prompting. A useful age constraint might have changed the output, but the established route for catching a bad output was also bypassed. Midnite's lack of approval did not prevent the communication from reaching the public or remove the advertiser's exposure to the ruling.

The gap between a documented process and an executed process appears well beyond this case. An EY US survey published on 15 September questioned 202 senior AI executives at organisations with at least $1 billion in annual revenue. Although 98% reported formal AI governance policies, 47% said their organisation had previously failed to apply its governance process to an urgent deployment. The survey does not show that the Midnite case is typical, but it illustrates the same operating tension: the policy can exist while the work travels around it.

A review checkpoint only works when the asset reaches it and when the reviewer has the relevant rule, the full communication and enough authority to stop or change the work. Merely placing a name in an approval matrix does not create meaningful oversight.

That point echoes a September 2026 report from Parliament's Joint Committee on Human Rights. In recommending a new AI Bill, the Committee argued that merely having a human in the loop is insufficient for meaningful human involvement. Its proposals are not enacted law and address a much wider field than advertising, but the principle travels: human review has value only when the person can understand, challenge and alter the result.

Generative marketing needs layered compliance

The Midnite ruling points towards three layers of control, each doing a different job.

Before generation, teams can translate stable and known restrictions into the environment that creates the asset. Some belong in prompts or templates, while others are better expressed as deterministic system rules, restricted options, approved source libraries or requirements for supporting evidence. A model should not be invited to invent a regulated claim and then leave a reviewer to discover that it lacks substantiation.

After generation, the asset needs to be assessed as a customer will encounter it. Automated checks may identify missing disclosures, prohibited terms or visual features that require attention. Specialist review remains necessary where compliance turns on likely interpretation, prominence, overall impression or contextual judgement. The generated output, rather than the intent behind it, is the object being reviewed.

Before publication, permissions must enforce the agreed route. The right client, manager or specialist needs to approve the right version in the right context. Affiliate and agency work should not become publishable merely because somebody can access an ad account. The workflow should preserve the prompt, output, edits, evidence and decision so the organisation can reconstruct what happened.

These controls are not interchangeable: publication permission cannot improve an omitted generation constraint, a careful prompt cannot certify the output and a post-generation scan cannot ensure that client approval occurred. Layering matters because each control catches a different kind of failure.

The same model extends beyond gambling

The specific age rule in this case belongs to gambling advertising. Other regulated categories have different legal tests, so the ASA's conclusion should not be transplanted wholesale into financial services, healthcare or insurance.

The operating-model lesson is broader: a financial promotion generator may need restrictions on unsupported performance claims before drafting, an assessment of balance and prominence after drafting and specialist approval before release. A healthcare image generator may need constraints on prohibited depictions, review of the actual visual claim and publication rights limited to authorised users.

Generative systems make these distinctions more important because they expand the number of moments at which a communication can change. The prompt, reference material, model output, human edit and channel adaptation can each introduce a new fact or alter the overall impression. Treating compliance as one final gate asks a single review to recover every earlier omission.

The Midnite ad lasted only a few hours, yet it still became a published ruling because its fictional character created a clear impression of age and the usual approval process, although documented, never touched the work.

As marketing becomes more generative, compliance cannot sit only at final approval. Organisations need to decide which rules constrain generation, which require evaluation of the finished communication and which demand explicit specialist authority before publication. The work is not complete until all three have happened.

What teams need to know

What did the ASA find wrong with the Midnite ad?

The ASA concluded that the central AI-generated character seemed to be under 25 while gambling. That breached the CAP Code rules for gambling advertising.

Did it matter that the character was fictional?

No. The rule concerned whether the person seemed to be under 25. The ASA assessed the overall impression created by the finished ad, not the biological age of a real performer.

Would an age instruction in the prompt have guaranteed compliance?

No. It would have added a relevant generation constraint, but the finished character would still need review because customer perception may differ from the prompt's intent.

Where should generative marketing controls sit?

Across the workflow. Known restrictions can constrain generation, the completed output must be evaluated and publication should require the correct approval authority.

Has Parliament made “human in the loop” review a new legal requirement?

No. The Joint Committee on Human Rights recommended wider legislation and stronger safeguards. Its report supports meaningful oversight as a governance principle, but its proposals are not enacted law.