SB StartupBasket
All ideas
77 /100 GO Low complexity

MarkPass — per-asset disclosure ledger for EU ad agencies

Records who reviewed each AI-touched ad, what was disclosed, and whether the label survived publication.

— views
Evaluation Scores
77/100

GO

Overall Score

16
Problem
13
Demand
12
Build
12
Distrib.
11
Revenue
8
Time
5
Defense

MarkPass

1. One-liner

Records who reviewed each AI-touched ad, what was disclosed, and whether the label survived publication.

2. Trend signal — why now?

Three weeks ago the ground moved under every agency that touches generative AI.

Article 50 of the EU AI Act became enforceable on 2 August 2026. Not proposed, not consulted on, not “coming into force in phases” — applicable law, three weeks before I’m writing this. The European Commission confirmed on 31 July 2026 it would begin enforcing from that date. Penalties run to €15 million or 3% of worldwide annual turnover, whichever is higher (Article 99). Enforcement is decentralised to national market surveillance authorities, which means 27 separate regulators with 27 separate appetites for making an example of someone.

Here’s the part that makes this an agency problem rather than an OpenAI problem. Article 50 splits duties: providers mark the file, deployers disclose to the audience. The agency or brand that puts the output in front of an EU viewer is the deployer. Legal commentary is blunt on this — “there is no automatic transfer of responsibility to the maker.” You can’t contract your way out of it by pointing at Midjourney. And the extraterritorial reach catches non-EU businesses running AI creative at European audiences.

The second signal is that agencies are already bleeding money on this, today, independent of any regulator. Meta’s 2026 ad policy requires disclosure on any creative where AI generated, substantially modified, or composited visual or audio content. Undisclosed AI content now accounts for 14% of all Meta ad rejections — the third-largest rejection category. That’s not a compliance abstraction. That’s a paused campaign on a Friday afternoon with a client on the phone.

The third signal is that the obvious technical fix is broken. The European AI Office’s technical guidance names C2PA as the reference implementation for machine-readable marking. But C2PA manifests do not survive the internet. Instagram, X, Facebook, and TikTok strip metadata during upload, transcoding, and re-encoding; manifests break on screenshots, resizing, recompression, and format changes. LinkedIn is the notable outlier that preserves and displays them. So an asset that was fully compliant when it left the studio becomes undetectable at the social layer — and the deployer, who holds the liability, has no artifact proving they ever complied.

And watermarks don’t rescue you either. Anthropic characterises a detected mark as a signal that content may have been “processed by Claude” — which, as one analysis points out, makes it poor evidence for deciding whether a publisher complied with Article 50(4), because a human-drafted piece run through Claude for proofreading carries the same mark.

Meanwhile the Future of Life Institute reported transparency obligations were the second most common trigger in its AI Act compliance checker in 2026, hitting around 33% of respondents.

Put it together: a live legal duty, a daily cash penalty at the ad platform, and a reference technology that fails at exactly the moment it’s needed. The agency is left holding a liability it cannot evidence.

Provenance:

3. The opportunity

The gap is between doing the disclosure and being able to prove you did it, per asset, months later.

Every vendor in this space is selling one of two things. The first is org-level AI governance: policy templates, tool inventories, AI literacy training, a posture document you show once a year. Useful, and I’ve written up that shape before — but it answers “is this company AI-Act-aware?” not “was this specific ad, published on 14 September to a German audience, properly disclosed, and who signed off?”

The second is provenance tech: C2PA signing, watermarking, detection. Genuinely good engineering that dies on contact with a social upload pipeline. It marks the file. It does not create a record that outlives the file.

Nobody is selling the third thing, which is the thing that actually gets asked for in an enforcement letter or a client indemnity dispute: a durable, per-asset, timestamped record of the disclosure decision and the human review behind it.

This maps to a pattern I keep seeing. The duty here is per-item, not per-business. Vendors reliably sell the per-business licence — the annual posture product — because it’s easier to price and easier to sell. The per-item matrix is left to spreadsheets. That’s where the money on the table is.

The specific incumbent worth naming is AI Disclosure Register (ai-disclosureregister.com), which is the closest thing that exists: a 7-question asset assessment producing timestamped PDF decision records, at $49/month or $199/year founding rate. It validates the market — someone independently arrived at the same thesis and is charging for it. But it’s a UK sole trader’s side project with no testimonials, no customer counts, a v1.1.0 ruleset, and a personal email as the contact. More importantly it’s a questionnaire, not a workflow. It sits outside where creative actually gets made and shipped, so it captures a declared intention rather than an observed fact, and it does nothing about the two hard parts: evidencing substantive human editorial review, and checking whether your label actually survived to the live placement.

What a focused team does 10× better: sit inside the delivery workflow, capture the review as it happens rather than reconstructing it from memory, and go look at the published placement to confirm the disclosure is still there.

4. Target market

Primary customer: Owner or ops/traffic director at an independent marketing, creative, social, or performance agency with 5–60 staff, headquartered in the EU (start: Netherlands, Germany, Ireland, Nordics — high English-language business fluency, high AI-tool adoption, active regulators) or running paid social into EU audiences from the UK/US. Typically €400K–€6M annual revenue, 8–40 active client accounts, shipping somewhere between 50 and 800 creative assets a month across Meta, TikTok, Google, and LinkedIn.

Why they buy: Two pains stacked on top of each other, one legal and one operational.

The legal one is the one they lose sleep over but can’t act on. Their client contracts increasingly contain AI warranties. When a client’s legal team asks “can you confirm all deliverables comply with Article 50,” the honest answer today is a shrug and a Slack search. The industry guidance is explicit about what’s required — document “where AI enters, what it changes, who checks the factual substance, who can reject or rewrite it, and who holds final editorial responsibility.” Almost no agency does this. Worse, the same guidance calls out that many agencies describe work as “human reviewed” when the actual review is an account executive scanning a draft for tone and typos — and the Commission has said superficial checks like spell-checking and grammatical correction do not count as substantive editorial control. So a lot of agencies believe they’re covered by an exemption they don’t actually qualify for.

The operational one is the one that gets the credit card out. Ads get rejected. 14% of Meta rejections are undisclosed AI. Each rejection is a scramble: which asset, was AI used, who made it, was it generated or just retouched, do we relabel and resubmit or appeal. That loop runs weekly at a mid-size agency and it burns the most expensive hours in the building.

The operational questions they cannot currently answer, straight from the industry guidance: “Do you know where AI elements are contained in your assets? Can you distinguish between fully AI-generated and merely AI-modified assets? Is labeling ensured throughout the entire process chain — from creation to publication, including after download?”

Rough TAM reasoning: IBISWorld counts 472,000 advertising agency businesses in Europe in a €220.1 billion market. The overwhelming majority are micro-firms; strip to agencies with 5+ staff running paid social and you’re plausibly at 40,000–70,000 addressable firms. Add EU-facing in-house brand marketing teams and non-EU agencies serving EU audiences and the reachable pool grows again. I only need a few hundred of them.

Why now for them: The obligation went live 2 August 2026. Machine-readable marking compliance for already-deployed generative AI runs to 2 December 2026, so there’s a second deadline in the calendar this quarter. Their clients’ procurement and legal teams are writing AI warranties into renewals right now. And the ad rejections are happening today regardless of the regulator.

5. Product sketch (MVP)

  • Asset intake — drop a file or connect the shared Drive/Dropbox folder the creative team already uses. Each asset gets an entry with the tool that made it, version, date, and operator.
  • AI-touch classification — reads embedded C2PA/Content Credentials where they still exist, and where they don’t, prompts the creator with a short structured question set that distinguishes fully AI-generated from AI-modified from assistive-only (the distinction that decides whether disclosure is required at all).
  • Review capture — the named reviewer signs off in the tool with a substantive-review checklist tied to the Commission’s language, not a tick-box “approved”. Captures who held editorial responsibility, what they checked, and what they changed. This is the part that turns a claimed exemption into an evidenced one.
  • Disclosure wording generator — produces the visible label text per placement and per market, in the local language, sized to the platform’s own policy (Meta, TikTok, Google, YouTube, LinkedIn each differ).
  • Live placement check — after publication, fetches the live ad or post and verifies the visible disclosure is present and the manifest state, flagging assets where the label was stripped or lost in transcode. This is the piece nobody else does.
  • Per-asset passport — a permanent, timestamped, exportable record per asset: classification, reviewer, disclosure text, placements, verification results, ruleset version in force at the time.
  • Client-facing attestation pack — one-click PDF/portal export scoped to a single client and date range, for the moment their legal team asks. This is the artifact the agency forwards to win the argument.
  • Rejection triage — paste a Meta/Google rejection ID, get the matching asset record and the specific gap to fix before resubmitting.

6. AI angle — what’s load-bearing

Remove the AI and this becomes a spreadsheet, so let me be precise about where it does real work rather than decorate.

Classification of AI-touch level. The legally operative distinction is between fully AI-generated content, AI-modified content, and assistive use that doesn’t trigger disclosure (grammar correction, research, structuring, first drafts). That judgment currently requires a human who has read the guidance to look at each asset. A vision-and-text model that ingests the asset plus the creator’s short answers and returns a defensible classification with reasoning is the core of the product. At 300 assets a month, that’s the difference between a viable process and no process.

Substantive-review assessment. When a reviewer claims editorial control, the model interrogates the claim against what actually changed — diffing draft against published copy, surfacing whether edits were cosmetic or substantive. This directly targets the failure mode the guidance names: agencies asserting “human reviewed” when the review was typo-scanning. An agency that can show a machine-assessed substantive-edit trail is in a materially stronger position than one with a signature.

Per-market, per-platform disclosure drafting. Generating compliant label wording across 24 EU languages and five platform rulebooks, updated as policies drift, is a language task at a volume no small agency staffs for.

Live placement verification. Vision model reads the rendered published ad and confirms the disclosure is actually visible to a viewer — not merely present in a field somewhere. Given metadata gets stripped, visual verification is the only reliable check, and it’s a genuine AI job.

If you deleted the AI you’d be selling a form. The form is the incumbent, and it’s a $49/mo side project for a reason.

7. Localization angle (if any)

EU-first by construction — this is a European legal duty and the product is worthless outside its shadow. But localization is a real wedge inside the EU, not a checkbox.

Language: disclosure text must be intelligible to the audience, so an agency running Dutch, German, and Polish placements needs three correct labels, not one English one. Twenty-four official languages, and the wording is legally consequential.

27 regulators: enforcement is decentralised to national market surveillance authorities, and Member States set their own penalty rules. Early enforcement posture will vary sharply — Ireland, Germany, and the Netherlands will not move at the same speed as Malta. Tracking which authority is active, and what they’ve actually pursued, is durable local knowledge a global vendor won’t bother maintaining.

Sector overlays: national advertising self-regulatory bodies and sector codes sit on top of the AI Act. Getting those right is unglamorous and defensible.

The non-EU angle is real too: a US or UK agency running paid social at European audiences is in scope, and most don’t know it. That’s a distinct, easily-targeted segment with the same product.

8. Business model — path to $1M–$5M ARR

  • Pricing: €149/mo Studio (up to 150 assets/month, 3 seats, 5 client workspaces), €399/mo Agency (600 assets, 10 seats, unlimited clients, live placement checks, client attestation portal), €899/mo Network (multi-office, API, white-label client portal, priority ruleset updates). Annual prepay at 2 months free.
  • ACV: ~€3,600 blended, assuming the mix skews to Agency tier. Realistic given agencies already pay far more for scheduling, DAM, and reporting tools.
  • Rough math to $1M ARR: 280 agencies at €300/mo average = €1.0M. Out of 40,000+ addressable EU firms, that’s under 1% penetration. This is the comfortable number.
  • Rough math to $5M ARR: ~1,150 customers at €360/mo, or 700 customers at €600/mo with the Network tier and in-house brand teams pulling the average up. Requires expanding beyond agencies into direct brand marketing departments and adding at least one adjacent duty (the December 2026 machine-readable marking deadline, or national ad-code overlays) to justify the higher tier. Reachable in 24–30 months, not 12.
  • Expansion path: per-asset volume is the natural meter and grows with the client’s own business. Then seats as the agency grows. Then the client-facing attestation portal as a per-client-workspace add-on — the agency’s own clients start asking for standing access, which is the best kind of expansion because the customer’s customer is pulling. Longer term, the accumulated per-asset corpus supports an audit-defence service priced separately.

Gross margin is straightforward SaaS minus inference. Vision classification on a few hundred assets a month per customer is cents, not euros. The live placement checks are the only meaningful variable cost and they’re bounded by asset volume, which is what you’re metering anyway.

9. Go-to-market wedge — first 100 customers

  • The Meta rejection channel — the sharpest wedge. Undisclosed AI is the third-largest ad rejection category. Agencies experiencing this post about it in specific places: the PPC and paid-social communities, Meta’s own partner forums, and agency Slack/Discord groups. Build a free “why was my ad rejected for AI disclosure” diagnostic — paste the rejection, get the specific fix and the compliant label text. Free tool, no signup. That tool is the top of the funnel and it solves a problem that is on fire this week, which is what gets a stranger to trust you. Convert diagnostic users to the ledger by showing them the record they wish they’d had.
  • Scrape the agency directories and target on observable evidence. Clutch, Sortlist, and the national agency association directories (BVA in the Netherlands, GWA in Germany, IAPI in Ireland) publish member lists with sites. Pull agencies with 5–60 staff, then check their own published work and Meta Ad Library placements for visibly AI-generated creative with no disclosure. That’s a specific, evidenced, personalised opener: “here are four of your live placements that a market surveillance authority would ask about.” Expect a far better reply rate than a generic AI Act email because you’re showing them their own exposure. 2,000 agencies, personalised video to the top 400, target 8–12% reply.
  • Ride the December 2026 deadline with the people who advise agencies. The machine-readable marking deadline is 2 December 2026 and every EU tech/media law firm and agency-association compliance officer is publishing about Article 50 right now. Co-host webinars with three or four mid-tier firms — they get content and lead-gen, you get the room. Agency associations run compliance briefings for members and are actively looking for practical tooling to point at, because “here’s the law” without “here’s what to do Monday” makes for a bad member briefing.
  • Client-side pull. When one agency issues a client attestation pack, the client’s marketing lead sees a standard their other three agencies don’t meet. Make the pack good-looking and prominently sourced, and let it do referral work. Explicitly ask: “want your other agencies to send these too?”
  • Beachhead the non-EU-but-in-scope agencies. UK and US agencies running EU paid social are in scope and mostly don’t know it. That’s a clean, alarming, true message with almost no competing noise, and those agencies have bigger budgets.

The first 100 is the diagnostic tool plus the personalised exposure outreach. I can see it clearly, which is the bar.

10. Build complexity — justification

Low. File intake, structured records, PDF export, and multi-tenant workspaces are all standard web-stack work. C2PA manifest reading is a solved library problem, not research. The AI classification and disclosure drafting run on off-the-shelf vision-and-text APIs — no fine-tuning, no custom models, no proprietary dataset needed on day one. The genuinely fiddly bits are the live placement verification (fetching and rendering published ads across five platforms, each with different access) and keeping the ruleset current across 27 jurisdictions and five platform policies. The first is scope-limitable — ship v1 checking Meta and LinkedIn only, add TikTok and Google after. The second is ongoing editorial work, which is a moat rather than a build cost.

A technical founder plus a part-time regulatory researcher ships a credible v1 in 8–10 weeks. The free rejection-diagnostic tool ships in two.

11. Gating checklist

GatePass?Note
Legal in target market✅Helping firms comply with a live EU regulation. No grey area.
Ethical — no harm / dark patterns✅Product increases disclosure to end audiences. The incentive points the right way.
Market exists (evidence above)✅Live law with €15M/3% penalties, 14% of Meta rejections, 472K European agencies, and a paying incumbent.
1–5 person team can build this✅Technical founder + regulatory researcher, 8–10 weeks to v1.
Launchable with <$50K / ₹40L✅Off-the-shelf APIs, standard hosting. Main cost is the researcher’s time and outreach tooling.

All five pass.

12. Feasibility score

AxisWeightScoreNotes
Problem intensity2016/20Live legal duty with €15M/3% exposure, plus a weekly operational bleed via ad rejections. Not quite hair-on-fire because enforcement is three weeks old and no agency has been fined yet — the fear is anticipatory, and anticipatory fear converts worse than realised pain. The Meta rejections are what makes it 16 rather than 13.
Demand evidence1513/15Multiple independent hard signals: enforceable regulation with dated deadlines, a competitor charging money, 14% of Meta ad rejections, FLI reporting transparency as the #2 compliance-checker trigger at ~33% of respondents, 472K European agencies. A skeptic nods. Docked for no direct verbatim agency complaints found — the voice evidence is industry-guidance framing of agency questions, not agencies speaking in their own words.
Build feasibility1512/15Standard stack, off-the-shelf AI, 8–10 weeks for a pair. Docked for the live placement verification across five platforms, which is genuinely fiddly and partly at the mercy of platform access.
Distribution clarity1512/15Named directories, a specific free diagnostic tied to a live pain, named associations, and a client-pull referral loop. Conversion on the personalised-exposure play is unproven, and the free tool may attract agencies too small to pay.
Revenue mechanics1511/15€149–899/mo is well within agency tool budgets and the $1M path needs under 1% penetration. Docked because willingness-to-pay for anticipatory compliance is the classic overestimate, and the only pricing benchmark in-category is a $49/mo side project — that’s a thin anchor and it may drag the market’s price expectation down.
Time to first revenue88/10Diagnostic tool in 2 weeks, v1 in 8–10, paid conversion plausible within 4–8 weeks of launch given the December deadline. Not 9–10 because agencies buy on a procurement rhythm and often wait for a renewal or an incident.
Defensibility105/10Execution moat mostly. The real moats compound slowly: accumulated per-asset records create switching cost (your evidence lives here), and the 27-jurisdiction ruleset is tedious editorial work competitors won’t want to maintain. But a well-funded compliance vendor or a DAM incumbent could bolt this on. Month 3 you’re copyable; month 12 the ledger history and ruleset depth start to bite.
Total10077/100

13. Qualitative modifiers

Founder-fit tags

technical-heavy · sales-heavy

Technical enough to build the classification and verification pipeline; sales-heavy because agency owners buy from people who understand agency life and because the association/law-firm channel is relationship work. A founder with agency-world credibility is worth more here than one without.

Key assumptions to validate (3–5)

  1. Assumption: Agencies will pay for evidence of compliance before any enforcement action exists, rather than waiting for the first fine. How to test: 30 structured calls with EU agency owners in the 5–60 staff band. Ask directly what they’ve changed since 2 August, and offer a paid pilot at €149/mo. Count how many put a card down versus how many say “interesting, come back when someone gets fined.” Payment is the only signal that counts.
  2. Assumption: The ad-rejection pain is a strong enough wedge to pull agencies into a compliance product they weren’t shopping for. How to test: Ship the free rejection diagnostic first, standalone. Measure how many users voluntarily ask “how do I stop this happening again” — that’s the conversion mechanism, and if it doesn’t fire, the funnel is broken.
  3. Assumption: Agencies, not their clients, are the buyer. It’s possible the brand’s legal team is the real budget holder and the agency is just the one being asked. How to test: In the same 30 calls, ask who would sign off the spend. If it’s consistently “I’d have to ask the client,” the whole GTM inverts toward brand-side and the pricing model changes.
  4. Assumption: Live placement verification works reliably enough across Meta and LinkedIn to be a headline feature rather than a footnote. How to test: Build the verification path only, run it against 200 known live placements, and measure how often it correctly determines disclosure presence. Below 85% and it becomes a supporting feature, not the differentiator.
  5. Assumption: The exemption confusion is real — that a meaningful share of agencies wrongly believe their “human review” clears Article 50(4). How to test: In discovery calls, ask them to describe their review process, then score it against the Commission’s substantive-review standard. If most already qualify, the review-capture feature loses its punch.

Risk flags

  1. Regulatory softening: The EU has already deferred high-risk obligations to August 2027 via the Digital Omnibus, and there is active political pressure to simplify the AI Act. If Article 50 gets watered down or enforcement is deprioritised, the anticipatory-fear half of the demand evaporates overnight. The Meta rejection pain survives that, which is precisely why the product must not be positioned as AI-Act-only. Build it so it stands on platform-policy compliance alone.
  2. Platform dependency: Live placement verification depends on being able to fetch published ads from Meta, TikTok, Google, and LinkedIn. Access terms change, and Ad Library coverage is uneven. The differentiating feature is the one most exposed to someone else’s product decision.
  3. Incumbent absorption: This is a feature a DAM vendor, an agency management platform, or an established compliance suite could ship. Defensibility is 5/10 for a reason. The counter is speed and depth of the jurisdiction ruleset, plus the accumulated record making migration painful — but that’s a 12-month moat, not a 3-month one.
  4. Market timing — possibly early: Three weeks of enforcement, zero fines. Compliance markets typically don’t open their wallets until someone visible gets hit. This could be six months early, which for a bootstrapper means six months of runway spent on education. The December 2026 machine-readable deadline is the nearest forcing function and the go-to-market should be built around it.
  5. Price anchoring: The only visible in-category competitor charges $49/mo. If the market anchors there, the €399 tier is a hard sell and the $5M path stretches. Mitigate by never competing on the questionnaire — sell the verification and the client attestation pack, which the $49 product cannot produce.

14. Structured verdict

Score:                  77/100
Verdict:                GO
Confidence:             Medium
Best-fit builder:       Technical founder with agency-world credibility, plus a
                        part-time EU regulatory researcher. Someone who has sat
                        in an agency traffic meeting will sell this far better
                        than someone who has only read the regulation.
Time to revenue:        6–10 weeks (free diagnostic at week 2, paid v1 at week 10)
Capital to launch:      $8–12K (€7–11K) — inference, hosting, outreach tooling,
                        and a few weeks of regulatory research contracting
Top 3 assumptions to validate first:
  1. Agencies pay before enforcement exists — 30 calls, offer a €149/mo paid
     pilot, count cards down not head nods
  2. The Meta rejection pain converts into compliance-product demand — ship the
     free diagnostic standalone, measure unprompted "how do I prevent this"
  3. The agency is the buyer, not the brand — ask who signs off; if it's the
     client, the entire GTM inverts
Kill criteria:
  - Abandon if fewer than 4 of 30 qualified agency calls will commit to a paid
    pilot at €149/mo
  - Abandon if the free rejection diagnostic gets 500+ uses with under 5%
    asking about prevention — that means the pain is acute but not adjacent
  - Abandon if Article 50 is materially deferred or narrowed by the Digital
    Omnibus process AND the platform-policy-only positioning fails to close
    10 customers on its own
  - Abandon if live placement verification accuracy stays below 85% on Meta
    after 6 weeks, and no other feature differentiates from the $49 incumbent

15. Next step — 1-week validation sprint

  • Day 1–2: Build the free Meta rejection diagnostic. Nothing else. Paste a rejection reason, get the specific AI-disclosure gap and compliant label text in the right language. Ship it, post it in four paid-social and agency communities. This is a real tool that helps people immediately, which is the only honest way to earn attention.
  • Day 3–4: Pull 300 EU agencies from Sortlist and two national association directories, 5–60 staff, running paid social. Check Meta Ad Library for visibly AI-generated creative without disclosure. Send 80 personalised messages showing them their own live placements and the specific exposure. Book calls.
  • Day 5: Run every call that books. Two questions decide it: what have you actually changed since 2 August? and would you pay €149/mo starting today for a per-asset record and a client attestation pack? Take payment on the call if they say yes — a pilot invoice, not a waitlist.

Falsifiable outcome: 30 qualified conversations. Go if 4 or more commit real money at €149/mo. Below 4, the demand is anticipatory rather than urgent, and the correct move is to keep the free diagnostic running as a tripwire and revisit when the first national authority issues an Article 50 penalty. Head-nods and “definitely interesting” count as zero.

Interested in a detailed proposal?

Get a deep-dive with market research, competitive analysis, and implementation roadmap.

Contact us

info@startupbasket.ai