Generative AI live: what holds up in a real brand activation
An AI photobooth or a DOOH screen forgives nothing: queues, light, network and moderation fail in front of everyone. This is our guide to designing the flow, choosing models, getting the right consent and measuring without inventing results.
In a live activation, generative AI competes with the queue: every second of generation, every image rejected by a filter and every network drop is visible. Current image models (Google's Nano Banana 2 and Pro, OpenAI's GPT Image 2.5) transform selfies with good quality, but with limits on latency, identity references and use in Europe that you must test before promising anything.
A face processed to identify someone is biometric data: sensitive data in Colombia (Law 1581) and a special category in the European Union (GDPR Article 9). Since August 2, 2026, AI Act Article 50 also requires deepfakes to be labelled. Our rule: explicit consent before the photo, automated plus human moderation, scheduled deletion and real funnel metrics.
Why live is a hard environment
Six constraints that never show up in an office demo.
| Constraint | What happens on site | How we design for it |
|---|---|---|
| Latency | OpenAI warns a complex prompt can take up to 2 minutes; Google gives 11 s to 6 min for Veo 3.1 at peak times | Images first, video only as deferred delivery; short, tested prompts |
| Throughput | A queue of 200 people multiplies every extra second | Asynchronous queues, several vendors and verified rate limits |
| Moderation | Vendor filters can reject a legitimate photo | A visual fallback and human review before the screen |
| Light | Backlight and shadows degrade face transforms | Controlled lighting and framing guides in the camera view |
| Network | Event wifi tends to saturate at peak times | Dedicated connection and retries; never a single link |
| Queues and drop-off | If nobody sees a result quickly, people leave | A QR code on the guest's phone so they can wait outside the line |
The practical conclusion: the winner is the model that delivers within the time your audience is willing to wait, with a rejection rate you can absorb, not the most impressive one.
The pipeline, step by step
Seven stages; if one fails, the whole experience falls over.
- Capture. The guest's own phone camera (via QR) or a fixed camera with controlled light. Framing guides and a quality check before upload.
- Consent. Before the photo, not after: purpose, display on a public screen, retention period and a separate box for brand communications. No acceptance, no capture.
- Generation. One fixed, tested prompt per style, with brand references; guests pick from a few options instead of typing free text.
- Moderation. Automated first (vendor filters plus your own), then human for anything going to a public screen. A rejection should return an alternative, not an error.
- Display. Screen, mosaic or DOOH, with the AI-generated label visible from first exposure.
- Print or share. Download, on-site print or email; logos, legal lines and prices are composited on top, never generated.
- Deletion. The original selfie is deleted as soon as the result exists, and the result when the announced period ends. Keep proof of consent, not the face.
Which models to test for faces and styles
Options verified as of September 2026; none replaces your own test with real photos of your audience.
| Model | Strength for an activation | Limit to keep in mind | List cost |
|---|---|---|---|
| Nano Banana 2 (Google, GA May 28, 2026) | Up to 14 references, 4 for characters and 3 for style | Test face consistency on your own photos | $0.067 per 1K image ($67 per 1,000) |
| Nano Banana 2 Lite (GA Jun 30, 2026) | Google's cheapest option, with ultra-low latency per the company | 1K only, no character or style references | $0.0336 per image ($33.60 per 1,000) |
| Nano Banana Pro (GA May 28, 2026) | Studio quality and 4K; up to 5 character references | Pricier: for showcase pieces more than volume | $0.134 (1K or 2K) and $0.24 (4K) |
| GPT Image 2.5 Sunburst and Flare (OpenAI, Sept 8, 2026) | Sunburst for precise editing, Flare for fast generation; up to 3840 px | OpenAI says a complex prompt can take up to 2 minutes and a recurring character may lose consistency | Per token: $8 per 1M image input, $30 per 1M image output |
| Qwen-Image (Alibaba) | Open weights under Apache 2.0, commercial use allowed | Self-hosted: you run the GPUs, queue and moderation | Your infrastructure |
| FLUX.2 [dev] and HunyuanImage 3.0 | Popular open weights | FLUX.2 [dev] has a non-commercial licence; HunyuanImage 3.0's licence excludes the EU, the UK and South Korea | Not usable without the right licence |
Two lessons from this table. First, the cheapest option (Nano Banana 2 Lite) takes no character references, which is exactly what a face swap needs; for identity-preserving transforms the real comparison is between Nano Banana 2, Pro and GPT Image 2.5. Second, models change fast. The original Nano Banana shuts down on October 2, 2026 and OpenAI closed the Sora API on September 24, so your pipeline must be able to switch vendors without rebuilding the experience.
For video, Veo 3.1 generates 4, 6 or 8-second clips and only allows adult people (allow_adult) in the EU, the UK, Switzerland and the Middle East and North Africa; Gemini Omni Flash cannot edit uploaded videos in the EEA, Switzerland or the UK and restricts images of minors there. Live, treat video as a deferred delivery by email, not an on-screen result.
Consent, biometric data and minors
A selfie is personal data. It becomes biometric data when processed through technical means that allow the person to be uniquely identified: GDPR recital 51 says exactly this about photographs. A face swap that extracts facial geometry or a face vector to transfer identity comes very close to that line, so our rule is to always treat it as biometric data.
European Union. GDPR Article 9 prohibits processing biometric data for the purpose of uniquely identifying a person, save for exceptions such as explicit consent (Article 9(2)(a)). Large-scale processing of these categories also requires a data protection impact assessment (Article 35). And if the experience infers emotions or categorises people by biometric traits, AI Act Article 50(3) requires informing them.
Colombia. Law 1581 of 2012 classifies biometric data as sensitive (Articles 5 and 6) and requires explicit authorization to process it, on top of prior, informed authorization you can prove (Article 9). The SIC's Circular 002 of 2024 asks for a privacy impact study before deploying high-risk AI, and fines reach 2,000 monthly minimum wages, with possible closure of operations involving sensitive data.
- Minors: our rule is to keep them out of face transforms unless a parent or legal guardian authorizes it on site. Some vendors already restrict this: Gemini Omni Flash limits images of minors in the EEA, Switzerland and the UK.
- Retention: announce short periods and enforce them with automatic deletion. Google, for example, deletes Veo videos from its servers after 2 days; your copies in galleries, CRM or screens are your responsibility.
- Transfers: if the AI vendor is outside Colombia or the EU, sign the transmission contract or the relevant clauses before the event, not after.
Brand safety and content labelling
Since August 2, 2026, AI Act Article 50 splits the work: providers must mark outputs in a machine-readable way, and whoever deploys a deepfake must disclose it. A realistic portrait of a real person, transformed and shown in public, can be a deepfake in the legal sense; if the work is evidently artistic or fictional, the duty is lighter but does not disappear.
The Commission's code of practice, finalised on June 10, 2026, spells out how: an icon or label perceivable at first exposure without any user action (for example, top right), at the start and at regular intervals in videos, and applicable offline too, meaning on your physical screens. For evidently creative works the icon may sit in notes or credits, but it must still be perceivable at first exposure. The EU published optional icons on September 24, 2026.
Technical provenance helps but is not enough on its own: images from Google's models carry SynthID and OpenAI Media Service is C2PA-certified, yet no out-of-home operator appears on the C2PA Conforming Products List as of September 2026. In France, the influencer law also requires the mention "Images virtuelles" on commercial content showing AI-generated faces or silhouettes.
Our reading: labelling costs little, and the real risk lies in execution. Per IAB, 73% of Gen Z and Millennial consumers say disclosure would increase or not change their likelihood to buy, and McDonald's Netherlands pulled an AI-generated Christmas ad in December 2025 after critics called it "AI slop".
What we have built at Slash
Six projects and what each one teaches about the live pipeline.
- L'Oréal Guardians: a generative AI face swap in Celebrate Consumer Care (pick a Guardian and your selfie becomes a brand avatar) and, as the centrepiece, a gigapixel Three.js mosaic where hundreds of avatars form the logo, navigable in 3D for demos and lobbies.
- Nigloland × Supersonic / L'Oréal: a Belle Époque photo souvenir in the park, with a QR journey, attraction map, in-scene selfie, email capture and AI composition in French and English, without a heavy booth.
- Peoplesnap: Slash Experience's white-label photobooth web app. The guest's phone is the activation: QR, selfie, AI editing (100+ parameters, moderation included), social sharing, print and mosaics on DOOH screens, with first-party capture into the CRM.
- Alain Afflelou · Magic Sunny: a virtual sunglasses try-on with four selfies, terms acceptance up front and a clear camera-permission screen before sharing or saving.
- Cartier · Trinity 100: a branded photobooth in premium malls, three photos for the ring's three bands, on-site print and data into the CRM; we rolled it out again in Bogotá, Panama and São Paulo.
- JCDecaux × Transmilenio: live data on more than 3,000 digital totems in Bogotá. Not generative AI, but it shows what DOOH at scale demands: an architecture that pushes content to thousands of screens with low latency.
The common pattern: the guest's phone as the entry point, consent and permissions before the camera, and a result that travels from the phone to a screen, a print or the CRM.
How to measure, and a checklist for your team
We don't publish generic conversion rates: they depend on the venue, the audience and the mechanic. Track the full funnel with your own events, from the first scan to the CRM, and compare against an activation without AI when you can.
- Participation: scans, consents, captures and approved results; the drop between steps shows where the flow breaks.
- Time: queue wait, time to result and dwell time in front of the screen.
- UGC: downloads, shares, prints and posts that mention the brand.
- CRM: sign-ups with marketing consent, separate from the photo consent.
- Quality and cost: moderation rejections, retries per image and cost per participant.
Checklist for planning an activation
- Set the goal (data, reach or experience) and the metric that proves it.
- Test two or three models with real photos: skin tones, ages, glasses and venue lighting.
- Measure latency and rejections under peak conditions, not in the office.
- Write the consent with your legal team: purpose, public screen, retention, minors and transfers.
- Design moderation: automated filter, human review and a visual fallback.
- Plan the AI label on screens and prints from first exposure.
- Secure a dedicated network, a backup vendor and offline capture.
- Schedule deletion and check after the event that it happened.
Key takeaways
- Live, the winning model is the one that delivers within the time your audience will wait, not the flashiest in a demo.
- Nano Banana 2 Lite is Google's cheapest, but it takes no character references: for face swaps, compare Nano Banana 2, Pro and GPT Image 2.5.
- Treat every face swap as biometric data: explicit consent before the photo, minors out and scheduled deletion.
- Since August 2, 2026, deepfakes must be labelled from first exposure, including on physical screens.
- Measure the full funnel, from scan to CRM, before promising any numbers.
Sources
- Image generation (Nano Banana models)
- Gemini API pricing
- Generate videos with Veo 3.1
- Gemini Omni Flash
- Image generation guide
- API deprecations
- Article 50: transparency obligations for providers and deployers
- Code of Practice on transparency of AI-generated content
- EU icons for labelling AI-generated content
- Regulation (EU) 2016/679 (GDPR)
- Circular Externa 002 de 2024: datos personales en sistemas de inteligencia artificial
- The AI Ad Gap Widens
Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.
The questions we hear often
Is a face swap at an event biometric data?
A photo is personal data; per GDPR recital 51, it becomes biometric when processed through technical means that allow unique identification. Since a face swap works on facial features, we recommend treating it as biometric data: sensitive data in Colombia (Law 1581) and a special category in the EU (GDPR Article 9).
Which image model suits an AI photobooth?
It depends on latency and on how much identity you need to preserve. As of September 2026 we would test Nano Banana 2 ($0.067 per 1K image), Nano Banana Pro for showcase pieces and GPT Image 2.5 Sunburst for precise editing, always with real photos of your audience.
Do generated images on a DOOH screen need a label?
In the EU, if the image is a deepfake, yes: AI Act Article 50 has required it since August 2, 2026, and the code of practice asks for an icon visible from first exposure, offline too. Colombia has no equivalent rule, but we recommend labelling anyway.
Can generated video be used live?
Rarely as an instant result: Google gives Veo 3.1 latencies from 11 seconds to 6 minutes at peak times. It works better as a deferred delivery by email. Veo also only allows adult people in the EU, and Gemini Omni Flash does not edit uploaded videos in the EEA, Switzerland or the UK.
How long can I keep guests' photos?
Only as long as the announced purpose requires. Our recommendation: delete the original selfie as soon as the result exists, and the result when the announced period ends, keeping only proof of consent.
More analysis to read next
Image models in 2026: which to use for brand work
Nano Banana 2 and Pro, GPT Image 2.5, Qwen-Image: which model to use for brand assets, what each image costs and what the AI Act requires since August 2026.
Image, video and audioVideo models in 2026: from demo to ad
Gemini Omni Flash, Veo 3.1, Kling 3.0, Seedance, Wan 3.0: what works for ads, what a second costs, what the Sora shutdown teaches and how to label in the EU.
Image, video and audioRights and provenance of AI content
Who owns AI output? Lawsuits and settlements, vendor indemnities, likeness and voice, AI Act Article 50, C2PA, SynthID and a practical policy for brand teams.
Let's put it in production
Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.
I reply personally. No endless forms, no canned replies.