The EU AI Act: A Definitive Guide for Marketing Teams
June 2026 · Practical compliance guidance for marketers, agencies, and brand teams
June 2026 · Practical compliance guidance for marketers, agencies, and brand teams
Contents
- Executive Summary
- What Is the EU AI Act?
- The Timeline: Key Dates
- Does It Apply to UK Businesses?
- Provider vs. Deployer: What’s Your Role?
- Risk Categories Explained
- Channel-by-Channel Guidance
- The Do’s and Don’ts
- Things to Be Aware Of
- Penalties
- Practical Compliance Checklist
- The UK Regulatory Landscape
1. Executive Summary
The EU AI Act is the world’s first comprehensive AI regulation. It entered into force on 1 August 2024, and the critical deadline for marketing teams is 2 August 2026, when transparency obligations and most high-risk AI rules become fully enforceable.
Here is what you need to know right now:
- It applies to you even if you are based in the UK. If your AI-generated content, ads, or outputs reach people in the EU, you are in scope.
- AI-generated content must be labelled. Images, video, audio, and text created or significantly modified by AI must be disclosed clearly and visibly.
- Deepfakes must be explicitly disclosed. Synthetic depictions of real people in advertising must be identified as AI-generated.
- Some AI practices are already banned. Manipulative AI, social scoring, and exploitation of vulnerabilities have been prohibited since February 2025.
- Penalties are severe. Up to €35 million or 7% of global annual turnover for the most serious breaches.
- You are probably a “deployer,” not a “provider.” Most marketing teams use third-party AI tools. You still have obligations, but they are lighter than those of the companies building the tools.
- The UK has no equivalent law (yet). The UK takes a principles-based, sector-led approach. But that does not exempt UK businesses from the EU Act if they reach EU audiences.
2. What Is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is a legally binding framework that regulates artificial intelligence systems based on the level of risk they pose. It was adopted by the European Parliament in March 2024, entered into force on 1 August 2024, and is being phased in over several years.
The Act does not regulate AI as a category. It regulates AI by use case. The same underlying technology (a large language model, for example) may trigger different obligations depending on how it is deployed. A chatbot answering FAQ questions faces different rules than an AI system profiling individuals for credit decisions.
For marketing teams, the Act is relevant in three ways:
- Transparency: You must disclose when content is AI-generated, when people are interacting with AI, and when deepfakes are used.
- Prohibited practices: Certain uses of AI in marketing are now illegal, including subliminal manipulation, social scoring, and exploiting vulnerabilities.
- Responsibility: You remain responsible for all AI outputs used in your campaigns, regardless of whether the AI tool was built by you or a third party.
Key definition: AI system The Act defines an AI system as “a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” This is broad enough to capture ChatGPT, Midjourney, Google’s Performance Max, Meta’s Advantage+, and most martech tools with AI features.
3. The Timeline: Key Dates
| Date | Status | What happens |
|---|---|---|
| 1 August 2024 | ✅ Done | EU AI Act enters into force. Legal framework established. |
| 2 February 2025 | ✅ Done | Prohibited AI practices banned. Subliminal manipulation, social scoring, exploitation of vulnerabilities. AI literacy obligations begin. |
| 2 August 2025 | ✅ Done | Rules for General-Purpose AI (GPAI) models take effect. Providers of models like ChatGPT, Claude, and Gemini must comply. |
| 2 August 2026 | ⚡ NEXT | The critical deadline for marketers. Article 50 transparency obligations become enforceable. AI-generated content must be labelled. Deepfakes must be disclosed. Chatbot interactions must be identified. High-risk AI system obligations (Annex III) apply. |
| 2 December 2026 | 🔜 Coming | Machine-readable watermarking obligation for AI-generated content from GPAI models already on the market. New prohibitions on “nudifier” AI applications. |
| 2 August 2027 | 🔜 Future | High-risk AI systems in regulated products (Annex I). May also be the new deadline for Annex III systems if the “AI Omnibus” delay is enacted. |
| 2 August 2028 | 🔜 Future | Product-regulated high-risk AI systems (if Digital Omnibus enacted). |
| 2 August 2030 | 🔜 Future | High-risk AI systems used by public authorities that predated the Act. |
⚠️ Important: The August 2026 deadline has NOT been delayed. A proposed “AI Omnibus” package aims to postpone some high-risk AI obligations to December 2027 or August 2028. However, the transparency obligations under Article 50 (labelling AI content, disclosing deepfakes, chatbot identification) remain on track for 2 August 2026. Plan for this date.
4. Does It Apply to UK Businesses?
Yes. Despite Brexit, the EU AI Act has extraterritorial scope, much like the GDPR before it. The Act applies to:
- Providers (developers) who place AI systems on the EU market, regardless of where they are based.
- Deployers (users) whose AI outputs are used by or affect individuals in the EU.
- Any business where the output of an AI system is intended to be used in the EU.
- Businesses with EU subsidiaries or distribution partners that bring AI systems into the EU.
What this means in practice
| Scenario | In scope? |
|---|---|
| UK brand running Google Ads targeting users in France, Germany, or Spain | ✅ Yes |
| UK agency creating AI-generated social media content seen by EU audiences | ✅ Yes |
| UK company using a chatbot on a website accessible from the EU | ✅ Yes |
| UK brand using ChatGPT to write email campaigns sent to EU subscribers | ✅ Yes |
| UK business targeting only UK consumers with no EU reach | ❌ No |
| UK business using AI for internal analytics with no EU-facing output | ❌ No |
The practical test: If a reasonable person in the EU could encounter your AI-generated content, ad, chatbot, or personalised experience, the Act applies to you. It does not matter where the AI was built, where your team sits, or where the servers are hosted.
5. Provider vs. Deployer: What’s Your Role?
The Act distinguishes between two key roles. Understanding which one you occupy determines the scope of your obligations.
Provider (Developer/Supplier)
Any entity that builds, develops, or places an AI system on the market under its own name.
Marketing relevance: You are a provider if you build your own AI tools (e.g., a proprietary content generation platform, a custom ad-targeting algorithm) and offer them to clients.
Heaviest obligations: Risk management, technical documentation, conformity assessments, CE marking, EU database registration, quality management systems.
Deployer (User)
Any entity that uses an AI system in a professional context.
Marketing relevance: You are a deployer if you use third-party tools like ChatGPT, Midjourney, Jasper, Google Performance Max, Meta Advantage+, or any SaaS platform with AI features.
Lighter obligations: Use AI per provider instructions, ensure human oversight, maintain records, be transparent with audiences, ensure AI literacy in your team.
Most marketing teams are deployers. You use AI tools built by others. But you can be both: if you build a custom AI tool and also use third-party tools, you wear both hats and carry both sets of obligations.
Agencies: pay attention. If you are a marketing agency using AI tools on behalf of clients, you are a deployer. But if you build proprietary AI capabilities and offer them as a service, you may also be a provider. The classification is not about your job title; it is about what you actually do with the technology.
6. Risk Categories Explained
The Act classifies AI systems into four risk tiers. Most marketing AI falls into the “limited” or “minimal” category, but some applications can cross into “high” or “unacceptable.”
🔴 Unacceptable Risk — Banned since February 2025
- AI that uses subliminal techniques to manipulate behaviour below conscious awareness
- AI that exploits vulnerabilities (age, disability) to distort behaviour
- Social scoring: classifying people based on social behaviour or personal traits for unrelated treatment
- Emotion recognition in workplaces or educational settings (with exceptions)
- Real-time biometric identification in public spaces (with exceptions)
Marketing relevance: Dark patterns powered by AI that manipulate consumers without their awareness. AI-driven targeting that exploits psychological vulnerabilities. Using AI to generate fake reviews or testimonials.
🟡 High Risk — Strict obligations from August 2026 (Annex III) or later (Annex I)
- AI in critical infrastructure, education, employment, law enforcement
- AI systems that profile individuals for credit, insurance, or essential services
- AI used in democratic processes (elections)
Marketing relevance: Generally not high-risk. However, AI profiling for financial product marketing (credit cards, loans, insurance) could trigger high-risk classification. Targeted job advertisements using AI profiling may also qualify.
🔵 Limited Risk — Transparency obligations apply
- Chatbots: must disclose they are AI
- Deepfakes: must be labelled as AI-generated
- AI-generated content: must be marked as artificially generated
- Emotion recognition systems: must inform users
Marketing relevance: This is where most marketing AI lives. Every piece of AI-generated ad copy, image, video, or social media post must be labelled. Every chatbot must identify itself. Every deepfake must be disclosed.
🟢 Minimal Risk — No specific obligations
- AI-powered spam filters
- AI-enhanced video game NPCs
- Basic recommendation engines
Marketing relevance: AI tools used for internal analytics, basic A/B test optimisation, or spam filtering generally fall here. No specific AI Act obligations, though existing laws (GDPR, consumer protection) still apply.
7. Channel-by-Channel Guidance
📝 Content Creation (ChatGPT, Claude, Gemini, Jasper, etc.)
If you use generative AI to write blog posts, social media captions, email copy, ad headlines, or any text that reaches EU audiences:
- Visible labelling required. AI-generated text published to inform the public on matters of public interest must be disclosed. The label should be clear, concise, and placed at the beginning or near the content.
- Exception for editorial oversight. If the content has undergone “substantial human review and editorial responsibility,” the labelling requirement may not apply. This means genuine editing, fact-checking, and rewriting, not just pressing “accept” on a ChatGPT draft.
- Machine-readable marking. By December 2026, AI-generated content must also carry embedded technical markers (watermarks or metadata) identifying it as AI-generated.
- Copyright compliance. GPAI providers must publish summaries of copyrighted training data. Deployers should be aware that AI-generated content may carry copyright risks.
Practical impact: If your content team uses ChatGPT to draft a LinkedIn article or a blog post that EU readers will see, you need a disclosure policy. “This article was created with the assistance of AI” or similar.
🔍 Google Ads / Paid Search
Google Ads uses AI extensively: Performance Max campaigns, responsive search ads, automated bidding, AI-generated ad copy and assets.
- You are the deployer. Google is the provider. You are responsible for how you use the outputs.
- AI-generated ad assets. If Google’s AI generates ad copy, images, or video for your campaigns reaching EU users, transparency obligations apply. Google is likely to build compliance features into its platform, but you remain responsible for verifying they work.
- Targeting restrictions. The Act prohibits AI systems that classify people based on social behaviour, socio-economic status, or personal characteristics in ways that lead to unfavourable treatment. Review your audience targeting.
- Automated campaigns do not remove your responsibility. Even when ads are generated or distributed through automated platforms, the advertiser is responsible.
Practical impact: Audit your Performance Max and Advantage+ campaigns. Understand what assets Google’s AI is generating. Ensure your targeting does not rely on prohibited classification methods.
📱 Paid Social (Meta, TikTok, LinkedIn, X)
Meta’s Advantage+ campaigns, TikTok’s Smart Creative, LinkedIn’s AI-powered targeting: all use AI to generate creative, optimise delivery, and target audiences.
- Platform-level labelling. Meta already labels AI-generated content with “AI info” tags. TikTok and others are implementing similar systems. Platform labels do not absolve you of your obligations.
- Your AI-generated creative. If your team uses AI tools (Midjourney, DALL-E, Canva AI) to create ad visuals or video for paid social, these must be labelled as AI-generated when shown to EU users.
- Deepfake rules apply. Synthetic imagery of real people (celebrities, influencers, or realistic-looking AI-generated “stock” people) must be explicitly disclosed.
- Targeting by sensitive categories is prohibited. The Act, combined with the Digital Services Act, bans targeted advertising based on sensitive personal data and prohibits targeted advertising to minors.
Practical impact: Keep a register of all AI-generated creative assets used in paid social campaigns targeting EU audiences. Review audience segments for prohibited classification.
📣 Organic Social Media
The Act does not differentiate between paid and organic content. If AI-generated content is published publicly and could reach EU individuals, transparency obligations apply.
- AI-written posts. If your brand uses ChatGPT or similar tools to draft social media posts published without substantial human editing, they should be labelled as AI-generated.
- AI-generated images and video. Posts containing AI-generated visuals must carry visible disclosure.
- AI-assisted vs. AI-generated. The line is not yet clearly defined. If AI does the heavy lifting and a human merely reviews, it is likely AI-generated. If a human writes and uses AI for minor assistance (grammar checks), it is less likely to trigger the obligation.
- Exception for creative/satirical content. Content that is “evidently artistic, creative, satirical, fictional or analogous” may be exempt, provided the public is not misled.
Practical impact: Establish a clear internal policy on when AI assistance becomes AI generation. When in doubt, label.
📧 Email Marketing
- AI-personalised content. If you use AI to personalise email content (subject lines, product recommendations, dynamic copy), the personalisation itself is unlikely to trigger labelling unless it crosses into prohibited profiling categories.
- AI-generated email copy. If the substantive content is AI-generated, disclosure may be required, particularly for emails informing the public on matters of public interest.
- Chatbots in email. If campaigns drive to AI-powered chatbot interactions, the chatbot must disclose it is AI.
🤖 Chatbots and Conversational AI
- Mandatory disclosure. Users must be clearly informed they are interacting with an AI system “at the latest during the initial interaction.” This applies to website chatbots, WhatsApp Business bots, Messenger bots, and any AI-powered customer service tool.
- No exceptions. Even if the chatbot is highly human-like, it must identify itself as AI.
- Emotion recognition. If your chatbot uses sentiment analysis or emotion recognition, individuals must be informed.
🎯 Personalisation and Targeting
- Prohibited: Social scoring. AI that classifies people based on social behaviour or personal characteristics for unfavourable treatment in unrelated contexts is banned.
- Prohibited: Exploitation of vulnerabilities. AI targeting that identifies and exploits age, disability, or economic vulnerability is banned.
- Prohibited: Subliminal manipulation. AI that uses subliminal techniques to manipulate behaviour below conscious awareness is banned.
- GDPR still applies. The AI Act complements, does not replace, the GDPR. Consent, data minimisation, and the right to not be subject to automated decision-making all remain in force.
8. The Do’s and Don’ts
✅ Do
- Audit every AI tool in your marketing stack
- Classify each tool by risk level
- Establish a clear AI content labelling policy
- Train your team on AI literacy obligations
- Keep records of AI-generated content and the tools used to create it
- Ensure all chatbots identify themselves as AI
- Review audience targeting for prohibited categories
- Implement human oversight processes for AI-generated content
- Check vendor compliance (are your AI tool providers meeting their obligations?)
- Stay informed on the European Commission’s Code of Practice and implementation guidelines
- Build disclosure into your creative workflow, not as an afterthought
- Document your compliance efforts (demonstrable good faith matters)
❌ Don’t
- Use AI to generate fake reviews, testimonials, or endorsements
- Deploy subliminal or manipulative AI techniques
- Use AI for social scoring or behavioural classification
- Exploit vulnerable groups (age, disability, economic status) through AI targeting
- Present AI-generated deepfakes as real without disclosure
- Assume platform-level labels absolve you of responsibility
- Ignore the Act because “we’re a UK business”
- Assume organic social media is exempt from labelling rules
- Use emotion recognition AI without disclosure
- Wait until August 2026 to start preparing
- Assume your agency’s AI use is their problem, not yours (both parties are responsible)
- Treat the AI Act as a one-time compliance exercise; it will continue to evolve
9. Things to Be Aware Of
The “deployer” obligation is lighter, but it is not zero
Many marketing teams assume that because they use third-party AI tools, the compliance burden falls entirely on the tool provider. It does not. As a deployer, you must use AI tools according to the provider’s instructions, ensure human oversight, maintain records, be transparent with your audience, and ensure your team has adequate AI literacy.
The Act interacts with existing legislation
The EU AI Act layers on top of:
- GDPR: Data protection, consent, automated decision-making rights
- Digital Services Act (DSA): Platform obligations, advertising transparency, bans on targeted ads to minors and based on sensitive data
- Digital Markets Act (DMA): Fair competition in digital advertising
- Unfair Commercial Practices Directive: Consumer protection against misleading and aggressive practices
- ePrivacy Directive: Cookie consent and electronic communications
A single marketing campaign may trigger obligations under multiple regulations simultaneously.
The “substantial human review” exception is not a loophole
The Act exempts AI-generated text from labelling if it has undergone “substantial human review and editorial responsibility.” This does not mean glancing at a ChatGPT output and clicking publish. It means genuine editorial engagement: fact-checking, rewriting, restructuring, and exercising independent judgment.
Platform compliance features are your starting point, not your finish line
Google, Meta, TikTok, and other platforms are building AI disclosure features into their advertising tools. These are helpful, but they do not cover all your obligations. You are responsible for your own AI use, your targeting methods, and your overall compliance posture.
The Code of Practice is coming
The European Commission is expected to publish a Code of Practice on AI-generated content in 2026. This will provide practical implementation guidance for the transparency obligations. Until it is published, some details remain ambiguous. Build flexibility into your compliance processes.
AI literacy is a legal requirement
Since February 2025, both providers and deployers must ensure that staff interacting with AI have “a sufficient level of AI literacy.” For marketing teams, this means training on what AI tools you use, what they can and cannot do, what the risks are, and what your legal obligations are.
Enforcement will be real
The EU AI Office has enforcement powers from August 2026. National competent authorities in each member state will also enforce. The EU has a track record of enforcing digital regulations (GDPR fines have exceeded €4 billion cumulatively). The AI Act will be no different.
10. Penalties
| Violation | Maximum Fine |
|---|---|
| Prohibited AI practices (subliminal manipulation, social scoring, exploitation of vulnerabilities) | €35 million or 7% of global annual turnover |
| Non-compliance with high-risk AI system obligations | €15 million or 3% of global annual turnover |
| Failure to comply with transparency obligations (Article 50) | €15 million or 3% of global annual turnover |
| Providing incorrect, incomplete, or misleading information to regulators | €7.5 million or 1% of global annual turnover |
For SMEs and startups: The Act includes proportionality provisions. Penalties are calibrated to be “effective, proportionate and dissuasive,” with lower caps for SMEs and startups. But “lower” is relative: a fine of €7.5 million or 1% of turnover is still significant.
11. Practical Compliance Checklist
AI Inventory and Classification
- Complete audit of all AI tools used in marketing (including embedded AI in platforms like Google Ads, Meta, HubSpot, Mailchimp)
- Each tool classified by risk level (unacceptable, high, limited, minimal)
- Provider vs. deployer role determined for each tool
- Vendor compliance verified
Content and Creative
- AI content labelling policy established and communicated to all content creators
- Clear internal guidelines on when “AI-assisted” becomes “AI-generated”
- Disclosure language defined for AI-generated content across channels
- Deepfake disclosure process in place for any synthetic imagery of real people
- Human review process documented (and it is genuine, not perfunctory)
- Register of AI-generated assets maintained
Channels and Targeting
- All chatbots and conversational AI identified as AI in the first interaction
- Audience targeting reviewed for prohibited categories
- Automated campaign outputs audited (Performance Max, Advantage+, etc.)
- Email personalisation reviewed for compliance
Team and Process
- AI literacy training delivered to all marketing staff who use AI tools
- Designated compliance owner for AI Act obligations
- Incident response process for AI-related compliance failures
- Client contracts updated (for agencies) to address AI Act responsibilities
Monitoring and Documentation
- Process for monitoring European Commission guidance and Code of Practice updates
- Compliance documentation maintained and up to date
- Regular review cadence established (quarterly minimum)
- Records of AI system logs maintained for at least six months (for high-risk systems)
12. The UK Regulatory Landscape
The UK has taken a fundamentally different approach to AI regulation. Understanding the differences is essential for UK-based marketers who also operate in EU markets.
The UK approach: principles-based, sector-led
The UK does not have a single, comprehensive AI law. Instead, it relies on existing sectoral regulators (the ICO, FCA, CMA, ASA) to apply cross-cutting principles to AI within their domains:
- Safety, security and robustness
- Appropriate transparency and explainability
- Fairness
- Accountability and governance
- Contestability and redress
What the UK has done
- Data Use and Access Act: Now in force. Changes to automated decision-making, legitimate interests, and new criminal offences for non-consensual deepfakes.
- AI Security Institute: Tests and evaluates frontier AI models for safety.
- Regulatory sandboxes: The Regulating for Growth Bill (announced May 2026) will put AI regulatory sandboxes on a statutory footing.
- Advisory AI Growth Lab: Launched June 2026. Legislation expected Q4 2026.
What the UK has NOT done
- No comprehensive AI Act equivalent
- No mandatory risk classification system
- No legally binding AI-specific transparency obligations
- No AI-specific penalties regime
What this means for UK marketers
| If you… | You need to comply with… |
|---|---|
| Target only UK consumers | UK law (ASA rules, GDPR UK, Data Use and Access Act, consumer protection law). No EU AI Act obligations. |
| Target EU consumers | Both UK law AND the EU AI Act. The stricter standard applies. |
| Have EU subsidiaries or partners | Both. The EU entity has direct obligations. |
| Are a UK agency with EU clients | Both. Your work product, delivered to EU audiences, is in scope. |
The dual compliance reality: If you operate in both markets, build to the higher standard. The EU AI Act’s transparency and prohibited practices rules are more prescriptive than anything the UK currently has. Compliance with the EU Act will likely exceed UK requirements, making it the sensible baseline.
Disclaimer: This guide is for informational purposes and does not constitute legal advice. The EU AI Act is complex and continues to evolve. The European Commission is expected to publish additional guidelines and a Code of Practice in 2026. For specific compliance questions, consult a qualified legal professional with expertise in EU digital regulation.
Prepared June 2026. Based on publicly available guidance from the European Commission, the AI Office, the ASA, and legal analysis from leading law firms.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.