The EU AI Act Just Changed Marketing Forever. The STAR Framework Was Already Ready.
There is a piece of legislation that will fundamentally reshape how marketers use artificial intelligence, and most marketing teams have not read it. The EU...
There is a piece of legislation that will fundamentally reshape how marketers use artificial intelligence, and most marketing teams have not read it. The EU AI Act, which entered into force on 1 August 2024 and has been rolling out in stages since, is the world’s first comprehensive law on AI. It classifies AI systems by risk level, bans certain practices outright, and imposes transparency obligations that will affect every marketer who uses AI-generated content, chatbots, or algorithmic targeting.
If you are a marketer serving EU customers, regardless of where you are based, this applies to you. The Act has extraterritorial scope, the same logic that made GDPR a global standard, and the penalties are significant: up to €35 million or 7% of worldwide annual turnover for the most serious violations.
But here is what most commentary on the Act misses: the question is not whether your marketing complies with the EU AI Act. The question is whether your marketing was ethical before the Act forced the issue. And that is where behavioural science frameworks like the STAR Framework become not just relevant, but essential.
What the Act Actually Bans
The prohibited practices list is the place to start, because it reveals what the EU considers fundamentally unacceptable in AI-mediated interactions with humans.
Social scoring. AI that evaluates or classifies people based on their social behaviour, personal traits, or predicted characteristics, leading to unfavourable treatment in unrelated contexts. If your marketing AI assigns people scores that determine how they are treated across different products, channels, or pricing tiers, you have a problem.
Manipulative and deceptive AI. Systems that deploy subliminal techniques or purposefully manipulative methods to distort a person’s behaviour in ways they are not aware of. This is the EU’s answer to dark patterns, extended into AI. If your personalisation engine is designed to exploit cognitive biases without the user’s awareness, the Act considers that a fundamental violation.
Exploitation of vulnerabilities. AI that targets people’s vulnerabilities due to age, disability, or specific social or economic situations to distort their behaviour. If your targeting algorithms identify and exploit moments of emotional or financial vulnerability, you are now in prohibited territory.
Read that list carefully. It describes a significant portion of what performance marketing has been doing for the last decade.
The STAR Framework: Built for This Moment
The STAR Framework classifies consumers into four primary psychological types based on their core motivational needs, drawn from Self Determination Theory. Socialisers are driven by relatedness. Thinkers are driven by competence. Adventurers are driven by autonomy. Realists are driven by security. Each type branches into three archetypes, giving twelve distinct profiles with different motivational signatures, communication preferences, and decision-making tendencies.
What makes STAR relevant to the EU AI Act is not the taxonomy itself. It is the philosophical foundation underneath it.
STAR was built on seven psychological pillars: Self Determination Theory, the Big Five personality model, Dual Process Theory, Regulatory Focus Theory, Social Identity Theory, Cognitive Bias Theory, and Appraisal Theory of Emotion. Every one of these frameworks shares a common assumption: that understanding why people do what they do is a prerequisite for communicating with them effectively, and that this understanding carries an obligation to respect the person, not exploit them.
The EU AI Act’s prohibited practices list is essentially a regulatory codification of what happens when you violate that obligation. Manipulative AI exploits cognitive biases without consent. Social scoring reduces people to predicted characteristics. Vulnerability targeting weaponises moments of weakness. STAR’s approach is the opposite: it uses psychological insight to match communication to what people actually need, not to override their decision-making.
The Transparency Problem
The Act’s transparency requirements, which take effect on 2 August 2026, are where most marketers will feel the immediate impact. Chatbots must disclose that they are AI. AI-generated content must be labelled. Deepfakes must be marked. Generative AI systems must implement machine-readable watermarking.
For marketers who have been using AI to generate content, personalise communications, or power chatbots without disclosure, this is a compliance deadline that is now weeks away, not months.
But transparency is not just a legal requirement. It is a trust requirement. And trust, as the STAR Framework demonstrates, is the foundation of every sustainable consumer relationship.
Consider how STAR handles consumer profiling. The STAR CPA (Consumer Profile Assessment) is a self-assessment tool. The user discovers their own type. No one is classified without their knowledge. No algorithm assigns them a score in the background. The profiling is transparent because the person being profileed is the one doing the profiling.
This is exactly the kind of architecture the EU AI Act is pushing towards. Not profiling-as-surveillance, but profiling-as-self-discovery. Not algorithmic classification imposed on people, but psychological insight offered to people. The difference is consent, transparency, and agency.
Risk-Based Regulation Meets Type-Based Marketing
The EU AI Act’s fundamental principle is risk-based classification: not all AI systems pose the same level of risk, so they should not all be treated the same way. The Act establishes four risk tiers, unacceptable, high, limited, and minimal, and applies graduated obligations to each.
This is, conceptually, the same logic that STAR applies to consumer segmentation. Not all consumers need the same communication. Not all segments respond to the same message. Not all psychological types are equally comfortable with the same level of personalisation.
A Socialiser, driven by relatedness, may welcome AI-mediated community recommendations and social proof. They want to know what people like them are doing. A Realist, driven by security, may find the same recommendation intrusive, a signal that someone is watching. A Thinker, driven by competence, wants data and the ability to verify claims independently. An Adventurer, driven by autonomy, wants to explore on their own terms, not be funnelled.
The EU AI Act’s transparency requirements are, in effect, a regulatory recognition of this psychological reality. One-size-fits-all AI-driven marketing does not just produce worse outcomes. It produces ethically questionable outcomes, because it treats all people as though they have the same psychological relationship with being targeted, profiled, and persuaded.
STAR’s approach is to segment by motivation, not by behaviour. This matters because behavioural data tells you what someone did. Motivational insight tells you why they did it. And the why is what determines whether your marketing is welcome or manipulative.
The Vulnerability Question
The Act’s prohibition on exploiting vulnerabilities is the provision that should make every performance marketer pause. Because the entire architecture of modern digital marketing is built on identifying and targeting moments of heightened receptivity, which is, depending on your perspective, either good timing or vulnerability exploitation.
Consider a student searching for accommodation at 2am during clearing. Their search behaviour signals urgency, anxiety, and limited options. A performance marketing algorithm that identifies this moment and serves them a high-pressure, scarcity-driven ad is, arguably, exploiting a vulnerability. A STAR-informed approach would recognise this moment differently. A Realist student in this situation needs reassurance, clarity, and a sense that the system is predictable and fair. A Socialiser needs to know there is a community waiting for them. An Adventurer needs to feel that they still have choices. A Thinker needs data: occupancy rates, contract terms, cancellation policies.
Same situation. Four different psychological needs. Four different ethical responses. The STAR approach does not exploit the vulnerability. It addresses the need.
This is the distinction the EU AI Act is trying to codify. Not “did you target someone effectively?” but “did you respect the person you were targeting?”
What Marketers Should Do Now
The Act’s staged timeline means different obligations apply at different points. Here is what matters for marketing teams:
Already in force: AI literacy obligations. Your marketing team needs to understand the AI systems they are using and the regulatory framework governing them. This is not optional and the deadline has passed.
2 August 2026: Transparency obligations. Chatbots must disclose they are AI. AI-generated marketing content must be labelled. If your content marketing strategy relies on AI-generated text, images, or video without disclosure, you need a labelling system in place now.
2 December 2027: High-risk AI obligations. If your marketing AI systems are classified as high-risk (and consumer profiling for credit, insurance, or essential services could fall here), full compliance requirements apply: risk management systems, data governance, technical documentation, human oversight, and conformity assessments.
Practical steps:
-
Audit your AI marketing stack. Catalogue every AI tool your team uses for content generation, personalisation, targeting, chatbots, and consumer profiling. Classify each against the four risk tiers.
-
Implement transparency now. Do not wait for the August deadline. If your chatbot does not disclose it is AI, fix it today. If your AI-generated content is not labelled, start labelling it.
-
Adopt a type-based, not behaviour-based, targeting philosophy. STAR’s approach to consumer segmentation is inherently more compliant with the Act’s spirit because it respects individual differences in how people want to be communicated with, rather than exploiting behavioural data to override their preferences.
-
Make profiling consensual. The STAR CPA model, self-assessment where the consumer discovers their own type, is the gold standard for ethical profiling. It is transparent, consensual, and empowering. Build your consumer insight strategy around models that give people agency over their own data.
-
Train your team on the ethical foundations, not just the legal requirements. Compliance is the floor. Ethical marketing is the ceiling. The EU AI Act sets minimum standards. STAR’s framework provides a principled approach that exceeds those standards because it was built on respect for human autonomy from the start.
The Bigger Picture
The EU AI Act is not the end of AI in marketing. It is the end of AI in marketing without accountability. The era of algorithmic targeting that treats people as behavioural data points, to be profiled, predicted, and manipulated without their knowledge or consent, is ending. Not because marketers chose to end it, but because legislators decided it was incompatible with fundamental rights.
The STAR Framework was not built in response to the EU AI Act. It was built because understanding what motivates people is more effective, more sustainable, and more respectful than exploiting what they click on. The fact that it now aligns with the regulatory direction of travel is not a coincidence. It is what happens when you build on psychological science instead of behavioural surveillance.
The marketers who will thrive in the post-Act environment are not the ones who find the cleverest compliance workarounds. They are the ones who recognise that ethical marketing and effective marketing were never in conflict. They were always the same thing. The EU AI Act just made it official.
David Chadderton spent his twenties and thirties teaching people how to make life-or-death decisions at forty thousand feet. He now applies the same principles to consumer psychology, which, depending on the brief, can feel equally high-stakes. He’s the creator of the STAR Framework and the author of The STAR Framework: Rewriting the Rules of Consumer Engagement (NYC Big Book Award 2025), The STAR Operating System: Decode Mindset, Understand Motivation, Transform Human Behaviour, and Dear Algorithm, It’s Not Me, It’s You. By day, a Chief Marketing Officer. By night, a behavioural science obsessive who writes The Unoptimised Human because he can’t stop thinking about why people do what they do.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.