Marketing19 min read11 June 2026

The EU AI Act: A Definitive Guide for Marketing Teams

June 2026 · Practical compliance guidance for marketers, agencies, and brand teams

June 2026 · Practical compliance guidance for marketers, agencies, and brand teams


Contents

  1. Executive Summary
  2. What Is the EU AI Act?
  3. The Timeline: Key Dates
  4. Does It Apply to UK Businesses?
  5. Provider vs. Deployer: What’s Your Role?
  6. Risk Categories Explained
  7. Channel-by-Channel Guidance
  8. The Do’s and Don’ts
  9. Things to Be Aware Of
  10. Penalties
  11. Practical Compliance Checklist
  12. The UK Regulatory Landscape

1. Executive Summary

The EU AI Act is the world’s first comprehensive AI regulation. It entered into force on 1 August 2024, and the critical deadline for marketing teams is 2 August 2026, when transparency obligations and most high-risk AI rules become fully enforceable.

Here is what you need to know right now:


2. What Is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is a legally binding framework that regulates artificial intelligence systems based on the level of risk they pose. It was adopted by the European Parliament in March 2024, entered into force on 1 August 2024, and is being phased in over several years.

The Act does not regulate AI as a category. It regulates AI by use case. The same underlying technology (a large language model, for example) may trigger different obligations depending on how it is deployed. A chatbot answering FAQ questions faces different rules than an AI system profiling individuals for credit decisions.

For marketing teams, the Act is relevant in three ways:

  1. Transparency: You must disclose when content is AI-generated, when people are interacting with AI, and when deepfakes are used.
  2. Prohibited practices: Certain uses of AI in marketing are now illegal, including subliminal manipulation, social scoring, and exploiting vulnerabilities.
  3. Responsibility: You remain responsible for all AI outputs used in your campaigns, regardless of whether the AI tool was built by you or a third party.

Key definition: AI system The Act defines an AI system as “a machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” This is broad enough to capture ChatGPT, Midjourney, Google’s Performance Max, Meta’s Advantage+, and most martech tools with AI features.


3. The Timeline: Key Dates

Date Status What happens
1 August 2024 ✅ Done EU AI Act enters into force. Legal framework established.
2 February 2025 ✅ Done Prohibited AI practices banned. Subliminal manipulation, social scoring, exploitation of vulnerabilities. AI literacy obligations begin.
2 August 2025 ✅ Done Rules for General-Purpose AI (GPAI) models take effect. Providers of models like ChatGPT, Claude, and Gemini must comply.
2 August 2026 ⚡ NEXT The critical deadline for marketers. Article 50 transparency obligations become enforceable. AI-generated content must be labelled. Deepfakes must be disclosed. Chatbot interactions must be identified. High-risk AI system obligations (Annex III) apply.
2 December 2026 🔜 Coming Machine-readable watermarking obligation for AI-generated content from GPAI models already on the market. New prohibitions on “nudifier” AI applications.
2 August 2027 🔜 Future High-risk AI systems in regulated products (Annex I). May also be the new deadline for Annex III systems if the “AI Omnibus” delay is enacted.
2 August 2028 🔜 Future Product-regulated high-risk AI systems (if Digital Omnibus enacted).
2 August 2030 🔜 Future High-risk AI systems used by public authorities that predated the Act.

⚠️ Important: The August 2026 deadline has NOT been delayed. A proposed “AI Omnibus” package aims to postpone some high-risk AI obligations to December 2027 or August 2028. However, the transparency obligations under Article 50 (labelling AI content, disclosing deepfakes, chatbot identification) remain on track for 2 August 2026. Plan for this date.


4. Does It Apply to UK Businesses?

Yes. Despite Brexit, the EU AI Act has extraterritorial scope, much like the GDPR before it. The Act applies to:

What this means in practice

Scenario In scope?
UK brand running Google Ads targeting users in France, Germany, or Spain ✅ Yes
UK agency creating AI-generated social media content seen by EU audiences ✅ Yes
UK company using a chatbot on a website accessible from the EU ✅ Yes
UK brand using ChatGPT to write email campaigns sent to EU subscribers ✅ Yes
UK business targeting only UK consumers with no EU reach ❌ No
UK business using AI for internal analytics with no EU-facing output ❌ No

The practical test: If a reasonable person in the EU could encounter your AI-generated content, ad, chatbot, or personalised experience, the Act applies to you. It does not matter where the AI was built, where your team sits, or where the servers are hosted.


5. Provider vs. Deployer: What’s Your Role?

The Act distinguishes between two key roles. Understanding which one you occupy determines the scope of your obligations.

Provider (Developer/Supplier)

Any entity that builds, develops, or places an AI system on the market under its own name.

Marketing relevance: You are a provider if you build your own AI tools (e.g., a proprietary content generation platform, a custom ad-targeting algorithm) and offer them to clients.

Heaviest obligations: Risk management, technical documentation, conformity assessments, CE marking, EU database registration, quality management systems.

Deployer (User)

Any entity that uses an AI system in a professional context.

Marketing relevance: You are a deployer if you use third-party tools like ChatGPT, Midjourney, Jasper, Google Performance Max, Meta Advantage+, or any SaaS platform with AI features.

Lighter obligations: Use AI per provider instructions, ensure human oversight, maintain records, be transparent with audiences, ensure AI literacy in your team.

Most marketing teams are deployers. You use AI tools built by others. But you can be both: if you build a custom AI tool and also use third-party tools, you wear both hats and carry both sets of obligations.

Agencies: pay attention. If you are a marketing agency using AI tools on behalf of clients, you are a deployer. But if you build proprietary AI capabilities and offer them as a service, you may also be a provider. The classification is not about your job title; it is about what you actually do with the technology.


6. Risk Categories Explained

The Act classifies AI systems into four risk tiers. Most marketing AI falls into the “limited” or “minimal” category, but some applications can cross into “high” or “unacceptable.”

🔴 Unacceptable Risk — Banned since February 2025

Marketing relevance: Dark patterns powered by AI that manipulate consumers without their awareness. AI-driven targeting that exploits psychological vulnerabilities. Using AI to generate fake reviews or testimonials.

🟡 High Risk — Strict obligations from August 2026 (Annex III) or later (Annex I)

Marketing relevance: Generally not high-risk. However, AI profiling for financial product marketing (credit cards, loans, insurance) could trigger high-risk classification. Targeted job advertisements using AI profiling may also qualify.

🔵 Limited Risk — Transparency obligations apply

Marketing relevance: This is where most marketing AI lives. Every piece of AI-generated ad copy, image, video, or social media post must be labelled. Every chatbot must identify itself. Every deepfake must be disclosed.

🟢 Minimal Risk — No specific obligations

Marketing relevance: AI tools used for internal analytics, basic A/B test optimisation, or spam filtering generally fall here. No specific AI Act obligations, though existing laws (GDPR, consumer protection) still apply.


7. Channel-by-Channel Guidance

📝 Content Creation (ChatGPT, Claude, Gemini, Jasper, etc.)

If you use generative AI to write blog posts, social media captions, email copy, ad headlines, or any text that reaches EU audiences:

Practical impact: If your content team uses ChatGPT to draft a LinkedIn article or a blog post that EU readers will see, you need a disclosure policy. “This article was created with the assistance of AI” or similar.

Google Ads uses AI extensively: Performance Max campaigns, responsive search ads, automated bidding, AI-generated ad copy and assets.

Practical impact: Audit your Performance Max and Advantage+ campaigns. Understand what assets Google’s AI is generating. Ensure your targeting does not rely on prohibited classification methods.

📱 Paid Social (Meta, TikTok, LinkedIn, X)

Meta’s Advantage+ campaigns, TikTok’s Smart Creative, LinkedIn’s AI-powered targeting: all use AI to generate creative, optimise delivery, and target audiences.

Practical impact: Keep a register of all AI-generated creative assets used in paid social campaigns targeting EU audiences. Review audience segments for prohibited classification.

📣 Organic Social Media

The Act does not differentiate between paid and organic content. If AI-generated content is published publicly and could reach EU individuals, transparency obligations apply.

Practical impact: Establish a clear internal policy on when AI assistance becomes AI generation. When in doubt, label.

📧 Email Marketing

🤖 Chatbots and Conversational AI

🎯 Personalisation and Targeting


8. The Do’s and Don’ts

✅ Do

❌ Don’t


9. Things to Be Aware Of

The “deployer” obligation is lighter, but it is not zero

Many marketing teams assume that because they use third-party AI tools, the compliance burden falls entirely on the tool provider. It does not. As a deployer, you must use AI tools according to the provider’s instructions, ensure human oversight, maintain records, be transparent with your audience, and ensure your team has adequate AI literacy.

The Act interacts with existing legislation

The EU AI Act layers on top of:

A single marketing campaign may trigger obligations under multiple regulations simultaneously.

The “substantial human review” exception is not a loophole

The Act exempts AI-generated text from labelling if it has undergone “substantial human review and editorial responsibility.” This does not mean glancing at a ChatGPT output and clicking publish. It means genuine editorial engagement: fact-checking, rewriting, restructuring, and exercising independent judgment.

Platform compliance features are your starting point, not your finish line

Google, Meta, TikTok, and other platforms are building AI disclosure features into their advertising tools. These are helpful, but they do not cover all your obligations. You are responsible for your own AI use, your targeting methods, and your overall compliance posture.

The Code of Practice is coming

The European Commission is expected to publish a Code of Practice on AI-generated content in 2026. This will provide practical implementation guidance for the transparency obligations. Until it is published, some details remain ambiguous. Build flexibility into your compliance processes.

Since February 2025, both providers and deployers must ensure that staff interacting with AI have “a sufficient level of AI literacy.” For marketing teams, this means training on what AI tools you use, what they can and cannot do, what the risks are, and what your legal obligations are.

Enforcement will be real

The EU AI Office has enforcement powers from August 2026. National competent authorities in each member state will also enforce. The EU has a track record of enforcing digital regulations (GDPR fines have exceeded €4 billion cumulatively). The AI Act will be no different.


10. Penalties

Violation Maximum Fine
Prohibited AI practices (subliminal manipulation, social scoring, exploitation of vulnerabilities) €35 million or 7% of global annual turnover
Non-compliance with high-risk AI system obligations €15 million or 3% of global annual turnover
Failure to comply with transparency obligations (Article 50) €15 million or 3% of global annual turnover
Providing incorrect, incomplete, or misleading information to regulators €7.5 million or 1% of global annual turnover

For SMEs and startups: The Act includes proportionality provisions. Penalties are calibrated to be “effective, proportionate and dissuasive,” with lower caps for SMEs and startups. But “lower” is relative: a fine of €7.5 million or 1% of turnover is still significant.


11. Practical Compliance Checklist

AI Inventory and Classification

Content and Creative

Channels and Targeting

Team and Process

Monitoring and Documentation


12. The UK Regulatory Landscape

The UK has taken a fundamentally different approach to AI regulation. Understanding the differences is essential for UK-based marketers who also operate in EU markets.

The UK approach: principles-based, sector-led

The UK does not have a single, comprehensive AI law. Instead, it relies on existing sectoral regulators (the ICO, FCA, CMA, ASA) to apply cross-cutting principles to AI within their domains:

  1. Safety, security and robustness
  2. Appropriate transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

What the UK has done

What the UK has NOT done

What this means for UK marketers

If you… You need to comply with…
Target only UK consumers UK law (ASA rules, GDPR UK, Data Use and Access Act, consumer protection law). No EU AI Act obligations.
Target EU consumers Both UK law AND the EU AI Act. The stricter standard applies.
Have EU subsidiaries or partners Both. The EU entity has direct obligations.
Are a UK agency with EU clients Both. Your work product, delivered to EU audiences, is in scope.

The dual compliance reality: If you operate in both markets, build to the higher standard. The EU AI Act’s transparency and prohibited practices rules are more prescriptive than anything the UK currently has. Compliance with the EU Act will likely exceed UK requirements, making it the sensible baseline.


Disclaimer: This guide is for informational purposes and does not constitute legal advice. The EU AI Act is complex and continues to evolve. The European Commission is expected to publish additional guidelines and a Code of Practice in 2026. For specific compliance questions, consult a qualified legal professional with expertise in EU digital regulation.

Prepared June 2026. Based on publicly available guidance from the European Commission, the AI Office, the ASA, and legal analysis from leading law firms.

The STAR Framework

If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.