Subscribe
Learn Library

The AI Act Is Here — Should Marketers Panic?

This article explains how the EU AI Act impacts marketers, detailing its risk-tier system and relationship with GDPR. It outlines five actionable steps, including inventorying AI tools, auditing vendors, and updating contracts to ensure compliance and build brand trust.

ai-marketingworkflow
2026-08-08Go Next Marketer6 min read

A few days ago, a friend who works as a marketing director messaged me, sounding urgent: "Did you see? That EU AI law officially took effect on August 2. My team uses AI every day to generate images, write copy, and run customer-service bots — are we about to step on a landmine?"

I replied: Yes. And it's worse than just stepping on a landmine.

But panic won't help. First, you have to understand one thing: what does this law actually regulate, and what does it leave alone?

What Is the AI Act?

Let's start with the basics.

The AI Act — formally the EU Artificial Intelligence Act — was passed in 2024 as a regulation (EU 2024/1689) and, after a transition period, officially took effect on August 2, 2026. It is the world's first comprehensive law dedicated to artificial intelligence.

Its core logic can be summed up in one sentence: regulate by risk tier.

The EU sorts all AI applications into four tiers:

The first tier — minimal risk. Spam filters, AI NPCs in games. Unregulated. Use them freely.

The second tier — limited risk. Here's the key point: this tier hits marketing directly. Chatbots, AI-generated images and copy, synthetic video, deepfakes — all of these fall into this category. It comes with one requirement, and it's non-negotiable: you have to tell users that the content was produced or manipulated by AI. You can't pretend a person wrote it or drew it.

The third tier — high risk. Hiring-screening algorithms, credit-scoring systems, facial recognition, critical infrastructure. These require strict review, documentation, and human oversight.

The fourth tier — unacceptable risk. Banned outright. Social scoring, behavioral manipulation, automated profiling based on race or physiological characteristics — these are off-limits from the start.

AI Act risk tiers — minimal, limited, high, unacceptable

Notice this: the EU didn't say "every AI-generated banner has to go through review." What it provides is a framework, and the final judgment is left to the people using it.

That's exactly what happened when GDPR first landed a few years ago.

How Does It Relate to GDPR?

This is the most-asked question, and the one most people get wrong.

Many assume: we already went through GDPR, our data compliance is sorted, so the AI Act is probably about the same, right?

No.

To put it plainly: GDPR regulates data. The AI Act regulates systems. Two laws, running in parallel, each governing its own domain, both in force at the same time.

Consider an example. You use a generative AI tool to power personalized recommendations for ad targeting. The tool touches users' personal information, so GDPR applies — you need a legal basis for data processing, user consent, and guarantees around the right to erasure(the GDPR "right to be forgotten"). At the same time, the tool is an AI model, so the AI Act applies — you have to ensure the output doesn't carry discriminatory bias, and synthetic content has to be labeled.

You can't dodge either one.

That raises a practical issue: where you used to defend just one front — data protection compliance — you now have two. It makes sense that the legal team's workload just doubled.

The fines are worth a look, too. GDPR's top penalty is EUR 20 million or 4% of global turnover. The AI Act goes harder — up to EUR 35 million or 7% of global turnover. And turnover is calculated globally, not just within the EU. For multinational brands, that's no laughing matter.

What Should Marketers Actually Do Now?

We've covered a lot of framework. When it comes down to execution, it really comes down to a few things.

First — take inventory.

Which AI tools are actually in use across your company? Don't just look at the marketing department's procurement list. The tools employees quietly use on their own, plugin features embedded in existing software, the ChatGPT Plus subscription a marketing assistant bought on their own to save time — this "shadow AI"(tools adopted without official approval)is where the real landmines are.

Build a table that lays out: tool name, purpose, whether it touches user data, and whether the output gets published externally. Then update it regularly — don't let it become a one-time static document.

Second — audit your vendors.

Most of the AI systems your team uses aren't built in-house — they're bought. So the questions follow: where does the model's training data come from? Are there copyright risks? Has the vendor itself achieved compliance?

A key design choice in the AI Act is that responsibility is distributed along the supply chain. The provider(the developer)has its obligations; the deployer(the user)has its own. Buying a tool doesn't mean you can offload all responsibility onto the vendor.

So the next time you sign a contract with a vendor, add one question: where's your declaration of conformity(the vendor's formal compliance statement)?

Third — rewrite your contracts.

Contracts need to spell out who bears responsibility when something goes wrong. Legally, you can't offload all liability onto the other side — but you can use contracts to make the liability controllable and allocable.

Fourth — train your people.

AI literacy isn't just for the tech team. Copywriters, designers, social-media managers in the marketing department — anyone producing content with AI tools needs to know what can be published, what can't, and how anything published must be labeled.

And don't just read slides at people during training. Walk through real campaign cases: does this banner count as synthetic content? Does it need a watermark? Should the customer-service bot disclose what it is upfront?

Fifth — pick the right partners.

If outsourcing, agencies, or managed-service providers are part of your execution chain, they need to understand these rules too. No matter how solid your own compliance is, if a partner drops the ball somewhere along the line, the reputational hit still lands on you.

Five concrete actions for marketers — inventory, audit, contracts, train, partners

Is Compliance Actually Worth It?

One last thing that's worth being honest about.

Preparing for all of this does take time and money. Every AI tool you bring in has to be evaluated, put through an approval process, and documented. Standardized one-size-fits-all solutions don't work anymore — each tool has to be reviewed individually.

But look at it from another angle.

A brand that has done compliance well — what does that mean? It means you can look users in the eye and say: we use AI, we know where the boundaries are, and we label everything clearly. That transparency itself is trust.

And trust is a brand's most expensive asset.

When GDPR first came out, there was a wave of companies that thought the sky was falling. And then? The ones that survived turned "data protection" into a competitive badge of honor.

The AI Act will probably follow the same path. The early preparers win. The late ones pay fines.

I'm not certain whether this law will eventually be amended, loosened, or watered down when individual countries implement it. But one thing is certain: using AI transparently — there is no going back from that.

The AI Act Is Here — Should Marketers Panic? | Go Next Marketer