Subscribe
Learn Library

The EU AI Act Is Live — Marketers, Are You Sweating Yet?

An educational article explaining the EU AI Act's four risk tiers, how it stacks with GDPR, the compliance challenges marketers face around AI-generated ads and content labeling, and six concrete preparation steps.

ai-marketingmetaworkflow
2026-08-04Go Next Marketer9 min read

A few days ago, I was scrolling through my WeChat Moments feed when I saw a post that almost made me spit out my coffee.

On August 2, 2026, the EU's Artificial Intelligence Act (AI Act) officially entered into force.

Not a discussion draft. Not a request for public comment. It's really here.

You might be thinking: what does this have to do with me? I don't even do business in Europe.

I'd suggest you don't scroll past this one.

Why Should a Law Make Marketers Sit Up?

Let me tell you an old story first.

Back in 2018, the EU came out with something called GDPR (General Data Protection Regulation, the EU's flagship privacy law). How many companies back then thought "this has nothing to do with me"? And then? The fines started flying — up to EUR 20 million, or 4% of global annual turnover. Companies were pulling all-nighters rewriting privacy policies, redoing cookie banners, and redrafting user agreements.

I still remember that frantic scramble.

Now the AI Act is here. And what's its maximum fine?

EUR 35 million, or 7% of global annual turnover.

Let that sink in.

That's harsher than GDPR.

So what does it actually regulate? How does it relate to GDPR? And how should marketers prepare?

Today, I'm going to break it all down for you piece by piece, in plain English.

What Does This Law Actually Regulate?

Let's start with the most fundamental question: who does the AI Act govern?

The answer is blunt — it governs the AI system itself.

Unlike GDPR, which watches how you handle user data, the AI Act watches the AI tool you're using: is it safe? Will it deceive people? Does it discriminate? Can it be trusted?

And how does it govern?

It sorts things into four risk tiers.

The first tier is minimal risk. Things like spam filters or AI in video games. Use them freely, no rules attached.

The second tier is limited risk. Pay attention here — this is the one most relevant to marketers. What's in it? Chatbots, AI-generated images, synthetic video, deepfakes, AI-written copy. The core rule is simple: you have to tell users "this was made by AI."

The third tier is high risk. Hiring screens, credit scoring, facial recognition — that sort of thing. These require a pile of compliance documents and technical documentation.

The fourth tier is unacceptable risk. Outright banned. Examples: social credit scoring by algorithm, behavior manipulation based on ethnicity.

EU AI Act Risk Tiers — four risk classifications with Limited Risk highlighted for marketers

See, the lines are drawn clearly.

It's not a blanket ban on AI. Instead, it's telling you: different risks, different obligations.

How Does It Really Relate to GDPR?

This is the biggest misconception out there.

"Isn't it just GDPR 2.0?"

No.

These two regulate fundamentally different things.

GDPR governs personal data — what user information you've collected, what it's used for, how it's stored.

The AI Act governs the AI system itself — whether the algorithm is safe, transparent, and free of bias.

And the two of them stack.

Meaning what?

Say you use a generative AI tool to personalize ad delivery, and it also happens to build user profiles.

Then you have to comply with both laws:

  • Where did the user data come from, and was it authorized? — That's GDPR's business.
  • Is the AI-generated ad content watermarked and labeled? Does the algorithm discriminate against certain groups? — That's the AI Act's business.

You can't slip on either one.

See, that's much messier than dealing with GDPR alone.

When GDPR goes wrong, there's a ready-made tool called DPIA — Data Protection Impact Assessment.

The AI Act? It has its own tool, called FRIA — Fundamental Rights Impact Assessment. It's specifically for high-risk scenarios, checking whether your AI could infringe on people's fundamental rights.

The names sound similar, but they do completely different jobs. Don't mix them up.

Is This Law a Good Thing or a Bad Thing?

Honestly, after reading the whole act, my feelings are mixed.

The good side is obvious.

It draws a clear line for companies: what's allowed, what isn't, and how to prove you're in the clear on the gray areas. Before, everyone using AI had a vague unease — is this thing even compliant? If something goes wrong, who's on the hook? Now there are rules, and that brings peace of mind.

And the framework is built to last. AI tech changes every three months, but laws can't be rewritten that fast. By using a "risk-tiered" approach, it turns the rules into a framework-level construct — no matter how the tech shifts, the judgment logic doesn't.

The troublesome side is real too.

The biggest headache: you can't coast on autopilot anymore.

In the past, using an AI tool meant buying it, installing it, and getting to work. Now? Every single use case has to be assessed one by one. What scenario is this tool used in, which risk tier does it fall under, does it need labeling, does it need an impact assessment, is the liability the Provider's or the Deployer's…

A standardized, one-size-fits-all solution? Doesn't exist. Fully automated compliance? Don't count on it anytime soon either.

Time, headcount, money — you have to pour in all three.

Three Hard Hurdles in Front of Marketers

I've chatted with several friends in marketing, and the consensus is that the hard part of implementation isn't the law itself — it's three other things.

The first one: the regulations stack on top of each other.

The AI Act doesn't operate in isolation. It's tangled up with GDPR, copyright law, and consumer protection — all at once.

You publish one AI-generated ad, and you have to think simultaneously: did the training data infringe copyright? Does the generated content mislead consumers? Is the synthetic image labeled? Was the user profiling authorized?

One exam. Four proctors.

The second one: whose fault is it, really?

The AI Act defines two roles: the Provider (the party that develops the AI) and the Deployer (the party that uses the AI).

You're the marketer. You bought an AI tool to produce ads — you're the Deployer.

If the tool itself has bugs, bias, or infringement risk — that's the Provider's problem.

But here's the thing: when something blows up, the Deployer is usually the first one getting the knock on the door.

Without clear internal red lines, the team either gets scared and won't touch AI at all (missing out on tools they should be using, falling behind), or they get too bold and use it recklessly (and look blank when something goes wrong). Both extremes mean paying a steep price.

The third one: data governance and brand trust.

The output quality of an AI model depends entirely on the data you feed it. Dirty data in, dirty output out; if the data's provenance is unclear, the entire compliance chain breaks.

This isn't just a legal issue. It's a brand trust issue.

Users know you're using AI, but what they really want to know is: can they trust the AI you're using?

So What Should You Do? Six Things

The good news is, there's a method to preparing for this.

I've broken it into six steps. Follow them, and at the very least you won't be running around in a panic.

One: take inventory first.

Where exactly is your company using AI right now? Officially procured tools, AI features bundled into software, the "shadow" AI tools employees quietly use on their own — none of them can be missed.

A lot of people are startled after this step: turns out our company is using AI way more than we realized, and we had no idea.

Once you've mapped it out, build a living inventory. And note — living, not static. AI tools update so fast that a static spreadsheet is dead in three months.

Two: interrogate your suppliers.

Most of the AI tools you use come from third parties. Reading their website pitch isn't enough. You have to follow the supply chain upstream and ask: how was the model trained? Where did the data come from? Who's on the hook if something goes wrong?

Because the AI Act allocates liability all along the value chain. You might think you can just pass the buck to your supplier — the law disagrees.

Three: rewrite the contracts.

Most legacy procurement contracts are basically blank or hand-wave their way past the AI section. Now you have to spell it out: who's liable for infringement? Who's liable for bias? How much is paid out on a data breach?

A contract can't eliminate liability, but it can make liability manageable and controllable.

Four: refresh your internal policies.

Wire your AI usage rules together with existing data privacy, cybersecurity, intellectual property, HR, and external communications policies. Don't let each one be written in its own silo, contradicting the others.

Five: train your people.

The word sounds tired, but this time it's not a box-ticking exercise.

AI literacy means different roles need different knowledge. Legal needs to understand compliance determinations. Creative needs to understand the labeling rules for synthetic content. Media buyers need to understand the boundaries of user profiling.

One-size-fits-all training equals no training at all.

Six: pick the right partners.

If you're going to work with outside vendors, don't just compare price and case studies. One question is enough: what have you yourselves done to prepare for AI compliance?

Anyone who hasn't thought it through and can't even produce a single internal AI usage policy — steer clear. When things go wrong, they won't be able to help you, and they'll probably drag you down with them.

Six preparation steps for AI Act compliance — inventory, suppliers, contracts, policies, training, partners

One Last Thing

After talking through all this, I went back and looked at that WeChat Moments post again, and I'm not so panicked anymore.

When new regulations land, the first reaction is always panic. But once you actually take it apart, you realize: it's not here to block the road. It's here to set the rules.

Once the rules are set, whoever reads them first, whoever prepares first, whoever complies first — gets the ticket to the next round of competition.

Just like when GDPR arrived: the companies that prepared in advance went on to do just fine. The ones that didn't either paid astronomical tuition fees, or got knocked out of the game entirely.

It's happening again, history repeating.

Except this time, the stakes are higher.