Compliance · Marketing Ops

For three years the EU AI Act was a thing your legal team would deal with later. Later arrived on 2 August 2026.

That is the date Article 50 — the transparency chapter — started to apply, and the date the Commission’s AI Office and national market surveillance authorities began enforcing it. In plain terms: chatbots have to tell people they are chatbots, AI-generated or manipulated content has to carry machine-readable marks, and deepfakes have to be labelled. Breaches of these obligations sit in the penalty band that reaches EUR 15 million or 3% of worldwide annual turnover.

Almost everything written about this has been written by law firms, for law firms. This is the operator’s version: which of your assets are actually in scope, who carries the obligation, and what to change in your stack this month.

What actually changed on 2 August 2026?

Article 50 covers four situations, and it is worth reading them as four different products rather than one rule: AI systems that interact directly with people, AI systems that generate synthetic audio, image, video or text, emotion recognition and biometric categorisation, and deepfakes plus AI-generated text published to inform the public on matters of public interest.

The mental model that helps most: this is not a consent regime, it is a disclosure regime. GDPR asks whether you are allowed to process someone’s data. Article 50 asks whether the person understands what they are looking at. You can keep using every AI tool you use today. You cannot keep being ambiguous about it.

The timing detail people miss: the disclosure has to reach the person at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and it has to meet accessibility requirements. A note in your terms of service is not a disclosure. A grey 10px line under the chat window that a screen reader skips is not one either.

The compliance shortcut: the Commission published its Article 50 guidelines on 29 July 2026 alongside a Code of Practice on Transparency of AI-generated Content, and more than 180 organisations signed at launch. Adhering to that code is the recognised way to demonstrate compliance with the marking and labelling duties. Providers and deployers who choose not to sign have to demonstrate compliance through alternative, equivalently adequate means — which is a polite way of saying you will have to invent and defend your own method.

Are you the provider or the deployer?

This single distinction decides how much work you have. A provider develops an AI system and places it on the market under its own name. A deployer uses one under its own authority in a professional capacity. If you run marketing on HubSpot, Meta and an off-the-shelf chatbot, you are a deployer of all three.

The obligations split accordingly. Informing people that they are talking to an AI, and marking generated content in a machine-readable format, are drafted at the provider — your vendors. Disclosing emotion recognition and biometric categorisation, and disclosing deepfakes, are drafted at the deployer — you.

Which sounds like most of it is someone else’s problem. It is not, for two reasons. First, the provider ships the capability but you configure the surface: if you rename the assistant, replace the vendor’s default disclosure with your own copy, or design a widget where the notice is invisible on mobile, the ambiguity is yours. Second, the exemption everyone reaches for — disclosure is not required where the AI is obvious — is measured from the point of view of a reasonably well-informed, observant and circumspect person, in context. An assistant with a human first name, a headshot and a typing indicator is engineered to defeat exactly that test.

The four places marketing teams actually get caught

1. The website and WhatsApp chatbot

The most common failure is not a missing disclosure — it is a disclosure that was there and got designed away. Check the vendor default is still on, that it appears in the first message rather than in a collapsed panel, and that it survives on mobile. If your bot hands off to a human, say when that happens too. The person’s understanding is the thing being regulated, not the checkbox in the admin panel.

2. AI ad creative that looks real

A deepfake, in the Act’s definition, is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic. Read that again with your last creative batch in mind. A photoreal AI product shot staged in a place that looks like a real place, an AI-generated spokesperson, a synthetic customer testimonial: all candidates. Native generation inside ad platforms made this a volume problem rather than an occasional one — we covered that shift when Meta put its own image model inside the ad tools. Platform auto-labelling helps, but the disclosure duty for deployers is yours, and platform labels are not a defence you control.

3. AI-written content — read the carve-out before you panic

This is where most teams over-comply. The deployer duty on AI-generated text applies to text published to inform the public on matters of public interest, and it does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Separately, the marking obligation does not apply where the system performs an assistive function for standard editing or does not substantially alter the input. Your product page is not a matter of public interest, and a drafted-then-edited article with a named accountable author is exactly the case the carve-out describes. The fix here is editorial governance, not a banner on every post.

4. Emotion and biometric tooling

If you run emotion inference on faces or voices — video ad testing panels, sentiment scoring on recorded sales calls from the audio itself — you are a deployer of an emotion recognition system, you must inform the people exposed to it, and you process that data under GDPR. Worth being precise, because most people over-apply this one: sentiment analysis on the text of support tickets is not biometric, and it is not what this paragraph covers.

The key idea: Article 50 does not ask you to use less AI. It asks you to stop being ambiguous about it. The teams that will struggle are not the heavy AI users — they are the teams that cannot produce a list of where AI touches a customer.
A five-minute test: name every customer-facing surface where AI speaks, writes or generates. Bot, SDR sequences, ad creative, on-site personalisation, review replies. If that list does not exist in writing, building it is the work. The legal review is the easy part afterwards.

A 30-day compliance pass for your marketing stack

Not a legal project. A week of inventory, a week of copy and configuration, and a standing owner. Here is the pass I would run on any client stack.

Surface What to do this month
Chatbots and AI assistants Disclosure in the first message, visible on mobile, readable by a screen reader. Say when a human takes over.
AI voice and outbound Disclose at the opening of the call or message, not after qualification. Store the exact wording used.
Paid social and display creative Tag every synthetic asset at production time. Keep platform AI labelling switched on. Disclose photoreal generations of people or places.
Content and SEO Named author with editorial responsibility, documented review step. That is the carve-out — make it real rather than assumed.
Research and call analytics Any emotion or biometric inference: notify participants, confirm the GDPR basis, and ask whether you need the feature at all.
Vendors Two questions per vendor: are you a signatory to the Code of Practice, and do your outputs carry machine-readable marks?
The register One sheet: system, vendor, your role, disclosure wording, owner, last reviewed. This is the artefact clients and auditors ask for.

That last row is the one worth doing even if nothing else gets done. The register is what turns a vague anxiety into a five-minute answer, and it is the same inventory the AI literacy obligations have been quietly asking organisations to produce since early 2025. It also happens to be the document that makes the governance conversation possible internally — the same reason we argued for writing rules down before switching on AI write access to a CRM.

Questions people keep asking

Does this apply if my company is not based in the EU?

The Act reaches systems and outputs used in the Union, not only companies established in it. If you run campaigns, chatbots or generated creative aimed at people in the EU, the working assumption should be yes — and the specific analysis belongs with your counsel.

Do I have to label every blog post I drafted with AI?

No. The deployer duty on text is limited to publications informing the public on matters of public interest, and it falls away where there was human review or editorial control with someone holding editorial responsibility. Assistive editing that does not substantially alter the input is outside the marking obligation as well.

Who enforces this, and what is the exposure?

National market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are involved. Breaches of the transparency obligations sit in the band reaching EUR 15 million or 3% of worldwide annual turnover.

Disclosure is a trust asset, not a tax

The instinct in most marketing teams is that saying this is AI costs conversion. In practice the opposite has been true wherever it has been tested properly: people disengage when they suspect they are being handled by a machine that is pretending otherwise, not when they are told plainly and then given a fast, useful answer. The disclosure is not the friction. The discovery is.

Which is the practical case for treating this as an operations project rather than a legal one. The inventory, the wording, the ownership, the review cadence — these are the same habits that make an AI-heavy marketing function reviewable at all. The regulation just set a date on them.

One caveat, stated plainly: this is an operator’s reading of the rules, not legal advice. The classification of a specific system, and anything close to the line, is a conversation for your counsel — go into it with your register in hand and it will take an hour instead of a month.

Want the register built for you?

I run AI disclosure audits for marketing teams: full inventory of AI touchpoints across web, ads, CRM and content, provider-versus-deployer mapping, disclosure copy that does not kill conversion, and an owner and review cadence you can actually keep. Typically a week of work.

Book an AI disclosure audit

Nacho Hernandez

Nacho HernandezMarketing & Business Consultant · Studio IdeagoLinkedIn →