7 EU AI Act transparency questions to ask before AI-enabled marketing goes live
Foreword
This article provides an operational checklist for EU-based and EU-facing marketing teams and agencies. The applicable requirements depend on your role, the system, the content, the intended use and the markets reached.
If you run a marketing team or a digital agency and use AI for content, chatbots, ads or analytics, Article 50 of the EU AI Act has been part of your compliance landscape since August 2026.
It sets out transparency obligations for anyone who places AI systems on the EU market or uses them in a professional context:
If you are based in the EU and use AI tools for your own marketing or for your clients’ campaigns, you are in scope as a deployer.
If you are based outside the EU but your website, ads, content or chatbots target EU audiences (e.g. EU domains, EU languages, EU pricing, EU contact details), you are very likely in scope as well, because your AI outputs are used in the EU.
Note: This article is for information purposes only and does not constitute legal advice. For specific situations, consult qualified counsel.
-
Non-compliance with Article 50 can lead to administrative fines of up to €15 million or 3% of your total worldwide annual turnover (whichever is higher) for certain infringements related to transparency obligations. Beyond fines, there are real reputational and commercial risks:
loss of trust from clients and end-users when AI use is not clearly disclosed;
platform takedowns or demonetisation when synthetic content is not properly labelled;
contractual exposure if your clients hold you responsible for compliance failures in campaigns you run.
For marketing teams and agencies, the goal is not to “avoid AI”, but to use it transparently and responsibly, so you can scale without creating hidden legal and brand risks.
-
In practice, most digital agencies and in-house marketing teams are touched by Article 50, even if they don’t develop their own AI models. You are likely in scope if you:
configure and deploy AI chatbots or assistants on your website, landing pages or clients’ sites;
use generative AI to produce texts, images, audio or video for campaigns, social media, ads or content marketing;
experiment with synthetic presenters, voice clones or deepfake-style visuals;
publish AI-drafted articles, press releases or thought-leadership content on topics of public interest (policy, health, environment, etc.);
test or use emotion recognition or biometric categorisation tools (e.g. in-store analytics, event tech, online behaviour analysis).
-
The AI Act distinguishes two main roles:
Provider: the entity that develops or places an AI system on the market (or puts it into service under its own name/trademark). Providers carry most of the technical compliance burden (e.g. marking outputs in a machine-readable way, ensuring detectability, designing transparent interactions).
Deployer: the entity that uses an AI system under its own authority in a professional context. Deployers carry the operational transparency burden: making sure that, in your actual campaigns and communications, people are properly informed when they interact with AI or are exposed to AI-generated content.
In many marketing scenarios:
For AI chatbots/assistants: the provider must ensure the system tells users “you are talking to an AI”; you, as deployer, must check that this notice is actually present and not hidden by your branding or UX.
For synthetic images/audio/video (deepfakes): the provider must embed technical markings; you, as deployer, must add visible/audible labels so that your audience understands what they are seeing/hearing.
For AI-generated text on public-interest topics: the provider may mark the text technically; you, as deployer, must decide whether a human editorial review is in place and, if not, disclose that the text is AI-generated.
-
You might think you are “just a deployer”, but in practice many agencies and marketing teams cross the line into provider territory without realising it. You are likely to be considered a provider (and not just a deployer) if you:
Rebrand a third-party AI tool under your own name or trademark and offer it to clients as “your” solution (e.g. “YourAgency AI Chatbot”, “YourAgency Content Generator”).
Heavily customise or integrate an AI system (chatbot, content generator, synthetic voice tool) and then place it on the market or make it available to clients as part of your service offering, under your own responsibility.
Develop in-house AI workflows or agents (e.g. custom GPTs, agentic workflows, automated content pipelines) that you then offer as a service to clients, rather than using them strictly for your own internal marketing.
In those situations, the AI Act may treat you as the provider of that AI system, which means:
you inherit the provider obligations under Article 50 (technical marking, interaction transparency, documentation);
you may also trigger other AI Act obligations (risk management, technical documentation, post-market monitoring) depending on the system’s risk profile.
7 key questions on AI transparency
1. Are people interacting with an AI assistant, chatbot or avatar?
The Legal Context (Art. 50(1)): Under Article 50(1), AI systems designed to interact directly with natural persons must inform users that they are interacting with an AI.
Provider vs. Deployer Nuance: The primary obligation to design and build the system with proper disclosure mechanisms lies with the Provider (the software vendor). However, as a Deployer (agency or brand implementing the bot), you configure the user experience (UX) and interface. You must ensure that vendor disclosure settings remain visible, clear, and unhindered at the point of first interaction.
For marketing teams and agencies
This can include website chatbots, conversational lead-capture tools, campaign assistants, avatars, messaging bots and AI-powered customer-support flows.
Review before launch
Is it clear that the user is interacting with AI before or at the moment the conversation begins?
Does your branding, copy, or avatar imply or explicitly claim that the assistant is a human (which is strictly non-compliant)?
Have you ensured that the vendor's built-in AI notices are not hidden by custom CSS or UI re-branding?
Operational next step
Create a Chatbot Launch Checklist: disclosure wording, copy tone, UI owner, escalation route to human agents, data input scope, and vendor compliance verification.
2. Are you publishing realistic AI-generated or manipulated images, video or audio?
The Legal Context (Art. 50(2) & Art. 50(4)): It is vital to distinguish between technical marking and user disclosures:
Technical Marking (Art. 50(2)): Providers of generative AI tools must embed machine-readable metadata and watermarks into AI-generated media outputs.
Visual/Audible Disclosure (Art. 50(4)): Deployers (marketing teams) must explicitly disclose content if it constitutes a Deepfake—i.e., AI-generated or manipulated image, audio, or video that resembles existing persons, places, objects, or events and would falsely appear authentic or truthful to a reasonable person.
For marketing teams and agencies
Think synthetic spokespersons, voice clones, realistic product footage, deepfake-style founder videos, event visuals or manipulated testimonials.
(Note: Purely fantastical or stylized content—like an AI-generated dragon—does not trigger deepfake labeling obligations because it cannot reasonably deceive a viewer).
Review before publishing
Would an ordinary viewer reasonably think this person, voice, event or scene was real?
Is the disclosure made visibly or audibly at the first exposure to the content (e.g., at the start of a video or as an overlay on an image)?
If the content is artistic or satirical, is the disclosure integrated in a way that informs the audience without ruining the creative work?
Operational next step
Add an “AI synthetic-media check” to your final creative-approval process.
3. Are you publishing AI-generated text to inform the public on a matter of public interest?
The Legal Context (Art. 50(4), 2nd Subparagraph): Deployers must label AI-generated or AI-manipulated text published to inform the public on matters of public interest (e.g., public health, environmental issues, consumer safety, socio-economic policy)
The Editorial Exception: You do not need an AI label on the text if the content has undergone a process of substantive human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.
For marketing teams and agencies
This may be relevant to public statements, issue-led campaigns, public-health or safety communications, political or social communications, sustainability claims, reports, press releases and thought-leadership intended to influence public debate.
Review before publication
Is the content intended to inform the public on a topic of public interest?
Did a qualified human editor substantively review the facts, claims, and final copy before release?
Is the entity holding editorial responsibility clearly identifiable (e.g., named author, corporate publisher)?
Operational next step
Define a standard of “substantive editorial review” and retain basic proof: named owner, date, approval record and source checks.
4. Are you building, branding or putting an AI system into service under your own name?
The Legal Context (Art. 3(3) & Art. 50(1)-(2)): If an agency or brand takes an underlying AI model/tool, customizes it heavily, and places it on the market or puts it into service under its own name or trademark, it transitions legally from a Deployer to a Provider.
For marketing agencies
This can happen when an agency productises an assistant, AI content generator, campaign optimisation tool or branded workflow for client delivery.
Review before selling or launching
Is the tool presented to clients or end-users as your own proprietary solution?
If you are legally a Provider, have you ensured the system is natively designed to provide the required Article 50 transparency notifications?
Do your Statements of Work (SOW) and proposals accurately reflect whether you are supplying software (Provider) or a managed service (Deployer)?
Operational next step
Create a Service Boundary Canvas before the service is sold: intended use, data, output, human controls, responsibilities, limitations and support.
5. Are you using AI to infer emotions or categorise people using biometric data?
The Legal Context (Art. 50(3) & GDPR): Deployers using emotion recognition or biometric categorization systems must inform exposed individuals. Furthermore, certain emotion recognition uses (e.g., in workplace or educational settings) are strictly prohibited under Article 5 of the AI Act.
For marketing teams and agencies
Examples can include event or in-store analytics based on faces, voice-based emotion analysis, webcam sentiment tools or biometric categorisation used in audience segmentation.
Do not handle this as routine marketing technology.
Review immediately
Are biometric data, faces, voices or behavioural signals used to infer emotion or personal characteristics?
Has a Data Protection Impact Assessment (DPIA) under GDPR Article 35 been conducted alongside the AI Act review?
Are clear, pre-exposure notices presented to individuals before data capture occurs?
Operational next step
Pause wider rollout and obtain qualified legal, privacy and technical review. Your role is to help map the workflow and prepare the right operational facts — not determine legal compliance on your own.
6. Are you using AI only behind the scenes — or does the output reach a client, audience or individual?
The Legal Context (Art. 50(4)): Internal, non-public operational uses of AI (e.g., internal brainwriting, preliminary coding, administrative scheduling, or drafting internal strategic briefs) generally fall outside public-facing transparency labeling rules.
Review
Is the tool used only internally?
Is any output delivered to a client, published to an audience or used to interact with an individual?
Could an internal workflow become external-facing later?
Are internal teams clear about what may and may not leave the organisation without review?
Operational next step
Maintain an AI use register that separates internal experimentation, client delivery and public-facing AI use.
7. Can your agency or marketing team give one clear answer about transparency?
The legal rules are important, but client trust is often lost first through inconsistent answers. If sales says “we rarely use AI,” delivery says “we use it everywhere,” and the client discovers synthetic content later, you have a governance problem even before a legal one.
Review
Can sales, account managers and delivery teams explain AI use consistently?
Do you know where AI interaction notices or synthetic-content labels are used?
Do you have a clear rule for human review and editorial accountability?
Can you explain the role of your vendors, your team and your client?
Are your proposals and RFP responses aligned with actual delivery practice?
Operational next step
Create a client-facing AI use statement and an internal FAQ for sales, account and delivery teams.
Debunking frequent misinformation about the EU AI Act:
-
MYTH.
Text does not systematically require public labeling in every context. Under Article 50(4), text only requires public disclosure if it is published to inform the public on matters of public interest. Furthermore, an explicit exception applies if the text has undergone human review or editorial control by a person/entity holding editorial responsibility. Internal drafts, technical logs, or human-reviewed marketing copy do not need mandatory user-facing labels.
-
MYTH. Not all visuals require a visible label. For deployers, visible disclosure is primarily mandatory for deepfakes (realistic depictions of real persons, places, or events that could mislead people). Abstract art, obviously fictional visuals (e.g., a dragon driving a car), or simple background generation in ads generally fall outside mandatory deepfake labeling. Additionally, providers must embed technical markings (metadata/watermarking), but internal or B2B technical visuals are often exempt.
-
Why this is completely FALSE:
Many businesses believe that liability sits entirely with the AI vendor or developer. This is a dangerous misconception. Regulations explicitly distinguish between Providers (those who build/train AI) and Deployers (businesses, marketers, or individuals who use AI systems for professional purposes). As a deployer, you are directly accountable for how AI is used in your workflows. If your team uses unvetted AI tools ("Shadow AI"), publishes unlabeled synthetic content, or breaches data privacy laws (GDPR) via third-party LLMs, your organization bears the direct regulatory, financial, and brand equity risks. Under the EU AI Act, non-compliance with transparency obligations can result in heavy administrative fines (up to €15M or 3% of global annual turnover) regardless of whether you built the model or simply deployed it.
References (for the legally minded)
Regulation (EU) 2024/1689 (AI Act) – Article 50 (transparency obligations for providers and deployers).
Commission Guidelines on transparency obligations for providers and deployers of AI systems under Article 50(published July 2026, applicable from 2 August 2026).
Code of Practice on Transparency of AI-generated Content (voluntary code assessed as adequate by the Commission and the AI Board).
GDPR (for emotion recognition and biometric categorisation systems, especially Article 9 and DPIA requirements)