7 EU AI Act transparency questions to ask before AI-enabled marketing goes live

Foreword

This article provides an operational checklist for EU-based and EU-facing marketing teams and agencies. The applicable requirements depend on your role, the system, the content, the intended use and the markets reached.

If you run a marketing team or a digital agency and use AI for content, chatbots, ads or analytics, Article 50 of the EU AI Act has been part of your compliance landscape since August 2026.

It sets out transparency obligations for anyone who places AI systems on the EU market or uses them in a professional context:

  • If you are based in the EU and use AI tools for your own marketing or for your clients’ campaigns, you are in scope as a deployer.

  • If you are based outside the EU but your website, ads, content or chatbots target EU audiences (e.g. EU domains, EU languages, EU pricing, EU contact details), you are very likely in scope as well, because your AI outputs are used in the EU.

Note: This article is for information purposes only and does not constitute legal advice. For specific situations, consult qualified counsel.

7 key questions on AI transparency

1. Are people interacting with an AI assistant, chatbot or avatar?

The Legal Context (Art. 50(1)): Under Article 50(1), AI systems designed to interact directly with natural persons must inform users that they are interacting with an AI.

Provider vs. Deployer Nuance: The primary obligation to design and build the system with proper disclosure mechanisms lies with the Provider (the software vendor). However, as a Deployer (agency or brand implementing the bot), you configure the user experience (UX) and interface. You must ensure that vendor disclosure settings remain visible, clear, and unhindered at the point of first interaction.

For marketing teams and agencies
This can include website chatbots, conversational lead-capture tools, campaign assistants, avatars, messaging bots and AI-powered customer-support flows.

Review before launch

  • Is it clear that the user is interacting with AI before or at the moment the conversation begins?

  • Does your branding, copy, or avatar imply or explicitly claim that the assistant is a human (which is strictly non-compliant)?

  • Have you ensured that the vendor's built-in AI notices are not hidden by custom CSS or UI re-branding?

Operational next step
Create a Chatbot Launch Checklist: disclosure wording, copy tone, UI owner, escalation route to human agents, data input scope, and vendor compliance verification.

2. Are you publishing realistic AI-generated or manipulated images, video or audio?

The Legal Context (Art. 50(2) & Art. 50(4)): It is vital to distinguish between technical marking and user disclosures:

  1. Technical Marking (Art. 50(2)): Providers of generative AI tools must embed machine-readable metadata and watermarks into AI-generated media outputs.

  2. Visual/Audible Disclosure (Art. 50(4)): Deployers (marketing teams) must explicitly disclose content if it constitutes a Deepfake—i.e., AI-generated or manipulated image, audio, or video that resembles existing persons, places, objects, or events and would falsely appear authentic or truthful to a reasonable person.

For marketing teams and agencies
Think synthetic spokespersons, voice clones, realistic product footage, deepfake-style founder videos, event visuals or manipulated testimonials.

(Note: Purely fantastical or stylized content—like an AI-generated dragon—does not trigger deepfake labeling obligations because it cannot reasonably deceive a viewer).

Review before publishing

  • Would an ordinary viewer reasonably think this person, voice, event or scene was real?

  • Is the disclosure made visibly or audibly at the first exposure to the content (e.g., at the start of a video or as an overlay on an image)?

  • If the content is artistic or satirical, is the disclosure integrated in a way that informs the audience without ruining the creative work?

Operational next step
Add an “AI synthetic-media check” to your final creative-approval process.

3. Are you publishing AI-generated text to inform the public on a matter of public interest?

The Legal Context (Art. 50(4), 2nd Subparagraph): Deployers must label AI-generated or AI-manipulated text published to inform the public on matters of public interest (e.g., public health, environmental issues, consumer safety, socio-economic policy)

The Editorial Exception: You do not need an AI label on the text if the content has undergone a process of substantive human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.

For marketing teams and agencies
This may be relevant to public statements, issue-led campaigns, public-health or safety communications, political or social communications, sustainability claims, reports, press releases and thought-leadership intended to influence public debate.

Review before publication

  • Is the content intended to inform the public on a topic of public interest?

  • Did a qualified human editor substantively review the facts, claims, and final copy before release?

  • Is the entity holding editorial responsibility clearly identifiable (e.g., named author, corporate publisher)?

Operational next step
Define a standard of “substantive editorial review” and retain basic proof: named owner, date, approval record and source checks.

4. Are you building, branding or putting an AI system into service under your own name?

The Legal Context (Art. 3(3) & Art. 50(1)-(2)): If an agency or brand takes an underlying AI model/tool, customizes it heavily, and places it on the market or puts it into service under its own name or trademark, it transitions legally from a Deployer to a Provider.

For marketing agencies
This can happen when an agency productises an assistant, AI content generator, campaign optimisation tool or branded workflow for client delivery.

Review before selling or launching

  • Is the tool presented to clients or end-users as your own proprietary solution?

  • If you are legally a Provider, have you ensured the system is natively designed to provide the required Article 50 transparency notifications?

  • Do your Statements of Work (SOW) and proposals accurately reflect whether you are supplying software (Provider) or a managed service (Deployer)?

Operational next step
Create a Service Boundary Canvas before the service is sold: intended use, data, output, human controls, responsibilities, limitations and support.

5. Are you using AI to infer emotions or categorise people using biometric data?

The Legal Context (Art. 50(3) & GDPR): Deployers using emotion recognition or biometric categorization systems must inform exposed individuals. Furthermore, certain emotion recognition uses (e.g., in workplace or educational settings) are strictly prohibited under Article 5 of the AI Act.


For marketing teams and agencies
Examples can include event or in-store analytics based on faces, voice-based emotion analysis, webcam sentiment tools or biometric categorisation used in audience segmentation.

Do not handle this as routine marketing technology.

Review immediately

  • Are biometric data, faces, voices or behavioural signals used to infer emotion or personal characteristics?

  • Has a Data Protection Impact Assessment (DPIA) under GDPR Article 35 been conducted alongside the AI Act review?

  • Are clear, pre-exposure notices presented to individuals before data capture occurs?

Operational next step
Pause wider rollout and obtain qualified legal, privacy and technical review. Your role is to help map the workflow and prepare the right operational facts — not determine legal compliance on your own.

6. Are you using AI only behind the scenes — or does the output reach a client, audience or individual?

The Legal Context (Art. 50(4)): Internal, non-public operational uses of AI (e.g., internal brainwriting, preliminary coding, administrative scheduling, or drafting internal strategic briefs) generally fall outside public-facing transparency labeling rules.

Review

  • Is the tool used only internally?

  • Is any output delivered to a client, published to an audience or used to interact with an individual?

  • Could an internal workflow become external-facing later?

  • Are internal teams clear about what may and may not leave the organisation without review?

Operational next step
Maintain an AI use register that separates internal experimentation, client delivery and public-facing AI use.

7. Can your agency or marketing team give one clear answer about transparency?

The legal rules are important, but client trust is often lost first through inconsistent answers. If sales says “we rarely use AI,” delivery says “we use it everywhere,” and the client discovers synthetic content later, you have a governance problem even before a legal one.

Review

  • Can sales, account managers and delivery teams explain AI use consistently?

  • Do you know where AI interaction notices or synthetic-content labels are used?

  • Do you have a clear rule for human review and editorial accountability?

  • Can you explain the role of your vendors, your team and your client?

  • Are your proposals and RFP responses aligned with actual delivery practice?

Operational next step
Create a client-facing AI use statement and an internal FAQ for sales, account and delivery teams.

Debunking frequent misinformation about the EU AI Act:

References (for the legally minded)

Flora Peter

I’m Flora Peter, an AI governance consultant with 20 years of experience in digital marketing and agency operations. I help marketing teams and agencies turn AI risk into practical governance and responsible growth.

How exposed is your marketing team to AI risk?

Free 2-minute AI Exposure Check: spot gaps across AI tools, client data, human review, transparency, IP, training and incident response, then identify where to act first.

https://www.florapeter.com/ai-exposure
Previous
Previous

The real price of AI in marketing: why cost uncertainty is a governance risk

Next
Next

The AI brand damage you’re not watching for - Part 1: Brand identity