Marketers: know Your EU AI Act transparency obligations in 7 questions

Key takeways:

  • High financial & brand stakes: Ignoring compliance risks non-compliance fines up to €15M or 3% of global turnover, alongside severe erosion of customer trust.

Deployer vs. Provider Roles:

  • Deployers (using third-party AI): Must disclose AI chatbots at first interaction, label deepfakes, and disclose public-interest AI text unless backed by real human editorial review.

  • Providers (building/selling AI SaaS): Responsible for technical watermarking and machine-readable output tagging.

If you run a marketing team or a digital agency and use AI for content, chatbots, ads or analytics, Article 50 of the EU AI Act has been part of your compliance landscape since August 2026.

It sets out transparency obligations for anyone who places AI systems on the EU market or uses them in a professional context:

  • If you are based in the EU and use AI tools for your own marketing or for your clients’ campaigns, you are in scope as a deployer.

  • If you are based outside the EU but your website, ads, content or chatbots target EU audiences (e.g. EU domains, EU languages, EU pricing, EU contact details), you are very likely in scope as well, because your AI outputs are used in the EU.

Note: This article is for information purposes only and does not constitute legal advice. For specific situations, consult qualified counsel.

7 key questions on AI transparency

1. Do you develop or sell AI tools (chatbot, AI generator, SaaS with AI features)?

Providers under the EU AI ACT

You are a “provider” under the EU AI Act.

As a provider of AI systems, you have direct transparency obligations under Article 50 of the AI Act, in addition to any other obligations that may apply (e.g. for high-risk AI systems, general-purpose AI models, etc.).

Core obligations relevant to Article 50

  • If your AI system interacts directly with natural persons (e.g. chatbot, AI assistant, avatar, conversational agent):

    • You must design and develop the system so that natural persons are informed that they are interacting with an AI system, unless this is obvious from the context and circumstances of use.

    • This information must be provided at the latest at the time of the first interaction, in a clear and accessible manner, and in accordance with applicable accessibility requirements.

    • This obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.

  • If your AI system generates or manipulates audio, image, video or text content (including general-purpose AI systems used for such generation/manipulation):

    • You must ensure that the outputs of the AI system are marked in a machine-readable format and are detectable as artificially generated or manipulated.

    • The technical means used must be effective, robust, reliable and interoperable, to the extent that this is technically feasible, taking into account available state-of-the-art techniques and cost of implementation.

    • This obligation does not apply where:

      • the performance of the system involves standard editing functions that do not substantially alter the underlying content (e.g. basic spellcheck, simple retouching);

      • the AI system is used for machine-to-machine exchanges where outputs are not exposed to natural persons;

      • the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.

Recommended actions

  • Map which of your AI systems fall under each of the above categories (interaction with persons; synthetic content generation/manipulation).

  • For interaction systems: implement clear, accessible notices (e.g. “You are conversing with an AI-powered assistant”) at the start of the interaction; document this in your UX and technical specifications.

  • For generative/manipulation systems: implement technical marking (e.g. metadata, watermarks, cryptographic signatures or equivalent) and, where relevant, detection capabilities (e.g. APIs, verification tools) for downstream users.

  • Consider adhering to the EU Code of Practice on Transparency of AI-generated Content, which can provide a presumption of compliance with the marking and detectability obligations, where applicable.

  • Keep records of your technical and organisational measures (design choices, limitations, feasibility assessments, etc.) as part of your AI Act compliance documentation.

2. Do you mainly use existing AI tools for your own or clients’ marketing?

You are primarily a “deployer” under the EU AI Act.

As a deployer of AI systems (using tools developed by others for your own or clients’ marketing activities), your main transparency obligations under Article 50 relate to how you expose people to certain AI systems or AI-generated content, rather than how the systems are built.

Core obligations relevant to Article 50

  • If you use AI systems that interact directly with natural persons (e.g. chatbots, AI assistants on your or your clients’ websites):

    • The primary legal obligation to inform persons that they are interacting with an AI system generally falls on the provider of the AI system.

    • However, as a deployer, you should:

      • verify that your vendor’s AI system complies with this obligation (clear, accessible notice at first interaction);

      • ensure that your own branding, UX or communications do not obscure or contradict this notice;

      • consider reinforcing this information in your own terms, privacy notices or FAQs where appropriate.

  • If you publish or distribute AI-generated or manipulated content (images, audio, video, text) to the public, additional obligations may apply depending on the type of content (see the specific rows below on deepfakes, AI text for public interest, etc.).

Recommended actions

  • Inventory the AI tools you use in marketing (content generation, chatbots, analytics, personalisation, etc.).

  • For each tool, identify whether it:

    • interacts directly with people (chatbot, assistant);

    • generates or manipulates synthetic content (text, images, audio, video);

    • involves emotion recognition or biometric categorisation.

  • Check your vendors’ documentation and contractual commitments regarding AI Act transparency obligations (especially Article 50).

  • Implement internal guidelines for your teams and clients on responsible and transparent use of AI in marketing communications.

3. Do you use AI chatbots/assistants that talk to visitors or leads?

You deploy AI systems that interact directly with natural persons.

Under Article 50(1) of the EU AI Act, when an AI system is designed to interact directly with natural persons (e.g. chatbot, AI assistant, avatar on a website, messaging channel or app), there is a specific transparency obligation.

Who is responsible

  • The primary legal obligation to inform persons that they are interacting with an AI system falls on the provider of the AI system (the company that develops and supplies the chatbot/assistant).

  • As a deployer (you use the chatbot/assistant for your own or clients’ interactions with visitors or leads), you are not directly responsible for designing this notice, but you have a duty of care in how you deploy the system.

What this means in practice

  • You should verify with your vendor that the chatbot/assistant:

    • clearly informs users, at the latest at the first interaction, that they are interacting with an AI system (e.g. “You are conversing with an AI-powered assistant”);

    • provides this information in a clear, accessible manner, compliant with applicable accessibility requirements;

    • does not mislead users into believing they are interacting with a human when they are not, unless this is obvious from the context (e.g. clearly fictional or game-like scenario).

  • You should ensure that your own branding, UX, scripts or marketing materials do not obscure, contradict or undermine this notice (e.g. implying the assistant is a human employee when it is not).

  • Where you heavily customise the chatbot’s behaviour, tone or interface, assess whether the AI nature remains clear to a reasonably well-informed user.

Recommended actions

  • Review your chatbot/assistant implementations (on your site, landing pages, clients’ sites, etc.).

  • Confirm in writing with your provider that their system is designed to comply with Article 50(1) of the AI Act.

  • If needed, add your own supplementary notices (e.g. in FAQs, terms of use, privacy policy) stating that certain interactions are AI-powered.

  • Train your teams and clients to avoid representations that could mislead users about the human or non-human nature of the assistant.

4. Do you create realistic AI-generated images, audio or video (deepfake-style)?

Deepfakes explained according to the EU AI ACT

Under Article 50(4) of the AI Act, deployers of AI systems that generate or manipulate audio, image or video content that falsely appears to a reasonable person to be authentic or truthful (commonly referred to as deepfakes) have a specific transparency obligation.

When does this apply?

This obligation applies when you publish or distribute content (e.g. ads, social posts, videos, audio clips, visuals) that:

  • is artificially generated or manipulated using an AI system; and

  • resembles existing persons, objects, places, events or actions in a way that could mislead a reasonable person into believing the content is authentic or truthful.

Your obligation as a deployer:

  • You must clearly disclose that the content has been artificially generated or manipulated.

  • This disclosure must be made at the latest at the time of first exposure to the content (e.g. when a user first sees the image, starts watching the video, or hears the audio).

  • The disclosure must be understandable and perceptible without the need for technical tools (i.e. a human can see or hear it directly, without needing special software).

Exceptions and attenuations

  • The obligation does not apply where the content forms part of an artistic, creative, satirical, fictional or analogous work, provided that its use is appropriately disclosed in a manner that does not unduly impair the experience of the work (e.g. notice in the intro, credits, description, depending on the medium).

  • The obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.

Recommended actions

  • Identify all marketing and communication assets where you use realistic AI-generated or manipulated images, audio or video (e.g. synthetic presenters, voice clones, deepfake-style visuals).

  • For each such asset, implement a clear, visible/audible label, for example:

    • “AI-generated image”;

    • “This video includes synthetic elements”;

    • “Voice generated by AI”.

  • Place the notice:

    • for videos: at the start and/or in a persistent on-screen label;

    • for images: in the caption or immediately adjacent text;

    • for audio: at the beginning of the clip or via an audible disclaimer.

  • For artistic, satirical or fictional content, ensure the disclosure is appropriate to the medium (e.g. in the intro, credits, description) and does not ruin the experience while still informing the audience.

  • Keep an internal register of AI-generated assets and how they are labelled, as part of your compliance documentation.

5. Do you publish AI-generated text to inform the public on matters of public interest?

You publish AI-generated text for public-interest information, which triggers specific transparency obligations.

Under Article 50(4) of the EU AI Act, deployers that publish text generated by an AI system with the purpose of informing the public on matters of public interest must disclose that the text is AI-generated, unless certain conditions are met.

What counts as “text to inform the public on matters of public interest”?

This typically includes content such as:

  • news articles and press releases on political, economic, social or environmental developments;

  • public communications on health, safety, security or major scientific/technical issues;

  • policy briefs, position papers or thought-leadership articles intended to inform public debate on significant societal issues.

Your obligation as a deployer

  • You must clearly disclose that the text has been generated by an AI system.

  • This disclosure must be made in a manner that is clear and understandable to the average reader.

Exception – human editorial responsibility:

  • The disclosure obligation does not apply if a natural or legal person has exercised editorial responsibility over the content and has substantively reviewed it before publication.

  • “Substantive review” means more than light editing or spellchecking; it implies real human oversight over the substance, accuracy and framing of the content (fact-checking, validation of claims, editorial approval).

  • If you rely on this exception, you must be able to demonstrate that such human review took place (e.g. documented editorial process, named responsible editor, workflow records).

Exceptions for law enforcement:

  • The obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.

Recommended actions

  • Identify all channels and content types where you publish AI-generated text intended to inform the public on matters of public interest (website articles, press releases, white papers, LinkedIn long-form posts, etc.).

  • For each such content type, assess whether:

    • there is real human editorial review (fact-checking, validation of substance, editorial sign-off); or

    • the text is only lightly edited or published as-generated.

  • If there is no substantive human review:

    • add a clear notice, for example: “This article was written with the help of AI.” or “Text generated by AI, then reviewed by our editorial team.” (only if review is real).

  • If there is substantive human review:

    • document your editorial process (who reviews, what checks are performed, who has authority to approve/alter/reject the content);

    • retain records that can demonstrate this process if questioned by regulators.

  • Include these rules in your internal editorial guidelines and train your content and communications teams accordingly.

6. Do you use emotion recognition or biometric categorisation systems?

You deploy emotion recognition or biometric categorisation systems, which are subject to strict transparency and data protection rules.

Under Article 50(3) of the EU AI Act, deployers of AI systems used for emotion recognition or biometric categorisation have specific transparency obligations towards the natural persons exposed to such systems.

Scope

This applies where you use AI systems that:

  • infer or analyse emotions, intentions or psychological states of natural persons (emotion recognition); and/or

  • categorise natural persons based on biometric data (e.g. facial features, voice, gait) to deduce sensitive or personal characteristics (biometric categorisation).

Examples in a marketing/agency context may include:

  • in-store or event-based systems analysing facial expressions or emotions;

  • online tools inferring emotional states from webcam or voice;

  • segmentation tools categorising individuals based on biometric characteristics.

Your obligation as a deployer:

  • You must inform natural persons who are exposed to the operation of such systems that the system is being used.

  • This information must be provided in a clear and understandable manner, at a time and in a format that allows persons to become aware of the system’s operation (e.g. signage, notices, digital banners, QR codes linking to detailed information).

  • You must also comply with all applicable data protection rules, in particular the GDPR, including requirements on:

    • lawful basis for processing;

    • transparency (privacy notices);

    • data minimisation and purpose limitation;

    • security and retention;

    • data subject rights.

Prohibitions and high-risk considerations:

  • Certain uses of emotion recognition systems are prohibited under Article 5 of the AI Act, for example:

    • emotion recognition in the workplace;

    • emotion recognition in educational settings;

    • certain forms of real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (with narrow exceptions).

  • If your use case falls under these prohibitions, you must not use such systems in those contexts, regardless of any transparency measures.

Recommended actions

  • Map all uses of emotion recognition or biometric categorisation systems in your own operations or for your clients (physical locations, online experiences, events, HR tools, etc.).

  • For each such use:

    • verify whether it is prohibited under Article 5 of the AI Act (e.g. workplace, education); if yes, discontinue that use.

    • implement clear, visible notices informing persons that such a system is in operation (e.g. “This device uses an AI-based emotion recognition system”).

    • ensure your privacy notices and GDPR documentation cover these systems (purpose, legal basis, data categories, retention, rights, etc.).

  • Conduct, where appropriate, a data protection impact assessment (DPIA) under the GDPR, given the sensitive nature of biometric and emotional data.

  • Train your teams and clients on the high-risk nature of these technologies and the need for strict compliance with both the AI Act and GDPR.

7. Do you only use AI for internal tasks (brainstorming, internal docs, non-public content)?

Your current AI use is primarily internal, which limits your direct transparency obligations under Article 50.

If you only use AI systems for internal tasks such as brainstorming, drafting internal documents, internal analysis, or generating content that is not exposed to the public or to natural persons outside your organisation, your direct transparency obligations under Article 50 of the AI Act are likely limited or non-existent for these specific uses.

Why?

Most Article 50 obligations are triggered when:

  • AI systems interact directly with natural persons outside the provider/deployer organisation (e.g. chatbots on public websites, assistants interacting with clients); or

  • AI-generated or manipulated content is published or distributed to the public (e.g. ads, social posts, articles, videos); or

  • natural persons are exposed to emotion recognition or biometric categorisation systems.

Purely internal uses, with no external exposure, generally fall outside these scopes.

Recommended actions

  • Keep an internal inventory of AI tools and use cases, distinguishing between:

    • internal-only uses (brainstorming, internal docs, non-public content);

    • uses that involve external-facing interactions or publications (website, social media, client deliverables, events, etc.).

  • For internal-only uses:

    • implement basic responsible-AI guidelines (no confidential or personal data leakage, human review of critical outputs, awareness of biases and limitations).

    • monitor whether any of these use cases might evolve towards external exposure (e.g. reusing AI-generated content in public communications), which could trigger Article 50 obligations.

  • Periodically review your AI usage as your activities evolve, to ensure that new public-facing or person-facing uses are assessed for AI Act and GDPR compliance.

Debunking frequent misinformation about the EU AI Act:

References (for the legally minded)

Flora Peter

I’m Flora Peter, an AI governance consultant with 20 years of experience in digital marketing and agency operations. I help marketing teams and agencies turn AI risk into practical governance and responsible growth.

https://www.florapeter.com
Next
Next

The AI brand damage you’re not watching for (Part 1. Brand identity)