Marketers: know Your EU AI Act transparency obligations in 7 questions
Key takeways:
High financial & brand stakes: Ignoring compliance risks non-compliance fines up to €15M or 3% of global turnover, alongside severe erosion of customer trust.
Deployer vs. Provider Roles:
Deployers (using third-party AI): Must disclose AI chatbots at first interaction, label deepfakes, and disclose public-interest AI text unless backed by real human editorial review.
Providers (building/selling AI SaaS): Responsible for technical watermarking and machine-readable output tagging.
If you run a marketing team or a digital agency and use AI for content, chatbots, ads or analytics, Article 50 of the EU AI Act has been part of your compliance landscape since August 2026.
It sets out transparency obligations for anyone who places AI systems on the EU market or uses them in a professional context:
If you are based in the EU and use AI tools for your own marketing or for your clients’ campaigns, you are in scope as a deployer.
If you are based outside the EU but your website, ads, content or chatbots target EU audiences (e.g. EU domains, EU languages, EU pricing, EU contact details), you are very likely in scope as well, because your AI outputs are used in the EU.
Note: This article is for information purposes only and does not constitute legal advice. For specific situations, consult qualified counsel.
-
Non-compliance with Article 50 can lead to administrative fines of up to €15 million or 3% of your total worldwide annual turnover (whichever is higher) for certain infringements related to transparency obligations. Beyond fines, there are real reputational and commercial risks:
loss of trust from clients and end-users when AI use is not clearly disclosed;
platform takedowns or demonetisation when synthetic content is not properly labelled;
contractual exposure if your clients hold you responsible for compliance failures in campaigns you run.
For marketing teams and agencies, the goal is not to “avoid AI”, but to use it transparently and responsibly, so you can scale without creating hidden legal and brand risks.
-
In practice, most digital agencies and in-house marketing teams are touched by Article 50, even if they don’t develop their own AI models. You are likely in scope if you:
configure and deploy AI chatbots or assistants on your website, landing pages or clients’ sites;
use generative AI to produce texts, images, audio or video for campaigns, social media, ads or content marketing;
experiment with synthetic presenters, voice clones or deepfake-style visuals;
publish AI-drafted articles, press releases or thought-leadership content on topics of public interest (policy, health, environment, etc.);
test or use emotion recognition or biometric categorisation tools (e.g. in-store analytics, event tech, online behaviour analysis).
-
The AI Act distinguishes two main roles:
Provider: the entity that develops or places an AI system on the market (or puts it into service under its own name/trademark). Providers carry most of the technical compliance burden (e.g. marking outputs in a machine-readable way, ensuring detectability, designing transparent interactions).
Deployer: the entity that uses an AI system under its own authority in a professional context. Deployers carry the operational transparency burden: making sure that, in your actual campaigns and communications, people are properly informed when they interact with AI or are exposed to AI-generated content.
In many marketing scenarios:
For AI chatbots/assistants: the provider must ensure the system tells users “you are talking to an AI”; you, as deployer, must check that this notice is actually present and not hidden by your branding or UX.
For synthetic images/audio/video (deepfakes): the provider must embed technical markings; you, as deployer, must add visible/audible labels so that your audience understands what they are seeing/hearing.
For AI-generated text on public-interest topics: the provider may mark the text technically; you, as deployer, must decide whether a human editorial review is in place and, if not, disclose that the text is AI-generated.
-
You might think you are “just a deployer”, but in practice many agencies and marketing teams cross the line into provider territory without realising it. You are likely to be considered a provider (and not just a deployer) if you:
Rebrand a third-party AI tool under your own name or trademark and offer it to clients as “your” solution (e.g. “YourAgency AI Chatbot”, “YourAgency Content Generator”).
Heavily customise or integrate an AI system (chatbot, content generator, synthetic voice tool) and then place it on the market or make it available to clients as part of your service offering, under your own responsibility.
Develop in-house AI workflows or agents (e.g. custom GPTs, agentic workflows, automated content pipelines) that you then offer as a service to clients, rather than using them strictly for your own internal marketing.
In those situations, the AI Act may treat you as the provider of that AI system, which means:
you inherit the provider obligations under Article 50 (technical marking, interaction transparency, documentation);
you may also trigger other AI Act obligations (risk management, technical documentation, post-market monitoring) depending on the system’s risk profile.
7 key questions on AI transparency
1. Do you develop or sell AI tools (chatbot, AI generator, SaaS with AI features)?
Providers under the EU AI ACT
You are a “provider” under the EU AI Act.
As a provider of AI systems, you have direct transparency obligations under Article 50 of the AI Act, in addition to any other obligations that may apply (e.g. for high-risk AI systems, general-purpose AI models, etc.).
Core obligations relevant to Article 50
If your AI system interacts directly with natural persons (e.g. chatbot, AI assistant, avatar, conversational agent):
You must design and develop the system so that natural persons are informed that they are interacting with an AI system, unless this is obvious from the context and circumstances of use.
This information must be provided at the latest at the time of the first interaction, in a clear and accessible manner, and in accordance with applicable accessibility requirements.
This obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.
If your AI system generates or manipulates audio, image, video or text content (including general-purpose AI systems used for such generation/manipulation):
You must ensure that the outputs of the AI system are marked in a machine-readable format and are detectable as artificially generated or manipulated.
The technical means used must be effective, robust, reliable and interoperable, to the extent that this is technically feasible, taking into account available state-of-the-art techniques and cost of implementation.
This obligation does not apply where:
the performance of the system involves standard editing functions that do not substantially alter the underlying content (e.g. basic spellcheck, simple retouching);
the AI system is used for machine-to-machine exchanges where outputs are not exposed to natural persons;
the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.
Recommended actions
Map which of your AI systems fall under each of the above categories (interaction with persons; synthetic content generation/manipulation).
For interaction systems: implement clear, accessible notices (e.g. “You are conversing with an AI-powered assistant”) at the start of the interaction; document this in your UX and technical specifications.
For generative/manipulation systems: implement technical marking (e.g. metadata, watermarks, cryptographic signatures or equivalent) and, where relevant, detection capabilities (e.g. APIs, verification tools) for downstream users.
Consider adhering to the EU Code of Practice on Transparency of AI-generated Content, which can provide a presumption of compliance with the marking and detectability obligations, where applicable.
Keep records of your technical and organisational measures (design choices, limitations, feasibility assessments, etc.) as part of your AI Act compliance documentation.
2. Do you mainly use existing AI tools for your own or clients’ marketing?
You are primarily a “deployer” under the EU AI Act.
As a deployer of AI systems (using tools developed by others for your own or clients’ marketing activities), your main transparency obligations under Article 50 relate to how you expose people to certain AI systems or AI-generated content, rather than how the systems are built.
Core obligations relevant to Article 50
If you use AI systems that interact directly with natural persons (e.g. chatbots, AI assistants on your or your clients’ websites):
The primary legal obligation to inform persons that they are interacting with an AI system generally falls on the provider of the AI system.
However, as a deployer, you should:
verify that your vendor’s AI system complies with this obligation (clear, accessible notice at first interaction);
ensure that your own branding, UX or communications do not obscure or contradict this notice;
consider reinforcing this information in your own terms, privacy notices or FAQs where appropriate.
If you publish or distribute AI-generated or manipulated content (images, audio, video, text) to the public, additional obligations may apply depending on the type of content (see the specific rows below on deepfakes, AI text for public interest, etc.).
Recommended actions
Inventory the AI tools you use in marketing (content generation, chatbots, analytics, personalisation, etc.).
For each tool, identify whether it:
interacts directly with people (chatbot, assistant);
generates or manipulates synthetic content (text, images, audio, video);
involves emotion recognition or biometric categorisation.
Check your vendors’ documentation and contractual commitments regarding AI Act transparency obligations (especially Article 50).
Implement internal guidelines for your teams and clients on responsible and transparent use of AI in marketing communications.
3. Do you use AI chatbots/assistants that talk to visitors or leads?
You deploy AI systems that interact directly with natural persons.
Under Article 50(1) of the EU AI Act, when an AI system is designed to interact directly with natural persons (e.g. chatbot, AI assistant, avatar on a website, messaging channel or app), there is a specific transparency obligation.
Who is responsible
The primary legal obligation to inform persons that they are interacting with an AI system falls on the provider of the AI system (the company that develops and supplies the chatbot/assistant).
As a deployer (you use the chatbot/assistant for your own or clients’ interactions with visitors or leads), you are not directly responsible for designing this notice, but you have a duty of care in how you deploy the system.
What this means in practice
You should verify with your vendor that the chatbot/assistant:
clearly informs users, at the latest at the first interaction, that they are interacting with an AI system (e.g. “You are conversing with an AI-powered assistant”);
provides this information in a clear, accessible manner, compliant with applicable accessibility requirements;
does not mislead users into believing they are interacting with a human when they are not, unless this is obvious from the context (e.g. clearly fictional or game-like scenario).
You should ensure that your own branding, UX, scripts or marketing materials do not obscure, contradict or undermine this notice (e.g. implying the assistant is a human employee when it is not).
Where you heavily customise the chatbot’s behaviour, tone or interface, assess whether the AI nature remains clear to a reasonably well-informed user.
Recommended actions
Review your chatbot/assistant implementations (on your site, landing pages, clients’ sites, etc.).
Confirm in writing with your provider that their system is designed to comply with Article 50(1) of the AI Act.
If needed, add your own supplementary notices (e.g. in FAQs, terms of use, privacy policy) stating that certain interactions are AI-powered.
Train your teams and clients to avoid representations that could mislead users about the human or non-human nature of the assistant.
4. Do you create realistic AI-generated images, audio or video (deepfake-style)?
Under Article 50(4) of the AI Act, deployers of AI systems that generate or manipulate audio, image or video content that falsely appears to a reasonable person to be authentic or truthful (commonly referred to as deepfakes) have a specific transparency obligation.
When does this apply?
This obligation applies when you publish or distribute content (e.g. ads, social posts, videos, audio clips, visuals) that:
is artificially generated or manipulated using an AI system; and
resembles existing persons, objects, places, events or actions in a way that could mislead a reasonable person into believing the content is authentic or truthful.
Your obligation as a deployer:
You must clearly disclose that the content has been artificially generated or manipulated.
This disclosure must be made at the latest at the time of first exposure to the content (e.g. when a user first sees the image, starts watching the video, or hears the audio).
The disclosure must be understandable and perceptible without the need for technical tools (i.e. a human can see or hear it directly, without needing special software).
Exceptions and attenuations
The obligation does not apply where the content forms part of an artistic, creative, satirical, fictional or analogous work, provided that its use is appropriately disclosed in a manner that does not unduly impair the experience of the work (e.g. notice in the intro, credits, description, depending on the medium).
The obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.
Recommended actions
Identify all marketing and communication assets where you use realistic AI-generated or manipulated images, audio or video (e.g. synthetic presenters, voice clones, deepfake-style visuals).
For each such asset, implement a clear, visible/audible label, for example:
“AI-generated image”;
“This video includes synthetic elements”;
“Voice generated by AI”.
Place the notice:
for videos: at the start and/or in a persistent on-screen label;
for images: in the caption or immediately adjacent text;
for audio: at the beginning of the clip or via an audible disclaimer.
For artistic, satirical or fictional content, ensure the disclosure is appropriate to the medium (e.g. in the intro, credits, description) and does not ruin the experience while still informing the audience.
Keep an internal register of AI-generated assets and how they are labelled, as part of your compliance documentation.
5. Do you publish AI-generated text to inform the public on matters of public interest?
You publish AI-generated text for public-interest information, which triggers specific transparency obligations.
Under Article 50(4) of the EU AI Act, deployers that publish text generated by an AI system with the purpose of informing the public on matters of public interest must disclose that the text is AI-generated, unless certain conditions are met.
What counts as “text to inform the public on matters of public interest”?
This typically includes content such as:
news articles and press releases on political, economic, social or environmental developments;
public communications on health, safety, security or major scientific/technical issues;
policy briefs, position papers or thought-leadership articles intended to inform public debate on significant societal issues.
Your obligation as a deployer
You must clearly disclose that the text has been generated by an AI system.
This disclosure must be made in a manner that is clear and understandable to the average reader.
Exception – human editorial responsibility:
The disclosure obligation does not apply if a natural or legal person has exercised editorial responsibility over the content and has substantively reviewed it before publication.
“Substantive review” means more than light editing or spellchecking; it implies real human oversight over the substance, accuracy and framing of the content (fact-checking, validation of claims, editorial approval).
If you rely on this exception, you must be able to demonstrate that such human review took place (e.g. documented editorial process, named responsible editor, workflow records).
Exceptions for law enforcement:
The obligation does not apply where the AI system is used by competent authorities for the detection, prevention, investigation or prosecution of criminal offences, subject to applicable safeguards.
Recommended actions
Identify all channels and content types where you publish AI-generated text intended to inform the public on matters of public interest (website articles, press releases, white papers, LinkedIn long-form posts, etc.).
For each such content type, assess whether:
there is real human editorial review (fact-checking, validation of substance, editorial sign-off); or
the text is only lightly edited or published as-generated.
If there is no substantive human review:
add a clear notice, for example: “This article was written with the help of AI.” or “Text generated by AI, then reviewed by our editorial team.” (only if review is real).
If there is substantive human review:
document your editorial process (who reviews, what checks are performed, who has authority to approve/alter/reject the content);
retain records that can demonstrate this process if questioned by regulators.
Include these rules in your internal editorial guidelines and train your content and communications teams accordingly.
6. Do you use emotion recognition or biometric categorisation systems?
You deploy emotion recognition or biometric categorisation systems, which are subject to strict transparency and data protection rules.
Under Article 50(3) of the EU AI Act, deployers of AI systems used for emotion recognition or biometric categorisation have specific transparency obligations towards the natural persons exposed to such systems.
Scope
This applies where you use AI systems that:
infer or analyse emotions, intentions or psychological states of natural persons (emotion recognition); and/or
categorise natural persons based on biometric data (e.g. facial features, voice, gait) to deduce sensitive or personal characteristics (biometric categorisation).
Examples in a marketing/agency context may include:
in-store or event-based systems analysing facial expressions or emotions;
online tools inferring emotional states from webcam or voice;
segmentation tools categorising individuals based on biometric characteristics.
Your obligation as a deployer:
You must inform natural persons who are exposed to the operation of such systems that the system is being used.
This information must be provided in a clear and understandable manner, at a time and in a format that allows persons to become aware of the system’s operation (e.g. signage, notices, digital banners, QR codes linking to detailed information).
You must also comply with all applicable data protection rules, in particular the GDPR, including requirements on:
lawful basis for processing;
transparency (privacy notices);
data minimisation and purpose limitation;
security and retention;
data subject rights.
Prohibitions and high-risk considerations:
Certain uses of emotion recognition systems are prohibited under Article 5 of the AI Act, for example:
emotion recognition in the workplace;
emotion recognition in educational settings;
certain forms of real-time remote biometric identification in publicly accessible spaces for law enforcement purposes (with narrow exceptions).
If your use case falls under these prohibitions, you must not use such systems in those contexts, regardless of any transparency measures.
Recommended actions
Map all uses of emotion recognition or biometric categorisation systems in your own operations or for your clients (physical locations, online experiences, events, HR tools, etc.).
For each such use:
verify whether it is prohibited under Article 5 of the AI Act (e.g. workplace, education); if yes, discontinue that use.
implement clear, visible notices informing persons that such a system is in operation (e.g. “This device uses an AI-based emotion recognition system”).
ensure your privacy notices and GDPR documentation cover these systems (purpose, legal basis, data categories, retention, rights, etc.).
Conduct, where appropriate, a data protection impact assessment (DPIA) under the GDPR, given the sensitive nature of biometric and emotional data.
Train your teams and clients on the high-risk nature of these technologies and the need for strict compliance with both the AI Act and GDPR.
7. Do you only use AI for internal tasks (brainstorming, internal docs, non-public content)?
Your current AI use is primarily internal, which limits your direct transparency obligations under Article 50.
If you only use AI systems for internal tasks such as brainstorming, drafting internal documents, internal analysis, or generating content that is not exposed to the public or to natural persons outside your organisation, your direct transparency obligations under Article 50 of the AI Act are likely limited or non-existent for these specific uses.
Why?
Most Article 50 obligations are triggered when:
AI systems interact directly with natural persons outside the provider/deployer organisation (e.g. chatbots on public websites, assistants interacting with clients); or
AI-generated or manipulated content is published or distributed to the public (e.g. ads, social posts, articles, videos); or
natural persons are exposed to emotion recognition or biometric categorisation systems.
Purely internal uses, with no external exposure, generally fall outside these scopes.
Recommended actions
Keep an internal inventory of AI tools and use cases, distinguishing between:
internal-only uses (brainstorming, internal docs, non-public content);
uses that involve external-facing interactions or publications (website, social media, client deliverables, events, etc.).
For internal-only uses:
implement basic responsible-AI guidelines (no confidential or personal data leakage, human review of critical outputs, awareness of biases and limitations).
monitor whether any of these use cases might evolve towards external exposure (e.g. reusing AI-generated content in public communications), which could trigger Article 50 obligations.
Periodically review your AI usage as your activities evolve, to ensure that new public-facing or person-facing uses are assessed for AI Act and GDPR compliance.
Debunking frequent misinformation about the EU AI Act:
-
MYTH.
Text does not systematically require public labeling in every context. Under Article 50(4), text only requires public disclosure if it is published to inform the public on matters of public interest. Furthermore, an explicit exception applies if the text has undergone human review or editorial control by a person/entity holding editorial responsibility. Internal drafts, technical logs, or human-reviewed marketing copy do not need mandatory user-facing labels.
-
MYTH. Not all visuals require a visible label. For deployers, visible disclosure is primarily mandatory for deepfakes (realistic depictions of real persons, places, or events that could mislead people). Abstract art, obviously fictional visuals (e.g., a dragon driving a car), or simple background generation in ads generally fall outside mandatory deepfake labeling. Additionally, providers must embed technical markings (metadata/watermarking), but internal or B2B technical visuals are often exempt.
-
Why this is completely FALSE:
Many businesses believe that liability sits entirely with the AI vendor or developer. This is a dangerous misconception. Regulations explicitly distinguish between Providers (those who build/train AI) and Deployers (businesses, marketers, or individuals who use AI systems for professional purposes). As a deployer, you are directly accountable for how AI is used in your workflows. If your team uses unvetted AI tools ("Shadow AI"), publishes unlabeled synthetic content, or breaches data privacy laws (GDPR) via third-party LLMs, your organization bears the direct regulatory, financial, and brand equity risks. Under the EU AI Act, non-compliance with transparency obligations can result in heavy administrative fines (up to €15M or 3% of global annual turnover) regardless of whether you built the model or simply deployed it.
References (for the legally minded)
Regulation (EU) 2024/1689 (AI Act) – Article 50 (transparency obligations for providers and deployers).
Commission Guidelines on transparency obligations for providers and deployers of AI systems under Article 50(published July 2026, applicable from 2 August 2026).
Code of Practice on Transparency of AI-generated Content (voluntary code assessed as adequate by the Commission and the AI Board).
GDPR (for emotion recognition and biometric categorisation systems, especially Article 9 and DPIA requirements)