AI Act and Marketing: How to Prepare for the New Regulations
Date
3 August 2026
On 2nd August, the new European legislation governing the use of artificial intelligence, the AI Act, came into force. Being prepared is an obligation; being caught off guard could prove costly.
Understanding right from the outset which business processes are at risk and how to adapt your communications is not merely a matter of legal protection, but a critical factor in safeguarding your brand’s standing in the market.
What is it all about? How can you achieve compliance? What are the risks for businesses and organisations?
First and foremost, it is essential to understand how this new regulatory framework operates. It will have a structural impact on the management of communications, marketing, and digital strategies comparable to the rollout of the GDPR regarding data privacy.
What will we cover on this article:
- Why Managing AI Effectively is a Corporate Priority
- The AI Act: From Risk-Based Concepts to Organisational Accountability
- Substantive Differences Between the AI Act and GDPR for Marketers
- Opportunities and Costs of the AI Act
- Complexity, Accountability, and Data Governance in the AI Act Era
- How to Ensure Your Organisation is Prepared
Why Managing AI Effectively is a Corporate Priority
In an landscape where Artificial Intelligence has become a cornerstone of both business and creative operations, setting the boundaries within which this technology operates is no longer merely an ethical choice, but a core strategic priority. In this context, regulations have evolved specifically to safeguard the rights of European citizens, spanning data privacy, intellectual property, the right to information, and protection against misleading advertising.
As is so often the case, regulation arrives when the world has already begun to shift, for better and for worse. While on one hand AI is being adopted across an ever-widening range of sectors, on the other we are witnessing a surge in litigation and regulatory fines related to output copyright infringements, data protection breaches, campaign assets that risk being deemed deceptive, and algorithms embedding themselves into every facet of our daily lives.
Aligning AI strategies with existing regulatory frameworks, such as the GDPR, data governance protocols, and the new AI Act, is the only viable way to manage risk and protect every organisation’s most vital asset: public trust.
The AI Act: From Risk-Based Concepts to Organisational Accountability
Developed by the European Commission to establish the world’s first regulatory framework for Artificial Intelligence, the AI Act was created with a clear objective: to ensure that the development and adoption of AI take place in full compliance with fundamental rights, safety, and transparency.
Far from being a law designed to curb innovation, it provides a structured framework that sets the rules of the game for businesses, public bodies, organisations, and industry professionals alike.
First and foremost, the AI Act introduces a risk-based approach, categorising AI applications into four distinct levels:
- Minimal risk: Tools such as spam filters or AI-powered video games, which are permitted for unrestricted use.
- Limited risk (Transparency): The category that directly impacts marketing and communications. It includes chatbots as well as AI-generated or manipulated content (deepfakes, synthetic visuals, and copy), for which it mandates a clear obligation to inform the end user.
- High risk: Critical systems subject to strict compliance and documentation requirements, such as recruitment and HR selection processes, critical infrastructure management, advanced biometric systems involving facial recognition, or credit scoring algorithms.
- Unacceptable risk: Banned practices, including behavioral manipulation or social scoring (such as the automated profiling of individuals based on social, racial, or physiological characteristics).
The AI Act does not, therefore, impose a rigid set of universal rules applicable to every single post, banner, or campaign.
Much like the rollout of the GDPR a few years ago, the European regulation provides general guidelines and an evaluative framework. Ultimately, however, the responsibility falls on those developing and executing the strategy to assess, on a case-by-case basis, whether the systems or assets created using AI tools present potential risks or negative impacts.
Substantive Differences Between the AI Act and GDPR for Marketers
It would be a mistake to view the AI Act simply as an update or extension of the GDPR. Although both pieces of legislation were established by the European Union to safeguard citizens’ fundamental rights, they operate on entirely separate legal planes.
The fundamental difference lies in the subject matter of the regulation: the GDPR governs the protection and processing of personal data, whereas the AI Act regulates the safety, transparency, and reliability of technological systems and algorithms, irrespective of whether they process personal data.
These two regulatory frameworks are not mutually exclusive; rather, they apply cumulatively.
For instance, a Generative AI tool used for ad campaign personalisation or customer profiling must simultaneously ensure compliance with user privacy (GDPR) and guarantee the absence of discriminatory bias while clearly labelling synthetic content (AI Act).
Understanding where data boundaries end and technology governance begins is the crucial first step towards building marketing workflows that are genuinely secure and scalable.
The table below outlines the key touchpoints and fundamental differences to bear in mind:
| Scope of the comparison | GDPR (General Data Protection Regulation) | EU AI Act (Artificial Intelligence Act) |
| Subject Matter of the Regulation | Personal Data: governs the collection, use, storage and protection of information relating to natural persons. | AI Systems: governs the design, development, placing on the market and use of artificial intelligence models and software. |
| Assessment Criteria | Based on the sensitivity level of the data and the purposes of the processing (e.g. health data vs. work email). | Based on the risk level of the AI system (Unacceptable Risk, High, Limited, Minimal). |
| Key Player in Marketing | User consent, profiling for direct marketing, cookie tracking, rights of access and erasure. | Transparency of outputs (watermarks on images and summary texts), labelling of chatbots and prevention of bias. |
| Roles and Parties Involved | Data Controller and Data Processor. | Provider and Deployer. |
| Assessment Tools | DPIA (Data Protection Impact Assessment): privacy and data impact assessment. | FRIA (Fundamental Rights Impact Assessment): assessment of the impact on fundamental human rights (for high-risk contexts) and system compliance. |
| Sanctions Regime | Up to 20 million euros or up to 4% of the company’s annual global turnover. | Up to 35 million euros or up to 7% of annual global turnover (depending on the seriousness of the breach). |
Opportunities and Costs of the AI Act
The entry into force of the AI Act introduces a regulatory framework that transforms how brands must plan their communications, bringing with it new operational demands alongside valuable strategic opportunities.
Chief among these advantages is a clear model of accountability for businesses and professionals alike. This serves to define the legal and ethical boundaries of algorithmic use, safeguarding the brand (or the identity of the institution or organisation) against reputational crises and copyright infringements. Furthermore, the inherent design of this regulation provides a robust, future-proof framework capable of withstanding rapid technological evolution without forcing organisations into a state of constant readjustment.
Conversely, there is an undeniable new operational burden: allocating time, resources, and capital to evaluate every application of AI on a case-by-case basis, effectively eliminating the possibility of relying on standardized or fully automated solutions.
Complexity, Accountability, and Data Governance in the AI Act Era
The entry into force of the European regulation represents a fundamental step towards the ethical use of technology, yet it presents marketers with three direct challenges:
- Regulatory overlap: The AI Act does not operate in isolation; rather, it is closely intertwined with the GDPR, copyright law, and consumer protection frameworks. Ensuring that AI-generated promotional content complies with training data sourcing, copyright, and labelling obligations requires ongoing, multidisciplinary analysis.
- Interpretation of liabilities: Clearly distinguishing between the roles of technology developers (Providers) and those implementing it in the market (Deployers) is critical. Without defined internal guidelines, marketing teams risk operational paralysis driven by the fear of sanctions, or excessive recklessness that exposes the brand to reputational crises.
- Data governance and trust: The security and reliability of AI models depend directly on the quality and traceability of the data fed into them. Maintaining transparency across these processes is not merely about avoiding severe legal penalties, it is an indispensable requirement for protecting public trust.
How to Ensure Your Organisation is Prepared
In a rapidly evolving technological landscape, the AI Act is not a drag on innovation, but rather an accelerator for market transparency and credibility. So, how can organisations ensure they are prepared?
There are several steps to follow:
1. Assessment of Internal Processes
The first step is to understand where and how Artificial Intelligence is already being used. It is essential to audit official tools, features integrated into existing software, and applications adopted independently by staff, bringing to light any unformalised or shadow usage. This mapping exercise enables the organisation to identify its specific regulatory role, assess the level of risk, and establish key priorities for action. The end result should be a dynamic, continuously updated register, not a static snapshot destined to quickly become obsolete.
2. Vendor Assessment
A significant proportion of the AI systems used by organisations originates from third-party suppliers. Consequently, evaluating an individual tool in isolation is no longer sufficient: businesses must map out the entire supply chain. Indeed, the AI Act distributes responsibilities across the entire value chain.
3. Reviewing Contracts
Contracts must also accurately reflect what occurs at an operational level. Contractual frameworks are not intended to eliminate an organisation’s liability; rather, they must render that liability manageable and governable.
4. Updating Policies and Procedures
Following the analysis phase, recommendations must be translated into concrete operational procedures. These procedures need to align seamlessly with existing policies covering data privacy, cybersecurity, intellectual property, human resources, and corporate communications.
5. Training
AI literacy is indispensable, and it must be tailored to the specific needs and operational functions of the organisation.
6. Choosing the Right Partners
Choosing the right partners means collaborating with organisations that are already proactively addressing these issues, businesses structured to comply with new regulatory frameworks and backed by appropriate insurance coverage extending beyond standard public and professional liability to cover cyber risks specifically.
At SAY, we have established dedicated procedures and frameworks to navigate these scenarios. Furthermore, beyond merely managing risk, we have structured our operations to capitalise on the opportunities. We view Artificial Intelligence as a performance accelerator: from content production and advanced data analytics to visual experimentation, we transform emerging technologies into tangible solutions. We achieve this by combining research, human validation, and regulatory compliance to convert innovation into genuine,
Partnering with SAY S.p.A. means choosing an agile, forward-thinking partner equipped to guide your strategic decisions with agility, providing communication tools and content assets that remain fully compliant with regulatory frameworks, no matter how complex.
Discover how we can empower your business
Regulatory Sources & References:
- Regulation (EU) 2024/1689 – EU AI Act: Official text of the Artificial Intelligence Act. It addresses risk classification, corporate AI literacy (Art. 4), prohibited practices (Art. 5), risk management systems (Art. 9), human oversight (Art. 14), Fundamental Rights Impact Assessment — FRIA (Art. 27), and transparency and watermarking obligations for synthetic content (Art. 50).
- 🔗 EUR-Lex (Regulation EU 2024/1689)
- 🔗 European Commission Press Release & Factsheets (IP/21/1682)
- Regulation (EU) 2016/679 – GDPR (General Data Protection Regulation): European framework governing personal data protection, focusing on definitions (Art. 4), processing principles (Art. 5), automated decision-making and profiling (Art. 22), and Data Protection Impact Assessments — DPIA (Art. 35).
- 🔗 EUR-Lex (Regulation EU 2016/679)
- European Parliament Research Service (EPRS): Research studies and publications from the European Parliament’s research center regarding copyright of AI-generated works, as well as the economic and governance impacts of the AI Act on digital services and marketing.
- 🔗 EPRS Research Archive – European Parliament
- Copyright, Case Law, and Generative AI: Ongoing monitoring of landmark cases and international jurisprudence regarding copyright and the use of generative outputs via the Taylor Wessing AI & Copyright Case Tracker.
- 🔗 Taylor Wessing – AI & Copyright Case Tracker
- Compliance Guidance, Regulatory Intersections, and Enforcement Regimes: Guidelines and cross-regulatory analysis on the interplay between the AI Act and the GDPR, produced by the European Data Protection Board (EDPB), the European Data Protection Supervisor (EDPS), and the International Association of Privacy Professionals (IAPP).
- 🔗 European Data Protection Board (EDPB)
- 🔗 IAPP – Mapping the Interplays: EU AI Act and GDPR