Cover image for “The EU AI Act is a 2026 problem for marketers, not a 2027 one”
← essays · 2026-06-30

The EU AI Act is a 2026 problem for marketers, not a 2027 one

Everyone read the headline that the high-risk rules got delayed to 2027. The part that binds marketing teams — Article 50 transparency and disclosure — goes live August 2, 2026, and it covers your AI spokespeople, avatars, voiceovers, and chatbots. What's actually due, and what to do before the deadline.

Current as of June 30, 2026. A planning guide for marketers, not legal advice — confirm specifics with counsel for the markets you operate in.

The headline most marketing leaders took away from the EU AI Act this year was relief: the hardest obligations slipped. In May 2026, EU legislators agreed a Digital Omnibus that pushed the standalone high-risk rules from August 2026 to December 2, 2027, and the product-embedded ones to August 2, 2028. Plenty of teams filed the Act under “deal with it next year.”

That was the wrong file. The part of the Act that actually governs what a marketing team ships every day is Article 50, the transparency and disclosure regime, and it was not delayed. It applies on August 2, 2026. If you produce AI content for the EU market, that deadline is weeks away, and most of the obligations land on you as the deployer, not on the vendor whose model you used.

What got delayed, and what didn’t

The Act entered into force on August 1, 2024 and switches on in waves. The bans on the worst practices and the AI-literacy duty took effect in February 2025. The rules for general-purpose models took effect in August 2025. The high-risk rules — the conformity assessments, the technical files, the registration in an EU database — are the heavy compliance lift, and those are what the Omnibus moved into 2027 and 2028.

Article 50 sits between those. It is not high-risk; it is a disclosure obligation that applies to ordinary AI systems, and the Omnibus left its August 2, 2026 date intact. One narrow concession: for AI systems already on the market before that date, the machine-readable watermarking duty in Article 50(2) gets a four-month grace period to December 2, 2026. Everything else in Article 50 starts on schedule.

One caveat worth watching: as of late June 2026 the Omnibus is an agreed text, not yet published in the Official Journal. Until it is, the original deadlines technically stand, which only raises the stakes on the August date. DLA Piper flagged this: plan against August 2, 2026, not against the relief you read about.

The four things Article 50 actually requires

The Commission’s draft guidelines, published May 8, 2026, spell out four scenarios. Two are mostly the model provider’s job. Two are yours.

Chatbot disclosure. Any AI system that interacts with a person has to tell them they’re dealing with AI, at the first interaction, unless it’s obvious from context. Customer-service bots, virtual assistants, agentic systems acting on a user’s behalf. Burying it in the terms of service does not count. This is a provider duty, but if you build the bot’s front end, you own the disclosure UX.

Synthetic-content watermarking. Providers of generative systems have to embed machine-readable markers so outputs can be detected as AI-made. This is a technical duty on the model maker, not on you. Your job is to make sure your vendor contracts require it, and to know which of your tools comply.

Emotion recognition and biometric categorization. If you deploy a system that infers a customer’s emotional state or sorts people by inferred demographic traits, you have to tell the people being assessed, in real time, and you need a lawful basis under the GDPR. An in-store or on-site system that reads shopper mood or categorizes faces triggers this.

Deepfakes and AI-generated public text. This is the provision that catches marketing, and it is broader than the word “deepfake” suggests. If you deploy AI to create image, audio, or video that resembles a real person, place, or event and could plausibly look authentic, you have to disclose that it’s AI-generated. The Commission’s guidance makes three points that surprise people: intent to deceive is irrelevant, the test is whether your actual audience could believe it’s real, and a fictitious-but-realistic AI human counts. The examples the Commission called out by name are a marketing brief: AI-generated videos with realistic presenters, synthetic brand ambassadors, AI voiceovers that sound like a real person, AI-altered footage of a person, AI photos of events that never happened, digital avatars in customer communications.

The same provision covers AI-generated text “published to inform the public on matters of public interest.” There’s an editorial carve-out, but the guidelines read it narrowly: a human skimming the AI’s copy doesn’t qualify; you need substantive review by someone with professional competence who holds editorial responsibility. If your content program runs on AI drafts touching social, economic, or policy topics, this is a question for you, not a hypothetical.

Disclosure has to be clear and come at first exposure. For video, that means a persistent or repeated label, because viewers join midway. For audio, an audible disclaimer. For a static image, a permanent, consistently placed mark.

The rule that’s already in force

One piece you don’t get to plan for, because it’s been enforceable since February 2025: the Article 5 ban on AI that uses subliminal or manipulative techniques to materially distort behavior, especially by exploiting vulnerabilities tied to age, disability, or economic circumstance. Hyper-personalized targeting that crosses from persuasion into overriding a person’s ability to decide is the exposure here. The Commission published three studies on this provision in May 2026 and is still working on where the line sits between personalization and manipulation. Until that guidance lands, the safe reading is the strict one.

Where marketing crosses into high-risk

The 2027 delay matters if your team touches functions beyond marketing. AI used for recruitment, CV screening, performance evaluation, or promotion and termination decisions is high-risk under Annex III, as is AI used in creditworthiness or insurance decisions. A marketing org that runs AI hiring tools, or that personalizes financial offers in a way that shapes credit access, inherits the full high-risk compliance load: conformity assessment, a risk-management system, human oversight, registration. That’s the work that moved to December 2027. The transparency work did not move.

The models you use, not the ones you build

You’re almost certainly a downstream deployer of foundation models, not a model provider, so the general-purpose AI rules that took effect in August 2025 hit you indirectly. Your providers have to publish training-data summaries, keep a copyright policy, and hand downstream users documentation on capabilities and limits. Ask for it. Confirm your vendors signed the GPAI Code of Practice or can show equivalent compliance, and write that requirement into contracts. One trap: if you fine-tune a model enough to materially change its capabilities, you can become a provider yourself, with the duties that follow.

What it costs to get this wrong

The fines are tiered above the GDPR’s ceiling. Prohibited practices under Article 5 run to €35 million or 7% of global annual turnover, whichever is higher. Transparency and high-risk violations run to €15 million or 3%. Enforcement of Article 50 falls to national market-surveillance authorities; general-purpose model oversight sits with the EU AI Office. No headline fines had landed as of June 2026, but the Commission was explicit that enforcement ramps as the August deadline passes, and that organizations which don’t sign the Code of Practice on AI-generated content (published June 10, 2026) carry a heavier burden to prove compliance on their own.

This is the inverse of the US picture, where the federal posture turned deregulatory in 2025 and the real rules live in a contested state patchwork. A global marketing team gets the worst of both: one extraterritorial European framework with teeth, and fifty moving US targets. I mapped that split in more detail in the regulatory landscape brief.

What to do before August 2

  1. Inventory every AI tool in content production, customer interaction, and ad targeting. You can’t disclose what you haven’t catalogued.
  2. Classify each against Article 50’s four scenarios. Most marketing tools land in chatbot disclosure or deepfake/synthetic-content disclosure.
  3. Build disclosure into the product, not the footer. First-interaction chatbot notice; a persistent label on synthetic video; an audible note on AI voice.
  4. Push the watermarking duty onto your vendors in writing, and confirm which tools already comply before the December 2026 grace period closes.
  5. Decide the editorial question for AI-generated public-facing text: real human review with named responsibility, or disclosure.
  6. Sign the Code of Practice on AI-generated content. Signatories get a presumption of compliance; everyone else has to build the argument from scratch.
  7. Audit your targeting against the Article 5 manipulation ban, which is already live.

The high-risk delay bought time for the heaviest engineering. It bought marketing teams nothing. The work that’s actually due is disclosure, it’s due August 2, 2026, and most of it is UX and contract language you can ship now.