Skip to main content
ProjectsServicesAboutBlogContact
pl
← Back to blog

· 4 min read

The EU AI Act: What It Means for Brands and Creative Agencies

ai · law

The EU AI Act: What It Means for Brands and Creative Agencies

The AI Act is the world’s first comprehensive law regulating artificial intelligence. It entered into force on August 1, 2024, but it’s being rolled out in phases, and one of the most important milestones just passed on August 2, 2026. Here’s what it actually covers, and what it means for companies that use AI in marketing, content and brand communication on a daily basis, which, practically speaking, includes most of my own clients.

What the AI Act is, and who it applies to

The AI Act, formally Regulation (EU) 2024/1689, is EU law governing the design, market placement and use of AI systems. Like GDPR, it has extraterritorial reach: it applies not just to companies based in the EU, but to any provider or user whose AI systems reach the EU market or whose output is used within the EU, regardless of where the company is actually based.

In practice that covers a very wide group: not just the makers of AI tools, but also companies, agencies and brands that simply use those tools in their work, for example to generate images, ad copy, customer-service chatbots, or automate recruitment.

Four risk tiers

The AI Act sorts AI systems into four categories, based on their potential risk to people’s rights and safety:

  • Unacceptable risk — systems that are banned outright.
  • High risk — allowed, but under strict requirements (e.g. recruitment, credit scoring, education, healthcare).
  • Limited risk — transparency obligations, e.g. chatbots or AI-generated content.
  • Minimal risk — no additional obligations (e.g. spam filters, AI in video games).

What’s banned

Since February 2, 2025, practices classified as unacceptable risk have been prohibited. The key ones include:

  • social scoring of citizens carried out by public authorities,
  • subliminal manipulation techniques that cause real harm,
  • exploiting vulnerabilities related to age, disability, or a person’s difficult life situation,
  • untargeted scraping of facial images from the internet to build facial recognition databases,
  • emotion recognition in the workplace and in educational institutions (with exceptions for medical and safety purposes).

Transparency obligations: this affects creative work too

This is the part of the regulation most relevant to brands, agencies and content creators. Article 50 of the AI Act introduces an obligation to inform people when they’re dealing with content that’s AI-generated or manipulated:

  • chatbots and conversational assistants must clearly disclose that a user is talking to an AI system, unless that’s already obvious from context,
  • deepfake content (image, audio, video) must be labelled as artificially generated or manipulated,
  • AI-generated text published in the public interest (e.g. news-style articles) is also subject to labelling requirements, with exceptions for content that goes through human editorial review.

For creative agencies, including mine, that’s a concrete, practical takeaway: if a campaign uses an AI-generated voiceover, a synthetic face in an ad, or a fully AI-generated image presented as a real photo, it needs to be clearly labelled as such.

Rollout timeline

  • August 1, 2024 — the regulation enters into force.
  • February 2, 2025 — ban on unacceptable-risk practices, plus a requirement for organizations to ensure staff have adequate AI literacy.
  • August 2, 2025 — rules for general-purpose AI models (like large language models) kick in, along with the oversight structure: the EU AI Office and national supervisory authorities.
  • August 2, 2026 — the bulk of the regulation applies: obligations for high-risk systems and the Article 50 transparency requirements.
  • August 2, 2027 — full application for high-risk systems that are safety components of products already covered by other EU legislation (e.g. toys, medical devices, machinery).

Penalties

Violating the ban on unacceptable-risk practices can result in fines of up to €35 million or 7% of global annual turnover, whichever is higher. Other violations, including those related to high-risk systems or general-purpose AI models, carry fines of up to €15 million or 3% of turnover, and providing incorrect information to supervisory authorities can cost up to €7.5 million or 1% of turnover.

What this means in practice

You don’t need to be a tech company for the AI Act to matter to you. If your marketing communication relies on generative AI (images, copy, voice, video), or you’re using chatbots or recruitment automation tools, it’s worth already:

  • auditing the AI tools your company actually uses, and checking which risk category they might fall into,
  • setting clear internal rules for labelling AI-generated content in marketing materials and social media,
  • checking the terms of the AI vendors you rely on, to see how they themselves meet the regulation’s requirements.

Disclaimer: this is a practical introduction to the topic, not legal advice. For specific or borderline cases, it’s worth consulting a lawyer who specializes in technology law.

Wondering how to actually use AI in your brand communication while staying compliant, without losing authenticity? Get in touch, I’d be happy to talk it through.