Skip to content
✨ Discover What's Waiting For You - Start Free Today
AI Marketing

How the EU AI Act Will Reshape Marketing Compliance


The Gist

  • Compliance, not choice. Anthropic added watermarks to Claude’s output to meet the EU AI Act’s August 2 enforcement deadline, not as a voluntary transparency move.
  • Deployers carry real risk. Most marketers count as “deployers” under the Act, and noncompliance with high-risk rules or missed disclosures can trigger fines up to 3% of worldwide turnover.
  • Personalization tactics need a second look. Bans on manipulative techniques, emotion inference and certain biometric uses could catch common marketing AI applications off guard.

Anthropic recently revealed that its models will now watermark all text produced by its Claude system, enabling other systems to identify it as AI-generated. As Anthropic’s own statement makes clear, this was not a benevolent step toward AI transparency, but last-minute compliance with the Aug. 2 enforcement date of the European Union’s AI Act. (If you’re keeping score, OpenAI still doesn’t watermark system-generated text, although it does label AI-generated graphics and audio.)

The practical impact of Anthropic’s watermarks is likely to be limited, although Anthropic raised some alarms by stating that even human-produced content might be flagged if it’s run through Claude for editing.

The more important effect of the announcement may be that it reminds marketers about the AI Act, which has attracted much less attention than earlier EU regulations such as GDPR. Most discussion seems limited to the requirement that consumers be informed when they’re interacting with AI-generated text, images, and other outputs. But there’s considerably more to the Act than that.

(This is a good place to note that I’m not a lawyer and you need competent legal advice on compliance.)

FAQ: EU AI Act Compliance for Marketers

Editor’s note: These questions address what Anthropic’s Claude watermarking update means for marketers who deploy AI tools subject to the EU AI Act.

How the EU AI Act Classifies AI Systems and Who’s Liable

Let’s start with the structure of the law itself. It defines four classes of AI applications: prohibited, high-risk, limited risk (chatbots and deepfakes) and minimal risk (such as video games and spam filters). It further distinguishes between AI system developers and AI system deployers (which would be most marketers). It’s up to developers to avoid providing prohibited functions and to carefully govern the high-risk ones.

But deployers are responsible for notifying consumers when they are interacting with limited-risk AI systems and for following instructions provided by the developers for high-risk systems. If your company deploys a prohibited application or fails to follow the rules governing high-risk applications, you could be fined up to 3% of worldwide annual turnover.

What AI Uses Are Banned Under the Act

So, what’s prohibited? The list is long but the applications most relevant to marketers include manipulative or deceptive techniques, social scoring and inferring emotion. Other prohibitions relate to biometrics, which is clearly an EU hot button: the rule explicitly bans compiling facial recognition databases through untargeted internet scraping, using biometrics to infer sensitive attributes such as race, religion, political opinions and sexual orientation, and law enforcement use of biometrics for real- time remote identification in public spaces and assessing the risk of committing crimes.

Of course, one person’s evil manipulation is another person’s clever marketing hack, so it’s particularly important to consider whether any of your current AI programs run afoul of the new rules.

Related Article: Does Your Chatbot Meet EU AI Act Disclosure Rules?

Where High-Risk AI Rules Hit Marketing and HR

High-risk applications relate mostly to government: law enforcement, judicial administration, safety, critical infrastructure, influencing elections, public services, and border control. But they also include using AI to manage access to education, training, insurance and employment, which could apply to private businesses as well. The rules related to these are largely concerned with governance, including risk management, data governance, technical documentation, record-keeping, human oversight, quality management and usage instructions.

View All

What Deployers Must Do to Stay Compliant

Deployers inherit many of these requirements through their responsibility to follow usage instructions. In addition, they have obligations to monitor system operations, assign competent human oversight, suspend use if there’s a risk, keep logs and report problems. All this is in addition to the better-publicized requirements to inform individuals when they’re exposed to AI-written text (on matters of public interest and if not reviewed by humans), deepfakes, emotion recognition, and biometric identification.

EU AI Act Compliance Checkpoints for Marketing Teams

The following table highlights the most important lessons, actions and strategic considerations emerging from Anthropic’s Claude watermarking update and the EU AI Act’s compliance requirements for marketers.

Key Area What Happened Why It Matters Recommended Action
AI Content Labeling Anthropic began watermarking all Claude-generated text to comply with the EU AI Act’s August 2 deadline Marketers using Claude for content creation or editing may see human-written text flagged as AI-generated Audit AI-assisted content workflows and confirm how watermarking affects published assets
System Classification The Act sorts AI applications into prohibited, high-risk, limited-risk and minimal-risk tiers Marketing tools often fall into limited-risk or high-risk categories with different obligations Map every AI tool in use against the Act’s four risk tiers
Deployer Liability Deployers — most marketers — must follow developer instructions and disclose limited-risk AI use to consumers Noncompliance carries fines up to 3% of worldwide annual turnover Build a disclosure and documentation process for every consumer-facing AI application
Prohibited Practices The Act bans manipulative/deceptive AI techniques, social scoring, emotion inference and several biometric uses Common marketing personalization tactics could cross into banned territory Review AI-driven personalization and targeting tools for manipulative or biometric-inference risk
Supplier Monitoring AI vendors like Anthropic will keep changing systems to meet the Act’s requirements Vendor changes can shift a marketer’s own compliance posture overnight Assign an owner to track vendor compliance updates and reassess quarterly

4 Steps Marketers Should Take Now

In short, the AI Act dumps quite a bit on marketers’ already crowded plates. Many of the obligations are really just good practice, so organizations with strong AI foundations in place may find there’s little additional burden. Others may need to beef up their existing governance capabilities to comply. Either way, if your company does business in the EU, here are some things to look at (after talking to your lawyer).

  • Assess your existing systems for compliance. The most common gap will likely be notifying individuals when they are interacting with limited-risk AI. But take a close look at whether you have any prohibited or high-risk applications in place and modify your systems and practices accordingly.
  • Identify instructions provided by AI developers and ensure you are following them. Such instructions may not always exist and are likely to evolve over time. Remember that, however they change, your firm is responsible for following them.
  • Develop adequate reporting and record keeping procedures if these aren’t already in place. The AI Act is quite specific about what’s required and even well-organized companies may find they don’t fully meet the EU’s bureaucratic standards. The good news is that, like most EU regulations, the AI Act cuts some slack for small businesses.
  • Keep an eye on your AI suppliers. Like Anthropic, AI developers will continue to modify their systems to meet the requirements of the Act. Some of these changes may require changes in your own applications or, on the bright side, make your own compliance easier. There’s also a good chance that some systems will banned in the EU or voluntarily withdrawn by their developers. Prepare plans to deal with business disruption if you lose access to a critical system.

Learn how you can join our contributor community.



Content Curated Originally From Here