The AI Act and marketing: what actually affects us?
For most marketing tasks the AI Act changes little — anyone using language models for texts and analysis is a deployer, not a provider. It becomes relevant in three places, and those are better known in advance.
In short
- Anyone using finished tools is a deployer, not a provider — considerably lighter obligations follow from that.
- Most marketing applications fall into the lowest risk class: draft texts, analyses, translations.
- Four obligations are practically relevant: competence, transparency in direct interaction, labelling of certain content, and care with personnel decisions.
- Substantially modifying a system or offering it under your own name turns a deployer into a provider — with considerably more obligations.
Provider or deployer
The most important distinction, because it determines the entire scope of obligations.
| Role | Who that is | Scope of obligations |
|---|---|---|
| Provider | develops an AI system or places it on the market under their own name | extensive |
| Deployer | uses an AI system in their own name for their own purposes | manageable |
A company using a language model for draft texts is a deployer. A company building a model into its own product and selling that under its own name can become a provider — as can anyone substantially modifying a system or using it for a purpose other than the one the maker intended.
Worth knowing
The switch from deployer to provider happens more easily than you would think — and it is the most consequential fork in the whole framework.
Anyone integrating a model and offering the result under their own name as a product or service can slip into the provider role. The same applies on substantial modification, or on use for a purpose other than the intended one. Anyone considering an AI-supported feature of their own for customers should settle that question before building, not afterwards.
The risk classes in a marketing context
Prohibited
Among other things, manipulative techniques that influence behaviour subliminally and can cause harm, as well as exploiting vulnerability.
In marketing: not touched in ordinary practice — it becomes relevant with heavily personalised targeting that exploits detected vulnerability.
High-risk
Applications in certain areas, including employment and personnel selection.
In marketing: not the marketing work itself — but it does apply if the same software is used for candidate selection.
Subject to transparency
Systems interacting directly with people, as well as certain artificially generated or manipulated content.
In marketing: chat assistants on the website, and machine-generated image, audio or video content that appears genuine.
Low risk
The normal case: draft texts, translations, summaries, analyses, topic research.
In marketing: this is where by far the largest part of the work happens.
The four practically relevant obligations
- Competence in handling. Staff using AI systems need a sufficient understanding of them. In practice that means training and a short written rule — both sensible anyway.
- Transparency in direct interaction. Anyone writing to a chat assistant has to be able to tell they are not talking to a person — unless it is obvious anyway.
- Labelling of certain generated content. Particularly artificially generated or manipulated image, audio and video content that could depict real people or events. This does not apply in the same way to abstract illustrations.
- Particular care with personnel decisions. As soon as AI systems play a part in selecting or assessing staff, considerably stricter requirements apply.
Point one is the only one affecting practically everyone — and it can be handled with what is due anyway: one page of rules and an introduction spread over a few weeks.
Have those two things and you meet the competence part while also getting the operational benefit. Conversely: writing the rule only to tick off an obligation gets you neither — it only gets read if it belongs to the work.
Does this apply to Swiss companies?
Switzerland has not adopted the AI Act. It can nonetheless reach Swiss companies if they offer AI systems in the EU or if the output of those systems is used in the EU.
Independently of that, Switzerland is preparing its own regulation. For practice that means: settle competence, transparency and accountability cleanly today and you are prepared for both directions — and have the operational benefit immediately.
Help me work out what the AI Act means for our marketing. Our situation: - Location and markets: [countries] - AI-supported applications we use: [list with purpose] - Do we offer customers an AI-supported feature? [yes/no, what] - Do we have a chat assistant on the website? [yes/no] - Do we generate image, audio or video content by machine? [yes/no, what kind] - Do we use AI in candidate selection or staff assessment? [yes/no] Tasks: 1. For each application named, work out whether we would be deployer or provider. Name the cases where it could tip. 2. Assign each application to a risk class and justify it. 3. Name which of the four practically relevant obligations affect us: competence, transparency in interaction, labelling of generated content, care with personnel decisions. 4. Tell me which of our details are not sufficient for a confident classification and what an expert has to assess. 5. Name what we should do anyway, independently of the legal obligation. Do not invent article numbers or deadlines. Where you are uncertain, say so.
In closing
For ordinary marketing work the AI Act changes little: draft texts, translations and analyses fall into the lowest class, and anyone using finished tools is a deployer.
Three places deserve attention: a chat assistant with direct interaction, machine-generated content that could appear genuine, and any contact with personnel decisions. And a fourth that is easily missed: the switch to the provider role as soon as something AI-supported is offered under your own name.
Common questions
Does the AI Act affect ordinary marketing?
Little, in ordinary practice. Draft texts, translations, summaries and analyses fall into the lowest risk class, and anyone using finished tools is a deployer and not a provider — considerably lighter obligations follow from that.
What is the difference between provider and deployer?
A provider develops an AI system or places it on the market under their own name; a deployer uses a system in their own name for their own purposes. The switch happens more easily than expected — for instance when a model is built into your own product and that is sold under your own name, or on substantial modification.
Which obligations are relevant for small companies?
Four: sufficient competence among staff in handling the systems used; transparency when people interact directly with a system; labelling of certain machine-generated content; and particular care as soon as AI plays a part in personnel selection or assessment.
Do AI-generated texts have to be labelled?
The labelling obligations aim above all at artificially generated or manipulated image, audio and video content that could depict real people or events. This does not apply in the same way to ordinary professional texts and abstract illustrations — in case of doubt the assessment belongs with an expert.
Does the AI Act apply to Swiss companies?
Switzerland has not adopted it. It can nonetheless reach Swiss companies if they offer AI systems in the EU or the output is used there. Independently of that, Switzerland is preparing its own regulation — settle competence, transparency and accountability cleanly today and you are prepared for both.
Marketing that sets itself up
The Studio Engine beta is live. Claim your spot and help shape it from the start.
Join the beta →