The EU AI Act is the world's first comprehensive AI law. It regulates AI by risk tier — banning some uses outright, imposing strict obligations on "high-risk" AI, requiring transparency for others, and leaving minimal-risk uses largely free. It applies to any company whose AI systems are used in the EU, not just European ones.
If your product, marketing, or operations touch the EU market, the AI Act likely reaches you. Here's a plain-language explanation of how it works and what to do.
The risk-tier structure
The Act's core idea is that obligations scale with risk. It sorts AI uses into four tiers:
Unacceptable risk — banned
A small set of uses are prohibited outright, such as social scoring by governments and certain manipulative or exploitative systems. These can't be deployed in the EU at all.
High-risk — strict obligations
AI used in sensitive areas — things like employment and hiring, credit, critical infrastructure, education, and certain safety components — faces the heaviest requirements: risk management, data governance, documentation, human oversight, transparency, and conformity assessment. This tier is where most compliance work concentrates.
Limited risk — transparency
Systems like chatbots and generative AI carry transparency duties: people must be told they're interacting with AI, and AI-generated content (including deepfakes) must generally be disclosed. This tier matters a lot for marketing.
Minimal risk — largely unregulated
The majority of AI uses — spam filters, recommendation features, and the like — fall here and face few specific obligations.
Who it applies to
Like GDPR, the AI Act has extraterritorial reach: it applies to providers and deployers whose AI systems are used in the EU, regardless of where the company is based. A US company whose AI touches EU users or customers can be in scope. There are also specific obligations for providers of general-purpose AI models.
Timeline
The Act entered into force in 2024 and applies in phases: the bans on unacceptable-risk uses came first, obligations for general-purpose AI and other provisions follow on a staggered schedule, and the full high-risk regime phases in over a longer window. The practical implication is that obligations are arriving in waves, so mapping your exposure now avoids a scramble later.
What to do about it
Start by figuring out which of your AI uses fall into which tier — most compliance effort belongs on high-risk and limited-risk (transparency) uses. That classification comes out of an AI risk assessment, and it feeds directly into your AI use policy. For marketers specifically, the transparency obligations around chatbots and AI-generated content are the ones to get ahead of — see responsible AI in marketing. The EU AI Act also pairs naturally with voluntary frameworks like the NIST AI RMF and ISO 42001, which help you operationalize the requirements.
This is an overview, not legal advice; for binding interpretation involve counsel. If you want your exposure mapped and a compliance plan built, that's our AI compliance and policy assessment.
Frequently asked questions
What is the EU AI Act?
It's the first comprehensive AI law, regulating AI by risk tier: banning unacceptable-risk uses, imposing strict obligations on high-risk AI, requiring transparency for limited-risk uses like chatbots and generative AI, and leaving minimal-risk uses largely free.
Does the EU AI Act apply to US companies?
It can. Like GDPR, it has extraterritorial reach and applies to providers and deployers whose AI systems are used in the EU, regardless of where the company is based.
What are the EU AI Act's risk tiers?
Unacceptable (banned), high-risk (strict obligations like risk management, documentation, and human oversight), limited-risk (transparency duties, e.g. disclosing AI and AI-generated content), and minimal-risk (few specific obligations).
What does the EU AI Act mean for marketing?
Mainly the transparency tier: people must be told when they're interacting with AI (chatbots), and AI-generated content and deepfakes must generally be disclosed. Marketers should get ahead of these disclosure obligations.
How do I prepare for the EU AI Act?
Classify your AI uses by risk tier via an AI risk assessment, focus compliance on high-risk and transparency uses, write it into your AI policy, and consider frameworks like the NIST AI RMF and ISO 42001 to operationalize it. Involve legal counsel for binding interpretation.