The EU AI Act Has Reached the Marketing Department
For many businesses, the EU AI Act has sounded like a problem for technology companies, lawyers and compliance teams.
That assumption is now dangerous.
From 2 August 2026, important transparency requirements are being enforced across the European Union. They concern chatbots, AI-generated or altered material, machine-readable identification and deepfakes.
These are not remote technical issues. They touch advertising, customer service, influencer campaigns, social media, corporate video, synthetic voices and almost every communications team using generative AI.
The AI Act has reached the marketing department.
Using AI is not the same as governing it.
Most marketing and PR teams already use AI in some form. It helps draft copy, translate material, edit images, generate concepts, analyse data and respond to customers.
Adoption has moved faster than policy.
Employees frequently use different tools under different accounts. Agencies and freelancers bring their own systems. Material may pass through several platforms before publication. Few organisations maintain a complete record of where AI was used, which information entered a tool or who approved the final output.
That informal approach becomes difficult to defend once transparency, copyright, privacy or factual accuracy is challenged.
Transparency is now an operational requirement.
The European Commission states that certain interactive AI systems must inform people when they are dealing with AI rather than a human. Deepfake images, video and audio must be labelled, while applicable AI-generated or altered material must carry machine-readable identification.
The exact obligation depends on the system, content and context. Communications teams should obtain appropriate legal advice rather than assuming every use requires the same treatment.
But the practical direction is unmistakable: organisations need to know when AI has materially shaped an interaction or piece of content and whether disclosure is required.
That cannot be decided reliably after publication.
Marketing teams face the most visible failures.
A compliance problem inside a back-office system may remain contained. A synthetic executive video, misleading chatbot answer or undisclosed manipulated image can become public immediately.
The legal question will matter. So will the reputational one.
Audiences may forgive the use of AI. They are far less likely to forgive discovering that a company attempted to conceal it, fabricated evidence or allowed a machine to present inaccurate information as corporate fact.
This is why corporate communication must be involved in AI governance. The communications team understands how a technical failure becomes a public interpretation about honesty, competence and control.
For organisations operating in complex digital environments, Lighthouse PR’s Technology and Cybersecurity Market Expertise also helps connect regulatory language with the realities of public trust and operational risk.
Deepfakes require a clear boundary.
Synthetic media offers legitimate creative opportunities. A company can translate a training video, adapt a spokesperson’s delivery or create clearly fictional campaign material.
The risk begins when a reasonable person could mistake generated content for a real event, statement or endorsement.
Using a synthetic customer, cloning an executive’s voice or altering footage without clear disclosure may save production time while creating disproportionate reputational exposure.
Every organisation needs a defined approval threshold for:
Synthetic or cloned voices
AI-generated people and testimonials
Material alteration of real images or video
Virtual brand representatives
Automated customer conversations
AI-generated claims about products, performance or competitors
“The agency produced it” is not a governance defence. The brand publishing the material owns the consequences.
Confidentiality is part of the communications risk.
The AI Act is not the only concern. Marketing teams regularly handle unreleased financial information, customer data, campaign plans, contracts and sensitive executive material.
Entering that information into an unapproved public AI tool may expose it outside the controls the organisation applies to other business systems.
An effective policy must therefore specify which tools are approved, which information must never be entered, how work is stored and when human review is mandatory.
Training is equally important. A policy hidden on an intranet will not change behaviour if employees cannot recognise the practical risk inside everyday tasks.
Human approval must mean more than clicking "accept".
Many organisations say a human remains in the loop. That phrase has little value unless the reviewer has enough knowledge, time and authority to challenge the output.
Human review should verify facts, sources, rights, disclosure, tone and consistency with the company’s public position. High-risk content should also receive specialist approval from legal, compliance or senior leadership.
Responsibility must be named. When everyone can generate content, ambiguity about who owns publication becomes a serious weakness.
Build the governance before the incident.
Marketing and communication leaders should now establish:
An inventory of AI tools used internally and by agencies
Approved and prohibited uses
Data and confidentiality rules
Labelling and disclosure procedures
Human-review requirements based on risk
Records of material AI involvement
An escalation process for inaccurate or deceptive output
A response plan for deepfakes targeting the organisation
This should not be designed to prevent useful experimentation. Clear rules make responsible adoption easier because employees need to know where the boundaries are.
Trust will be the real enforcement mechanism.
Regulators can investigate and sanction organisations. Customers, employees and journalists can impose a different penalty: disbelief.
Once an organisation is known for synthetic evidence, hidden manipulation, or unreliable automated answers, every future communication will be met with greater suspicion.
The businesses that handle AI well will not necessarily use it the least. They will be able to explain where they use it, how people remain accountable, and why audiences can trust the final result.
AI governance has therefore become part of brand governance.
The marketing department is no longer waiting for the AI Act to arrive. It is already operating inside it.
———
About the Author
Ana Maria Gardiner is a senior communications executive, board-level adviser and founder of Lighthouse PR.
With extensive experience providing strategic counsel to multinational organisations and leadership teams. Her expertise spans corporate reputation, public relations, marketing communications, crisis management and high-stakes communications.
Throughout her career, Ana Maria has led and implemented communications strategies for organisations including JPMorgan, Coca-Cola, ExxonMobil, Siemens Energy, HEINEKEN, Carrefour, Lexus, Franklin Templeton, BNP Paribas, Sungrow, XTB, Bitget, EssilorLuxottica and Pfizer, which includes projects across the Middle East, North Africa, and Central and Eastern Europe, covering a broad range of industries and business environments.
She works closely with senior executives and board-level decision-makers, advising Lighthouse PR clients on reputation management, strategic positioning, communications risk management, and development of responses to sensitive situations and crises.
Ana Maria holds a bachelor’s degree in political science and a master’s degree in European affairs.
About Lighthouse PR
Lighthouse PR is an independent public relations and strategic communications consultancy headquartered in Bucharest, working with organisations across Romania, Central Europe, and South-Eastern Europe. The agency provides senior-led counsel to companies operating in financial services, energy, manufacturing, technology and cybersecurity, transport and logistics, retail, and FMCG.
Its portfolio of services includes media relations, corporate communications, reputation management, crisis communications, crisis preparedness and response, stakeholder and investor communications, social media and influencer management, B2B communications, risk assessments, business continuity planning, resilience framework development, media buying, corporate events, and SEO and website design services.
Lighthouse PR holds ISO 9001 and ISO 27001 certifications and is the exclusive representative for Romania and the Republic of Moldova of Eurocom Worldwide and Crisis Communication Network Europe, the two international networks that strengthen the agency’s capacity to manage communications projects and crises with regional and international dimensions.
Through its consultancy model, Lighthouse PR places senior expertise at the heart of every client relationship, from strategy development and reputation management to communication programmes and the coordination of responses in sensitive situations.
Lighthouse PR: Clear. Concise. Convincing.