The EU AI Act for Marketers, Without the Jargon
The EU AI Act is long, and almost none of it is aimed at you. If your team uses an AI feature inside a tool someone else built, you are a deployer of a limited-risk system, and your practical obligation fits in a paragraph. The heavy duties belong to whoever publishes and hosts the model.
Key Takeaways
- Most marketing teams are deployers of limited-risk AI, not providers — the role you occupy decides which obligations apply to you at all.
- The operative duty is Article 50 transparency, applicable from 2 August 2026. The Commission adopted its Article 50 guidelines on 20 July 2026.
- Systems already on the market before 2 August 2026 have until 2 December 2026 for the content-marking duty.
- General-purpose AI obligations sit upstream with the model publisher and inference host — and open-weight models make your own file easier to defend, because the exact version can be pinned and reproduced.
The EU AI Act has produced a great deal of anxiety in marketing teams and very little clarity. Part of that is the length of the text. Most of it is that the coverage rarely separates the two questions that actually matter to you: which role you occupy, and which risk category the system you are using falls into.
Answer those two and the list of things you have to do gets short quickly.
Provider or deployer: the only question that changes your life
The Act assigns duties by role. Two of them matter here.
A provider develops an AI system and places it on the market under its own name. A deployer uses an AI system supplied by someone else in the course of its professional activity. If you type questions into an AI assistant built into your analytics platform, you are a deployer. The platform vendor is closer to the provider side, and the company that published the underlying model is further upstream still.
One caveat worth knowing: the roles are not permanently fixed. If you substantially modify a system, or put your own brand on somebody else's and sell it, you can find yourself holding provider duties you did not plan for. Wiring an off-the-shelf assistant into your reporting workflow does not do that. Rebuilding it and reselling it might.
Limited risk, in plain terms
The Act sorts systems by the harm they could cause. An AI that reads your own analytics database and writes a paragraph about why organic traffic dipped is not making decisions about anyone's employment, credit or liberty. It is a limited-risk system, and the regime for limited-risk systems is essentially about transparency rather than conformity assessments, technical files and audits.
This is the part that gets lost. A lot of AI Act commentary describes high-risk obligations — risk management systems, data governance documentation, human oversight design, post-market monitoring — and readers assume those land on them. For a marketing team using an analytics assistant, they generally do not.
The obligation that does land on you: Article 50
Article 50 is the transparency article, and its core idea is simple: people should know when they are dealing with an AI. It applies from 2 August 2026. The European Commission adopted its guidelines on Article 50 on 20 July 2026, which is the document to read if you want the Commission's own reading of scope and edge cases.
There is also a transitional detail worth noting. Systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with the content-marking duty. If you have an AI feature that has been running for a year, that grace period may apply to it — which is a reason to know when each feature in your stack actually launched.
In practice, for a marketing team, the work is unglamorous: make sure that the AI surfaces your customers, prospects or staff touch are visibly labelled as AI, that AI-generated content produced for publication is handled in line with the marking rules, and that somebody has written down which systems are in scope.
What sits upstream, and why that is good news
The obligations on general-purpose AI models — Article 53 onward — have applied since 2 August 2025, with the Commission's enforcement powers arriving on 2 August 2026. These cover things like technical documentation, information for downstream providers, copyright policy and training-data summaries.
They belong to the model publisher and the inference host. Not to a deployer. That is deliberate design in the Act: the party with visibility into how a model was built carries the duties that require visibility into how a model was built.
What this means for you as a buyer is that a chunk of your diligence is really a question you can pass along. Ask your vendor which model they use, who publishes it, who hosts the inference, and how those parties address their upstream obligations. A vendor who cannot name the model is a vendor who cannot answer.
Why open weights make your file easier to defend
Models released under free and open-source licences get partial exemptions from some of those general-purpose obligations. That is the legal angle, and it is real. But there is a more practical reason a deployer should care about open weights, and it has nothing to do with exemptions.
Auditability. With published weights you can pin an exact version, inspect it, red-team it and reproduce a result months later. Every claim you make in an internal assessment stays checkable. With a closed API, the model behind the endpoint can change under you silently — and then the assessment you wrote in March describes something that no longer exists, with no way to demonstrate what did or did not change.
That is one of the reasons Seal AI runs on an open-weight model: gpt-oss-120b, under the Apache 2.0 licence, hosted on Scaleway Generative APIs in Paris, France. Scaleway is a French company whose parent is the Iliad group, with no US ownership. As the platform, SealMetrics is a deployer of a limited-risk AI system, and we say so plainly rather than implying the assistant is anything other than a model reading your reports. The full architecture write-up is in the Seal AI documentation.
Reproducibility also has an internal payoff. It is what let us run a controlled comparison of candidate models against our own assistant and publish the benchmark, including the run we threw away as invalid. You cannot do that with a model you are not allowed to hold still.
What to do before 2 August 2026
A short, concrete list. None of it needs outside help for a typical marketing organisation.
- Inventory the AI you already use. Include the features that appeared inside tools you have had for years. Note roughly when each one launched, because of the 2 December 2026 transitional date.
- Assign a role per system. Deployer for almost everything. Flag anything you have substantially modified or white-labelled, since that is where the role can shift.
- Check the labelling. Anywhere a person interacts with an AI — assistants, chat widgets, automated replies — it should be obvious that it is an AI. Read the Commission's 20 July 2026 guidelines for the detail.
- Handle AI-generated content deliberately. Decide where marking applies to what you publish, and write the decision down rather than leaving it to individual judgement.
- Ask vendors for their upstream position in writing. Which model, published by whom, hosted where, and how the general-purpose obligations are met. File the replies.
- Give it an owner. One named person with the inventory and the vendor answers. Most of the failures here are organisational, not legal.
The bottom line
The AI Act is a large piece of law with a small footprint on a typical marketing team. Know your role, know your risk category, label the AI, keep an inventory, and push the model-level questions upstream to the people who can actually answer them.
The teams that will struggle are not the ones with complicated AI. They are the ones that cannot list what they are running, or name the model behind it. That is a solvable problem, and now is a considerably better time to solve it than after 2 August.
This article is general information about how the EU AI Act is structured, not legal advice. Obligations depend on your specific systems, role and jurisdiction — take advice from a qualified professional before relying on any of it.
