top of page

“Environmentally friendly”, “carbon neutral” and “responsible” have become established terms in marketing. Environmental claims have not been allowed to be misleading before either, but from 27 September 2026 the rules will become more specific and certain practices will be prohibited in all circumstances. The new rules on green claims mean that companies should review their consumer-facing environmental claims, sustainability labels, climate targets and product information.


What rules are changing?


The reform is based on Directive (EU) 2024/825, which amends the EU directives on unfair commercial practices and consumer rights. In Finland, the Directive has been implemented through an amendment to the Consumer Protection Act and a new Government Decree. The reform applies to consumer-facing marketing and practices in customer relationships, regardless of the size of the company. The rules may apply to websites, advertising, commercial content on social media, packaging, product information in online stores and other sustainability communications aimed at consumers.


The Directive should not be confused with the separate Green Claims Directive proposal. Its legislative process is currently stalled, and the proposal has neither been adopted nor formally withdrawn.


When will the new rules apply?


The new provisions will apply from 27 September 2026. A limited transitional rule applies to marketing included on goods, or on their packaging, that were placed on the market before that date. Certain prohibitions concerning sustainability labels, generic environmental claims and the scope of environmental claims will only apply to such marketing from 27 March 2027. This is not a general extension for all green claims. The transitional rule does not apply, for example, to online advertising, new packaging or other practices prohibited under the new rules.


What kinds of environmental claims can be used?


Generic expressions such as “environmentally friendly”, “green”, “ecological” and “climate friendly” will generally be prohibited unless the company can demonstrate recognised excellent environmental performance that is relevant to the claim. Such performance may be based, for example, on the EU Ecolabel or an officially recognised Type I ecolabel compliant with EN ISO 14024.


A generic claim can be made more specific by clearly explaining, in the same communication, which characteristic or part of the product the claim relates to. Even a specific claim must be truthful, up to date and verifiable. A company must not market an entire product or business as environmentally better if the claimed benefit relates only to the packaging or to one particular function.


The assessment of the term “responsible” depends on the overall impression created by the communication, as the term may refer not only to environmental impacts but also to social characteristics. If it creates the impression of a positive environmental impact, the rules on environmental claims may apply.


What about carbon neutrality and offsetting?


A product or service must not be marketed as having a neutral, reduced or positive environmental impact if the claim is based on greenhouse gas emissions offsetting. For example, offsetting-based claims such as “carbon-neutral product”, “carbon-neutral delivery” and “climate compensated” will be prohibited.


A company may still communicate genuine emissions reductions and the financing of climate projects, provided that the information is presented accurately and without misleading consumers. Offsetting must not, however, be presented as an environmental characteristic of the product itself or as a way of cancelling out the emissions caused by the product.


What is required for sustainability labels and climate targets?


A sustainability label may only be used if it is based on a qualifying third-party certification scheme or has been established by a public authority. The scheme’s conditions must be publicly available, transparent and non-discriminatory, and compliance with the requirements must be independently monitored. A company’s own assessment or internal scoring system is not, on its own, sufficient to support a “Green Choice”-type label.


A future-looking environmental claim, such as “we will be carbon neutral by 2030”, requires public and verifiable commitments as well as a detailed and realistic implementation plan.

The plan must include a measurable timeline, an assessment of the resources needed and regular monitoring by an independent expert. The expert’s findings must also be made available to consumers.


What else does the reform cover?


The new prohibitions also concern product durability, software updates and repairability. For example, it is prohibited to market goods if the company has information about a feature that limits their durability, or to claim that goods are repairable when they cannot be repaired. A software update that merely enhances functionality must not be presented as necessary.


Before a contract is concluded, consumers must be provided with new information, including information about the statutory liability for defects. Where the conditions laid down by law are met, information must also be provided about a producer’s free-of-charge durability guarantee lasting more than two years, the minimum period for software updates, the repairability score, and the availability of spare parts and repair instructions.


What can happen if the rules are breached?


Compliance with the rules is supervised by the Finnish Consumer Ombudsman.

Non-compliant practices may be prohibited, and the prohibition may be reinforced with a conditional fine. A penalty payment may also be imposed for breaches of the rules. In certain situations, the Market Court may require a company to correct its marketing.


A consumer may also be entitled to a reasonable price reduction if an unfair commercial practice can be assumed to have influenced the purchasing decision. An intentional or negligent breach may also result in liability for damages.


What should companies do now?


Before 27 September 2026, companies should:


  • review environmental claims used on websites, in campaigns, on social media and on packaging;

  • specify which product, characteristic or stage of the product life cycle each claim relates to;

  • compile up-to-date evidence supporting the claims and document the calculation methods used;

  • review offsetting claims, proprietary sustainability labels and future environmental targets;

  • ensure that product information flows properly from manufacturers to sellers and online stores; and

  • assign clear responsibility for approving and monitoring environmental claims.


The reform does not mean the end of sustainability communications. However, broad promises will increasingly need to be replaced with specific, understandable and verifiable information.

Folks helps companies identify risks related to environmental claims and packaging labels and build practical processes for marketing that complies with the new rules.


Smiling woman with black glasses and a white blouse stands with arms crossed in front of a stone wall. Anna Paimela, Partner, Folks

Anna Paimela

Partner

+358 40 1648626








If you would like to receive our articles directly in your inbox, subscribe to the Folks newsletter here.

The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.

 

From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.

 

Which obligations under the AI Act already apply?

 

The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.

 

Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.

 

Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.

 

When will the obligations concerning high-risk AI systems begin to apply?

 

One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.

 

However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.

 

The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.

 

How should companies prepare for the AI Act in 2026?

 

A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.

 

In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.

 

When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.

 

At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.

 

In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.

 

The time for waiting is coming to an end

 

The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.

 

Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.

We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.


Hymyilevä nainen valkoisessa paidassa seisoo rosoisen kiviseinän edessä. Folksin juristi Katri Aarnio.

Katri Aarnio

Counsel

+358 50 306 2031








To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.

Artificial intelligence has become part of everyday operations in many organisations. Some companies are already implementing a consistent AI strategy, while others are still at the beginning of their journey. The reality, however, is that many organisations already use AI extensively across different functions, either through tools selected by the company or through applications adopted independently by employees.


Many companies find themselves in a situation where they have not yet had time to establish a consistent policy for the use of AI. In some cases, guidance already exists, but it was drafted before the requirements of the EU AI Act became relevant. Now, at the latest, is the right time to ensure that the company’s AI practices and expertise are up to date. This is also critical for ensuring that personnel have the level of AI literacy required under the AI Act.


Why is an AI policy needed?


An AI policy is not merely a formality. It is a practical tool that enables a company to use AI responsibly and safely. At the same time, it helps the organisation respond to new regulatory requirements and creates the conditions for effective innovation.


  1. Ensuring AI literacy: First, an AI policy supports the obligation to ensure an adequate level of AI literacy under the AI Act. Since February 2025, every organisation using AI has been required, to the best of its ability, to ensure that its personnel have a sufficient understanding of the risks, opportunities and potential harm associated with AI. A well-drafted AI policy is a key part of meeting this organisational and training obligation. The European Commission has also indicated that fines and other penalties may be more likely in cases where an organisation has failed to comply with the AI literacy obligation.


  2. Encouraging responsible use: Clear rules encourage employees to use AI. When employees understand what is permitted and what is not, the use of AI can develop from cautious experimentation into systematic business improvement. A clear policy creates a sense of security that encourages employees to explore new ways of making their work more efficient without fearing that the use of AI could inadvertently breach contractual or regulatory obligations or cause other risks to materialise. In this way, an AI policy serves not only as a risk management tool but also as a tool for innovation.


  3. Managing hidden use: An AI policy helps an organisation identify and manage undisclosed use and shadow AI. In many organisations, AI tools have been introduced through applications selected independently by employees. Where the use of AI is not identified, the related risks cannot be managed either. A policy makes the use of AI visible and enables the organisation to provide guidance on tools that employees adopt independently without separate approval. A complete ban on AI may not necessarily reduce risks. On the contrary, it may make it more difficult to provide employees with practical guidance on appropriate ways of working.


  4. Protecting trade secrets and personal data: One of the most important functions of an AI policy is to establish clear boundaries for the use of trade secrets and personal data in connection with AI. When an employee enters customer data, internal plans or personal data into an AI tool, the information may spread beyond the organisation’s control. The policy should establish practical rules on what information may be used, under what conditions and in which environments. In this way, it protects the interests of both the company and its stakeholders.


  5. Implementing the requirements of the AI Act: An AI policy helps an organisation put into practice the operating models and restrictions required under AI regulation. The AI Act imposes obligations particularly in relation to high-risk use cases, including requirements concerning data governance, the retention of logs, and the monitoring and oversight of use. Merely being aware of these obligations is not enough. They must be implemented in a way that makes them visible in day-to-day processes and decision-making. The policy acts as a bridge between legal requirements and practical work.


  6. Building trust among stakeholders: An AI policy also sends a message to external stakeholders. When a company can demonstrate that it uses AI in a considered and responsible manner, it builds trust among customers, business partners and authorities. Trust, in turn, strengthens the company’s reputation and distinguishes it positively from its competitors. An AI policy therefore serves simultaneously as a risk management tool, a training instrument and a strategic statement of responsible business conduct.

AI policy is an investment in a sustainable future

The use of AI introduces new types of risk, but it also creates enormous opportunities. A clear AI policy helps turn AI into a genuine business strength by enabling new forms of innovation while ensuring that the associated risks are managed appropriately.

Whether AI is already an essential part of the company’s daily operations or still at the experimental stage, now is the right time to ensure that internal guidance and training are up to date.


Legal Folksin Counsel Katri Aarnio. Hymyilevä nainen valkoisessa paidassa seisoo betoniseinän edessä. Hän näyttää iloiselta ja rauhalliselta. Taustalla rosoinen pinta.


Katri Aarnio

Counsel

050 306 2031






To receive our articles directly by email, subscribe to the Folks newsletter here.

bottom of page