The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.
From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.
Which obligations under the AI Act already apply?
The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.
Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.
Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.
When will the obligations concerning high-risk AI systems begin to apply?
One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.
However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.
The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.
How should companies prepare for the AI Act in 2026?
A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.
In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.
When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.
At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.
In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.
The time for waiting is coming to an end
The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.
Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.
We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.
Updated: Aug 5
Artificial intelligence has entered the world of marketing quickly and with relatively little friction. Images, videos, audio, advertising copy and campaign ideas can now be created in an instant. From a legal perspective, however, this does not mean that the basic rules of marketing have lost their relevance. Rather, AI places familiar questions in a new context. Is the marketing truthful? Does the recipient understand what they are being shown? Who is responsible for the end result?
Which new rules and guidance should marketers pay attention to?
The current discussion is being shaped by three key sets of materials. First, the International Chamber of Commerce, or ICC, has published guidance on the responsible use of AI in marketing. The guidance supplements the ICC’s marketing rules and emphasises that marketing must be lawful, decent, honest and truthful, regardless of the technology used to create it. The ICC guidance is a form of self-regulation rather than directly binding legislation. In practice, however, it may still be relevant when assessing the level of care that can reasonably be expected from a responsible marketer.
Second, Article 50 of the EU AI Act introduces binding transparency obligations relevant to marketing. Many of these obligations will apply from 2 August 2026. They concern, among other things, situations in which a person interacts with an AI system or is exposed to certain content generated or manipulated by AI. Third, the European Commission has published draft guidelines on Article 50, while a Code of Practice on the labelling of AI-generated content is also being prepared. According to the Commission’s draft, the guidelines are intended to provide practical assistance with interpretation. They do not constitute a binding or final interpretation of the AI Act.
There is no automatic obligation to disclose the use of AI
AI can be used in many different ways and at various stages of the marketing process. It is therefore important to recognise that its use does not need to be disclosed automatically in every situation. The ICC guidance states this quite clearly, and the AI Act does not create a general disclosure obligation either. The mere use of generative AI to create advertising materials or marketing communications does not in itself require disclosure. The key question is whether failing to disclose the use of AI could give the recipient a misleading overall impression. Where that is the case, disclosure may be necessary.
Deepfake content is a particular risk area in marketing
Article 50 of the AI Act makes disclosure of AI use a statutory obligation in certain situations. From a marketing perspective, the most relevant example is deepfake content. Under the AI Act, the deployer of an AI system must disclose when image, audio or video content has been generated or manipulated by AI in a way that constitutes a deepfake. According to the AI Act and the Commission’s draft guidelines, a deepfake is content that resembles existing persons, objects, places, entities or events and could falsely appear to be authentic or truthful.
This definition is significant for marketing because deepfakes are not limited to situations involving the imitation of a well-known person. AI-generated content that realistically depicts an existing location, event or product-use context may also fall within the scope of the deepfake rules where the recipient could mistakenly believe it to be genuine. In a marketing context, this could include an AI-generated video showing realistic “customers” using a product in a seemingly authentic setting.
The ICC guidance takes the assessment one step further from a practical perspective. Where AI is used to create or materially alter the image, voice or other likeness of a real and identifiable person for marketing purposes, the person’s permission should generally be obtained and the limits of that permission respected. In practice, marketers must therefore assess two separate questions. They must determine whether they are entitled to use content depicting the person and whether the use of AI must be disclosed to the audience. Article 50 of the AI Act does not directly address consent, as its focus is on transparency. The Commission’s draft guidelines nevertheless point out that deepfake content may also raise issues relating to data protection, intellectual property rights and personality rights.
Disclosure must be assessed from the recipient’s perspective
Another important consideration is the target audience. Both the ICC guidance and the Commission’s draft guidelines on Article 50 emphasise that the clarity of a disclosure must be assessed from the audience’s perspective. In marketing directed at children, older people or other potentially vulnerable groups, the threshold for disclosing the use of AI may in practice be lower. The disclosure must be presented in a way that the particular audience can understand. A purely technical label, a sentence hidden in the terms of use or a vague reference to AI may not be sufficient. According to the Commission’s draft guidelines, the information must be provided clearly and prominently no later than at the time of the first interaction or exposure. It must not be hidden in user instructions or behind a menu structure.
The draft Code of Practice develops this idea further. It suggests that labels for deepfakes and certain AI-generated texts should be easily noticeable, accessible and appropriate for the relevant type of content. The draft also proposes the development of a common EU-wide AI icon and the possibility of a second layer of information explaining in greater detail which elements of the content have been generated or manipulated by AI. From a practical perspective, another interesting proposal is that the label should, where possible, travel with the content when a video or image is shared across different channels.
Responsibility for AI use must be built into marketing processes
For businesses, this means that the use of AI in marketing is not merely a choice of tool for the creative team. The ICC guidance emphasises that the marketer remains responsible for its marketing even where the campaign has been implemented with the assistance of an agency, influencer, platform operator or AI tool. Organisations should update their internal training and instructions so that everyone involved in marketing understands their responsibilities. The same objective is reflected in the AI literacy obligations under the AI Act. Businesses must ensure that personnel using AI have an adequate understanding of its opportunities, limitations and risks.
In practice, a responsible marketer should address three fundamental issues. First, the business should identify where AI is used in the campaign and whether the end result must be labelled under the AI Act. It should then assess whether failing to disclose the use of AI could create a misleading impression, including in situations where the express disclosure obligations under the AI Act do not apply.
Finally, contracts with advertising agencies, influencers and technology providers should support compliance. The marketer should know when AI has been used to create the final output so that it can fulfil its own obligations where necessary.
The use of AI in marketing is not inherently problematic. On the contrary, it can improve quality, accelerate production and create new possibilities for creative work. However, the more authentic AI-generated content looks and sounds, the more important it becomes to consider whether the recipient understands what they are being shown. In this respect, the ICC guidance and Article 50 of the AI Act point in the same direction. Both serve as reminders that trust lies at the very heart of marketing. Where the use of AI undermines that trust, technical efficiency can quickly turn into legal risk and reputational harm.
Businesses should begin preparing early
Final interpretation and enforcement practice are still developing. The Commission’s guidelines on Article 50 and the Code of Practice remain in draft form. The ICC has also stated that it will update its guidance as technology and industry practices evolve. Businesses should nevertheless begin preparing for the obligations now by updating their processes, internal guidance, contracts and approval procedures. From August 2026 onwards, transparency will in many situations become an increasingly concrete and directly applicable legal obligation.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly by email, subscribe to the Folks newsletter here.
- Katri Aarnio
- Oct 17, 2025
Updated: Aug 5
Artificial intelligence has become part of everyday operations in many organisations. Some companies are already implementing a consistent AI strategy, while others are still at the beginning of their journey. The reality, however, is that many organisations already use AI extensively across different functions, either through tools selected by the company or through applications adopted independently by employees.
Many companies find themselves in a situation where they have not yet had time to establish a consistent policy for the use of AI. In some cases, guidance already exists, but it was drafted before the requirements of the EU AI Act became relevant. Now, at the latest, is the right time to ensure that the company’s AI practices and expertise are up to date. This is also critical for ensuring that personnel have the level of AI literacy required under the AI Act.
Why is an AI policy needed?
An AI policy is not merely a formality. It is a practical tool that enables a company to use AI responsibly and safely. At the same time, it helps the organisation respond to new regulatory requirements and creates the conditions for effective innovation.
Ensuring AI literacy: First, an AI policy supports the obligation to ensure an adequate level of AI literacy under the AI Act. Since February 2025, every organisation using AI has been required, to the best of its ability, to ensure that its personnel have a sufficient understanding of the risks, opportunities and potential harm associated with AI. A well-drafted AI policy is a key part of meeting this organisational and training obligation. The European Commission has also indicated that fines and other penalties may be more likely in cases where an organisation has failed to comply with the AI literacy obligation.
Encouraging responsible use: Clear rules encourage employees to use AI. When employees understand what is permitted and what is not, the use of AI can develop from cautious experimentation into systematic business improvement. A clear policy creates a sense of security that encourages employees to explore new ways of making their work more efficient without fearing that the use of AI could inadvertently breach contractual or regulatory obligations or cause other risks to materialise. In this way, an AI policy serves not only as a risk management tool but also as a tool for innovation.
Managing hidden use: An AI policy helps an organisation identify and manage undisclosed use and shadow AI. In many organisations, AI tools have been introduced through applications selected independently by employees. Where the use of AI is not identified, the related risks cannot be managed either. A policy makes the use of AI visible and enables the organisation to provide guidance on tools that employees adopt independently without separate approval. A complete ban on AI may not necessarily reduce risks. On the contrary, it may make it more difficult to provide employees with practical guidance on appropriate ways of working.
Protecting trade secrets and personal data: One of the most important functions of an AI policy is to establish clear boundaries for the use of trade secrets and personal data in connection with AI. When an employee enters customer data, internal plans or personal data into an AI tool, the information may spread beyond the organisation’s control. The policy should establish practical rules on what information may be used, under what conditions and in which environments. In this way, it protects the interests of both the company and its stakeholders.
Implementing the requirements of the AI Act: An AI policy helps an organisation put into practice the operating models and restrictions required under AI regulation. The AI Act imposes obligations particularly in relation to high-risk use cases, including requirements concerning data governance, the retention of logs, and the monitoring and oversight of use. Merely being aware of these obligations is not enough. They must be implemented in a way that makes them visible in day-to-day processes and decision-making. The policy acts as a bridge between legal requirements and practical work.
Building trust among stakeholders: An AI policy also sends a message to external stakeholders. When a company can demonstrate that it uses AI in a considered and responsible manner, it builds trust among customers, business partners and authorities. Trust, in turn, strengthens the company’s reputation and distinguishes it positively from its competitors. An AI policy therefore serves simultaneously as a risk management tool, a training instrument and a strategic statement of responsible business conduct.
AI policy is an investment in a sustainable future
The use of AI introduces new types of risk, but it also creates enormous opportunities. A clear AI policy helps turn AI into a genuine business strength by enabling new forms of innovation while ensuring that the associated risks are managed appropriately.
Whether AI is already an essential part of the company’s daily operations or still at the experimental stage, now is the right time to ensure that internal guidance and training are up to date.

Katri Aarnio
Counsel
050 306 2031
To receive our articles directly by email, subscribe to the Folks newsletter here.
