top of page

Artificial intelligence has entered the world of marketing quickly and with relatively little friction. Images, videos, audio, advertising copy and campaign ideas can now be created in an instant. From a legal perspective, however, this does not mean that the basic rules of marketing have lost their relevance. Rather, AI places familiar questions in a new context. Is the marketing truthful? Does the recipient understand what they are being shown? Who is responsible for the end result?


Which new rules and guidance should marketers pay attention to?


The current discussion is being shaped by three key sets of materials. First, the International Chamber of Commerce, or ICC, has published guidance on the responsible use of AI in marketing. The guidance supplements the ICC’s marketing rules and emphasises that marketing must be lawful, decent, honest and truthful, regardless of the technology used to create it. The ICC guidance is a form of self-regulation rather than directly binding legislation. In practice, however, it may still be relevant when assessing the level of care that can reasonably be expected from a responsible marketer.


Second, Article 50 of the EU AI Act introduces binding transparency obligations relevant to marketing. Many of these obligations will apply from 2 August 2026. They concern, among other things, situations in which a person interacts with an AI system or is exposed to certain content generated or manipulated by AI. Third, the European Commission has published draft guidelines on Article 50, while a Code of Practice on the labelling of AI-generated content is also being prepared. According to the Commission’s draft, the guidelines are intended to provide practical assistance with interpretation. They do not constitute a binding or final interpretation of the AI Act.


There is no automatic obligation to disclose the use of AI


AI can be used in many different ways and at various stages of the marketing process. It is therefore important to recognise that its use does not need to be disclosed automatically in every situation. The ICC guidance states this quite clearly, and the AI Act does not create a general disclosure obligation either. The mere use of generative AI to create advertising materials or marketing communications does not in itself require disclosure. The key question is whether failing to disclose the use of AI could give the recipient a misleading overall impression. Where that is the case, disclosure may be necessary.


Deepfake content is a particular risk area in marketing


Article 50 of the AI Act makes disclosure of AI use a statutory obligation in certain situations. From a marketing perspective, the most relevant example is deepfake content. Under the AI Act, the deployer of an AI system must disclose when image, audio or video content has been generated or manipulated by AI in a way that constitutes a deepfake. According to the AI Act and the Commission’s draft guidelines, a deepfake is content that resembles existing persons, objects, places, entities or events and could falsely appear to be authentic or truthful.


This definition is significant for marketing because deepfakes are not limited to situations involving the imitation of a well-known person. AI-generated content that realistically depicts an existing location, event or product-use context may also fall within the scope of the deepfake rules where the recipient could mistakenly believe it to be genuine. In a marketing context, this could include an AI-generated video showing realistic “customers” using a product in a seemingly authentic setting.


The ICC guidance takes the assessment one step further from a practical perspective. Where AI is used to create or materially alter the image, voice or other likeness of a real and identifiable person for marketing purposes, the person’s permission should generally be obtained and the limits of that permission respected. In practice, marketers must therefore assess two separate questions. They must determine whether they are entitled to use content depicting the person and whether the use of AI must be disclosed to the audience. Article 50 of the AI Act does not directly address consent, as its focus is on transparency. The Commission’s draft guidelines nevertheless point out that deepfake content may also raise issues relating to data protection, intellectual property rights and personality rights.


Disclosure must be assessed from the recipient’s perspective


Another important consideration is the target audience. Both the ICC guidance and the Commission’s draft guidelines on Article 50 emphasise that the clarity of a disclosure must be assessed from the audience’s perspective. In marketing directed at children, older people or other potentially vulnerable groups, the threshold for disclosing the use of AI may in practice be lower. The disclosure must be presented in a way that the particular audience can understand. A purely technical label, a sentence hidden in the terms of use or a vague reference to AI may not be sufficient. According to the Commission’s draft guidelines, the information must be provided clearly and prominently no later than at the time of the first interaction or exposure. It must not be hidden in user instructions or behind a menu structure.


The draft Code of Practice develops this idea further. It suggests that labels for deepfakes and certain AI-generated texts should be easily noticeable, accessible and appropriate for the relevant type of content. The draft also proposes the development of a common EU-wide AI icon and the possibility of a second layer of information explaining in greater detail which elements of the content have been generated or manipulated by AI. From a practical perspective, another interesting proposal is that the label should, where possible, travel with the content when a video or image is shared across different channels.


Responsibility for AI use must be built into marketing processes


For businesses, this means that the use of AI in marketing is not merely a choice of tool for the creative team. The ICC guidance emphasises that the marketer remains responsible for its marketing even where the campaign has been implemented with the assistance of an agency, influencer, platform operator or AI tool. Organisations should update their internal training and instructions so that everyone involved in marketing understands their responsibilities. The same objective is reflected in the AI literacy obligations under the AI Act. Businesses must ensure that personnel using AI have an adequate understanding of its opportunities, limitations and risks.


In practice, a responsible marketer should address three fundamental issues. First, the business should identify where AI is used in the campaign and whether the end result must be labelled under the AI Act. It should then assess whether failing to disclose the use of AI could create a misleading impression, including in situations where the express disclosure obligations under the AI Act do not apply.

Finally, contracts with advertising agencies, influencers and technology providers should support compliance. The marketer should know when AI has been used to create the final output so that it can fulfil its own obligations where necessary.


The use of AI in marketing is not inherently problematic. On the contrary, it can improve quality, accelerate production and create new possibilities for creative work. However, the more authentic AI-generated content looks and sounds, the more important it becomes to consider whether the recipient understands what they are being shown. In this respect, the ICC guidance and Article 50 of the AI Act point in the same direction. Both serve as reminders that trust lies at the very heart of marketing. Where the use of AI undermines that trust, technical efficiency can quickly turn into legal risk and reputational harm.


Businesses should begin preparing early


Final interpretation and enforcement practice are still developing. The Commission’s guidelines on Article 50 and the Code of Practice remain in draft form. The ICC has also stated that it will update its guidance as technology and industry practices evolve. Businesses should nevertheless begin preparing for the obligations now by updating their processes, internal guidance, contracts and approval procedures. From August 2026 onwards, transparency will in many situations become an increasingly concrete and directly applicable legal obligation.


Hymyilevä nainen seisoo tiiliseinän edessä valkoisessa kauluspaidassa. Kuvassa on Folksin juristi Katri Aarnio.


Katri Aarnio

Counsel

+358 50 306 2031




To receive our articles directly by email, subscribe to the Folks newsletter here.

Artificial intelligence has become part of everyday operations in many organisations. Some companies are already implementing a consistent AI strategy, while others are still at the beginning of their journey. The reality, however, is that many organisations already use AI extensively across different functions, either through tools selected by the company or through applications adopted independently by employees.


Many companies find themselves in a situation where they have not yet had time to establish a consistent policy for the use of AI. In some cases, guidance already exists, but it was drafted before the requirements of the EU AI Act became relevant. Now, at the latest, is the right time to ensure that the company’s AI practices and expertise are up to date. This is also critical for ensuring that personnel have the level of AI literacy required under the AI Act.


Why is an AI policy needed?


An AI policy is not merely a formality. It is a practical tool that enables a company to use AI responsibly and safely. At the same time, it helps the organisation respond to new regulatory requirements and creates the conditions for effective innovation.


  1. Ensuring AI literacy: First, an AI policy supports the obligation to ensure an adequate level of AI literacy under the AI Act. Since February 2025, every organisation using AI has been required, to the best of its ability, to ensure that its personnel have a sufficient understanding of the risks, opportunities and potential harm associated with AI. A well-drafted AI policy is a key part of meeting this organisational and training obligation. The European Commission has also indicated that fines and other penalties may be more likely in cases where an organisation has failed to comply with the AI literacy obligation.


  2. Encouraging responsible use: Clear rules encourage employees to use AI. When employees understand what is permitted and what is not, the use of AI can develop from cautious experimentation into systematic business improvement. A clear policy creates a sense of security that encourages employees to explore new ways of making their work more efficient without fearing that the use of AI could inadvertently breach contractual or regulatory obligations or cause other risks to materialise. In this way, an AI policy serves not only as a risk management tool but also as a tool for innovation.


  3. Managing hidden use: An AI policy helps an organisation identify and manage undisclosed use and shadow AI. In many organisations, AI tools have been introduced through applications selected independently by employees. Where the use of AI is not identified, the related risks cannot be managed either. A policy makes the use of AI visible and enables the organisation to provide guidance on tools that employees adopt independently without separate approval. A complete ban on AI may not necessarily reduce risks. On the contrary, it may make it more difficult to provide employees with practical guidance on appropriate ways of working.


  4. Protecting trade secrets and personal data: One of the most important functions of an AI policy is to establish clear boundaries for the use of trade secrets and personal data in connection with AI. When an employee enters customer data, internal plans or personal data into an AI tool, the information may spread beyond the organisation’s control. The policy should establish practical rules on what information may be used, under what conditions and in which environments. In this way, it protects the interests of both the company and its stakeholders.


  5. Implementing the requirements of the AI Act: An AI policy helps an organisation put into practice the operating models and restrictions required under AI regulation. The AI Act imposes obligations particularly in relation to high-risk use cases, including requirements concerning data governance, the retention of logs, and the monitoring and oversight of use. Merely being aware of these obligations is not enough. They must be implemented in a way that makes them visible in day-to-day processes and decision-making. The policy acts as a bridge between legal requirements and practical work.


  6. Building trust among stakeholders: An AI policy also sends a message to external stakeholders. When a company can demonstrate that it uses AI in a considered and responsible manner, it builds trust among customers, business partners and authorities. Trust, in turn, strengthens the company’s reputation and distinguishes it positively from its competitors. An AI policy therefore serves simultaneously as a risk management tool, a training instrument and a strategic statement of responsible business conduct.

An AI policy is an investment in a sustainable future

The use of AI introduces new types of risk, but it also creates enormous opportunities. A clear AI policy helps turn AI into a genuine business strength by enabling new forms of innovation while ensuring that the associated risks are managed appropriately.

Whether AI is already an essential part of the company’s daily operations or still at the experimental stage, now is the right time to ensure that internal guidance and training are up to date.


Legal Folksin Counsel Katri Aarnio. Hymyilevä nainen valkoisessa paidassa seisoo betoniseinän edessä. Hän näyttää iloiselta ja rauhalliselta. Taustalla rosoinen pinta.


Katri Aarnio

Counsel

050 306 2031






To receive our articles directly by email, subscribe to the Folks newsletter here.

EU digital regulation has undergone a major transformation in recent years. New legislation has been introduced at a rapid pace in areas ranging from online services and artificial intelligence to data use and cybersecurity. Nor does the pace appear to be slowing, as further obligations will become applicable in the near future.


Below, we have compiled an overview of recent developments in digital regulation and the new obligations on the horizon.


Major online platforms under scrutiny


The EU Digital Services Act, or DSA, entered into application in stages during 2023 and 2024. It imposes extensive obligations on various digital service platforms, including requirements to address illegal content and improve transparency towards users. The European Commission and national supervisory authorities have already initiated their first enforcement actions. X, for example, is being investigated for potential infringements relating to practices that manipulate users and a lack of transparency in advertising.

Very large online platforms acting as so-called gatekeepers have also had to update their practices since May 2023 as a result of the EU Digital Markets Act, or DMA. The DMA aims to improve competition and transparency within the ecosystems of major technology platforms. In April 2025, the European Commission imposed the first fines under the DMA. Apple was fined EUR 500 million for restrictions imposed in its App Store that prevented application developers from making sufficient use of alternative distribution channels. Meta was fined EUR 200 million for its “consent or pay” model, which required Facebook and Instagram users to pay in return for more limited processing of their personal data.


Towards risk-based AI regulation With enthusiasm around artificial intelligence at its peak, the first obligations under the EU AI Act became applicable in February 2025. The development, provision and use of AI systems involving prohibited practices must now be discontinued. Organisations have also had to consider what types of training and other measures are needed to meet their obligation to ensure an adequate level of AI literacy.

To clarify some of the questions left open by the AI Act, the Commission published non-binding guidance in early 2025 on matters including the definition of an AI system, prohibited AI practices and the AI literacy obligation. Further changes are approaching rapidly, as the remaining obligations under the AI Act will become applicable in stages between 2025 and 2027. The requirements concerning high-risk AI systems will have a particularly significant effect on both providers and deployers.


Fairer rules for the data market As data plays an increasingly important role in society, the EU has sought to facilitate its free movement between different operators within the internal market. A key legislative initiative supporting this strategy is the Data Act, most of whose obligations will apply from 12 September 2025. The regulation focuses particularly on connected products and Internet of Things devices. In future, users of these devices must be given access to the data generated by them. The Data Act also prohibits the use of unfair contractual terms relating to data where such terms have been unilaterally imposed on another business.

The Data Act will also affect cloud services, and vendor lock-in situations are expected largely to become a thing of the past. Among other things, switching charges that restrict customers from changing cloud service providers will gradually be abolished. Cloud service providers will be required to assist customers with switching services, and customers will be entitled to terminate a cloud service with two months’ notice. The near future will show how the detailed contractual practices develop and what effects the obligations under the Data Act will have, for example, on the pricing of cloud services.


Preparing for cybersecurity threats through regulation


The obligations under the long-awaited NIS2 Directive entered into force in Finland on 8 April 2025, when the Directive was finally implemented nationally through the Cybersecurity Act. As cybersecurity threats increase, organisations operating in critical sectors now have statutory obligations to manage cybersecurity risks and notify the authorities of significant security incidents. The new cybersecurity regulatory framework does not end with the Cybersecurity Act. Further requirements will follow in the coming years under the Cyber Resilience Act, or CRA. The CRA will apply to hardware and software products with digital elements that can be connected, either directly or indirectly, to another device or network. Operators falling within its scope still have time to prepare. The obligations concerning the reporting of vulnerabilities will apply from 11 September 2026, while the requirements concerning the cybersecurity features of products will apply from 11 December 2027.


Cybersecurity threats have also been addressed through sector-specific regulation. In particular, the Digital Operational Resilience Act, or DORA, which became applicable on 17 January 2025, has had a significant impact both on financial-sector entities and on IT service providers supplying services to the financial sector. The beginning of the year saw an extensive round of contract updates as the requirements of DORA were negotiated into agreements between financial entities and IT service providers. The Commission has also drafted and published several regulatory technical standards specifying the requirements of DORA in greater detail. Supervisory authorities are currently carrying out criticality assessments aimed at identifying the critical IT service providers that will become subject to direct regulatory oversight. The designations are expected to take effect in autumn 2025.


What does the future hold?


Within just a few years, the EU’s digital regulatory framework has developed into an extensive body of legislation with a genuine impact on companies’ day-to-day operations. The breadth of the reforms and the speed at which they have been implemented have prompted many organisations to review their processes, contracts and technical solutions. There is no pause in sight. The Commission and national authorities have also demonstrated their willingness to intervene where shortcomings are identified. Enforcement can therefore be expected gradually to extend beyond the largest operators.


For organisations, this means above all that they must remain alert. New regulation is not merely an administrative obligation. It is often also a strategic question. How can services be designed to be user-oriented and competitive while also complying with regulatory requirements? Although the amount of regulation may feel burdensome, it also offers opportunities for differentiation. Operators that address the new requirements and opportunities at an early stage may be able to turn their regulatory obligations into a competitive advantage.


As regulation becomes more stringent, clear direction and practical interpretation are more important than ever. We support our clients with both.

Legal Folksin Counsel Katri Aarnio. Hymyilevä nainen valkoisessa paidassa seisoo betoniseinän edessä. Hän näyttää iloiselta ja rauhalliselta. Taustalla rosoinen pinta.


Katri Aarnio

Counsel

050 306 2031







To receive our articles directly by email, subscribe to the Folks newsletter here.

bottom of page