“Environmentally friendly”, “carbon neutral” and “responsible” have become established terms in marketing. Environmental claims have not been allowed to be misleading before either, but from 27 September 2026 the rules will become more specific and certain practices will be prohibited in all circumstances. The new rules on green claims mean that companies should review their consumer-facing environmental claims, sustainability labels, climate targets and product information.
What rules are changing?
The reform is based on Directive (EU) 2024/825, which amends the EU directives on unfair commercial practices and consumer rights. In Finland, the Directive has been implemented through an amendment to the Consumer Protection Act and a new Government Decree. The reform applies to consumer-facing marketing and practices in customer relationships, regardless of the size of the company. The rules may apply to websites, advertising, commercial content on social media, packaging, product information in online stores and other sustainability communications aimed at consumers.
The Directive should not be confused with the separate Green Claims Directive proposal. Its legislative process is currently stalled, and the proposal has neither been adopted nor formally withdrawn.
When will the new rules apply?
The new provisions will apply from 27 September 2026. A limited transitional rule applies to marketing included on goods, or on their packaging, that were placed on the market before that date. Certain prohibitions concerning sustainability labels, generic environmental claims and the scope of environmental claims will only apply to such marketing from 27 March 2027. This is not a general extension for all green claims. The transitional rule does not apply, for example, to online advertising, new packaging or other practices prohibited under the new rules.
What kinds of environmental claims can be used?
Generic expressions such as “environmentally friendly”, “green”, “ecological” and “climate friendly” will generally be prohibited unless the company can demonstrate recognised excellent environmental performance that is relevant to the claim. Such performance may be based, for example, on the EU Ecolabel or an officially recognised Type I ecolabel compliant with EN ISO 14024.
A generic claim can be made more specific by clearly explaining, in the same communication, which characteristic or part of the product the claim relates to. Even a specific claim must be truthful, up to date and verifiable. A company must not market an entire product or business as environmentally better if the claimed benefit relates only to the packaging or to one particular function.
The assessment of the term “responsible” depends on the overall impression created by the communication, as the term may refer not only to environmental impacts but also to social characteristics. If it creates the impression of a positive environmental impact, the rules on environmental claims may apply.
What about carbon neutrality and offsetting?
A product or service must not be marketed as having a neutral, reduced or positive environmental impact if the claim is based on greenhouse gas emissions offsetting. For example, offsetting-based claims such as “carbon-neutral product”, “carbon-neutral delivery” and “climate compensated” will be prohibited.
A company may still communicate genuine emissions reductions and the financing of climate projects, provided that the information is presented accurately and without misleading consumers. Offsetting must not, however, be presented as an environmental characteristic of the product itself or as a way of cancelling out the emissions caused by the product.
What is required for sustainability labels and climate targets?
A sustainability label may only be used if it is based on a qualifying third-party certification scheme or has been established by a public authority. The scheme’s conditions must be publicly available, transparent and non-discriminatory, and compliance with the requirements must be independently monitored. A company’s own assessment or internal scoring system is not, on its own, sufficient to support a “Green Choice”-type label.
A future-looking environmental claim, such as “we will be carbon neutral by 2030”, requires public and verifiable commitments as well as a detailed and realistic implementation plan.
The plan must include a measurable timeline, an assessment of the resources needed and regular monitoring by an independent expert. The expert’s findings must also be made available to consumers.
What else does the reform cover?
The new prohibitions also concern product durability, software updates and repairability. For example, it is prohibited to market goods if the company has information about a feature that limits their durability, or to claim that goods are repairable when they cannot be repaired. A software update that merely enhances functionality must not be presented as necessary.
Before a contract is concluded, consumers must be provided with new information, including information about the statutory liability for defects. Where the conditions laid down by law are met, information must also be provided about a producer’s free-of-charge durability guarantee lasting more than two years, the minimum period for software updates, the repairability score, and the availability of spare parts and repair instructions.
What can happen if the rules are breached?
Compliance with the rules is supervised by the Finnish Consumer Ombudsman.
Non-compliant practices may be prohibited, and the prohibition may be reinforced with a conditional fine. A penalty payment may also be imposed for breaches of the rules. In certain situations, the Market Court may require a company to correct its marketing.
A consumer may also be entitled to a reasonable price reduction if an unfair commercial practice can be assumed to have influenced the purchasing decision. An intentional or negligent breach may also result in liability for damages.
What should companies do now?
Before 27 September 2026, companies should:
review environmental claims used on websites, in campaigns, on social media and on packaging;
specify which product, characteristic or stage of the product life cycle each claim relates to;
compile up-to-date evidence supporting the claims and document the calculation methods used;
review offsetting claims, proprietary sustainability labels and future environmental targets;
ensure that product information flows properly from manufacturers to sellers and online stores; and
assign clear responsibility for approving and monitoring environmental claims.
The reform does not mean the end of sustainability communications. However, broad promises will increasingly need to be replaced with specific, understandable and verifiable information.
Folks helps companies identify risks related to environmental claims and packaging labels and build practical processes for marketing that complies with the new rules.

Anna Paimela
Partner
+358 40 1648626
If you would like to receive our articles directly in your inbox, subscribe to the Folks newsletter here.
The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.
From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.
Which obligations under the AI Act already apply?
The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.
Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.
Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.
When will the obligations concerning high-risk AI systems begin to apply?
One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.
However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.
The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.
How should companies prepare for the AI Act in 2026?
A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.
In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.
When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.
At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.
In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.
The time for waiting is coming to an end
The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.
Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.
We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.
AI tools are developing at a remarkable pace. Not long ago, an AI-generated image was easy to recognise, but today, the best AI-generated images are so convincing that they can be indistinguishable from genuine photographs. AI can also be used to produce text, audio and video, offering creative industry professionals significant opportunities to accelerate content production and develop new forms of expression.
At the same time, the use of AI raises numerous legal questions. In this blog post, I discuss the legal considerations that companies operating in the creative industries should take into account before introducing AI tools and using them as part of their creative work.
Who owns AI-assisted content, and how can it be protected?
A key question is whether the creator obtains an exclusive right to use and license material produced with the assistance of AI, or whether the result remains freely available for anyone to use. There is no straightforward answer, as it depends on the extent of the human creator’s own creative contribution to the work.
Copyright belongs to the person who creates a work, provided that the work is sufficiently independent and original. Copyright protection always requires a creative contribution by a human, and the assessment is made on a case-by-case basis. Copyright never protects an idea as such, but only the specific form in which the idea is expressed.
When a creative professional uses AI as a tool in their work, the existence of copyright is assessed according to these same principles. Copyright does not arise where a person gives the AI only a general instruction and the AI produces the final content entirely without any creative contribution from the user.
The situation is different if AI is used as part of a broader creative process. If the creator uses AI, for example, to support brainstorming, then creates the content themselves and uses AI only for final refinements, the work is likely to contain enough of the creator’s own creative contribution to qualify for copyright protection.
The use of AI should also be documented in case of potential disputes. Retaining the creator’s own drafts and the prompts used can make it easier to demonstrate which parts of the final result are based on human creative work.
If content is created using generative AI and the result does not qualify for copyright protection, protection may in some cases also be sought through trademarks. For example, Moomin Characters has protected Moomin characters as trademarks. However, it is important to note that a trademark only provides protection in specified classes of goods and services and within a particular geographical area. It does not protect the creative content as such. Its scope and purpose therefore differ from those of copyright protection.
If a creative project involving extensive use of generative AI is being planned, trademark protection may nevertheless be worth considering alongside copyright as a complementary form of protection.
Can AI-generated material be used freely?
Material created with AI is not automatically free from third-party rights. The key questions are which AI service was used to produce the material and how liability has been allocated in the service’s terms of use.
Some AI services use only licensed training data or other material that is not protected by copyright and contractually assume responsibility for ensuring that the materials generated by the AI do not infringe third-party copyrights. In such cases, the service provider bears responsibility for the output to the extent agreed in the terms of use, and the user’s legal risk is substantially lower.
Many widely used services, however, have been trained on extensive datasets collected from the internet, which may also contain copyright-protected material. In most services, the service provider does not contractually assume responsibility for ensuring that the generated content does not infringe third-party rights. Instead, responsibility for using the content remains with the user. Material produced using such services therefore requires careful review before publication.
In summary, there is no universally applicable answer as to whether AI-generated materials may be used freely. The allocation of responsibility depends primarily on the service used and its terms of use, which should be reviewed before AI is introduced as part of content production.
Can confidential information be entered into an AI service?
As a general rule, confidential information should not be entered into an AI service unless the service is specifically intended for business use and its terms and information security have been carefully assessed.
For business purposes, companies should use business or enterprise versions of generative AI services unless they operate a local AI solution on their own servers. In consumer services, such as the free and Plus versions of ChatGPT, materials and prompts entered into the service may, in accordance with the terms of use, be used to train the AI model. In addition, the service provider may reserve broad rights to use and even share material uploaded by users for purposes other than AI model training.
This means that if a company’s employees use consumer licences in their work, they may compromise the confidentiality of information by entering confidential material into the service.
The practical risk may arise, for example, where a screenwriter or copywriter uses a free consumer AI service to refine a text and enters an unpublished script or campaign concept into the service. Under consumer licences, the content may be used to develop AI models, meaning that the material is no longer under the company’s exclusive control. Even if the content does not appear elsewhere in an identical form, there is a risk that recognisable features of the material may be used as part of outputs generated for other users.
It is also important to note that other risks do not disappear even if the use of content for training purposes can be prohibited separately in the service settings or terms of use. Under consumer licences, service providers often do not provide binding guarantees regarding the security of the service. Information entered into the service may therefore be exposed to data breaches or other information security incidents. Protecting confidential information requires selecting a licence suitable for business use and assessing the service’s terms and information security before introducing the AI service.
Can personal data be entered into an AI service?
If personal data, such as a person’s image, voice or name, is entered into an AI service, the General Data Protection Regulation, or GDPR, applies.
The company is responsible for ensuring that the licensing terms of the AI service have been carefully assessed. As part of its compliance with the GDPR, the company must ensure, among other things, that material uploaded to the service is not used to train the AI, that it is possible to enter into the data processing agreement required by the GDPR with the service provider, and that the AI service provides appropriate security for the protection of personal data. In practice, the use of an AI service will generally also require a data protection impact assessment.
The use of AI services under free consumer licences will generally not comply with the GDPR, as service providers often also use uploaded material for their own purposes.
Is it permissible to use AI to generate images or voices of real people?
Particular attention is also required where AI is used to produce images of real people or to create AI-generated copies of a real person’s voice. A person’s image, voice and other identifying features constitute personal data. AI-generated material may also be considered personal data if a specific individual can be identified from it. In such cases, all GDPR requirements apply, including the requirement to inform the individual about the processing of their personal data and the requirement to have a lawful basis for the processing.
In content production, it is also important to recognise that using a person’s image or voice for commercial purposes requires that person’s consent. In 2025, the Helsinki Court of Appeal ordered an underwear company to pay Jasper Pääkkönen EUR 300,000 in compensation for the unauthorised use of his name, image and voice in an extensive advertising campaign. The judgment is not yet final, and the Supreme Court has granted leave to appeal. The obligation to obtain consent also applies where the person’s image or voice has been generated using AI.
When must AI-generated content be labelled as a deepfake?
The EU’s new AI Act introduces transparency requirements concerning deepfakes. The Act will become applicable gradually, and the provisions concerning deepfakes will apply from 2 August 2026.
Deepfakes are AI-generated or AI-manipulated image, audio or video content that resembles existing people, objects, places, entities or events and may falsely appear to the recipient to be authentic or truthful. The transparency obligation is therefore not limited to deepfakes depicting people.
Under the AI Act, deepfakes must be clearly labelled as having been artificially generated or manipulated. However, the Act includes an exception for creative works. Where the content forms part of an evidently artistic, creative, satirical, fictional or similar work or programme, the disclosure may be made in a manner that does not interfere with the display or enjoyment of the work.
For example, a documentary-style television production may use highly realistic AI-generated images or videos to illustrate historical events. If the context does not otherwise indicate that the material is artificial, viewers may believe it to be genuine archival footage. In such a case, the transparency obligation under the AI Act must generally be considered. However, the exception for creative works allows the use of AI to be disclosed in a manner appropriate to the nature of the work, for example in the programme’s end credits, provided that the audience is not left with a false impression of the authenticity of the content.
A breach of the transparency obligation concerning deepfakes may result in an administrative fine under the AI Act.
Checklist for creative industry professionals
Rights: ensure that your own creative contribution is sufficient if you want the final result to qualify for copyright protection.
Documentation: document the use of AI and your own creative contribution.
Terms of use: review the service terms and determine what rights you receive to the generated content and who is responsible for potential infringements.
Business-level licences: only use business-level licences for professional purposes and enter into a data processing agreement where necessary.
GDPR and consent: using a person’s image or voice requires compliance with data protection rules and, for commercial use, the person’s consent.
Deepfakes: if content has been artificially generated or manipulated, ensure that the disclosure requirements of the AI Act are met.
Would you like to discuss the legal questions surrounding AI? We help companies assess the legal risks and opportunities associated with the use of AI in the creative industries and in other AI-enabled business operations.

Lila Kallio Counsel
+358 41 465 1365

Katri Aarnio Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to the Folks newsletter here.
