← All posts

The EU AI Act Just Hit Marketers. What Indian Teams Should Know

a.
Anurag Sharma
Marketing leader, Bengaluru
| |

Key takeaways

  • High-risk obligations under the EU AI Act took full effect August 2026. The staged rollout is over.
  • Marketing exposure concentrates in transparency: label chatbots, disclose synthetic media.
  • Extraterritorial by design: EU-targeted campaigns from India are in scope.
  • The near-term enforcement is procurement questionnaires, not fines.
  • One afternoon: inventory, disclosures, data notes, kill-switch owner. Then back to work.

Quick answer

The EU AI Act’s high-risk obligations took full effect in August 2026. For most marketing teams the impact is narrower than the panic suggests: the practices squarely affected are undisclosed AI-driven manipulation, emotion recognition, and certain profiling, plus transparency duties when people interact with AI systems or AI-generated content. Indian teams are in scope the moment their campaigns target EU users. The practical response is a one-page inventory of where AI touches your marketing, disclosure where it interacts with humans, and documentation of your data sources. An afternoon of work, not a compliance department.

A law most marketers ignored for two years just became enforceable, and the panic content has arrived on schedule.

The EU AI Act entered into force on August 1, 2024, and its obligations have been landing in stages since. The stage that matters most arrived this month: from August 2026, the bulk of the high-risk system obligations apply in full. If you market to anyone in the EU, and plenty of Indian SaaS, D2C, and services companies do, some of this now describes you. Most of the commentary is either fear-selling or dismissal, so let’s do neither and read the thing like operators.

What does the EU AI Act actually regulate in marketing?

The Act sorts AI systems by risk. Three layers touch marketing work.

Prohibited practices, banned outright since early 2025: AI that manipulates people subliminally or exploits vulnerabilities in ways likely to cause harm, and social scoring. Marketing translation: dark-pattern personalisation engineered to exploit, not persuade.

High-risk systems, the tier whose obligations matured in August 2026: these are mostly defined by use cases like employment, credit, and essential services. Everyday campaign work rarely lands here, but marketing adjacent to credit decisions, insurance pricing, or hiring funnels can. If your “marketing” personalisation feeds a decision about what someone can access or afford, read this tier carefully.

Transparency duties, the layer that touches nearly everyone: people must be told when they are interacting with an AI system, chatbots included, and AI-generated or manipulated content, deepfakes especially, must be disclosed as such. Providers of generative systems also carry marking obligations for synthetic content.

Does an Indian company actually fall under this?

If you place AI system outputs in front of people in the EU, the Act does not care where your office is. Extraterritorial reach is the design, exactly as it was with GDPR. The realistic exposure for an India-first team is not a Brussels inspector at your door. It is commercial: EU clients and partners are already inserting AI-compliance clauses into contracts, procurement questionnaires now ask about your AI usage, and an enterprise deal can stall on your inability to answer. Compliance is becoming a sales asset before it is a legal risk.

Penalties at the top end are serious, up to 35 million euros or 7 percent of global turnover for prohibited practices. Nobody is fining a 6-person Bengaluru team that number next quarter. Your buyer’s legal team quietly discarding your proposal is the near-term cost.

What should a lean marketing team actually do?

  1. The inventory. One page listing everywhere AI touches your marketing: chatbots, personalisation, generated creatives, scoring, enrichment. You cannot assess what you have not listed, and the inventory is the first thing any EU partner will ask for.
  2. Disclosure where humans meet machines. Label the chatbot as a chatbot. Mark synthetic media where a reasonable person could be misled, especially anything resembling a real human. This costs a UI string and some caption discipline.
  3. A data note per AI use. Two sentences each: what data goes in, where it came from. This intersects with GDPR homework you likely owe anyway.
  4. A kill-switch owner. One named person who can answer “what AI do we run and can we turn it off” in a client call. That question is now in procurement scripts.

The operator move: then stop. A lean team does not need an AI governance committee, an ethics board, or a 60-page policy. It needs to not be caught blank on four questions.

Common pitfalls

Assuming India-based means out of scope. Targeting EU users puts you in scope, and your EU customers’ procurement teams enforce faster than regulators do.

Panic-buying compliance software. The current obligation for most marketing teams is an inventory and disclosures, not a platform subscription.

Ignoring it because “we just use ChatGPT”. Deployers have lighter duties than providers, but transparency duties still apply to what you put in front of users.

Treating this as legal’s problem. The disclosures live in your chatbot, your captions, and your ad creative. Marketing owns the surface where compliance is visible.

Who this applies to

Indian and global lean teams with EU customers, EU traffic, or EU enterprise deals in the pipeline. Purely domestic businesses can file this under “watch”, because India’s own AI governance conversation is borrowing from the same template. This is one operator’s reading, not legal advice; anything touching the high-risk tier deserves a real lawyer. My challenge to you: build the one-page inventory this week, before a procurement questionnaire builds it for you.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. Like GDPR, it reaches any provider or deployer whose AI system outputs are used in the EU, regardless of company location.

What do marketers have to disclose under the EU AI Act?

That users are interacting with an AI system where that is not obvious, and that content is AI-generated or manipulated where it could mislead, with deepfakes carrying the strictest duties.

Are the EU AI Act fines really 35 million euros?

That is the top band, reserved for prohibited practices, scaled to severity and turnover. The realistic near-term cost for small teams is failed procurement, not maximum fines.

Is ordinary ad personalisation banned by the EU AI Act?

No. Persuasion and personalisation remain legal. The prohibitions target manipulation that exploits vulnerabilities or operates subliminally to cause harm.

Want the next framework early?

The Operator goes one level deeper every Sunday. One theme, one framework, one move you can make this week.

Subscribe free

Keep reading.

Anurag Sharma
About the author

Anurag Sharma

I run marketing for a living, from Bengaluru. I founded a D2C brand, solo-built a content agency that worked with 100+ brands, produced 1400+ podcast episodes with 2M+ listens, and lead a 30-person marketing team. Everything I write here reflects what I have actually run, not theory.

1400+ episodes2M+ listens30-person teamAre We Cooked?
liked this?

Get The Operator in your inbox.

Every Sunday at 9 AM. One play, field notes from the week, one tool, one ask. For marketing leaders and founders running lean.

Leave a Reply

Your email address will not be published. Required fields are marked *