EU AI Act—a simple 90-day plan for marketers and agencies.
August 11th, 2025
The gist.
If you sell into or process EU data, you’re in scope.
The Act has staggered enforcement, but some obligations already apply, and more will come later this year and next year.
Like GDPR, preparing now saves money, avoids panic, and positions you as a trustworthy partner.
Why this matters.
Fines can be significant for non-compliance, even for non-EU companies.
Clients increasingly ask for vendor compliance proof before signing contracts.
Getting ahead signals professionalism and reduces the risk of losing deals.
90-day plan.
Inventory AI use cases — Make a list of every way AI touches customer data: ad targeting, personalization, analytics support, chatbots, etc.
Classify by risk — Use the EU’s categories: minimal, limited, general-purpose, or high-risk. High-risk includes areas like biometric ID or credit scoring.
Vendor checks — Send a 10-question AI transparency checklist to your key platforms. Ask about model transparency, data flows, and opt-outs. Keep a record.
Update policies — Add a plain-English AI section to your privacy policy and SOWs covering purpose, data handling, and human oversight.
Add user notices — On any AI-powered customer touchpoint (chat, personalization, recommendations), disclose it’s AI-driven and offer opt-outs.
Train your team — Run a 60-minute session on what’s allowed, what’s not, and who to ask when in doubt.
Tools to make it easier.
Data & Model Register — A simple spreadsheet to track AI use cases and risk classification.
Vendor Questionnaire — Prebuilt questions to send to software partners.
AI Disclosure Templates — Language for privacy policies, SOWs, and user-facing notices.
Campaign Risk Checklist — Quick reference for marketing and creative teams.