Interactive Outfitters, LLC

EU AI Act—a simple 90-day plan for marketers and agencies.

EU AI Act

The gist.

  • If you sell into or process EU data, you’re in scope.
  • The Act has staggered enforcement, but some obligations already apply, and more will come later this year and next year.
  • Like GDPR, preparing now saves money, avoids panic, and positions you as a trustworthy partner.

Why this matters.

  • Fines can be significant for non-compliance, even for non-EU companies.
  • Clients increasingly ask for vendor compliance proof before signing contracts.
  • Getting ahead signals professionalism and reduces the risk of losing deals.

90-day plan.

  • Inventory AI use cases — Make a list of every way AI touches customer data: ad targeting, personalization, analytics support, chatbots, etc.
  • Classify by risk — Use the EU’s categories: minimal, limited, general-purpose, or high-risk. High-risk includes areas like biometric ID or credit scoring.
  • Vendor checks — Send a 10-question AI transparency checklist to your key platforms. Ask about model transparency, data flows, and opt-outs. Keep a record.
  • Update policies — Add a plain-English AI section to your privacy policy and SOWs covering purpose, data handling, and human oversight.
  • Add user notices — On any AI-powered customer touchpoint (chat, personalization, recommendations), disclose it’s AI-driven and offer opt-outs.
  • Train your team — Run a 60-minute session on what’s allowed, what’s not, and who to ask when in doubt.

Tools to make it easier.

  • Data & Model Register — A simple spreadsheet to track AI use cases and risk classification.
  • Vendor Questionnaire — Prebuilt questions to send to software partners.
  • AI Disclosure Templates — Language for privacy policies, SOWs, and user-facing notices.
  • Campaign Risk Checklist — Quick reference for marketing and creative teams.

Helpful links: