Resources · Guide · July 2026

The EU AI Act for marketing: which deadline applies when

The EU AI Act does not have one deadline, it has five. Article 4 has applied since February 2025, Article 50 since August 2026, machine-readable labelling and two new prohibitions follow in December 2026, and the high-risk obligations arrive in late 2027 and mid 2028. This guide sorts the dates, corrects the penalty figure that circulates almost everywhere, and assesses 12 typical marketing use cases. It is based on Regulation (EU) 2024/1689 and the Digital Omnibus Regulation (EU) 2026/1744, which entered into force on 27 July 2026.

10 sources·21 minutes·Last reviewed 31 July 2026
Chapter 01

The deadline cascade at a glance

Most of the confusion around the EU AI Act comes from a single date being quoted as though it stood for the whole regulation. In reality the obligations enter into application in stages, and the Digital Omnibus Regulation changed that staging again in July 2026. For marketing the first three rows of the table below are the decisive ones; the last two concern almost only organisations with high-risk applications.

2 Feb 2025

in force

Prohibitions under Article 5, AI literacy obligation under Article 4

Marketing relevance: High

2 Aug 2025

in force

Obligations for providers of general-purpose AI models

Marketing relevance: Indirect

2 Aug 2026

in force

Transparency obligations under Article 50(1), start of national market surveillance

Marketing relevance: High

2 Dec 2026

upcoming

Machine-readable labelling under Article 50(2), two new prohibited practices

Marketing relevance: High

2 Aug 2027

upcoming

National regulatory sandboxes

Marketing relevance: Low

2 Dec 2027

upcoming

Standalone high-risk AI under Annex III

Marketing relevance: Low

2 Aug 2028

upcoming

Product-embedded high-risk AI under Annex I

Marketing relevance: Low
Chapter 02

What has applied since 2 August 2026

On 2 August 2026 the 24 month transition period for the central obligations of the AI Act came to an end. Two things changed that day. First, the transparency obligations under Article 50(1) became applicable, meaning the disclosure duties for chatbots, deepfakes and emotion recognition. Second, national market surveillance began, which is what makes the penalty framework of the regulation practically reachable.

What that does not mean is that audits started on a broad front that day. Supervisory structures in Germany are still being built, and the national implementing act that formally designates the Bundesnetzagentur had not been adopted at the editorial cut-off of this guide. Anyone who concludes from that that nothing is happening is confusing the moment of the first audit with the moment an obligation comes into being. The obligation exists whether or not it is checked, and a breach remains a breach even if it surfaces later.

For marketing teams the practical consequence is narrow and concrete. If you run a chatbot with an AI backend on your website, you need a recognisable notice at the point of contact itself. A line in the privacy policy is not enough, because that covers the data protection side rather than the transparency obligation of the AI Act. If you produce photorealistic depictions of real people, you need clear labelling. Both are craft, not a legal opinion.

Chapter 03

2 December 2026 is the next real date

In the public debate August 2026 is the date everyone writes about. For marketing, December 2026 is the more important one, because that is when the obligation that genuinely reaches into every image and video workflow takes effect.

Machine-readable labelling under Article 50(2). Providers of generative systems must ensure that their outputs are marked in a machine-readable format as artificially generated or manipulated. The Digital Omnibus Regulation differentiated the scope of this obligation according to when a system entered the market. For deployers the practical consequence is one thing above all: the metadata your tool supplies must not be lost inside your production chain. That is exactly what happens in practice all the time, because image editing, compression and content management systems strip metadata as a matter of routine.

Two new prohibited practices under Article 5. The Digital Omnibus Regulation adds AI systems that generate non-consensual intimate imagery and systems that generate child sexual abuse material to the list of prohibitions. Both sit in the highest penalty tier at up to 35 million euro. For legitimate marketing this is not a change of behaviour, but it is a signal about where enforcement is aimed: at generative imaging.

Anyone who checks today whether their image pipeline preserves provenance metadata has until December to repair it. Anyone who starts in November checks under time pressure. The check itself takes a few hours.

Chapter 04

What the Digital Omnibus actually changed

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal of the European Union on 24 July and entered into force on 27 July 2026. It amends more than 40 articles of the AI Act. The reason was sober: the harmonised technical standards, without which a conformity assessment is not practically feasible, were not available in time.

High-risk deadlines postponed. Standalone systems under Annex III apply from 2 December 2027, product-embedded systems under Annex I from 2 August 2028. Neither affects marketing directly in most cases, but both touch adjacent areas such as AI supported recruitment or credit assessment.

The definition of high-risk was narrowed. Systems that support users, automate workflows or serve quality control now count as high-risk only where their failure or malfunction can actually create risks to health or safety. A number of previously covered applications fall out of scope.

Article 4 was recast, not deleted. The original wording required organisations to ensure a sufficient level of AI literacy. That is an obligation of result. The new wording requires them to support the development of that literacy, without having to guarantee a particular level for every individual. The obligation has applied since 2 February 2025 and continues to apply; what has eased is the pressure to evidence the outcome of individual training. The practical advice barely changes: a documented, role-appropriate training concept remains the simplest way to be able to answer questions in an audit, and it has operational value independently of the legal position.

The EU AI Office gained its own powers. Investigation, inspection and enforcement now sit there as well, which makes it effectively a market surveillance authority in its own right. For mid-sized companies the national authority remains the first point of contact, but the old rule of thumb that the AI Office is only concerned with the large model providers no longer holds.

Relief for small mid-caps. The privileges previously reserved for SMEs, including simplified technical documentation and the adjusted penalty ceilings under Article 99(6), were extended to companies with fewer than 750 employees and less than 150 million euro in annual turnover or less than 129 million euro in balance sheet total.

What the Digital Omnibus did not postpone are the transparency obligations under Article 50(1). The headline that the EU has delayed its AI rules does not translate into a reprieve for marketing and customer communication.

Chapter 05

The four transparency obligations under Article 50

Article 50 of Regulation 2024/1689 is the central provision for marketing. It defines four transparency obligations, each with a different addressee and a different trigger.

01

AI interacting with people

Where your chatbot, voice assistant or conversational agent interacts directly with end customers, you must make it clearly and visibly apparent that they are dealing with an AI. A line in the privacy policy is not sufficient. What works in practice is a short notice at the start of the conversation plus a permanent marker in the widget.

02

AI generated content, machine-readable

Providers of generative models must ensure their outputs are marked in a machine-readable format as artificially generated, for example through C2PA metadata. This obligation falls on the providers. As a deployer your task is to make sure that this metadata is not lost inside your processing chain. The differentiated scope takes effect on 2 December 2026.

03

Deepfakes

AI generated or manipulated images, audio or video that convincingly depict real people, places or events must be clearly and visibly labelled as AI generated. This covers every campaign using photorealistic AI visuals. Clearly synthetic illustrations are exempt.

04

Emotion recognition and biometric categorisation

If you deploy AI tools that analyse users emotions or categorise people biometrically, you must inform the individuals concerned. Rarely relevant in classic marketing, but it becomes a live issue quickly with voice bots and video analysis.

For machine-readable labelling, C2PA has established itself as the industry standard, backed by Adobe, Microsoft, OpenAI, BBC and Sony among others. If you generate images through Adobe Firefly, Midjourney or comparable tools, the metadata is often already embedded without you knowing. The actual work lies in not losing it during further processing.

One point on visual execution that is often missed: a peer reviewed study by Lindgaard and colleagues from 2006 at Carleton University Ottawa shows that users form a stable aesthetic judgement about a website after as little as 50 milliseconds. What was measured is perceived visual appeal, not credibility, which is the claim frequently and wrongly attached to it. In practice this means transparency notices should be visible enough for the legal obligation and integrated enough not to disturb the first impression. If you want to go deeper into how website elements affect perception, our Web Design Cost Guide covers this study in detail.

Chapter 06

The penalties, explained honestly

Almost every publication on the EU AI Act quotes the maximum of 35 million euro or 7 per cent of worldwide annual turnover. What is rarely mentioned is that this ceiling applies under Article 99(3) exclusively to breaches of Article 5, that is to the prohibited practices. The transparency obligations under Article 50 that matter for marketing are expressly assigned to the second tier by paragraph 4, point g.

Article 5

EUR 35m

Prohibited AI practices

or 7% turnoverRare in marketing

Article 50

EUR 15m

Transparency, marketing

or 3% turnoverMain marketing risk

Other

EUR 7.5m

Incorrect information

or 1% turnoverSecondary risk

The reversal rule for SMEs is the practically most important line in this table. For a company with 10 million euro in annual turnover, the ceiling for a breach of Article 50 is not 15 million euro but 3 per cent of turnover, that is 300,000 euro. Still substantial, but a different order of magnitude from the number that travels through the headlines.

Chapter 07

12 typical marketing use cases, assessed

These are the 12 AI applications we see most often at mid-sized clients, each with a risk classification and the concrete obligation attached. The classifications take account of the narrower definition of high-risk introduced by the Digital Omnibus Regulation. This list does not replace individual legal advice, but it gives a defensible orientation for the majority of marketing setups.

Website chatbot

Limited

Clearly visible AI notice at the widget and at the start of the conversation. The privacy policy alone is not enough. In force since 2 August 2026.

AI generated newsletter copy

Minimal

No direct obligation for standard marketing copy. Where content informs the public on matters of public interest, a visible notice is required.

AI generated social media images

Limited

Visible label on the content plus preservation of provenance metadata through the processing chain. The differentiated scope for machine-readable labelling takes effect on 2 December 2026.

Deepfake advertising with real people

Limited, with conditions

Clear labelling obligation and very high reputational exposure. Clear the rights with the person depicted beforehand, independently of the AI Act.

AI personalisation in newsletters

Minimal

No direct AI Act obligation. The profiling rules of the General Data Protection Regulation apply in parallel, including the right to object.

AI lead scoring in B2B

Limited

It becomes relevant where the scoring has effects on identifiable natural persons, for instance in credit offers. Pure B2B sales scoring generally remains limited risk.

AI voice bot for phone support

Limited

A clear notice at the start of the call. A line in the website footer is not enough, because the notice has to occur at the point of contact itself.

AI product recommendations in a shop

Minimal

Standard recommendations are generally minimal risk. With hyper-personalised dynamic pricing the classification can rise.

AI driven A/B testing

Minimal

No direct AI Act obligation. Standard performance optimisation.

AI translation of marketing content

Minimal

No direct labelling obligation for translations. Editorial quality control remains your responsibility.

AI generated marketing video

Limited

For photorealistic depictions the labelling obligation applies as it does to images. For clearly animated explainer video the requirement is considerably lighter.

AI sentiment analysis of reviews

Minimal to limited

As soon as profiles of identifiable individuals emerge from the data, both the transparency obligation and data protection law apply. Aggregated analysis without personal reference stays minimal.

Chapter 08

Provider or deployer: which role is your company in?

The EU AI Act distinguishes several roles, of which two matter in practice for mid-sized marketing teams: provider and deployer. Getting the classification right determines which obligations reach you and how extensive your setup has to be.

A provider is anyone who develops an AI system, or has it developed, and places it on the market under their own name or trade mark. That means OpenAI, Anthropic, Google and Microsoft, but also European providers such as Aleph Alpha or DeepL. The provider obligations are extensive: technical documentation, conformity assessment, marking for high-risk systems, risk management, data quality requirements.

A deployer is anyone who uses an AI system under their own authority. That covers most mid-sized companies using ChatGPT, Claude, Midjourney or sector-specific tools. Deployer obligations are considerably lighter by comparison, but they are not nil. What reaches you: AI literacy in the team under Article 4, in force since February 2025; transparency obligations towards users under Article 50, in force since August 2026; and for high-risk applications additionally human oversight, log retention and risk management.

An important special rule: if you substantially modify an AI system, place it on the market under your own brand, or put it to a purpose other than the one intended by the provider, you become a provider yourself. A practical example: you take a model API, build your own customer service bot around it with your logo, and resell it as your own product. That switches your role, and the considerably stricter provider obligations apply.

Concretely: most mid-sized companies are deployers only. Their compliance rests on three blocks, namely an AI inventory, a risk classification of the systems in use, and implementation of the transparency obligations at the relevant touchpoints. Those three blocks form the basis of the setup described in the next chapter.

Chapter 09

What is actually inside an ALVÉRA AI Act setup

A defensible AI Act setup for marketing consists of six components that build on one another. Skip one and you end up with documentation that does not hold in an audit.

01

AI inventory

A systematic record of every AI system in the company, including embedded features in standard software. Tools that individual staff use through private accounts belong in the record too, because in an audit they are attributed to the company.

02

Risk classification

Every recorded system is classified against the categories of the regulation: prohibited, high-risk, limited risk, minimal risk. For each classification we document the reasoning so it can be evidenced in an audit. The narrower definition of high-risk introduced in July 2026 is taken into account.

03

Transparency setup

Implementation of the Article 50 obligations at every relevant touchpoint: AI notice in the chat widget, labelling of AI generated images, a note in the newsletter, adjustment of the privacy policy. Designed so that conversion does not suffer.

04

Metadata chain check

A check on whether provenance metadata from generative tools survives the processing chain, meaning image editing, compression and the content management system. Preparation for the differentiated scope from 2 December 2026.

05

Training concept under Article 4

A role-appropriate training concept for everyone who uses AI tools. Content: a working understanding of the regulation, safe use, and the typical pitfalls such as personal data in prompts. Since Article 4 was recast, no guaranteed outcome is required, but a documented concept remains the simplest evidence.

06

Documentation and monitoring

Adding the AI processing activities to the record of processing activities, building AI Act specific documentation, and ongoing observation of new tools entering the company and of regulatory change.

The AI Act does not penalise using AI. It penalises hiding it.

Almost everything marketing does with AI day to day is permitted and stays permitted. What the regulation asks for is recognisability: that a chatbot is recognisable as a chatbot and a photorealistic image as generated. That is not a threat to the craft, it is a requirement on its honesty.

Assessment by the ALVÉRA Performance Solutions team
Chapter 10

What an AI Act setup costs at ALVÉRA

The ranges below are our own calculation, based on the effort we actually incur on comparable projects. We deliberately do not anchor them to third party industry studies, because the available cost studies on the AI Act concern high-risk systems and conformity assessments, which is an entirely different kind of effort. If you already keep clean data protection documentation you will sit at the lower end of each range. Starting from scratch puts you at the upper end.

Tier 01

AI Act Audit

from EUR 2,500

The entry point for companies that want to know where they stand. Within two weeks we deliver a complete gap analysis.

  • AI inventory across all departments
  • Risk classification of every system
  • Gap analysis with prioritisation
  • Recommended actions with effort estimates
  • Documented reasoning for each classification
Most chosen
Tier 02

AI Act Setup

from EUR 6,500

Audit plus full implementation of the transparency obligations at every touchpoint, including a training concept.

  • Everything from Tier 01
  • Transparency notices at every touchpoint
  • Metadata chain check
  • Training concept under Article 4 for up to 15 staff
  • Update to the record of processing activities
  • Compliance documentation for audits
Tier 03

Full Compliance

from EUR 14,500

Setup plus ongoing support over twelve months, with quarterly updates on regulatory change.

  • Everything from Tier 02
  • Quarterly updates on the legal position
  • Ongoing assessment of new AI tools
  • Preparation for 2 December 2026
  • Annual readiness audit
  • A point of contact for authority enquiries
Enterprise

AI Governance Framework

from EUR 25,000

For corporates and small mid-caps with complex AI estates, multiple sites and their own high-risk applications under Annex III. We build a governance framework that integrates data protection, the AI Act, NIS-2 and ISO 27001 requirements and docks onto the existing compliance organisation rather than sitting beside it.

Request an enterprise callReply within one working day
Initial phase

12 to 16 weeks to an adopted framework

Scope

Multiple sites and country entities, one consolidated AI inventory

Integration

Data protection, AI Act, NIS-2 and ISO 27001 in one rulebook

Afterwards

Ongoing support on a retainer, with quarterly reviews

Our services are offered to businesses, self-employed professionals and organisations, not to private consumers. All prices are net and shown without VAT. The from prices are starting points; final pricing is calculated individually in an initial conversation and depends above all on the number of AI systems in use and the maturity of existing documentation.

Chapter 11

Why there are offers from EUR 499, and what they leave out

Since early 2026 offers for AI Act compliance at low three-figure prices have been appearing in growing numbers. Standardised templates, automated checklists, generated assessments. Such offers are not inherently dubious, they simply solve a different problem from the one you have.

What templates cannot do is the classification. A mid-sized company with two chatbots has different obligations from one with twelve AI tools across sales. The risk classification is the core of the documentation, and it depends on the specific purpose of use, not on the tool category. A template cannot make that distinction, because it does not know your purpose.

What templates equally cannot do is the metadata check. Whether your image pipeline preserves provenance information or discards it on export cannot be derived from a questionnaire. Someone has to trace it through your actual workflow.

The honest comparison is therefore not EUR 499 against EUR 2,500. It is a template against an inventory. For a company with a single chatbot and no generative image production, the template may genuinely be enough. If that describes you, do not buy an audit.

Chapter 12

When you should not work with us

If your company develops or places on the market high-risk AI systems under Annex III, for instance in recruitment, credit assessment or critical infrastructure, and you are the provider of those systems, you need specialist compliance advice with its own technical auditors and access to notified bodies. That is not our core business, and 2 December 2027 is your relevant date, not December 2026.

If you need a legally binding opinion, for instance because proceedings are already under way or a cease and desist letter has arrived, that belongs with a law firm. We assess setups and implement them; we do not provide legal advice.

If what you want is documentation that looks good in an audit without anything changing in your practice, we are the wrong address. A classification that does not reflect actual use is worse in an audit than none at all, because it demonstrates that the question was asked and answered incorrectly.

What we are good at: marketing applications at mid-sized clients with limited or minimal risk. Chatbots, generative image and text tools, personalisation, AI assisted newsletters. That is the area where the bulk of marketing AI use actually sits.

Chapter 13

Every source, documented

Every legal statement in this guide is traceable to the text of the regulation or to an official publication. Market figures come from named industry studies and are shown with their method and sample. Price figures are our own calculation and marked as such.

Block 1: Legal basis

  • Regulation (EU) 2024/1689: the AI Act, in force since 1 August 2024, applying in stages. Published in the Official Journal of the European Union, EUR-Lex CELEX 32024R1689.
  • Regulation (EU) 2026/1744: the Digital Omnibus Regulation on AI. Adopted 8 July 2026, published 24 July 2026, in force since 27 July 2026. Amends more than 40 articles of the AI Act. ELI: data.europa.eu/eli/reg/2026/1744/oj.
  • Article 99, penalties: official text via the AI Act Service Desk of the European Commission. Paragraph 3: EUR 35 million or 7 per cent. Paragraph 4(g): EUR 15 million or 3 per cent for Article 50. Paragraph 5: EUR 7.5 million or 1 per cent for incorrect information. Paragraph 6: the lower amount for SMEs.
  • Digital Omnibus on AI, Commission proposal: presented 19 November 2025. Trilogue agreement 7 May 2026, adoption by the European Parliament 16 June 2026, Council adoption 29 June 2026.

Block 2: Supervision and standards

  • Bundesnetzagentur: the intended national market surveillance authority in Germany, already operating an AI Service Desk. Formal designation follows through national implementing legislation, which had not been adopted at the editorial cut-off of this guide.
  • EU AI Office: supervises general-purpose AI models. Granted its own investigative, inspection and enforcement powers by the Digital Omnibus Regulation.
  • C2PA: Coalition for Content Provenance and Authenticity. An open industry standard for machine-readable provenance metadata, backed by Adobe, Microsoft, OpenAI, BBC and Sony among others.

Block 3: Market data and research

  • Bitkom, Marketing im digitalen Wandel 2026: online survey of 180 companies from the German digital sector drawn from the Bitkom network, calendar weeks 44 to 50 of 2025, published 12 February 2026. Bitkom states explicitly that the results are not representative. 84 per cent see AI as the most important marketing trend through 2027, 51 per cent already use generative AI, 87 per cent name building trust as their top marketing objective. German market data.
  • Bitkom, Digitalisierung der Wirtschaft 2026: representative telephone survey of 604 companies with 20 or more employees, calendar weeks 2 to 6 of 2026, published 11 March 2026. 41 per cent use AI, up from 17 per cent a year earlier; 51 per cent report difficulties with digitalisation; 13 per cent see their existence threatened. German market data.
  • Lindgaard, G., Fernandes, G., Dudek, C. and Brown, J. (2006): Attention web designers: You have 50 milliseconds to make a good first impression. Behaviour and Information Technology, Vol 25 No 2, pages 115 to 126. DOI 10.1080/01449290500330448. Carleton University Ottawa. What was measured is the aesthetic judgement, not credibility.

This guide is updated when there are material legal developments, in particular on the adoption of the German implementing act and on the availability of the harmonised CEN-CENELEC JTC 21 standards. It does not replace legal advice in an individual case.

Frequently asked

The ten questions we are asked most often

Which EU AI Act deadlines apply to marketing, and when?

Five dates matter for marketing. Since 2 February 2025 the prohibitions under Article 5 and the AI literacy obligation under Article 4 have applied. Since 2 August 2026 the transparency obligations under Article 50(1) apply, meaning the labelling of chatbots, deepfakes and emotion recognition, and national market surveillance begins. On 2 December 2026 the machine-readable labelling under Article 50(2) takes effect in the form differentiated by the Digital Omnibus, together with two new prohibited practices. On 2 December 2027 the obligations for standalone high-risk AI under Annex III follow, and on 2 August 2028 those for product-embedded systems under Annex I. For typical marketing applications the first three dates are the decisive ones.

Do marketing breaches really carry fines of 35 million euro?

No. The widely quoted 35 million euro or 7 per cent of worldwide annual turnover applies under Article 99(3) exclusively to breaches of Article 5, that is to the prohibited AI practices. The transparency obligations under Article 50 are expressly assigned to the second tier by Article 99(4)(g): up to 15 million euro or 3 per cent. For incorrect, incomplete or misleading information supplied to authorities, paragraph 5 provides for up to 7.5 million euro or 1 per cent. For SMEs including start-ups, paragraph 6 applies the lower of the two amounts.

What changes on 2 December 2026?

Two things. First, the machine-readable labelling of AI generated content under Article 50(2): the Digital Omnibus Regulation staggers it according to when a system entered the market. Second, two new prohibited practices under Article 5: AI systems that generate non-consensual intimate imagery and systems that generate child sexual abuse material. Both fall into the highest penalty tier. For marketing the first point matters most, because it affects every image and video workflow that uses generative tools.

Do I have to label AI generated text and images in marketing?

It depends on the medium and the purpose. Article 50(2) requires machine-readable marking of AI generated or manipulated content in a format that reflects the state of the art, for example C2PA metadata. For text, the visible disclosure obligation applies where the content informs the public on matters of public interest. For most marketing text such as product descriptions, newsletters and social posts, that obligation does not apply directly. For images and video the obligation is broader, in particular for deepfakes, meaning convincingly realistic depictions of real people, places or events. Clearly synthetic illustrations and abstract graphics carry a lighter burden.

What did the Digital Omnibus change about the AI literacy obligation?

Article 4 was not deleted but recast. The original wording required providers and deployers to ensure a sufficient level of AI literacy, which is an obligation of result. The new wording requires them to support the development of that literacy, without having to guarantee that every individual reaches a particular level. The obligation itself has applied since 2 February 2025 and continues to apply. In practice a documented, role-appropriate training concept remains sensible and demonstrable in an audit, but the pressure to evidence the outcome of individual training sessions has eased.

Do I need an AI officer in my company?

The EU AI Act does not mandate a formal AI officer, unlike the General Data Protection Regulation with its data protection officer. A named responsibility is still sensible, because Article 4 sets out a duty to support AI literacy and because someone has to be able to answer questions in an audit. In practice the role is often attached to the data protection officer or to the compliance function.

Does the AI Act apply if I only use ChatGPT, Midjourney or Claude as tools?

Yes. The AI Act distinguishes between providers, such as OpenAI or Anthropic, and deployers, meaning organisations that put AI to use. The GPAI obligations fall directly on the providers of the base models only. As a deployer you carry your own obligations: AI literacy in the team under Article 4, transparency obligations towards users under Article 50, and for high-risk applications additionally risk management and documentation under Article 26. Most mid-sized companies are deployers only.

Which authority is responsible in Germany?

For operational market surveillance in Germany the Bundesnetzagentur, the federal network agency, is the intended authority. It already operates an AI Service Desk as a point of contact. Formal designation follows through national implementing legislation. At European level the EU AI Office supervises general-purpose AI models and, through the Digital Omnibus Regulation, has been granted its own investigative, inspection and enforcement powers. For mid-sized companies the national authority remains the first point of contact.

What did the Digital Omnibus actually postpone?

Regulation (EU) 2026/1744 entered into force on 27 July 2026 and amends more than 40 articles of the AI Act. What was postponed are the obligations for high-risk AI: standalone systems under Annex III to 2 December 2027, product-embedded systems under Annex I to 2 August 2028. In addition the definition of high-risk was narrowed and the deadline for national regulatory sandboxes moved to 2 August 2027. What was not postponed are the transparency obligations under Article 50(1). The headline that the EU has delayed its AI rules does not translate into a reprieve for marketing and customer communication.

What does an AI Act audit cost at ALVÉRA?

Our AI Act marketing audit starts at 2,500 euro for an AI inventory and risk classification. The setup, including transparency notices, a training concept and an update to the record of processing activities, starts at 6,500 euro. Ongoing compliance support with monitoring and quarterly updates starts at 14,500 euro for the first year. Implementations with a bespoke AI governance framework start at 25,000 euro. All figures are net prices excluding VAT and are addressed to businesses only. The final price depends on the number of AI systems in use and on the maturity of existing data protection documentation, and is calculated in an initial conversation.

Next step

Let us talk about where you stand on the AI Act

In a 15 minute conversation we work out where you stand on the EU AI Act, which of the upcoming deadlines actually reaches you, and what scope fits your setup. If we conclude that you are better served by a law firm, we will say so.

Book a free intro call

15 minutes · Not a sales call · Reply within one working day

Or see all services first

A
About the team

The ALVÉRA team

Performance Solutions, ALVÉRA Global Agency

The Performance Solutions team at ALVÉRA Global Agency covers every discipline around visibility, reach and measurable results. That includes digital marketing, SEO, GEO, SEA, social media and marketing management. With the EU AI Act, compliance has become a fixed part of every marketing strategy, which is why ALVÉRA has offered dedicated audit and setup services for mid-sized clients in German-speaking markets since early 2026.

Keep reading

More resources for your 2026 marketing strategy