MAILCRAFT
Home Features Pricing About Blog Contact Log in Get Started →
Email compliance & security

The EU AI Act and Email Marketing: What Changes and When

The EU AI Act and Email Marketing: What Changes and When

The EU AI Act entered into force on 1 August 2024. And for a team drafting newsletters with AI tools? Nothing changes overnight. Obligations apply in stages, and most everyday marketing uses sit in the lowest risk tier, so the AI Act email marketing story is mainly about preparation. The Commission’s entry into force announcement sets out the basics. One caveat before we go on: this is a practical explainer written in August 2024, not legal advice.

What actually happened on 1 August 2024?

The regulation entered into force. That starts the clock, but the requirements themselves begin to apply later. A bit of history: the Commission proposed it in April 2021, and the European Parliament and the Council agreed on it in December 2023. What we got is one uniform framework across all EU countries instead of a patchwork of national rules. Its purpose is to address risks to health, safety and fundamental rights by attaching requirements to specific uses of AI.

Who carries those requirements? Two groups: developers and deployers. For a marketer the split is simple. The vendor that builds a writing assistant is the developer. Your team, which uses it at work, is the deployer. Most of the heavy duties sit with whoever builds the system, which is good news for you. But deployers still need to know which category their use belongs to.

The risk-based approach in plain words

The Act sorts AI systems by how much harm they could cause. More risk, more duties. Stripped of the legalese, the tiers look like this:

  • Minimal risk - no obligations under the Act, although companies may adopt voluntary codes of conduct.
  • Transparency duties - certain systems, such as chatbots and some AI-generated content, must be recognisable as AI.
  • High risk - strict requirements before and after a system reaches the market.
  • Banned practices - uses considered a clear threat to people’s safety, livelihoods and rights.

Spam filters are the Commission’s own example of minimal risk. And according to the EU regulatory framework for AI, the vast majority of systems currently used in the EU fall into that category. So the practical question for a marketing team is not whether AI is allowed. It is which tier each tool lands in. Answering it takes an afternoon, not a legal department.

Where does AI Act email marketing use fit in those categories?

Drafting subject lines, rewriting copy, filtering spam, picking send times. The typical email work belongs to the minimal-risk group, which carries no obligations under the Act. An AI writing assistant for newsletters is a drafting aid, and a person reads its output before it goes anywhere. Spam and deliverability filtering is the textbook minimal-risk case. Segmentation suggestions work the same way, since a marketer decides whether to act on them. None of this alters how much AI’s impact on email marketing depends on the people steering it (we covered that in our piece on AI’s impact on email marketing).

The case to watch is a chatbot on the signup or support page. It talks directly to people, so it falls under transparency duties and not the minimal tier. And a separate thing that people tend to mix up: personal data in your lists and segments stays governed by GDPR regardless of the new regulation. Need a refresh on that side? The GDPR minimum checklist is the place to start.

AI Act transparency: what it means for AI-generated email content

The idea behind transparency duties is easy to state: people should know when they talk to a machine and when certain content was produced by AI. For chatbots the rule is direct. Users must be told they are interacting with an AI system. A short line in the chat window does the job. Hiding the bot behind a human name works against the whole idea.

AI generated email content is murkier, because only some synthetic content falls under labelling duties. A newsletter drafted with a tool and then reviewed and edited by a person is a different situation from publishing raw machine output. So while the details settle, human review is the sensible default. And there is one habit I would keep whatever the law says: never send AI copy without a named person approving facts, offers and tone.

The AI Act timeline: which dates matter for marketers

The rules arrive in stages. Entry into force is a starting point, not a deadline. After 1 August 2024, the provisions on general-purpose AI models, or GPAI, will enter into application 12 months later. The Act as a whole becomes generally applicable on 2 August 2026, with some exceptions, as the Commission’s AI policy overview explains. GPAI, by the way, means the large models behind most writing tools. Those duties fall on the model providers, not on the marketing team using the product.

What does that mean in practice? You have time to prepare calmly. It is also a good reason to ask vendors how they plan to comply. A supplier with a clear answer today is less likely to surprise you later. Vague replies? Note them in your records. They are a signal.

What to do now: AI in email marketing compliance steps

Three low-effort habits cover most teams today: list your tools, keep a human in the loop and write things down. Nothing fancy. The steps below turn them into a routine.

  1. Inventory every AI tool and feature the team uses, including those built into other software, with its purpose and vendor.
  2. Classify each use against the risk tiers, flagging chatbots and public-facing generated content.
  3. Set a human review rule that applies before anything is sent.
  4. Keep simple records of which tool was used for what and who approved it.
  5. Ask vendors where data is processed and how they are preparing for the Act.

That last question is easier to judge once you understand what EU data residency means for a marketing stack. But whatever the answers, the foundation stays the same. In MailCraft, as in any serious platform, campaigns, lists, segmentation and SPF/DKIM/DMARC authentication do the work that no AI tool replaces. A well-labelled chatbot will not rescue a message that fails authentication.

So where does that leave us? For now, the AI Act email marketing impact is modest: most uses sit in the minimal tier, and the EU AI Act marketing duties centre on transparency. Preparation beats waiting, because an inventory and a review rule cost little and answer most questions a regulator, client or manager might ask. Treat this article as orientation, not legal advice, and check specific cases with a qualified adviser.

FAQ

Does the EU AI Act ban using AI to write newsletters?

No. Drafting newsletters with AI is not among the banned practices, which target uses seen as a clear threat to people’s safety, livelihoods and rights. Most everyday AI systems fall into the minimal-risk tier and carry no obligations under the Act.

Do we have to label AI-generated email content?

Not every sentence a tool helped to draft. Transparency duties cover chatbots and some AI-generated content. Text that a person has reviewed, edited and approved is the safer practice. For your specific case, check with a legal adviser.

When do the AI Act rules start to apply?

The Act has been in force since 1 August 2024, but obligations are phased in over time. Provisions on general-purpose AI models enter into application 12 months after that date. General application follows on 2 August 2026, with some exceptions.