← All industries

Industry guide

Marketing, media & customer-facing AI

Generative content, customer-service chatbots, personalisation and synthetic media are where most SMBs first meet AI law. The EU AI Act's transparency rules (chatbot disclosure, deepfake labelling, machine-readable marking) have applied since August 2026; California requires large providers to embed provenance and offer detection tools and all generative developers to publish training-data summaries; Utah requires chatbots to admit they are AI when asked; and courts and regulators hold you to whatever your bot tells customers, as Air Canada learned.

Regulated uses

  • Customer-service and sales chatbots and voice agents
  • AI-generated images, video, audio and ad copy
  • Deepfakes, voice clones and synthetic spokespeople
  • Personalisation, profiling and targeted advertising
  • Facial recognition or analytics in stores and venues
  • Performance claims about AI products in marketing

Laws by region

RegionLawStatus
EUEU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689)In force
EUEU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744)In force
USCalifornia SB 942California AI Transparency Act (SB 942, as amended by AB 853)In force
USCalifornia AB 2013California Generative AI Training Data Transparency Act (AB 2013)In force
USUtah AI Policy ActUtah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025)In force
USTexas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149)In force
USEO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial IntelligenceIn force
CanadaPIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA)In force
CanadaQuebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions)In force
CanadaCanada GenAI Code of ConductVoluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI SystemsVoluntary
StandardsNIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1)Voluntary
StandardsISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management systemVoluntary

Obligations checklist

  • Make every chatbot or voice agent say it is AI — up front where the law requires, and always when asked.
  • Label AI-generated or manipulated images, video and audio, and keep machine-readable marks (C2PA-style metadata) intact.
  • Keep chatbot answers tied to an approved knowledge base, log conversations and offer an easy path to a human.
  • Substantiate every claim about what your AI can do before you publish it.
  • If you develop generative AI for Californians, publish the AB 2013 training-data summary.
  • Tell people when profiling or tracking technology is used and how to opt out (Quebec, GDPR).
  • Do not run facial recognition on customers without a lawful basis, testing and safeguards.

Real cases

  • Ruling2024 · CA-BC
    Moffatt v. Air Canada — airline liable for its chatbot's wrong answer

    Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.

  • Ban2023 · US-federal
    FTC v. Rite Aid — five-year ban on facial recognition surveillance

    Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.

  • Fine2024 · EU
    Italian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)

    OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.

  • Ruling2026 · CA-federal
    Canadian privacy regulators v. OpenAI — joint findings on ChatGPT training data

    Complaint well-founded. The federal OPC treated it as conditionally resolved on the strength of OpenAI's commitments (filtering tools, clearer notices about accuracy and sources, improved access tools, quarterly reporting); the Quebec, BC and Alberta offices found the consent and retention issues unresolved. No fine was imposed — PIPEDA gives the OPC no penalty powers.

Where do you stand in marketing, media & customer-facing ai?

The screener is pre-filled for this sector — ten minutes to your level and gaps.

Take the check for Marketing, media & customer-facing AI →

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.