Industry guide
Marketing, media & customer-facing AI
Generative content, customer-service chatbots, personalisation and synthetic media are where most SMBs first meet AI law. The EU AI Act's transparency rules (chatbot disclosure, deepfake labelling, machine-readable marking) have applied since August 2026; California requires large providers to embed provenance and offer detection tools and all generative developers to publish training-data summaries; Utah requires chatbots to admit they are AI when asked; and courts and regulators hold you to whatever your bot tells customers, as Air Canada learned.
Regulated uses
- Customer-service and sales chatbots and voice agents
- AI-generated images, video, audio and ad copy
- Deepfakes, voice clones and synthetic spokespeople
- Personalisation, profiling and targeted advertising
- Facial recognition or analytics in stores and venues
- Performance claims about AI products in marketing
Laws by region
| Region | Law | Status |
|---|---|---|
| EU | EU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689) | In force |
| EU | EU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) | In force |
| US | California SB 942California AI Transparency Act (SB 942, as amended by AB 853) | In force |
| US | California AB 2013California Generative AI Training Data Transparency Act (AB 2013) | In force |
| US | Utah AI Policy ActUtah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025) | In force |
| US | Texas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149) | In force |
| US | EO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence | In force |
| Canada | PIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA) | In force |
| Canada | Quebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions) | In force |
| Canada | Canada GenAI Code of ConductVoluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems | Voluntary |
| Standards | NIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) | Voluntary |
| Standards | ISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management system | Voluntary |
Obligations checklist
- Make every chatbot or voice agent say it is AI — up front where the law requires, and always when asked.
- Label AI-generated or manipulated images, video and audio, and keep machine-readable marks (C2PA-style metadata) intact.
- Keep chatbot answers tied to an approved knowledge base, log conversations and offer an easy path to a human.
- Substantiate every claim about what your AI can do before you publish it.
- If you develop generative AI for Californians, publish the AB 2013 training-data summary.
- Tell people when profiling or tracking technology is used and how to opt out (Quebec, GDPR).
- Do not run facial recognition on customers without a lawful basis, testing and safeguards.
Real cases
- Ruling2024 · CA-BCMoffatt v. Air Canada — airline liable for its chatbot's wrong answer
Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
- Fine2024 · EUItalian Garante v. OpenAI — EUR 15 million ChatGPT fine (later annulled on appeal)
OpenAI appealed, calling the fine disproportionate. The Rome Tribunal suspended the fine in March 2025 and then, in judgment no. 4153/2026 filed 18 March 2026, annulled it, reported as finding that once OpenAI had an Irish establishment the GDPR 'one-stop-shop' made Ireland's DPC the lead authority, so the Garante lacked competence. The substantive findings were not endorsed; the corrective orders and campaign had already been carried out.
- Ruling2026 · CA-federalCanadian privacy regulators v. OpenAI — joint findings on ChatGPT training data
Complaint well-founded. The federal OPC treated it as conditionally resolved on the strength of OpenAI's commitments (filtering tools, clearer notices about accuracy and sources, improved access tools, quarterly reporting); the Quebec, BC and Alberta offices found the consent and retention issues unresolved. No fine was imposed — PIPEDA gives the OPC no penalty powers.
Where do you stand in marketing, media & customer-facing ai?
The screener is pre-filled for this sector — ten minutes to your level and gaps.
Sources
- The EU AI Act's Transparency Rules: A Practical Guide to Article 50 — artificialintelligenceact.eu ↗
- New California AI Disclosure Rules Become Operative — Morgan Lewis ↗
- Moffatt v. Air Canada — McCarthy Tétrault ↗
Last reviewed Sep 25, 2026.