AIComplianceEthics

The EU AI Act for Social Media Teams: What Actually Applies

The EU AI Act applies in full from August 2026. Here's what genuinely binds social media teams — deepfake labels, AI literacy — and what doesn't.

Dan — Founder, SocialKit9 min read

The EU AI Act sorts AI systems by risk level and puts the overwhelming majority of its obligations on the companies that build those systems, not on the marketing teams that use them. For a social media team, most of it is simply not addressed to you — the parts that bite are one transparency article covering deepfakes and certain synthetic content, plus a staff-competence duty in force since early 2025. Its general application date is 2 August 2026, tomorrow as this publishes, so it is worth knowing which lines touch your work before someone in your team Slack announces that every AI-assisted caption now needs a label.

This is a practitioner's read, not legal advice. If your work sits near recruitment advertising, financial services, health claims, or biometrics, get a qualified adviser on your setup.

Deployer, not provider — the distinction that decides almost everything

The Act splits duties between two roles. A provider develops an AI system or model and places it on the EU market under its own name. A deployer uses an AI system under its own authority in a professional capacity.

If you are prompting a chat model to draft captions, generating images in a design tool, or using a video generator, you are a deployer. Nearly every heavy obligation in the Act — technical documentation, conformity assessment, CE marking, quality management systems, database registration, machine-readable watermarking of outputs — sits on the provider instead. The exception worth watching: if you stop using someone else's tool and start building and branding your own AI assistant, you can move toward provider status. Take advice rather than assuming the deployer path.

Where the timeline stands as of August 2026

The Act entered into force on 1 August 2024 and switched on in stages:

StageWhat turned on
February 2025Banned practices; AI literacy duty on providers and deployers
August 2025General-purpose AI model obligations; governance; most penalties
August 2026General application, including the transparency article on deepfakes and synthetic content
August 2027Remaining categories, including AI embedded in regulated products

One honest caveat: as of August 2026, the timing and scope of the Act's high-risk chapter have been the subject of active amendment discussion at EU level. If your work plausibly touches a high-risk category, confirm current dates with an adviser rather than a blog post.

What genuinely applies to a normal social media team

1. Deepfake disclosure

This is the big one. If you deploy an AI system to generate or manipulate image, audio, or video that resembles real people, objects, places, or events and would plausibly appear authentic, you must disclose that it was artificially generated or manipulated. The Act's definition of a deepfake turns on exactly that resemblance-plus-believability test. In practice:

  • In scope: a photoreal AI avatar presenting your product as a spokesperson; a cloned voice-over; a generated "customer testimonial" video; a photoreal scene of your product in a place that never existed.
  • Out of scope: an obviously illustrated or stylised graphic; an abstract background; anything no reasonable viewer would mistake for a real photograph or recording.

There is a carve-out for evidently artistic, satirical, or fictional work: the disclosure still exists but can be handled so it does not wreck the piece. A parody sketch does not need a warning stamped across the first frame.

If AI visuals are routine for you, this is the duty to build into your process — our guides to AI image generation and AI video for social cover the same territory.

2. AI literacy — already live, cheap to satisfy

Since February 2025, deployers have had a duty to ensure a sufficient level of AI literacy among staff who operate AI systems on their behalf, proportionate to their role and context. There is no prescribed curriculum, no certification, and no filing.

What satisfies it in a small team is unglamorous: a note of which tools are approved and for what, a short session covering hallucination risk and confidential-data rules, and a dated record that it happened. If you already maintain an AI usage policy for your social team, add a training log and an owner's name and you have something concrete for a client's procurement questionnaire.

3. AI-generated text on matters of public interest

The text disclosure duty is narrower than most people assume. It applies to AI-generated or AI-manipulated text published to inform the public on matters of public interest — and it falls away entirely where the content has undergone human review or editorial control and a person or company holds editorial responsibility for it.

A product launch caption is not a matter of public interest. A hashtag set is not. A brand newsroom thread explaining a public health topic or commenting on a policy debate might be — and even then, a named human reviewing and owning the copy resolves it. Human review inside your publishing flow is the compliance mechanism, not a nice-to-have.

4. Practices you should simply never touch

A handful of AI uses have been banned outright since February 2025. The ones that occasionally drift near marketing:

  • Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases.
  • Inferring emotions of employees in the workplace (outside narrow medical or safety cases).
  • Biometric categorisation used to deduce race, political opinions, trade union membership, religious beliefs, or sexual orientation.
  • Manipulative or subliminal techniques that materially distort behaviour and cause significant harm.

If a vendor pitches a tool that reads faces in a live stream to score sentiment, or promises audience-building from harvested face data, that is a hard no however good the demo looks.

5. Conversational AI

Systems that interact directly with people must make clear they are AI unless it is obvious. The duty sits with providers, but the upshot is the same: do not let a bot pass as a person. If you run AI-assisted DM automation, label the assistant in its first message.

The list of things it does not require

The anxiety is usually louder than the obligation. As a deployer running ordinary organic social, the Act does not require you to:

  • Label AI-assisted captions, hooks, hashtag sets, or first drafts.
  • Label grammar, tone, translation, or standard-editing help — outputs that do not substantially alter the meaning of what you supplied are explicitly carved out of the marking duty.
  • Embed machine-readable watermarks yourself. That sits with the tool provider; not stripping the metadata your tools attach is good practice rather than a stated deployer obligation.
  • Appoint an AI officer. No such role exists in the Act.
  • Register your tools with a national authority or in any EU database.
  • Run a conformity assessment, maintain a quality management system, or produce technical documentation.
  • Complete a fundamental rights impact assessment — that targets high-risk deployments by public bodies and a few regulated services, not caption drafting.
  • Label AI-derived scheduling suggestions, best-time recommendations, or analytics summaries.

Does it apply if you are not in the EU?

Often, yes. The Act reaches deployers established or located in the Union, and also those in third countries where the output of the AI system is used in the Union. A UK or US agency producing AI-generated video for a client's German audience should assume it is in scope. For agencies running AI-assisted social work across mixed geographies, one standard — the stricter one — beats two content processes.

Penalties, kept in proportion

The headline figures are large: up to €35 million or 7% of global annual turnover for the banned practices, and up to €15 million or 3% for most other breaches, including the transparency duties. Two things temper the panic. For SMEs and startups the cap is the lower of the fixed amount or the percentage, not the higher. And a small agency that labels its AI avatars and keeps a training log is not the target.

The AI Act is not your only rulebook

Platform policies are separate, contractual, and global. Meta, TikTok, and YouTube each run their own AI-content labeling systems, and their thresholds do not map neatly onto the Act's. A platform's native AI label is usually the cleanest way to satisfy both at once — check the mechanics for each network you publish to on our supported platforms page.

GDPR still governs any personal data you feed into a model, and consumer protection law still prohibits misleading commercial practices — arguably a bigger real-world risk for anyone generating fake-looking testimonials. The ethical questions around AI in social media marketing do not resolve because a regulation drew a line somewhere. Compliance is the floor.

Wiring this into your posting SOP

Rules that live in a policy document and nowhere else do not survive a busy week. Three practical moves:

Add an AI-provenance field to your content brief. One line per asset: what was AI-generated, which tool, whether it depicts anything real. That is your evidence trail. Fold it into your social media SOP so it becomes muscle memory rather than a separate compliance chore.

Put a named human in front of publish. A structured content approval workflow turns "we review things" into a defensible statement. In SocialKit, approval workflows are available on Team and Enterprise plans, so the sign-off gate sits inside the scheduling queue rather than a parallel spreadsheet, and the visual calendar shows what is still awaiting review.

Handle disclosure per platform, not globally. Labeling mechanics differ by network: some want a native toggle, some expect an in-caption line. Composing once and customising the caption per platform lets you attach the right disclosure to each destination without maintaining eleven drafts. Our guide to what to disclose and how covers the wording; treat placement as part of your automation guardrails.

Your one-page checklist

  1. Classify yourself. Deployer for every off-the-shelf AI tool. Flag anything you build and brand yourself for legal review.
  2. List your AI tools. What each is approved for, and what data may never be pasted into it.
  3. Log AI literacy training. One dated session with attendees. Repeat when the tool list changes materially.
  4. Screen for banned practices. No face scraping, no emotion inference on staff, no biometric categorisation. Ask vendors directly.
  5. Set a deepfake rule. Any photoreal AI-generated or AI-altered media that could pass as real gets disclosed. Write the standard wording once.
  6. Record provenance per asset. Tool used, what was generated, whether it depicts anything real.
  7. Require named human sign-off before publish. The most weight for the least effort.
  8. Label conversational AI. Any bot answering DMs or comments identifies itself up front.
  9. Check platform labels separately. Native toggles where they exist; in-caption disclosure where they do not.
  10. Fold it into your written social media policy rather than keeping a separate AI document nobody opens.
  11. Name an owner and a review date. A policy nobody owns rots within two quarters.

Most teams will find they already satisfy seven or eight of these and simply have not written them down. The gap is documentation, not behaviour — and the fix is an afternoon, not a project.

If you want the review gate and per-platform disclosure living beside your calendar, SocialKit covers all 11 networks on every plan, from €29/month Solo (€17.40/month billed annually as of August 2026) with a 7-day free trial. Start on the pricing page and build the review step in before it becomes urgent.