Plans
Learn Library

Run AI Marketing? Do the Compliance Math First

A learn article on compliance risks of AI marketing, covering GDPR, ICO guidance, EU AI Act obligations, and AI tool data retention. It outlines a four-point checklist for consent, transparency, and output review.

ai-marketing
2026-09-26SupaMarketers5 min read

A few days ago I had dinner with a friend who runs a cross-border e-commerce business. He was thrilled: his company now hands everything to AI — writing ad copy, building customer profiles, sending automated follow-up emails. Efficiency doubled, and the team was cut in half.

I said, congratulations.

Then I asked him one question: your users' data — how is the AI using it? Did anyone actually give consent?

He froze.

I've seen that blank stare enough times. In many teams' eyes, AI is just a tool — and a tool is something you just use. But the moment AI touches users' personal information, the story changes. A marketing AI deals in data by its very nature: who saw your ads, who opened your emails, who bought what. In the eyes of the UK regulator, all of this is personal data, and it falls under GDPR.

The regulators have already said it plainly

The UK's Information Commissioner's Office (ICO) puts its position bluntly: AI marketing tools, when processing personal data, must follow the rules of GDPR.

Transparency, consent, data security. No room for negotiation on any of the three.

Why is marketing so prone to crossing the line? Think about it: a marketing AI's core job is to feed in user behavior data and spit out sharper profiles and harder conversions. The deeper the data goes in, the more surface area you expose. And ICO scrutiny of this space is ramping up further starting February 2026.

And don't assume only the parts that directly touch data carry risk. The ad content itself is regulated too: the UK's ASA has already moved to ban misleading AI-generated ads. Some people put "This content was AI-generated" on a product page and think that buys immunity. It doesn't. Disclosure doesn't cure misleading — what should be banned still gets banned.

Paying is not the same as privacy

One more concrete case. Anthropic's Claude — plenty of companies use it to draft proposals and organize client files.

Since September 2025, chats from Claude's Free, Pro, and Max accounts are used to train the model by default.

Note: by default.

Many bosses assume: I paid, I bought a subscription, so my data is private. That's not how it works. Your chat logs, even the code you write along the way, can all become food for the model. And if the training toggle is on, the data can be kept for up to 5 years.

5 years. A snippet of client data you casually pasted in two years ago may still be sitting on the model's side.

To turn it off, you have to go digging in settings: Settings, Privacy, Privacy settings, and switch off "Help improve Claude." Only the Enterprise and Team plans — Claude for Work — are kept out of training by default.

From a GDPR standpoint, the problem here is obvious: holding data for 5 years for training purposes makes both data minimisation and purpose limitation (GDPR principles: collect only what you need, use it only for the stated purpose) look shaky no matter how you count. If your teams are using AI tools, it's time to dig out the internal policy and reread it.

The fines are already flying

There's something heavier still: the EU AI Act.

Since February 2025, its prohibitions are in force. Social scoring, manipulative AI, certain biometric uses — touch any of them and you're in violation. Even if you're a UK company, as long as your business reaches the EU market, you're still within range.

In August 2026, the main requirements for high-risk AI systems land too, and violations can be fined directly.

How much? In the most serious cases, EUR 35 million, or 7% of global annual turnover.

That's higher than under GDPR.

One easily overlooked point: Article 4 of the Act requires organizations to ensure their staff have sufficient AI literacy. Why would even this be regulated? Because employees run wild with AI tools: data pasted in casually, wrong outputs nobody catches, decisions made that nobody can explain afterward. Those holes get filled by the organization, in the end.

One more thing, more fundamental than every clause above. Every regulatory action — GDPR, the AI Act, whichever — ends up at the same question: can you prove that your training data was lawfully collected and lawfully used?

If you can't show that, everything else is off the table.

Your compliance strategy is your data strategy.

A four-point check-up

So what should you do? It's not complicated — four things.

  1. Go through every AI marketing tool you hold and shore up consent for how data is used. It must be explicit, clear consent — no sneaking by on pre-ticked boxes.

  2. Sensitive data: no lawful basis, don't touch it. Don't gamble.

  3. Keep data processing transparent and traceable end to end. What the AI actually did with the data — you must be able to explain it at any moment.

  4. Look back at AI outputs regularly: check for bias, check for privacy risks. Models change, data changes; last quarter's inspection doesn't hold for this quarter.

Back to trust

Some people think compliance is just paying for peace of mind — if no fine arrives, you've profited.

I don't see it that way.

When GDPR first came out, how many companies decided it had nothing to do with them — until the fine showed up and the customers ran out, and only then did they start cramming. This time it's AI's turn, and the script hasn't changed.

Users' trust is invisible in ordinary times and most expensive when it's lost.

Same AI marketing: if you can explain the whole story of your data clearly, customers will dare to hand you their information, and regulators can't find fault. If you can't explain it, doubled efficiency just doubles the speed at which you crash.

Back to that friend from the beginning. Over the second half of that dinner he didn't say a word — he typed all four check-up items into the notes app on his phone.

When was the last check-up for your AI marketing?

Continue reading