Connecting AI to customer data takes 4 checks: the plan you subscribed to, a data processing agreement, the configured retention period and data residency. The AI Act becomes fully applicable on August 2, 2026, and its obligation to train teams has applied since February 2025. The point most often missed sits in your own business tools: when a vendor promises that your data trains no model, it means its providers' models, rarely its own.
On August 2, 2026, the AI Act becomes fully applicable. If your marketing team already uses AI on customer data, as most of the teams I work with do, this date concerns you directly. The next morning, your CRM will be exactly as legal as it was the day before. What changes is that the authorities will finally have the power to inspect and impose penalties.
The hard part, when you try to prepare, is that almost all the available content is written for lawyers. It starts from the AI model and works back to the law. In marketing, the question runs the other way: you have a CRM, an email tool, an analytics tool and 3 AI assistants orbiting them. What you want to know is what you're allowed to connect to what, and what GDPR already requires of you on those data flows.
The answers below all refer to the vendors' official documentation or to the EU texts, accessed on July 21, 2026.
What changes on August 2 and what was just pushed back
The timeline comes first, because plenty of wrong dates are circulating about it. These are the deadlines as published by the European Commission.
| Date | What applies |
|---|---|
| August 1, 2024 | The regulation enters into force |
| February 2, 2025 | Prohibited practices and the AI literacy obligation |
| August 2, 2025 | Governance and obligations for general-purpose AI models |
| August 2, 2026 | Full application, transparency, enforcement powers |
| December 2, 2027 | High-risk systems listed in Annex III |
| August 2, 2028 | High-risk systems embedded in products |
The last 2 rows have just moved. The Digital Omnibus package, adopted by the European Parliament on June 16, 2026, and then approved by the Council on June 29, postponed the obligations for the high-risk systems listed in Annex III. They were due to apply in August 2026 and will now apply in December 2027. Many articles published in the first half of the year still give the old timeline, or place full entry into force in February 2026. If you're preparing a committee presentation on this topic, check when your sources were published.
This postponement doesn't let you off the hook in the short term. The obligations that really affect a marketing team, transparency and AI literacy, are untouched by the delay. They do arrive on August 2, 2026.
Which tool for which data
This is the table I wish I had every time a client asks me, in a meeting, whether their team can paste a CRM export into a given tool. It compares the business plans of the 4 main assistants on the 4 criteria that really determine what you can put into them under GDPR.
| Plan | Training on your data | Retention period | European residency | Data processing agreement |
|---|---|---|---|---|
| Claude Team and Enterprise | Only with your express permission | Unlimited by default, configurable from 30 days on Enterprise | Not available directly | Automatic |
| Anthropic API | Only with your express permission | Conversation content not retained by default | United States or global routing | Automatic |
| ChatGPT Business | Off by default, reversible through opt-in | Unlimited, purged within 30 days after deletion | Not documented for this plan | On request, through a form |
| ChatGPT Enterprise | Off by default, reversible through opt-in | Set by the administrator | Yes, for eligible new customers | On request, through a form |
| Gemini for Google Workspace | Only with your permission or instruction | From 90 days to unlimited, set by the administrator | Yes, depending on the edition | Automatic |
| Microsoft 365 Copilot | No, with no opt-in caveat | Not published, set by your internal policy | Yes, automatic for an EU or EFTA tenant | Automatic |
Each row comes from the vendor's official documentation, accessed on July 21, 2026: Anthropic retention and Anthropic residency, OpenAI enterprise privacy and OpenAI residency, Google Workspace Privacy Hub, Microsoft 365 Copilot privacy. These policies change fast, so check the date before you rely on this table 6 months from now.
3 differences that matter more than the rest
The training column deserves a closer look: at a glance it shows 4 identical answers, and the wording tells a different story. Microsoft writes, without reservation, that prompts and data accessed through Microsoft Graph aren't used to train models. OpenAI and Google frame the commitment as a default setting that explicit consent can lift. Anthropic sits in between, making any use conditional on express permission. For a data protection officer (DPO), this nuance is the whole conversation.
Next comes the data processing agreement. At Anthropic, Google and Microsoft, it's built into the commercial terms automatically: you accepted it when you subscribed. At OpenAI, you have to fill in a form to have it executed. If nobody in your company has done so, you're using a processor without the contractual framework that GDPR Article 28 requires.
The third gap is European residency, where the differences are widest. Microsoft applies its EU Data Boundary automatically and at no extra cost as long as your tenant is registered in the EU or EFTA. Google makes it depend on the edition you subscribe to. OpenAI reserves it for new Enterprise and Edu customers, subject to commercial eligibility.
Anthropic currently offers only 2 residency values, the United States or global routing, and storage happens only in the United States. Several French comparison articles claim otherwise and cite Frankfurt or Paris. European residency for Claude does exist through Amazon Bedrock or Google Cloud, and in that case the cloud provider becomes your processor, with its own terms.
Finally, 2 notes on terminology. The ChatGPT Team plan was renamed ChatGPT Business on August 29, 2025, with identical features and pricing: if your internal documentation still says Team, it means the same thing. And Microsoft states explicitly that models provided by Anthropic as a subprocessor are excluded from its EU Data Boundary, a good illustration of the cascading subprocessing issue covered further down.
This table covers the model. It says nothing about what you allow the agent to do inside your systems, which remains the main risk factor. I covered that point in my article on data privacy when you connect AI to your CRM.
The blind spot: the AI already inside your CRM
The previous table covers the assistants your teams open on purpose. It leaves out the AI already running in your business tools, the kind nobody decided to turn on because it arrived with an update. Yet that's where I found the most unexpected information.
Everything rests on a distinction that sales pitches routinely blur. When a vendor says your data trains no model, it almost always means the models of its third-party providers. Whether it trains its own models on your data is a separate question, with a different answer.
| Tool | Training by the model provider | Training by the vendor itself | Documented retention |
|---|---|---|---|
| HubSpot AI and Breeze | Contractually prohibited | Yes, on by default and pooled across accounts | No published period |
| Salesforce Einstein | Zero retention at the provider | Yes for predictive AI, on by default | Prompts logged, period not published |
| Brevo | Not documented | Yes, provided for in the terms of use | No published policy |
HubSpot is the clearest case, because it's entirely public and yet rarely read. The vendor documents that it may use customer data to train and improve its own models, that some models are trained on data from many customer accounts at once, and that data used to build an already trained model can't be removed from it. The option sits in the account's AI settings, and it's on by default. Opting out therefore only applies going forward.
Salesforce follows similar logic over a narrower scope. Generative AI benefits from zero retention at the model providers, which is solid, but the data sharing used to train global predictive models is on by default, except for Government Cloud organizations or those that have opted out.
Finally, Brevo, the French email marketing platform, names its 4 AI providers in the list of subprocessors attached to its terms of use, and reserves the right to use content and usage data to improve its AI features. No AI-specific retention period appears there, and one of the declared providers is based in the United States.
All of this is public, freely available in each vendor's official documentation. The hard part is knowing that there are 2 separate questions, so that you think to ask the second one.
The question to ask your vendor fits in one sentence: do you train your own models with our data, and if so, how do we turn that sharing off? An answer that only covers third-party providers leaves the question open.
The AI Act applied to marketing
Most AI Act guides describe the 4 risk levels and stop there. For a marketing team, those levels translate into concrete rules for each use, and they sit on top of your existing GDPR obligations.
Scoring and profiling
First piece of good news: standard lead scoring and behavioral targeting don't count as high-risk systems. Ordinary advertising profiling stays in the limited-risk category. It moves into high risk when a score leaves its original purpose, typically when a score built for marketing is later used to assess creditworthiness or to price insurance. As long as your scores stay within the commercial scope, you're outside the heaviest regime.
That good news has a limit. The AI Act comes on top of GDPR. A scoring system that escapes the high-risk category under the AI Act remains fully subject to GDPR, with its requirements for a legal basis, transparency toward the people concerned and data minimization.
Conversational agents
Article 50 of the AI Act applies from August 2, 2026. A system that interacts directly with a person must let them know they're dealing with an AI, unless that's obvious from the circumstances. In practice, that means your support chatbot, your lead qualification agent on the website and your appointment booking assistant. A clear notice from the first message is enough.
Generated content
In workshops, this is the point where I most often have to ease a worry. For deployers, the obligation to label AI-generated content covers texts published to inform the public on matters of public interest: politics, justice, fundamental rights, health, the environment. Marketing and commercial content falls outside this obligation.
Your LinkedIn posts, newsletters and product pages written with help from AI therefore don't need a legal notice. You can still add one as an editorial choice, which I do for generated visuals. That's a brand decision, separate from compliance.
Set the rules before you deploy
The AI Marketing Cockpit: your brand encoded, your tools connected, 54 ready-to-use skills.
Discover the AI Marketing CockpitThe obligation almost nobody mentions: training your teams
Article 4 of the AI Act went largely unnoticed, even though it concerns every company that uses AI. It requires providers and deployers alike to take measures to ensure a sufficient level of AI literacy among their staff and among third parties acting on their behalf.
Keep 2 details in mind. First, the date: this obligation has applied since February 2, 2025. It has been in force for a year and a half. What arrives on August 2, 2026, is enforcement by national authorities. Second, the scope: it covers your contractors and agencies as well as your employees.
The good news is how flexible it is. The Commission imposes no format, duration or certification. The expected level depends on the technical knowledge of the people involved and on the context in which the systems are used. Internal documentation is enough to show that you acted.
In other words, a marketing team that has been trained on its AI tools, knows where the limits are and keeps a written record of that training meets Article 4. A team that discovered ChatGPT on its own, with no framework and no record, falls short. I described what I've seen on the ground in what I learned from training more than 100 employees.
DPIA and subprocessing: what GDPR requires
When an impact assessment becomes mandatory
The data protection impact assessment, or DPIA, is a GDPR obligation, separate from the AI regulation. The CNIL, France's data protection authority, applies the 9 criteria of the European Data Protection Board: as soon as 2 of them are met, the assessment is mandatory.
The criteria a marketing team runs into are large-scale processing, the combination of several datasets, innovative use, and the collection of sensitive or highly personal data. A customer base enrichment that combines your CRM with behavioral data and an AI model easily meets 2 of them.
The strictest rule concerns profiling: the CNIL considers an impact assessment always required when profiling or automated decision-making is involved. Automated lead scoring on a database of several tens of thousands of contacts falls into this category. The assessment must be carried out before the processing starts, then kept up to date.
Cascading subprocessing
In meetings, this is the topic that surprises people most. When your CRM adds an AI feature, it usually didn't build it itself: it calls a third-party model. Your chain of responsibility then has 3 links. You are the controller, your CRM vendor is your processor, and the model provider becomes a subprocessor.
You can frame the situation with 3 checks. Does the AI provider appear in your vendor's public list of subprocessors? Does the vendor's data processing agreement explicitly cover AI features, or do you need an amendment? And is the processing listed in your record of processing activities, with any transfer outside the European Union noted?
The most telling example comes from Microsoft, which states in its own documentation that models provided by Anthropic as a subprocessor are excluded from its EU Data Boundary. A customer who chose Microsoft for European residency can therefore see some processing leave that boundary through subprocessing. The information is public, for anyone who goes and reads it.
5 misconceptions still going around
These 5 claims come up regularly in the committees I take part in. They're either wrong today or were wrong from the start.
“The AI Act came fully into force in February 2026.” No. February 2025 covers the prohibited practices and the AI literacy obligation. Full application and enforcement powers arrive on August 2, 2026.
“High-risk system obligations apply in August 2026.” Not since late June. The Digital Omnibus postponed them to December 2027 for Annex III, and to August 2028 for systems embedded in products.
“Claude lets you host your data in Europe.” Not directly. Only the United States and global routing are offered, and storage is in the United States. European residency goes through a third-party cloud provider.
“You have to label all AI-generated content.” The obligation covers texts on matters of public interest. Your marketing content is excluded.
“My CRM guarantees that my data trains no model.” Check which models it means. The commitment usually covers the models of third-party providers. HubSpot and Salesforce both document training their own models on customer data, on by default.
“Data sent to the API is kept for 7 days.” That was true until recently. Anthropic's documentation now states that conversation content isn't retained by default on the API, while the commercial plans with an interface keep data indefinitely as long as no retention policy is configured. The logic has flipped: the chat tool remembers and the API forgets.
Where to start
If you have to present this topic to a committee in the coming weeks, this is the order I follow with my clients.
- List the AI tools the team actually uses, personal accounts included. That step almost always brings the most surprises.
- Check the plan behind each one, since privacy rules change completely between a consumer account and a business plan.
- Confirm that a data processing agreement exists, especially at OpenAI, where you have to request it.
- Open your CRM's AI settings and check whether the sharing used to train the vendor's models is turned on.
- Check whether your processing triggers an impact assessment, especially when scoring or profiling is involved.
- Add a notice to your conversational agents telling people they're talking to an AI, before August 2.
- Document the training of your teams and contractors, which addresses Article 4.
These steps cost little. What they mostly require is knowing what's really running in the team, which is rarely clear at the start. And if you'd rather mask personal data upstream than reason only in terms of access rights, I wrote a practical guide to anonymizing data before handing it to an AI. To size up your team before getting into the details of compliance, the free AI marketing diagnostic takes stock in a few minutes.
One last word on mindset. The European framework is often presented as a brake. On the ground, it mostly brings things to light: it forces you to put in writing what your team does with AI. Companies that do the work usually find that visibility into their own usage is a bigger problem than compliance.