← Industries/AdTech & Marketing Automation

Promethean for AdTech & Marketing Automation

AI Act Art. 50 requires transparency: chatbots and AI-generated content must disclose they're AI. GDPR + ePrivacy demand lawful basis + consent records per decision. DSA pressure on platforms cascades to adtech vendors. Promethean's per-decision evidence layer is what makes 'every ad shown, every personalized message, every chatbot reply is traceable to the model + prompt + consent state' verifiable rather than asserted.

Updated ·Sector page · AdTech & Marketing Automation·Reading time ~ 6 min

Who this is for

Compliance + product teams in adtech / marketing-automation SMBs (AI ads · personalization · automated outreach · chatbots). Typically:

  • Seed–Series B adtech / martech with 5–80 engineers; 1–6 AI features in production.
  • Customer base: brand advertisers + agencies + DTC e-commerce + content publishers.
  • Decision volume: 1M–100M ad / personalization decisions per month across all customers.
  • Multi-tenant by customer brand; multi-jurisdiction by user.
  • Regulator pressure compounding: ePrivacy + GDPR + DSA + AI Act + national consumer-protection.

The regulatory pressure

EU AI Act Art. 50 — transparency obligations

Chatbots and AI-generated content interacting with humans must disclose AI involvement. Synthetic content (text, image, audio, video) must be marked machine-readably as AI-generated.

GDPR Art. 6 + ePrivacy — lawful basis + cookie consent

Behavioural targeting requires consent under ePrivacy + lawful basis under GDPR. Per-decision evidence linking targeting outputs to consent state required if challenged.

Digital Services Act (DSA) Art. 26 + 39 — ad transparency

Online platforms + VLOPs must disclose ad parameters + repository. Adtech vendors serving DSA-regulated platforms inherit transparency obligations.

GDPR Art. 22 — automated decisions affecting consumers

Personalisation that materially affects pricing, eligibility, or access to services can fall under Art. 22. The Schufa scope extension makes scoring-style personalisation suspect.

Deep-dive →

Where LLMs typically run in AdTech & Marketing Automation

AI ad-copy generation

Drafter producing ad creative variants per campaign. Schema constraint on prohibited terms (medical, financial); reviewer-gate on schema violations; chain shows generation-rate + reviewer engagement.

Audience-targeting classification

Classifier assigning users to behavioural segments. Closed-enum outputs; per-decision consent-state recorded; chain provides evidence for ePrivacy/GDPR audit.

Marketing chatbot

Drafter producing conversational responses. AI Act Art. 50 disclosure built into the spec; reviewer-gate on schema violations + sensitive-topic flags.

Email personalisation engine

Drafter + classifier combination personalising email content per recipient. Schema-bound output; deterministic fallback to safe-default content when model errors.

How the substrate maps to your audit

Your LLM featureWhat the regulator asksPromethean evidence
AI ad copyDSA + national consumer-protection: who saw what AI-generated content?outputCanonicalHash binds the generated ad; chain shows generation history + reviewer engagement.
Audience targetingGDPR + ePrivacy: was consent in place at decision time?inputHash + tenantId capture the decision context; consent-state recorded per decision.
AI chatbot Art. 50 disclosureUser informed they're interacting with AI at start of session.Spec's promptTemplate forces disclosure in the AI's opening; L12 entry shows spec hash.
Personalisation Art. 22 challengeDid personalisation materially affect access to services?Reviewer-gate firings; override-rate aggregates; chain shows decision distribution.
Synthetic-content markingAI Act Art. 50 machine-readable marking of synthetic content.Chain entry records the synthetic-generation event; operator's content-pipeline applies the C2PA / similar marking.

Which Promethean tier fits

Recommended for typical SMBs in AdTech & Marketing Automation

Team€79 / spec / month

Unlimited specs; €79 per active spec per month. 100k entries per spec. Daily OTS anchoring. Single-tenant.

AdTech volume is high but stake-per-decision is low — Team tier (€79/spec/month) often works at smaller SMB scale (100k–1M entries/spec/month). Upgrade to Production (€499/mo flat) when crossing 1M entries total or needing multi-tenant primitives for serving multiple advertiser customers from one workspace.

Larger AdTech & Marketing Automation operators with multi-tenant or framework-template needs upgrade to Production (€499 / month flat).

What this looks like in practice

Hypothetical: a martech SMB during a DPA investigation into adtech consent

A martech SMB serving 200 advertiser customers receives a DPA inquiry following user complaints about untargeted behavioural ads. The DPA asks: 'Provide per-decision evidence linking the targeting output to the consent state of the user; demonstrate that ads were not shown to users who had opted out.' Without Promethean: months of log-archeology + complex reconstruction of consent-state-at-decision-time. With Promethean: chain-export filtered to the affected period; each L12 entry's inputHash carries the consent-state representation; the operator demonstrates per-decision consent-checking with verify.mjs. The investigation concludes the SMB had appropriate controls; no fine issued.

Frequently asked

AdTech volumes can be hundreds of millions of decisions monthly. Does Promethean scale?

Yes, but not for every micro-decision. Enterprise tier carries a 10M entries/month fair-use allowance — that's a billing envelope, not measured peak throughput; production scaling is honest at Production tier today and would warrant onboarding-assist conversation at the 10M end. For micro-decisioning (ad-impression scoring), you'd typically not record every impression — you'd record the rule-application decisions (which audience-segment classifier ran, which targeting policy applied) at a higher granularity. Per-impression bidding doesn't typically need substrate-level audit; per-customer-decisioning does.

AI Act Art. 50 disclosure on chatbots: does Promethean enforce it?

Promethean enforces it via the spec. The promptTemplate in a chatbot spec can require the disclosure in the system prompt; the spec hash binds that requirement to every chat-response L12 entry. If you change the spec to remove the disclosure, the spec hash changes and the chain shows it. A regulator inspecting your chain can see exactly which version of the disclosure language was active across what time window.

DSA transparency for adtech vendors serving VLOPs — what's our exposure?

VLOPs (Very Large Online Platforms) are directly regulated under DSA Art. 26 + Art. 39 for advertising transparency. As a vendor serving VLOPs, you'll be asked for the data your customer needs to publish in their ad-repository. Promethean's chain provides per-decision evidence (which ad-targeting model ran, what targeting criteria applied, who saw the ad in aggregate) that flows into the VLOP's transparency reporting. You're not directly regulated by DSA unless you become a VLOP yourself, but your customers will demand evidence.

GDPR Art. 22 — does personalisation trigger it?

Depends. Pure content recommendation (which articles to show, which products to feature) is typically not legal-effects-bearing; the personalisation is presentation. But personalised pricing, personalised access to services, personalised credit-application gates — those DO trigger Art. 22. Post-Schufa, even scoring-style processing can fall under Art. 22 if it materially influences downstream decisions. Promethean's chain provides the per-decision evidence; your compliance team assesses whether Art. 22 applies per spec.

Most adtech vendors are using GenAI for creative production now. Does that change the regulatory surface?

Yes. AI Act Art. 50 applies — synthetic ad content must be machine-readably marked as AI-generated; users should be able to identify it. The substrate records each generation event with the spec + model identity; pair with your C2PA / similar marking pipeline to satisfy the machine-readability requirement. National consumer-protection authorities are increasingly auditing AI-generated advertising claims (especially in financial + medical sectors); the L12 chain is the audit-trail layer underneath.

Definitions used on this page

The substrate primitives referenced above (L12 receipt chain, spec hash, reviewer gate, fallback behaviour, OpenTimestamps anchor, tenant ID) all have canonical definitions in the glossary:

See full glossary →·See citations index →