EU AI Act for e-commerce: you’re the deployer, not the bystander
You may have heard the EU AI Act deadline moved. It did – for one part. But the piece that matters most for EU AI Act e-commerce compliance went live on 2 August 2026, and enforcement started with it.
The confusion is understandable. Late in 2025 the Commission put forward a simplification package – the “AI Omnibus” – and it genuinely pushed things back. The obligations for high-risk systems in sensitive areas now apply from December 2027. Systems baked into physical products get until August 2028. So if you read a headline about the AI Act being delayed, you read something true.
You just read the wrong half. The transparency rules didn’t move. They apply now, and the Commission’s AI Office began enforcing them on 2 August.
For most online stores that’s not the problem it sounds like. The obligations are small and cheap. The trap is a different one, and it’s structural: the AI Act puts the duty on the people running the system, not the people who built it. Which means the question “who handles compliance here” has an answer you might not like.
Provider or deployer
The Act draws a line between two roles. A provider develops an AI system or has one developed and puts it on the market under its own name. A deployer uses that system under its own authority. Different roles, different duties.
The instinct in a technical team is to file AI regulation under someone else’s problem – a thing for the companies training the large models. That instinct is backwards. If you stand up a support chatbot on top of somebody else’s model, you didn’t build the model, but you are running the system. The transparency obligations for that interaction are yours. The vendor’s terms of service don’t transfer them, because the law didn’t assign them to the vendor in the first place.
This isn’t a loophole anyone forgot to close. It’s the design. The person who decides to point an AI system at customers is the person best placed to tell those customers what’s going on. So that’s where the duty sits.
Once you see it that way, the rest of the Act gets easier to read. You stop asking “is this AI regulated” and start asking “what am I deploying, and what does deploying it oblige me to say.”

Most of your AI is fine under the EU AI Act e-commerce rules
Here’s the part the checklists bury under eight steps of dread: the majority of AI in a normal online store carries minimal obligations or none.
- Your recommendation engine – the “you might also like” block – is minimal risk. Effectively unregulated. The same goes for most of the quiet machine learning humming under a storefront: search ranking, fraud scoring on your own transactions, inventory forecasting. The Act was written to leave low-risk systems alone, and it does.
- Chatbots and other interactive AI sit one notch up, in what the Act treats as a transparency risk. The obligation is disclosure, and only disclosure: the user has to know they’re talking to a machine rather than a person. That’s the whole requirement. Not an audit, not a filing – a clear signal that there’s software on the other end.
- Dynamic pricing is fine when it does the ordinary thing. Adjusting to demand, stock levels, or competitor moves is standard commerce and the Act leaves it be. There’s a hard edge, though: pricing or personalisation that sets out to exploit someone’s vulnerability – age, disability, financial desperation – is a prohibited practice, not merely a risky one. That prohibition has been in force since February 2025. Ordinary revenue optimisation is nowhere near that line. Deliberately targeting the vulnerable crosses it.
- AI-generated content is the one that catches people who weren’t thinking about it. If you generate product descriptions or imagery with a model, that content has to be marked as AI-generated in a machine-readable way. There’s some breathing room, but narrower than people assume: the rules apply from 2 August 2026 to in-scope systems regardless of when you deployed them – the only transitional relief is for the marking-and-detection duty specifically, where providers of generative systems already on the market have until 2 December 2026. You also don’t have to go back and relabel content you generated before the deadline. But new generative output going forward needs the marking.

What Article 50 actually asks of you
Strip the transparency rules down and there are four situations that trigger a duty: direct interaction with a person, AI-generated content, emotion recognition or biometric categorisation, and deepfakes or AI-written text published to inform the public on matters of public interest.
For a typical e-shop, two of those four ever come up. You’re running something interactive, so you disclose it. You’re generating content, so you mark it. Label the bot, mark the output – for most sellers, that is the whole of EU AI Act e-commerce compliance. The Commission published detailed guidance on exactly this in July 2026, so the specifics aren’t a matter of guesswork.
For the record, non-compliance with these transparency obligations can draw fines of up to EUR 15 million or 3% of worldwide annual turnover, with proportionality taken into account for smaller companies. I mention it once and move on, because leading with the fine is how you end up doing compliance out of fear instead of understanding – and fear tends to buy the wrong things.
The three that actually bite – and where they hide
If the transparency duties are the easy part, here’s the part worth real attention. A few e-commerce uses of AI land in the high-risk or prohibited tiers, and they tend to hide in tools you bought rather than built.
Buy-now-pay-later and credit checks are the big one. Any AI that decides who gets access to credit is high-risk under the Act – it’s the same category as loan-approval scoring, and it’s there because a wrong answer materially affects someone’s life. The catch for retailers is that this capability usually arrives inside a platform or a plugin. You didn’t build a credit model; you switched on a feature. But switching it on makes you its deployer.
Emotion and sentiment recognition is the second. The rules here depend on where you point it. Used on employees or in education, emotion recognition is prohibited outright. Used elsewhere – a retail context, say – it’s high-risk rather than banned, but high-risk still means real obligations, and it’s rarely worth the trouble for the marginal insight it returns.
Manipulative or exploitative systems are the third, and as above, these aren’t regulated – they’re prohibited. If a tool is designed to deceive users into decisions they wouldn’t otherwise make, or to exploit a vulnerability, it’s on the wrong side of a line that’s already been enforceable for over a year.
The common thread is procurement. On takeover and audit work we sometimes find bought-in AI that a client treats as the vendor’s compliance problem – a scoring widget, a personalisation engine, a plugin someone enabled two years ago and forgot. The vendor built it. But under the Act the client deploys it, and the duty follows the deployment, not the build. That’s not a reason to panic. It’s a reason to know what’s switched on.
What to actually do
None of this is a legal programme. For most stores, getting straight with the EU AI Act e-commerce obligations is an afternoon and a list.
Inventory the AI that touches your customers – not every model in the stack, just the ones users encounter or that make decisions about them. Disclose the interactive ones. Mark the generated content. Then take the handful of things that might be high-risk or prohibited – anything doing credit decisions, anything reading emotion, anything shaping prices in ways you’d be uncomfortable explaining out loud – and give those a real look rather than a hopeful shrug.
The cost of skipping this isn’t the fine on day one. Enforcement won’t arrive at a small storefront on a Tuesday morning. The cost is quieter: nobody owns the question, so the answer defaults to “the vendor probably handles it,” and that answer is wrong in exactly the cases that matter most.
If you’re mid-build or mid-takeover and want a second pair of eyes on which of your AI touches the customer – and which tier each piece lands in – that’s a conversation we have anyway. Worth having before it’s the regulator asking.
Let’s Talk