Artificial intelligence has quietly become part of everyday work in e-commerce. Product descriptions that once took an afternoon to write can now be drafted in seconds. Product photography that would have required a studio, a model, and a budget can be generated instead. While AI is widely beneficial and accommodating, that convenience comes with a catch and it does have the potential to impose many new risks. These systems produce text and images that look polished and authoritative whether or not the underlying information is correct. It is familiar to anyone who has read AI output closely. Left unchecked, small inaccuracies of this kind turn into returns, complaints, and disputes.

With AI’s rapid growth and unconventional application, the European Union has introduced a new initiative that has been in the works since 2021, the EU AI Act (Regulation (EU) 2024/1689). The rules that matter most to online retailers took effect just days ago. This initiative’s main aim is to contribute to safe and sustainable use of AI. The Act provides a legal framework through risk-based rules for providers (the technology vendors creating the technologies and services), deployers (the ones using these technologies and services, which includes a business generating texts for its webshop), importers (Union-established entity placing an AI system on the market from a third-country provider) and distributors (any person in the supply chain (other than provider/importer) making a system available on the Union market) to be enforced by proper authorities, at EU and national levels.

On 2 August 2026, the EU AI Act became broadly applicable and enforceable, overseen by the European Commission's AI Office alongside national authorities. Among the provisions now live is Article 50, which sets out when AI use has to be disclosed, covering deepfakes, chatbots, and content generated by AI. It lays out transparency requirements for both the companies that build these systems and the businesses that use them. The Act itself has been arriving in stages. The AI Act first came into force in August 2024. From August 2025, the rules on General-purpose AI (GPAI) models became effective. Additionally, the Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and pushed the deadline for most high-risk AI systems back to 2 December 2027.

Why is it relevant for ecommerce?

The EU AI Act is relevant as it's the first serious attempt to translate the worries about AI, which include bias and discrimination, manipulation of individual behavior, mass surveillance through biometric tracking, and many more into a binding, enforceable law rather than voluntary ethical principles companies can ignore.

The Act is very much relevant for online retailers. Most shops fall into the transparency section, which means being clear with users when they are speaking to a chatbot rather than a person, and ensuring AI-generated content is properly marked.

Who the roles apply to?

One note on the table above: these roles are not permanently fixed. If you put your own name or trademark on a vendor's AI tool, modify it substantially, or use it for a purpose it wasn't designed for, you may cross from deployer into provider.

What does it include?

The EU AI Act is the first, big-scale, comprehensive law for artificial intelligence. It is a risk-based system, which categorises AI uses into different hazard levels; from unacceptable risk, high risk, limited risk (transparency) to minimal risk and no risk.

Systems used in areas with serious consequences for people's lives and health, such as hiring, credit scoring, and law enforcement, are classed as high risk and must meet strict conditions covering documentation, human oversight, and testing for bias. Systems that pose a lower risk, including chatbots and deepfakes, are subject to transparency rules instead: people have to be told what they are dealing with. The intention behind it is to protect the safety and fundamental rights of people in the EU. It also provides legal certainty and strengthens the governance. Additionally, requirements create scrutiny for the general-purpose AI models (like GPT or Claude).

This can be seen in a recent development from Anthropic, provider of Claude, which has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. The company has committed to carrying machine-readable marking in Claude models launched in the EU from August 2026 onwards. Older models fall in the transition period. The generated text will include watermarks and generated files will contain signed provenance metadata.

Main risk categories

(with examples) → different rules for different levels of risk.

  • Unacceptable risk (threat to safety, banned outright): includes manipulative/deceptive AI, social scoring, certain biometric categorization.
  • High-risk (serious hazard to health, safety and rights): mainly HR and hiring AI, credit scoring, some biometric identification. These obligations now apply from 2 December 2027.
  • Limited risk (transparency risk): obligations toward clear and transparent use of AI; making sure that AI content is labelled as such, as well as people using AI chatbots should be aware that they are conversing with artificial intelligence.
  • Minimal risk: spam filters, basic recommendation engines, most current personalization

E-commerce under the AI Act

The majority of AI technologies used in ecommerce, such as chatbots, product suggestion engines, AI-written product descriptions, and generated lifestyle images, are classified as low-risk or minimal-risk rather than high-risk. Therefore, the Act does not require a compliance department or evaluations of compliance for the great majority of shops.

What is this practically for your shop? What to do now?

  • Chatbots and customer service AI: customers need to know when they're talking to a machine rather than a person. Article 50(1) requires providers to design these systems so the disclosure happens by default. Deployers need to make sure that this part of the chat tool remains intact so that the customers are made aware.
  • AI-generated content: product visuals, videos, or copy generated or materially altered by AI need to carry machine-readable marking so the content is detectable as AI-made. This doesn't require a visible watermark on the image itself, just marking that survives in the file. However, the obligation sits with the company that built the tool, so it is not your job. Ordinary retouching (background removal, cropping, colour correction) isn't caught by this.
  • Recommendation engines: these stay in the low-risk category, and ordinary personalisation stays there. Showing someone products based on what they browsed, or flagging that stock is genuinely running low, is normal commerce and the Act does not imply heavy regulation. For it to fit into the prohibited category, they would need to cross into manipulating purchasing decisions by exploiting a customer's emotional state or financial vulnerability.
  • Buy-now-pay-later and credit scoring: if your checkout uses a third-party tool that decides whether a customer qualifies for credit, that tool is treated differently under the law. It can count as "high-risk," which comes with much stricter rules and requirements around documentation, testing and human oversight. Those requirements were moved to 2 December 2027.

Additionally, a very practical aspect of the EU AI Act is the obligation of deployers and providers to support AI literacy among the staff and those who deal with the operation and usage of AI systems on their behalf. In general, the providers or deployers are not required to guarantee that people have a certain degree of AI literacy. It focuses on ensuring that people implement AI systems in an informed manner and are made aware of the potential dangers, opportunities, and negative effects of AI.

What this act does not cover

Article 50 is about disclosure and meeting the regulation requirements, not accuracy. It asks you, as a business, to tell people they're dealing with AI and to make generated content detectable. And yet, it has nothing to say about whether that content is correct. Unless the AI usage concerns a high-risk category (biometrics, employment and worker management, etc.), the Act does not mandate that the generated content has to be factual or truthful.

This matters more than it sounds. If your AI describes a product on your website as something different than it actually is, you have met the AI Act's requirements but are still in violation. Under EU law, primarily through the Unfair Commercial Practices Directive (2005/29/EC), webshops are strictly prohibited from deceiving shoppers with false or hidden information regarding prices, product features, discounts, and customer reviews. The same goes for AI-written review summaries or automated size guidance. A label saying content was AI-generated doesn't move responsibility for it away from you. This is the part that's easy to miss when a new regulation is implemented. The AI Act supplements the running consumer law that has been in place for years. It adds obligations, it doesn't replace anything.

Should I comply with this law?

The implementation, oversight, and enforcement of the AI Act falls under the control of the AI Office and Member State authorities as of August 2, 2026. GPAI models are subject to enforcement by the AI Office. It has the authority to demand technical documents, assess models, mandate corrective actions, and impose penalties for noncompliance.

If your e-commerce business uses an AI system under its own authority as part of running the business, you are legally classified as a "deployer". That covers the customer service chatbot, the virtual try-on tool, the personalisation engine, and it applies whether you bought the tool or built it. If you built it, you are a provider as well as a deployer, and the provider obligations are the heavier of the two.

  • Established in the EU → the Act applies to you directly. Your size doesn't change this. There's no small-business exemption from the transparency rules.
  • Established outside of the EU → The Act reaches providers and deployers in third countries where the output produced by the AI system is used in the Union.

Common misconceptions

  • We're too small for this to apply → small businesses are not exempt from the transparency rules. Size affects how much work compliance is, not whether it applies.
  • We don't build AI, we just use tools someone else made → That is what makes you a deployer. The test is whether you use an AI system under your own authority in the course of a professional activity, not whether you built it.
  • High-risk deadline moved, so not much applies yet → only the high-risk obligations have been moved. The transparency rules in Article 50, which are the ones which are most relevant for ecommerce, have applied since August 2nd 2026.

Practical takeaway: For online shops, the one date that matters most is August 2, 2026. Most e-commerce AI, chatbots, generated product copy, AI images, fall under transparency rules (Article 50), and on whom the rules are already applicable.

Quick checklist

  • List every AI tool currently in use, and note who built each one
  • Flag any customer-facing AI (chatbots, generated content) for disclosure
  • Check whether any tool runs under your own brand rather than the vendor's
  • Ask vendors one specific question: do their generative tools apply machine-readable marking to output, and if not yet, by what date
  • Add AI disclosure to the chat window itself, not the terms page
  • Brief the people who operate these tools, and keep a note that you did
  • Put a recurring reminder (quarterly) to re-check as you add new tools

Note on this article

Thanks to Charlotte Meindersma for answering my questions about the Act in practice. Any errors that might occur in the text are mine.

This piece is intended as a general introduction and is not giving any legal advice. While this article was carefully and extensively researched, it may contain inaccuracies and the interpretations might change. If a point matters to your business, check it against the original text of Regulation (EU) 2024/1689, available on EUR-Lex, and consult a qualified lawyer.

For this article, AI was used for redaction, editing and research. AI was used to help locate and verify sources for this article. All information was checked against the official EUR-Lex text.

Sources:

http://data.europa.eu/eli/reg/2024/1689/oj

http://data.europa.eu/eli/reg/2026/1744/oj

http://data.europa.eu/eli/reg/2024/1689/2026-07-27

https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence

https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_en