Key Takeaways
- Article 50 transparency obligations have applied since 2 August 2026, and the AI Office and national authorities began enforcing the AI Act that day.
- The Digital Omnibus on AI deferred the high-risk rules, not these: Annex III to 2 December 2027, Annex I embedded systems to 2 August 2028.
- Article 50 sits in the €15 million / 3% tier, not the €35 million / 7% tier Article 99(3) reserves for prohibited practices.
- Article 99(6) gives SMEs the lower of the amount or the percentage, inverting the "whichever is higher" rule.
- Recommendation engines, dynamic pricing and personalisation appear nowhere in Annex III. Hiring screening and credit scoring do.
Introduction
The deadline everyone was counting down to has already passed. On 2 August 2026 the majority of the EU AI Act became applicable, and the Commission's AI Office, with national authorities, began enforcing it. Six days earlier the Digital Omnibus on AI entered into force and moved the high-risk deadlines — which is why guidance written this spring points at the wrong dates, some still telling merchants that high-risk obligations bit on 2 August.
If you sell online into the EU, the question is narrow: what your store does that is regulated today, what becomes regulated in 2027, and what was never in scope.
EU AI Act eCommerce Compliance: What Applies Now, and What Moved
Article 50's transparency duties apply to online stores from 2 August 2026 and are enforceable now. The Digital Omnibus on AI, in force 27 July 2026, deferred only the high-risk regimes: Annex III systems to 2 December 2027, and Annex I embedded systems to 2 August 2028.
| Obligation | Status | Date |
|---|---|---|
| Definitions and AI literacy (Articles 3-4) | Live | 2 February 2025 |
| Prohibited practices (Article 5) | Live | 2 February 2025 |
| Article 50 transparency: chatbots, synthetic content, deep fakes | Live and enforceable | 2 August 2026 |
| Article 50(2) marking, systems on market before 2 Aug 2026 | Grace period | 2 December 2026 |
| High-risk systems listed in Annex III | Deferred by the Omnibus | 2 December 2027 |
| High-risk AI embedded in Annex I products | Deferred by the Omnibus | 2 August 2028 |
Two rows matter now. AI literacy under Article 4 has been due since 2 February 2025, and the Guidelines confirm it reaches here: "Literacy requirements under Article 4 AI Act also apply to both providers and deployers of AI systems within the scope of Article 50 AI Act."
The one piece of Article 50 relief is paragraph-specific. Per the Commission's FAQ, the limited grace period covers "only... AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content", with those providers complying "only as from 2 December 2026". Every other Article 50 duty landed on 2 August.
Our read: a plan that still says "complete high-risk assessment by August 2026" needs re-dating, not rewriting. The Digital Omnibus bought time on the documentation-heavy part of the AI Act, and none on the part a customer meets in your chat widget.
Which of Your Store's AI Systems Are Actually High-Risk?
Almost none of them. Annex III does not list product recommendation engines, retail dynamic pricing or marketing personalisation. The realistic high-risk exposures for a retailer are staff hiring screening under Annex III point 4 and in-house consumer-credit or BNPL scoring under point 5(b) — both deferred to 2 December 2027.
| Store system | Where it lands | What you owe |
|---|---|---|
| Support chatbot or shopping assistant | Article 50(1) | Say it is AI at first interaction — now |
| AI imagery that alters the product | Deep fake, Article 50(4) | Disclose the manipulation — now |
| AI-written product descriptions | Outside Article 50(4) | No visible label; marking sits upstream |
| Recommendations, pricing, personalisation | Not in Annex III | No high-risk duties; GDPR still applies |
| Order fraud detection | Excluded from Annex III 5(b) | Not high-risk |
| CV screening for hiring | Annex III point 4 | High-risk from 2 December 2027 |
| In-house credit or BNPL scoring | Annex III point 5(b) | High-risk from 2 December 2027 |
The tiers are independent — a system "can also fall within the scope of Article 50" without being high-risk.
On imagery, routine work is generally fine: "colour correction, background extensions... replacements of backgrounds for clearly aesthetic purposes" in product ads "is likely to have only a minor impact" on perceived authenticity — the Guidelines treat this as context-dependent, not a blanket clearance. The line is crossed by an image that can "mislead as to the actual product appearance". Make the studio prettier, not the product different.
AI Product Descriptions: No Visible Label, but a Marking Duty Upstream
AI-generated product copy does not need a visible "AI-generated" label. The Guidelines place "AI-manipulated text that is part of a company's advertisement or product descriptions (not including any claims related to e.g. health, consumer safety or sustainability)" outside Article 50(4), because it is not published to inform the public on matters of public interest.
That parenthetical is load-bearing: health, consumer-safety and sustainability claims are carved back in, and the Guidelines' matters of public interest expressly include consumer safety. AI-drafted copy about a supplement's effects or a child car seat's protection does not sit inside the example.
The other half gets conflated with this one. Article 50(2) requires providers of systems generating synthetic text to ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated" — a duty belonging to the provider of the generative tool, not to you. Both hold at once. Ask each vendor in writing how it satisfies Article 50(2). These Guidelines, adopted 20 July 2026, are Commission practical guidance, not binding law.
What Are the Penalties for an Online Store?
Article 50 breaches carry administrative fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. The €35 million / 7% headline does not apply: Article 99(3) reserves that tier for the prohibited practices in Article 5.
| Breach | Ceiling | Basis |
|---|---|---|
| Prohibited AI practices | €35m or 7% of turnover, whichever is higher | Article 99(3) |
| Article 50 transparency failures | €15m or 3%, whichever is higher | Article 99(4)(g) |
| Misleading information to authorities | €7.5m or 1%, whichever is higher | Article 99(5) |
| Any of the above, offender is an SME | Whichever is lower | Article 99(6) |
That last row is the one nobody quotes, and for a small merchant it changes the risk entirely. Article 99(6) provides that for SMEs, including start-ups, each fine "shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower". For a store turning over €4 million, 3% is €120,000 — that figure, not €15 million, describes its exposure. Quote €35 million at a 12-person merchant and the obligation gets filed as somebody else's problem.
Provider or Deployer: Which One Is Your Store?
Buy your chatbot or copy generator from someone else and you are its deployer, not its provider. Article 50(1) and 50(2) bind providers; Article 50(4) binds deployers. The Guidelines define a deployer's authority as "assuming responsibility over the decision to deploy the system and over the manner of the actual use".
Technical control is not the test. Deployer status "does not necessarily require technical control over the operation of the AI system, so long as the deployer takes the decision for what purposes and how to use the AI system". Having no engineers is not a defence.
Modifying a bought-in system makes you its provider. A company that takes an existing generative system and "modifies that system (e.g. with new training data), which it afterwards puts into service under its own name or trade market [sic]... becomes a provider of the new system". Fine-tuning a model on your catalogue is that pattern.
Being outside the EU does not put you outside the Regulation. Providers "established or located outside the Union are also subject to the AI Act if the output of their AI system is used in the Union", limited only by the rule that incidental or unauthorised downstream use does not alone trigger those obligations. Deliberately shipping to Germany is not incidental. Relief runs the other way too: merely commissioning an agency to make an ad, without controlling whether it uses AI, does not make you a deployer.
A Six-Step Pass Through Your Store
- Inventory every AI touchpoint a customer can reach — chat widget, on-site search, copy generation, imagery, review summaries. Our AI governance primer covers the register format.
- Mark each system provider or deployer. Bought as-is means deployer; fine-tuned or rebranded means provider.
- Fix the chatbot disclosure first — the one Article 50 obligation anyone can check from outside your business in ten seconds. Our Article 50 disclosure guide covers the wording.
- Put the Article 50(2) question to every generative vendor in writing and file the answer.
- Diary your two real Annex III exposures — hiring screening, and in-house credit or BNPL scoring — for 2 December 2027.
- Record your Article 4 AI literacy measures. Due since 2 February 2025; a dated training record is cheap evidence.
Common Mistakes That Fail an Article 50 Check
The Guidelines are unusually direct here. Each of these is listed as insufficient on its own:
- Disclosure buried in terms and conditions or documentation — these "may complement, though not replace, in-context disclosure".
- Machine-readable markings such as metadata or watermarks "that are not perceivable by users at the point of interaction".
- Ambiguous signals, including "generic references to 'assistant'" or human-like representations that may mislead.
- Site-wide catch-alls. A statement like "Services on this website use AI" is named as insufficient.
- Technical descriptions such as "this system uses LLMs" — naming the technology, not the artificial origin.
Endorsed instead: "Prominent, plain-language labels or banners (e.g. 'You are interacting with an AI system')" and first-turn greetings, positioned "close to the interaction interface"; for voice, a spoken statement at the start. Article 50(5) fixes the timing — clear and distinguishable, "at the latest at the time of the first interaction", and accessible.
The second mistake is a decision, not an oversight: concluding your chatbot is so obviously a bot that Article 50(1) falls away. The Guidelines read that exception restrictively — it "should be limited to cases where there is almost no doubt left about the nature of the interaction for an average person", and general awareness that AI systems exist "does not imply that they recognise them in interactions". Where the system is reachable by the general public including vulnerable users, "the exception cannot be relied upon". The Commission's own examples of obviousness are developer tools and internal staff assistants. A storefront is neither.
How Enforcement Actually Works Right Now
No enforcement action, fine or investigation exists under Article 50 — the obligation became applicable on 2 August 2026. The honest framing is exposure, not precedent.
Enforcement runs through the Member States; the Commission's FAQ says compliance "will mainly be enforced by national competent market surveillance authorities". That machinery is uneven: the artificialintelligenceact.eu tracker, in its 17 June 2026 update, recorded 9 of 27 Member States as having fully designated their authorities, 12 partially and 6 not at all — against a 2 August 2025 deadline.
The voluntary Code of Practice on Transparency of AI-generated Content, published 10 June 2026, had over 180 signatories by 31 July 2026 — but the Commission is explicit that "the transparency requirements under article 50 of the AI Act are legal obligations".
How PrivacyForge Helps
Most of this work is inventory and evidence. PrivacyForge's AI governance module holds a register of the AI systems touching your store, records the provider-versus-deployer classification for each, and keeps vendor answers to the Article 50(2) marking question with your processor records — so the call you made in August is still retrievable, with its date, when someone asks in 2027.
Because AI transparency and data-protection duties land on the same systems, that register sits beside your GDPR compliance records and data map, not in its own spreadsheet. Our free EU AI Act deadline and risk classifier triages a system in minutes.
Frequently Asked Questions
Does the EU AI Act apply to my online store if I am based outside the EU?
It can. The Commission's Guidelines state that providers "established or located outside the Union are also subject to the AI Act if the output of their AI system is used in the Union". Incidental or unauthorised downstream use does not alone trigger those obligations — but deliberately shipping to EU customers is not incidental.
Do AI-generated product descriptions need a visible AI label?
Generally no. The Commission's Guidelines place "AI-manipulated text that is part of a company's advertisement or product descriptions (not including any claims related to e.g. health, consumer safety or sustainability)" outside Article 50(4). The parenthetical matters: health, consumer-safety and sustainability claims are carved back in. Article 50(2) separately makes the tool's provider mark outputs machine-readably.
Is my product recommendation engine high-risk under the EU AI Act?
No. Product recommendation systems appear nowhere in Annex III, the list of stand-alone high-risk uses, and neither do retail dynamic pricing or marketing personalisation. A retailer's realistic high-risk exposures are hiring and candidate screening under Annex III point 4 and creditworthiness scoring under point 5(b), both now applying from 2 December 2027.
Do I have to tell customers they are chatting with an AI?
Yes, since 2 August 2026. Article 50(1) requires people interacting directly with an AI system to be informed of that fact, unless it is obvious to a reasonably well-informed, observant and circumspect person. Article 50(5) requires the information to be clear and distinguishable, at the latest at first interaction.
What are the EU AI Act penalties for a small online store?
Article 50 breaches fall under Article 99(4): up to €15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups, Article 99(6) applies the lower of the two instead — so a store turning over €4 million faces a €120,000 ceiling. The €35 million / 7% tier covers only Article 5 prohibited practices.
What is the difference between a provider and a deployer under Article 50?
Providers place AI systems on the market and carry Article 50(1) and 50(2); deployers decide to use them and carry Article 50(4). The Guidelines define a deployer's authority as "assuming responsibility over the decision to deploy... and over the manner of the actual use". Modifying a bought-in system and releasing it under your own name makes you a provider.
Conclusion
The AI Act stopped being a countdown on 2 August 2026. For an online store the live obligations are narrow and cheap: say so when a shopper is talking to a bot, know which vendor owes machine-readable marking, keep a dated record of both. Annex III high-risk, the expensive part, moved to 2 December 2027 — a reprieve only if you use it. Start with the chat widget.
This is informational content, not legal advice; for your own systems, consult a qualified adviser. To see where your store stands, start a PrivacyForge trial and build the register.
Sources
- European Commission — Transparency obligations under Article 50 AI Act (FAQ)
- European Commission — Commission starts enforcing AI Act rules and new transparency requirements (31 July 2026)
- European Commission — Guidelines on transparency obligations for providers and deployers of AI systems, C(2026) 5054 final, 20 July 2026
- European Commission AI Act Service Desk — Timeline for the implementation of the EU AI Act
- European Commission AI Act Service Desk — Article 113 (entry into application)
- European Commission — Code of Practice on Transparency of AI-generated Content
- AI Act Explorer — Article 50 (transparency obligations)
- AI Act Explorer — Article 99 (penalties)
- AI Act Explorer — Annex III (high-risk AI systems)
- AI Act Explorer — National implementation plans tracker (updated 17 June 2026)