EU AI Act for AI providers in e-commerce & retail
Last updated 1 August 2026
This guide maps the EU AI Act (Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus) to the AI systems AI providers actually run in e-commerce & retail: which uses are high-risk, which only carry transparency duties, and what is due by when. It reflects the post-Omnibus dates — the high-risk regime now applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while Article 50 transparency has applied since 2 August 2026.
Are you the provider?
You are a provider if you develop an AI system (or have one developed) and place it on the market or put it into service under your own name or trade mark — including SaaS companies shipping AI features built on third-party models (Article 3(3)).
Providers carry the heaviest obligations: for high-risk systems the full Chapter III regime (risk management, data governance, technical documentation, conformity assessment, CE marking, registration), and for generative systems the Article 50(2) machine-readable marking duty. If your organisation also acts as a deployer, read the companion guide for AI deployers in e-commerce & retail too — many companies are both.
Typical AI uses in e-commerce & retail
- product-description and image generation at catalogue scale
- shopping assistants and support chatbots
- recommendation and dynamic pricing engines
- virtual try-on and AI product photography
High-risk triggers in e-commerce & retail
Typical AI uses in this industry do not fall into the Annex III high-risk categories — the practical workload is the Article 50 transparency tier below. Re-check if you expand into employment screening, credit, education scoring or other Annex III contexts, and remember Article 6(3) edge cases cut both ways.
Transparency duties (Article 50) — since 2 August 2026
- Shopping and support chatbots must disclose they are AI (Article 50(1)).
- Providers of generation features must machine-readably mark synthetic product images and copy (Article 50(2)) — C2PA Content Credentials is the leading standard.
- Realistic AI 'model' photos of people can qualify as deep fakes needing a visible label (Article 50(4)).
Worth knowing
- Recommendation and pricing engines are generally minimal-risk under the AI Act (DSA/consumer law still apply).
Your timeline (post-Digital-Omnibus)
- 2 February 2025 — prohibitions (Article 5) and AI literacy (Article 4) apply. Already in force.
- 2 August 2025 — GPAI model rules (Chapter V) apply.
- 2 August 2026 — general application: Article 50 transparency, governance, penalties. In force.
- 2 December 2026 — Article 50(2) marking grace period ends for systems on the market before 2 August 2026; new Omnibus prohibitions apply.
- 2 December 2027 — high-risk obligations for Annex III systems (moved from 2 August 2026 by the Digital Omnibus).
- 2 August 2028 — high-risk obligations for AI embedded in Annex I regulated products (moved from 2 August 2027).
Penalties
Prohibited practices: up to €35,000,000 or 7% of worldwide annual turnover (Article 99(3)). High-risk and transparency breaches: up to €15,000,000 or 3% (Article 99(4)), whichever is higher. See what you actually risk in practice.
Next step: get your specific list
The fastest way to turn this into your own obligation list is the free 3-minute EU AI Act risk self-assessment — risk tier, obligations with article references, personalised timeline and penalty exposure. If your exposure is chatbots or AI-generated content, the Article 50 checker goes clause by clause.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check