E-Law

AI Regulation: These requirements have been in effect for online retailers since August 2, 2026

Aug 27, 2026·Author: Stephan Dunger

As of August 2, 2026, the transparency requirements of the AI Regulation (Art. 50 AI Reg.) apply: Chatbots must identify themselves as AI, and AI-generated or manipulated content must be disclosed—this also applies to online stores with AI customer service, AI-generated product images, or AI-generated text. The often-feared high-risk obligations, on the other hand, were postponed shortly before the deadline to the end of 2027 and 2028. This article clarifies what really applies to online retailers now—and what does not.

At a Glance: The Deadlines for the AI Regulation

  • February 2, 2025: Prohibitions on certain AI practices and the requirement for employees to have AI competence (Art. 4)—already in effect.
  • August 2, 2025: Obligations for providers of large AI foundation models (GPAI)—already in effect.
  • August 2, 2026: Transparency obligations under Art. 50 – chatbots and AI content . Effective for just under four weeks.
  • December 2, 2027: High-risk obligations under Annex III – postponed by the “Digital Omnibus.”
  • August 2, 2028: High-risk AI in regulated products (Annex I).
  • Fines: Violations of Article 50 can result in fines of up to €15 million or 3% of global annual revenue.

What AI Act obligations have applied to online stores since August 2, 2026?

Since August 2, 2026, the transparency obligations under Article 50 of the AI Regulation (Regulation (EU) 2024/1689) have been in effect—these are the provisions of the AI Act that online retailers must now specifically implement. There are two distinct sets of obligations: First, interaction transparency: Anyone using an AI system that communicates directly with people—typically a customer service chatbot—must ensure that users can recognize that they are speaking with an AI. Second, content transparency: AI-generated or AI-manipulated image, audio, and video content that deceptively resembles real people, places, or events must be disclosed as artificially generated. Prohibitions on certain practices, the requirement to train employees in the use of AI (effective February 2, 2025), and the obligations for providers of large AI models (effective August 2, 2025) have been in effect for some time.

Do I have to label my chatbot as AI?

Yes. If your online store uses an AI chatbot for customer service, visitors must be able to recognize that they are interacting with an AI—unless this is already obvious to a reasonable user given the circumstances. In practice, however, no one should rely on this exception: A clear notice in the chat window (“You are chatting with our AI assistant”) costs nothing and eliminates any risk of misinterpretation. The handoff point is also important: If the conversation shifts from the bot to a human employee, this should also be recognizable to the customer. The notice must be included in the interaction itself—a hidden paragraph in the privacy policy is not sufficient.

Do AI-generated product descriptions and AI-generated images need to be labeled?

It depends. The labeling requirement under Article 50 applies to content that feigns authenticity: photorealistic AI images that replicate real people, places, or events (the “deepfake” rule), as well as AI-generated texts that inform the public about matters of public interest. Ordinary AI-generated product descriptions and translations generally do not fall under this category—the editorial responsibility for the accuracy of the content remains with the retailer in any case. The situation may be different for photorealistic AI renderings, such as AI-generated “models” or application scenarios that look like real photos. Incidentally, the obligation to provide machine-readable labeling (e.g., watermarks) applies to the provider of the AI tool, not the online store using it—but it’s still worth checking.

Typical AI Applications in an Online StoreClassification effective August 2, 2026
AI chatbot in customer serviceTransparency required: Users must be able to recognize the AI as such.
Photorealistic AI images (AI models, scenes)Subject to disclosure if they deceptively replicate real people, places, or events.
AI product descriptions and translationsGenerally no labeling requirement—responsibility for content remains with the retailer.
Recommendation engine, personalizationNot a high-risk system; no Article 50 obligation applies; the general AI competence requirement applies.
AI in applicant tracking systemsHigh-risk according to Annex III—obligations do not take effect until December 2, 2027.

When do the high-risk rules apply—and what has the “Digital Omnibus” postponed?

The high-risk obligations will take effect later than originally planned: The EU’s “Digital Omnibus,” formally adopted at the end of June 2026, postpones the obligations for high-risk systems under Annex III (such as AI in personnel selection or creditworthiness assessments) to December 2, 2027, and for AI in regulated products under Annex I to August 2, 2028. This clears up a common misconception: The high-risk rules did not take effect on August 2, 2026. However, the transparency requirements of Article 50 remain unaffected—they have been in effect since the effective date. For most e-commerce applications, this is good news: Chatbots, product descriptions, image generators, and recommendation systems are typically not considered high-risk—but they may still be subject to transparency requirements.

What fines are imposed for violations?

Violations of the transparency obligations under Article 50 can be penalized with fines of up to €15 million or 3% of the global annual revenue from the preceding fiscal year—whichever amount is higher. In addition, there is a risk under competition law: Anyone who passes off AI-generated content as supposedly real photos or a bot as a human advisor may also face allegations of misleading consumers. Realistically speaking, regulatory authorities will initially focus on issuing warnings and requiring corrective action for smaller merchants—but you shouldn’t count on this leniency.

What should online store operators do now?

The effort involved is manageable if you take a systematic approach:

  • AI inventory: List all AI applications in the store—chatbots, text generation, image tools, translation, and AI functions provided by service providers.
  • Label chatbots: Include a visible notice in the chat window and ensure a clear transition when a human takes over.
  • Review image library: Identify and disclose photorealistic AI images or replace them with real photos.
  • Document AI proficiency: Provide verifiable proof of employee training in AI use (mandatory as of February 2, 2025).
  • Inquire with providers: Obtain confirmation that the generators used mark their output in a machine-readable format.

As a shop system manufacturer based in Chemnitz, XONIC Solutions has been supporting legal compliance in e-commerce since 2005—from button solutions to cookie consent; the XONIC Shop System is developed according to the “Privacy by Design” principle. We’ve already summarized what’s important for a GDPR-compliant e-commerce platform —and the Sistrix AI Check shows how visible your store is in AI responses.

Note: This article does not constitute legal advice. Binding information regarding the classification of your specific AI applications can be obtained from specialized law firms.

Frequently Asked Questions About the AI Regulation in E-commerce

Yes. The transparency requirements under Article 50 do not have any revenue or size thresholds—anyone who operates an AI chatbot or publishes AI-generated content that is deceptively realistic must label it as such. Exemptions for small and medium-sized enterprises are primarily available in high-risk areas, which do not apply to most online stores anyway.

No. The disclosure must appear where users encounter the AI—for a chatbot, this means in the chat window no later than the start of the interaction; for content, it must appear on the content itself. A general paragraph in the privacy policy or terms of service does not fulfill this obligation.

As of February 2, 2025, companies that use AI systems must ensure that their employees have sufficient AI competence—appropriate to their role and the intended use. For an online store, this means in practice: brief, documented training for everyone who works with chatbots, text generation, or image tools.

No, typically not. Product recommendations and personalization in an online store do not fall under the high-risk use cases listed in Annex III (such as personnel selection, credit granting, or critical infrastructure). The general obligations still apply—in particular, ensuring employees have AI competence.

Sources

Stephan Dunger
About the author

Stephan Dunger

Lead developer & store system expert · XONIC Solutions GmbH · With the company since 2012

Stephan Dunger is one of the brains behind the XONIC store system. He has been developing the platform together with the team since 2012 - from the database to the interfaces to the checkout.

A passionate programmer, technical mind and consultant at the same time: with his in-depth knowledge of store systems and e-commerce, Stephan combines the depth of a developer with an eye for the big picture. Together with the XONIC team, he shapes the technical direction, consistently thinks about functions from the retailer's perspective and advises on customized solutions.

The result is software with a face: customers don't get an anonymous provider, but a direct line to the people who develop XONIC. Pragmatic, fast and at eye level.

Customer testimonials

write review
Never miss a thing.

Legal updates and new features straight to your inbox.

Subscribe to the newsletter