As of August 2, 2026, the transparency requirements of the AI Regulation (Art. 50 AI Reg.) apply: Chatbots must identify themselves as AI, and AI-generated or manipulated content must be disclosed—this also applies to online stores with AI customer service, AI-generated product images, or AI-generated text. The often-feared high-risk obligations, on the other hand, were postponed shortly before the deadline to the end of 2027 and 2028. This article clarifies what really applies to online retailers now—and what does not.
At a Glance: The Deadlines for the AI Regulation
- February 2, 2025: Prohibitions on certain AI practices and the requirement for employees to have AI competence (Art. 4)—already in effect.
- August 2, 2025: Obligations for providers of large AI foundation models (GPAI)—already in effect.
- August 2, 2026: Transparency obligations under Art. 50 – chatbots and AI content . Effective for just under four weeks.
- December 2, 2027: High-risk obligations under Annex III – postponed by the “Digital Omnibus.”
- August 2, 2028: High-risk AI in regulated products (Annex I).
- Fines: Violations of Article 50 can result in fines of up to €15 million or 3% of global annual revenue.
What AI Act obligations have applied to online stores since August 2, 2026?
Since August 2, 2026, the transparency obligations under Article 50 of the AI Regulation (Regulation (EU) 2024/1689) have been in effect—these are the provisions of the AI Act that online retailers must now specifically implement. There are two distinct sets of obligations: First, interaction transparency: Anyone using an AI system that communicates directly with people—typically a customer service chatbot—must ensure that users can recognize that they are speaking with an AI. Second, content transparency: AI-generated or AI-manipulated image, audio, and video content that deceptively resembles real people, places, or events must be disclosed as artificially generated. Prohibitions on certain practices, the requirement to train employees in the use of AI (effective February 2, 2025), and the obligations for providers of large AI models (effective August 2, 2025) have been in effect for some time.
Do I have to label my chatbot as AI?
Yes. If your online store uses an AI chatbot for customer service, visitors must be able to recognize that they are interacting with an AI—unless this is already obvious to a reasonable user given the circumstances. In practice, however, no one should rely on this exception: A clear notice in the chat window (“You are chatting with our AI assistant”) costs nothing and eliminates any risk of misinterpretation. The handoff point is also important: If the conversation shifts from the bot to a human employee, this should also be recognizable to the customer. The notice must be included in the interaction itself—a hidden paragraph in the privacy policy is not sufficient.
Do AI-generated product descriptions and AI-generated images need to be labeled?
It depends. The labeling requirement under Article 50 applies to content that feigns authenticity: photorealistic AI images that replicate real people, places, or events (the “deepfake” rule), as well as AI-generated texts that inform the public about matters of public interest. Ordinary AI-generated product descriptions and translations generally do not fall under this category—the editorial responsibility for the accuracy of the content remains with the retailer in any case. The situation may be different for photorealistic AI renderings, such as AI-generated “models” or application scenarios that look like real photos. Incidentally, the obligation to provide machine-readable labeling (e.g., watermarks) applies to the provider of the AI tool, not the online store using it—but it’s still worth checking.
| Typical AI Applications in an Online Store | Classification effective August 2, 2026 |
|---|---|
| AI chatbot in customer service | Transparency required: Users must be able to recognize the AI as such. |
| Photorealistic AI images (AI models, scenes) | Subject to disclosure if they deceptively replicate real people, places, or events. |
| AI product descriptions and translations | Generally no labeling requirement—responsibility for content remains with the retailer. |
| Recommendation engine, personalization | Not a high-risk system; no Article 50 obligation applies; the general AI competence requirement applies. |
| AI in applicant tracking systems | High-risk according to Annex III—obligations do not take effect until December 2, 2027. |
When do the high-risk rules apply—and what has the “Digital Omnibus” postponed?
The high-risk obligations will take effect later than originally planned: The EU’s “Digital Omnibus,” formally adopted at the end of June 2026, postpones the obligations for high-risk systems under Annex III (such as AI in personnel selection or creditworthiness assessments) to December 2, 2027, and for AI in regulated products under Annex I to August 2, 2028. This clears up a common misconception: The high-risk rules did not take effect on August 2, 2026. However, the transparency requirements of Article 50 remain unaffected—they have been in effect since the effective date. For most e-commerce applications, this is good news: Chatbots, product descriptions, image generators, and recommendation systems are typically not considered high-risk—but they may still be subject to transparency requirements.
What fines are imposed for violations?
Violations of the transparency obligations under Article 50 can be penalized with fines of up to €15 million or 3% of the global annual revenue from the preceding fiscal year—whichever amount is higher. In addition, there is a risk under competition law: Anyone who passes off AI-generated content as supposedly real photos or a bot as a human advisor may also face allegations of misleading consumers. Realistically speaking, regulatory authorities will initially focus on issuing warnings and requiring corrective action for smaller merchants—but you shouldn’t count on this leniency.
What should online store operators do now?
The effort involved is manageable if you take a systematic approach:
- AI inventory: List all AI applications in the store—chatbots, text generation, image tools, translation, and AI functions provided by service providers.
- Label chatbots: Include a visible notice in the chat window and ensure a clear transition when a human takes over.
- Review image library: Identify and disclose photorealistic AI images or replace them with real photos.
- Document AI proficiency: Provide verifiable proof of employee training in AI use (mandatory as of February 2, 2025).
- Inquire with providers: Obtain confirmation that the generators used mark their output in a machine-readable format.
As a shop system manufacturer based in Chemnitz, XONIC Solutions has been supporting legal compliance in e-commerce since 2005—from button solutions to cookie consent; the XONIC Shop System is developed according to the “Privacy by Design” principle. We’ve already summarized what’s important for a GDPR-compliant e-commerce platform —and the Sistrix AI Check shows how visible your store is in AI responses.
Note: This article does not constitute legal advice. Binding information regarding the classification of your specific AI applications can be obtained from specialized law firms.
